Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.

Antwort
Alt 02.01.2014, 13:00   #1
Mixia
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



Frohes neues Jahr,

Ähnlich wie in diesem Post [ http://www.trojaner-board.de/146908-...-browsern.html ], habe auch ich (bzw mein Vater) folgendes Problem:
Nation-zoom (.com) öffnet sich automatisch sowohl beim Öffnen von Chrome, als auch beim Öffnen des Internet Explorers. Ich habe bereits (pro forma) versucht, die Startseite zu ändern, was nichts brachte.
In den letzten Tagen wurde ein 7-zip file manager installiert, allerdings weiß mein Vater nicht mehr von welcher Seite, könnte also das Einfallstor gewesen sein.
Der Virusscan zeigt nichts an.

Schritt 1:
Laufwerksemulationen abschalten mit Defogger
-wurde gemacht

Schritt 2:
Systemscan mit FRST
FRST :
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-01-2014 01
Ran by Hans Desktop PC (administrator) on HANSDESKTOPPC on 02-01-2014 13:01:26
Running from C:\Users\Hans Desktop PC\Downloads
Windows 7 Professional N Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\eEBAPI\eEBSvc.exe
(AVM GmbH) C:\Program Files (x86)\FRITZ!Powerline\PowerlineService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
() C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe
() D:\Program Files (x86)\Kies\Kies.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
() D:\Program Files (x86)\Kies\KiesTrayAgent.exe
() D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
() C:\Users\Hans Desktop PC\Downloads\Defogger.exe

==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] - D:\Program Files (x86)\Kies\KiesTrayAgent.exe
HKLM-x32\...\Run: [NBAgent] - C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe [1493288 2012-01-13] (Nero AG)
HKCU\...\Run: [KiesPreload] - D:\Program Files (x86)\Kies\Kies.exe /preload
HKCU\...\Run: [] - D:\Program Files (x86)\Kies\External\FirmwareUpdate\KiesPDLR.exe Run
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2741616 2011-03-04] (Hewlett-Packard Company)
HKCU\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Hans Desktop PC\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.tagesschau.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x84E3C03977D6CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms}
SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = 
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B&q={searchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=NIS&chn=retail&geo=DE&ver=20&locale=de_DE&gct=sb&qsrc=2869
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\IPSBHO.dll (Symantec Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

Chrome: 
=======
CHR HomePage: hxxp://tagesschau.de/
CHR RestoreOnStartup: "hxxp://www.nationzoom.com/?type=hp&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B"
CHR Extension: (Google Docs) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Extended Protection) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0
CHR Extension: (Google Search) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Lightning Newtab) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.1.7.9_0
CHR Extension: (Norton Identity Protection) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0
CHR Extension: (Google Wallet) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (MySearchDial __MSG_newtab__) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff\9.4.4_0
CHR Extension: (Gmail) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\HANSDE~1\AppData\Local\mysearchdial-speeddial.crx
CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\Exts\Chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\HANSDE~1\AppData\Local\mysearchdial-speeddial.crx
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1388584618&from=tugs&uid=M4-CT128M4SSD2_00000000112603133F2B

==================== Services (Whitelisted) =================

R2 AVMPowerlineService; C:\Program Files (x86)\FRITZ!Powerline\PowerlineService.exe [126976 2013-10-11] (AVM GmbH)
R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\eEBAPI\eEBSVC.exe [90112 2004-11-17] (SEIKO EPSON CORPORATION)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe [275696 2013-10-08] (Symantec Corporation)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-07-04] (TuneUp Software)
R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248704 2013-08-14] ()

==================== Drivers (Whitelisted) ====================

R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20131203.001\BHDrvx64.sys [1526488 2013-12-03] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-24] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-24] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140101.001\IDSvia64.sys [521944 2013-12-14] (Symantec Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140101.021\ENG64.SYS [126040 2013-12-26] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140101.021\EX64.SYS [2099288 2013-12-26] (Symantec Corporation)
R1 SRTSP; C:\Windows\System32\Drivers\NISx64\1501000.012\SRTSP64.SYS [858200 2013-09-27] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS [36952 2013-09-10] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1501000.012\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1501000.012\SYMEFA64.SYS [1147480 2013-09-27] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-14] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS [264280 2013-09-27] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1501000.012\SYMNETS.SYS [590936 2013-09-26] (Symantec Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-05-03] (TuneUp Software)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-02 13:01 - 2014-01-02 13:01 - 00015190 _____ C:\Users\Hans Desktop PC\Downloads\FRST.txt
2014-01-02 13:01 - 2014-01-02 13:01 - 00000000 ____D C:\FRST
2014-01-02 13:00 - 2014-01-02 13:00 - 01931426 _____ (Farbar) C:\Users\Hans Desktop PC\Downloads\FRST64.exe
2014-01-02 12:59 - 2014-01-02 12:59 - 00000492 _____ C:\Users\Hans Desktop PC\Downloads\defogger_disable.log
2014-01-02 12:59 - 2014-01-02 12:59 - 00000000 _____ C:\Users\Hans Desktop PC\defogger_reenable
2014-01-02 12:58 - 2014-01-02 12:58 - 00050477 _____ C:\Users\Hans Desktop PC\Downloads\Defogger.exe
2014-01-02 11:53 - 2014-01-02 11:53 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012
2014-01-02 11:32 - 2014-01-02 11:35 - 00003990 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8C789A6B-65A8-4A76-A311-F27A13C4B32B}
2014-01-01 17:51 - 2014-01-01 17:52 - 00063044 _____ C:\Users\Hans Desktop PC\Downloads\Bravo Hits - Vol. 32.rar.nzb
2014-01-01 15:12 - 2014-01-01 15:16 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Mp3tag
2014-01-01 14:57 - 2014-01-02 12:03 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\newnext.me
2014-01-01 14:57 - 2014-01-01 14:59 - 00000000 ____D C:\ProgramData\WPM
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\genienext
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\.android
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Program Files (x86)\7-Zip
2014-01-01 14:44 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero
2014-01-01 13:24 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero_AG
2014-01-01 11:57 - 2014-01-01 11:57 - 00000000 ____D C:\Program Files (x86)\MarkAny
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Nero
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\ProgramData\LightScribe
2014-01-01 11:44 - 2014-01-01 11:44 - 00002213 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00002193 _____ C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2012
2014-01-01 11:44 - 2012-07-04 10:49 - 00034656 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe
2014-01-01 11:44 - 2012-07-04 10:49 - 00025952 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll
2014-01-01 11:44 - 2012-07-04 10:49 - 00021344 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll
2014-01-01 11:16 - 2014-01-01 11:37 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CrashDumps
2013-12-31 11:13 - 2014-01-02 11:27 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-Q5-TTL.DAT
2013-12-24 19:01 - 2013-12-24 19:02 - 00259770 _____ C:\Windows\msxml4-KB2758694-enu.LOG
2013-12-24 18:38 - 2013-12-24 18:38 - 02634152 _____ C:\Users\Hans Desktop PC\Downloads\mp3tagv258setup.exe
2013-12-24 18:38 - 2013-12-24 18:38 - 00000983 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2013-12-24 18:38 - 2013-12-24 18:38 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Hausverwalter
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl Data Service
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl Data Service
2013-12-24 11:13 - 2013-12-24 11:13 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2013-12-22 17:38 - 2013-12-22 17:38 - 00001181 _____ C:\Users\Public\Desktop\MAGIX Video easy TERRATEC Edition.lnk
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\ProgramData\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-12-22 17:37 - 2013-12-22 17:37 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-12-22 17:34 - 2013-12-22 17:36 - 211870088 _____ (MAGIX AG) C:\Users\Hans Desktop PC\Downloads\MAGIX_Video_easy_TERRATEC_Edition.exe
2013-12-22 17:34 - 2013-12-22 17:34 - 00000000 ____D C:\ProgramData\CMUV
2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files\DIFX
2013-12-22 17:32 - 2013-12-22 17:32 - 00000000 ____D C:\Program Files (x86)\TERRATEC
2013-12-22 17:29 - 2013-12-22 17:32 - 03311568 _____ C:\Users\Hans Desktop PC\Downloads\TERRATEC_CINERGY_HTC_Stick_HD_Driver_Setup_7.0.122.90_XP_Vista_7_8.exe
2013-12-22 17:28 - 2013-12-22 17:28 - 00001137 _____ C:\Users\Hans Desktop PC\Desktop\DVBViewer TERRATEC Edition.lnk
2013-12-22 17:28 - 2013-12-22 17:28 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition
2013-12-22 16:51 - 2013-12-22 16:51 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:51 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:50 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-12-22 15:54 - 2013-12-22 15:54 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk
2013-12-22 15:53 - 2013-12-22 15:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk
2013-12-22 15:52 - 2013-12-22 16:01 - 00000000 ____D C:\ProgramData\Nero
2013-12-22 15:10 - 2013-12-22 15:56 - 00000000 ____D C:\Program Files (x86)\Nero
2013-12-22 15:10 - 2011-12-01 11:42 - 00072240 _____ (Nero AG) C:\Windows\system32\Drivers\NBVol.sys
2013-12-22 15:10 - 2011-12-01 11:42 - 00015920 _____ (Nero AG) C:\Windows\system32\Drivers\NBVolUp.sys
2013-12-22 15:04 - 2013-12-22 15:04 - 00002037 _____ C:\Users\Public\Desktop\LightScribe.lnk
2013-12-22 15:04 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2013-12-22 15:04 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2013-12-22 15:04 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2013-12-22 15:04 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2013-12-22 15:04 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2013-12-22 15:03 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2013-12-22 15:03 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2013-12-22 15:03 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2013-12-22 15:03 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2013-12-22 15:03 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2013-12-22 15:03 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2013-12-18 16:56 - 2013-12-25 11:15 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mein Steuer-Sparbuch Heute
2013-12-15 16:46 - 2013-12-15 16:46 - 00001000 _____ C:\Users\Public\Desktop\WISO Hausverwalter 2014.lnk
2013-12-15 16:34 - 2013-12-15 16:34 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl
2013-12-15 12:45 - 2013-12-24 11:46 - 00000651 _____ C:\Windows\wiso.ini
2013-12-15 12:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl
2013-12-15 12:45 - 2013-12-15 12:45 - 00000986 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk
2013-12-15 12:12 - 2013-12-24 11:45 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH
2013-12-11 17:08 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-11 17:08 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-11 17:08 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-11 17:08 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-11 17:07 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-11 17:07 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-11 17:07 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-11 17:07 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-11 17:07 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-11 17:07 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-11 17:07 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-11 17:07 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-11 17:07 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-11 17:07 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-11 17:07 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-11 17:07 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-11 17:07 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-11 17:07 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-11 17:07 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-11 17:07 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-11 17:07 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-11 17:07 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-11 17:07 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-11 17:07 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-11 17:07 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-11 17:07 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-11 17:07 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-11 17:07 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-11 17:07 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-11 17:07 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-11 17:07 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-11 17:07 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-11 17:07 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-11 17:07 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-11 17:07 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 15:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 15:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 15:22 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 15:22 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 15:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 15:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 15:22 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 15:22 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 15:22 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 15:22 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 15:22 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 15:22 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 15:22 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 15:22 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 15:22 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 15:22 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 15:22 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 15:22 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 15:22 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-04 19:13 - 2014-01-02 11:27 - 00000100 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WB.CFG
2013-12-04 19:13 - 2014-01-02 11:27 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-TTL.DAT
2013-12-03 12:19 - 2013-12-03 12:20 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CUSTPDF Writer
2013-12-03 12:14 - 2014-01-01 14:58 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Mobogenie
2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\wangzhisong\AppData\Local\Mobogenie
2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\wangzhisong
2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mobogenie
2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\cache
2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 _____ C:\Users\Hans Desktop PC\daemonprocess.txt
2013-12-03 12:13 - 2014-01-02 12:13 - 00000318 _____ C:\Windows\Tasks\DigitalSite.job
2013-12-03 12:13 - 2014-01-01 14:58 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2013-12-03 12:13 - 2013-12-03 12:13 - 00351124 _____ C:\Users\Hans Desktop PC\AppData\Local\mysearchdial-speeddial.crx
2013-12-03 12:13 - 2013-12-03 12:13 - 00003288 _____ C:\Windows\System32\Tasks\DigitalSite
2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\DigitalSite
2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\0D0S1L2Z1P1B
2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Program Files\PDFCreator
2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Program Files (x86)\GPLGS
2013-12-03 12:13 - 2011-10-04 22:43 - 00087552 _____ C:\Windows\system32\custmon64i.dll
2013-12-03 12:12 - 2013-12-03 12:12 - 01295288 _____ C:\Users\Hans Desktop PC\Downloads\PDFCreatorSetup.exe

==================== One Month Modified Files and Folders =======

2014-01-02 13:01 - 2014-01-02 13:01 - 00015190 _____ C:\Users\Hans Desktop PC\Downloads\FRST.txt
2014-01-02 13:01 - 2014-01-02 13:01 - 00000000 ____D C:\FRST
2014-01-02 13:00 - 2014-01-02 13:00 - 01931426 _____ (Farbar) C:\Users\Hans Desktop PC\Downloads\FRST64.exe
2014-01-02 12:59 - 2014-01-02 12:59 - 00000492 _____ C:\Users\Hans Desktop PC\Downloads\defogger_disable.log
2014-01-02 12:59 - 2014-01-02 12:59 - 00000000 _____ C:\Users\Hans Desktop PC\defogger_reenable
2014-01-02 12:59 - 2013-10-31 19:40 - 00000000 ____D C:\Users\Hans Desktop PC
2014-01-02 12:58 - 2014-01-02 12:58 - 00050477 _____ C:\Users\Hans Desktop PC\Downloads\Defogger.exe
2014-01-02 12:28 - 2013-11-01 18:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-02 12:13 - 2013-12-03 12:13 - 00000318 _____ C:\Windows\Tasks\DigitalSite.job
2014-01-02 12:09 - 2009-07-14 05:50 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-02 12:09 - 2009-07-14 05:50 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-02 12:07 - 2011-04-12 09:14 - 00653928 _____ C:\Windows\system32\perfh007.dat
2014-01-02 12:07 - 2011-04-12 09:14 - 00129800 _____ C:\Windows\system32\perfc007.dat
2014-01-02 12:07 - 2009-07-14 06:12 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-02 12:05 - 2013-10-31 19:36 - 01701272 _____ C:\Windows\WindowsUpdate.log
2014-01-02 12:04 - 2013-11-03 19:48 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-02 12:04 - 2013-11-03 19:48 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-02 12:03 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\newnext.me
2014-01-02 12:02 - 2013-10-31 19:44 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs
2014-01-02 12:02 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-02 12:02 - 2009-07-14 05:56 - 00037809 _____ C:\Windows\setupact.log
2014-01-02 11:53 - 2014-01-02 11:53 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012
2014-01-02 11:35 - 2014-01-02 11:32 - 00003990 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8C789A6B-65A8-4A76-A311-F27A13C4B32B}
2014-01-02 11:27 - 2013-12-31 11:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-Q5-TTL.DAT
2014-01-02 11:27 - 2013-12-04 19:13 - 00000100 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WB.CFG
2014-01-02 11:27 - 2013-12-04 19:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-TTL.DAT
2014-01-02 10:28 - 2010-11-21 04:47 - 00049552 _____ C:\Windows\PFRO.log
2014-01-01 17:52 - 2014-01-01 17:51 - 00063044 _____ C:\Users\Hans Desktop PC\Downloads\Bravo Hits - Vol. 32.rar.nzb
2014-01-01 15:16 - 2014-01-01 15:12 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Mp3tag
2014-01-01 14:59 - 2014-01-01 14:57 - 00000000 ____D C:\ProgramData\WPM
2014-01-01 14:58 - 2013-12-03 12:14 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Mobogenie
2014-01-01 14:58 - 2013-12-03 12:13 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\genienext
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\.android
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Program Files (x86)\7-Zip
2014-01-01 14:57 - 2013-11-03 19:48 - 00002373 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-01 14:57 - 2013-10-31 19:41 - 00001635 _____ C:\Users\Hans Desktop PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-01 14:44 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero
2014-01-01 14:44 - 2014-01-01 13:24 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero_AG
2014-01-01 11:58 - 2013-11-01 19:08 - 00000793 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-01-01 11:57 - 2014-01-01 11:57 - 00000000 ____D C:\Program Files (x86)\MarkAny
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Nero
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\ProgramData\LightScribe
2014-01-01 11:44 - 2014-01-01 11:44 - 00002213 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00002193 _____ C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2012
2014-01-01 11:37 - 2014-01-01 11:16 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CrashDumps
2013-12-25 11:15 - 2013-12-18 16:56 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mein Steuer-Sparbuch Heute
2013-12-24 19:02 - 2013-12-24 19:01 - 00259770 _____ C:\Windows\msxml4-KB2758694-enu.LOG
2013-12-24 18:38 - 2013-12-24 18:38 - 02634152 _____ C:\Users\Hans Desktop PC\Downloads\mp3tagv258setup.exe
2013-12-24 18:38 - 2013-12-24 18:38 - 00000983 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2013-12-24 18:38 - 2013-12-24 18:38 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-12-24 11:46 - 2013-12-15 12:45 - 00000651 _____ C:\Windows\wiso.ini
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Hausverwalter
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl Data Service
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl Data Service
2013-12-24 11:45 - 2013-12-15 12:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl
2013-12-24 11:45 - 2013-12-15 12:12 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH
2013-12-24 11:13 - 2013-12-24 11:13 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2013-12-24 10:14 - 2013-10-31 19:40 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\VirtualStore
2013-12-22 18:12 - 2013-10-31 21:27 - 00154336 _____ C:\Users\Hans Desktop PC\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-22 17:42 - 2009-07-14 05:50 - 00507536 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-22 17:38 - 2013-12-22 17:38 - 00001181 _____ C:\Users\Public\Desktop\MAGIX Video easy TERRATEC Edition.lnk
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\ProgramData\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-12-22 17:37 - 2013-12-22 17:37 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-12-22 17:36 - 2013-12-22 17:34 - 211870088 _____ (MAGIX AG) C:\Users\Hans Desktop PC\Downloads\MAGIX_Video_easy_TERRATEC_Edition.exe
2013-12-22 17:34 - 2013-12-22 17:34 - 00000000 ____D C:\ProgramData\CMUV
2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files\DIFX
2013-12-22 17:33 - 2013-10-31 23:07 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-22 17:32 - 2013-12-22 17:32 - 00000000 ____D C:\Program Files (x86)\TERRATEC
2013-12-22 17:32 - 2013-12-22 17:29 - 03311568 _____ C:\Users\Hans Desktop PC\Downloads\TERRATEC_CINERGY_HTC_Stick_HD_Driver_Setup_7.0.122.90_XP_Vista_7_8.exe
2013-12-22 17:28 - 2013-12-22 17:28 - 00001137 _____ C:\Users\Hans Desktop PC\Desktop\DVBViewer TERRATEC Edition.lnk
2013-12-22 17:28 - 2013-12-22 17:28 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition
2013-12-22 17:27 - 2013-11-01 19:01 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Downloaded Installations
2013-12-22 16:51 - 2013-12-22 16:51 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\TuneUp Software
2013-12-22 16:51 - 2013-12-22 16:50 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:50 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-12-22 16:01 - 2013-12-22 15:52 - 00000000 ____D C:\ProgramData\Nero
2013-12-22 15:56 - 2013-12-22 15:10 - 00000000 ____D C:\Program Files (x86)\Nero
2013-12-22 15:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Cursors
2013-12-22 15:54 - 2013-12-22 15:54 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk
2013-12-22 15:53 - 2013-12-22 15:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk
2013-12-22 15:04 - 2013-12-22 15:04 - 00002037 _____ C:\Users\Public\Desktop\LightScribe.lnk
2013-12-15 19:30 - 2013-11-01 19:08 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Samsung
2013-12-15 16:46 - 2013-12-15 16:46 - 00001000 _____ C:\Users\Public\Desktop\WISO Hausverwalter 2014.lnk
2013-12-15 16:34 - 2013-12-15 16:34 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl
2013-12-15 12:45 - 2013-12-15 12:45 - 00000986 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk
2013-12-15 12:08 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-12-15 00:13 - 2013-11-03 19:48 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Google
2013-12-14 17:34 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-11 17:08 - 2013-10-31 20:26 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 15:28 - 2013-11-01 18:59 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 15:28 - 2013-11-01 18:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 15:28 - 2013-11-01 18:59 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-08 17:20 - 2013-10-31 23:34 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\ChessBase
2013-12-08 11:59 - 2013-11-03 19:48 - 00004124 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-08 11:59 - 2013-11-03 19:48 - 00003872 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-03 12:20 - 2013-12-03 12:19 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CUSTPDF Writer
2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\wangzhisong\AppData\Local\Mobogenie
2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\wangzhisong
2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mobogenie
2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\cache
2013-12-03 12:14 - 2013-12-03 12:14 - 00000000 _____ C:\Users\Hans Desktop PC\daemonprocess.txt
2013-12-03 12:13 - 2013-12-03 12:13 - 00351124 _____ C:\Users\Hans Desktop PC\AppData\Local\mysearchdial-speeddial.crx
2013-12-03 12:13 - 2013-12-03 12:13 - 00003288 _____ C:\Windows\System32\Tasks\DigitalSite
2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\DigitalSite
2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\0D0S1L2Z1P1B
2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Program Files\PDFCreator
2013-12-03 12:13 - 2013-12-03 12:13 - 00000000 ____D C:\Program Files (x86)\GPLGS
2013-12-03 12:12 - 2013-12-03 12:12 - 01295288 _____ C:\Users\Hans Desktop PC\Downloads\PDFCreatorSetup.exe

