|  | 
| 
 | |||||||
| Log-Analyse und Auswertung: versehentlich zip-anhang einer email geöffnet und .exe ausgeführtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. | 
|  | 
|  | 
|  14.02.2014, 03:43 | #1 | 
|  |   versehentlich zip-anhang einer email geöffnet und .exe ausgeführt einen schönen guten tag, leider habe ich aus dummheit einen email-anhang ("clients.045-264.zip") geöffnet und das entpackte .exe ausgeführt. nun bin ich mir leider nicht sicher, ob ich mir etwas eingefangen habe. bislang konnte ich keine ungewohnten symptome feststellen. für einen kurzen blick auf folgendes logfile wäre ich sehr dankbar. Code: 
  ATTFilter Zoek.exe v5.0.0.0 Updated 13-February-2014
Tool run by maddin on 14.02.2014 at  2:32:05,03.
Microsoft Windows 7 Professional  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: D:\Temp\zoek.exe [Scan all users] [Script inserted] 
==== System Restore Info ======================
14.02.2014 02:32:24 Zoek.exe System Restore Point Created Succesfully.
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
C:\Users\maddin\AppData\Local\Software deleted
"C:\Users\maddin\AppData\Roaming\kock" deleted
"C:\Users\maddin\AppData\Roaming\xmldm" deleted
"C:\Users\maddin\AppData\Roaming\FreePDF" deleted
==== Files Recently Created / Modified ======================
====== C:\Windows ====
====== C:\Users\maddin\AppData\Local\Temp ====
2014-02-12 20:44:37	F00F3F47062646F900AA327B1D5CA3A1	166912	----a-w-	C:\Users\maddin\AppData\Local\Temp\CAEC.tmp.exe
====== Java Cache =====
2014-02-10 21:56:08	3699C586D409D9321E7F5723A48BD59A	8924	----a-w-	C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\34d52bc0-177c3d57
2014-02-10 22:02:14	5E1B59D4862D63C597EA1C1742962C95	19166	----a-w-	C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\3a90453-5e4cc1fe
2014-02-10 21:56:09	550011EB0B59C3290CC967BC294A3EC6	16070	----a-w-	C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\44d52fe0-784eaaae
2014-02-10 21:56:08	65C0853659D0B24F7C88EE2E749E31D5	10843	----a-w-	C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\cad9aa1-58e2a035
2014-02-10 22:01:12	ADD2C33D1DA5F76DAD52CE6118A36D59	16417	----a-w-	C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\229dcfa4-37107e06
2014-02-10 21:56:09	890462FBC3F94ED780C54EA7696115F0	409714	----a-w-	C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\42e9fba7-2779916d
2014-02-10 21:56:07	EA550C3048C9DC750DD9101C3A933E5A	241410	----a-w-	C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\3f646bc4-40a1fcaa
2014-02-10 21:56:08	A1C4ABF69B70006EB9CF3455FEACADD6	183196	----a-w-	C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\16b572af-4d8008ca
2014-02-10 21:56:09	F5F7ABB943B52839DBF7FBF0D7227FB5	175421	----a-w-	C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\816c546-3637db8e
====== C:\Windows\SysWOW64 =====
2014-02-13 02:00:41	3D485254E43EF4E4F707346B5731EA9A	454656	----a-w-	C:\Windows\SysWOW64\vbscript.dll
2014-02-13 02:00:22	B8F28AAC003060E3B125D2447CFC19E2	164864	----a-w-	C:\Windows\SysWOW64\msrating.dll
2014-02-13 02:00:22	B5B3334F177CED627C2D7FE38235B6B1	2724864	----a-w-	C:\Windows\SysWOW64\mshtml.tlb
2014-02-13 02:00:22	85AC8EB265EDCAD86D651D45C5E3AB83	440832	----a-w-	C:\Windows\SysWOW64\ieui.dll
2014-02-13 02:00:21	C9D1131E2163CE932DF3EAAF0EEA3673	524288	----a-w-	C:\Windows\SysWOW64\msfeeds.dll
2014-02-13 02:00:21	6A06EB11F1E5BDAA795DAE7838F9FE20	43008	----a-w-	C:\Windows\SysWOW64\jsproxy.dll
2014-02-13 02:00:20	7D6B20C69CC8EECB8F31D4FAF913BBE8	112128	----a-w-	C:\Windows\SysWOW64\ieUnatt.exe
2014-02-13 02:00:20	5DD49C02D059C1E6E47A8FB4A076C9B1	703488	----a-w-	C:\Windows\SysWOW64\ieapfltr.dll
2014-02-13 02:00:20	408805B8083896DC95E6340F4016BEBD	61952	----a-w-	C:\Windows\SysWOW64\iesetup.dll
2014-02-13 02:00:20	260D6B421E5551E8BA75D16B5CA90D9A	51200	----a-w-	C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-13 02:00:20	0F739443669F3A48F1B2325995117BFE	553472	----a-w-	C:\Windows\SysWOW64\jscript9diag.dll
2014-02-13 02:00:20	0E7B7C9F483300F9FF97C6A1E4BC4F57	32768	----a-w-	C:\Windows\SysWOW64\iernonce.dll
2014-02-13 02:00:19	9C89246184979A070B0C6CCF61C68136	1820160	----a-w-	C:\Windows\SysWOW64\wininet.dll
2014-02-13 02:00:19	5D9DC6332A4FC66388B09BBE7CF53750	1156096	----a-w-	C:\Windows\SysWOW64\urlmon.dll
2014-02-13 02:00:19	40E68599FE3A10F816217D3789FCE74E	1964032	----a-w-	C:\Windows\SysWOW64\inetcpl.cpl
2014-02-13 02:00:19	34CBED7698D557DDB43F8732FBC2ACB9	2168320	----a-w-	C:\Windows\SysWOW64\iertutil.dll
2014-02-13 02:00:18	79FA7D8B488F90EDE325963379A6F738	11266048	----a-w-	C:\Windows\SysWOW64\ieframe.dll
2014-02-13 02:00:17	C863E5A2417DF0F2A31ED32C3B2CB23F	17103872	----a-w-	C:\Windows\SysWOW64\mshtml.dll
2014-02-13 02:00:17	99280392987A1A96C756A9F38C4CE396	4244480	----a-w-	C:\Windows\SysWOW64\jscript9.dll
2014-02-12 22:31:30	E4561704CBFA193761743E5AF746C669	1237504	----a-w-	C:\Windows\SysWOW64\msxml3.dll
2014-02-12 22:31:30	17B06F23237FCD731FA2E10ECD6EDFE1	2048	----a-w-	C:\Windows\SysWOW64\msxml3r.dll
2014-02-12 22:30:55	D96106CF60505734B14F6AE80AAA4B07	1987584	----a-w-	C:\Windows\SysWOW64\d3d10warp.dll
2014-02-12 22:30:55	14800BD31701A5047AC3145BB1E698AE	3419136	----a-w-	C:\Windows\SysWOW64\d2d1.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2014-02-13 02:00:41	F67C7D80745379DC4C5332EFFE5AC696	548864	----a-w-	C:\Windows\Sysnative\vbscript.dll
2014-02-13 02:00:22	94C59DD02BC7EA0E421055B9946CA861	2724864	----a-w-	C:\Windows\Sysnative\mshtml.tlb
2014-02-13 02:00:22	1D1D7F52EC84294859642A4309FE648E	195584	----a-w-	C:\Windows\Sysnative\msrating.dll
2014-02-13 02:00:21	FD08F8BA2437A85F500EFFE3FD3158A6	33792	----a-w-	C:\Windows\Sysnative\iernonce.dll
2014-02-13 02:00:21	E77092C38028EB0A5C461B3436E0A6D5	4096	----a-w-	C:\Windows\Sysnative\ieetwcollectorres.dll
2014-02-13 02:00:21	CDE728C8FB1D6E132CED44835FA44C87	627200	----a-w-	C:\Windows\Sysnative\msfeeds.dll
2014-02-13 02:00:21	99ED8FBAFD325550D07A32664D9E3CC8	53760	----a-w-	C:\Windows\Sysnative\jsproxy.dll
2014-02-13 02:00:21	63B5E990896BA81D604032A48CC80A5C	574976	----a-w-	C:\Windows\Sysnative\ieui.dll
2014-02-13 02:00:21	27516B54E116D5EF8B0129B5C829A87C	218624	----a-w-	C:\Windows\Sysnative\ie4uinit.exe
2014-02-13 02:00:20	FCFAEDF0AA1A78A1875FDB798598408B	48640	----a-w-	C:\Windows\Sysnative\ieetwproxystub.dll
2014-02-13 02:00:20	F348B2D0983C91392632B4291C517AA4	817664	----a-w-	C:\Windows\Sysnative\ieapfltr.dll
2014-02-13 02:00:20	E129D34089E70215B65EA611F802FA9A	111616	----a-w-	C:\Windows\Sysnative\ieetwcollector.exe
2014-02-13 02:00:20	D016F5092E4FFC41147E8555A71D2DDE	23170048	----a-w-	C:\Windows\Sysnative\mshtml.dll
2014-02-13 02:00:20	C1E2C16D58D76323800C3EE5E2C5095A	66048	----a-w-	C:\Windows\Sysnative\iesetup.dll
2014-02-13 02:00:20	3906C9640406FC0FC00A324947C74893	708608	----a-w-	C:\Windows\Sysnative\jscript9diag.dll
2014-02-13 02:00:20	338415F2E9A188875B6E43B5269620B0	139264	----a-w-	C:\Windows\Sysnative\ieUnatt.exe
2014-02-13 02:00:19	83296DE8CFFEADA636DCC1AB2E3BF643	2041856	----a-w-	C:\Windows\Sysnative\inetcpl.cpl
2014-02-13 02:00:19	6300AD525D639CECBB3D144B6D7B30F9	2765824	----a-w-	C:\Windows\Sysnative\iertutil.dll
2014-02-13 02:00:19	263B6E451526A90FF8B1CEC759F22956	2334208	----a-w-	C:\Windows\Sysnative\wininet.dll
2014-02-13 02:00:19	22874047B810B5B174C68ACD7C0B6510	1393664	----a-w-	C:\Windows\Sysnative\urlmon.dll
2014-02-13 02:00:18	DB02F4D37E5F7F07A0D0F9FAA68249EE	13051392	----a-w-	C:\Windows\Sysnative\ieframe.dll
2014-02-13 02:00:17	5922EEA922D3AD686342F866CAEE851F	5768704	----a-w-	C:\Windows\Sysnative\jscript9.dll
2014-02-12 22:31:30	CD2C20CC3B385A32701F78C0ACBBE9F3	2048	----a-w-	C:\Windows\Sysnative\msxml3r.dll
2014-02-12 22:31:30	0D298133C359AB8CB9EB4FA178BF3947	1882112	----a-w-	C:\Windows\Sysnative\msxml3.dll
2014-02-12 22:30:55	E8710B5DDA963E6BA198DF5FB209E72A	2565120	----a-w-	C:\Windows\Sysnative\d3d10warp.dll
2014-02-12 22:30:55	C676E5EA388AF7C4C031F56F9B42E362	3928064	----a-w-	C:\Windows\Sysnative\d2d1.dll
====== C:\Windows\Sysnative\drivers =====
2014-01-15 17:51:06	F7FFDF2A1D19A76A87759126B244C816	53248	----a-w-	C:\Windows\Sysnative\drivers\usbehci.sys
2014-01-15 17:51:06	D7322DA647332AB0FA3809555BB04325	325120	----a-w-	C:\Windows\Sysnative\drivers\usbport.sys
2014-01-15 17:51:06	C1A8966E0D09BFB501045105B30D86F2	25600	----a-w-	C:\Windows\Sysnative\drivers\usbohci.sys
2014-01-15 17:51:06	91D3C92A44FC682DD791147604E79152	99840	----a-w-	C:\Windows\Sysnative\drivers\usbccgp.sys
2014-01-15 17:51:06	2E682DCE4319A90E02A327F8A427544A	30720	----a-w-	C:\Windows\Sysnative\drivers\usbuhci.sys
2014-01-15 17:51:06	245FE7FC634D6A993E682E0A9EBA4ABB	343040	----a-w-	C:\Windows\Sysnative\drivers\usbhub.sys
2014-01-15 17:51:06	1A13DCABD19D093B4D3949CE33EF1FA1	7808	----a-w-	C:\Windows\Sysnative\drivers\usbd.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
======= C:\PROGRA~2 =====
2014-02-04 23:21:31	--------	d-----w-	C:\PROGRA~2\Mozilla Thunderbird
======= C: =====
====== C:\Users\maddin\AppData\Roaming ======
====== C:\Users\maddin ======
====== C: exe-files ==
2014-02-13 02:00:21	9E8F9FDD407DDE997965EEFD9E635CCF	469504	----a-w-	C:\Program Files (x86)\Internet Explorer\ieinstal.exe
2014-02-13 02:00:21	27516B54E116D5EF8B0129B5C829A87C	218624	----a-w-	C:\Windows\System32\ie4uinit.exe
2014-02-13 02:00:20	E129D34089E70215B65EA611F802FA9A	111616	----a-w-	C:\Windows\System32\ieetwcollector.exe
2014-02-13 02:00:20	AFAB9B381886ABE3490689B7633A858F	482816	----a-w-	C:\Program Files\Internet Explorer\ieinstal.exe
2014-02-13 02:00:20	7D6B20C69CC8EECB8F31D4FAF913BBE8	112128	----a-w-	C:\Windows\SysWOW64\ieUnatt.exe
2014-02-13 02:00:20	338415F2E9A188875B6E43B5269620B0	139264	----a-w-	C:\Windows\System32\ieUnatt.exe
2014-02-13 02:00:19	C6E1178294BDEAB1CACF50427688DF05	806104	----a-w-	C:\Program Files\Internet Explorer\iexplore.exe
2014-02-13 02:00:19	4263F6C131E513CEA1AE82B5B81A4E1A	808152	----a-w-	C:\Program Files (x86)\Internet Explorer\iexplore.exe
2014-02-12 20:44:37	F00F3F47062646F900AA327B1D5CA3A1	166912	----a-w-	C:\Users\maddin\AppData\Local\Temp\CAEC.tmp.exe
=== C: other files ==
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-1421330230-1166473182-2705663632-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"CAEC.tmp"="C:\Users\maddin\AppData\Local\Temp\CAEC.tmp.exe"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"IMSS"="C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
"SwitchBoard"="C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
"AdobeCS5ServiceManager"="C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe -launchedbylogin"
"FreePDF Assistant"="C:\Program Files (x86)\FreePDF_XP\fpassist.exe"
"CorelDRAW Graphics Suite 11b"="C:\Program Files (x86)\Corel\Corel Graphics 11\Register\registration.exe /title=CorelDRAW Graphics Suite 11 /date=112411 serial=DR11WBL-2155594-HXE"
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CAEC.tmp"="C:\Users\maddin\AppData\Local\Temp\CAEC.tmp.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\Windows\\SysWOW64\\nvinit.dll"
==== Startup Registry Enabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\Windows\system32\igfxtray.exe"
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe"
"Persistence"="C:\Windows\system32\igfxpers.exe"
"IntelPROSet"="C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe /tf Intel PROSet/Wireless"
"DBRMTray"="C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe"
"NVHotkey"="rundll32.exe C:\Windows\system32\nvHotkey.dll,Start"
"SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DBRMTray"="C:\Dell\DBRM\Reminder\TrayApp.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\Windows\\system32\\nvinitx.dll"
==== Startup Registry Disabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AdobeAAMUpdater-1.0]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AdobeAAMUpdater-1.0"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\OOBE\\PDApp\\UWA\\UpdaterStartupUtility.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Apoint]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Apoint"
"hkey"="HKLM"
