Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   GVU Trojaner, Anmeldung im abgesicherten Modus nicht möglich (https://www.trojaner-board.de/137024-gvu-trojaner-anmeldung-abgesicherten-modus-moeglich.html)

Sabine99 22.06.2013 14:49

GVU Trojaner, Anmeldung im abgesicherten Modus nicht möglich
 
Hallo,
diese ist das erste mal, dass ich mir hier Hilfe hole.
Auf meinem PC befindet sich seit einigen Tagen, der GVU Trojaner.
Anmelden im abgesicherten Modus ist nicht möglich, der PC fährt automatisch wieder runter und dann lande ich wieder bei der "normalen" Anwendung.
Ich habe jetzt einige Zeit mit meinem Laptop im Internet gesucht und eine CD mit OTLPE erstellt und damit den PC "gescannt?"
Die beiden Dateien werde ich anhängen.
Der PC hatte vor einigen Monaten, bereits einmal den GVU Virus, aber eine Version, die ich im abgesicherten Modus, löschen der Dateien und anschließendem Virenscan weg bekommen habe.
Habe Vista als Betriebsprogramm, Virenscanner ist Norton 360.
Ich hoffe, ich habe alle relevanten Informationen aufgeführt.

Vielen Dank erst einmal
Sabine 99 :heulen:

schrauber 22.06.2013 14:57

Hi,

Fixen mit OTL

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.
Code:

:OTL
O4 - HKU\*****_ON_C..\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] C:\Users\*****\AppData\Local\Temp\ACh0XXd.exe (Mozilla Foundation)
O20 - HKU\*****_ON_C Winlogon: Shell - (cmd.exe) - C:\Windows\System32\cmd.exe (Microsoft Corporation)
[2013/06/17 00:17:27 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/06/18 13:43:50 | 000,163,139 | ---- | M] () -- C:\Users\*****\AppData\Roaming\2433f433
[2013/06/18 13:43:50 | 000,163,116 | ---- | M] () -- C:\Users\*****\AppData\Local\2433f433
[2013/06/18 13:43:50 | 000,163,066 | ---- | M] () -- C:\ProgramData\2433f433
[2013/03/26 15:23:47 | 095,023,320 | ---- | C] () -- C:\ProgramData\1945825.pad
@Alternate Data Stream - 17 bytes -> C:\Users\*****:zylomtr{000HQ7FF-AD7A-3FG3-4A90-24BL1LF8IVV1}
@Alternate Data Stream - 16 bytes -> C:\Users\*****:zylomtr{002AVPFP-JHLQ-ABE5-RUNH-200OMT85IVUS}
:Commands
[emptytemp]

  • Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Schließe bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<Uhrzeit_Datum>.txt)
    Kopiere nun den Inhalt hier in Deinen Thread

Sabine99 22.06.2013 15:29

Hallo,

habe ein bisschen Zeit benötigt, aber hier ist es.

========== OTL ==========
Registry value HKEY_USERS\*****_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\qcgce2mrvjq91kk1e7pnbb19m52fx deleted successfully.
C:\Users\*****\AppData\Local\Temp\ACh0XXd.exe moved successfully.
Registry value HKEY_USERS\*****_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:cmd.exe deleted successfully.
C:\Windows\System32\cmd.exe moved successfully.
C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1\x86\x86 folder moved successfully.
C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1\x86 folder moved successfully.
C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 folder moved successfully.
C:\Users\*****\AppData\Roaming\2433f433 moved successfully.
C:\Users\*****\AppData\Local\2433f433 moved successfully.
C:\ProgramData\2433f433 moved successfully.
C:\ProgramData\1945825.pad moved successfully.
ADS C:\Users\*****:zylomtr{000HQ7FF-AD7A-3FG3-4A90-24BL1LF8IVV1} deleted successfully.
ADS C:\Users\*****:zylomtr{002AVPFP-JHLQ-ABE5-RUNH-200OMT85IVUS} deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: *****
->Temp folder emptied: 6824373 bytes
->Temporary Internet Files folder emptied: 216164868 bytes
->Java cache emptied: 54468807 bytes
->Google Chrome cache emptied: 856432 bytes
->Flash cache emptied: 58071 bytes

User: IUSR_NMPR

User: Public

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 13420 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 227507 bytes

Total Files Cleaned = 266.00 mb


OTLPE by OldTimer - Version 3.1.48.0 log created on 06222013_172054

Vielen Dank

Sabine99

schrauber 22.06.2013 17:59

Neu booten? :)

Sabine99 22.06.2013 18:03

Hallo Schrauber,

das funktioniert jetzt.:singsing:

Es kommt eine Meldung "Überprüfen Sie die Computersicherheit"
Hatte ich vorher nicht. Was soll ich weiter machen, PC ist noch vom Netz getrennt.

Grüße

Sabine99

schrauber 22.06.2013 18:54

Eins nach dem anderen :). Ab jetzt alles im normalen Windows.

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


Systemscan mit FRST
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Scan.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

Sabine99 22.06.2013 19:45

Hallo Schrauber,

der erste Schritt hat funktioniert.

Anbei die Daten:
# AdwCleaner v2.303 - Datei am 22/06/2013 um 20:00:03 erstellt
# Aktualisiert am 08/06/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : ***** - *****-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\*****\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y2YXSZ0F\adwcleaner2303.exe
# Option [Löschen]


**** [Dienste] ****

Gestoppt & Gelöscht : DefaultTabUpdate
Gestoppt & Gelöscht : WajamUpdater

***** [Dateien / Ordner] *****

Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\*****\AppData\Local\umcqw.dat
Datei Gelöscht : C:\Users\*****\AppData\Local\umcqw_nav.dat
Datei Gelöscht : C:\Users\*****\AppData\Local\umcqw_navps.dat
Ordner Gelöscht : C:\Program Files\Ask.com
Ordner Gelöscht : C:\Program Files\BabylonToolbar
Ordner Gelöscht : C:\Program Files\Common Files\Software Update Utility
Ordner Gelöscht : C:\Program Files\Conduit
Ordner Gelöscht : C:\Program Files\facemoods.com
Ordner Gelöscht : C:\Program Files\FileConverter_1.3
Ordner Gelöscht : C:\Program Files\FLV_Runner
Ordner Gelöscht : C:\Program Files\GamesBar
Ordner Gelöscht : C:\Program Files\PriceGong
Ordner Gelöscht : C:\Program Files\SweetIM
Ordner Gelöscht : C:\Program Files\Viewpoint
Ordner Gelöscht : C:\Program Files\Wajam
Ordner Gelöscht : C:\ProgramData\APN
Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong
Ordner Gelöscht : C:\ProgramData\ParetoLogic
Ordner Gelöscht : C:\ProgramData\SweetIM
Ordner Gelöscht : C:\ProgramData\Viewpoint
Ordner Gelöscht : C:\Users\*****\AppData\Local\Babylon
Ordner Gelöscht : C:\Users\*****\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
Ordner Gelöscht : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif
Ordner Gelöscht : C:\Users\*****\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\*****\AppData\LocalLow\AskToolbar
Ordner Gelöscht : C:\Users\*****\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\*****\AppData\LocalLow\facemoods.com
Ordner Gelöscht : C:\Users\*****\AppData\LocalLow\FileConverter_1.3
Ordner Gelöscht : C:\Users\*****\AppData\LocalLow\FLV_Runner
Ordner Gelöscht : C:\Users\*****\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\DefaultTab
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\DriverCure
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\iWin
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\ParetoLogic
Ordner Gelöscht : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\APN
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DefaultTab
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\FileConverter_1.3
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\FLV_Runner
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\Ask.com
Schlüssel Gelöscht : HKCU\Software\BabylonToolbar
Schlüssel Gelöscht : HKCU\Software\Default Tab
Schlüssel Gelöscht : HKCU\Software\DefaultTab
Schlüssel Gelöscht : HKCU\Software\facemoods.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A81A974F-8A22-43E6-9243-5198FF758DA1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BabylonToolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DefaultTab
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\facemoods
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\FileConverter_1.3 Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\FLV_Runner Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PriceGong
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SoftwareUpdUtility
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wajam
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3BBD3C14-4C16-4989-8366-95BC9179779D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{64182481-4F71-486B-A045-B233BD0DA8FC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{78E516EF-11DE-47A1-8364-A99B917EC5EE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07CEA379-7178-4758-9C80-969876E32395}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{153D7D79-706C-443D-BA98-41CA86982C9D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3BBD3C14-4C16-4989-8366-95BC9179779D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64182481-4F71-486B-A045-B233BD0DA8FC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{78E516EF-11DE-47A1-8364-A99B917EC5EE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gelöscht : HKCU\Software\Wajam
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\Zugo
Schlüssel Gelöscht : HKLM\Software\APN
Schlüssel Gelöscht : HKLM\Software\AskToolbar
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\BabylonToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\DefaultTabBHO.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\priam_bho.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\PriceGongIE.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\b
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Babylon.dskBnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylnApp.appCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{07CEA379-7178-4758-9C80-969876E32395}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{153D7D79-706C-443D-BA98-41CA86982C9D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3BBD3C14-4C16-4989-8366-95BC9179779D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{78E516EF-11DE-47A1-8364-A99B917EC5EE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.escrtSrvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\facemoods.xtrnl
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\facemoodsApp.appCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\F479A18A22A86E3429341589FF57D81A
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\FA20CB7A821113A4CB8FA1E38E303D3B
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\F479A18A22A86E3429341589FF57D81A
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\FA20CB7A821113A4CB8FA1E38E303D3B
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PriceFactorIE.PriceGongBHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PriceFactorIE.PriceGongBHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PriceGongIE.PriceGongCtrl
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PriceGongIE.PriceGongCtrl.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sim-packages
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3201318
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3241949
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.sweetie
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{8B3372D0-09F0-41A5-8D9B-134E148672FB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamBHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\Default Tab
Schlüssel Gelöscht : HKLM\Software\facemoods.com
Schlüssel Gelöscht : HKLM\Software\FileConverter_1.3
Schlüssel Gelöscht : HKLM\Software\FLV_Runner
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif
Schlüssel Gelöscht : HKLM\Software\InstallIQ
Schlüssel Gelöscht : HKLM\Software\MetaStream
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{059B7FB7-340F-4825-8359-95621BB54FC5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3717A8F6-7842-4713-BBDF-ACFAB5A81B09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{449725C9-9524-41C6-AF1E-BF29F9CC469F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2291587-2AD0-48CE-BD6A-95E87E7A8C47}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3BBD3C14-4C16-4989-8366-95BC9179779D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486B-A045-B233BD0DA8FC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{78E516EF-11DE-47A1-8364-A99B917EC5EE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07CEA379-7178-4758-9C80-969876E32395}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{153D7D79-706C-443D-BA98-41CA86982C9D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\120DFADEB50841F408F04D2A278F9509
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2BDF3E992C0908741B7C11F4B4E0F775
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B3BC4CF5ECE1F54BBA174C13A1AB907
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75D5168E5E176C24981B4E5DBD991078
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8724E58E6C7D00C48A0D4F3345EB2C26
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB676B0E1B9EFA049B9F7DDDA9645734
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31BBB0B825EDEF45AB0FE7099C68C81
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B471D8D7319336B4CA89374ED0D7B806
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5BAE2ED018083A4C8DA86D6E3F4B024
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC30043663AA2CA4DA1DAA9CA5FDCC75
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BEABAA33A5E68374DBF197F2A00CD011
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB61AF52AD64B6B45930BE969F316720
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDC83385E6C239F4C876A77A37DF581D
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F479A18A22A86E3429341589FF57D81A
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FA20CB7A821113A4CB8FA1E38E303D3B
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A81A974F-8A22-43E6-9243-5198FF758DA1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facemoods
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileConverter_1.3 Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FLV_Runner Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PriceGong
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
Schlüssel Gelöscht : HKLM\Software\Viewpoint
Schlüssel Gelöscht : HKLM\Software\Wajam
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{3BBD3C14-4C16-4989-8366-95BC9179779D}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{78E516EF-11DE-47A1-8364-A99B917EC5EE}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{3BBD3C14-4C16-4989-8366-95BC9179779D}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{78E516EF-11DE-47A1-8364-A99B917EC5EE}]
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{8a9386b4-e958-4c4c-adf4-8f26db3e4829}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{3BBD3C14-4C16-4989-8366-95BC9179779D}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{78E516EF-11DE-47A1-8364-A99B917EC5EE}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{3BBD3C14-4C16-4989-8366-95BC9179779D}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{78E516EF-11DE-47A1-8364-A99B917EC5EE}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16490