Some content of TEMP:
====================
C:\Users\Hans Desktop PC\AppData\Local\Temp\opsrnrpevolrwo.exe
C:\Users\Hans Desktop PC\AppData\Local\Temp\TUUUninstallHelper.exe
C:\Users\Hans Desktop PC\AppData\Local\Temp\twnplxhj.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
         

Addition
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-01-2014 01
Ran by Hans Desktop PC at 2014-01-02 13:01:48
Running from C:\Users\Hans Desktop PC\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

==================== Installed Programs ======================

7-Zip 9.20 (x32 Version:  - )
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05 - Adobe Systems Incorporated)
Alt.Binz Prepaid Usenet edition Version 0.39.14 (x32 Version: 0.39.14 - Prepaid usenet)
ChessBase 12 64-bit (Version: 12.0.0.0 - ChessBase)
DRAGON 1.7 (x32 Version: 1.7 - PREPAID-USENET LIMITED)
DVBViewer TERRATEC Edition (x32 Version:  - CM&V)
EPSON Scan (x32 Version:  - )
EPSON Speed Dial Utility (x32 Version: 3.0.202 - SEIKO EPSON CORP.)
Epson Universal Laser P6 (Version:  - )
EPSON-Drucker-Software (Version:  - )
EpsonNet Config V2 (x32 Version: 2.2b - SEIKO EPSON CORPORATION)
EpsonNet SetupManager (x32 Version: 1.5.dE - SEIKO EPSON CORPORATION)
EpsonNet SetupManager (x32 Version: 1.5.dE - SEIKO EPSON CORPORATION) Hidden
eWallet 7.4.3 for Windows PCs (x32 Version: 7.4.3 - Ilium Software)
Fritz 13 (x32 Version: 13.0.0.0 - ChessBase)
FRITZ!Powerline (x32 Version: 01.00.54 - AVM Berlin)
Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (x32 Version: 7.5.4805.320 - Google Inc.)
Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden
High-Definition Video Playback (x32 Version: 11.1.11100.4.196 - Nero AG) Hidden
Houdini 3 Pro (x32 Version: 13.12.0.0 - ChessBase)
K-Lite Codec Pack 10.1.0 Full (x32 Version: 10.1.0 - )
LightScribe System Software (x32 Version: 1.18.22.2 - LightScribe)
Magic DVD Copier Version 4.9 build 5 (x32 Version:  - Magic DVD Software, Inc.)
MAGIX Video easy TERRATEC Edition (Version: 3.0.1.50 - MAGIX AG) Hidden
MAGIX Video easy TERRATEC Edition (x32 Version: 3.0.1.50 - MAGIX AG)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Mp3tag v2.58 (x32 Version: v2.58 - Florian Heidenreich)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0 - Microsoft Corporation)
MyFreeCodec (HKCU Version:  - )
Nero 11 Cliparts (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 Disc Menus 1 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 Disc Menus 2 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 Disc Menus 3 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 Disc Menus Basic (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 Effects Basic (x32 Version: 11.0.11400.14.0 - Nero AG) Hidden
Nero 11 Image Samples (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 Kwik Themes 1 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 Kwik Themes 2 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 Kwik Themes 3 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 Kwik Themes 4 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 Kwik Themes Basic (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 PiP Effects 1 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 PiP Effects Basic (x32 Version: 11.0.11400.14.0 - Nero AG) Hidden
Nero 11 Platinum (x32 Version: 11.2.00700 - Nero AG)
Nero 11 Video Samples (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero 11 Video Transitions 1 (x32 Version: 11.0.11200.12.0 - Nero AG) Hidden
Nero Audio Pack 1 (x32 Version: 11.0.11500.110.0 - Nero AG) Hidden
Nero BackItUp 11 (x32 Version: 6.2.18400.2.100 - Nero AG) Hidden
Nero BackItUp 11 Help (CHM) (x32 Version: 11.0.10400 - Nero AG) Hidden
Nero Backup Drivers (Version: 1.0.11100.8.0 - Nero AG)
Nero Burning ROM 11 (x32 Version: 11.2.10300.0.0 - Nero AG) Hidden
Nero Burning ROM 11 Help (CHM) (x32 Version: 11.0.10300 - Nero AG) Hidden
Nero ControlCenter 11 (x32 Version: 11.0.12700.0.27 - Nero AG) Hidden
Nero ControlCenter 11 Help (CHM) (x32 Version: 11.0.10300 - Nero AG) Hidden
Nero Core Components 11 (x32 Version: 11.0.16300.1.23 - Nero AG) Hidden
Nero CoverDesigner 11 (x32 Version: 6.0.11000.13.100 - Nero AG) Hidden
Nero CoverDesigner 11 Help (CHM) (x32 Version: 11.0.10300 - Nero AG) Hidden
Nero Express 11 (x32 Version: 11.2.10300.0.0 - Nero AG) Hidden
Nero Express 11 Help (CHM) (x32 Version: 11.0.10300 - Nero AG) Hidden
Nero Kwik Media (x32 Version: 1.10.24800.146.100 - Nero AG) Hidden
Nero Kwik Media Help (CHM) (x32 Version: 11.0.10200 - Nero AG) Hidden
Nero Recode 11 (x32 Version: 5.2.10900.0.0 - Nero AG) Hidden
Nero Recode 11 Help (CHM) (x32 Version: 11.0.10600 - Nero AG) Hidden
Nero RescueAgent 11 (x32 Version: 4.0.10600.10.100 - Nero AG) Hidden
Nero RescueAgent 11 Help (CHM) (x32 Version: 11.0.10400 - Nero AG) Hidden
Nero SharedVideoCodecs (x32 Version: 1.0.11500.1.5 - Nero AG) Hidden
Nero SoundTrax 11 (x32 Version: 5.0.10700.6.100 - Nero AG) Hidden
Nero SoundTrax 11 Help (CHM) (x32 Version: 11.0.10400 - Nero AG) Hidden
Nero Update (x32 Version: 11.0.11500.28.0 - Nero AG) Hidden
Nero Video 11 (x32 Version: 8.2.15700.3.100 - Nero AG) Hidden
Nero Video 11 Help (CHM) (x32 Version: 11.0.10300 - Nero AG) Hidden
Nero WaveEditor 11 (x32 Version: 6.2.11300.0.100 - Nero AG) Hidden
Nero WaveEditor 11 Help (CHM) (x32 Version: 11.0.10400 - Nero AG) Hidden
nero.prerequisites.msi (x32 Version: 11.0.20010 - Nero AG) Hidden
Norton Internet Security (x32 Version: 21.1.0.18 - Symantec Corporation)
PDF Creator (Version:  - )
PDF Creator Packages (HKCU Version:  - )
Samsung Kies (x32 Version: 2.6.1.13105_6 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.6.1.13105_6 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.29.0 - SAMSUNG Electronics Co., Ltd.)
Synology Assistant (remove only) (x32 Version:  - )
TERRATEC CINERGY HTC Stick HD (64Bit) (x32 Version: 7.0.122.90 - TERRATEC)
TERRATEC CINERGY HTC Stick HD (x32 Version: 7.0.122.90 - TERRATEC)
TuneUp Utilities 2012 (x32 Version: 12.0.3600.114 - TuneUp Software)
TuneUp Utilities 2012 (x32 Version: 12.0.3600.114 - TuneUp Software) Hidden
TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.114 - TuneUp Software) Hidden
Update for 2007 Microsoft Office System (KB967642) (x32 Version:  - Microsoft)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (x32 Version:  - Microsoft)
Update for PDF Creator (HKCU Version:  - ) <==== ATTENTION
Update für Microsoft Office Excel 2007 Help (KB963678) (x32 Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (x32 Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32 Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (x32 Version:  - Microsoft)
Welcome App (Start-up experience) (x32 Version: 11.0.23500.0.0 - Nero AG) Hidden
Windows-Treiberpaket - TERRATEC (CXIR) HIDClass  (06/04/2013 7.0.122.9) (Version: 06/04/2013 7.0.122.9 - TERRATEC)
Windows-Treiberpaket - TERRATEC (CXPOLARIS) Media  (06/04/2013 7.0.122.9) (Version: 06/04/2013 7.0.122.9 - TERRATEC)
WISO Hausverwalter 2014 (x32 Version: 8.00.8332 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2014 (x32 Version: 21.00.8480 - Buhl Data Service GmbH)

==================== Restore Points  =========================

01-01-2014 12:51:07 Geplanter Prüfpunkt

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {1D9BBA07-34D3-4EEE-93E8-03513A16D453} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {3E804A6C-C97E-4DCE-B4E4-518162A21706} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\symerr.exe [2013-08-01] (Symantec Corporation)
Task: {42926C80-5756-4BC0-B43B-84C1D7B75D96} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-03] (Google Inc.)
Task: {54D916DD-808F-43F0-94F5-EB42E960B7FD} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2012-07-04] (TuneUp Software)
Task: {85D5354C-5AA1-426B-AD66-5CCC71F65602} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\symerr.exe [2013-08-01] (Symantec Corporation)
Task: {AD3516DE-A407-4723-9697-36A1F9E93AB0} - System32\Tasks\DigitalSite => C:\Users\Hans Desktop PC\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {C5C94D19-5421-4B9B-8B21-788D065F45B2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated)
Task: {C7AE8B62-AE23-4FEC-BA85-145B9241F746} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\WSCStub.exe [2013-10-08] (Symantec Corporation)
Task: {E3B687E7-6B87-4064-B2FC-FD3B55EC102E} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-09-05] (Adobe Systems Incorporated)
Task: {E666C32A-9E5C-4F5C-AFFC-002E80FAFEE7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-03] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe <==== ATTENTION
Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\HANSDE~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2011-03-04 12:02 - 2011-03-04 12:02 - 02121728 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
2011-03-04 12:02 - 2011-03-04 12:02 - 07745536 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
2011-03-04 12:02 - 2011-03-04 12:02 - 00135168 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
2013-12-08 12:07 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libglesv2.dll
2013-12-08 12:07 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libegl.dll
2013-12-08 12:07 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll
2013-12-08 12:07 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
2013-12-08 12:07 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll
2013-12-08 12:07 - 2013-12-04 03:48 - 13586896 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll
2013-07-10 18:07 - 2013-07-10 18:07 - 00756888 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============

Name: Standardtastatur (PS/2)
Description: Standardtastatur (PS/2)
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardtastaturen)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Cinergy HTC USB XS
Description: Cinergy HTC USB XS
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Microsoft PS/2-Maus
Description: Microsoft PS/2-Maus
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/02/2014 00:04:33 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/02/2014 10:29:50 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/01/2014 03:10:57 PM) (Source: .NET Runtime) (User: )
Description: .NET Runtime version 4.0.30319.1008 - Fehler beim Initialisieren der Profilerstellungs-API-Anfügeinfrastruktur. Dieser Prozess ermöglicht einem Profiler das Anfügen nicht. HRESULT: 0x80004005.  Prozess-ID (dezimal): 2232. Meldungs-ID: [0x2509].

Error: (01/01/2014 01:32:41 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: D:\Program Files (x86)\Kies\Kies.exe . Error code = 0x800700d8

Error: (01/01/2014 01:32:41 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: D:\Program Files (x86)\Kies\Kies.exe . Error code = 0x800700d8

Error: (01/01/2014 11:57:15 AM) (Source: .NET Runtime) (User: )
Description: Anwendung: Kies.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
   bei Kies.Plugin.DeviceHost.DeviceHostVM.threadOutlookFolder(System.Object)
   bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   bei System.Threading.ThreadHelper.ThreadStart(System.Object)

Error: (01/01/2014 11:45:37 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: nvwgf2um.dll, Version: 8.15.11.8593, Zeitstempel: 0x4a5be117
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000423de
ID des fehlerhaften Prozesses: 0xdf4
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3

Error: (01/01/2014 11:36:47 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: OneClick.exe, Version: 12.0.3600.114, Zeitstempel: 0x4ff402dc
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1116
Ausnahmecode: 0x0eedfade
Fehleroffset: 0x0000c41f
ID des fehlerhaften Prozesses: 0x103c
Startzeit der fehlerhaften Anwendung: 0xOneClick.exe0
Pfad der fehlerhaften Anwendung: OneClick.exe1
Pfad des fehlerhaften Moduls: OneClick.exe2
Berichtskennung: OneClick.exe3

Error: (01/01/2014 11:16:44 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: OneClick.exe, Version: 12.0.3600.114, Zeitstempel: 0x4ff402dc
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1116
Ausnahmecode: 0x0eedfade
Fehleroffset: 0x0000c41f
ID des fehlerhaften Prozesses: 0x13bc
Startzeit der fehlerhaften Anwendung: 0xOneClick.exe0
Pfad der fehlerhaften Anwendung: OneClick.exe1
Pfad des fehlerhaften Moduls: OneClick.exe2
Berichtskennung: OneClick.exe3

Error: (01/01/2014 11:08:21 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (01/02/2014 00:02:44 PM) (Source: Ntfs) (User: )
Description: Auf dem Volume "F:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (01/02/2014 00:02:42 PM) (Source: atapi) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort7 gefunden.

Error: (01/02/2014 10:28:02 AM) (Source: Ntfs) (User: )
Description: Auf dem Volume "F:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (01/02/2014 10:27:59 AM) (Source: atapi) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort7 gefunden.

Error: (01/01/2014 01:49:53 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (01/01/2014 11:06:32 AM) (Source: Ntfs) (User: )
Description: Auf dem Volume "F:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (01/01/2014 11:06:30 AM) (Source: atapi) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort7 gefunden.

Error: (12/31/2013 11:20:08 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.

Error: (12/31/2013 11:20:02 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.

Error: (12/31/2013 11:20:02 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.


Microsoft Office Sessions:
=========================

==================== Memory info =========================== 

Percentage of memory in use: 36%
Total physical RAM: 6135.17 MB
Available physical RAM: 3924.49 MB
Total Pagefile: 12268.52 MB
Available Pagefile: 9614.11 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:119.14 GB) (Free:54.59 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: (Volume) (Fixed) (Total:1863.01 GB) (Free:81.13 GB) NTFS
Drive g: (Acer) (Fixed) (Total:691.95 GB) (Free:374.16 GB) NTFS
Drive h: (DATA) (Fixed) (Total:692.21 GB) (Free:0.01 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 42BEBAC4)
Partition 1: (Not Active) - (Size=100 MB) - (Type=27)
Partition 2: (Active) - (Size=119 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 1397 GB) (Disk ID: F41CCCF5)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=692 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=692 GB) - (Type=07 NTFS)

========================================================
Disk: 3 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 74D6C828)
Partition 1: (Not Active) - (Size=-198626508800) - (Type=07 NTFS)

==================== End Of Log ============================
         
Schritt 3:
Scan mit GMER
Gmer:
Code:
ATTFilter
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2014-01-02 13:10:11
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 M4-CT128M4SSD2 rev.0002 119,24GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\HANSDE~1\AppData\Local\Temp\pwtdipod.sys


---- User code sections - GMER 2.1 ----

.text    C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1612] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                               0000000074fc1465 2 bytes [FC, 74]
.text    C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1612] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                              0000000074fc14bb 2 bytes [FC, 74]
.text    ...                                                                                                                                                                    * 2
.text    C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[1812] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                           0000000074fc1465 2 bytes [FC, 74]
.text    C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[1812] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                          0000000074fc14bb 2 bytes [FC, 74]
.text    ...                                                                                                                                                                    * 2
---- Processes - GMER 2.1 ----

Library  D:\Program Files (x86)\Kies\Kies.exe (*** suspicious ***) @ D:\Program Files (x86)\Kies\Kies.exe [3264]                                                                0000000000d40000
Library  D:\Program Files (x86)\Kies\External\MACSSDK.dll (*** suspicious ***) @ D:\Program Files (x86)\Kies\Kies.exe [3264]                                                    0000000010000000
Library  D:\Program Files (x86)\Kies\KiesTrayAgent.exe (*** suspicious ***) @ D:\Program Files (x86)\Kies\KiesTrayAgent.exe [3576]                                              0000000000400000
Library  D:\Program Files (x86)\Kies\External\DeviceModules\UPNPDevice_Kies.dll (*** suspicious ***) @ D:\Program Files (x86)\Kies\KiesTrayAgent.exe [3576]                     0000000010000000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]            0000000001180000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wgui14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]                0000000067cf0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\rsdcom48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]              0000000072ac0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\MSVCR100.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]              0000000071bc0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\QtCorers48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]            0000000071940000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\MSVCP100.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]              0000000071830000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\QtGuirs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]             0000000066bd0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\QtNetworkrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]         0000000069a20000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\SSLEAY32.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]              0000000069d00000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\LIBEAY32.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]              0000000069900000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\QtXmlrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]             0000000069800000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\QtSqlrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]             0000000069740000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\QtScriptrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]          0000000068950000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\Qt3Supportrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]        0000000068700000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\QtWebKitrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]          00000000653d0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\QtTestrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]            0000000069ca0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\rscorewinapi48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]        0000000065380000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\rsguiwinapi48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]         0000000065330000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wcore14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               0000000064fa0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\rsodbc48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]              0000000064f70000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wfvie14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               0000000064d10000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\QtXmlPatternsrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]     0000000064a80000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\QtSvgrs48.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]             0000000064a30000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wsteu14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               0000000064860000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wreli14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               0000000064680000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wauff14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               0000000064260000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\clucene-core.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]          0000000064150000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\clucene-shared.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]        0000000064130000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\zlib.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]                  0000000061b80000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\clucene-contribs-lib.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]  00000000640e0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wmain14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               0000000003da0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wbae114.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               0000000067820000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wbae214.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               0000000067680000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wbae314.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               00000000674c0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wbae414.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               0000000063df0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\whau114.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               0000000063cd0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\whau214.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               0000000063b80000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wwerb14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               0000000063a40000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wkont14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               00000000621c0000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wimp14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]                0000000063900000
Library  D:\Program Files (x86)\WISO\Steuersoftware 2014\wfabu14.dll (*** suspicious ***) @ D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe [3592]               00000000637b0000

---- EOF - GMER 2.1 ----
         
Vielen Dank fürs Helfen!