"command"="C:\\Program Files\\DellTPad\\Apoint.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CanonMyPrinter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CanonMyPrinter"
"hkey"="HKLM"
"command"="C:\\Program Files\\Canon\\MyPrinter\\BJMyPrt.exe /logon"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CnwiDeviceAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CnwiDeviceAgent"
"hkey"="HKLM"
"command"="C:\\Program Files\\Canon\\imagePROGRAFStatusMonitor\\cnwida.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Dell Webcam Central]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Dell Webcam Central"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Dell Webcam\\Dell Webcam Central\\WebcamDell2.exe\" /mode2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Desktop Disc Tool]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Desktop Disc Tool"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Roxio\\OEM\\Roxio Burn\\RoxioBurnLauncher.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\FreeFallProtection]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="FreeFallProtection"
"hkey"="HKLM"
"command"="C:\\Program Files (x86)\\STMicroelectronics\\AccelerometerP11\\FF_Protection.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PDVD9LanguageShortcut]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVD9LanguageShortcut"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\CyberLink\\PowerDVD9\\Language\\Language.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RemoteControl9]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RemoteControl9"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\CyberLink\\PowerDVD9\\PDVD9Serv.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RoxWatchTray]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RoxWatchTray"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Common Files\\Roxio Shared\\OEM\\12.0\\SharedCOM\\RoxWatchTray12OEM.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CineForm Status.lnk]
"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\CineForm Status.lnk"
"backup"="C:\\Windows\\pss\\CineForm Status.lnk.CommonStartup"
"backupExtension"=".CommonStartup"
"command"="C:\\PROGRA~2\\CineForm\\Tools\\GOPROC~1.EXE "
"item"="CineForm Status"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GV LicenseManager.lnk]
"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\GV LicenseManager.lnk"
"backup"="C:\\Windows\\pss\\GV LicenseManager.lnk.CommonStartup"
"backupExtension"=".CommonStartup"
"command"="C:\\PROGRA~2\\GRASSV~1\\GVLICE~1\\APPMAI~1.EXE "
"item"="GV LicenseManager"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^imagePROGRAF Status Monitor.lnk]
"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\imagePROGRAF Status Monitor.lnk"
"backup"="C:\\Windows\\pss\\imagePROGRAF Status Monitor.lnk.CommonStartup"
"backupExtension"=".CommonStartup"
"command"="C:\\PROGRA~1\\Canon\\IMAGEP~1\\cnwism.exe /w"
"item"="imagePROGRAF Status Monitor"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AESTFilters]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Canon imagePROGRAF Status Monitor]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Credential Vault Host Control Service]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Credential Vault Host Storage]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\RoxMediaDB12OEM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\RoxWatch12]
==== Startup Folders ======================
2012-03-22 17:18:15	834	----a-w-	C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
2012-03-22 17:18:15	2026	----a-w-	C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell System Manager.lnk
2012-03-22 17:18:15	1353	----a-w-	C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Spyder3Utility.lnk
==== Other Scheduled Tasks ======================
"C:\Windows\SysNative\tasks\AdobeAAMUpdater-1.0-ms2p5-maddin" [C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe]
"C:\Windows\SysNative\tasks\{0C4D7B98-6EBB-4731-ADAA-C91447093380}" [D:\Temp\Delpart.exe]
"C:\Windows\SysNative\tasks\{2FE67FED-22CF-4EC7-8D6D-A466E4A80B3E}" [C:\Program Files (x86)\Corel\Corel Graphics 11\Programs\CorelDrw.exe]
"C:\Windows\SysNative\tasks\{D3D457AC-3188-4F74-BF49-9367FBD5CCA1}" [D:\Temp\Delpart.exe]
"C:\Windows\SysNative\tasks\{DC334E4C-3EA2-4AF3-88BC-94B721D8EC8A}" [C:\Program Files (x86)\Corel\Corel Graphics 11\Programs\CorelDrw.exe]
"C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]
==== Firefox Extensions ======================
ProfilePath: C:\Users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default
- Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
- Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
- Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
==== Firefox Plugins ======================
Profilepath: C:\Users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default
4BF70B35B943BD73BD6E13EB7C1BA4B3	- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll -	Shockwave Flash
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://g.uk.msn.com/USREL/8"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{49606DC7-976D-4030-A74E-9FB5C842FA68}"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://g.uk.msn.com/USREL/8"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"
{49606DC7-976D-4030-A74E-9FB5C842FA68} Unknown  Url="Not_Found"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1421330230-1166473182-2705663632-1001\Software\Microsoft\Internet Explorer\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\maddin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\maddin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\maddin\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\maddin\AppData\Local\Mozilla\Firefox\Profiles\xcc0q5jk.default\Cache emptied successfully
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=2 folders=5 345 bytes)
==== Empty Temp Folders ======================
C:\Users\Administrator\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Users\maddin\AppData\Local\Temp  will be emptied at reboot
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\maddin\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on 14.02.2014 at  2:41:20,27 ======================
         sorry, mein erster beitrag, ich bitte um nachsicht, falls ich was falsch gemacht habe. danke und gruß martin | 
|  14.02.2014, 06:26 | #2 | 
| /// the machine /// TB-Ausbilder         |   versehentlich zip-anhang einer email geöffnet und .exe ausgeführt hi,__________________ Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop:  FRST 32-Bit | FRST   64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen) 
 
				__________________ | 
|  14.02.2014, 08:43 | #3 | 
|  |   versehentlich zip-anhang einer email geöffnet und .exe ausgeführt guten morgen,__________________ danke für die schnelle antwort. hier die beiden logfiles: FRST Logfile: Code: 
  ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-02-2014 01
Ran by maddin (administrator) on MS2P5 on 14-02-2014 08:37:54
Running from D:\Temp
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dell Inc.) c:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe
(Intel Corporation) C:\Windows\system32\IProsetMonitor.exe
(CANON INC.) C:\Windows\system32\cnwiols6.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(O2Micro International) C:\Windows\system32\DRIVERS\o2flash.exe
() c:\Windows\SysWOW64\srvany.exe
(O2Micro.) c:\Windows\sysWOW64\SDIOAssist.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Dell Computer Corporation) C:\dell\DBRM\Reminder\DbrmTrayicon.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dell Inc.) C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe
() C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-07] (IDT, Inc.)
HKLM\...\Run: [IntelPROSet] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1934608 2010-12-23] (Intel(R) Corporation)
HKLM\...\Run: [DBRMTray] - C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation)
HKLM\...\Run: [NVHotkey] - C:\Windows\system32\nvHotkey.dll [335976 2011-08-03] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-01-17] (Intel Corporation)
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM-x32\...\Run: [CorelDRAW Graphics Suite 11b] - C:\Program Files (x86)\Corel\Corel Graphics 11\Register\registration.exe /title="CorelDRAW Graphics Suite 11" /date=112411 serial=DR11WBL-2155594-HXE
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\RunOnce: [DBRMTray] - C:\Dell\DBRM\Reminder\TrayApp.exe [7168 2010-02-05] (Microsoft)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\Run: [AdobeBridge] - [X]
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\Run: [CAEC.tmp] - C:\Users\maddin\AppData\Local\Temp\CAEC.tmp.exe <===== ATTENTION
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: G - G:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {1d21dd65-4547-11e3-857e-247703030988} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {1d21dd68-4547-11e3-857e-247703030988} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {22e3c9fb-e1ec-11e0-aa0c-247703030988} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {22e3c9fe-e1ec-11e0-aa0c-247703030988} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {2c49e9a9-d9dd-11e0-ab33-d067e535e73a} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {30e281d1-e614-11e0-b39d-806e6f6e6963} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {30e281fe-e614-11e0-b39d-247703030988} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {5149e011-30fa-11e3-bcfd-247703030988} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {5543e75e-e158-11e0-9a49-247703030988} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {5543e76e-e158-11e0-9a49-247703030988} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {6385fb0d-e0a7-11e0-9a28-247703030988} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {6385fb0f-e0a7-11e0-9a28-247703030988} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {6385fb14-e0a7-11e0-9a28-247703030988} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {7d345f3a-d399-11e0-ab52-d067e535e73a} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {7d345f3e-d399-11e0-ab52-d067e535e73a} - G:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {a44b1a51-dfa8-11e0-99bd-806e6f6e6963} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {b639d855-6982-11e3-849e-247703030988} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {b639d85a-6982-11e3-849e-247703030988} - G:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {c6193b4e-d657-11e0-ab3f-247703030988} - F:\AutoRun.exe
HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {f85593fd-3313-11e3-bc0a-247703030988} - F:\AutoRun.exe
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [240232 2011-08-03] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201320 2011-08-03] (NVIDIA Corporation)
Lsa: [Authentication Packages] msv1_0 wvauth
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/USREL/8
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USREL/8
SearchScopes: HKLM - DefaultScope {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = 
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-06-30]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-09-02]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-22]
==================== Services (Whitelisted) =================
S4 Canon imagePROGRAF Status Monitor; C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe [713488 2009-10-09] (CANON INC)
R2 iPFDeviceAgentService; C:\Windows\system32\cnwiols6.exe [210944 2008-12-08] (CANON INC.)
R2 O2SDIOAssist; c:\Windows\SysWOW64\srvany.exe [8192 2003-04-19] ()
S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1629696 2010-07-13] ()
R2 ZcfgSvc7; C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe [992256 2010-12-23] (Intel(R) Corporation)
==================== Drivers (Whitelisted) ====================
R1 cdrblock; C:\Windows\System32\DRIVERS\cdrblock.sys [37704 2012-06-29] (Grass Valley K.K.)