Leider gelingt es mir nicht das Junkware removal tool herunter zu laden.
Ich habe Norton deaktiviert. (Hoffe ich doch)
Bekomme bei meinen Versuchen immer die Meldung

Error during execution
c: JRT\get.bat
Das System kann die angegebene Datei nicht finden.

Da benötige ich noch mal Hilfe. (Das Ganze geht nämlich über meine sonstigen Tätigkeiten am PC weit hinaus :lach:)

Danke

Sabine99

schrauber 23.06.2013 08:39

Lass JRT weg und mach den Rest. Und poste die Logs bitte in Codetags :)

So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

Sabine99 23.06.2013 11:05

Hallo Schrauber,
anbei die Daten.

1. ADW Cleaner
Code:

========== OTL ==========
Registry value HKEY_USERS\Heggensberger_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\qcgce2mrvjq91kk1e7pnbb19m52fx deleted successfully.
C:\Users\heggensberger\AppData\Local\Temp\ACh0XXd.exe moved successfully.
Registry value HKEY_USERS\Heggensberger_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:cmd.exe deleted successfully.
C:\Windows\System32\cmd.exe moved successfully.
C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1\x86\x86 folder moved successfully.
C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1\x86 folder moved successfully.
C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 folder moved successfully.
C:\Users\heggensberger\AppData\Roaming\2433f433 moved successfully.
C:\Users\heggensberger\AppData\Local\2433f433 moved successfully.
C:\ProgramData\2433f433 moved successfully.
C:\ProgramData\1945825.pad moved successfully.
ADS C:\Users\Heggensberger:zylomtr{000HQ7FF-AD7A-3FG3-4A90-24BL1LF8IVV1} deleted successfully.
ADS C:\Users\Heggensberger:zylomtr{002AVPFP-JHLQ-ABE5-RUNH-200OMT85IVUS} deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users

Danke und Grüße

Sabine99
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: heggensberger
->Temp folder emptied: 6824373 bytes
->Temporary Internet Files folder emptied: 216164868 bytes
->Java cache emptied: 54468807 bytes
->Google Chrome cache emptied: 856432 bytes
->Flash cache emptied: 58071 bytes
 
User: IUSR_NMPR
 
User: Public
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 13420 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 227507 bytes
 
Total Files Cleaned = 266.00 mb
 
 
OTLPE by OldTimer - Version 3.1.48.0 log created on 06222013_172054

2. JRT nicht durchgeführt

3. FRST

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-06-2013
Ran by ***** (administrator) on 23-06-2013 11:45:06
Running from C:\Users\*****\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y2YXSZ0F
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
() C:\Program Files\PC Speed Up\PCSUService.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
() C:\Windows\system32\securitz.exe
() C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
(Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe
(Wajam) C:\Program Files\Wajam\Updater\WajamUpdater.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Lexware GmbH & Co. KG) C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe
(ODSoft multimedia) C:\Program Files\Sceneo\AbsolutTV\Services\ODSBC\ODSBCApp.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Smartbar) C:\Users\*****\AppData\Local\Smartbar\Application\SnapDo.exe
(Hewlett-Packard Co.) C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RaUI.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(MindSpark) C:\PROGRA~1\INBOXA~2\bar\1.bin\1gsrchmn.exe
(VER_COMPANY_NAME) C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbrmon.exe
(COMPANYVERS_NAME) C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe
(MindSpark) C:\Program Files\InboxAce_1g\bar\1.bin\1gHighIn.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [UpdatePPShortCut] "C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\PowerProducer" update "Software\CyberLink\PowerProducer\4.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM\...\Run: []  [x]
HKLM\...\Run: [Windows Defender] %programfiles%\windows defender\msascui.exe -hide [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [LexwareInfoService] c:\program files\common files\lexware\update manager\lxupdatemanager.exe /autostart [339240 2008-11-03] (Lexware GmbH & Co. KG)
HKLM\...\Run: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\nbkeyscan.exe" [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [RemoteControl] "c:\program files\homecinema\powerdvd\pdvdserv.exe" [71216 2007-02-09] (Cyberlink Corp.)
HKLM\...\Run: [TVBroadcast] c:\program files\sceneo\absoluttv\services\odsbc\odsbcapp.exe [797696 2007-08-08] (ODSoft multimedia)
HKLM\...\Run: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe [90112 2006-11-29] (Ulead Systems, Inc.)
HKLM\...\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [Ocs_SM] C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizer.exe [106496 2013-06-22] (OCS)
HKLM\...\Run: [InboxAce Search Scope Monitor] "C:\PROGRA~1\INBOXA~2\bar\1.bin\1gsrchmn.exe" /m=2 /w /h [44784 2013-06-23] (MindSpark)
HKLM\...\Run: [InboxAce_1g Browser Plugin Loader] C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbrmon.exe [30096 2013-06-23] (VER_COMPANY_NAME)
HKCU\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\nmbgmonitor.exe" [202024 2007-10-15] (Nero AG)
HKCU\...\Run: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autorun [1233920 2009-04-11] (Microsoft Corporation)
HKCU\...\Run: [SearchEngineProtection] C:\Program Files\GamesBar\update\SearchEngineProtection.exe [x]
HKCU\...\Run: [AOL Dialer] C:\Program Files\Common Files\AOL\ACS\AOlDial.exe [x]
HKCU\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] C:\Users\HEGGEN~1\AppData\Local\Temp\ACh0XXd.exe [x]
HKCU\...\Run: [PCSpeedUp] C:\Program Files\PC Speed Up\PCSUNotifier.exe [256448 2012-12-14] ()
HKCU\...\Run: [Browser Infrastructure Helper] C:\Users\*****\AppData\Local\Smartbar\Application\SnapDo.exe startup [20992 2013-06-09] (Smartbar)
HKCU\...\Winlogon: [Shell] cmd.exe <==== ATTENTION
HKCR\...409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e\n. ATTENTION! ====> ZeroAccess
HKCU\...\Command Processor: "C:\Users\HEGGEN~1\AppData\Local\Temp\ACh0XXd.exe" <======= ATTENTION
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)

==================== Internet (Whitelisted) ====================

ProxyServer: 192.168.1.1:80
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.mywebsearch.com/index.jhtml?n=77DE8857&p2=^YO^xdm155^YY^de&ptb=5E276747-34FA-4490-AD7C-A0004CE67D9D&si=KI_INB_FIG_GER_24
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=DE&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=ds&q={searchTerms}&installDate={installDate}
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.gamesgofree.com/?utm_source=hpe&utm_medium=hp3
URLSearchHook: (No Name) - {5fdb0cd8-5760-44d1-8d13-a78bf558c3c7} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll (MindSpark)
SearchScopes: HKLM - {8fe8d013-c3fd-4802-af48-79274e9f969e} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^YO^xdm155^YY^de&si=KI_INB_FIG_GER_24&ptb=5E276747-34FA-4490-AD7C-A0004CE67D9D&psa=&ind=2013062305&st=sb&n=77fce4a1&searchfor={searchTerms}
HKCU SearchScopes: DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=DE&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=ds&q={searchTerms}&installDate={installDate}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=DE&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=ds&q={searchTerms}&installDate={installDate}
SearchScopes: HKCU - {8fe8d013-c3fd-4802-af48-79274e9f969e} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^YO^xdm155^YY^de&si=KI_INB_FIG_GER_24&ptb=5E276747-34FA-4490-AD7C-A0004CE67D9D&psa=&ind=2013062305&st=sb&n=77fce4a1&searchfor={searchTerms}
BHO: GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
BHO: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Search Assistant BHO - {9359da42-06fb-46f2-9e4a-05c05b98a5ef} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll (MindSpark)
BHO: Wajam - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll (Wajam)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.21.5\bh\delta.dll (Delta-search.com)
BHO: Toolbar BHO - {d5a1d22b-9e17-454f-8ecd-83c578fb3983} - C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbar.dll (MindSpark)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.21.5\deltaTlbr.dll (Delta-search.com)
Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM - InboxAce - {3775afd7-5921-4571-968f-85a631203d1c} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll (MindSpark)
Toolbar: HKCU -InboxAce - {3775AFD7-5921-4571-968F-85A631203D1C} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll (MindSpark)
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Chrome:
=======
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013"
CHR Extension: (Snap.Do ) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0
CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1
CHR Extension: (Norton Identity Protection) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.11.8_0
CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

========================== Services (Whitelisted) =================

R2 InboxAce_1gService; C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe [42504 2013-06-23] (COMPANYVERS_NAME)
R2 N360; C:\Program Files\Norton 360\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation)
R2 PCSUService; C:\Program Files\PC Speed Up\PCSUService.exe [320448 2012-12-14] ()
R2 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe [75040 2008-09-05] (Ralink Technology, Corp.)
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
R2 Robocopz; C:\Windows\system32\securitz.exe [68608 2013-06-22] ()
R2 SearchAnonymizer; C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [40960 2013-06-22] ()
R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1681408 2007-08-16] (Buhl Data Service GmbH)
R2 WajamUpdater; C:\Program Files\Wajam\Updater\WajamUpdater.exe [109064 2013-05-02] (Wajam)
S2 BrowserDefendert; BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [x]