Alt 02.01.2014, 13:05   #2
sunjojo
/// Malwareteam
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern





Ich habe dein Thema in Arbeit und melde mich so schnell als möglich mit weiteren Anweisungen.

Bitte beachte, dass alle meine Antworten zuerst von einem Ausbilder freigegeben werden müssen, bevor ich diese hier posten darf. Dies garantiert, dass Du Hilfe von einem ausgebildeten Helfer bekommst.

Ich bedanke mich für deine Geduld
__________________

__________________

Alt 02.01.2014, 18:54   #3
sunjojo
/// Malwareteam
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



Hallo Mixia,

Meine Name ist Jonas und ich werde dir bei deiner Bereinigung helfen. Diese kann mit viel Arbeit für dich verbunden sein. Bevor wir anfangen können, lies bitte die Bereinigungsregeln und Hinweise:
Regeln zum Ablauf der Bereinigung
  • Arbeite die Anleitungen und Schritte sorgfältig und nacheinander ab.
  • Wenn du etwas nicht verstehst oder du dir unsicher bist, frage nach und schildere das Problem, so gut es geht. Handle nicht auf eigene Faust.
    • Die Ausführung diverser Bereinigungsprogramme (mit Scripts aus anderen Threads) können dein Betriebssystem zerschießen!
  • Die Bereinigung eines Rechners in verschiedenen Foren zur selben Zeit ist verboten (Crossposting).
  • Installiere oder deinstalliere keine zusätzlichen Programme, lösche keine Dateien und führe nicht selbstständig Systemupdates durch.
  • Die Symptome können verschwunden sein, jedoch bedeutet das Verschwinden von äußeren Merkmalen einer Infektion nicht, dass du wieder clean bist.
    • Ich werde dir ein eindeutiges Clean geben, solange arbeite bitte mit.
Hinweise
  • Ich kann dir nie eine Garantie geben, dass alles entfernt wurde. Die Formatierung der Festplatte und das Neuinstallieren deines Betriebssystems ist immer sicherer und meistens schneller.
  • Die von uns benutzten Programme erstellen meist ein Ergebnisprotokoll (Logfile genannt). Bitte füge alle von mir in einem Schritt geforderten Logfiles in einer Antwort/einem Post ein.
Wenn du alles gelesen hast, kann es losgehen. Bitte speichere alle Programme auf dem Desktop und führe sie von dort aus.



Schritt 1
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).
Schritt 2
Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, wird ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.



Poste folgende Logfiles in deiner nächsten Antwort:
  • AdwCleaner-Scan
  • FRST-Scan
__________________
__________________

Alt 02.01.2014, 21:45   #4
Mixia
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



Hallo Jonas,

Ich lasse gerade den Adwcleaner laufen. Woher weiß ich denn, wann der fertig ist? Er läuft seit etwas mehr als zwei Stunden und hat auch schone einiges gefunden. Außerdem leuchtet der 'Bericht'- Button.
Es steht allerdings immer noch 'Warte ab.' über der Leiste, die komplett grau ist.

Mixia

Alt 02.01.2014, 22:44   #5
sunjojo
/// Malwareteam
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



Zitat:
Ich lasse gerade den Adwcleaner laufen. Woher weiß ich denn, wann der fertig ist? Er läuft seit etwas mehr als zwei Stunden und hat auch schone einiges gefunden. Außerdem leuchtet der 'Bericht'- Button.
Es steht allerdings immer noch 'Warte ab.' über der Leiste, die komplett grau ist.
Wenn über der grauen Leiste "Warte ab ... " steht, ist der AdwCleaner bereits mit seinem Suchlauf fertig und du musst auf "Löschen" drücken, damit die gefundenen Sachen gelöscht werden .

__________________
Gruß,

Jonas

Alt 03.01.2014, 08:48   #6
Mixia
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



O.K

Hier sind dann die Logs

Adwcleaner:
Code:
ATTFilter
# AdwCleaner v3.016 - Bericht erstellt am 03/01/2014 um 09:40:28
# Aktualisiert 23/12/2013 von Xplode
# Betriebssystem : Windows 7 Professional N Service Pack 1 (64 bits)
# Benutzername : Hans Desktop PC - HANSDESKTOPPC
# Gestartet von : C:\Users\Hans Desktop PC\Desktop\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
Ordner Gelöscht : C:\Program Files (x86)\Mobogenie
Ordner Gelöscht : C:\Users\Hans Desktop PC\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Hans Desktop PC\AppData\Roaming\digitalsite
Ordner Gelöscht : C:\Users\Hans Desktop PC\Documents\Mobogenie
Ordner Gelöscht : C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml
Ordner Gelöscht : C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Ordner Gelöscht : C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Datei Gelöscht : C:\Users\Hans Desktop PC\AppData\Local\mysearchdial-speeddial.crx
Datei Gelöscht : C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx
Datei Gelöscht : C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage
Datei Gelöscht : C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pflphaooapbgpeakohlggbpidpppgdff_0.localstorage
Datei Gelöscht : C:\Windows\Tasks\digitalsite.job
Datei Gelöscht : C:\Windows\System32\Tasks\digitalsite

***** [ Verknüpfungen ] *****

Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Hans Desktop PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Hans Desktop PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Hans Desktop PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Hans Desktop PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Hans Desktop PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk

***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NextLive]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKLM\Software\Myfree Codec
Schlüssel Gelöscht : HKLM\Software\nationzoomSoftware
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.16428

Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v31.0.1650.63

[ Datei : C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [11409 octets] - [02/01/2014 20:31:52]
AdwCleaner[R1].txt - [11470 octets] - [03/01/2014 09:39:38]
AdwCleaner[S0].txt - [8737 octets] - [03/01/2014 09:40:28]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8797 octets] ##########
         
Und hier FRST

FRST (2):

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-01-2014
Ran by Hans Desktop PC (administrator) on HANSDESKTOPPC on 03-01-2014 09:43:16
Running from C:\Users\Hans Desktop PC\Downloads
Windows 7 Professional N Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\eEBAPI\eEBSvc.exe
(AVM GmbH) C:\Program Files (x86)\FRITZ!Powerline\PowerlineService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
() C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe
(Samsung) D:\Program Files (x86)\Kies\Kies.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
() D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe
(Samsung Electronics Co., Ltd.) D:\Program Files (x86)\Kies\KiesTrayAgent.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] - D:\Program Files (x86)\Kies\KiesTrayAgent.exe [311152 2013-12-11] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [NBAgent] - C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe [1493288 2012-01-13] (Nero AG)
HKCU\...\Run: [KiesPreload] - D:\Program Files (x86)\Kies\Kies.exe [1564528 2013-12-11] (Samsung)
HKCU\...\Run: [] - D:\Program Files (x86)\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-12-11] (Samsung)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2741616 2011-03-04] (Hewlett-Packard Company)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.tagesschau.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x84E3C03977D6CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\IPSBHO.dll (Symantec Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

Chrome: 
=======
CHR HomePage: hxxp://tagesschau.de/
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Extension: (Google Docs) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Norton Identity Protection) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0
CHR Extension: (Google Wallet) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Gmail) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\Exts\Chrome.crx

==================== Services (Whitelisted) =================

R2 AVMPowerlineService; C:\Program Files (x86)\FRITZ!Powerline\PowerlineService.exe [126976 2013-10-11] (AVM GmbH)
R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\eEBAPI\eEBSVC.exe [90112 2004-11-17] (SEIKO EPSON CORPORATION)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe [275696 2013-10-08] (Symantec Corporation)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-07-04] (TuneUp Software)
R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248704 2013-08-14] ()

==================== Drivers (Whitelisted) ====================

R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20131203.001\BHDrvx64.sys [1526488 2013-12-03] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-24] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-24] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140102.001\IDSvia64.sys [521944 2013-12-14] (Symantec Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140102.008\ENG64.SYS [126040 2013-12-26] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140102.008\EX64.SYS [2099288 2013-12-26] (Symantec Corporation)
R1 SRTSP; C:\Windows\System32\Drivers\NISx64\1501000.012\SRTSP64.SYS [858200 2013-09-27] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS [36952 2013-09-10] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1501000.012\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1501000.012\SYMEFA64.SYS [1147480 2013-09-27] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-14] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS [264280 2013-09-27] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1501000.012\SYMNETS.SYS [590936 2013-09-26] (Symantec Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-05-03] (TuneUp Software)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-03 09:43 - 2014-01-03 09:43 - 00000000 ____D C:\Users\Hans Desktop PC\Downloads\FRST-OlderVersion
2014-01-03 09:42 - 2014-01-03 09:42 - 00008921 _____ C:\Users\Hans Desktop PC\Desktop\AdwCleaner[S0].txt
2014-01-03 02:33 - 2014-01-03 02:33 - 00535712 _____ C:\Windows\Minidump\010314-22230-01.dmp
2014-01-02 20:31 - 2014-01-03 09:40 - 00000000 ____D C:\AdwCleaner
2014-01-02 20:30 - 2014-01-02 20:30 - 01233962 _____ C:\Users\Hans Desktop PC\Desktop\adwcleaner.exe
2014-01-02 13:10 - 2014-01-02 13:10 - 00010330 _____ C:\Users\Hans Desktop PC\Desktop\Gmer.txt
2014-01-02 13:04 - 2014-01-02 13:04 - 00377856 _____ C:\Users\Hans Desktop PC\Downloads\gmer_2.1.19163.exe
2014-01-02 13:03 - 2014-01-02 20:29 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Viruslog
2014-01-02 13:03 - 2014-01-02 13:03 - 00043723 _____ C:\Users\Hans Desktop PC\Desktop\FRST.txt
2014-01-02 13:03 - 2014-01-02 13:03 - 00025562 _____ C:\Users\Hans Desktop PC\Desktop\Addition.txt
2014-01-02 13:01 - 2014-01-03 09:43 - 00009511 _____ C:\Users\Hans Desktop PC\Downloads\FRST.txt
2014-01-02 13:01 - 2014-01-03 09:43 - 00000000 ____D C:\FRST
2014-01-02 13:01 - 2014-01-02 13:02 - 00025562 _____ C:\Users\Hans Desktop PC\Downloads\Addition.txt
2014-01-02 13:00 - 2014-01-03 09:43 - 01931750 _____ (Farbar) C:\Users\Hans Desktop PC\Downloads\FRST64.exe
2014-01-02 12:59 - 2014-01-02 12:59 - 00000492 _____ C:\Users\Hans Desktop PC\Downloads\defogger_disable.log
2014-01-02 12:59 - 2014-01-02 12:59 - 00000000 _____ C:\Users\Hans Desktop PC\defogger_reenable
2014-01-02 12:58 - 2014-01-02 12:58 - 00050477 _____ C:\Users\Hans Desktop PC\Downloads\Defogger.exe
2014-01-02 11:53 - 2014-01-02 11:53 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012
2014-01-02 11:32 - 2014-01-03 06:47 - 00003990 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8C789A6B-65A8-4A76-A311-F27A13C4B32B}
2014-01-01 17:51 - 2014-01-01 17:52 - 00063044 _____ C:\Users\Hans Desktop PC\Downloads\Bravo Hits - Vol. 32.rar.nzb
2014-01-01 15:12 - 2014-01-01 15:16 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Mp3tag
2014-01-01 14:57 - 2014-01-03 09:39 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\newnext.me
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\genienext
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\.android
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Program Files (x86)\7-Zip
2014-01-01 14:44 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero
2014-01-01 13:24 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero_AG
2014-01-01 11:57 - 2014-01-01 11:57 - 00000000 ____D C:\Program Files (x86)\MarkAny
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Nero
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\ProgramData\LightScribe
2014-01-01 11:44 - 2014-01-01 11:44 - 00002213 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00002193 _____ C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2012
2014-01-01 11:44 - 2012-07-04 10:49 - 00034656 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe
2014-01-01 11:44 - 2012-07-04 10:49 - 00025952 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll
2014-01-01 11:44 - 2012-07-04 10:49 - 00021344 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll
2014-01-01 11:16 - 2014-01-03 00:00 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CrashDumps
2013-12-31 11:13 - 2014-01-03 00:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-Q5-TTL.DAT
2013-12-24 19:01 - 2013-12-24 19:02 - 00259770 _____ C:\Windows\msxml4-KB2758694-enu.LOG
2013-12-24 18:38 - 2013-12-24 18:38 - 02634152 _____ C:\Users\Hans Desktop PC\Downloads\mp3tagv258setup.exe
2013-12-24 18:38 - 2013-12-24 18:38 - 00000983 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2013-12-24 18:38 - 2013-12-24 18:38 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Hausverwalter
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl Data Service
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl Data Service
2013-12-24 11:13 - 2013-12-24 11:13 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2013-12-22 17:38 - 2013-12-22 17:38 - 00001181 _____ C:\Users\Public\Desktop\MAGIX Video easy TERRATEC Edition.lnk
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\ProgramData\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-12-22 17:37 - 2013-12-22 17:37 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-12-22 17:34 - 2013-12-22 17:36 - 211870088 _____ (MAGIX AG) C:\Users\Hans Desktop PC\Downloads\MAGIX_Video_easy_TERRATEC_Edition.exe
2013-12-22 17:34 - 2013-12-22 17:34 - 00000000 ____D C:\ProgramData\CMUV
2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files\DIFX
2013-12-22 17:32 - 2013-12-22 17:32 - 00000000 ____D C:\Program Files (x86)\TERRATEC
2013-12-22 17:29 - 2013-12-22 17:32 - 03311568 _____ C:\Users\Hans Desktop PC\Downloads\TERRATEC_CINERGY_HTC_Stick_HD_Driver_Setup_7.0.122.90_XP_Vista_7_8.exe
2013-12-22 17:28 - 2013-12-22 17:28 - 00001137 _____ C:\Users\Hans Desktop PC\Desktop\DVBViewer TERRATEC Edition.lnk
2013-12-22 17:28 - 2013-12-22 17:28 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition
2013-12-22 16:51 - 2013-12-22 16:51 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:51 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:50 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-12-22 15:54 - 2013-12-22 15:54 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk
2013-12-22 15:53 - 2013-12-22 15:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk
2013-12-22 15:52 - 2013-12-22 16:01 - 00000000 ____D C:\ProgramData\Nero
2013-12-22 15:10 - 2013-12-22 15:56 - 00000000 ____D C:\Program Files (x86)\Nero
2013-12-22 15:10 - 2011-12-01 11:42 - 00072240 _____ (Nero AG) C:\Windows\system32\Drivers\NBVol.sys
2013-12-22 15:10 - 2011-12-01 11:42 - 00015920 _____ (Nero AG) C:\Windows\system32\Drivers\NBVolUp.sys
2013-12-22 15:04 - 2013-12-22 15:04 - 00002037 _____ C:\Users\Public\Desktop\LightScribe.lnk
2013-12-22 15:04 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2013-12-22 15:04 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2013-12-22 15:04 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2013-12-22 15:04 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2013-12-22 15:04 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2013-12-22 15:03 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2013-12-22 15:03 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2013-12-22 15:03 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2013-12-22 15:03 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2013-12-22 15:03 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2013-12-22 15:03 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2013-12-18 16:56 - 2013-12-25 11:15 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mein Steuer-Sparbuch Heute
2013-12-15 16:46 - 2013-12-15 16:46 - 00001000 _____ C:\Users\Public\Desktop\WISO Hausverwalter 2014.lnk
2013-12-15 16:34 - 2013-12-15 16:34 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl
2013-12-15 12:45 - 2013-12-24 11:46 - 00000651 _____ C:\Windows\wiso.ini
2013-12-15 12:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl
2013-12-15 12:45 - 2013-12-15 12:45 - 00000986 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk
2013-12-15 12:12 - 2013-12-24 11:45 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH
2013-12-11 17:08 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-11 17:08 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-11 17:08 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-11 17:08 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-11 17:07 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-11 17:07 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-11 17:07 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-11 17:07 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-11 17:07 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-11 17:07 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-11 17:07 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-11 17:07 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-11 17:07 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-11 17:07 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-11 17:07 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-11 17:07 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-11 17:07 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-11 17:07 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-11 17:07 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-11 17:07 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-11 17:07 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-11 17:07 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-11 17:07 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-11 17:07 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-11 17:07 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-11 17:07 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-11 17:07 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-11 17:07 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-11 17:07 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-11 17:07 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-11 17:07 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-11 17:07 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-11 17:07 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-11 17:07 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-11 17:07 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 15:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 15:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 15:22 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 15:22 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 15:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 15:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 15:22 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 15:22 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 15:22 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 15:22 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 15:22 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 15:22 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 15:22 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 15:22 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 15:22 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 15:22 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 15:22 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 15:22 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 15:22 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-04 19:13 - 2014-01-03 00:13 - 00000103 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WB.CFG
2013-12-04 19:13 - 2014-01-03 00:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-TTL.DAT