S3 Spyder3; C:\Windows\System32\DRIVERS\Spyder3.sys [15360 2008-09-08] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-14 08:37 - 2014-02-14 08:37 - 00000000 ____D () C:\FRST
2014-02-14 03:10 - 2014-02-14 03:11 - 00000000 ____D () C:\AdwCleaner
2014-02-14 02:40 - 2014-02-14 02:32 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-14 02:32 - 2014-02-14 02:41 - 00023557 _____ () C:\zoek-results.log
2014-02-14 02:30 - 2014-02-14 03:01 - 00000000 ____D () C:\zoek_backup
2014-02-13 03:00 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-13 03:00 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-13 03:00 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-13 03:00 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-13 03:00 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-13 03:00 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-13 03:00 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-13 03:00 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-13 03:00 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-13 03:00 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-13 03:00 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-13 03:00 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-13 03:00 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-13 03:00 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-13 03:00 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-13 03:00 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-13 03:00 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-13 03:00 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-13 03:00 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-13 03:00 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-13 03:00 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-13 03:00 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-13 03:00 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-13 03:00 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-13 03:00 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-13 03:00 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-13 03:00 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-13 03:00 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-13 03:00 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-13 03:00 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-13 03:00 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-13 03:00 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-13 03:00 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-13 03:00 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-13 03:00 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-13 03:00 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-13 03:00 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-13 03:00 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-13 03:00 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-13 03:00 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-13 03:00 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-12 23:31 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-12 23:31 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-12 23:31 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-12 23:31 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-12 23:30 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-12 23:30 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-12 23:30 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-12 23:30 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-11 18:02 - 2014-02-11 18:02 - 00000146 _____ () C:\Users\maddin\Desktop\Dell Touchpad - Verknüpfung.lnk
2014-02-05 00:21 - 2014-02-05 08:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-01-26 09:11 - 2014-01-26 09:11 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-15 18:51 - 2013-11-27 02:42 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 18:51 - 2013-11-27 02:42 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 18:51 - 2013-11-27 02:42 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 18:51 - 2013-11-27 02:42 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 18:51 - 2013-11-27 02:42 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 18:51 - 2013-11-27 02:42 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 18:51 - 2013-11-27 02:42 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 18:50 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
==================== One Month Modified Files and Folders =======
2014-02-14 08:37 - 2014-02-14 08:37 - 00000000 ____D () C:\FRST
2014-02-14 08:37 - 2010-11-21 07:50 - 00697082 _____ () C:\Windows\system32\perfh007.dat
2014-02-14 08:37 - 2010-11-21 07:50 - 00148346 _____ () C:\Windows\system32\perfc007.dat
2014-02-14 08:37 - 2009-07-14 06:13 - 01613340 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-14 08:36 - 2011-08-24 17:32 - 01747097 _____ () C:\Windows\WindowsUpdate.log
2014-02-14 08:33 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-14 08:33 - 2009-07-14 05:51 - 00232039 _____ () C:\Windows\setupact.log
2014-02-14 03:19 - 2009-07-14 05:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-14 03:19 - 2009-07-14 05:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-14 03:11 - 2014-02-14 03:10 - 00000000 ____D () C:\AdwCleaner
2014-02-14 03:01 - 2014-02-14 02:30 - 00000000 ____D () C:\zoek_backup
2014-02-14 02:41 - 2014-02-14 02:32 - 00023557 _____ () C:\zoek-results.log
2014-02-14 02:41 - 2010-11-21 04:47 - 00028706 _____ () C:\Windows\PFRO.log
2014-02-14 02:32 - 2014-02-14 02:40 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-13 03:04 - 2011-02-11 18:45 - 01591234 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-11 18:02 - 2014-02-11 18:02 - 00000146 _____ () C:\Users\maddin\Desktop\Dell Touchpad - Verknüpfung.lnk
2014-02-10 23:02 - 2013-03-22 14:55 - 00000072 _____ () C:\Users\Public\LMDebug.log
2014-02-06 13:16 - 2014-02-13 03:00 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 12:30 - 2014-02-13 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 12:30 - 2014-02-13 03:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 12:12 - 2014-02-13 03:00 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 12:07 - 2014-02-13 03:00 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 12:06 - 2014-02-13 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 11:57 - 2014-02-13 03:00 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 11:56 - 2014-02-13 03:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 11:52 - 2014-02-13 03:00 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 11:49 - 2014-02-13 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 11:48 - 2014-02-13 03:00 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 11:48 - 2014-02-13 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 11:38 - 2014-02-13 03:00 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-06 11:32 - 2014-02-13 03:00 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 11:20 - 2014-02-13 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-06 11:17 - 2014-02-13 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 11:11 - 2014-02-13 03:00 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 11:01 - 2014-02-13 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-06 11:00 - 2014-02-13 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-13 03:00 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-06 10:57 - 2014-02-13 03:00 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:52 - 2014-02-13 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-06 10:52 - 2014-02-13 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-06 10:50 - 2014-02-13 03:00 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:49 - 2014-02-13 03:00 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-06 10:47 - 2014-02-13 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-06 10:46 - 2014-02-13 03:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-06 10:25 - 2014-02-13 03:00 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-06 10:25 - 2014-02-13 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-06 10:24 - 2014-02-13 03:00 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 10:22 - 2014-02-13 03:00 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 10:13 - 2014-02-13 03:00 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-06 10:09 - 2014-02-13 03:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-06 10:03 - 2014-02-13 03:00 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-06 09:55 - 2014-02-13 03:00 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:41 - 2014-02-13 03:00 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-06 09:40 - 2014-02-13 03:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-06 09:36 - 2014-02-13 03:00 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-06 09:34 - 2014-02-13 03:00 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-05 10:26 - 2011-09-11 14:19 - 00000000 ____D () C:\Users\maddin\AppData\Local\FreePDF_XP
2014-02-05 09:30 - 2012-10-15 14:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-05 08:11 - 2014-02-05 00:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-02-01 23:46 - 2011-08-31 01:16 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\IrfanView
2014-01-31 23:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-01-28 00:21 - 2011-11-20 00:11 - 00012288 _____ () C:\Users\maddin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-26 09:17 - 2013-10-21 22:11 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-26 09:11 - 2014-01-26 09:11 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-26 09:11 - 2013-06-25 17:19 - 00000000 ____D () C:\Program Files (x86)\Java
2014-01-16 08:33 - 2009-07-14 05:45 - 05131376 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-01-16 03:01 - 2013-08-14 06:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-16 03:00 - 2011-09-04 13:42 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\maddin\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-09 11:55
==================== End Of Log ============================
         Code: 
  ATTFilter  Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-02-2014 01
Ran by maddin at 2014-02-14 08:38:06
Running from D:\Temp
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov)
AccelerometerP11 (x32 Version: 2.00.10.22 - STMicroelectronics)
Adobe AIR (x32 Version: 1.5.3.9120 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 1.5.3.9120 - Adobe Systems Inc.) Hidden
Adobe Community Help (x32 Version: 3.0.0 - Adobe Systems Incorporated) Hidden
Adobe Community Help (x32 Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Flash Player 10 ActiveX (x32 Version: 10.3.181.23 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117 - Adobe Systems Incorporated)
Adobe Media Player (x32 Version: 1.8 - Adobe Systems Incorporated)
Adobe Media Player (x32 Version: 1.8 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CS5 (x32 Version: 12.0 - Adobe Systems Incorporated)
BioAPI Framework (Version: 1.0.2 - Dell Inc.) Hidden
Canon Inkjet Printer Driver Add-On Module V2.00 (Version:  - )
Canon My Printer (x32 Version:  - )
Canon RAW Codec (x32 Version: 1.8.0.68 - Canon Inc.)
Canon Utilities EOS Utility (x32 Version: 2.11.2.0 - Canon Inc.)
Canon Utilities Picture Style Editor (x32 Version: 1.10.1.0 - Canon Inc.)
CanoScan Toolbox Ver4.9 (x32 Version:  - )
Color Efex Pro 3.0 Complete (x32 Version: 3.1.1.0 - Nik Software, Inc.)
Color Efex Pro 4 (x32 Version: 4.0.0.2 - Nik Software, Inc.)
CorelDRAW Home & Student Suite X6 - BR (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Capture (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Common (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Connect (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Custom Data (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - CZ (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - DE (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Draw (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - EN (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - ES (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Extra Content (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Filters (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - FontNav (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - FR (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - IPM (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - IT (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - NL (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - PHOTO-PAINT (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - PL (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Redist (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - RU (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Setup Files (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - VideoBrowser (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Writing Tools (x32 Version: 16.1 -  Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 (x32 Version: 16.1.0.843 - Corel Corporation)
Custom (Version: 12.34.56.789 - Wave Systems Corp.) Hidden
CyberLink PowerDVD 9.5 (x32 Version: 9.5.1.3225 - CyberLink Corp.)
CyberLink PowerDVD 9.5 (x32 Version: 9.5.1.3225 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Backup and Recovery Manager (Version: 1.3.1 - Dell Inc.)
Dell ControlVault Host Components Installer 64 bit (Version: 2.0.20.159 - Broadcom Corporation) Hidden
Dell Data Protection | Access (Version: 01.01.00.085 - Wave Systems Corp) Hidden
Dell Data Protection | Access (x32 Version: 2.0.00000.085 - Dell Inc.)
Dell Data Protection | Access | Drivers (x32 Version: 1.00.011 - Dell Inc.)
Dell Data Protection | Access | Middleware (x32 Version: 1.00.005 - Dell Inc.)
Dell Edoc Viewer (Version: 1.0.0 - Dell Inc)
Dell System Manager (Version: 1.6.00000 - Dell Inc.)
Dell Touchpad (Version: 7.1208.101.118 - ALPS ELECTRIC CO., LTD.)
Dell Webcam Central (x32 Version: 1.40.28 - Creative Technology Ltd)
DellAccess (Version: 01.01.00.053 - Wave Systems Corp.) Hidden
Dfine 2.0 (x32 Version: 2.1.0.7 - Nik Software, Inc.)
DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
EDIUS (x32 Version: 6.51 - Grass Valley K.K.)
EDIUS Codec Option 6.51 (x32 Version: 6.51 - Grass Valley K.K.)
EDIUS DVD Menu Style 1.00 (x32 Version: 1.00 - Grass Valley K.K.)
EMBASSY Security Center (Version: 04.03.00.067 - Wave Systems Corp.) Hidden
FreePDF (Remove only) (x32 Version:  - )
Gemalto (Version: 01.64.01.0010 - Wave Systems Corp) Hidden
GoPro CineForm Studio 1.2.1 (x32 Version: 1.2.1 - CineForm, Inc & GoPro, Inc.)
GPL Ghostscript (Version: 9.04 - Artifex Software Inc.)
GV LicenseManager 1.01 (x32 Version: 1.01 - Grass Valley K.K.)
HDR Efex Pro (x32 Version: 1.2.0.0 - Nik Software, Inc.)
HDR Efex Pro 2 (x32 Version: 2.0.0.0 - Nik Software, Inc.)
Helicon Focus 5.2.9 (x32 Version:  - Helicon Soft Ltd.)
imagePROGRAF Status Monitor (x32 Version: 4.30 - Canon)
Intel PROSet Wireless (Version:  - ) Hidden
Intel(R) Control Center (x32 Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Identity Protection Technology 1.1.2.0 (x32 Version: 1.1.2.0 - Intel Corporation)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Network Connections 15.7.176.1 (Version: 15.7.176.1 - Intel)
Intel(R) Network Connections 15.7.176.1 (Version: 15.7.176.1 - Intel) Hidden
Intel(R) Processor Graphics (x32 Version: 8.15.10.2266 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi-Software (Version: 14.00.20110 - Intel Corporation)
Intel(R) Rapid Storage Technology (x32 Version: 10.1.0.1008 - Intel Corporation)
iPF6300 Media Configuration Tool (x32 Version: 4.02.02 - Canon)
IrfanView (remove only) (x32 Version: 4.28 - Irfan Skiljan)
Java 7 Update 51 (x32 Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 24 (64-bit) (Version: 6.0.240 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Business 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (x32 Version: 4.0.50401.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden
Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Mobile Partner (x32 Version: 11.300.05.03.40 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 10.0.2 (x86 de) (x32 Version: 10.0.2 - Mozilla)
Mozilla Maintenance Service (x32 Version: 24.3.0 - Mozilla)
Mozilla Thunderbird 24.3.0 (x86 de) (x32 Version: 24.3.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation)
No23 Recorder (x32 Version: 2.1.0.3 - No23)
No23 Recorder (x32 Version: 2.1.0.3 - No23) Hidden
NTRU TCG Software Stack (Version: 2.1.34 - Security Innovation) Hidden
NVIDIA 3D Vision Controller Driver (x32 Version: 280.19 - NVIDIA Corporation) Hidden
NVIDIA 3D Vision Controller-Treiber 285.62 (Version: 285.62 - NVIDIA Corporation)
NVIDIA Grafiktreiber 280.26 (Version: 280.26 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.2.24.0 (Version: 1.2.24.0 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.46.235 - NVIDIA Corporation) Hidden
NVIDIA nView 136.02 (Version: 136.02 - NVIDIA Corporation)
NVIDIA nView Desktop Manager (Version: 6.14.10.13594 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.11.0621 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.11.0621 (Version: 9.11.0621 - NVIDIA Corporation)
NVIDIA Systemsteuerung 280.26 (Version: 280.26 - NVIDIA Corporation) Hidden
O2Micro Flash Memory Card Windows Driver (x32 Version: 3.0.07.23 - O2Micro International LTD.)
O2Micro Flash Memory Card Windows Driver (x32 Version: 3.0.07.23 - O2Micro International LTD.) Hidden
PC-CCID (Version: 2.0.0 - Gemalto) Hidden
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
PDF-XChange Viewer (Version: 2.5.197.0 - Tracker Software Products Ltd.)
PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden
Preboot Manager (Version: 03.03.00.049 - Wave Systems Corp.) Hidden
Private Information Manager (Version: 07.01.00.007 - Wave Systems Corp.) Hidden
proDAD Mercalli 2.0 (x32 Version: 2.0.105.1 - proDAD GmbH)
PTGui Pro 9.1.3 (x32 Version:  - New House Internet Services B.V.)
QuickTime Alternative 1.81 (x32 Version: 1.81 - )
RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
RedMon - Redirection Port Monitor (Version:  - )
Roxio Activation Module (x32 Version: 1.0 - Roxio) Hidden
Roxio BackOnTrack (x32 Version: 1.3.3 - Roxio) Hidden
Roxio Burn (x32 Version: 1.8 - Roxio) Hidden
Roxio Creator Starter (x32 Version: 1.0.439 - Roxio) Hidden
Roxio Creator Starter (x32 Version: 12.1.77.0 - Roxio)
Roxio Creator Starter (x32 Version: 5.0.0 - Roxio) Hidden
Roxio Express Labeler 3 (x32 Version: 3.2.2 - Roxio) Hidden
Roxio File Backup (Version: 1.3.2 - Roxio) Hidden
Samsung ML-371x Series (x32 Version: 1.27 (16.01.2013) - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (x32 Version: 1.01.00.04 - Samsung Electronics Co., Ltd.)
Sharpener Pro 3.0 (x32 Version: 3.0.0.5 - Nik Software, Inc.)
Silver Efex Pro 2 (x32 Version: 2.0.0.0 - Nik Software, Inc.)
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden
SPBA 5.9 (Version: 5.9.4.6686 - UPEK Inc.) Hidden
Spyder3Elite (x32 Version:  - )
Spyder3Studio SR (x32 Version:  - )
Trusted Drive Manager (Version: 4.0.0.512 - Wave Systems Corp.) Hidden
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1 - Microsoft Corporation)
Upek Touchchip Fingerprint Reader (Version: 1.2.004 - Dell Inc.) Hidden
Viveza 2 (x32 Version: 2.0.0.4 - Nik Software, Inc.)
Wave Infrastructure Installer (Version: 07.66.40.0008 - Wave Systems Corp) Hidden
Wave Support Software Installer (Version: 05.13.00.014 - Wave Systems Corp) Hidden
WIDCOMM Bluetooth Software (Version: 6.3.0.7900 - Broadcom Corporation)
Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices  (03/07/2012 ) (Version: 03/07/2012  - GoPro)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows-Treiberpaket - Dell Inc. PBADRV System  (09/11/2009 1.0.1.6) (Version: 09/11/2009 1.0.1.6 - Dell Inc.)