==================== Drivers (Whitelisted) ====================

R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130531.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
S3 CH375; C:\Windows\System32\Drivers\CH375WDM.SYS [28403 2011-03-14] (www.winchiphead.com)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2013-04-13] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2013-04-13] (Symantec Corporation)
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc.              )
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130621.001\IDSvix86.sys [386720 2013-04-12] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVENG.SYS [93272 2013-05-22] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVEX15.SYS [1611992 2013-05-22] (Symantec Corporation)
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [645120 2008-08-21] (Ralink Technology Corp.)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
S3 SRTSP; C:\Windows\System32\Drivers\N360\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-22] (Symantec Corporation)
R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [36512 2013-03-05] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\N360\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-30] (America Online, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-23 11:44 - 2013-06-23 11:44 - 00000000 ____D C:\FRST
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-23 11:24 - 2013-06-23 11:24 - 00000000 ___AD C:\Program Files\InboxAce_1gEI
2013-06-23 11:24 - 2013-06-23 11:24 - 00000000 ____D C:\Program Files\InboxAce_1g
2013-06-22 23:20 - 2013-06-22 23:20 - 00000000 ____D C:\_OTL
2013-06-22 22:02 - 2013-06-22 22:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 20:31 - 2013-06-22 20:33 - 00000000 ____D C:\JRT
2013-06-22 20:31 - 2013-06-22 20:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 20:25 - 2013-06-22 20:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 20:24 - 2013-06-22 20:25 - 00000000 ____D C:\Users\*****\AppData\Local\Smartbar
2013-06-22 20:23 - 2013-06-22 20:24 - 00000000 ____D C:\Program Files\Wajam
2013-06-22 20:23 - 2013-06-22 20:24 - 00000000 ____A C:\END
2013-06-22 20:23 - 2013-06-22 20:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Users\*****\AppData\Local\Wajam
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:18 - 2013-06-23 11:12 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-22 20:18 - 2013-06-22 21:34 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-22 20:18 - 2013-06-22 20:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 20:17 - 2013-06-22 20:17 - 00000000 ____D C:\Users\*****\AppData\Roaming\Delta
2013-06-22 20:17 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-22 20:17 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Delta
2013-06-22 20:16 - 2013-06-22 20:17 - 00000000 ____D C:\Users\*****\AppData\Roaming\BabSolution
2013-06-22 20:16 - 2013-06-22 20:16 - 00068608 ____A () C:\Windows\System32\securitz.exe
2013-06-22 20:16 - 2013-06-22 20:16 - 00001446 ____A C:\Users\UpdatusUser\Desktop\Amazon.lnk
2013-06-22 20:16 - 2013-06-22 20:16 - 00001446 ____A C:\Users\*****\Desktop\Amazon.lnk
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\OCS
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\DesktopIconForAmazon
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Babylon
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\ProgramData\Babylon
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:00 - 2013-06-22 20:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 19:58 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:18 - 2012-08-21 13:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2013-06-17 06:17 - 2013-06-17 06:18 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2013-06-17 06:17 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-14 13:38 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-14 13:38 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-14 13:38 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-14 13:38 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-14 13:38 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-14 13:38 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-14 13:38 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-14 13:38 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-14 13:38 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-14 13:38 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-14 13:32 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-14 13:31 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-14 13:31 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-14 13:31 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-14 13:31 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-14 13:31 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-14 13:31 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll

==================== One Month Modified Files and Folders ========

2013-06-23 11:44 - 2013-06-23 11:44 - 00000000 ____D C:\FRST
2013-06-23 11:31 - 2010-01-26 15:57 - 00002591 ____A C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-23 11:24 - 2013-06-23 11:24 - 00000000 ___AD C:\Program Files\InboxAce_1gEI
2013-06-23 11:24 - 2013-06-23 11:24 - 00000000 ____D C:\Program Files\InboxAce_1g
2013-06-23 11:15 - 2010-01-23 16:48 - 01552636 ____A C:\Windows\WindowsUpdate.log
2013-06-23 11:12 - 2013-06-22 20:18 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-23 11:10 - 2011-11-22 19:11 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-23 11:08 - 2010-01-24 10:55 - 00000000 ____D C:\ProgramData\NVIDIA
2013-06-23 11:08 - 2010-01-23 17:02 - 01032624 ____A C:\Windows\PFRO.log
2013-06-23 11:08 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-23 11:08 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-23 11:08 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-22 23:20 - 2013-06-22 23:20 - 00000000 ____D C:\_OTL
2013-06-22 22:02 - 2013-06-22 22:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 21:59 - 2010-01-23 17:06 - 00000000 ___AD C:\users\*****
2013-06-22 21:56 - 2006-11-02 15:01 - 00032530 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-22 21:51 - 2011-11-22 19:11 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-22 21:50 - 2012-08-22 20:11 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-22 21:34 - 2013-06-22 20:18 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-22 20:33 - 2013-06-22 20:31 - 00000000 ____D C:\JRT
2013-06-22 20:31 - 2013-06-22 20:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 20:25 - 2013-06-22 20:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 20:25 - 2013-06-22 20:24 - 00000000 ____D C:\Users\*****\AppData\Local\Smartbar
2013-06-22 20:24 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\Wajam
2013-06-22 20:24 - 2013-06-22 20:23 - 00000000 ____A C:\END
2013-06-22 20:23 - 2013-06-22 20:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Users\*****\AppData\Local\Wajam
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:18 - 2013-06-22 20:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 20:17 - 2013-06-22 20:17 - 00000000 ____D C:\Users\*****\AppData\Roaming\Delta
2013-06-22 20:17 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-22 20:17 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Delta
2013-06-22 20:17 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\BabSolution
2013-06-22 20:17 - 2011-10-21 13:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-22 20:16 - 2013-06-22 20:16 - 00068608 ____A () C:\Windows\System32\securitz.exe
2013-06-22 20:16 - 2013-06-22 20:16 - 00001446 ____A C:\Users\UpdatusUser\Desktop\Amazon.lnk
2013-06-22 20:16 - 2013-06-22 20:16 - 00001446 ____A C:\Users\*****\Desktop\Amazon.lnk
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\OCS
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\DesktopIconForAmazon
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Babylon
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\ProgramData\Babylon
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:04 - 2011-04-17 19:29 - 00000000 ____D C:\Windows\System32\Drivers\N360
2013-06-22 20:03 - 2011-04-17 19:30 - 00002023 ____A C:\Users\Public\Desktop\Norton 360.lnk
2013-06-22 20:00 - 2013-06-22 20:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 19:58 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-22 19:54 - 2013-01-09 21:21 - 00001935 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-22 19:23 - 2011-04-17 19:30 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS
2013-06-22 19:23 - 2011-04-17 19:30 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT
2013-06-18 19:47 - 2013-02-02 13:52 - 00000524 ____A C:\Users\*****\Desktop\eMail (12).website
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:19 - 2012-05-21 20:02 - 00000000 ____D C:\Users\*****\AppData\Roaming\Apple Computer
2013-06-17 06:19 - 2010-01-26 10:43 - 00000000 ____D C:\Users\*****\AppData\Local\Apple Computer
2013-06-17 06:18 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:17 - 2013-06-17 06:09 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-17 06:17 - 2010-02-13 14:59 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-06-17 06:17 - 2010-02-13 14:54 - 00000000 ____D C:\ProgramData\Apple
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2012-05-21 06:11 - 00001690 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2013-06-17 06:09 - 2008-01-23 14:46 - 00000000 ____D C:\Program Files\QuickTime
2013-06-15 19:25 - 2010-12-28 12:53 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-06-14 17:02 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-06-14 16:48 - 2012-08-22 20:11 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-14 16:48 - 2011-09-04 07:42 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-14 16:43 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-14 13:36 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e

Files to move or delete:
====================
C:\ProgramData\nvModes.dat

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-23 11:14

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---


und die Addition

Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-06-2013
Ran by ***** at 2013-06-23 11:45:25
Running from C:\Users\*****\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y2YXSZ0F
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