==================== One Month Modified Files and Folders =======

2014-01-03 09:43 - 2014-01-03 09:43 - 00000000 ____D C:\Users\Hans Desktop PC\Downloads\FRST-OlderVersion
2014-01-03 09:43 - 2014-01-02 13:01 - 00009511 _____ C:\Users\Hans Desktop PC\Downloads\FRST.txt
2014-01-03 09:43 - 2014-01-02 13:01 - 00000000 ____D C:\FRST
2014-01-03 09:43 - 2014-01-02 13:00 - 01931750 _____ (Farbar) C:\Users\Hans Desktop PC\Downloads\FRST64.exe
2014-01-03 09:42 - 2014-01-03 09:42 - 00008921 _____ C:\Users\Hans Desktop PC\Desktop\AdwCleaner[S0].txt
2014-01-03 09:41 - 2013-11-03 19:48 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-03 09:41 - 2013-10-31 19:44 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs
2014-01-03 09:41 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-03 09:41 - 2009-07-14 05:56 - 00037921 _____ C:\Windows\setupact.log
2014-01-03 09:40 - 2014-01-02 20:31 - 00000000 ____D C:\AdwCleaner
2014-01-03 09:40 - 2013-11-03 19:48 - 00001282 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-03 09:40 - 2013-10-31 19:41 - 00001015 _____ C:\Users\Hans Desktop PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-03 09:40 - 2013-10-31 19:36 - 01757854 _____ C:\Windows\WindowsUpdate.log
2014-01-03 09:39 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\newnext.me
2014-01-03 09:39 - 2013-11-03 19:48 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-03 09:39 - 2013-11-01 18:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-03 06:47 - 2014-01-02 11:32 - 00003990 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8C789A6B-65A8-4A76-A311-F27A13C4B32B}
2014-01-03 02:40 - 2009-07-14 05:50 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-03 02:40 - 2009-07-14 05:50 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-03 02:37 - 2011-04-12 09:14 - 00653928 _____ C:\Windows\system32\perfh007.dat
2014-01-03 02:37 - 2011-04-12 09:14 - 00129800 _____ C:\Windows\system32\perfc007.dat
2014-01-03 02:37 - 2009-07-14 06:12 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-03 02:33 - 2014-01-03 02:33 - 00535712 _____ C:\Windows\Minidump\010314-22230-01.dmp
2014-01-03 02:33 - 2013-11-10 18:08 - 704441021 _____ C:\Windows\MEMORY.DMP
2014-01-03 02:33 - 2013-11-10 18:08 - 00000000 ____D C:\Windows\Minidump
2014-01-03 00:13 - 2013-12-31 11:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-Q5-TTL.DAT
2014-01-03 00:13 - 2013-12-04 19:13 - 00000103 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WB.CFG
2014-01-03 00:13 - 2013-12-04 19:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-TTL.DAT
2014-01-03 00:00 - 2014-01-01 11:16 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CrashDumps
2014-01-02 20:30 - 2014-01-02 20:30 - 01233962 _____ C:\Users\Hans Desktop PC\Desktop\adwcleaner.exe
2014-01-02 20:29 - 2014-01-02 13:03 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Viruslog
2014-01-02 13:10 - 2014-01-02 13:10 - 00010330 _____ C:\Users\Hans Desktop PC\Desktop\Gmer.txt
2014-01-02 13:04 - 2014-01-02 13:04 - 00377856 _____ C:\Users\Hans Desktop PC\Downloads\gmer_2.1.19163.exe
2014-01-02 13:03 - 2014-01-02 13:03 - 00043723 _____ C:\Users\Hans Desktop PC\Desktop\FRST.txt
2014-01-02 13:03 - 2014-01-02 13:03 - 00025562 _____ C:\Users\Hans Desktop PC\Desktop\Addition.txt
2014-01-02 13:02 - 2014-01-02 13:01 - 00025562 _____ C:\Users\Hans Desktop PC\Downloads\Addition.txt
2014-01-02 12:59 - 2014-01-02 12:59 - 00000492 _____ C:\Users\Hans Desktop PC\Downloads\defogger_disable.log
2014-01-02 12:59 - 2014-01-02 12:59 - 00000000 _____ C:\Users\Hans Desktop PC\defogger_reenable
2014-01-02 12:59 - 2013-10-31 19:40 - 00000000 ____D C:\Users\Hans Desktop PC
2014-01-02 12:58 - 2014-01-02 12:58 - 00050477 _____ C:\Users\Hans Desktop PC\Downloads\Defogger.exe
2014-01-02 11:53 - 2014-01-02 11:53 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012
2014-01-02 10:28 - 2010-11-21 04:47 - 00049552 _____ C:\Windows\PFRO.log
2014-01-01 17:52 - 2014-01-01 17:51 - 00063044 _____ C:\Users\Hans Desktop PC\Downloads\Bravo Hits - Vol. 32.rar.nzb
2014-01-01 15:16 - 2014-01-01 15:12 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Mp3tag
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\genienext
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\.android
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Program Files (x86)\7-Zip
2014-01-01 14:44 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero
2014-01-01 14:44 - 2014-01-01 13:24 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero_AG
2014-01-01 11:58 - 2013-11-01 19:08 - 00000793 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-01-01 11:57 - 2014-01-01 11:57 - 00000000 ____D C:\Program Files (x86)\MarkAny
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Nero
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\ProgramData\LightScribe
2014-01-01 11:44 - 2014-01-01 11:44 - 00002213 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00002193 _____ C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2012
2013-12-25 11:15 - 2013-12-18 16:56 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mein Steuer-Sparbuch Heute
2013-12-24 19:02 - 2013-12-24 19:01 - 00259770 _____ C:\Windows\msxml4-KB2758694-enu.LOG
2013-12-24 18:38 - 2013-12-24 18:38 - 02634152 _____ C:\Users\Hans Desktop PC\Downloads\mp3tagv258setup.exe
2013-12-24 18:38 - 2013-12-24 18:38 - 00000983 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2013-12-24 18:38 - 2013-12-24 18:38 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-12-24 11:46 - 2013-12-15 12:45 - 00000651 _____ C:\Windows\wiso.ini
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Hausverwalter
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl Data Service
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl Data Service
2013-12-24 11:45 - 2013-12-15 12:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl
2013-12-24 11:45 - 2013-12-15 12:12 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH
2013-12-24 11:13 - 2013-12-24 11:13 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2013-12-24 10:14 - 2013-10-31 19:40 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\VirtualStore
2013-12-22 18:12 - 2013-10-31 21:27 - 00154336 _____ C:\Users\Hans Desktop PC\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-22 17:42 - 2009-07-14 05:50 - 00507536 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-22 17:38 - 2013-12-22 17:38 - 00001181 _____ C:\Users\Public\Desktop\MAGIX Video easy TERRATEC Edition.lnk
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\ProgramData\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-12-22 17:37 - 2013-12-22 17:37 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-12-22 17:36 - 2013-12-22 17:34 - 211870088 _____ (MAGIX AG) C:\Users\Hans Desktop PC\Downloads\MAGIX_Video_easy_TERRATEC_Edition.exe
2013-12-22 17:34 - 2013-12-22 17:34 - 00000000 ____D C:\ProgramData\CMUV
2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files\DIFX
2013-12-22 17:33 - 2013-10-31 23:07 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-22 17:32 - 2013-12-22 17:32 - 00000000 ____D C:\Program Files (x86)\TERRATEC
2013-12-22 17:32 - 2013-12-22 17:29 - 03311568 _____ C:\Users\Hans Desktop PC\Downloads\TERRATEC_CINERGY_HTC_Stick_HD_Driver_Setup_7.0.122.90_XP_Vista_7_8.exe
2013-12-22 17:28 - 2013-12-22 17:28 - 00001137 _____ C:\Users\Hans Desktop PC\Desktop\DVBViewer TERRATEC Edition.lnk
2013-12-22 17:28 - 2013-12-22 17:28 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition
2013-12-22 17:27 - 2013-11-01 19:01 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Downloaded Installations
2013-12-22 16:51 - 2013-12-22 16:51 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\TuneUp Software
2013-12-22 16:51 - 2013-12-22 16:50 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:50 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-12-22 16:01 - 2013-12-22 15:52 - 00000000 ____D C:\ProgramData\Nero
2013-12-22 15:56 - 2013-12-22 15:10 - 00000000 ____D C:\Program Files (x86)\Nero
2013-12-22 15:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Cursors
2013-12-22 15:54 - 2013-12-22 15:54 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk
2013-12-22 15:53 - 2013-12-22 15:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk
2013-12-22 15:04 - 2013-12-22 15:04 - 00002037 _____ C:\Users\Public\Desktop\LightScribe.lnk
2013-12-15 19:30 - 2013-11-01 19:08 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Samsung
2013-12-15 16:46 - 2013-12-15 16:46 - 00001000 _____ C:\Users\Public\Desktop\WISO Hausverwalter 2014.lnk
2013-12-15 16:34 - 2013-12-15 16:34 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl
2013-12-15 12:45 - 2013-12-15 12:45 - 00000986 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk
2013-12-15 12:08 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-12-15 00:13 - 2013-11-03 19:48 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Google
2013-12-14 17:34 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-11 17:08 - 2013-10-31 20:26 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 15:28 - 2013-11-01 18:59 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 15:28 - 2013-11-01 18:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 15:28 - 2013-11-01 18:59 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-08 17:20 - 2013-10-31 23:34 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\ChessBase
2013-12-08 11:59 - 2013-11-03 19:48 - 00004124 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-08 11:59 - 2013-11-03 19:48 - 00003872 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

Some content of TEMP:
====================
C:\Users\Hans Desktop PC\AppData\Local\Temp\opsrnrpevolrwo.exe
C:\Users\Hans Desktop PC\AppData\Local\Temp\Quarantine.exe
C:\Users\Hans Desktop PC\AppData\Local\Temp\TUUUninstallHelper.exe
C:\Users\Hans Desktop PC\AppData\Local\Temp\twnplxhj.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-01 13:44

==================== End Of Log ============================
         
--- --- ---


Das Internet öffnet sich außerdem ohne Nationzoom!

Alt 03.01.2014, 12:36   #7
sunjojo
/// Malwareteam
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
2014-01-01 14:57 - 2014-01-03 09:39 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\newnext.me
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\genienext
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\.android
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

Schritt 2
Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.

Schritt 3

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

Schritt 4
Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, wird ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.

Gibt es noch weitere Probleme?



Poste folgende Logfiles in deiner nächsten Antwort:
  • FRST-Fix
  • MBAM-Scan
  • ESET-Scan
  • FRST-Scan
__________________
Gruß,

Jonas

Alt 05.01.2014, 10:37   #8
Mixia
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



So, sorry für die späte Antwort, hier die Logs:

FRST fix
Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-01-2014
Ran by Hans Desktop PC at 2014-01-03 13:54:43 Run:1
Running from C:\Users\Hans Desktop PC\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
2014-01-01 14:57 - 2014-01-03 09:39 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\newnext.me
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\genienext
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Users\Hans Desktop PC\.android
*****************

C:\Users\Hans Desktop PC\AppData\Roaming\newnext.me => Moved successfully.
C:\Users\Hans Desktop PC\AppData\Local\genienext => Moved successfully.
C:\Users\Hans Desktop PC\.android => Moved successfully.

==== End of Fixlog ====
         
MBAM-Scan
Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2014.01.03.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Hans Desktop PC :: HANSDESKTOPPC [Administrator]

Schutz: Aktiviert

03.01.2014 13:58:10
mbam-log-2014-01-03 (13-58-10).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 212034
Laufzeit: 1 Minute(n), 54 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 4
C:\Users\Hans Desktop PC\AppData\Local\Temp\parent.txt (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Hans Desktop PC\AppData\Local\Temp\3efc3261-d7ab-4c89-9d67-a643347389a70\parent.txt (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Hans Desktop PC\AppData\Local\Temp\fullpackage_temp1388584612\Baofeng.exe (PUP.Optional.NationZoom.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Hans Desktop PC\AppData\Local\Temp\fullpackage_temp1388584612\tmp\NewGdp.exe (PUP.Optional.WpManager.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)
         
ESET
Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2014.01.03.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Hans Desktop PC :: HANSDESKTOPPC [Administrator]

Schutz: Aktiviert

03.01.2014 13:58:10
mbam-log-2014-01-03 (13-58-10).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 212034
Laufzeit: 1 Minute(n), 54 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 4
C:\Users\Hans Desktop PC\AppData\Local\Temp\parent.txt (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Hans Desktop PC\AppData\Local\Temp\3efc3261-d7ab-4c89-9d67-a643347389a70\parent.txt (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Hans Desktop PC\AppData\Local\Temp\fullpackage_temp1388584612\Baofeng.exe (PUP.Optional.NationZoom.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Hans Desktop PC\AppData\Local\Temp\fullpackage_temp1388584612\tmp\NewGdp.exe (PUP.Optional.WpManager.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)
         
FRST 3

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2014
Ran by Hans Desktop PC (administrator) on HANSDESKTOPPC on 05-01-2014 11:29:34
Running from C:\Users\Hans Desktop PC\Downloads
Windows 7 Professional N Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\eEBAPI\eEBSvc.exe
(AVM GmbH) C:\Program Files (x86)\FRITZ!Powerline\PowerlineService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
() C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe
(Samsung) D:\Program Files (x86)\Kies\Kies.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
() D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe
(Samsung Electronics Co., Ltd.) D:\Program Files (x86)\Kies\KiesTrayAgent.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] - D:\Program Files (x86)\Kies\KiesTrayAgent.exe [311152 2013-12-11] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [NBAgent] - C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe [1493288 2012-01-13] (Nero AG)
HKCU\...\Run: [KiesPreload] - D:\Program Files (x86)\Kies\Kies.exe [1564528 2013-12-11] (Samsung)
HKCU\...\Run: [] - D:\Program Files (x86)\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-12-11] (Samsung)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2741616 2011-03-04] (Hewlett-Packard Company)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.tagesschau.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x84E3C03977D6CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\IPSBHO.dll (Symantec Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

Chrome: 
=======
CHR HomePage: hxxp://tagesschau.de/
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Extension: (Google Docs) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Norton Identity Protection) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0
CHR Extension: (Google Wallet) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Gmail) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\Exts\Chrome.crx

==================== Services (Whitelisted) =================

R2 AVMPowerlineService; C:\Program Files (x86)\FRITZ!Powerline\PowerlineService.exe [126976 2013-10-11] (AVM GmbH)
R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\eEBAPI\eEBSVC.exe [90112 2004-11-17] (SEIKO EPSON CORPORATION)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe [275696 2013-10-08] (Symantec Corporation)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-07-04] (TuneUp Software)
R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248704 2013-08-14] ()