Xvid Video Codec (x32 Version: 1.3.2 - Xvid Team)
==================== Restore Points  =========================
14-01-2014 16:15:30 Windows Update
16-01-2014 02:00:10 Windows Update
24-01-2014 08:53:37 Geplanter Prüfpunkt
25-01-2014 00:07:16 Windows Update
26-01-2014 08:10:55 Installed Java 7 Update 51
28-01-2014 17:23:36 Windows Update
01-02-2014 09:22:25 Windows Update
07-02-2014 20:49:41 Windows Update
11-02-2014 07:30:39 Windows Update
13-02-2014 02:00:11 Windows Update
14-02-2014 01:32:20 zoek.exe restore point
==================== Hosts content: ==========================
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {323FA560-8206-4AE6-8ADD-7D835D50C4B9} - System32\Tasks\{0C4D7B98-6EBB-4731-ADAA-C91447093380} => D:\Temp\Delpart.exe
Task: {B3EEABE8-B3B6-4649-B2B9-5C4E76514513} - System32\Tasks\{DC334E4C-3EA2-4AF3-88BC-94B721D8EC8A} => C:\Program Files (x86)\Corel\Corel Graphics 11\Programs\CorelDrw.exe
Task: {B8F007C2-DE44-4FA8-A7FB-ECFC52D3FED0} - System32\Tasks\AdobeAAMUpdater-1.0-ms2p5-maddin => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated)
Task: {DADBFA70-8776-487C-9ED3-31B4521C6AB8} - System32\Tasks\{D3D457AC-3188-4F74-BF49-9367FBD5CCA1} => D:\Temp\Delpart.exe
Task: {DCE1F4B1-68A1-4173-8549-4811D2E7AC61} - System32\Tasks\{2FE67FED-22CF-4EC7-8D6D-A466E4A80B3E} => C:\Program Files (x86)\Corel\Corel Graphics 11\Programs\CorelDrw.exe
==================== Loaded Modules (whitelisted) =============
2010-12-23 19:33 - 2010-12-23 19:33 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-02-08 07:41 - 2011-02-08 07:41 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2008-12-05 10:05 - 2008-12-11 17:40 - 08119870 _____ () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
2008-12-11 17:43 - 2008-12-11 17:29 - 00131072 _____ () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\CSensor.dll
2008-12-11 17:43 - 2008-12-11 17:28 - 00331776 _____ () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\CGamma.dll
2014-02-05 00:21 - 2014-02-05 00:21 - 03019376 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2014-02-05 00:21 - 2014-02-05 00:21 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2014-02-05 00:21 - 2014-02-05 00:21 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2011-09-01 19:13 - 2012-02-23 10:44 - 01911768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-10-21 22:14 - 2013-10-21 22:14 - 16233864 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\ProgramData\Temp:054203E4
AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Disabled items from MSCONFIG ==============
MSCONFIG\Services: AESTFilters => 2
MSCONFIG\Services: Canon imagePROGRAF Status Monitor => 2
MSCONFIG\Services: Credential Vault Host Control Service => 2
MSCONFIG\Services: Credential Vault Host Storage => 2
MSCONFIG\Services: RoxMediaDB12OEM => 3
MSCONFIG\Services: RoxWatch12 => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CineForm Status.lnk => C:\Windows\pss\CineForm Status.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GV LicenseManager.lnk => C:\Windows\pss\GV LicenseManager.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^imagePROGRAF Status Monitor.lnk => C:\Windows\pss\imagePROGRAF Status Monitor.lnk.CommonStartup
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: Apoint => C:\Program Files\DellTPad\Apoint.exe
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CnwiDeviceAgent => C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwida.exe
MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
MSCONFIG\startupreg: FreeFallProtection => C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
MSCONFIG\startupreg: PDVD9LanguageShortcut => "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
MSCONFIG\startupreg: RemoteControl9 => "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
MSCONFIG\startupreg: RoxWatchTray => "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (02/14/2014 08:33:25 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/14/2014 03:12:40 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/14/2014 02:41:12 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/13/2014 05:48:03 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/13/2014 03:11:33 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/13/2014 00:30:51 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.
Error: (02/12/2014 10:08:34 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.
Error: (02/12/2014 09:36:19 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/12/2014 08:11:05 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/11/2014 04:24:10 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (02/14/2014 08:34:25 AM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (02/14/2014 08:33:24 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "NTRU TSS v1.2.1.34 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%0
Error: (02/14/2014 03:13:40 AM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (02/14/2014 03:12:39 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "NTRU TSS v1.2.1.34 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%0
Error: (02/14/2014 02:42:12 AM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (02/14/2014 02:41:11 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "NTRU TSS v1.2.1.34 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%0
Error: (02/14/2014 02:37:50 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (02/14/2014 02:37:49 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (02/14/2014 02:37:49 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (02/14/2014 02:37:49 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Microsoft Office Sessions:
=========================
Error: (02/14/2014 08:33:25 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/14/2014 03:12:40 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/14/2014 02:41:12 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/13/2014 05:48:03 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/13/2014 03:11:33 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/13/2014 00:30:51 AM) (Source: SideBySide)(User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3
Error: (02/12/2014 10:08:34 PM) (Source: SideBySide)(User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3
Error: (02/12/2014 09:36:19 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/12/2014 08:11:05 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/11/2014 04:24:10 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info =========================== 
Percentage of memory in use: 22%
Total physical RAM: 8148.9 MB
Available physical RAM: 6278.09 MB
Total Pagefile: 16295.98 MB
Available Pagefile: 14252.97 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:225.67 GB) (Free:156.96 GB) NTFS
Drive d: (Daten) (Fixed) (Total:238.47 GB) (Free:121.92 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 238 GB) (Disk ID: D1E3F7F7)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=13 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=226 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: D1E3F7C8)
Partition 1: (Not Active) - (Size=238 GB) - (Type=07 NTFS)
==================== End Of Log ============================
         was mir aufgefallen ist: vom zeitzunkt meiner unüberlegten aktion her ist das "CAEC.tmp.exe" verdächtig ! vielleicht hilft die information. danke und gruß martin Geändert von DeppoDepp (14.02.2014 um 09:05 Uhr) | 
|  15.02.2014, 09:32 | #4 | 
| /// the machine /// TB-Ausbilder         |   versehentlich zip-anhang einer email geöffnet und .exe ausgeführt hi, Scan mit Combofix 
 
				__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! | 
|  15.02.2014, 11:25 | #5 | 
|  |   versehentlich zip-anhang einer email geöffnet und .exe ausgeführt hallo und danke für die antwort, hier das logfile. es gab keine fehlermeldungen. Combofix Logfile: Code: 
  ATTFilter ComboFix 14-02-14.01 - maddin 15.02.2014  11:10:37.1.8 - x64
Microsoft Windows 7 Professional   6.1.7601.1.1252.49.1031.18.8149.6090 [GMT 1:00]
ausgeführt von:: c:\users\maddin\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\windows\SysWow64\cseDVH.dll
.
.
(((((((((((((((((((((((   Dateien erstellt von 2014-01-15 bis 2014-02-15  ))))))))))))))))))))))))))))))
.
.
2014-02-14 14:35 . 2013-12-04 03:28	10315576	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{D73B5779-DAB3-4075-B25F-373F10A43BEE}\mpengine.dll
2014-02-14 07:37 . 2014-02-14 07:38	--------	d-----w-	C:\FRST
2014-02-14 02:10 . 2014-02-14 02:11	--------	d-----w-	C:\AdwCleaner
2014-02-14 01:40 . 2014-02-15 10:13	--------	d-----w-	c:\users\maddin\AppData\Local\Temp
2014-02-14 01:40 . 2014-02-14 01:32	24064	----a-w-	c:\windows\zoek-delete.exe
2014-02-14 01:30 . 2014-02-14 02:01	--------	d-----w-	C:\zoek_backup
2014-02-12 22:31 . 2013-12-06 02:30	2048	----a-w-	c:\windows\system32\msxml3r.dll
2014-02-12 22:31 . 2013-12-06 02:30	1882112	----a-w-	c:\windows\system32\msxml3.dll
2014-02-12 22:31 . 2013-12-06 02:02	2048	----a-w-	c:\windows\SysWow64\msxml3r.dll
2014-02-12 22:31 . 2013-12-06 02:02	1237504	----a-w-	c:\windows\SysWow64\msxml3.dll
2014-02-12 22:30 . 2013-12-24 23:09	1987584	----a-w-	c:\windows\SysWow64\d3d10warp.dll
2014-02-12 22:30 . 2013-12-24 22:48	2565120	----a-w-	c:\windows\system32\d3d10warp.dll
2014-02-12 22:30 . 2013-11-26 08:16	3419136	----a-w-	c:\windows\SysWow64\d2d1.dll
2014-02-12 22:30 . 2013-11-22 22:48	3928064	----a-w-	c:\windows\system32\d2d1.dll
2014-02-04 23:21 . 2014-02-05 07:11	--------	d-----w-	c:\program files (x86)\Mozilla Thunderbird
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-16 02:00 . 2011-09-04 12:42	86054176	----a-w-	c:\windows\system32\MRT.exe
2013-12-18 20:09 . 2013-06-25 16:19	96168	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-12-18 05:13 . 2010-11-21 03:27	270496	------w-	c:\windows\system32\MpSigStub.exe
2013-11-27 01:42 . 2014-01-15 17:51	343040	----a-w-	c:\windows\system32\drivers\usbhub.sys
2013-11-27 01:42 . 2014-01-15 17:51	99840	----a-w-	c:\windows\system32\drivers\usbccgp.sys
2013-11-27 01:42 . 2014-01-15 17:51	325120	----a-w-	c:\windows\system32\drivers\usbport.sys
2013-11-27 01:42 . 2014-01-15 17:51	53248	----a-w-	c:\windows\system32\drivers\usbehci.sys
2013-11-27 01:42 . 2014-01-15 17:51	25600	----a-w-	c:\windows\system32\drivers\usbohci.sys
2013-11-27 01:42 . 2014-01-15 17:51	30720	----a-w-	c:\windows\system32\drivers\usbuhci.sys
2013-11-27 01:42 . 2014-01-15 17:51	7808	----a-w-	c:\windows\system32\drivers\usbd.sys
2013-11-26 10:32 . 2014-01-15 17:50	3156480	----a-w-	c:\windows\system32\win32k.sys
2013-11-20 00:57 . 2013-11-20 00:57	940032	----a-w-	c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-20 00:57 . 2013-11-20 00:57	194048	----a-w-	c:\windows\SysWow64\elshyph.dll
2013-11-20 00:57 . 2013-11-20 00:57	71680	----a-w-	c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-20 00:57 . 2013-11-20 00:57	645120	----a-w-	c:\windows\SysWow64\jsIntl.dll
2013-11-20 00:57 . 2013-11-20 00:57	62464	----a-w-	c:\windows\SysWow64\tdc.ocx
2013-11-20 00:57 . 2013-11-20 00:57	34816	----a-w-	c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-20 00:57 . 2013-11-20 00:57	337408	----a-w-	c:\windows\SysWow64\html.iec
2013-11-20 00:57 . 2013-11-20 00:57	24576	----a-w-	c:\windows\SysWow64\licmgr10.dll
2013-11-20 00:57 . 2013-11-20 00:57	235008	----a-w-	c:\windows\system32\elshyph.dll
2013-11-20 00:57 . 2013-11-20 00:57	182272	----a-w-	c:\windows\SysWow64\msls31.dll
2013-11-20 00:57 . 2013-11-20 00:57	151552	----a-w-	c:\windows\SysWow64\iexpress.exe
2013-11-20 00:57 . 2013-11-20 00:57	139264	----a-w-	c:\windows\SysWow64\wextract.exe
2013-11-20 00:57 . 2013-11-20 00:57	1051136	----a-w-	c:\windows\SysWow64\mshtmlmedia.dll
2013-11-20 00:57 . 2013-11-20 00:57	942592	----a-w-	c:\windows\system32\jsIntl.dll
2013-11-20 00:57 . 2013-11-20 00:57	90112	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2013-11-20 00:57 . 2013-11-20 00:57	86016	----a-w-	c:\windows\SysWow64\iesysprep.dll
2013-11-20 00:57 . 2013-11-20 00:57	86016	----a-w-	c:\windows\system32\RegisterIEPKEYs.exe
2013-11-20 00:57 . 2013-11-20 00:57	84992	----a-w-	c:\windows\system32\mshtmled.dll
2013-11-20 00:57 . 2013-11-20 00:57	83968	----a-w-	c:\windows\system32\MshtmlDac.dll
2013-11-20 00:57 . 2013-11-20 00:57	81408	----a-w-	c:\windows\system32\icardie.dll
2013-11-20 00:57 . 2013-11-20 00:57	774144	----a-w-	c:\windows\system32\jscript.dll
2013-11-20 00:57 . 2013-11-20 00:57	77312	----a-w-	c:\windows\system32\tdc.ocx
2013-11-20 00:57 . 2013-11-20 00:57	74240	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-20 00:57 . 2013-11-20 00:57	62464	----a-w-	c:\windows\system32\pngfilt.dll
2013-11-20 00:57 . 2013-11-20 00:57	61952	----a-w-	c:\windows\SysWow64\MshtmlDac.dll
2013-11-20 00:57 . 2013-11-20 00:57	616104	----a-w-	c:\windows\system32\ieapfltr.dat
2013-11-20 00:57 . 2013-11-20 00:57	52224	----a-w-	c:\windows\system32\msfeedsbs.dll
2013-11-20 00:57 . 2013-11-20 00:57	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2013-11-20 00:57 . 2013-11-20 00:57	48640	----a-w-	c:\windows\system32\mshtmler.dll