 Update for Microsoft Office 2007 (KB2508958)
32 Bit HP CIO Components Installer (Version: 3.1.1)
6500_E709_eDocs (Version: 1.00.0000)
6500_E709_Help (Version: 1.00.0000)
6500_E709a (Version: 50.0.165.000)
7-Zip 9.20
Adobe Flash Player 11 ActiveX (Version: 11.7.700.224)
Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7)
Apple Application Support (Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (Version: 2.1.3.127)
Bonjour (Version: 3.0.0.10)
bpd_scan (Version: 3.00.0000)
BPDSoftware (Version: 50.0.165.000)
BPDSoftware_Ini (Version: 1.00.0000)
BrowserDefender
BufferChm (Version: 120.0.194.000)
CALC
Cisco EAP-FAST Module (Version: 2.1.6)
Cisco LEAP Module (Version: 1.0.12)
Cisco PEAP Module (Version: 1.0.13)
Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000)
CVE-2012-4969
Delta Chrome Toolbar
Delta toolbar  (Version: 1.8.21.5)
Desktop Icon für Amazon (Version: 1.0.1 (de))
Destination Component (Version: 110.0.0.0)
DeviceDiscovery (Version: 120.0.194.000)
DocMgr (Version: 120.0.000.000)
DocProc (Version: 12.0.0.0)
EcrSystem (Version: 1.0.0)
ElsterFormular-Upgrade (Version: 13.3.0.9066)
Fax (Version: 120.0.194.000)
FreePDF (Remove only)
GamesBar (W) (Version: 3.2.0.36)
Google Chrome (Version: 27.0.1453.116)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.4.3607.2246)
Google Update Helper (Version: 1.3.21.145)
GPBaseService2 (Version: 130.0.371.000)
GPL Ghostscript (Version: 9.02)
HP Customer Participation Program 12.0 (Version: 12.0)
HP Document Manager 2.0 (Version: 2.0)
HP Imaging Device Functions 12.0 (Version: 12.0)
HP Officejet 6500 E709 Series (Version: 12.0)
HP Smart Web Printing (Version: 4.05)
HP Solution Center 13.0 (Version: 13.0)
HPDiagnosticAlert (Version: 1.00.0000)
HPProductAssistant (Version: 130.0.371.000)
HPSSupply (Version: 120.0.194.000)
iCloud (Version: 2.1.2.8)
InboxAce Toolbar
Intel(R) PRO Network Connections 12.2.41.0 (Version: 12.2.41.0)
iTunes (Version: 11.0.4.4)
Java Auto Updater (Version: 2.0.6.1)
Java(TM) 6 Update 29 (Version: 6.0.290)
Java(TM) 6 Update 4 (Version: 1.6.0.40)
Jewel Quest Deluxe (HKCU Version: 1.0.0)
Jewel Quest Solitaire Deluxe (HKCU Version: 1.0.0)
Lexware buchhalter 2008 (Version: 13.00.00.0090)
Lexware buchhalter 2010 (Version: 15.10.00.0010)
Lexware buchhalter Aktualisierung Februar 2008, Version 13.10 (Version: 13.10.00.0015)
Lexware Elster (Version: 10.10.00.0110)
Lexware Info Service (Version: 2.61.00.0033)
MakeDisc (Version: 3.0.2516)
MarketResearch (Version: 120.0.226.000)
MCE Software Encoder 1.1 (Version: 1.1.0.1918)
MediaShow (Version: 3.0.4325)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2698023)
Microsoft .NET Framework 1.1 Security Update (KB2742597)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1)
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 4.0.60310.0)
Microsoft VC9 runtime libraries (Version: 2.0.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Works (Version: 9.7.0621)
Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0)
MSVCSetup (Version: 1.00.0000)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Nero 8 Essentials (Version: 8.10.284)
neroxml (Version: 1.0.0)
Network (Version: 120.0.194.000)
Norton 360 (Version: 20.4.0.40)
NVIDIA 3D Vision Controller Driver (Version: 280.10)
NVIDIA 3D Vision Controller-Treiber 280.10 (Version: 280.10)
NVIDIA 3D Vision Treiber 311.06 (Version: 311.06)
NVIDIA Grafiktreiber 311.06 (Version: 311.06)
NVIDIA Install Application (Version: 2.1002.108.688)
NVIDIA PhysX (Version: 9.10.0514)
NVIDIA PhysX-Systemsoftware 9.10.0514 (Version: 9.10.0514)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.1106)
NVIDIA Systemsteuerung 311.06 (Version: 311.06)
NVIDIA Update 1.11.3 (Version: 1.11.3)
NVIDIA Update Components (Version: 1.11.3)
OCR Software by I.R.I.S. 12.0 (Version: 12.0)
PC Speed Up - Vollständige Deinstallation (Version: 3.2.4)
PhotoNow! (Version: 1.0.4310)
PowerDirector (Version: 6.5.2209a)
PowerDVD (Version: 7.0.3118.0)
PowerProducer (Version: 4.2.2504)
ProductContext (Version: 50.0.165.000)
PVSonyDll (Version: 1.00.0001)
QuickTime (Version: 7.74.80.86)
Ralink RT2870 Wireless LAN Card (Version: 1.0.4.0)
RedMon - Redirection Port Monitor
RENESIS® Player Browser Plugins (Version: 1.1.1)
RTC Client API v1.2 (Version: 1.2.0000)
Scan (Version: 12.0.0.0)
Sceneo AbsolutTV
SearchAnonymizer (Version: 1.0.1 (de))
Servicepack Datumsaktualisierung (Version: 1.00.00.0005)
Shop for HP Supplies (Version: 12)
Smart PC Cleaner v3.0 (Version: 3.0)
SmartWebPrinting (Version: 120.0.194.000)
Snap.Do (Version: 1.28.1.10797)
Snap.Do Engine (HKCU Version: 1.28.1.10797)
SolutionCenter (Version: 130.0.373.000)
Status (Version: 120.0.194.000)
Toolbox (Version: 120.0.194.000)
TrayApp (Version: 120.0.194.000)
Ulead PhotoImpact 12 (Version: 12.0)
UnloadSupport (Version: 11.0.0)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update für Microsoft Office Excel 2007 Help (KB963678)
Update für Microsoft Office Powerpoint 2007 Help (KB963669)
Update für Microsoft Office Word 2007 Help (KB963665)
VCRedistSetup (Version: 1.0.0)
Wajam (Version: 1.80)
WebReg (Version: 120.0.194.000)
Windows Mobile Device Updater Component (Version: 04.08.2345.00)
Zune (Version: 04.08.2345.00)
Zune Language Pack (CHS) (Version: 04.08.2345.00)
Zune Language Pack (CHT) (Version: 04.08.2345.00)
Zune Language Pack (CSY) (Version: 04.08.2345.00)
Zune Language Pack (DAN) (Version: 04.08.2345.00)
Zune Language Pack (DEU) (Version: 04.08.2345.00)
Zune Language Pack (ELL) (Version: 04.08.2345.00)
Zune Language Pack (ESP) (Version: 04.08.2345.00)
Zune Language Pack (FIN) (Version: 04.08.2345.00)
Zune Language Pack (FRA) (Version: 04.08.2345.00)
Zune Language Pack (HUN) (Version: 04.08.2345.00)
Zune Language Pack (IND) (Version: 04.08.2345.00)
Zune Language Pack (ITA) (Version: 04.08.2345.00)
Zune Language Pack (JPN) (Version: 04.08.2345.00)
Zune Language Pack (KOR) (Version: 04.08.2345.00)
Zune Language Pack (MSL) (Version: 04.08.2345.00)
Zune Language Pack (NLD) (Version: 04.08.2345.00)
Zune Language Pack (NOR) (Version: 04.08.2345.00)
Zune Language Pack (PLK) (Version: 04.08.2345.00)
Zune Language Pack (PTB) (Version: 04.08.2345.00)
Zune Language Pack (PTG) (Version: 04.08.2345.00)
Zune Language Pack (RUS) (Version: 04.08.2345.00)
Zune Language Pack (SVE) (Version: 04.08.2345.00)

==================== Restore Points  =========================


==================== Scheduled Tasks (whitelisted) =============

Task: {18998898-BEE2-40C0-B357-9ACD9D09D1BE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-14] (Adobe Systems Incorporated)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {447514A3-9452-4789-B411-E5C65175D705} - System32\Tasks\Start Registry Reviver => C:\Program Files\Reviversoft\Registry Reviver\RegistryReviver.exe No File
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation)
Task: {47BBF07F-2C14-478D-B834-588812EC701A} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files\Norton 360\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {4EB3E32D-1459-4F2D-8DAB-8A07CACD4314} - System32\Tasks\PC SpeedUp Service Deactivator => C:\Program Files\PC Speed Up\PCSUSD.exe [2012-12-14] ()
Task: {511E17BB-0D4E-43E2-894B-6B425BA47C5E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {62A78C06-6A05-4F07-B631-0693ED935194} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation)
Task: {6C23F747-DA4B-492C-9E9D-F32949CE0893} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton 360\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation)
Task: {95E2B338-1161-4814-9680-A7C997C5AF55} - System32\Tasks\BrowserDefendert => C:\Windows\system32\sc.exe [2006-11-02] (Microsoft Corporation)
Task: {9B38F5FE-9F6E-4FE0-A34A-3F013E6C755D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-11-22] (Google Inc.)
Task: {9CADA731-EECC-44E1-B935-EC53FA3E530F} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - ***** => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {A3C560AA-B9A0-450B-9167-A98E5E35A8E4} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files\Norton 360\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {A4944DD7-4B0D-403F-A359-0CE4E495459C} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe No File
Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation)
Task: {BFCCF36D-4D87-4DE7-8EE1-97209975D68F} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {C2D128C7-930F-4E34-BD90-D8EB71A4ADAD} - System32\Tasks\EPUpdater => C:\Users\HEGGEN~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [2013-06-06] ()
Task: {DF89FF18-14C6-47BA-A108-E5BBA33E9277} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-11-22] (Google Inc.)
Task: {E040D26E-843B-4749-9F2E-F9E2EBAE488B} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] ()

==================== Faulty Device Manager Devices =============

Name: SM-Bus-Controller
Description: SM-Bus-Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/22/2013 08:35:04 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (06/22/2013 08:29:21 PM) (Source: Application Error) (User: )
Description: Fehlerhafte Anwendung Explorer.EXE, Version 6.0.6002.18005, Zeitstempel 0x49e01da5, fehlerhaftes Modul SHLWAPI.dll, Version 6.0.6002.18738, Zeitstempel 0x50ada1fd, Ausnahmecode 0xc0000005, Fehleroffset 0x00020f35,
Prozess-ID 0x55c, Anwendungsstartzeit Explorer.EXE0.

Error: (06/22/2013 08:26:31 PM) (Source: Application Error) (User: )
Description: Fehlerhafte Anwendung iexplore.exe, Version 9.0.8112.16490, Zeitstempel 0x51955cca, fehlerhaftes Modul kernel32.dll, Version 6.0.6002.18704, Zeitstempel 0x5065ccb6, Ausnahmecode 0xc0000005, Fehleroffset 0x000495e9,
Prozess-ID 0xf28, Anwendungsstartzeit iexplore.exe0.

Error: (06/22/2013 08:24:18 PM) (Source: Application Hang) (User: )
Description: Programm iexplore.exe, Version 9.0.8112.16490 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen.
Prozess-ID: 1f2c
Anfangszeit: 01ce6f75475c9e40
Zeitpunkt der Beendigung: 0

Error: (06/18/2013 08:38:33 PM) (Source: Windows Search Service) (User: )
Description: Die Anwendung kann nicht initialisiert werden.

Kontext: Windows Anwendung


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (06/18/2013 08:38:33 PM) (Source: Windows Search Service) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (06/18/2013 08:38:33 PM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Element nicht gefunden.  (0x80070490)

Error: (06/18/2013 08:38:33 PM) (Source: Windows Search Service) (User: )
Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)

Error: (06/18/2013 08:38:33 PM) (Source: Windows Search Service) (User: )
Description: Die Eigenschaftenspeicherdaten können vom Windows-Suchdienst nicht geladen werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
        0x%08x (0xc0041800 - Der Inhaltsindex kann nicht gelesen werden.  )

Error: (06/18/2013 08:38:33 PM) (Source: Windows Search Service) (User: )
Description: Der Suchdienst hat beschädigte Datendateien im Index erkannt. Der Dienst versucht, dieses Problem durch Neuerstellung des Index automatisch zu beheben.


Details:
        Die Inhaltsindex-Metadaten können nicht gelesen werden.  (0xc0041801)


System errors:
=============
Error: (06/23/2013 11:45:00 AM) (Source: Service Control Manager) (User: )
Description: BrowserDefendert%%2

Error: (06/23/2013 11:44:00 AM) (Source: Service Control Manager) (User: )
Description: BrowserDefendert%%2

Error: (06/23/2013 11:43:00 AM) (Source: Service Control Manager) (User: )
Description: BrowserDefendert%%2

Error: (06/23/2013 11:42:00 AM) (Source: Service Control Manager) (User: )
Description: BrowserDefendert%%2

Error: (06/23/2013 11:41:00 AM) (Source: Service Control Manager) (User: )
Description: BrowserDefendert%%2

Error: (06/23/2013 11:40:00 AM) (Source: Service Control Manager) (User: )
Description: BrowserDefendert%%2

Error: (06/23/2013 11:39:00 AM) (Source: Service Control Manager) (User: )
Description: BrowserDefendert%%2

Error: (06/23/2013 11:38:00 AM) (Source: Service Control Manager) (User: )
Description: BrowserDefendert%%2

Error: (06/23/2013 11:37:00 AM) (Source: Service Control Manager) (User: )
Description: BrowserDefendert%%2

Error: (06/23/2013 11:36:00 AM) (Source: Service Control Manager) (User: )
Description: BrowserDefendert%%2


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Percentage of memory in use: 38%
Total physical RAM: 3069.45 MB
Available physical RAM: 1876.31 MB
Total Pagefile: 6351.94 MB
Available Pagefile: 5081.08 MB
Total Virtual: 2047.88 MB
Available Virtual: 1882.24 MB

==================== Drives ================================

Drive c: (BOOT) (Fixed) (Total:445.76 GB) (Free:361.57 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVER) (Fixed) (Total:19.99 GB) (Free:5.22 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 2BAB359D)
Partition 1: (Active) - (Size=446 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended)

==================== End Of Log ============================


schrauber 23.06.2013 16:06


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST Log. Noch Probleme? :)

Sabine99 23.06.2013 21:33

Hallo Schrauber,

Eset Onlinescan habe ich gemacht.