==================== Drivers (Whitelisted) ====================

R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20131203.001\BHDrvx64.sys [1526488 2013-12-03] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-24] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-24] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140103.001\IDSvia64.sys [521944 2013-12-14] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140104.006\ENG64.SYS [126040 2013-12-26] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140104.006\EX64.SYS [2099288 2013-12-26] (Symantec Corporation)
R1 SRTSP; C:\Windows\System32\Drivers\NISx64\1501000.012\SRTSP64.SYS [858200 2013-09-27] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS [36952 2013-09-10] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1501000.012\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1501000.012\SYMEFA64.SYS [1147480 2013-09-27] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-14] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS [264280 2013-09-27] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1501000.012\SYMNETS.SYS [590936 2013-09-26] (Symantec Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-05-03] (TuneUp Software)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-03 14:04 - 2014-01-03 14:04 - 02347384 _____ (ESET) C:\Users\Hans Desktop PC\Downloads\esetsmartinstaller_enu.exe
2014-01-03 13:56 - 2014-01-03 13:56 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Malwarebytes
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-03 13:56 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-03 13:55 - 2014-01-03 13:55 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Hans Desktop PC\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-03 09:43 - 2014-01-05 11:29 - 00000000 ____D C:\Users\Hans Desktop PC\Downloads\FRST-OlderVersion
2014-01-03 09:43 - 2014-01-03 09:43 - 00037064 _____ C:\Users\Hans Desktop PC\Desktop\FRST2.txt
2014-01-03 09:42 - 2014-01-03 09:42 - 00008921 _____ C:\Users\Hans Desktop PC\Desktop\AdwCleaner[S0].txt
2014-01-03 02:33 - 2014-01-03 02:33 - 00535712 _____ C:\Windows\Minidump\010314-22230-01.dmp
2014-01-02 20:31 - 2014-01-03 09:40 - 00000000 ____D C:\AdwCleaner
2014-01-02 20:30 - 2014-01-02 20:30 - 01233962 _____ C:\Users\Hans Desktop PC\Desktop\adwcleaner.exe
2014-01-02 13:10 - 2014-01-02 13:10 - 00010330 _____ C:\Users\Hans Desktop PC\Desktop\Gmer.txt
2014-01-02 13:04 - 2014-01-02 13:04 - 00377856 _____ C:\Users\Hans Desktop PC\Downloads\gmer_2.1.19163.exe
2014-01-02 13:03 - 2014-01-02 20:29 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Viruslog
2014-01-02 13:03 - 2014-01-02 13:03 - 00043723 _____ C:\Users\Hans Desktop PC\Desktop\FRST.txt
2014-01-02 13:03 - 2014-01-02 13:03 - 00025562 _____ C:\Users\Hans Desktop PC\Desktop\Addition.txt
2014-01-02 13:01 - 2014-01-05 11:29 - 00010593 _____ C:\Users\Hans Desktop PC\Downloads\FRST.txt
2014-01-02 13:01 - 2014-01-05 11:29 - 00000000 ____D C:\FRST
2014-01-02 13:01 - 2014-01-03 09:44 - 00028430 _____ C:\Users\Hans Desktop PC\Downloads\Addition.txt
2014-01-02 13:00 - 2014-01-05 11:29 - 01931368 _____ (Farbar) C:\Users\Hans Desktop PC\Downloads\FRST64.exe
2014-01-02 12:59 - 2014-01-02 12:59 - 00000492 _____ C:\Users\Hans Desktop PC\Downloads\defogger_disable.log
2014-01-02 12:59 - 2014-01-02 12:59 - 00000000 _____ C:\Users\Hans Desktop PC\defogger_reenable
2014-01-02 12:58 - 2014-01-02 12:58 - 00050477 _____ C:\Users\Hans Desktop PC\Downloads\Defogger.exe
2014-01-02 11:53 - 2014-01-02 11:53 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012
2014-01-02 11:32 - 2014-01-03 19:42 - 00003990 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8C789A6B-65A8-4A76-A311-F27A13C4B32B}
2014-01-01 17:51 - 2014-01-01 17:52 - 00063044 _____ C:\Users\Hans Desktop PC\Downloads\Bravo Hits - Vol. 32.rar.nzb
2014-01-01 15:12 - 2014-01-01 15:16 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Mp3tag
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Program Files (x86)\7-Zip
2014-01-01 14:44 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero
2014-01-01 13:24 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero_AG
2014-01-01 11:57 - 2014-01-01 11:57 - 00000000 ____D C:\Program Files (x86)\MarkAny
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Nero
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\ProgramData\LightScribe
2014-01-01 11:44 - 2014-01-01 11:44 - 00002213 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00002193 _____ C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2012
2014-01-01 11:44 - 2012-07-04 10:49 - 00034656 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe
2014-01-01 11:44 - 2012-07-04 10:49 - 00025952 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll
2014-01-01 11:44 - 2012-07-04 10:49 - 00021344 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll
2014-01-01 11:16 - 2014-01-03 00:00 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CrashDumps
2013-12-31 11:13 - 2014-01-03 00:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-Q5-TTL.DAT
2013-12-24 19:01 - 2013-12-24 19:02 - 00259770 _____ C:\Windows\msxml4-KB2758694-enu.LOG
2013-12-24 18:38 - 2013-12-24 18:38 - 02634152 _____ C:\Users\Hans Desktop PC\Downloads\mp3tagv258setup.exe
2013-12-24 18:38 - 2013-12-24 18:38 - 00000983 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2013-12-24 18:38 - 2013-12-24 18:38 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Hausverwalter
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl Data Service
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl Data Service
2013-12-24 11:13 - 2013-12-24 11:13 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2013-12-22 17:38 - 2013-12-22 17:38 - 00001181 _____ C:\Users\Public\Desktop\MAGIX Video easy TERRATEC Edition.lnk
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\ProgramData\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-12-22 17:37 - 2013-12-22 17:37 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-12-22 17:34 - 2013-12-22 17:36 - 211870088 _____ (MAGIX AG) C:\Users\Hans Desktop PC\Downloads\MAGIX_Video_easy_TERRATEC_Edition.exe
2013-12-22 17:34 - 2013-12-22 17:34 - 00000000 ____D C:\ProgramData\CMUV
2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files\DIFX
2013-12-22 17:32 - 2013-12-22 17:32 - 00000000 ____D C:\Program Files (x86)\TERRATEC
2013-12-22 17:29 - 2013-12-22 17:32 - 03311568 _____ C:\Users\Hans Desktop PC\Downloads\TERRATEC_CINERGY_HTC_Stick_HD_Driver_Setup_7.0.122.90_XP_Vista_7_8.exe
2013-12-22 17:28 - 2013-12-22 17:28 - 00001137 _____ C:\Users\Hans Desktop PC\Desktop\DVBViewer TERRATEC Edition.lnk
2013-12-22 17:28 - 2013-12-22 17:28 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition
2013-12-22 16:51 - 2013-12-22 16:51 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:51 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:50 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-12-22 15:54 - 2013-12-22 15:54 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk
2013-12-22 15:53 - 2013-12-22 15:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk
2013-12-22 15:52 - 2013-12-22 16:01 - 00000000 ____D C:\ProgramData\Nero
2013-12-22 15:10 - 2013-12-22 15:56 - 00000000 ____D C:\Program Files (x86)\Nero
2013-12-22 15:10 - 2011-12-01 11:42 - 00072240 _____ (Nero AG) C:\Windows\system32\Drivers\NBVol.sys
2013-12-22 15:10 - 2011-12-01 11:42 - 00015920 _____ (Nero AG) C:\Windows\system32\Drivers\NBVolUp.sys
2013-12-22 15:04 - 2013-12-22 15:04 - 00002037 _____ C:\Users\Public\Desktop\LightScribe.lnk
2013-12-22 15:04 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2013-12-22 15:04 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2013-12-22 15:04 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2013-12-22 15:04 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2013-12-22 15:04 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2013-12-22 15:03 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2013-12-22 15:03 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2013-12-22 15:03 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2013-12-22 15:03 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2013-12-22 15:03 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2013-12-22 15:03 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2013-12-18 16:56 - 2013-12-25 11:15 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mein Steuer-Sparbuch Heute
2013-12-15 16:46 - 2013-12-15 16:46 - 00001000 _____ C:\Users\Public\Desktop\WISO Hausverwalter 2014.lnk
2013-12-15 16:34 - 2013-12-15 16:34 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl
2013-12-15 12:45 - 2013-12-24 11:46 - 00000651 _____ C:\Windows\wiso.ini
2013-12-15 12:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl
2013-12-15 12:45 - 2013-12-15 12:45 - 00000986 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk
2013-12-15 12:12 - 2013-12-24 11:45 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH
2013-12-11 17:08 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-11 17:08 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-11 17:08 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-11 17:08 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-11 17:07 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-11 17:07 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-11 17:07 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-11 17:07 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-11 17:07 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-11 17:07 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-11 17:07 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-11 17:07 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-11 17:07 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-11 17:07 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-11 17:07 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-11 17:07 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-11 17:07 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-11 17:07 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-11 17:07 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-11 17:07 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-11 17:07 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-11 17:07 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-11 17:07 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-11 17:07 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-11 17:07 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-11 17:07 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-11 17:07 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-11 17:07 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-11 17:07 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-11 17:07 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-11 17:07 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-11 17:07 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-11 17:07 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-11 17:07 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-11 17:07 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 15:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 15:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 15:22 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 15:22 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 15:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 15:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 15:22 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 15:22 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 15:22 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 15:22 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 15:22 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 15:22 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 15:22 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 15:22 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 15:22 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 15:22 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 15:22 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 15:22 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 15:22 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys

==================== One Month Modified Files and Folders =======

2014-01-05 11:29 - 2014-01-03 09:43 - 00000000 ____D C:\Users\Hans Desktop PC\Downloads\FRST-OlderVersion
2014-01-05 11:29 - 2014-01-02 13:01 - 00010593 _____ C:\Users\Hans Desktop PC\Downloads\FRST.txt
2014-01-05 11:29 - 2014-01-02 13:01 - 00000000 ____D C:\FRST
2014-01-05 11:29 - 2014-01-02 13:00 - 01931368 _____ (Farbar) C:\Users\Hans Desktop PC\Downloads\FRST64.exe
2014-01-05 11:28 - 2013-11-01 18:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-05 11:04 - 2013-11-03 19:48 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-05 03:00 - 2013-10-31 19:36 - 01849357 _____ C:\Windows\WindowsUpdate.log
2014-01-04 18:13 - 2013-11-03 19:48 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-04 18:01 - 2013-10-31 19:44 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs
2014-01-03 19:42 - 2014-01-02 11:32 - 00003990 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8C789A6B-65A8-4A76-A311-F27A13C4B32B}
2014-01-03 14:10 - 2009-07-14 05:50 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-03 14:10 - 2009-07-14 05:50 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-03 14:07 - 2011-04-12 09:14 - 00653928 _____ C:\Windows\system32\perfh007.dat
2014-01-03 14:07 - 2011-04-12 09:14 - 00129800 _____ C:\Windows\system32\perfc007.dat
2014-01-03 14:07 - 2009-07-14 06:12 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-03 14:04 - 2014-01-03 14:04 - 02347384 _____ (ESET) C:\Users\Hans Desktop PC\Downloads\esetsmartinstaller_enu.exe
2014-01-03 14:03 - 2010-11-21 04:47 - 00050832 _____ C:\Windows\PFRO.log
2014-01-03 14:03 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-03 14:03 - 2009-07-14 05:56 - 00037977 _____ C:\Windows\setupact.log
2014-01-03 13:56 - 2014-01-03 13:56 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Malwarebytes
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-03 13:55 - 2014-01-03 13:55 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Hans Desktop PC\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-03 13:54 - 2013-10-31 19:40 - 00000000 ____D C:\Users\Hans Desktop PC
2014-01-03 09:44 - 2014-01-02 13:01 - 00028430 _____ C:\Users\Hans Desktop PC\Downloads\Addition.txt
2014-01-03 09:43 - 2014-01-03 09:43 - 00037064 _____ C:\Users\Hans Desktop PC\Desktop\FRST2.txt
2014-01-03 09:42 - 2014-01-03 09:42 - 00008921 _____ C:\Users\Hans Desktop PC\Desktop\AdwCleaner[S0].txt
2014-01-03 09:40 - 2014-01-02 20:31 - 00000000 ____D C:\AdwCleaner
2014-01-03 09:40 - 2013-11-03 19:48 - 00001282 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-03 09:40 - 2013-10-31 19:41 - 00001015 _____ C:\Users\Hans Desktop PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-03 02:33 - 2014-01-03 02:33 - 00535712 _____ C:\Windows\Minidump\010314-22230-01.dmp
2014-01-03 02:33 - 2013-11-10 18:08 - 704441021 _____ C:\Windows\MEMORY.DMP
2014-01-03 02:33 - 2013-11-10 18:08 - 00000000 ____D C:\Windows\Minidump
2014-01-03 00:13 - 2013-12-31 11:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-Q5-TTL.DAT
2014-01-03 00:13 - 2013-12-04 19:13 - 00000103 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WB.CFG
2014-01-03 00:13 - 2013-12-04 19:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-TTL.DAT
2014-01-03 00:00 - 2014-01-01 11:16 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CrashDumps
2014-01-02 20:30 - 2014-01-02 20:30 - 01233962 _____ C:\Users\Hans Desktop PC\Desktop\adwcleaner.exe
2014-01-02 20:29 - 2014-01-02 13:03 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Viruslog
2014-01-02 13:10 - 2014-01-02 13:10 - 00010330 _____ C:\Users\Hans Desktop PC\Desktop\Gmer.txt
2014-01-02 13:04 - 2014-01-02 13:04 - 00377856 _____ C:\Users\Hans Desktop PC\Downloads\gmer_2.1.19163.exe
2014-01-02 13:03 - 2014-01-02 13:03 - 00043723 _____ C:\Users\Hans Desktop PC\Desktop\FRST.txt
2014-01-02 13:03 - 2014-01-02 13:03 - 00025562 _____ C:\Users\Hans Desktop PC\Desktop\Addition.txt
2014-01-02 12:59 - 2014-01-02 12:59 - 00000492 _____ C:\Users\Hans Desktop PC\Downloads\defogger_disable.log
2014-01-02 12:59 - 2014-01-02 12:59 - 00000000 _____ C:\Users\Hans Desktop PC\defogger_reenable
2014-01-02 12:58 - 2014-01-02 12:58 - 00050477 _____ C:\Users\Hans Desktop PC\Downloads\Defogger.exe
2014-01-02 11:53 - 2014-01-02 11:53 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012
2014-01-01 17:52 - 2014-01-01 17:51 - 00063044 _____ C:\Users\Hans Desktop PC\Downloads\Bravo Hits - Vol. 32.rar.nzb
2014-01-01 15:16 - 2014-01-01 15:12 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Mp3tag
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Program Files (x86)\7-Zip
2014-01-01 14:44 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero
2014-01-01 14:44 - 2014-01-01 13:24 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero_AG
2014-01-01 11:58 - 2013-11-01 19:08 - 00000793 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-01-01 11:57 - 2014-01-01 11:57 - 00000000 ____D C:\Program Files (x86)\MarkAny
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Nero
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\ProgramData\LightScribe
2014-01-01 11:44 - 2014-01-01 11:44 - 00002213 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00002193 _____ C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2012
2013-12-25 11:15 - 2013-12-18 16:56 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mein Steuer-Sparbuch Heute
2013-12-24 19:02 - 2013-12-24 19:01 - 00259770 _____ C:\Windows\msxml4-KB2758694-enu.LOG
2013-12-24 18:38 - 2013-12-24 18:38 - 02634152 _____ C:\Users\Hans Desktop PC\Downloads\mp3tagv258setup.exe
2013-12-24 18:38 - 2013-12-24 18:38 - 00000983 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2013-12-24 18:38 - 2013-12-24 18:38 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-12-24 11:46 - 2013-12-15 12:45 - 00000651 _____ C:\Windows\wiso.ini
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Hausverwalter
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl Data Service
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl Data Service
2013-12-24 11:45 - 2013-12-15 12:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl
2013-12-24 11:45 - 2013-12-15 12:12 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH
2013-12-24 11:13 - 2013-12-24 11:13 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2013-12-24 10:14 - 2013-10-31 19:40 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\VirtualStore
2013-12-22 18:12 - 2013-10-31 21:27 - 00154336 _____ C:\Users\Hans Desktop PC\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-22 17:42 - 2009-07-14 05:50 - 00507536 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-22 17:38 - 2013-12-22 17:38 - 00001181 _____ C:\Users\Public\Desktop\MAGIX Video easy TERRATEC Edition.lnk
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\ProgramData\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-12-22 17:37 - 2013-12-22 17:37 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-12-22 17:36 - 2013-12-22 17:34 - 211870088 _____ (MAGIX AG) C:\Users\Hans Desktop PC\Downloads\MAGIX_Video_easy_TERRATEC_Edition.exe
2013-12-22 17:34 - 2013-12-22 17:34 - 00000000 ____D C:\ProgramData\CMUV
2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files\DIFX
2013-12-22 17:33 - 2013-10-31 23:07 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-22 17:32 - 2013-12-22 17:32 - 00000000 ____D C:\Program Files (x86)\TERRATEC
2013-12-22 17:32 - 2013-12-22 17:29 - 03311568 _____ C:\Users\Hans Desktop PC\Downloads\TERRATEC_CINERGY_HTC_Stick_HD_Driver_Setup_7.0.122.90_XP_Vista_7_8.exe
2013-12-22 17:28 - 2013-12-22 17:28 - 00001137 _____ C:\Users\Hans Desktop PC\Desktop\DVBViewer TERRATEC Edition.lnk
2013-12-22 17:28 - 2013-12-22 17:28 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition
2013-12-22 17:27 - 2013-11-01 19:01 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Downloaded Installations
2013-12-22 16:51 - 2013-12-22 16:51 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\TuneUp Software
2013-12-22 16:51 - 2013-12-22 16:50 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:50 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-12-22 16:01 - 2013-12-22 15:52 - 00000000 ____D C:\ProgramData\Nero
2013-12-22 15:56 - 2013-12-22 15:10 - 00000000 ____D C:\Program Files (x86)\Nero
2013-12-22 15:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Cursors
2013-12-22 15:54 - 2013-12-22 15:54 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk
2013-12-22 15:53 - 2013-12-22 15:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk
2013-12-22 15:04 - 2013-12-22 15:04 - 00002037 _____ C:\Users\Public\Desktop\LightScribe.lnk
2013-12-15 19:30 - 2013-11-01 19:08 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Samsung
2013-12-15 16:46 - 2013-12-15 16:46 - 00001000 _____ C:\Users\Public\Desktop\WISO Hausverwalter 2014.lnk
2013-12-15 16:34 - 2013-12-15 16:34 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl
2013-12-15 12:45 - 2013-12-15 12:45 - 00000986 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk
2013-12-15 12:08 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-12-15 00:13 - 2013-11-03 19:48 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Google
2013-12-14 17:34 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-11 17:08 - 2013-10-31 20:26 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 15:28 - 2013-11-01 18:59 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 15:28 - 2013-11-01 18:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 15:28 - 2013-11-01 18:59 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-08 17:20 - 2013-10-31 23:34 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\ChessBase
2013-12-08 11:59 - 2013-11-03 19:48 - 00004124 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-08 11:59 - 2013-11-03 19:48 - 00003872 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

Some content of TEMP:
====================
C:\Users\Hans Desktop PC\AppData\Local\Temp\opsrnrpevolrwo.exe
C:\Users\Hans Desktop PC\AppData\Local\Temp\Quarantine.exe
C:\Users\Hans Desktop PC\AppData\Local\Temp\TUUUninstallHelper.exe
C:\Users\Hans Desktop PC\AppData\Local\Temp\twnplxhj.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-01 13:44

==================== End Of Log ============================
         
--- --- ---


So, ich hoffe das waren die richtigen
Probleme mit Nationzoom gibt es keine mehr. Allerdings hat ESET ja noch einiges gefunden... Muss man sich da jetzt Sorgen machen?

Mixia

Alt 05.01.2014, 13:30   #9
sunjojo
/// Malwareteam
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



Zitat:
So, ich hoffe das waren die richtigen
Probleme mit Nationzoom gibt es keine mehr. Allerdings hat ESET ja noch einiges gefunden... Muss man sich da jetzt Sorgen machen?
Du hast ausversehen zweimal das Logfile von Malwarebytes Anti Malware gepostet und das ESET Logfile vergessen. Deine Frage kann ich dir erst beantworten, wenn du nochmal das ESET Logfile postest .
__________________
Gruß,

Jonas

Alt 06.01.2014, 10:49   #10
Mixia
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



Ich hatte den Logfile zwischenzeitlich gelöscht, also durfte ESET nochmal laufen.