2013-11-20 00:57 . 2013-11-20 00:57	48128	----a-w-	c:\windows\system32\imgutil.dll
2013-11-20 00:57 . 2013-11-20 00:57	453120	----a-w-	c:\windows\system32\dxtmsft.dll
2013-11-20 00:57 . 2013-11-20 00:57	413696	----a-w-	c:\windows\system32\html.iec
2013-11-20 00:57 . 2013-11-20 00:57	40448	----a-w-	c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-20 00:57 . 2013-11-20 00:57	36352	----a-w-	c:\windows\SysWow64\imgutil.dll
2013-11-20 00:57 . 2013-11-20 00:57	30208	----a-w-	c:\windows\system32\licmgr10.dll
2013-11-20 00:57 . 2013-11-20 00:57	296960	----a-w-	c:\windows\system32\dxtrans.dll
2013-11-20 00:57 . 2013-11-20 00:57	263376	----a-w-	c:\windows\system32\iedkcs32.dll
2013-11-20 00:57 . 2013-11-20 00:57	247808	----a-w-	c:\windows\system32\msls31.dll
2013-11-20 00:57 . 2013-11-20 00:57	243200	----a-w-	c:\windows\system32\webcheck.dll
2013-11-20 00:57 . 2013-11-20 00:57	235520	----a-w-	c:\windows\system32\url.dll
2013-11-20 00:57 . 2013-11-20 00:57	167424	----a-w-	c:\windows\system32\iexpress.exe
2013-11-20 00:57 . 2013-11-20 00:57	147968	----a-w-	c:\windows\system32\occache.dll
2013-11-20 00:57 . 2013-11-20 00:57	143872	----a-w-	c:\windows\system32\wextract.exe
2013-11-20 00:57 . 2013-11-20 00:57	13824	----a-w-	c:\windows\system32\mshta.exe
2013-11-20 00:57 . 2013-11-20 00:57	135680	----a-w-	c:\windows\system32\iepeers.dll
2013-11-20 00:57 . 2013-11-20 00:57	13312	----a-w-	c:\windows\SysWow64\mshta.exe
2013-11-20 00:57 . 2013-11-20 00:57	13312	----a-w-	c:\windows\system32\msfeedssync.exe
2013-11-20 00:57 . 2013-11-20 00:57	131072	----a-w-	c:\windows\system32\IEAdvpack.dll
2013-11-20 00:57 . 2013-11-20 00:57	1228800	----a-w-	c:\windows\system32\mshtmlmedia.dll
2013-11-20 00:57 . 2013-11-20 00:57	111616	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2013-11-20 00:57 . 2013-11-20 00:57	105984	----a-w-	c:\windows\system32\iesysprep.dll
2013-11-20 00:57 . 2013-11-20 00:57	101376	----a-w-	c:\windows\system32\inseng.dll
2013-11-20 00:57 . 2013-11-20 00:57	878080	----a-w-	c:\windows\system32\advapi32.dll
2013-11-20 00:57 . 2013-11-20 00:57	859648	----a-w-	c:\windows\system32\tdh.dll
2013-11-20 00:57 . 2013-11-20 00:57	7680	----a-w-	c:\windows\SysWow64\instnm.exe
2013-11-20 00:57 . 2013-11-20 00:57	640512	----a-w-	c:\windows\SysWow64\advapi32.dll
2013-11-20 00:57 . 2013-11-20 00:57	619520	----a-w-	c:\windows\SysWow64\tdh.dll
2013-11-20 00:57 . 2013-11-20 00:57	5549504	----a-w-	c:\windows\system32\ntoskrnl.exe
2013-11-20 00:57 . 2013-11-20 00:57	5120	----a-w-	c:\windows\SysWow64\wow32.dll
2013-11-20 00:57 . 2013-11-20 00:57	44032	----a-w-	c:\windows\apppatch\acwow64.dll
2013-11-20 00:57 . 2013-11-20 00:57	3969472	----a-w-	c:\windows\SysWow64\ntkrnlpa.exe
2013-11-20 00:57 . 2013-11-20 00:57	3914176	----a-w-	c:\windows\SysWow64\ntoskrnl.exe
2013-11-20 00:57 . 2013-11-20 00:57	25600	----a-w-	c:\windows\SysWow64\setup16.exe
2013-11-20 00:57 . 2013-11-20 00:57	243712	----a-w-	c:\windows\system32\wow64.dll
2013-11-20 00:57 . 2013-11-20 00:57	2048	----a-w-	c:\windows\SysWow64\user.exe
2013-11-20 00:57 . 2013-11-20 00:57	1732032	----a-w-	c:\windows\system32\ntdll.dll
2013-11-20 00:57 . 2013-11-20 00:57	14336	----a-w-	c:\windows\SysWow64\ntvdm64.dll
2013-11-20 00:57 . 2013-11-20 00:57	1292192	----a-w-	c:\windows\SysWow64\ntdll.dll
2013-11-20 00:57 . 2013-11-20 00:57	327168	----a-w-	c:\windows\system32\mswsock.dll
2013-11-20 00:57 . 2013-11-20 00:57	231424	----a-w-	c:\windows\SysWow64\mswsock.dll
2013-11-20 00:57 . 2013-11-20 00:57	1903552	----a-w-	c:\windows\system32\drivers\tcpip.sys
2013-11-20 00:57 . 2013-11-20 00:57	1887232	----a-w-	c:\windows\system32\d3d11.dll
2013-11-20 00:57 . 2013-11-20 00:57	1505280	----a-w-	c:\windows\SysWow64\d3d11.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160]
"IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2011-01-17 112152]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]
"FreePDF Assistant"="c:\program files (x86)\FreePDF_XP\fpassist.exe" [2011-02-23 371200]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2011-2-8 1136928]
Dell System Manager.lnk - c:\program files\Dell\Dell System Manager\DCPSysMgr.exe [2011-1-20 1552240]
Spyder3Utility.lnk - c:\program files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe [2008-12-5 8119870]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
R3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys;c:\windows\SYSNATIVE\DRIVERS\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 netvsc;netvsc;c:\windows\system32\DRIVERS\netvsc60.sys;c:\windows\SYSNATIVE\DRIVERS\netvsc60.sys [x]
R3 O2MDFRDR;O2MDFRDR;c:\windows\system32\drivers\O2MDFw7x64.sys;c:\windows\SYSNATIVE\drivers\O2MDFw7x64.sys [x]
R3 Spyder3;Datacolor Spyder3;c:\windows\system32\DRIVERS\Spyder3.sys;c:\windows\SYSNATIVE\DRIVERS\Spyder3.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 SynthVid;SynthVid;c:\windows\system32\DRIVERS\VMBusVideoM.sys;c:\windows\SYSNATIVE\DRIVERS\VMBusVideoM.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
R4 Canon imagePROGRAF Status Monitor;Canon imagePROGRAF Status Monitor;c:\program files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe;c:\program files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe [x]
R4 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [x]
R4 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [x]
R4 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [x]
R4 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys;c:\windows\SYSNATIVE\DRIVERS\stdcfltn.sys [x]
S1 cdrblock;cdrblock;c:\windows\system32\DRIVERS\cdrblock.sys;c:\windows\SYSNATIVE\DRIVERS\cdrblock.sys [x]
S2 dcpsysmgrsvc;Dell System Manager Service;c:\program files\Dell\Dell System Manager\DCPSysMgrSvc.exe;c:\program files\Dell\Dell System Manager\DCPSysMgrSvc.exe [x]
S2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe;c:\windows\SYSNATIVE\IProsetMonitor.exe [x]
S2 iPFDeviceAgentService;iPF Device Agent Service;c:\windows\system32\cnwiols6.exe;c:\windows\SYSNATIVE\cnwiols6.exe [x]
S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [x]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\nlssrv32.exe;c:\windows\SysWOW64\nlssrv32.exe [x]
S2 O2SDIOAssist;O2SDIOAssist;c:\windows\SysWOW64\srvany.exe;c:\windows\SysWOW64\srvany.exe [x]
S2 ZcfgSvc7;Intel(R) PROSet/Wireless ZeroConfig Service;c:\program files\Intel\WiFi\bin\ZCfgSvc7.exe;c:\program files\Intel\WiFi\bin\ZCfgSvc7.exe [x]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys;c:\windows\SYSNATIVE\DRIVERS\Accelern.sys [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x]
S3 cvusbdrv;Dell ControlVault;c:\windows\system32\Drivers\cvusbdrv.sys;c:\windows\SYSNATIVE\Drivers\cvusbdrv.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 O2MDRRDR;O2MDRRDR;c:\windows\system32\DRIVERS\O2MDRw7x64.sys;c:\windows\SYSNATIVE\DRIVERS\O2MDRw7x64.sys [x]
S3 O2SDJRDR;O2SDJRDR;c:\windows\system32\DRIVERS\o2sdjw7x64.sys;c:\windows\SYSNATIVE\DRIVERS\o2sdjw7x64.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}"
[HKEY_CLASSES_ROOT\CLSID\{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}]
2010-10-16 21:17	138608	----a-w-	c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}"
[HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}]
2010-10-16 21:17	138608	----a-w-	c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-01-07 525312]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-01-14 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-01-14 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-01-14 418328]
"IntelPROSet"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-23 1934608]
"DBRMTray"="c:\dell\DBRM\Reminder\DbrmTrayIcon.exe" [2011-03-08 227328]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2011-08-03 335976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default\
FF - prefs.js: browser.startup.homepage - www.google.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Wow6432Node-HKLM-Run-CorelDRAW Graphics Suite 11b - c:\program files (x86)\Corel\Corel Graphics 11\Register\registration.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10s_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10s_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\DRIVERS\o2flash.exe
c:\windows\sysWOW64\SDIOAssist.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-02-15  11:16:07 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2014-02-15 10:16
.
Vor Suchlauf: 14 Verzeichnis(se), 167.808.430.080 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 167.072.436.224 Bytes frei
.
- - End Of File - - B9CEB3D238BF390DDC4C214AC9274597
         gruß martin | 
|  16.02.2014, 07:12 | #6 | 
| /// the machine /// TB-Ausbilder         |   versehentlich zip-anhang einer email geöffnet und .exe ausgeführt Downloade Dir bitte   Malwarebytes Anti-Malware 
 Downloade Dir bitte  AdwCleaner auf deinen Desktop. 
 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu   vermeiden. 
 und ein frisches FRST log bitte. 
				__________________ --> versehentlich zip-anhang einer email geöffnet und .exe ausgeführt | 
|  16.02.2014, 20:16 | #7 | 
|  |   versehentlich zip-anhang einer email geöffnet und .exe ausgeführt hallo, hier die logfiles ! Code: 
  ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.02.16.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16518 maddin :: MS2P5 [Administrator] 16.02.2014 11:11:00 mbam-log-2014-02-16 (11-11-00).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 243491 Laufzeit: 1 Minute(n), 42 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code: 
  ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 16/02/2014 um 11:40:36
# Updated 28/01/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : maddin - MS2P5
# Gestartet von : C:\Users\maddin\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16518
-\\ Mozilla Firefox v10.0.2 (de)
[ Datei : C:\Users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [1372 octets] - [14/02/2014 03:10:24]
AdwCleaner[R1].txt - [920 octets] - [16/02/2014 11:21:13]
AdwCleaner[R2].txt - [979 octets] - [16/02/2014 11:39:40]
AdwCleaner[S0].txt - [1433 octets] - [14/02/2014 03:11:40]
AdwCleaner[S1].txt - [901 octets] - [16/02/2014 11:40:36]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [960 octets] ##########
         Code: 
  ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.1 (02.04.2014:1)
OS: Windows 7 Professional x64
Ran by maddin on 16.02.2014 at 19:57:06,25
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\maddin\AppData\Roaming\mozilla\firefox\profiles\xcc0q5jk.default\minidumps [41 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.02.2014 at 20:00:56,56
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         Code: 
  ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-02-2014 01
Ran by maddin (administrator) on MS2P5 on 16-02-2014 20:04:00
Running from C:\Users\maddin\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ 
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dell Inc.) c:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe
(Intel Corporation) C:\Windows\system32\IProsetMonitor.exe
(CANON INC.) C:\Windows\system32\cnwiols6.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(O2Micro International) C:\Windows\system32\DRIVERS\o2flash.exe
() c:\Windows\SysWOW64\srvany.exe
(O2Micro.) c:\Windows\sysWOW64\SDIOAssist.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Dell Computer Corporation) C:\dell\DBRM\Reminder\DbrmTrayicon.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dell Inc.) C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe
() C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-07] (IDT, Inc.)
HKLM\...\Run: [IntelPROSet] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1934608 2010-12-23] (Intel(R) Corporation)
HKLM\...\Run: [DBRMTray] - C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation)
HKLM\...\Run: [NVHotkey] - C:\Windows\system32\nvHotkey.dll [335976 2011-08-03] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-01-17] (Intel Corporation)
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [240232 2011-08-03] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201320 2011-08-03] (NVIDIA Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/USREL/8
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = 
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-06-30]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-09-02]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-22]
==================== Services (Whitelisted) =================
S4 Canon imagePROGRAF Status Monitor; C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe [713488 2009-10-09] (CANON INC)
R2 iPFDeviceAgentService; C:\Windows\system32\cnwiols6.exe [210944 2008-12-08] (CANON INC.)
R2 O2SDIOAssist; c:\Windows\SysWOW64\srvany.exe [8192 2003-04-19] ()
S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1629696 2010-07-13] ()
R2 ZcfgSvc7; C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe [992256 2010-12-23] (Intel(R) Corporation)
==================== Drivers (Whitelisted) ====================
R1 cdrblock; C:\Windows\System32\DRIVERS\cdrblock.sys [37704 2012-06-29] (Grass Valley K.K.)