Anbei das file:
Code:

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=a0300fd08f65924eaeb912e75fd50a47
# engine=14135
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-23 07:57:56
# local_time=2013-06-23 09:57:56 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=3592 16777213 100 93 93161 122679972 0 0
# compatibility_mode=5892 16776574 66 95 105941676 209550204 0 0
# scanned=403446
# found=4
# cleaned=0
# scan_time=15972
sh=106228D67FF3CEB63C349E5B9AF4A1F17A0AAFE4 ft=1 fh=a2f611a66ef2062d vn="a variant of Win32/SpeedingUpMyPC application" ac=I fn="C:\Program Files\Smart PC Cleaner\SmartPCCleaner.exe"
sh=1BFFA360A90A52AD75740EF7BDE8BB2007FE0823 ft=1 fh=4fb0814f538ae527 vn="a variant of Win32/Adware.SpeedingUpMyPC.C application" ac=I fn="C:\Program Files\Smart PC Cleaner\SPCSmartScan.exe"
sh=8C447DFBFEBC6B831E4C76DA47AF2F9CDBD62196 ft=1 fh=e0dfd5bc3e9d9eb5 vn="a variant of Win32/BHO.OGC trojan" ac=I fn="C:\Windows\System32\securitz.exe"
sh=9C58EF6120DF869D7A12F207651AFF3694A08E4C ft=1 fh=72e19e71b0950adc vn="Win32/Moure.D trojan" ac=I fn="C:\_OTL\MovedFiles\06222013_172054\C_Users\*****\AppData\Local\Temp\ACh0XXd.exe"

Leider funktioniert security check nicht.

Es kommt folgende Meldung:
C:Useres\****~1\AppData\Local\Temp\RarSFX0\SecurityCheck\SecurityCheck.bat
konnte nicht gefunden werden. Stellen Sie sicher, dass Sie den Namen richtig eingegeben haben und wiederholen Sie den Vorgang

Mache für heute Schluss, es kann sein, dass ich mich erst (spätestens) am Donnerstag wieder melde. Ist aber noch nicht ganz sicher, wenn möglich antworte ich früher.

Windows will updates installieren, habe ich aber heute nicht gemacht.

Danke

Sabine99

schrauber 24.06.2013 07:27

Updates kannste installieren. Poste bitte noch das frische FRST Log, dann entfernen wir die Reste.

Sabine99 27.06.2013 18:06

Hallo Schrauber,

und hier leider erst heute das neue log file.
Zusätzlich habe ich irgendwie Schwierigkeiten mir dem Internet Explorer. Hier werden nicht alle Buchstaben sofort angenommen. Ich muß oft Buchstaben öfter anklicken, bis diese angenommen werden. Im Word funktioniert es aber einwandfrei.


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-06-2013 02
Ran by ***** (administrator) on 27-06-2013 18:55:01
Running from C:\Users\*****\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K488KDUP
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
() C:\Program Files\PC Speed Up\PCSUService.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(COMPANYVERS_NAME) C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
() C:\Windows\system32\securitz.exe
() C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
(Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe
(COMPANYVERS_NAME) C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe
(Wajam) C:\Program Files\Wajam\Updater\WajamUpdater.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Lexware GmbH & Co. KG) C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe
(ODSoft multimedia) C:\Program Files\Sceneo\AbsolutTV\Services\ODSBC\ODSBCApp.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(MindSpark) C:\Program Files\InboxAce_1g\bar\1.bin\1gSrchMn.exe
(VER_COMPANY_NAME) C:\Program Files\InboxAce_1g\bar\1.bin\1gbrmon.exe
(VER_COMPANY_NAME) C:\Program Files\UtilityChest_49\bar\1.bin\49brmon.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
() C:\Program Files\PC Speed Up\PCSUNotifier.exe
(Smartbar) C:\Users\*****\AppData\Local\Smartbar\Application\SnapDo.exe
(Hewlett-Packard Co.) C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RaUI.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Lexware GmbH & Co. KG) C:\Program Files\Common Files\Lexware\LxWebAccess\LxWebAccess.exe
(Microsoft Corporation) C:\Windows\system32\msiexec.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [UpdatePPShortCut] "C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\PowerProducer" update "Software\CyberLink\PowerProducer\4.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM\...\Run: []  [x]
HKLM\...\Run: [Windows Defender] %programfiles%\windows defender\msascui.exe -hide [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [LexwareInfoService] c:\program files\common files\lexware\update manager\lxupdatemanager.exe /autostart [339240 2008-11-03] (Lexware GmbH & Co. KG)
HKLM\...\Run: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\nbkeyscan.exe" [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [RemoteControl] "c:\program files\homecinema\powerdvd\pdvdserv.exe" [71216 2007-02-09] (Cyberlink Corp.)
HKLM\...\Run: [TVBroadcast] c:\program files\sceneo\absoluttv\services\odsbc\odsbcapp.exe [797696 2007-08-08] (ODSoft multimedia)
HKLM\...\Run: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe [90112 2006-11-29] (Ulead Systems, Inc.)
HKLM\...\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [Ocs_SM] C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizer.exe [106496 2013-06-22] (OCS)
HKLM\...\Run: [InboxAce Search Scope Monitor] "C:\PROGRA~1\INBOXA~2\bar\1.bin\1gsrchmn.exe" /m=2 /w /h [44784 2013-06-23] (MindSpark)
HKLM\...\Run: [InboxAce_1g Browser Plugin Loader] C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbrmon.exe [30096 2013-06-23] (VER_COMPANY_NAME)
HKLM\...\Run: [Utility Chest Search Scope Monitor] "C:\PROGRA~1\UTILIT~2\bar\1.bin\49srchmn.exe" /m=2 /w /h [44784 2013-06-25] (MindSpark)
HKLM\...\Run: [UtilityChest_49 Browser Plugin Loader] C:\PROGRA~1\UTILIT~2\bar\1.bin\49brmon.exe [30096 2013-06-25] (VER_COMPANY_NAME)
HKCU\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\nmbgmonitor.exe" [202024 2007-10-15] (Nero AG)
HKCU\...\Run: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autorun [1233920 2009-04-11] (Microsoft Corporation)
HKCU\...\Run: [SearchEngineProtection] C:\Program Files\GamesBar\update\SearchEngineProtection.exe [x]
HKCU\...\Run: [AOL Dialer] C:\Program Files\Common Files\AOL\ACS\AOlDial.exe [x]
HKCU\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] C:\Users\HEGGEN~1\AppData\Local\Temp\ACh0XXd.exe [x] <===== ATTENTION
HKCU\...\Run: [PCSpeedUp] C:\Program Files\PC Speed Up\PCSUNotifier.exe [256448 2012-12-14] ()
HKCU\...\Run: [Browser Infrastructure Helper] C:\Users\*****\AppData\Local\Smartbar\Application\SnapDo.exe startup [20992 2013-06-09] (Smartbar)
HKCU\...\Winlogon: [Shell] cmd.exe <==== ATTENTION
HKCR\...409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e\n. ATTENTION! ====> ZeroAccess
HKCU\...\Command Processor: "C:\Users\HEGGEN~1\AppData\Local\Temp\ACh0XXd.exe" <======= ATTENTION
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)

==================== Internet (Whitelisted) ====================

ProxyServer: 192.168.1.1:80
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.mywebsearch.com/index.jhtml?n=77DE8857&p2=^YO^xdm155^YY^de&ptb=5E276747-34FA-4490-AD7C-A0004CE67D9D&si=KI_INB_FIG_GER_24
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=DE&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=ds&q={searchTerms}&installDate={installDate}
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.gamesgofree.com/?utm_source=hpe&utm_medium=hp3
URLSearchHook: (No Name) - {5fdb0cd8-5760-44d1-8d13-a78bf558c3c7} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll (MindSpark)
URLSearchHook: (No Name) - {7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
SearchScopes: HKLM - {8fe8d013-c3fd-4802-af48-79274e9f969e} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^YO^xdm155^YY^de&si=KI_INB_FIG_GER_24&ptb=5E276747-34FA-4490-AD7C-A0004CE67D9D&psa=&ind=2013062305&st=sb&n=77fce4a1&searchfor={searchTerms}
HKCU SearchScopes: DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=DE&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=ds&q={searchTerms}&installDate={installDate}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=DE&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=ds&q={searchTerms}&installDate={installDate}
SearchScopes: HKCU - {8fe8d013-c3fd-4802-af48-79274e9f969e} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^YO^xdm155^YY^de&si=KI_INB_FIG_GER_24&ptb=5E276747-34FA-4490-AD7C-A0004CE67D9D&psa=&ind=2013062305&st=sb&n=77fce4a1&searchfor={searchTerms}
BHO: Search Assistant BHO - {06e05b40-77fa-40b6-9077-ed1a7577b1ef} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
BHO: GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
BHO: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO: Toolbar BHO - {58f7b5ca-1162-42e8-8bbc-d543b4edd780} - C:\PROGRA~1\UTILIT~2\bar\1.bin\49bar.dll (MindSpark)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Search Assistant BHO - {9359da42-06fb-46f2-9e4a-05c05b98a5ef} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll (MindSpark)
BHO: Wajam - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll (Wajam)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.21.5\bh\delta.dll (Delta-search.com)
BHO: Toolbar BHO - {d5a1d22b-9e17-454f-8ecd-83c578fb3983} - C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbar.dll (MindSpark)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.21.5\deltaTlbr.dll (Delta-search.com)
Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM - InboxAce - {3775afd7-5921-4571-968f-85a631203d1c} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll (MindSpark)
Toolbar: HKLM - Utility Chest - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -InboxAce - {3775AFD7-5921-4571-968F-85A631203D1C} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll (MindSpark)
Toolbar: HKCU -Utility Chest - {CF67755F-9265-449C-87CF-B945519E073B} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Chrome:
=======
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013"
CHR Extension: (Snap.Do ) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0
CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1
CHR Extension: (Norton Identity Protection) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.11.8_0
CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