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=37fc8403c6af0544bec01a346c9274ca
# engine=16526
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-01-06 05:51:03
# local_time=2014-01-06 06:51:03 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=3591 16777213 100 88 506703 151584048 0 0
# compatibility_mode=5893 16776574 100 94 4885154 140617313 0 0
# scanned=887951
# found=16
# cleaned=0
# scan_time=56622
sh=C4023056ABDD4ABACAA1BE4CE5001233D89C633E ft=0 fh=0000000000000000 vn="INF/Autorun.gen worm" ac=I fn="D:\autorun.inf"
sh=D3BEBE43403FE3FC22C042B06460D784EE4CBB33 ft=1 fh=e198fa64f7b4f40c vn="a variant of MSIL/Injector.YJ trojan" ac=I fn="D:\downloads\complete\anydvd\SlySoft.AnyDVD.HD.v7.0.2.0.Final.Multilanguage.WinAll+RES-patch\SetupAnyDVD7020.exe"
sh=D3BEBE43403FE3FC22C042B06460D784EE4CBB33 ft=1 fh=e198fa64f7b4f40c vn="a variant of MSIL/Injector.YJ trojan" ac=I fn="D:\downloads\complete\anydvd.1\SlySoft.AnyDVD.HD.v7.0.2.0.Final.Multilanguage.WinAll+RES-patch\SetupAnyDVD7020.exe"
sh=875CD1A49E41E87C7600236230FE1ED97AA6FEDA ft=1 fh=c71c0011c0cf0adc vn="a variant of Win32/Injector.AMIX trojan" ac=I fn="D:\downloads\complete\Ass.Cleavage.9.XXX.WEBRIP.1080p.X264-TBP.rar\Ass.Cleavage.9.XXX.WEBRIP.1080p.X264-TBP.exe"
sh=6E75368491ACB6A1E7D4FFFEBFEC1640DA80D7BD ft=1 fh=c71c001179dacd20 vn="a variant of MSIL/Injector.AWM trojan" ac=I fn="D:\downloads\complete\Chess\Chess-Aquarium-Portable-con-Houdini-3.rar\Chess Aquarium Portable con Houdini 3.exe"
sh=396A4A8FEC2D717055D104DC040D9ACC6307F445 ft=0 fh=0000000000000000 vn="a variant of MSIL/Injector.ALA trojan" ac=I fn="D:\downloads\complete\Chessbase Opening Encyclopedia 2012\Chessbase Opening Encyclopedia 2012  .rar"
sh=0487003AE54739B38E320362E821A7C1A0F275A0 ft=1 fh=c71c001171e510c9 vn="a variant of MSIL/Injector.BKJ trojan" ac=I fn="D:\downloads\complete\DLL2\Anal.Sweetness.XXX.1080p.WEBRIP-x264-TBP.scr.rar\Anal.Sweetness.XXX.1080p.WEBRIP-x264-TBP.scr.exe"
sh=AE13B7396D6F3EDCB59B5F5F31DF6868912A9B35 ft=1 fh=c71c0011262daf0e vn="a variant of MSIL/Injector.BKJ trojan" ac=I fn="D:\downloads\complete\DLL2\Too.Much.Anal.DiSC1.XXX.DVDRip.x264-Pr0nStarS.scr.rar\Too.Much.Anal.DiSC1.XXX.DVDRip.x264-Pr0nStarS.scr.exe"
sh=A744D1AE174DE0B9929E901C23306C40D038D657 ft=1 fh=c71c0011b0d40813 vn="a variant of MSIL/Injector.BKJ trojan" ac=I fn="D:\downloads\complete\DLL2\Too.Much.Anal.DiSC2.XXX.DVDRip.x264-Pr0nStarS.scr.rar\Too.Much.Anal.DiSC2.XXX.DVDRip.x264-Pr0nStarS.scr.exe"
sh=C440A45A0FFB962049A0E0CC6EB8E427BC2E23D9 ft=0 fh=0000000000000000 vn="a variant of MSIL/Injector.BRI trojan" ac=I fn="D:\downloads\complete\Gotye (feat Kimbra) - Somebody That I Used to Know.rar\Gotye (feat Kimbra) - Somebody That I Used to Know.rar"
sh=F3E4A460052FC595E0C2F203954AA307FE3BE533 ft=1 fh=c71c0011e327583b vn="a variant of Win32/Injector.Autoit.P trojan" ac=I fn="D:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013\msexplorer.exe"
sh=F3E4A460052FC595E0C2F203954AA307FE3BE533 ft=1 fh=c71c0011e327583b vn="a variant of Win32/Injector.Autoit.P trojan" ac=I fn="G:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013\msexplorer.exe"
sh=C4023056ABDD4ABACAA1BE4CE5001233D89C633E ft=0 fh=0000000000000000 vn="INF/Autorun.gen worm" ac=I fn="H:\autorun.inf"
sh=87249CC159E9B7242E039F6145CDBDA5C803EFA1 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="H:\HG-PC\Backup Set 2013-07-29 192917\Backup Files 2013-07-29 192917\Backup files 1.zip"
sh=4572E1D2974418C974A4F95EDC554F6F9438EA7D ft=0 fh=0000000000000000 vn="Win32/Spy.Agent.NYU trojan" ac=I fn="H:\HG-PC\Backup Set 2013-07-29 192917\Backup Files 2013-07-29 192917\Backup files 2.zip"
sh=F3E4A460052FC595E0C2F203954AA307FE3BE533 ft=1 fh=c71c0011e327583b vn="a variant of Win32/Injector.Autoit.P trojan" ac=I fn="H:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013\msexplorer.exe"
         
Und ein frisches FRST
FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014
Ran by Hans Desktop PC (administrator) on HANSDESKTOPPC on 06-01-2014 11:48:19
Running from C:\Users\Hans Desktop PC\Downloads
Windows 7 Professional N Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\eEBAPI\eEBSvc.exe
(AVM GmbH) C:\Program Files (x86)\FRITZ!Powerline\PowerlineService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
() C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe
(Samsung) D:\Program Files (x86)\Kies\Kies.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
() D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe
(Samsung Electronics Co., Ltd.) D:\Program Files (x86)\Kies\KiesTrayAgent.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] - D:\Program Files (x86)\Kies\KiesTrayAgent.exe [311152 2013-12-11] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [NBAgent] - C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe [1493288 2012-01-13] (Nero AG)
HKCU\...\Run: [KiesPreload] - D:\Program Files (x86)\Kies\Kies.exe [1564528 2013-12-11] (Samsung)
HKCU\...\Run: [] - D:\Program Files (x86)\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-12-11] (Samsung)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2741616 2011-03-04] (Hewlett-Packard Company)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.tagesschau.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x84E3C03977D6CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\IPSBHO.dll (Symantec Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

Chrome: 
=======
CHR HomePage: hxxp://tagesschau.de/
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Extension: (Google Docs) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Norton Identity Protection) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0
CHR Extension: (Google Wallet) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Gmail) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\Exts\Chrome.crx

==================== Services (Whitelisted) =================

R2 AVMPowerlineService; C:\Program Files (x86)\FRITZ!Powerline\PowerlineService.exe [126976 2013-10-11] (AVM GmbH)
R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\eEBAPI\eEBSVC.exe [90112 2004-11-17] (SEIKO EPSON CORPORATION)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe [275696 2013-10-08] (Symantec Corporation)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-07-04] (TuneUp Software)
R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248704 2013-08-14] ()

==================== Drivers (Whitelisted) ====================

R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20131203.001\BHDrvx64.sys [1526488 2013-12-03] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-24] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-24] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140103.001\IDSvia64.sys [521944 2013-12-14] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140105.025\ENG64.SYS [126040 2013-12-26] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140105.025\EX64.SYS [2099288 2013-12-26] (Symantec Corporation)
R1 SRTSP; C:\Windows\System32\Drivers\NISx64\1501000.012\SRTSP64.SYS [858200 2013-09-27] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS [36952 2013-09-10] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1501000.012\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1501000.012\SYMEFA64.SYS [1147480 2013-09-27] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-14] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS [264280 2013-09-27] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1501000.012\SYMNETS.SYS [590936 2013-09-26] (Symantec Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-05-03] (TuneUp Software)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-05 15:04 - 2014-01-05 15:04 - 02347384 _____ (ESET) C:\Users\Hans Desktop PC\Downloads\esetsmartinstaller_enu (1).exe
2014-01-05 11:31 - 2014-01-05 11:31 - 00039109 _____ C:\Users\Hans Desktop PC\Desktop\FRST3.txt
2014-01-03 14:04 - 2014-01-03 14:04 - 02347384 _____ (ESET) C:\Users\Hans Desktop PC\Downloads\esetsmartinstaller_enu.exe
2014-01-03 13:56 - 2014-01-03 13:56 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Malwarebytes
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-03 13:56 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-03 13:55 - 2014-01-03 13:55 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Hans Desktop PC\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-03 09:43 - 2014-01-06 11:48 - 00000000 ____D C:\Users\Hans Desktop PC\Downloads\FRST-OlderVersion
2014-01-03 09:43 - 2014-01-03 09:43 - 00037064 _____ C:\Users\Hans Desktop PC\Desktop\FRST2.txt
2014-01-03 09:42 - 2014-01-03 09:42 - 00008921 _____ C:\Users\Hans Desktop PC\Desktop\AdwCleaner[S0].txt
2014-01-03 02:33 - 2014-01-03 02:33 - 00535712 _____ C:\Windows\Minidump\010314-22230-01.dmp
2014-01-02 20:31 - 2014-01-03 09:40 - 00000000 ____D C:\AdwCleaner
2014-01-02 20:30 - 2014-01-02 20:30 - 01233962 _____ C:\Users\Hans Desktop PC\Desktop\adwcleaner.exe
2014-01-02 13:10 - 2014-01-02 13:10 - 00010330 _____ C:\Users\Hans Desktop PC\Desktop\Gmer.txt
2014-01-02 13:04 - 2014-01-02 13:04 - 00377856 _____ C:\Users\Hans Desktop PC\Downloads\gmer_2.1.19163.exe
2014-01-02 13:03 - 2014-01-02 20:29 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Viruslog
2014-01-02 13:03 - 2014-01-02 13:03 - 00043723 _____ C:\Users\Hans Desktop PC\Desktop\FRST.txt
2014-01-02 13:03 - 2014-01-02 13:03 - 00025562 _____ C:\Users\Hans Desktop PC\Desktop\Addition.txt
2014-01-02 13:01 - 2014-01-06 11:48 - 00010593 _____ C:\Users\Hans Desktop PC\Downloads\FRST.txt
2014-01-02 13:01 - 2014-01-06 11:48 - 00000000 ____D C:\FRST
2014-01-02 13:01 - 2014-01-03 09:44 - 00028430 _____ C:\Users\Hans Desktop PC\Downloads\Addition.txt
2014-01-02 13:00 - 2014-01-06 11:48 - 01931762 _____ (Farbar) C:\Users\Hans Desktop PC\Downloads\FRST64.exe
2014-01-02 12:59 - 2014-01-02 12:59 - 00000492 _____ C:\Users\Hans Desktop PC\Downloads\defogger_disable.log
2014-01-02 12:59 - 2014-01-02 12:59 - 00000000 _____ C:\Users\Hans Desktop PC\defogger_reenable
2014-01-02 12:58 - 2014-01-02 12:58 - 00050477 _____ C:\Users\Hans Desktop PC\Downloads\Defogger.exe
2014-01-02 11:53 - 2014-01-02 11:53 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012
2014-01-02 11:32 - 2014-01-06 11:37 - 00003990 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8C789A6B-65A8-4A76-A311-F27A13C4B32B}
2014-01-01 17:51 - 2014-01-01 17:52 - 00063044 _____ C:\Users\Hans Desktop PC\Downloads\Bravo Hits - Vol. 32.rar.nzb
2014-01-01 15:12 - 2014-01-01 15:16 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Mp3tag
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Program Files (x86)\7-Zip
2014-01-01 14:44 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero
2014-01-01 13:24 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero_AG
2014-01-01 11:57 - 2014-01-01 11:57 - 00000000 ____D C:\Program Files (x86)\MarkAny
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Nero
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\ProgramData\LightScribe
2014-01-01 11:44 - 2014-01-01 11:44 - 00002213 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00002193 _____ C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2012
2014-01-01 11:44 - 2012-07-04 10:49 - 00034656 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe
2014-01-01 11:44 - 2012-07-04 10:49 - 00025952 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll
2014-01-01 11:44 - 2012-07-04 10:49 - 00021344 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll
2014-01-01 11:16 - 2014-01-03 00:00 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CrashDumps
2013-12-31 11:13 - 2014-01-03 00:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-Q5-TTL.DAT
2013-12-24 19:01 - 2013-12-24 19:02 - 00259770 _____ C:\Windows\msxml4-KB2758694-enu.LOG
2013-12-24 18:38 - 2013-12-24 18:38 - 02634152 _____ C:\Users\Hans Desktop PC\Downloads\mp3tagv258setup.exe
2013-12-24 18:38 - 2013-12-24 18:38 - 00000983 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2013-12-24 18:38 - 2013-12-24 18:38 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Hausverwalter
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl Data Service
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl Data Service
2013-12-24 11:13 - 2013-12-24 11:13 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2013-12-22 17:38 - 2013-12-22 17:38 - 00001181 _____ C:\Users\Public\Desktop\MAGIX Video easy TERRATEC Edition.lnk
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\ProgramData\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-12-22 17:37 - 2013-12-22 17:37 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-12-22 17:34 - 2013-12-22 17:36 - 211870088 _____ (MAGIX AG) C:\Users\Hans Desktop PC\Downloads\MAGIX_Video_easy_TERRATEC_Edition.exe
2013-12-22 17:34 - 2013-12-22 17:34 - 00000000 ____D C:\ProgramData\CMUV
2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files\DIFX
2013-12-22 17:32 - 2013-12-22 17:32 - 00000000 ____D C:\Program Files (x86)\TERRATEC
2013-12-22 17:29 - 2013-12-22 17:32 - 03311568 _____ C:\Users\Hans Desktop PC\Downloads\TERRATEC_CINERGY_HTC_Stick_HD_Driver_Setup_7.0.122.90_XP_Vista_7_8.exe
2013-12-22 17:28 - 2013-12-22 17:28 - 00001137 _____ C:\Users\Hans Desktop PC\Desktop\DVBViewer TERRATEC Edition.lnk
2013-12-22 17:28 - 2013-12-22 17:28 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition
2013-12-22 16:51 - 2013-12-22 16:51 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:51 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:50 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-12-22 15:54 - 2013-12-22 15:54 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk
2013-12-22 15:53 - 2013-12-22 15:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk
2013-12-22 15:52 - 2013-12-22 16:01 - 00000000 ____D C:\ProgramData\Nero
2013-12-22 15:10 - 2013-12-22 15:56 - 00000000 ____D C:\Program Files (x86)\Nero
2013-12-22 15:10 - 2011-12-01 11:42 - 00072240 _____ (Nero AG) C:\Windows\system32\Drivers\NBVol.sys
2013-12-22 15:10 - 2011-12-01 11:42 - 00015920 _____ (Nero AG) C:\Windows\system32\Drivers\NBVolUp.sys
2013-12-22 15:04 - 2013-12-22 15:04 - 00002037 _____ C:\Users\Public\Desktop\LightScribe.lnk
2013-12-22 15:04 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2013-12-22 15:04 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2013-12-22 15:04 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2013-12-22 15:04 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2013-12-22 15:04 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2013-12-22 15:03 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2013-12-22 15:03 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2013-12-22 15:03 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2013-12-22 15:03 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2013-12-22 15:03 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2013-12-22 15:03 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2013-12-18 16:56 - 2013-12-25 11:15 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mein Steuer-Sparbuch Heute
2013-12-15 16:46 - 2013-12-15 16:46 - 00001000 _____ C:\Users\Public\Desktop\WISO Hausverwalter 2014.lnk
2013-12-15 16:34 - 2013-12-15 16:34 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl
2013-12-15 12:45 - 2013-12-24 11:46 - 00000651 _____ C:\Windows\wiso.ini
2013-12-15 12:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl
2013-12-15 12:45 - 2013-12-15 12:45 - 00000986 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk
2013-12-15 12:12 - 2013-12-24 11:45 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH
2013-12-11 17:08 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-11 17:08 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-11 17:08 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-11 17:08 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-11 17:07 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-11 17:07 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-11 17:07 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-11 17:07 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-11 17:07 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-11 17:07 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-11 17:07 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-11 17:07 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-11 17:07 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-11 17:07 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-11 17:07 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-11 17:07 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-11 17:07 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-11 17:07 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-11 17:07 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-11 17:07 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-11 17:07 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-11 17:07 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-11 17:07 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-11 17:07 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-11 17:07 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-11 17:07 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-11 17:07 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-11 17:07 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-11 17:07 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-11 17:07 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-11 17:07 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-11 17:07 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-11 17:07 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-11 17:07 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-11 17:07 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 15:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 15:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 15:22 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 15:22 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 15:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 15:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 15:22 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 15:22 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 15:22 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 15:22 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 15:22 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 15:22 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 15:22 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 15:22 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 15:22 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 15:22 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 15:22 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 15:22 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 15:22 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys

==================== One Month Modified Files and Folders =======

2014-01-06 11:48 - 2014-01-03 09:43 - 00000000 ____D C:\Users\Hans Desktop PC\Downloads\FRST-OlderVersion
2014-01-06 11:48 - 2014-01-02 13:01 - 00010593 _____ C:\Users\Hans Desktop PC\Downloads\FRST.txt
2014-01-06 11:48 - 2014-01-02 13:01 - 00000000 ____D C:\FRST
2014-01-06 11:48 - 2014-01-02 13:00 - 01931762 _____ (Farbar) C:\Users\Hans Desktop PC\Downloads\FRST64.exe
2014-01-06 11:37 - 2014-01-02 11:32 - 00003990 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8C789A6B-65A8-4A76-A311-F27A13C4B32B}
2014-01-06 11:28 - 2013-11-01 18:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-06 11:04 - 2013-11-03 19:48 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-06 10:24 - 2013-10-31 19:36 - 01914218 _____ C:\Windows\WindowsUpdate.log
2014-01-05 15:04 - 2014-01-05 15:04 - 02347384 _____ (ESET) C:\Users\Hans Desktop PC\Downloads\esetsmartinstaller_enu (1).exe
2014-01-05 12:04 - 2013-11-03 19:48 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-05 11:31 - 2014-01-05 11:31 - 00039109 _____ C:\Users\Hans Desktop PC\Desktop\FRST3.txt
2014-01-04 18:01 - 2013-10-31 19:44 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs
2014-01-03 14:10 - 2009-07-14 05:50 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-03 14:10 - 2009-07-14 05:50 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-03 14:07 - 2011-04-12 09:14 - 00653928 _____ C:\Windows\system32\perfh007.dat
2014-01-03 14:07 - 2011-04-12 09:14 - 00129800 _____ C:\Windows\system32\perfc007.dat
2014-01-03 14:07 - 2009-07-14 06:12 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-03 14:04 - 2014-01-03 14:04 - 02347384 _____ (ESET) C:\Users\Hans Desktop PC\Downloads\esetsmartinstaller_enu.exe
2014-01-03 14:03 - 2010-11-21 04:47 - 00050832 _____ C:\Windows\PFRO.log
2014-01-03 14:03 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-03 14:03 - 2009-07-14 05:56 - 00037977 _____ C:\Windows\setupact.log
2014-01-03 13:56 - 2014-01-03 13:56 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Malwarebytes
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-03 13:55 - 2014-01-03 13:55 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Hans Desktop PC\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-03 13:54 - 2013-10-31 19:40 - 00000000 ____D C:\Users\Hans Desktop PC
2014-01-03 09:44 - 2014-01-02 13:01 - 00028430 _____ C:\Users\Hans Desktop PC\Downloads\Addition.txt
2014-01-03 09:43 - 2014-01-03 09:43 - 00037064 _____ C:\Users\Hans Desktop PC\Desktop\FRST2.txt
2014-01-03 09:42 - 2014-01-03 09:42 - 00008921 _____ C:\Users\Hans Desktop PC\Desktop\AdwCleaner[S0].txt
2014-01-03 09:40 - 2014-01-02 20:31 - 00000000 ____D C:\AdwCleaner
2014-01-03 09:40 - 2013-11-03 19:48 - 00001282 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-03 09:40 - 2013-10-31 19:41 - 00001015 _____ C:\Users\Hans Desktop PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-03 02:33 - 2014-01-03 02:33 - 00535712 _____ C:\Windows\Minidump\010314-22230-01.dmp
2014-01-03 02:33 - 2013-11-10 18:08 - 704441021 _____ C:\Windows\MEMORY.DMP
2014-01-03 02:33 - 2013-11-10 18:08 - 00000000 ____D C:\Windows\Minidump
2014-01-03 00:13 - 2013-12-31 11:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-Q5-TTL.DAT
2014-01-03 00:13 - 2013-12-04 19:13 - 00000103 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WB.CFG
2014-01-03 00:13 - 2013-12-04 19:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-TTL.DAT
2014-01-03 00:00 - 2014-01-01 11:16 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CrashDumps
2014-01-02 20:30 - 2014-01-02 20:30 - 01233962 _____ C:\Users\Hans Desktop PC\Desktop\adwcleaner.exe
2014-01-02 20:29 - 2014-01-02 13:03 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Viruslog
2014-01-02 13:10 - 2014-01-02 13:10 - 00010330 _____ C:\Users\Hans Desktop PC\Desktop\Gmer.txt
2014-01-02 13:04 - 2014-01-02 13:04 - 00377856 _____ C:\Users\Hans Desktop PC\Downloads\gmer_2.1.19163.exe
2014-01-02 13:03 - 2014-01-02 13:03 - 00043723 _____ C:\Users\Hans Desktop PC\Desktop\FRST.txt
2014-01-02 13:03 - 2014-01-02 13:03 - 00025562 _____ C:\Users\Hans Desktop PC\Desktop\Addition.txt
2014-01-02 12:59 - 2014-01-02 12:59 - 00000492 _____ C:\Users\Hans Desktop PC\Downloads\defogger_disable.log
2014-01-02 12:59 - 2014-01-02 12:59 - 00000000 _____ C:\Users\Hans Desktop PC\defogger_reenable
2014-01-02 12:58 - 2014-01-02 12:58 - 00050477 _____ C:\Users\Hans Desktop PC\Downloads\Defogger.exe
2014-01-02 11:53 - 2014-01-02 11:53 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012
2014-01-01 17:52 - 2014-01-01 17:51 - 00063044 _____ C:\Users\Hans Desktop PC\Downloads\Bravo Hits - Vol. 32.rar.nzb
2014-01-01 15:16 - 2014-01-01 15:12 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Mp3tag
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Program Files (x86)\7-Zip
2014-01-01 14:44 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero
2014-01-01 14:44 - 2014-01-01 13:24 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero_AG
2014-01-01 11:58 - 2013-11-01 19:08 - 00000793 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-01-01 11:57 - 2014-01-01 11:57 - 00000000 ____D C:\Program Files (x86)\MarkAny
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Nero
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\ProgramData\LightScribe
2014-01-01 11:44 - 2014-01-01 11:44 - 00002213 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00002193 _____ C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2012
2013-12-25 11:15 - 2013-12-18 16:56 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mein Steuer-Sparbuch Heute
2013-12-24 19:02 - 2013-12-24 19:01 - 00259770 _____ C:\Windows\msxml4-KB2758694-enu.LOG
2013-12-24 18:38 - 2013-12-24 18:38 - 02634152 _____ C:\Users\Hans Desktop PC\Downloads\mp3tagv258setup.exe
2013-12-24 18:38 - 2013-12-24 18:38 - 00000983 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2013-12-24 18:38 - 2013-12-24 18:38 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-12-24 11:46 - 2013-12-15 12:45 - 00000651 _____ C:\Windows\wiso.ini
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Hausverwalter
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl Data Service
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl Data Service
2013-12-24 11:45 - 2013-12-15 12:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl
2013-12-24 11:45 - 2013-12-15 12:12 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH
2013-12-24 11:13 - 2013-12-24 11:13 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2013-12-24 10:14 - 2013-10-31 19:40 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\VirtualStore
2013-12-22 18:12 - 2013-10-31 21:27 - 00154336 _____ C:\Users\Hans Desktop PC\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-22 17:42 - 2009-07-14 05:50 - 00507536 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-22 17:38 - 2013-12-22 17:38 - 00001181 _____ C:\Users\Public\Desktop\MAGIX Video easy TERRATEC Edition.lnk
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\ProgramData\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-12-22 17:37 - 2013-12-22 17:37 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-12-22 17:36 - 2013-12-22 17:34 - 211870088 _____ (MAGIX AG) C:\Users\Hans Desktop PC\Downloads\MAGIX_Video_easy_TERRATEC_Edition.exe
2013-12-22 17:34 - 2013-12-22 17:34 - 00000000 ____D C:\ProgramData\CMUV
2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files\DIFX
2013-12-22 17:33 - 2013-10-31 23:07 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-22 17:32 - 2013-12-22 17:32 - 00000000 ____D C:\Program Files (x86)\TERRATEC
2013-12-22 17:32 - 2013-12-22 17:29 - 03311568 _____ C:\Users\Hans Desktop PC\Downloads\TERRATEC_CINERGY_HTC_Stick_HD_Driver_Setup_7.0.122.90_XP_Vista_7_8.exe
2013-12-22 17:28 - 2013-12-22 17:28 - 00001137 _____ C:\Users\Hans Desktop PC\Desktop\DVBViewer TERRATEC Edition.lnk
2013-12-22 17:28 - 2013-12-22 17:28 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition
2013-12-22 17:27 - 2013-11-01 19:01 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Downloaded Installations
2013-12-22 16:51 - 2013-12-22 16:51 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\TuneUp Software
2013-12-22 16:51 - 2013-12-22 16:50 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:50 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-12-22 16:01 - 2013-12-22 15:52 - 00000000 ____D C:\ProgramData\Nero
2013-12-22 15:56 - 2013-12-22 15:10 - 00000000 ____D C:\Program Files (x86)\Nero
2013-12-22 15:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Cursors
2013-12-22 15:54 - 2013-12-22 15:54 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk
2013-12-22 15:53 - 2013-12-22 15:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk
2013-12-22 15:04 - 2013-12-22 15:04 - 00002037 _____ C:\Users\Public\Desktop\LightScribe.lnk
2013-12-15 19:30 - 2013-11-01 19:08 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Samsung
2013-12-15 16:46 - 2013-12-15 16:46 - 00001000 _____ C:\Users\Public\Desktop\WISO Hausverwalter 2014.lnk
2013-12-15 16:34 - 2013-12-15 16:34 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl
2013-12-15 12:45 - 2013-12-15 12:45 - 00000986 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk
2013-12-15 12:08 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-12-15 00:13 - 2013-11-03 19:48 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Google
2013-12-14 17:34 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-11 17:08 - 2013-10-31 20:26 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 15:28 - 2013-11-01 18:59 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 15:28 - 2013-11-01 18:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 15:28 - 2013-11-01 18:59 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-08 17:20 - 2013-10-31 23:34 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\ChessBase
2013-12-08 11:59 - 2013-11-03 19:48 - 00004124 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-08 11:59 - 2013-11-03 19:48 - 00003872 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

Some content of TEMP:
====================
C:\Users\Hans Desktop PC\AppData\Local\Temp\opsrnrpevolrwo.exe
C:\Users\Hans Desktop PC\AppData\Local\Temp\Quarantine.exe
C:\Users\Hans Desktop PC\AppData\Local\Temp\TUUUninstallHelper.exe
C:\Users\Hans Desktop PC\AppData\Local\Temp\twnplxhj.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-01 13:44

==================== End Of Log ============================
         
--- --- ---

Alt 06.01.2014, 20:40   #11
sunjojo
/// Malwareteam
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



Zitat:
Muss man sich da jetzt Sorgen machen?
Wir müssen auf jeden Fall nochmal was fixen. Die anderen Funden, die ESET auflistet, solltest du löschen. Generell sind Downloads von nicht sicheren Quellen ein Risiko, da diese häufig mit zusätzlicher Software wie Adware, PUPs oder sogar Malware versehen werden. Anscheinend sind auch in den Backups verseuchte Dateien, am besten solltest du auch diese löschen .



Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
H:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013
D:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013
G:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013
cmd: type D:\autorun.inf
H:\autorun.inf
D:\autorun.inf
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

Schritt 2
Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, wird ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.



Poste folgende Logfiles in deiner nächsten Antwort:
  • FRST-Fix
  • FRST-Scan
__________________
Gruß,

Jonas

Alt 07.01.2014, 16:02   #12
Mixia
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



Soll ich die ESET-Dateien manuell löschen?

FRST Fix
Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-01-2014
Ran by Hans Desktop PC at 2014-01-07 16:58:54 Run:2
Running from C:\Users\Hans Desktop PC\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
H:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013
D:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013
G:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013
cmd: type D:\autorun.inf
H:\autorun.inf
D:\autorun.inf
*****************

H:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013 => Moved successfully.
D:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013 => Moved successfully.
G:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013 => Moved successfully.

=========  type D:\autorun.inf =========

[autorun]
open=RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013\msexplorer.exe
shellexecute=RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013\msexplorer.exe
action=Ordner �ffnen um Dateien anzuzeigen
shell\Open=Open
shell\Open\command=RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013\msexplorer.exe
shell\Open\Default=1

========= End of CMD: =========

H:\autorun.inf => Moved successfully.
D:\autorun.inf => Moved successfully.

==== End of Fixlog ====
         
FRST

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014
Ran by Hans Desktop PC (administrator) on HANSDESKTOPPC on 07-01-2014 17:00:00
Running from C:\Users\Hans Desktop PC\Downloads
Windows 7 Professional N Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\eEBAPI\eEBSvc.exe
(AVM GmbH) C:\Program Files (x86)\FRITZ!Powerline\PowerlineService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
() C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe
(Samsung) D:\Program Files (x86)\Kies\Kies.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Samsung Electronics Co., Ltd.) D:\Program Files (x86)\Kies\KiesTrayAgent.exe
() D:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] - D:\Program Files (x86)\Kies\KiesTrayAgent.exe [311152 2013-12-11] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [NBAgent] - C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe [1493288 2012-01-13] (Nero AG)
HKCU\...\Run: [KiesPreload] - D:\Program Files (x86)\Kies\Kies.exe [1564528 2013-12-11] (Samsung)
HKCU\...\Run: [] - D:\Program Files (x86)\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-12-11] (Samsung)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2741616 2011-03-04] (Hewlett-Packard Company)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.tagesschau.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x84E3C03977D6CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\IPSBHO.dll (Symantec Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

Chrome: 
=======
CHR HomePage: hxxp://tagesschau.de/
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Extension: (Google Docs) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Norton Identity Protection) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0
CHR Extension: (Google Wallet) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Gmail) - C:\Users\Hans Desktop PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\Exts\Chrome.crx

==================== Services (Whitelisted) =================

R2 AVMPowerlineService; C:\Program Files (x86)\FRITZ!Powerline\PowerlineService.exe [126976 2013-10-11] (AVM GmbH)
R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\eEBAPI\eEBSVC.exe [90112 2004-11-17] (SEIKO EPSON CORPORATION)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe [275696 2013-10-08] (Symantec Corporation)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-07-04] (TuneUp Software)
R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248704 2013-08-14] ()

==================== Drivers (Whitelisted) ====================

R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20131218.001\BHDrvx64.sys [1526488 2013-12-18] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-24] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-24] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140103.001\IDSvia64.sys [521944 2013-12-14] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140106.001\ENG64.SYS [126040 2013-12-26] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140106.001\EX64.SYS [2099288 2013-12-26] (Symantec Corporation)
R1 SRTSP; C:\Windows\System32\Drivers\NISx64\1501000.012\SRTSP64.SYS [858200 2013-09-27] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS [36952 2013-09-10] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1501000.012\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1501000.012\SYMEFA64.SYS [1147480 2013-09-27] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-14] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS [264280 2013-09-27] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1501000.012\SYMNETS.SYS [590936 2013-09-26] (Symantec Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-05-03] (TuneUp Software)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-07 16:58 - 2014-01-07 16:58 - 00000233 _____ C:\Users\Hans Desktop PC\Desktop\Fixlist.txt
2014-01-06 18:25 - 2014-01-06 19:32 - 00000000 ____D C:\Program Files (x86)\Steam
2014-01-06 18:25 - 2014-01-06 18:25 - 01133552 _____ C:\Users\Hans Desktop PC\Downloads\SteamSetup.exe
2014-01-06 18:25 - 2014-01-06 18:25 - 00000967 _____ C:\Users\Public\Desktop\Steam.lnk
2014-01-06 11:48 - 2014-01-06 11:48 - 00039557 _____ C:\Users\Hans Desktop PC\Downloads\FRST4.txt
2014-01-06 11:48 - 2014-01-06 11:48 - 00039557 _____ C:\Users\Hans Desktop PC\Desktop\FRST4.txt
2014-01-05 15:04 - 2014-01-05 15:04 - 02347384 _____ (ESET) C:\Users\Hans Desktop PC\Downloads\esetsmartinstaller_enu (1).exe
2014-01-05 11:31 - 2014-01-05 11:31 - 00039109 _____ C:\Users\Hans Desktop PC\Desktop\FRST3.txt
2014-01-03 14:04 - 2014-01-03 14:04 - 02347384 _____ (ESET) C:\Users\Hans Desktop PC\Downloads\esetsmartinstaller_enu.exe
2014-01-03 13:56 - 2014-01-03 13:56 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Malwarebytes
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-03 13:56 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-03 13:55 - 2014-01-03 13:55 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Hans Desktop PC\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-03 09:43 - 2014-01-06 11:48 - 00000000 ____D C:\Users\Hans Desktop PC\Downloads\FRST-OlderVersion
2014-01-03 09:43 - 2014-01-03 09:43 - 00037064 _____ C:\Users\Hans Desktop PC\Desktop\FRST2.txt
2014-01-03 09:42 - 2014-01-03 09:42 - 00008921 _____ C:\Users\Hans Desktop PC\Desktop\AdwCleaner[S0].txt
2014-01-03 02:33 - 2014-01-03 02:33 - 00535712 _____ C:\Windows\Minidump\010314-22230-01.dmp
2014-01-02 20:31 - 2014-01-03 09:40 - 00000000 ____D C:\AdwCleaner
2014-01-02 20:30 - 2014-01-02 20:30 - 01233962 _____ C:\Users\Hans Desktop PC\Desktop\adwcleaner.exe
2014-01-02 13:10 - 2014-01-02 13:10 - 00010330 _____ C:\Users\Hans Desktop PC\Desktop\Gmer.txt
2014-01-02 13:04 - 2014-01-02 13:04 - 00377856 _____ C:\Users\Hans Desktop PC\Downloads\gmer_2.1.19163.exe
2014-01-02 13:03 - 2014-01-02 20:29 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Viruslog
2014-01-02 13:03 - 2014-01-02 13:03 - 00043723 _____ C:\Users\Hans Desktop PC\Desktop\FRST.txt
2014-01-02 13:03 - 2014-01-02 13:03 - 00025562 _____ C:\Users\Hans Desktop PC\Desktop\Addition.txt
2014-01-02 13:01 - 2014-01-07 17:00 - 00010513 _____ C:\Users\Hans Desktop PC\Downloads\FRST.txt
2014-01-02 13:01 - 2014-01-06 11:48 - 00000000 ____D C:\FRST
2014-01-02 13:01 - 2014-01-03 09:44 - 00028430 _____ C:\Users\Hans Desktop PC\Downloads\Addition.txt
2014-01-02 13:00 - 2014-01-06 11:48 - 01931762 _____ (Farbar) C:\Users\Hans Desktop PC\Downloads\FRST64.exe
2014-01-02 12:59 - 2014-01-02 12:59 - 00000492 _____ C:\Users\Hans Desktop PC\Downloads\defogger_disable.log
2014-01-02 12:59 - 2014-01-02 12:59 - 00000000 _____ C:\Users\Hans Desktop PC\defogger_reenable
2014-01-02 12:58 - 2014-01-02 12:58 - 00050477 _____ C:\Users\Hans Desktop PC\Downloads\Defogger.exe
2014-01-02 11:53 - 2014-01-02 11:53 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012
2014-01-02 11:32 - 2014-01-06 21:20 - 00003990 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8C789A6B-65A8-4A76-A311-F27A13C4B32B}
2014-01-01 17:51 - 2014-01-01 17:52 - 00063044 _____ C:\Users\Hans Desktop PC\Downloads\Bravo Hits - Vol. 32.rar.nzb
2014-01-01 15:12 - 2014-01-01 15:16 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Mp3tag
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Program Files (x86)\7-Zip
2014-01-01 14:44 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero
2014-01-01 13:24 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero_AG
2014-01-01 11:57 - 2014-01-01 11:57 - 00000000 ____D C:\Program Files (x86)\MarkAny
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Nero
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\ProgramData\LightScribe
2014-01-01 11:44 - 2014-01-01 11:44 - 00002213 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00002193 _____ C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2012
2014-01-01 11:44 - 2012-07-04 10:49 - 00034656 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe
2014-01-01 11:44 - 2012-07-04 10:49 - 00025952 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll
2014-01-01 11:44 - 2012-07-04 10:49 - 00021344 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll
2014-01-01 11:16 - 2014-01-03 00:00 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CrashDumps
2013-12-31 11:13 - 2014-01-03 00:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-Q5-TTL.DAT
2013-12-24 19:01 - 2013-12-24 19:02 - 00259770 _____ C:\Windows\msxml4-KB2758694-enu.LOG
2013-12-24 18:38 - 2013-12-24 18:38 - 02634152 _____ C:\Users\Hans Desktop PC\Downloads\mp3tagv258setup.exe
2013-12-24 18:38 - 2013-12-24 18:38 - 00000983 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2013-12-24 18:38 - 2013-12-24 18:38 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Hausverwalter
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl Data Service
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl Data Service
2013-12-24 11:13 - 2013-12-24 11:13 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2013-12-22 17:38 - 2013-12-22 17:38 - 00001181 _____ C:\Users\Public\Desktop\MAGIX Video easy TERRATEC Edition.lnk
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\ProgramData\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-12-22 17:37 - 2013-12-22 17:37 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-12-22 17:34 - 2013-12-22 17:36 - 211870088 _____ (MAGIX AG) C:\Users\Hans Desktop PC\Downloads\MAGIX_Video_easy_TERRATEC_Edition.exe
2013-12-22 17:34 - 2013-12-22 17:34 - 00000000 ____D C:\ProgramData\CMUV
2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files\DIFX
2013-12-22 17:32 - 2013-12-22 17:32 - 00000000 ____D C:\Program Files (x86)\TERRATEC
2013-12-22 17:29 - 2013-12-22 17:32 - 03311568 _____ C:\Users\Hans Desktop PC\Downloads\TERRATEC_CINERGY_HTC_Stick_HD_Driver_Setup_7.0.122.90_XP_Vista_7_8.exe
2013-12-22 17:28 - 2013-12-22 17:28 - 00001137 _____ C:\Users\Hans Desktop PC\Desktop\DVBViewer TERRATEC Edition.lnk
2013-12-22 17:28 - 2013-12-22 17:28 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition
2013-12-22 16:51 - 2013-12-22 16:51 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:51 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:50 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-12-22 15:54 - 2013-12-22 15:54 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk
2013-12-22 15:53 - 2013-12-22 15:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk
2013-12-22 15:52 - 2013-12-22 16:01 - 00000000 ____D C:\ProgramData\Nero
2013-12-22 15:10 - 2013-12-22 15:56 - 00000000 ____D C:\Program Files (x86)\Nero
2013-12-22 15:10 - 2011-12-01 11:42 - 00072240 _____ (Nero AG) C:\Windows\system32\Drivers\NBVol.sys
2013-12-22 15:10 - 2011-12-01 11:42 - 00015920 _____ (Nero AG) C:\Windows\system32\Drivers\NBVolUp.sys
2013-12-22 15:04 - 2013-12-22 15:04 - 00002037 _____ C:\Users\Public\Desktop\LightScribe.lnk
2013-12-22 15:04 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2013-12-22 15:04 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2013-12-22 15:04 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2013-12-22 15:04 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2013-12-22 15:04 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2013-12-22 15:03 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2013-12-22 15:03 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2013-12-22 15:03 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2013-12-22 15:03 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2013-12-22 15:03 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2013-12-22 15:03 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2013-12-18 16:56 - 2013-12-25 11:15 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mein Steuer-Sparbuch Heute
2013-12-15 16:46 - 2013-12-15 16:46 - 00001000 _____ C:\Users\Public\Desktop\WISO Hausverwalter 2014.lnk
2013-12-15 16:34 - 2013-12-15 16:34 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl
2013-12-15 12:45 - 2013-12-24 11:46 - 00000651 _____ C:\Windows\wiso.ini
2013-12-15 12:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl
2013-12-15 12:45 - 2013-12-15 12:45 - 00000986 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk
2013-12-15 12:12 - 2013-12-24 11:45 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH
2013-12-11 17:08 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-11 17:08 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-11 17:08 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-11 17:08 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-11 17:07 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-11 17:07 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-11 17:07 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-11 17:07 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-11 17:07 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-11 17:07 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-11 17:07 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-11 17:07 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-11 17:07 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-11 17:07 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-11 17:07 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-11 17:07 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-11 17:07 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-11 17:07 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-11 17:07 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-11 17:07 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-11 17:07 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-11 17:07 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-11 17:07 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-11 17:07 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-11 17:07 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-11 17:07 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-11 17:07 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-11 17:07 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-11 17:07 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-11 17:07 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-11 17:07 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-11 17:07 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-11 17:07 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-11 17:07 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-11 17:07 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 15:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 15:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 15:22 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 15:22 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 15:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 15:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 15:22 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 15:22 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 15:22 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 15:22 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 15:22 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 15:22 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 15:22 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 15:22 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 15:22 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 15:22 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 15:22 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 15:22 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 15:22 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys

==================== One Month Modified Files and Folders =======

2014-01-07 17:00 - 2014-01-02 13:01 - 00010513 _____ C:\Users\Hans Desktop PC\Downloads\FRST.txt
2014-01-07 16:58 - 2014-01-07 16:58 - 00000233 _____ C:\Users\Hans Desktop PC\Desktop\Fixlist.txt
2014-01-07 16:58 - 2011-04-12 09:14 - 00653928 _____ C:\Windows\system32\perfh007.dat
2014-01-07 16:58 - 2011-04-12 09:14 - 00129800 _____ C:\Windows\system32\perfc007.dat
2014-01-07 16:58 - 2009-07-14 06:12 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-07 16:54 - 2013-11-03 19:48 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-07 16:54 - 2013-10-31 19:44 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs
2014-01-07 16:54 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-07 16:54 - 2009-07-14 05:56 - 00038886 _____ C:\Windows\setupact.log
2014-01-06 21:32 - 2013-10-31 19:36 - 01970195 _____ C:\Windows\WindowsUpdate.log
2014-01-06 21:28 - 2013-11-01 18:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-06 21:20 - 2014-01-02 11:32 - 00003990 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8C789A6B-65A8-4A76-A311-F27A13C4B32B}
2014-01-06 21:04 - 2013-11-03 19:48 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-06 19:32 - 2014-01-06 18:25 - 00000000 ____D C:\Program Files (x86)\Steam
2014-01-06 18:25 - 2014-01-06 18:25 - 01133552 _____ C:\Users\Hans Desktop PC\Downloads\SteamSetup.exe
2014-01-06 18:25 - 2014-01-06 18:25 - 00000967 _____ C:\Users\Public\Desktop\Steam.lnk
2014-01-06 13:43 - 2009-07-14 05:50 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-06 13:43 - 2009-07-14 05:50 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-06 13:36 - 2010-11-21 04:47 - 00052380 _____ C:\Windows\PFRO.log
2014-01-06 11:48 - 2014-01-06 11:48 - 00039557 _____ C:\Users\Hans Desktop PC\Downloads\FRST4.txt
2014-01-06 11:48 - 2014-01-06 11:48 - 00039557 _____ C:\Users\Hans Desktop PC\Desktop\FRST4.txt
2014-01-06 11:48 - 2014-01-03 09:43 - 00000000 ____D C:\Users\Hans Desktop PC\Downloads\FRST-OlderVersion
2014-01-06 11:48 - 2014-01-02 13:01 - 00000000 ____D C:\FRST
2014-01-06 11:48 - 2014-01-02 13:00 - 01931762 _____ (Farbar) C:\Users\Hans Desktop PC\Downloads\FRST64.exe
2014-01-05 15:04 - 2014-01-05 15:04 - 02347384 _____ (ESET) C:\Users\Hans Desktop PC\Downloads\esetsmartinstaller_enu (1).exe
2014-01-05 11:31 - 2014-01-05 11:31 - 00039109 _____ C:\Users\Hans Desktop PC\Desktop\FRST3.txt
2014-01-03 14:04 - 2014-01-03 14:04 - 02347384 _____ (ESET) C:\Users\Hans Desktop PC\Downloads\esetsmartinstaller_enu.exe
2014-01-03 13:56 - 2014-01-03 13:56 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Malwarebytes
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-03 13:56 - 2014-01-03 13:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-03 13:55 - 2014-01-03 13:55 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Hans Desktop PC\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-03 13:54 - 2013-10-31 19:40 - 00000000 ____D C:\Users\Hans Desktop PC
2014-01-03 09:44 - 2014-01-02 13:01 - 00028430 _____ C:\Users\Hans Desktop PC\Downloads\Addition.txt
2014-01-03 09:43 - 2014-01-03 09:43 - 00037064 _____ C:\Users\Hans Desktop PC\Desktop\FRST2.txt
2014-01-03 09:42 - 2014-01-03 09:42 - 00008921 _____ C:\Users\Hans Desktop PC\Desktop\AdwCleaner[S0].txt
2014-01-03 09:40 - 2014-01-02 20:31 - 00000000 ____D C:\AdwCleaner
2014-01-03 09:40 - 2013-11-03 19:48 - 00001282 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-03 09:40 - 2013-10-31 19:41 - 00001015 _____ C:\Users\Hans Desktop PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-03 02:33 - 2014-01-03 02:33 - 00535712 _____ C:\Windows\Minidump\010314-22230-01.dmp
2014-01-03 02:33 - 2013-11-10 18:08 - 704441021 _____ C:\Windows\MEMORY.DMP
2014-01-03 02:33 - 2013-11-10 18:08 - 00000000 ____D C:\Windows\Minidump
2014-01-03 00:13 - 2013-12-31 11:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-Q5-TTL.DAT
2014-01-03 00:13 - 2013-12-04 19:13 - 00000103 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WB.CFG
2014-01-03 00:13 - 2013-12-04 19:13 - 00000005 _____ C:\Users\Hans Desktop PC\AppData\Roaming\WBPU-TTL.DAT
2014-01-03 00:00 - 2014-01-01 11:16 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\CrashDumps
2014-01-02 20:30 - 2014-01-02 20:30 - 01233962 _____ C:\Users\Hans Desktop PC\Desktop\adwcleaner.exe
2014-01-02 20:29 - 2014-01-02 13:03 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Viruslog
2014-01-02 13:10 - 2014-01-02 13:10 - 00010330 _____ C:\Users\Hans Desktop PC\Desktop\Gmer.txt
2014-01-02 13:04 - 2014-01-02 13:04 - 00377856 _____ C:\Users\Hans Desktop PC\Downloads\gmer_2.1.19163.exe
2014-01-02 13:03 - 2014-01-02 13:03 - 00043723 _____ C:\Users\Hans Desktop PC\Desktop\FRST.txt
2014-01-02 13:03 - 2014-01-02 13:03 - 00025562 _____ C:\Users\Hans Desktop PC\Desktop\Addition.txt
2014-01-02 12:59 - 2014-01-02 12:59 - 00000492 _____ C:\Users\Hans Desktop PC\Downloads\defogger_disable.log
2014-01-02 12:59 - 2014-01-02 12:59 - 00000000 _____ C:\Users\Hans Desktop PC\defogger_reenable
2014-01-02 12:58 - 2014-01-02 12:58 - 00050477 _____ C:\Users\Hans Desktop PC\Downloads\Defogger.exe
2014-01-02 11:53 - 2014-01-02 11:53 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012
2014-01-01 17:52 - 2014-01-01 17:51 - 00063044 _____ C:\Users\Hans Desktop PC\Downloads\Bravo Hits - Vol. 32.rar.nzb
2014-01-01 15:16 - 2014-01-01 15:12 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Mp3tag
2014-01-01 14:57 - 2014-01-01 14:57 - 00000000 ____D C:\Program Files (x86)\7-Zip
2014-01-01 14:44 - 2014-01-01 14:44 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero
2014-01-01 14:44 - 2014-01-01 13:24 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Nero_AG
2014-01-01 11:58 - 2013-11-01 19:08 - 00000793 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-01-01 11:57 - 2014-01-01 11:57 - 00000000 ____D C:\Program Files (x86)\MarkAny
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Nero
2014-01-01 11:50 - 2014-01-01 11:50 - 00000000 ____D C:\ProgramData\LightScribe
2014-01-01 11:44 - 2014-01-01 11:44 - 00002213 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00002193 _____ C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk
2014-01-01 11:44 - 2014-01-01 11:44 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2012
2013-12-25 11:15 - 2013-12-18 16:56 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Mein Steuer-Sparbuch Heute
2013-12-24 19:02 - 2013-12-24 19:01 - 00259770 _____ C:\Windows\msxml4-KB2758694-enu.LOG
2013-12-24 18:38 - 2013-12-24 18:38 - 02634152 _____ C:\Users\Hans Desktop PC\Downloads\mp3tagv258setup.exe
2013-12-24 18:38 - 2013-12-24 18:38 - 00000983 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2013-12-24 18:38 - 2013-12-24 18:38 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-12-24 11:46 - 2013-12-15 12:45 - 00000651 _____ C:\Windows\wiso.ini
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\Hausverwalter
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl Data Service
2013-12-24 11:45 - 2013-12-24 11:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl Data Service
2013-12-24 11:45 - 2013-12-15 12:45 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Buhl
2013-12-24 11:45 - 2013-12-15 12:12 - 00000000 ____D C:\ProgramData\Buhl Data Service GmbH
2013-12-24 11:13 - 2013-12-24 11:13 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2013-12-24 10:14 - 2013-10-31 19:40 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\VirtualStore
2013-12-22 18:12 - 2013-10-31 21:27 - 00154336 _____ C:\Users\Hans Desktop PC\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-22 17:42 - 2009-07-14 05:50 - 00507536 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-22 17:38 - 2013-12-22 17:38 - 00001181 _____ C:\Users\Public\Desktop\MAGIX Video easy TERRATEC Edition.lnk
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\ProgramData\MAGIX
2013-12-22 17:38 - 2013-12-22 17:38 - 00000000 ____D C:\Program Files (x86)\MAGIX
2013-12-22 17:37 - 2013-12-22 17:37 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-12-22 17:36 - 2013-12-22 17:34 - 211870088 _____ (MAGIX AG) C:\Users\Hans Desktop PC\Downloads\MAGIX_Video_easy_TERRATEC_Edition.exe
2013-12-22 17:34 - 2013-12-22 17:34 - 00000000 ____D C:\ProgramData\CMUV
2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files\DIFX
2013-12-22 17:33 - 2013-10-31 23:07 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-22 17:32 - 2013-12-22 17:32 - 00000000 ____D C:\Program Files (x86)\TERRATEC
2013-12-22 17:32 - 2013-12-22 17:29 - 03311568 _____ C:\Users\Hans Desktop PC\Downloads\TERRATEC_CINERGY_HTC_Stick_HD_Driver_Setup_7.0.122.90_XP_Vista_7_8.exe
2013-12-22 17:28 - 2013-12-22 17:28 - 00001137 _____ C:\Users\Hans Desktop PC\Desktop\DVBViewer TERRATEC Edition.lnk
2013-12-22 17:28 - 2013-12-22 17:28 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition
2013-12-22 17:27 - 2013-11-01 19:01 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Downloaded Installations
2013-12-22 16:51 - 2013-12-22 16:51 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\TuneUp Software
2013-12-22 16:51 - 2013-12-22 16:50 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-22 16:50 - 2013-12-22 16:50 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-12-22 16:01 - 2013-12-22 15:52 - 00000000 ____D C:\ProgramData\Nero
2013-12-22 15:56 - 2013-12-22 15:10 - 00000000 ____D C:\Program Files (x86)\Nero
2013-12-22 15:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Cursors
2013-12-22 15:54 - 2013-12-22 15:54 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk
2013-12-22 15:54 - 2013-12-22 15:54 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk
2013-12-22 15:53 - 2013-12-22 15:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk
2013-12-22 15:04 - 2013-12-22 15:04 - 00002037 _____ C:\Users\Public\Desktop\LightScribe.lnk
2013-12-15 19:30 - 2013-11-01 19:08 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Samsung
2013-12-15 16:46 - 2013-12-15 16:46 - 00001000 _____ C:\Users\Public\Desktop\WISO Hausverwalter 2014.lnk
2013-12-15 16:34 - 2013-12-15 16:34 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Roaming\Buhl
2013-12-15 12:45 - 2013-12-15 12:45 - 00000986 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk
2013-12-15 12:08 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-12-15 00:13 - 2013-11-03 19:48 - 00000000 ____D C:\Users\Hans Desktop PC\AppData\Local\Google
2013-12-14 17:34 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-11 17:08 - 2013-10-31 20:26 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 15:28 - 2013-11-01 18:59 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 15:28 - 2013-11-01 18:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 15:28 - 2013-11-01 18:59 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-08 17:20 - 2013-10-31 23:34 - 00000000 ____D C:\Users\Hans Desktop PC\Documents\ChessBase
2013-12-08 11:59 - 2013-11-03 19:48 - 00004124 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-08 11:59 - 2013-11-03 19:48 - 00003872 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

Some content of TEMP:
====================
C:\Users\Hans Desktop PC\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-01 13:44

==================== End Of Log ============================
         
--- --- ---

Alt 07.01.2014, 19:01   #13
sunjojo
/// Malwareteam
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



Schritt 1
Wenn du Malwarebytes Anti Malware und ESET nicht mehr behalten möchtest, deinstalliere die Programm bitte über die Systemsteuerung. Ich empfehle dir aber Malwarebytes Anti Malware als zusätzlichen Schutz zu behalten, mit dem du dein System einmal pro Woche scannen kannst (vorher die Datenbank updaten).

Schritt 2
Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Deine Logs zeigen keine schädlichen Einträge mehr, in meinen Augen bist du Clean. Hier sind noch Tipps zur Absicherung deines Systems für die Zukunft:

Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.

Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen .

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
Gruß,

Jonas

Alt 07.01.2014, 20:20   #14
Mixia
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



Alles gemacht.

Vielen Dank!

Alt 07.01.2014, 20:25   #15
sunjojo
/// Malwareteam
 
Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Standard

Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern



Hallo Mixia,

schön, dass wir dir helfen konnten .

Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht, damit erhalte ich keine Benachrichtungen über neue Antworten in diesem Thread. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM.

Jeder Andere bitte hier klicken und einen eigenen Thread erstellen.
__________________
Gruß,

Jonas

Antwort

Themen zu Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern
7-zip, flash player, homepage, inf/autorun.gen, installation, lightning, mobogenie, mobogenie entfernen, msil/injector.ala, msil/injector.awm, msil/injector.bkj, msil/injector.bri, msil/injector.yj, mysearchdial, nation zoom, nation zoom entfernen, nationzoom, nationzoom entfernen, newtab, nextlive, pup.optional.bundleinstaller.a, pup.optional.nationzoom.a, pup.optional.wpmanager.a, samsung kies, sich automatisch, software, synology, win32/injector.amix, win32/injector.autoit.p, win32/spy.agent.nyu, ändern



Ähnliche Themen: Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern


  1. Webseiten öffnen sich mit extremer Verzögerung in allen Browsern
    Log-Analyse und Auswertung - 20.10.2014 (9)
  2. Pop-up Fenster öffnen sich unkontrollierbar in allen Browsern
    Log-Analyse und Auswertung - 25.05.2014 (1)
  3. Werbefenster öffnen sich selbstständig in allen Browsern
    Plagegeister aller Art und deren Bekämpfung - 22.05.2014 (13)
  4. Werbung auf allen browsern, adope flash player hängt sich immer auf
    Plagegeister aller Art und deren Bekämpfung - 30.03.2014 (19)
  5. Nation Zoom erscheint beim Öffnen von Int. Explorer und Firefox, Windows 7
    Plagegeister aller Art und deren Bekämpfung - 04.03.2014 (55)
  6. Nation Zoom - ADWCleaner hängt sich auf
    Plagegeister aller Art und deren Bekämpfung - 04.02.2014 (13)
  7. Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten
    Plagegeister aller Art und deren Bekämpfung - 09.01.2014 (5)
  8. Windows 7: nation zoom nach cc cleaner Installation von dieser Seite: http://www.ccleaner.de/
    Log-Analyse und Auswertung - 05.01.2014 (14)
  9. WINDOWS 7 : Nation Zoom eingefangen
    Log-Analyse und Auswertung - 04.01.2014 (11)
  10. Nation Zoom öffnet sich ungefragt in allen Browsern
    Plagegeister aller Art und deren Bekämpfung - 04.01.2014 (12)
  11. nation zoom lässt sich nicht löschen
    Plagegeister aller Art und deren Bekämpfung - 03.01.2014 (5)
  12. Windows 7 : Nation Zoom und SpyHunter infizieren System.
    Log-Analyse und Auswertung - 03.01.2014 (11)
  13. Windows 7: Nation Zoom
    Log-Analyse und Auswertung - 29.12.2013 (9)
  14. Nation zoom und andere sich plötzlich öffnende Tabs
    Log-Analyse und Auswertung - 25.12.2013 (15)
  15. Windows 7: Nation Zoom läßt sich nicht entfernen
    Log-Analyse und Auswertung - 21.12.2013 (19)
  16. Windows 7 Firefox zeigt immer Nation Zoom als Startseite
    Log-Analyse und Auswertung - 18.12.2013 (12)
  17. Windows 7: Startseite Nation Zoom einfach nicht entfernbar
    Plagegeister aller Art und deren Bekämpfung - 12.12.2013 (11)

Zum Thema Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern - Frohes neues Jahr, Ähnlich wie in diesem Post [ http://www.trojaner-board.de/146908-...-browsern.html ], habe auch ich (bzw mein Vater) folgendes Problem: Nation-zoom (.com) öffnet sich automatisch sowohl beim Öffnen von Chrome, als - Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern...
Archiv
Du betrachtest: Windows 7: 'Nation Zoom' auto-öffnet sich in allen Browsern auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.