S3 Spyder3; C:\Windows\System32\DRIVERS\Spyder3.sys [15360 2008-09-08] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-16 20:04 - 2014-02-16 20:04 - 00010804 _____ () C:\Users\maddin\Desktop\FRST.txt
2014-02-16 20:00 - 2014-02-16 20:00 - 00000759 _____ () C:\Users\maddin\Desktop\JRT.txt
2014-02-16 19:57 - 2014-02-16 19:57 - 00000000 ____D () C:\Windows\ERUNT
2014-02-16 11:41 - 2014-02-16 11:41 - 00001039 _____ () C:\Users\maddin\Desktop\AdwCleaner[S1].txt
2014-02-16 11:20 - 2014-02-16 20:03 - 00002977 _____ () C:\Users\maddin\Desktop\post.txt
2014-02-16 11:18 - 2014-02-16 11:18 - 01037530 _____ (Thisisu) C:\Users\maddin\Desktop\JRT.exe
2014-02-16 11:06 - 2014-02-16 11:06 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\Malwarebytes
2014-02-16 11:05 - 2014-02-16 11:05 - 00001079 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-16 11:05 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-15 11:42 - 2014-02-15 11:42 - 00032236 _____ () C:\Users\maddin\Desktop\Addition_2014_02_15.txt
2014-02-15 11:42 - 2014-02-15 11:42 - 00027888 _____ () C:\Users\maddin\Desktop\FRST_2014_02_15.txt
2014-02-15 11:16 - 2014-02-15 11:16 - 00026272 _____ () C:\ComboFix.txt
2014-02-15 11:10 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-02-15 11:10 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-02-15 11:10 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-02-15 11:10 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-02-15 11:10 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-02-15 11:10 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-02-15 11:10 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-02-15 11:10 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-02-15 11:09 - 2014-02-15 11:16 - 00000000 ____D () C:\Qoobox
2014-02-15 11:09 - 2014-02-15 11:15 - 00000000 ____D () C:\Windows\erdnt
2014-02-15 11:07 - 2014-02-15 11:07 - 05183211 ____R (Swearware) C:\Users\maddin\Desktop\ComboFix.exe
2014-02-14 08:38 - 2014-02-14 08:38 - 00032488 _____ () C:\Users\maddin\Desktop\Addition_2014_02_14.txt
2014-02-14 08:37 - 2014-02-16 20:04 - 00000000 ____D () C:\FRST
2014-02-14 08:37 - 2014-02-14 08:38 - 00029381 _____ () C:\Users\maddin\Desktop\FRST_2014_02_14.txt
2014-02-14 08:36 - 2014-02-14 08:36 - 02152960 _____ (Farbar) C:\Users\maddin\Desktop\FRST64.exe
2014-02-14 03:10 - 2014-02-16 11:40 - 00000000 ____D () C:\AdwCleaner
2014-02-14 03:09 - 2014-02-14 03:09 - 01166132 _____ () C:\Users\maddin\Desktop\adwcleaner.exe
2014-02-14 03:05 - 2014-02-14 03:05 - 04102163 _____ () C:\Users\maddin\Desktop\tdsskiller.zip
2014-02-14 02:40 - 2014-02-14 02:32 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-14 02:32 - 2014-02-14 02:41 - 00023557 _____ () C:\zoek-results.log
2014-02-14 02:30 - 2014-02-14 03:01 - 00000000 ____D () C:\zoek_backup
2014-02-14 02:30 - 2014-02-14 02:30 - 01283584 _____ () C:\Users\maddin\Desktop\zoek.exe
2014-02-13 03:00 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-13 03:00 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-13 03:00 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-13 03:00 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-13 03:00 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-13 03:00 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-13 03:00 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-13 03:00 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-13 03:00 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-13 03:00 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-13 03:00 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-13 03:00 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-13 03:00 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-13 03:00 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-13 03:00 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-13 03:00 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-13 03:00 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-13 03:00 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-13 03:00 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-13 03:00 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-13 03:00 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-13 03:00 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-13 03:00 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-13 03:00 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-13 03:00 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-13 03:00 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-13 03:00 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-13 03:00 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-13 03:00 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-13 03:00 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-13 03:00 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-13 03:00 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-13 03:00 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-13 03:00 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-13 03:00 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-13 03:00 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-13 03:00 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-13 03:00 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-13 03:00 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-13 03:00 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-13 03:00 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-12 23:31 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-12 23:31 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-12 23:31 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-12 23:31 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-12 23:30 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-12 23:30 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-12 23:30 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-12 23:30 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-11 18:02 - 2014-02-11 18:02 - 00000146 _____ () C:\Users\maddin\Desktop\Dell Touchpad - Verknüpfung.lnk
2014-02-05 00:21 - 2014-02-05 08:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-01-26 09:11 - 2014-01-26 09:11 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
==================== One Month Modified Files and Folders =======
2014-02-16 20:04 - 2014-02-16 20:04 - 00010804 _____ () C:\Users\maddin\Desktop\FRST.txt
2014-02-16 20:04 - 2014-02-14 08:37 - 00000000 ____D () C:\FRST
2014-02-16 20:03 - 2014-02-16 11:20 - 00002977 _____ () C:\Users\maddin\Desktop\post.txt
2014-02-16 20:01 - 2010-11-21 07:50 - 00697082 _____ () C:\Windows\system32\perfh007.dat
2014-02-16 20:01 - 2010-11-21 07:50 - 00148346 _____ () C:\Windows\system32\perfc007.dat
2014-02-16 20:01 - 2009-07-14 06:13 - 01613340 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-16 20:01 - 2009-07-14 05:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-16 20:01 - 2009-07-14 05:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-16 20:00 - 2014-02-16 20:00 - 00000759 _____ () C:\Users\maddin\Desktop\JRT.txt
2014-02-16 19:57 - 2014-02-16 19:57 - 00000000 ____D () C:\Windows\ERUNT
2014-02-16 19:57 - 2011-08-24 17:32 - 01919183 _____ () C:\Windows\WindowsUpdate.log
2014-02-16 19:54 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-16 19:54 - 2009-07-14 05:51 - 00232767 _____ () C:\Windows\setupact.log
2014-02-16 11:41 - 2014-02-16 11:41 - 00001039 _____ () C:\Users\maddin\Desktop\AdwCleaner[S1].txt
2014-02-16 11:40 - 2014-02-14 03:10 - 00000000 ____D () C:\AdwCleaner
2014-02-16 11:18 - 2014-02-16 11:18 - 01037530 _____ (Thisisu) C:\Users\maddin\Desktop\JRT.exe
2014-02-16 11:06 - 2014-02-16 11:06 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\Malwarebytes
2014-02-16 11:05 - 2014-02-16 11:05 - 00001079 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-16 03:01 - 2013-08-14 06:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-16 03:00 - 2011-09-04 13:42 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-15 11:42 - 2014-02-15 11:42 - 00032236 _____ () C:\Users\maddin\Desktop\Addition_2014_02_15.txt
2014-02-15 11:42 - 2014-02-15 11:42 - 00027888 _____ () C:\Users\maddin\Desktop\FRST_2014_02_15.txt
2014-02-15 11:16 - 2014-02-15 11:16 - 00026272 _____ () C:\ComboFix.txt
2014-02-15 11:16 - 2014-02-15 11:09 - 00000000 ____D () C:\Qoobox
2014-02-15 11:16 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-02-15 11:15 - 2014-02-15 11:09 - 00000000 ____D () C:\Windows\erdnt
2014-02-15 11:14 - 2010-11-21 04:47 - 00029252 _____ () C:\Windows\PFRO.log
2014-02-15 11:14 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-02-15 11:13 - 2009-07-14 03:34 - 74186752 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-02-15 11:13 - 2009-07-14 03:34 - 44040192 _____ () C:\Windows\system32\config\components.bak
2014-02-15 11:13 - 2009-07-14 03:34 - 21757952 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-02-15 11:13 - 2009-07-14 03:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-02-15 11:13 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-02-15 11:13 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-02-15 11:07 - 2014-02-15 11:07 - 05183211 ____R (Swearware) C:\Users\maddin\Desktop\ComboFix.exe
2014-02-14 08:38 - 2014-02-14 08:38 - 00032488 _____ () C:\Users\maddin\Desktop\Addition_2014_02_14.txt
2014-02-14 08:38 - 2014-02-14 08:37 - 00029381 _____ () C:\Users\maddin\Desktop\FRST_2014_02_14.txt
2014-02-14 08:36 - 2014-02-14 08:36 - 02152960 _____ (Farbar) C:\Users\maddin\Desktop\FRST64.exe
2014-02-14 03:09 - 2014-02-14 03:09 - 01166132 _____ () C:\Users\maddin\Desktop\adwcleaner.exe
2014-02-14 03:05 - 2014-02-14 03:05 - 04102163 _____ () C:\Users\maddin\Desktop\tdsskiller.zip
2014-02-14 03:01 - 2014-02-14 02:30 - 00000000 ____D () C:\zoek_backup
2014-02-14 02:41 - 2014-02-14 02:32 - 00023557 _____ () C:\zoek-results.log
2014-02-14 02:32 - 2014-02-14 02:40 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-14 02:30 - 2014-02-14 02:30 - 01283584 _____ () C:\Users\maddin\Desktop\zoek.exe
2014-02-13 03:04 - 2011-02-11 18:45 - 01591234 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-11 18:02 - 2014-02-11 18:02 - 00000146 _____ () C:\Users\maddin\Desktop\Dell Touchpad - Verknüpfung.lnk
2014-02-10 23:02 - 2013-03-22 14:55 - 00000072 _____ () C:\Users\Public\LMDebug.log
2014-02-06 13:16 - 2014-02-13 03:00 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 12:30 - 2014-02-13 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 12:30 - 2014-02-13 03:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 12:12 - 2014-02-13 03:00 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 12:07 - 2014-02-13 03:00 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 12:06 - 2014-02-13 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 11:57 - 2014-02-13 03:00 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 11:56 - 2014-02-13 03:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 11:52 - 2014-02-13 03:00 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 11:49 - 2014-02-13 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 11:48 - 2014-02-13 03:00 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 11:48 - 2014-02-13 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 11:38 - 2014-02-13 03:00 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-06 11:32 - 2014-02-13 03:00 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 11:20 - 2014-02-13 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-06 11:17 - 2014-02-13 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 11:11 - 2014-02-13 03:00 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 11:01 - 2014-02-13 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-06 11:00 - 2014-02-13 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-13 03:00 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-06 10:57 - 2014-02-13 03:00 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:52 - 2014-02-13 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-06 10:52 - 2014-02-13 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-06 10:50 - 2014-02-13 03:00 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:49 - 2014-02-13 03:00 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-06 10:47 - 2014-02-13 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-06 10:46 - 2014-02-13 03:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-06 10:25 - 2014-02-13 03:00 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-06 10:25 - 2014-02-13 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-06 10:24 - 2014-02-13 03:00 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 10:22 - 2014-02-13 03:00 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 10:13 - 2014-02-13 03:00 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-06 10:09 - 2014-02-13 03:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-06 10:03 - 2014-02-13 03:00 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-06 09:55 - 2014-02-13 03:00 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:41 - 2014-02-13 03:00 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-06 09:40 - 2014-02-13 03:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-06 09:36 - 2014-02-13 03:00 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-06 09:34 - 2014-02-13 03:00 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-05 10:26 - 2011-09-11 14:19 - 00000000 ____D () C:\Users\maddin\AppData\Local\FreePDF_XP
2014-02-05 09:30 - 2012-10-15 14:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-05 08:11 - 2014-02-05 00:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-02-01 23:46 - 2011-08-31 01:16 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\IrfanView
2014-01-31 23:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-01-28 00:21 - 2011-11-20 00:11 - 00012288 _____ () C:\Users\maddin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-26 09:17 - 2013-10-21 22:11 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-26 09:11 - 2014-01-26 09:11 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-26 09:11 - 2013-06-25 17:19 - 00000000 ____D () C:\Program Files (x86)\Java
Some content of TEMP:
====================
C:\Users\maddin\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-09 11:55
==================== End Of Log ============================
         Code: 
  ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-02-2014 01
Ran by maddin at 2014-02-16 20:04:15
Running from C:\Users\maddin\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov)
AccelerometerP11 (x32 Version: 2.00.10.22 - STMicroelectronics)
Adobe AIR (x32 Version: 1.5.3.9120 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 1.5.3.9120 - Adobe Systems Inc.) Hidden
Adobe Community Help (x32 Version: 3.0.0 - Adobe Systems Incorporated) Hidden
Adobe Community Help (x32 Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Flash Player 10 ActiveX (x32 Version: 10.3.181.23 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117 - Adobe Systems Incorporated)
Adobe Media Player (x32 Version: 1.8 - Adobe Systems Incorporated)
Adobe Media Player (x32 Version: 1.8 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CS5 (x32 Version: 12.0 - Adobe Systems Incorporated)
BioAPI Framework (Version: 1.0.2 - Dell Inc.) Hidden
Canon Inkjet Printer Driver Add-On Module V2.00 (Version:  - )
Canon My Printer (x32 Version:  - )
Canon RAW Codec (x32 Version: 1.8.0.68 - Canon Inc.)
Canon Utilities EOS Utility (x32 Version: 2.11.2.0 - Canon Inc.)
Canon Utilities Picture Style Editor (x32 Version: 1.10.1.0 - Canon Inc.)
CanoScan Toolbox Ver4.9 (x32 Version:  - )
Color Efex Pro 3.0 Complete (x32 Version: 3.1.1.0 - Nik Software, Inc.)
Color Efex Pro 4 (x32 Version: 4.0.0.2 - Nik Software, Inc.)
CorelDRAW Home & Student Suite X6 - BR (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Capture (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Common (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Connect (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Custom Data (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - CZ (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - DE (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Draw (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - EN (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - ES (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Extra Content (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Filters (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - FontNav (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - FR (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - IPM (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - IT (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - NL (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - PHOTO-PAINT (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - PL (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Redist (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - RU (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Setup Files (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - VideoBrowser (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 - Writing Tools (x32 Version: 16.1 -  Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 (x32 Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X6 (x32 Version: 16.1.0.843 - Corel Corporation)
Custom (Version: 12.34.56.789 - Wave Systems Corp.) Hidden
CyberLink PowerDVD 9.5 (x32 Version: 9.5.1.3225 - CyberLink Corp.)
CyberLink PowerDVD 9.5 (x32 Version: 9.5.1.3225 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Backup and Recovery Manager (Version: 1.3.1 - Dell Inc.)
Dell ControlVault Host Components Installer 64 bit (Version: 2.0.20.159 - Broadcom Corporation) Hidden
Dell Data Protection | Access (Version: 01.01.00.085 - Wave Systems Corp) Hidden
Dell Data Protection | Access (x32 Version: 2.0.00000.085 - Dell Inc.)
Dell Data Protection | Access | Drivers (x32 Version: 1.00.011 - Dell Inc.)
Dell Data Protection | Access | Middleware (x32 Version: 1.00.005 - Dell Inc.)
Dell Edoc Viewer (Version: 1.0.0 - Dell Inc)
Dell System Manager (Version: 1.6.00000 - Dell Inc.)
Dell Touchpad (Version: 7.1208.101.118 - ALPS ELECTRIC CO., LTD.)
Dell Webcam Central (x32 Version: 1.40.28 - Creative Technology Ltd)
DellAccess (Version: 01.01.00.053 - Wave Systems Corp.) Hidden
Dfine 2.0 (x32 Version: 2.1.0.7 - Nik Software, Inc.)
DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
EDIUS (x32 Version: 6.51 - Grass Valley K.K.)
EDIUS Codec Option 6.51 (x32 Version: 6.51 - Grass Valley K.K.)
EDIUS DVD Menu Style 1.00 (x32 Version: 1.00 - Grass Valley K.K.)
EMBASSY Security Center (Version: 04.03.00.067 - Wave Systems Corp.) Hidden
FreePDF (Remove only) (x32 Version:  - )
Gemalto (Version: 01.64.01.0010 - Wave Systems Corp) Hidden
GoPro CineForm Studio 1.2.1 (x32 Version: 1.2.1 - CineForm, Inc & GoPro, Inc.)