========================== Services (Whitelisted) =================

R2 InboxAce_1gService; C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe [42504 2013-06-23] (COMPANYVERS_NAME)
R2 N360; C:\Program Files\Norton 360\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation)
R2 PCSUService; C:\Program Files\PC Speed Up\PCSUService.exe [320448 2012-12-14] ()
R2 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe [75040 2008-09-05] (Ralink Technology, Corp.)
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
R2 Robocopz; C:\Windows\system32\securitz.exe [68608 2013-06-22] ()
R2 SearchAnonymizer; C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [40960 2013-06-22] ()
R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1681408 2007-08-16] (Buhl Data Service GmbH)
R2 UtilityChest_49Service; C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe [42504 2013-06-25] (COMPANYVERS_NAME)
R2 WajamUpdater; C:\Program Files\Wajam\Updater\WajamUpdater.exe [109064 2013-05-02] (Wajam)
S2 BrowserDefendert; BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [x]

==================== Drivers (Whitelisted) ====================

R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130531.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
S3 CH375; C:\Windows\System32\Drivers\CH375WDM.SYS [28403 2011-03-14] (www.winchiphead.com)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2013-04-13] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2013-04-13] (Symantec Corporation)
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc.              )
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130621.001\IDSvix86.sys [386720 2013-04-12] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVENG.SYS [93272 2013-05-22] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVEX15.SYS [1611992 2013-05-22] (Symantec Corporation)
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [645120 2008-08-21] (Ralink Technology Corp.)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
S3 SRTSP; C:\Windows\System32\Drivers\N360\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-22] (Symantec Corporation)
R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [36512 2013-03-05] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\N360\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-30] (America Online, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 22:24 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 22:23 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:44 - 2013-06-23 11:44 - 00000000 ____D C:\FRST
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-23 11:24 - 2013-06-23 11:24 - 00000000 ____D C:\Program Files\InboxAce_1g
2013-06-22 23:20 - 2013-06-22 23:20 - 00000000 ____D C:\_OTL
2013-06-22 22:02 - 2013-06-22 22:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 20:31 - 2013-06-22 20:33 - 00000000 ____D C:\JRT
2013-06-22 20:31 - 2013-06-22 20:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 20:25 - 2013-06-22 20:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 20:24 - 2013-06-22 20:25 - 00000000 ____D C:\Users\*****\AppData\Local\Smartbar
2013-06-22 20:23 - 2013-06-27 18:45 - 00000000 ____A C:\END
2013-06-22 20:23 - 2013-06-22 20:24 - 00000000 ____D C:\Program Files\Wajam
2013-06-22 20:23 - 2013-06-22 20:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Users\*****\AppData\Local\Wajam
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:18 - 2013-06-27 18:44 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-22 20:18 - 2013-06-23 12:20 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-22 20:18 - 2013-06-22 20:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 20:17 - 2013-06-27 18:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-22 20:17 - 2013-06-22 20:17 - 00000000 ____D C:\Users\*****\AppData\Roaming\Delta
2013-06-22 20:17 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Delta
2013-06-22 20:16 - 2013-06-25 06:42 - 00000000 ____D C:\Users\*****\AppData\Roaming\DesktopIconForAmazon
2013-06-22 20:16 - 2013-06-22 20:17 - 00000000 ____D C:\Users\*****\AppData\Roaming\BabSolution
2013-06-22 20:16 - 2013-06-22 20:16 - 00068608 ____A () C:\Windows\System32\securitz.exe
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\OCS
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Babylon
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\ProgramData\Babylon
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:00 - 2013-06-22 20:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 19:58 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:18 - 2012-08-21 13:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2013-06-17 06:17 - 2013-06-17 06:18 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2013-06-17 06:17 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-14 13:38 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-14 13:38 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-14 13:38 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-14 13:38 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-14 13:38 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-14 13:38 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-14 13:38 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-14 13:38 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-14 13:38 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-14 13:38 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-14 13:32 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-14 13:31 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-14 13:31 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-14 13:31 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-14 13:31 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-14 13:31 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-14 13:31 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll

==================== One Month Modified Files and Folders ========

2013-06-27 18:51 - 2011-11-22 19:11 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-27 18:50 - 2012-08-22 20:11 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-27 18:49 - 2010-01-23 16:48 - 01624968 ____A C:\Windows\WindowsUpdate.log
2013-06-27 18:45 - 2013-06-22 20:23 - 00000000 ____A C:\END
2013-06-27 18:45 - 2010-12-28 12:53 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-06-27 18:44 - 2013-06-22 20:18 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-27 18:44 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-27 18:44 - 2011-11-22 19:11 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-27 18:44 - 2010-01-24 10:55 - 00000000 ____D C:\ProgramData\NVIDIA
2013-06-27 18:44 - 2010-01-23 17:02 - 01036168 ____A C:\Windows\PFRO.log
2013-06-27 18:44 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-27 18:44 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-27 18:44 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-25 06:42 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\DesktopIconForAmazon
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-25 06:39 - 2013-02-02 13:52 - 00000524 ____A C:\Users\*****\Desktop\eMail (12).website
2013-06-23 22:34 - 2006-11-02 15:01 - 00032530 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-23 22:23 - 2013-06-23 22:24 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 22:23 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 12:20 - 2013-06-22 20:18 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:44 - 2013-06-23 11:44 - 00000000 ____D C:\FRST
2013-06-23 11:31 - 2010-01-26 15:57 - 00002591 ____A C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-23 11:24 - 2013-06-23 11:24 - 00000000 ____D C:\Program Files\InboxAce_1g
2013-06-22 23:20 - 2013-06-22 23:20 - 00000000 ____D C:\_OTL
2013-06-22 22:02 - 2013-06-22 22:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 21:59 - 2010-01-23 17:06 - 00000000 ___AD C:\users\*****
2013-06-22 20:33 - 2013-06-22 20:31 - 00000000 ____D C:\JRT
2013-06-22 20:31 - 2013-06-22 20:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 20:25 - 2013-06-22 20:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 20:25 - 2013-06-22 20:24 - 00000000 ____D C:\Users\*****\AppData\Local\Smartbar
2013-06-22 20:24 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\Wajam
2013-06-22 20:23 - 2013-06-22 20:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Users\*****\AppData\Local\Wajam
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:18 - 2013-06-22 20:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 20:17 - 2013-06-22 20:17 - 00000000 ____D C:\Users\*****\AppData\Roaming\Delta
2013-06-22 20:17 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Delta
2013-06-22 20:17 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\BabSolution
2013-06-22 20:17 - 2011-10-21 13:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-22 20:16 - 2013-06-22 20:16 - 00068608 ____A () C:\Windows\System32\securitz.exe
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\OCS
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Babylon
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\ProgramData\Babylon
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:04 - 2011-04-17 19:29 - 00000000 ____D C:\Windows\System32\Drivers\N360
2013-06-22 20:03 - 2011-04-17 19:30 - 00002023 ____A C:\Users\Public\Desktop\Norton 360.lnk
2013-06-22 20:00 - 2013-06-22 20:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 19:58 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-22 19:54 - 2013-01-09 21:21 - 00001935 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-22 19:23 - 2011-04-17 19:30 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS
2013-06-22 19:23 - 2011-04-17 19:30 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:19 - 2012-05-21 20:02 - 00000000 ____D C:\Users\*****\AppData\Roaming\Apple Computer
2013-06-17 06:19 - 2010-01-26 10:43 - 00000000 ____D C:\Users\*****\AppData\Local\Apple Computer
2013-06-17 06:18 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:17 - 2013-06-17 06:09 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-17 06:17 - 2010-02-13 14:59 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-06-17 06:17 - 2010-02-13 14:54 - 00000000 ____D C:\ProgramData\Apple
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2012-05-21 06:11 - 00001690 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2013-06-17 06:09 - 2008-01-23 14:46 - 00000000 ____D C:\Program Files\QuickTime
2013-06-14 17:02 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-06-14 16:48 - 2012-08-22 20:11 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-14 16:48 - 2011-09-04 07:42 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-14 16:43 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-14 13:36 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e

Files to move or delete:
====================
C:\ProgramData\nvModes.dat

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-27 18:50

==================== End Of Log ============================

--- --- ---

--- --- ---


:rolleyes:

Vielen Dank und viele Grüße, ohne Dich wäre ich absolut hilflos :abklatsch:

Sabine99

schrauber 27.06.2013 19:35

Fix mit FRST
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
Code:

C:\Program Files\Smart PC Cleaner
C:\Windows\System32\securitz.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
() C:\Windows\system32\securitz.exe
() C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
(Smartbar) C:\Users\*****\AppData\Local\Smartbar\Application\SnapDo.exe
HKLM\...\Run: []  [x]
HKLM\...\Run: [Ocs_SM] C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizer.exe [106496 2013-06-22] (OCS)
HKCU\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] C:\Users\HEGGEN~1\AppData\Local\Temp\ACh0XXd.exe [x] <===== ATTENTION
HKCU\...\Run: [PCSpeedUp] C:\Program Files\PC Speed Up\PCSUNotifier.exe [256448 2012-12-14] ()
HKCU\...\Run: [Browser Infrastructure Helper] C:\Users\*****\AppData\Local\Smartbar\Application\SnapDo.exe startup [20992 2013-06-09] (Smartbar)
HKCU\...\Winlogon: [Shell] cmd.exe <==== ATTENTION
HKCR\...409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e\n. ATTENTION! ====> ZeroAccess
HKCU\...\Command Processor: "C:\Users\HEGGEN~1\AppData\Local\Temp\ACh0XXd.exe" <======= ATTENTION
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.mywebsearch.com/index.jhtml?n=77DE8857&p2=^YO^xdm155^YY^de&ptb=5E276747-34FA-4490-AD7C-A0004CE67D9D&si=KI_INB_FIG_GER_24
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=DE&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=ds&q={searchTerms}&installDate={installDate}
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.gamesgofree.com/?utm_source=hpe&utm_medium=hp3
SearchScopes: HKLM - {8fe8d013-c3fd-4802-af48-79274e9f969e} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^YO^xdm155^YY^de&si=KI_INB_FIG_GER_24&ptb=5E276747-34FA-4490-AD7C-A0004CE67D9D&psa=&ind=2013062305&st=sb&n=77fce4a1&searchfor={searchTerms}
HKCU SearchScopes: DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=DE&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=ds&q={searchTerms}&installDate={installDate}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=DE&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=ds&q={searchTerms}&installDate={installDate}
SearchScopes: HKCU - {8fe8d013-c3fd-4802-af48-79274e9f969e} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^YO^xdm155^YY^de&si=KI_INB_FIG_GER_24&ptb=5E276747-34FA-4490-AD7C-A0004CE67D9D&psa=&ind=2013062305&st=sb&n=77fce4a1&searchfor={searchTerms}
BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.21.5\bh\delta.dll (Delta-search.com)
DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095}
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013"
CHR Extension: (Snap.Do ) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0
R2 Robocopz; C:\Windows\system32\securitz.exe [68608 2013-06-22] ()
R2 SearchAnonymizer; C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [40960 2013-06-22] ()
R2 WajamUpdater; C:\Program Files\Wajam\Updater\WajamUpdater.exe [109064 2013-05-02] (Wajam)
S2 BrowserDefendert; BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [x]
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Fix Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



AdwCleaner löschen.