GPL Ghostscript (Version: 9.04 - Artifex Software Inc.)
GV LicenseManager 1.01 (x32 Version: 1.01 - Grass Valley K.K.)
HDR Efex Pro (x32 Version: 1.2.0.0 - Nik Software, Inc.)
HDR Efex Pro 2 (x32 Version: 2.0.0.0 - Nik Software, Inc.)
Helicon Focus 5.2.9 (x32 Version:  - Helicon Soft Ltd.)
imagePROGRAF Status Monitor (x32 Version: 4.30 - Canon)
Intel PROSet Wireless (Version:  - ) Hidden
Intel(R) Control Center (x32 Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Identity Protection Technology 1.1.2.0 (x32 Version: 1.1.2.0 - Intel Corporation)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Network Connections 15.7.176.1 (Version: 15.7.176.1 - Intel)
Intel(R) Network Connections 15.7.176.1 (Version: 15.7.176.1 - Intel) Hidden
Intel(R) Processor Graphics (x32 Version: 8.15.10.2266 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi-Software (Version: 14.00.20110 - Intel Corporation)
Intel(R) Rapid Storage Technology (x32 Version: 10.1.0.1008 - Intel Corporation)
iPF6300 Media Configuration Tool (x32 Version: 4.02.02 - Canon)
IrfanView (remove only) (x32 Version: 4.28 - Irfan Skiljan)
Java 7 Update 51 (x32 Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 24 (64-bit) (Version: 6.0.240 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Business 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (x32 Version: 4.0.50401.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden
Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Mobile Partner (x32 Version: 11.300.05.03.40 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 10.0.2 (x86 de) (x32 Version: 10.0.2 - Mozilla)
Mozilla Maintenance Service (x32 Version: 24.3.0 - Mozilla)
Mozilla Thunderbird 24.3.0 (x86 de) (x32 Version: 24.3.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation)
No23 Recorder (x32 Version: 2.1.0.3 - No23)
No23 Recorder (x32 Version: 2.1.0.3 - No23) Hidden
NTRU TCG Software Stack (Version: 2.1.34 - Security Innovation) Hidden
NVIDIA 3D Vision Controller Driver (x32 Version: 280.19 - NVIDIA Corporation) Hidden
NVIDIA 3D Vision Controller-Treiber 285.62 (Version: 285.62 - NVIDIA Corporation)
NVIDIA Grafiktreiber 280.26 (Version: 280.26 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.2.24.0 (Version: 1.2.24.0 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.46.235 - NVIDIA Corporation) Hidden
NVIDIA nView 136.02 (Version: 136.02 - NVIDIA Corporation)
NVIDIA nView Desktop Manager (Version: 6.14.10.13594 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.11.0621 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.11.0621 (Version: 9.11.0621 - NVIDIA Corporation)
NVIDIA Systemsteuerung 280.26 (Version: 280.26 - NVIDIA Corporation) Hidden
O2Micro Flash Memory Card Windows Driver (x32 Version: 3.0.07.23 - O2Micro International LTD.)
O2Micro Flash Memory Card Windows Driver (x32 Version: 3.0.07.23 - O2Micro International LTD.) Hidden
PC-CCID (Version: 2.0.0 - Gemalto) Hidden
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
PDF-XChange Viewer (Version: 2.5.197.0 - Tracker Software Products Ltd.)
PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden
Preboot Manager (Version: 03.03.00.049 - Wave Systems Corp.) Hidden
Private Information Manager (Version: 07.01.00.007 - Wave Systems Corp.) Hidden
proDAD Mercalli 2.0 (x32 Version: 2.0.105.1 - proDAD GmbH)
PTGui Pro 9.1.3 (x32 Version:  - New House Internet Services B.V.)
QuickTime Alternative 1.81 (x32 Version: 1.81 - )
RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
RedMon - Redirection Port Monitor (Version:  - )
Roxio Activation Module (x32 Version: 1.0 - Roxio) Hidden
Roxio BackOnTrack (x32 Version: 1.3.3 - Roxio) Hidden
Roxio Burn (x32 Version: 1.8 - Roxio) Hidden
Roxio Creator Starter (x32 Version: 1.0.439 - Roxio) Hidden
Roxio Creator Starter (x32 Version: 12.1.77.0 - Roxio)
Roxio Creator Starter (x32 Version: 5.0.0 - Roxio) Hidden
Roxio Express Labeler 3 (x32 Version: 3.2.2 - Roxio) Hidden
Roxio File Backup (Version: 1.3.2 - Roxio) Hidden
Samsung ML-371x Series (x32 Version: 1.27 (16.01.2013) - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (x32 Version: 1.01.00.04 - Samsung Electronics Co., Ltd.)
Sharpener Pro 3.0 (x32 Version: 3.0.0.5 - Nik Software, Inc.)
Silver Efex Pro 2 (x32 Version: 2.0.0.0 - Nik Software, Inc.)
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden
SPBA 5.9 (Version: 5.9.4.6686 - UPEK Inc.) Hidden
Spyder3Elite (x32 Version:  - )
Spyder3Studio SR (x32 Version:  - )
Trusted Drive Manager (Version: 4.0.0.512 - Wave Systems Corp.) Hidden
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1 - Microsoft Corporation)
Upek Touchchip Fingerprint Reader (Version: 1.2.004 - Dell Inc.) Hidden
Viveza 2 (x32 Version: 2.0.0.4 - Nik Software, Inc.)
Wave Infrastructure Installer (Version: 07.66.40.0008 - Wave Systems Corp) Hidden
Wave Support Software Installer (Version: 05.13.00.014 - Wave Systems Corp) Hidden
WIDCOMM Bluetooth Software (Version: 6.3.0.7900 - Broadcom Corporation)
Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices  (03/07/2012 ) (Version: 03/07/2012  - GoPro)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows-Treiberpaket - Dell Inc. PBADRV System  (09/11/2009 1.0.1.6) (Version: 09/11/2009 1.0.1.6 - Dell Inc.)
Xvid Video Codec (x32 Version: 1.3.2 - Xvid Team)
==================== Restore Points  =========================
16-01-2014 02:00:10 Windows Update
24-01-2014 08:53:37 Geplanter Prüfpunkt
25-01-2014 00:07:16 Windows Update
26-01-2014 08:10:55 Installed Java 7 Update 51
28-01-2014 17:23:36 Windows Update
01-02-2014 09:22:25 Windows Update
07-02-2014 20:49:41 Windows Update
11-02-2014 07:30:39 Windows Update
13-02-2014 02:00:11 Windows Update
14-02-2014 01:32:20 zoek.exe restore point
16-02-2014 02:00:10 Windows Update
==================== Hosts content: ==========================
2009-07-14 03:34 - 2014-02-15 11:14 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {323FA560-8206-4AE6-8ADD-7D835D50C4B9} - System32\Tasks\{0C4D7B98-6EBB-4731-ADAA-C91447093380} => D:\Temp\Delpart.exe
Task: {B3EEABE8-B3B6-4649-B2B9-5C4E76514513} - System32\Tasks\{DC334E4C-3EA2-4AF3-88BC-94B721D8EC8A} => C:\Program Files (x86)\Corel\Corel Graphics 11\Programs\CorelDrw.exe
Task: {B8F007C2-DE44-4FA8-A7FB-ECFC52D3FED0} - System32\Tasks\AdobeAAMUpdater-1.0-ms2p5-maddin => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated)
Task: {DADBFA70-8776-487C-9ED3-31B4521C6AB8} - System32\Tasks\{D3D457AC-3188-4F74-BF49-9367FBD5CCA1} => D:\Temp\Delpart.exe
Task: {DCE1F4B1-68A1-4173-8549-4811D2E7AC61} - System32\Tasks\{2FE67FED-22CF-4EC7-8D6D-A466E4A80B3E} => C:\Program Files (x86)\Corel\Corel Graphics 11\Programs\CorelDrw.exe
==================== Loaded Modules (whitelisted) =============
2010-12-23 19:33 - 2010-12-23 19:33 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-02-08 07:41 - 2011-02-08 07:41 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2008-12-05 10:05 - 2008-12-11 17:40 - 08119870 _____ () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
2008-12-11 17:43 - 2008-12-11 17:29 - 00131072 _____ () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\CSensor.dll
2008-12-11 17:43 - 2008-12-11 17:28 - 00331776 _____ () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\CGamma.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\ProgramData\Temp:054203E4
AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Disabled items from MSCONFIG ==============
MSCONFIG\Services: AESTFilters => 2
MSCONFIG\Services: Canon imagePROGRAF Status Monitor => 2
MSCONFIG\Services: Credential Vault Host Control Service => 2
MSCONFIG\Services: Credential Vault Host Storage => 2
MSCONFIG\Services: RoxMediaDB12OEM => 3
MSCONFIG\Services: RoxWatch12 => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CineForm Status.lnk => C:\Windows\pss\CineForm Status.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GV LicenseManager.lnk => C:\Windows\pss\GV LicenseManager.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^imagePROGRAF Status Monitor.lnk => C:\Windows\pss\imagePROGRAF Status Monitor.lnk.CommonStartup
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: Apoint => C:\Program Files\DellTPad\Apoint.exe
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CnwiDeviceAgent => C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwida.exe
MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
MSCONFIG\startupreg: FreeFallProtection => C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
MSCONFIG\startupreg: PDVD9LanguageShortcut => "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
MSCONFIG\startupreg: RemoteControl9 => "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
MSCONFIG\startupreg: RoxWatchTray => "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
  Date: 2014-02-15 11:13:24.204
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
  Date: 2014-02-15 11:13:24.157
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info =========================== 
Percentage of memory in use: 19%
Total physical RAM: 8148.9 MB
Available physical RAM: 6561.81 MB
Total Pagefile: 16295.98 MB
Available Pagefile: 14602.16 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:225.67 GB) (Free:155.79 GB) NTFS
Drive d: (Daten) (Fixed) (Total:238.47 GB) (Free:136.78 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 238 GB) (Disk ID: D1E3F7F7)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=13 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=226 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: D1E3F7C8)
Partition 1: (Not Active) - (Size=238 GB) - (Type=07 NTFS)
==================== End Of Log ============================
         martin | 
|  17.02.2014, 14:26 | #8 | 
| /// the machine /// TB-Ausbilder         |   versehentlich zip-anhang einer email geöffnet und .exe ausgeführtESET Online Scanner 
 Downloade Dir bitte  SecurityCheck und: 
 und ein frisches FRST log bitte. Noch Probleme?   
				__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! | 
|  18.02.2014, 02:23 | #9 | 
|  |   versehentlich zip-anhang einer email geöffnet und .exe ausgeführt hallo, anbei wieder die logfiles. Code: 
  ATTFilter ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=0e11bd4726aea14f85e923019de33e68
# engine=17111
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-18 12:57:06
# local_time=2014-02-18 01:57:06 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 300082 144314876 0 0
# scanned=235464
# found=0
# cleaned=0
# scan_time=3057
         Code: 
  ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Spyder3Elite Spyder3Studio SR Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 51 Adobe Flash Player 10 Flash Player out of Date! Adobe Flash Player 11.9.900.117 Mozilla Firefox 10.0.2 Firefox out of Date! Mozilla Thunderbird (24.3.0) ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Code: 
  ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-02-2014
Ran by maddin (administrator) on MS2P5 on 18-02-2014 02:04:27
Running from C:\Users\maddin\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ 
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dell Inc.) c:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe
(Intel Corporation) C:\Windows\system32\IProsetMonitor.exe
(CANON INC.) C:\Windows\system32\cnwiols6.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(O2Micro International) C:\Windows\system32\DRIVERS\o2flash.exe
() c:\Windows\SysWOW64\srvany.exe
(O2Micro.) c:\Windows\sysWOW64\SDIOAssist.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Dell Computer Corporation) C:\dell\DBRM\Reminder\DbrmTrayicon.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dell Inc.) C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe
() C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-07] (IDT, Inc.)
HKLM\...\Run: [IntelPROSet] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1934608 2010-12-23] (Intel(R) Corporation)
HKLM\...\Run: [DBRMTray] - C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation)
HKLM\...\Run: [NVHotkey] - C:\Windows\system32\nvHotkey.dll [335976 2011-08-03] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-01-17] (Intel Corporation)
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [240232 2011-08-03] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201320 2011-08-03] (NVIDIA Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/USREL/8
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = 
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-06-30]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-09-02]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-22]
==================== Services (Whitelisted) =================
S4 Canon imagePROGRAF Status Monitor; C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe [713488 2009-10-09] (CANON INC)
R2 iPFDeviceAgentService; C:\Windows\system32\cnwiols6.exe [210944 2008-12-08] (CANON INC.)
R2 O2SDIOAssist; c:\Windows\SysWOW64\srvany.exe [8192 2003-04-19] ()
S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1629696 2010-07-13] ()
R2 ZcfgSvc7; C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe [992256 2010-12-23] (Intel(R) Corporation)
==================== Drivers (Whitelisted) ====================
R1 cdrblock; C:\Windows\System32\DRIVERS\cdrblock.sys [37704 2012-06-29] (Grass Valley K.K.)
S3 Spyder3; C:\Windows\System32\DRIVERS\Spyder3.sys [15360 2008-09-08] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-18 02:04 - 2014-02-18 02:04 - 00010913 _____ () C:\Users\maddin\Desktop\FRST.txt
2014-02-18 02:04 - 2014-02-18 02:04 - 00000000 ____D () C:\Users\maddin\Desktop\FRST-OlderVersion
2014-02-18 02:03 - 2014-02-18 02:03 - 00000938 _____ () C:\Users\maddin\Desktop\checkup.txt
2014-02-18 02:00 - 2014-02-18 02:00 - 00987425 _____ () C:\Users\maddin\Desktop\SecurityCheck.exe
2014-02-18 01:03 - 2014-02-18 01:03 - 02347384 _____ (ESET) C:\Users\maddin\Desktop\esetsmartinstaller_enu.exe
2014-02-16 20:04 - 2014-02-16 20:04 - 00030582 _____ () C:\Users\maddin\Desktop\FRST_2014_02_16.txt
2014-02-16 20:04 - 2014-02-16 20:04 - 00025194 _____ () C:\Users\maddin\Desktop\Addition_2014_02_16.txt
2014-02-16 20:00 - 2014-02-16 20:00 - 00000759 _____ () C:\Users\maddin\Desktop\JRT.txt
2014-02-16 19:57 - 2014-02-16 19:57 - 00000000 ____D () C:\Windows\ERUNT
2014-02-16 11:41 - 2014-02-16 11:41 - 00001039 _____ () C:\Users\maddin\Desktop\AdwCleaner[S1].txt
2014-02-16 11:18 - 2014-02-16 11:18 - 01037530 _____ (Thisisu) C:\Users\maddin\Desktop\JRT.exe
2014-02-16 11:06 - 2014-02-16 11:06 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\Malwarebytes
2014-02-16 11:05 - 2014-02-16 11:05 - 00001079 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-16 11:05 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-15 11:42 - 2014-02-15 11:42 - 00032236 _____ () C:\Users\maddin\Desktop\Addition_2014_02_15.txt
2014-02-15 11:42 - 2014-02-15 11:42 - 00027888 _____ () C:\Users\maddin\Desktop\FRST_2014_02_15.txt
2014-02-15 11:16 - 2014-02-15 11:16 - 00026272 _____ () C:\ComboFix.txt
2014-02-15 11:10 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-02-15 11:10 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-02-15 11:10 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-02-15 11:10 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-02-15 11:10 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-02-15 11:10 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-02-15 11:10 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-02-15 11:10 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-02-15 11:09 - 2014-02-15 11:16 - 00000000 ____D () C:\Qoobox
2014-02-15 11:09 - 2014-02-15 11:15 - 00000000 ____D () C:\Windows\erdnt
2014-02-15 11:07 - 2014-02-15 11:07 - 05183211 ____R (Swearware) C:\Users\maddin\Desktop\ComboFix.exe
2014-02-14 08:38 - 2014-02-14 08:38 - 00032488 _____ () C:\Users\maddin\Desktop\Addition_2014_02_14.txt
2014-02-14 08:37 - 2014-02-18 02:04 - 00000000 ____D () C:\FRST
2014-02-14 08:37 - 2014-02-14 08:38 - 00029381 _____ () C:\Users\maddin\Desktop\FRST_2014_02_14.txt
2014-02-14 08:36 - 2014-02-18 02:04 - 02152448 _____ (Farbar) C:\Users\maddin\Desktop\FRST64.exe
2014-02-14 03:10 - 2014-02-16 11:40 - 00000000 ____D () C:\AdwCleaner
2014-02-14 03:09 - 2014-02-14 03:09 - 01166132 _____ () C:\Users\maddin\Desktop\adwcleaner.exe
2014-02-14 03:05 - 2014-02-14 03:05 - 04102163 _____ () C:\Users\maddin\Desktop\tdsskiller.zip
2014-02-14 02:40 - 2014-02-14 02:32 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-14 02:32 - 2014-02-14 02:41 - 00023557 _____ () C:\zoek-results.log
2014-02-14 02:30 - 2014-02-14 03:01 - 00000000 ____D () C:\zoek_backup
2014-02-14 02:30 - 2014-02-14 02:30 - 01283584 _____ () C:\Users\maddin\Desktop\zoek.exe
2014-02-13 03:00 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-13 03:00 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-13 03:00 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-13 03:00 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-13 03:00 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-13 03:00 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-13 03:00 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-13 03:00 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-13 03:00 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-13 03:00 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-13 03:00 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-13 03:00 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-13 03:00 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-13 03:00 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-13 03:00 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-13 03:00 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-13 03:00 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-13 03:00 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-13 03:00 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-13 03:00 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-13 03:00 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-13 03:00 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-13 03:00 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-13 03:00 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-13 03:00 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-13 03:00 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-13 03:00 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-13 03:00 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-13 03:00 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-13 03:00 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-13 03:00 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-13 03:00 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-13 03:00 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-13 03:00 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-13 03:00 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-13 03:00 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-13 03:00 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-13 03:00 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-13 03:00 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-13 03:00 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-13 03:00 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-12 23:31 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-12 23:31 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-12 23:31 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-12 23:31 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-12 23:30 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-12 23:30 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-12 23:30 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-12 23:30 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-11 18:02 - 2014-02-11 18:02 - 00000146 _____ () C:\Users\maddin\Desktop\Dell Touchpad - Verknüpfung.lnk
2014-02-05 00:21 - 2014-02-05 08:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-01-26 09:11 - 2014-01-26 09:11 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
==================== One Month Modified Files and Folders =======
2014-02-18 02:04 - 2014-02-18 02:04 - 00010913 _____ () C:\Users\maddin\Desktop\FRST.txt
2014-02-18 02:04 - 2014-02-18 02:04 - 00000000 ____D () C:\Users\maddin\Desktop\FRST-OlderVersion
2014-02-18 02:04 - 2014-02-14 08:37 - 00000000 ____D () C:\FRST
2014-02-18 02:04 - 2014-02-14 08:36 - 02152448 _____ (Farbar) C:\Users\maddin\Desktop\FRST64.exe
2014-02-18 02:03 - 2014-02-18 02:03 - 00000938 _____ () C:\Users\maddin\Desktop\checkup.txt
2014-02-18 02:00 - 2014-02-18 02:00 - 00987425 _____ () C:\Users\maddin\Desktop\SecurityCheck.exe
2014-02-18 01:03 - 2014-02-18 01:03 - 02347384 _____ (ESET) C:\Users\maddin\Desktop\esetsmartinstaller_enu.exe
2014-02-18 01:00 - 2010-11-21 07:50 - 00697082 _____ () C:\Windows\system32\perfh007.dat
2014-02-18 01:00 - 2010-11-21 07:50 - 00148346 _____ () C:\Windows\system32\perfc007.dat
2014-02-18 01:00 - 2009-07-14 06:13 - 01613340 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-18 00:15 - 2011-08-24 17:32 - 01958051 _____ () C:\Windows\WindowsUpdate.log
2014-02-17 23:55 - 2009-07-14 05:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-17 23:55 - 2009-07-14 05:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-17 23:48 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-17 23:48 - 2009-07-14 05:51 - 00233103 _____ () C:\Windows\setupact.log
2014-02-16 20:04 - 2014-02-16 20:04 - 00030582 _____ () C:\Users\maddin\Desktop\FRST_2014_02_16.txt
2014-02-16 20:04 - 2014-02-16 20:04 - 00025194 _____ () C:\Users\maddin\Desktop\Addition_2014_02_16.txt
2014-02-16 20:00 - 2014-02-16 20:00 - 00000759 _____ () C:\Users\maddin\Desktop\JRT.txt
2014-02-16 19:57 - 2014-02-16 19:57 - 00000000 ____D () C:\Windows\ERUNT
2014-02-16 11:41 - 2014-02-16 11:41 - 00001039 _____ () C:\Users\maddin\Desktop\AdwCleaner[S1].txt
2014-02-16 11:40 - 2014-02-14 03:10 - 00000000 ____D () C:\AdwCleaner
2014-02-16 11:18 - 2014-02-16 11:18 - 01037530 _____ (Thisisu) C:\Users\maddin\Desktop\JRT.exe
2014-02-16 11:06 - 2014-02-16 11:06 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\Malwarebytes
2014-02-16 11:05 - 2014-02-16 11:05 - 00001079 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-16 03:01 - 2013-08-14 06:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-16 03:00 - 2011-09-04 13:42 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-15 11:42 - 2014-02-15 11:42 - 00032236 _____ () C:\Users\maddin\Desktop\Addition_2014_02_15.txt
2014-02-15 11:42 - 2014-02-15 11:42 - 00027888 _____ () C:\Users\maddin\Desktop\FRST_2014_02_15.txt
2014-02-15 11:16 - 2014-02-15 11:16 - 00026272 _____ () C:\ComboFix.txt
2014-02-15 11:16 - 2014-02-15 11:09 - 00000000 ____D () C:\Qoobox
2014-02-15 11:16 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-02-15 11:15 - 2014-02-15 11:09 - 00000000 ____D () C:\Windows\erdnt
2014-02-15 11:14 - 2010-11-21 04:47 - 00029252 _____ () C:\Windows\PFRO.log
2014-02-15 11:14 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-02-15 11:13 - 2009-07-14 03:34 - 74186752 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-02-15 11:13 - 2009-07-14 03:34 - 44040192 _____ () C:\Windows\system32\config\components.bak
2014-02-15 11:13 - 2009-07-14 03:34 - 21757952 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-02-15 11:13 - 2009-07-14 03:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-02-15 11:13 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-02-15 11:13 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-02-15 11:07 - 2014-02-15 11:07 - 05183211 ____R (Swearware) C:\Users\maddin\Desktop\ComboFix.exe
2014-02-14 08:38 - 2014-02-14 08:38 - 00032488 _____ () C:\Users\maddin\Desktop\Addition_2014_02_14.txt
2014-02-14 08:38 - 2014-02-14 08:37 - 00029381 _____ () C:\Users\maddin\Desktop\FRST_2014_02_14.txt
2014-02-14 03:09 - 2014-02-14 03:09 - 01166132 _____ () C:\Users\maddin\Desktop\adwcleaner.exe
2014-02-14 03:05 - 2014-02-14 03:05 - 04102163 _____ () C:\Users\maddin\Desktop\tdsskiller.zip
2014-02-14 03:01 - 2014-02-14 02:30 - 00000000 ____D () C:\zoek_backup
2014-02-14 02:41 - 2014-02-14 02:32 - 00023557 _____ () C:\zoek-results.log
2014-02-14 02:32 - 2014-02-14 02:40 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-02-14 02:30 - 2014-02-14 02:30 - 01283584 _____ () C:\Users\maddin\Desktop\zoek.exe
2014-02-13 03:04 - 2011-02-11 18:45 - 01591234 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-11 18:02 - 2014-02-11 18:02 - 00000146 _____ () C:\Users\maddin\Desktop\Dell Touchpad - Verknüpfung.lnk
2014-02-10 23:02 - 2013-03-22 14:55 - 00000072 _____ () C:\Users\Public\LMDebug.log
2014-02-06 13:16 - 2014-02-13 03:00 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 12:30 - 2014-02-13 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 12:30 - 2014-02-13 03:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 12:12 - 2014-02-13 03:00 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 12:07 - 2014-02-13 03:00 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 12:06 - 2014-02-13 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 11:57 - 2014-02-13 03:00 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 11:56 - 2014-02-13 03:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 11:52 - 2014-02-13 03:00 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 11:49 - 2014-02-13 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 11:48 - 2014-02-13 03:00 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 11:48 - 2014-02-13 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 11:38 - 2014-02-13 03:00 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-06 11:32 - 2014-02-13 03:00 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 11:20 - 2014-02-13 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-06 11:17 - 2014-02-13 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 11:11 - 2014-02-13 03:00 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 11:01 - 2014-02-13 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-06 11:00 - 2014-02-13 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-13 03:00 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-06 10:57 - 2014-02-13 03:00 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:52 - 2014-02-13 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-06 10:52 - 2014-02-13 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-06 10:50 - 2014-02-13 03:00 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:49 - 2014-02-13 03:00 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-06 10:47 - 2014-02-13 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-06 10:46 - 2014-02-13 03:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-06 10:25 - 2014-02-13 03:00 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-06 10:25 - 2014-02-13 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-06 10:24 - 2014-02-13 03:00 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 10:22 - 2014-02-13 03:00 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 10:13 - 2014-02-13 03:00 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-06 10:09 - 2014-02-13 03:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-06 10:03 - 2014-02-13 03:00 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-06 09:55 - 2014-02-13 03:00 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:41 - 2014-02-13 03:00 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-06 09:40 - 2014-02-13 03:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-06 09:36 - 2014-02-13 03:00 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-06 09:34 - 2014-02-13 03:00 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-05 10:26 - 2011-09-11 14:19 - 00000000 ____D () C:\Users\maddin\AppData\Local\FreePDF_XP
2014-02-05 09:30 - 2012-10-15 14:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-05 08:11 - 2014-02-05 00:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-02-01 23:46 - 2011-08-31 01:16 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\IrfanView
2014-01-31 23:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-01-28 00:21 - 2011-11-20 00:11 - 00012288 _____ () C:\Users\maddin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-26 09:17 - 2013-10-21 22:11 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-26 09:11 - 2014-01-26 09:11 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-26 09:11 - 2013-06-25 17:19 - 00000000 ____D () C:\Program Files (x86)\Java
Some content of TEMP:
====================
C:\Users\maddin\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-09 11:55
==================== End Of Log ============================
         aber ich wollte auf nummer sicher gehen, dass ich nichts eingefangen habe. frage: hältst du einen regcleaner für sinnvoll und wenn ja, kannst du einen speziellen empfehlen ? nur mal so zum aufräumen ? vielen dank für die ausdauernde unterstützung.  gruß martin | 
|  18.02.2014, 16:37 | #10 | |
| /// the machine /// TB-Ausbilder         |   versehentlich zip-anhang einer email geöffnet und .exe ausgeführt Flash und Firefox updaten. Zitat: 
  Fertig  Die Reihenfolge ist hier entscheidend. 
 Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun  Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist. 
 Anti- Viren Software 
 Zusätzlicher Schutz 
 Sicheres Browsen 
 Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden. 
 Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts 
 Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. 
				__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! | 
|  18.02.2014, 17:46 | #11 | 
|  |   versehentlich zip-anhang einer email geöffnet und .exe ausgeführt so, alles erledigt, alles bestens.  bleibt mir nur noch, mich für die sehr kompetente unterstützung zu bedanken. ich hoffe, ich muss eure hilfe nicht mehr so bald in anspruch nehmen. als bescheidenen dank habe ich mal 20.- gespendet. beste grüße martin | 
|  19.02.2014, 15:35 | #12 | 
| /// the machine /// TB-Ausbilder         |   versehentlich zip-anhang einer email geöffnet und .exe ausgeführt Gern Geschehen    
				__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! | 
|  | 
| Themen zu versehentlich zip-anhang einer email geöffnet und .exe ausgeführt | 
| administrator, adobe, appdata, desktop, email, explorer, falsch, firefox, folge, google, internet, internet explorer, java, logfile, mozilla, registry, rundll, rundll32.exe, scan, software, system, system32, temp, webcam, windows |