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


neues FRST Log bitte.

Sabine99 27.06.2013 20:41

Hallo Schrauber,
anbei:
Fixlog.txt
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-06-2013 02
Ran by **** at 2013-06-27 21:20:16 Run:1
Running from C:\Users\****\Desktop
Boot Mode: Normal

==============================================

C:\Program Files\Smart PC Cleaner => Moved successfully.
C:\Windows\System32\securitz.exe => Moved successfully.
[2368] C:\Program Files\CyberLink\Shared Files\RichVideo.exe => Process closed successfully.
[2396] C:\Windows\system32\securitz.exe => Process closed successfully.
C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe => No running process found
C:\Users\*****\AppData\Local\Smartbar\Application\SnapDo.exe => No running process found
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Ocs_SM => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\qcgce2mrvjq91kk1e7pnbb19m52fx => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\PCSpeedUp => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Browser Infrastructure Helper => Value deleted successfully.
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon => Key deleted successfully.
HKCR\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32\\Default => Value was restored successfully.
HKCU\Software\Microsoft\Command Processor\\AutoRun => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8fe8d013-c3fd-4802-af48-79274e9f969e} => Key deleted successfully.
HKCR\CLSID\{8fe8d013-c3fd-4802-af48-79274e9f969e} => Key not found.
HKCR\CLSID\{8fe8d013-c3fd-4802-af48-79274e9f969e}\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key deleted successfully.
HKCR\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8fe8d013-c3fd-4802-af48-79274e9f969e} => Key deleted successfully.
HKCR\CLSID\{8fe8d013-c3fd-4802-af48-79274e9f969e} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully.
HKCR\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully.
HKCR\CLSID\{4FF78044-96B4-4312-A5B7-FDA3CB328095} => Key not found.
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013 ==> The Chrome "Settings" can be used to fix the entry.
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013" ==> The Chrome "Settings" can be used to fix the entry.
C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl directory not found.
Robocopz => Service deleted successfully.
SearchAnonymizer => Service deleted successfully.
WajamUpdater => Service deleted successfully.
BrowserDefendert => Service deleted successfully.

"C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e" directory move:

Could not move "C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e" directory. => Scheduled to move on reboot.


=========== Result of Scheduled Files to move ===========
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e => Directory could not move.

==== End of Fixlog ====

ADW
Code:

# AdwCleaner v2.303 - Datei am 27/06/2013 um 21:25:54 erstellt
# Aktualisiert am 08/06/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : ***** - *****-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\*****\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****

Gestoppt & Gelöscht : PCSUService

***** [Dateien / Ordner] *****

Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
Datei Gelöscht : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
Ordner Gelöscht : C:\Program Files\Delta
Ordner Gelöscht : C:\Program Files\Wajam
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\Users\HEGGEN~1\AppData\Local\Temp\Iminent
Ordner Gelöscht : C:\Users\HEGGEN~1\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\HEGGEN~1\AppData\Local\Temp\Smartbar
Ordner Gelöscht : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl
Ordner Gelöscht : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
Ordner Gelöscht : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif
Ordner Gelöscht : C:\Users\*****\AppData\Local\Smartbar
Ordner Gelöscht : C:\Users\*****\AppData\Local\Wajam
Ordner Gelöscht : C:\Users\*****\AppData\LocalLow\Delta
Ordner Gelöscht : C:\Users\*****\AppData\LocalLow\Smartbar
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\Delta
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\OCS

***** [Registrierungsdatenbank] *****

Daten Gelöscht : HKLM\..\Windows [AppInit_DLLs] = browse~1\261339~1.144\{c16c1~1\browse~1.dll
Schlüssel Gelöscht : HKCU\Software\5b6ded9b43cec41
Schlüssel Gelöscht : HKCU\Software\BabSolution
Schlüssel Gelöscht : HKCU\Software\DataMngr
Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta Chrome Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchAnonymizer
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wajam
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\SmartbarBackup
Schlüssel Gelöscht : HKCU\Software\SmartbarLog
Schlüssel Gelöscht : HKCU\Software\Wajam
Schlüssel Gelöscht : HKLM\SOFTWARE\5b6ded9b43cec41
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\priam_bho.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{13119113-0854-469D-807A-171568457991}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{33119133-0854-469D-807A-171568457991}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B89F5C49-51DB-4974-AB5A-E25901AA339C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E9B5B0D2-D08A-49FC-8B5C-159B60BAA268}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.BandObjectAttribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.DockingPanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBarBandObject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarDisplayState
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarMenuForm
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamBHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Schlüssel Gelöscht : HKLM\Software\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAnonymizer
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam
Schlüssel Gelöscht : HKLM\Software\Wajam
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16490

Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://home.mywebsearch.com/index.jhtml?n=77DE8857&p2=^YO^xdm155^YY^de&ptb=5E276747-34FA-4490-AD7C-A0004CE67D9D&si=KI_INB_FIG_GER_24 --> hxxp://www.google.com

-\\ Google Chrome v27.0.1453.116

Datei : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[S1].txt - [43012 octets] - [22/06/2013 20:00:03]
AdwCleaner[S2].txt - [13059 octets] - [27/06/2013 21:25:54]

########## EOF - C:\AdwCleaner[S2].txt - [13120 octets] ##########

Junkware removal tool hat leider wieder nicht funktioniert.
Es kam die Meldung:
Error during execution
C:\JRT\get.bat
System kann angegebene Datei nicht finden. (Norton ist deaktiviert)

Ich habe jetzt trotzdem noch den letzten scan gemacht
FRST:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-06-2013 02
Ran by ***** (administrator) on 27-06-2013 21:32:43
Running from C:\Users\*****\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(COMPANYVERS_NAME) C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe
(Lexware GmbH & Co. KG) C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(COMPANYVERS_NAME) C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe
(Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe
(ODSoft multimedia) C:\Program Files\Sceneo\AbsolutTV\Services\ODSBC\ODSBCApp.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(MindSpark) C:\Program Files\InboxAce_1g\bar\1.bin\1gSrchMn.exe
(VER_COMPANY_NAME) C:\Program Files\InboxAce_1g\bar\1.bin\1gbrmon.exe
(VER_COMPANY_NAME) C:\Program Files\UtilityChest_49\bar\1.bin\49brmon.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Hewlett-Packard Co.) C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RaUI.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [UpdatePPShortCut] "C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\PowerProducer" update "Software\CyberLink\PowerProducer\4.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM\...\Run: [Windows Defender] %programfiles%\windows defender\msascui.exe -hide [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [LexwareInfoService] c:\program files\common files\lexware\update manager\lxupdatemanager.exe /autostart [339240 2008-11-03] (Lexware GmbH & Co. KG)
HKLM\...\Run: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\nbkeyscan.exe" [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [RemoteControl] "c:\program files\homecinema\powerdvd\pdvdserv.exe" [71216 2007-02-09] (Cyberlink Corp.)
HKLM\...\Run: [TVBroadcast] c:\program files\sceneo\absoluttv\services\odsbc\odsbcapp.exe [797696 2007-08-08] (ODSoft multimedia)
HKLM\...\Run: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe [90112 2006-11-29] (Ulead Systems, Inc.)
HKLM\...\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [InboxAce Search Scope Monitor] "C:\PROGRA~1\INBOXA~2\bar\1.bin\1gsrchmn.exe" /m=2 /w /h [44784 2013-06-23] (MindSpark)
HKLM\...\Run: [InboxAce_1g Browser Plugin Loader] C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbrmon.exe [30096 2013-06-23] (VER_COMPANY_NAME)
HKLM\...\Run: [Utility Chest Search Scope Monitor] "C:\PROGRA~1\UTILIT~2\bar\1.bin\49srchmn.exe" /m=2 /w /h [44784 2013-06-25] (MindSpark)
HKLM\...\Run: [UtilityChest_49 Browser Plugin Loader] C:\PROGRA~1\UTILIT~2\bar\1.bin\49brmon.exe [30096 2013-06-25] (VER_COMPANY_NAME)
HKCU\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\nmbgmonitor.exe" [202024 2007-10-15] (Nero AG)
HKCU\...\Run: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autorun [1233920 2009-04-11] (Microsoft Corporation)
HKCU\...\Run: [SearchEngineProtection] C:\Program Files\GamesBar\update\SearchEngineProtection.exe [x]
HKCU\...\Run: [AOL Dialer] C:\Program Files\Common Files\AOL\ACS\AOlDial.exe [x]
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)

==================== Internet (Whitelisted) ====================

ProxyServer: 192.168.1.1:80
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
URLSearchHook: (No Name) - {7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
URLSearchHook: (No Name) - {5fdb0cd8-5760-44d1-8d13-a78bf558c3c7} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll (MindSpark)
HKCU SearchScopes: DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
BHO: Search Assistant BHO - {06e05b40-77fa-40b6-9077-ed1a7577b1ef} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
BHO: GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
BHO: Toolbar BHO - {58f7b5ca-1162-42e8-8bbc-d543b4edd780} - C:\PROGRA~1\UTILIT~2\bar\1.bin\49bar.dll (MindSpark)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Search Assistant BHO - {9359da42-06fb-46f2-9e4a-05c05b98a5ef} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll (MindSpark)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Toolbar BHO - {d5a1d22b-9e17-454f-8ecd-83c578fb3983} - C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbar.dll (MindSpark)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - InboxAce - {3775afd7-5921-4571-968f-85a631203d1c} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll (MindSpark)
Toolbar: HKLM - Utility Chest - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -InboxAce - {3775AFD7-5921-4571-968F-85A631203D1C} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll (MindSpark)
Toolbar: HKCU -Utility Chest - {CF67755F-9265-449C-87CF-B945519E073B} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Chrome:
=======
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013"
CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1
CHR Extension: (Norton Identity Protection) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.11.8_0
CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

========================== Services (Whitelisted) =================

R2 InboxAce_1gService; C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe [42504 2013-06-23] (COMPANYVERS_NAME)
R2 N360; C:\Program Files\Norton 360\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation)
R2 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe [75040 2008-09-05] (Ralink Technology, Corp.)
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1681408 2007-08-16] (Buhl Data Service GmbH)
R2 UtilityChest_49Service; C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe [42504 2013-06-25] (COMPANYVERS_NAME)

==================== Drivers (Whitelisted) ====================

R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130531.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
S3 CH375; C:\Windows\System32\Drivers\CH375WDM.SYS [28403 2011-03-14] (www.winchiphead.com)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2013-04-13] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2013-04-13] (Symantec Corporation)
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc.              )
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130621.001\IDSvix86.sys [386720 2013-04-12] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVENG.SYS [93272 2013-05-22] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVEX15.SYS [1611992 2013-05-22] (Symantec Corporation)
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [645120 2008-08-21] (Ralink Technology Corp.)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
S3 SRTSP; C:\Windows\System32\Drivers\N360\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-22] (Symantec Corporation)
R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [36512 2013-03-05] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\N360\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-30] (America Online, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-27 21:30 - 2013-06-27 21:30 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-06-27 21:25 - 2013-06-27 21:26 - 00013190 ____A C:\AdwCleaner[S2].txt
2013-06-27 21:25 - 2013-06-27 21:25 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-06-27 19:17 - 2013-06-27 19:18 - 01370369 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-06-27 19:15 - 2013-06-27 19:15 - 01370369 ____A (Farbar) C:\Users\*****\Downloads\FRST.exe
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 22:24 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 22:23 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:44 - 2013-06-27 21:22 - 00000000 ____D C:\FRST
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-23 11:24 - 2013-06-23 11:24 - 00000000 ____D C:\Program Files\InboxAce_1g
2013-06-22 23:20 - 2013-06-22 23:20 - 00000000 ____D C:\_OTL
2013-06-22 22:02 - 2013-06-22 22:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 20:31 - 2013-06-27 21:32 - 00000000 ____D C:\JRT
2013-06-22 20:31 - 2013-06-22 20:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 20:25 - 2013-06-22 20:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 20:23 - 2013-06-22 20:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:18 - 2013-06-27 21:24 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-22 20:18 - 2013-06-23 12:20 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-22 20:18 - 2013-06-22 20:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 20:17 - 2013-06-27 18:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:00 - 2013-06-22 20:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 19:58 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:18 - 2012-08-21 13:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2013-06-17 06:17 - 2013-06-17 06:18 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2013-06-17 06:17 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-14 13:38 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-14 13:38 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-14 13:38 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-14 13:38 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-14 13:38 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-14 13:38 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-14 13:38 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-14 13:38 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-14 13:38 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-14 13:38 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-14 13:32 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-14 13:31 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-14 13:31 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-14 13:31 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-14 13:31 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-14 13:31 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-14 13:31 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll

==================== One Month Modified Files and Folders ========

2013-06-27 21:32 - 2013-06-22 20:31 - 00000000 ____D C:\JRT
2013-06-27 21:32 - 2010-01-23 16:48 - 01652296 ____A C:\Windows\WindowsUpdate.log
2013-06-27 21:30 - 2013-06-27 21:30 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-06-27 21:28 - 2011-11-22 19:11 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-27 21:28 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-27 21:28 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-27 21:28 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-27 21:27 - 2010-01-24 10:55 - 00000000 ____D C:\ProgramData\NVIDIA
2013-06-27 21:26 - 2013-06-27 21:25 - 00013190 ____A C:\AdwCleaner[S2].txt
2013-06-27 21:26 - 2006-11-02 15:01 - 00032530 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-27 21:25 - 2013-06-27 21:25 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-06-27 21:24 - 2013-06-22 20:18 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-27 21:22 - 2013-06-23 11:44 - 00000000 ____D C:\FRST
2013-06-27 21:06 - 2010-12-28 12:53 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-06-27 19:51 - 2011-11-22 19:11 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-27 19:50 - 2012-08-22 20:11 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-27 19:18 - 2013-06-27 19:17 - 01370369 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-06-27 19:15 - 2013-06-27 19:15 - 01370369 ____A (Farbar) C:\Users\*****\Downloads\FRST.exe
2013-06-27 18:59 - 2010-01-26 15:57 - 00002591 ____A C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk
2013-06-27 18:44 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-27 18:44 - 2010-01-23 17:02 - 01036168 ____A C:\Windows\PFRO.log
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-25 06:39 - 2013-02-02 13:52 - 00000524 ____A C:\Users\*****\Desktop\eMail (12).website
2013-06-23 22:23 - 2013-06-23 22:24 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 22:23 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 12:20 - 2013-06-22 20:18 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-23 11:24 - 2013-06-23 11:24 - 00000000 ____D C:\Program Files\InboxAce_1g
2013-06-22 23:20 - 2013-06-22 23:20 - 00000000 ____D C:\_OTL
2013-06-22 22:02 - 2013-06-22 22:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 21:59 - 2010-01-23 17:06 - 00000000 ___AD C:\users\*****
2013-06-22 20:31 - 2013-06-22 20:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 20:25 - 2013-06-22 20:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 20:23 - 2013-06-22 20:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:18 - 2013-06-22 20:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 20:17 - 2011-10-21 13:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:04 - 2011-04-17 19:29 - 00000000 ____D C:\Windows\System32\Drivers\N360
2013-06-22 20:03 - 2011-04-17 19:30 - 00002023 ____A C:\Users\Public\Desktop\Norton 360.lnk
2013-06-22 20:00 - 2013-06-22 20:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 19:58 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-22 19:54 - 2013-01-09 21:21 - 00001935 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-22 19:23 - 2011-04-17 19:30 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS
2013-06-22 19:23 - 2011-04-17 19:30 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:19 - 2012-05-21 20:02 - 00000000 ____D C:\Users\*****\AppData\Roaming\Apple Computer
2013-06-17 06:19 - 2010-01-26 10:43 - 00000000 ____D C:\Users\*****\AppData\Local\Apple Computer
2013-06-17 06:18 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:17 - 2013-06-17 06:09 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-17 06:17 - 2010-02-13 14:59 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-06-17 06:17 - 2010-02-13 14:54 - 00000000 ____D C:\ProgramData\Apple
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2012-05-21 06:11 - 00001690 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2013-06-17 06:09 - 2008-01-23 14:46 - 00000000 ____D C:\Program Files\QuickTime
2013-06-14 17:02 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-06-14 16:48 - 2012-08-22 20:11 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-14 16:48 - 2011-09-04 07:42 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-14 16:43 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-14 13:36 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e

Files to move or delete:
====================
C:\ProgramData\nvModes.dat

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-27 21:12

==================== End Of Log ============================

--- --- ---


Ach ja und im Internet Explorer kann ich wieder ganz normal schreiben.

Grüße

Sabine 99

schrauber 28.06.2013 06:33

Hartnäckige Reste :)
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

Sabine99 28.06.2013 19:24

Hallo Schrauber,

leider bleibt Combofix hier "hängen". Norton und das Sichereitscenter von Windows sind aus, ich habe das jetzt mehrmals geprüft und mehr habe ich nicht.
Code:

Zielverzeichnis: C:\32788R22FWJFW
Lösche Datei: C:\32788R22FWJFW\023.dat
Lösche Datei: C:\32788R22FWJFW\023v.dat
Lösche Datei: C:\32788R22FWJFW\023w7.dat
Lösche Datei: C:\32788R22FWJFW\023w8.dat
Lösche Datei: C:\32788R22FWJFW\ActiveDrv.vbs
Lösche Datei: C:\32788R22FWJFW\AppDataFile.cfx
Lösche Datei: C:\32788R22FWJFW\AppDataFolder.cfx
Lösche Datei: C:\32788R22FWJFW\appinit.bad
Lösche Datei: C:\32788R22FWJFW\asp.str
Lösche Datei: C:\32788R22FWJFW\Assoc.cmd
Lösche Datei: C:\32788R22FWJFW\Auto-RC.cmd
Lösche Datei: C:\32788R22FWJFW\av.cmd
Lösche Datei: C:\32788R22FWJFW\av.vbs
Lösche Datei: C:\32788R22FWJFW\AWF.cmd
Lösche Datei: C:\32788R22FWJFW\badclsid.c
Lösche Datei: C:\32788R22FWJFW\BFE.dat
Lösche Datei: C:\32788R22FWJFW\Boot-Rk.cmd
Lösche Datei: C:\32788R22FWJFW\Boot.bat
Lösche Datei: C:\32788R22FWJFW\BootDrv.vbs
Lösche Datei: C:\32788R22FWJFW\c.bat
Lösche Datei: C:\32788R22FWJFW\Catch-sub.cmd
Lösche Datei: C:\32788R22FWJFW\catchme.3XE
Lösche Datei: C:\32788R22FWJFW\CF-Script.cmd
Lösche Datei: C:\32788R22FWJFW\clsid.c
Lösche Datei: C:\32788R22FWJFW\Combo-Fix.sys
Lösche Datei: C:\32788R22FWJFW\Combobatch.bat
Lösche Datei: C:\32788R22FWJFW\ComboFix-Download.3XE
Lösche Datei: C:\32788R22FWJFW\Create.cmd
Lösche Datei: C:\32788R22FWJFW\Creg.dat
Lösche Datei: C:\32788R22FWJFW\CregC.cmd
Lösche Datei: C:\32788R22FWJFW\CregC.dat
Lösche Datei: C:\32788R22FWJFW\dd.3XE
Lösche Datei: C:\32788R22FWJFW\ddsDo.sed
Lösche Datei: C:\32788R22FWJFW\DelClsid.bat
Lösche Datei: C:\32788R22FWJFW\DelClsid64.bat
Lösche Datei: C:\32788R22FWJFW\desktop.ini
Lösche Datei: C:\32788R22FWJFW\DesktopFile.cfx
Lösche Datei: C:\32788R22FWJFW\Dnl.dat
Lösche Datei: C:\32788R22FWJFW\DPF.str
Lösche Datei: C:\32788R22FWJFW\DrvRun.vbs
Lösche Datei: C:\32788R22FWJFW\dumphive.3XE
Lösche Datei: C:\32788R22FWJFW\embedded.sed
Lösche Datei: C:\32788R22FWJFW\EN-US\iexplore.exe
Entferne Verzeichnis: C:\32788R22FWJFW\EN-US\
Lösche Datei: C:\32788R22FWJFW\ERDNT.e_e
Lösche Datei: C:\32788R22FWJFW\ERDNTDOS.LOC
Lösche Datei: C:\32788R22FWJFW\ERDNTWIN.LOC
Lösche Datei: C:\32788R22FWJFW\ERUNT.3XE
Lösche Datei: C:\32788R22FWJFW\ERUNT.LOC
Lösche Datei: C:\32788R22FWJFW\Exe.reg
Lösche Datei: C:\32788R22FWJFW\extract.3XE
Lösche Datei: C:\32788R22FWJFW\FavoriteFolder.cfx
Lösche Datei: C:\32788R22FWJFW\FavoritesFile.cfx
Lösche Datei: C:\32788R22FWJFW\FD-SV.cmd
Lösche Datei: C:\32788R22FWJFW\ffdefstr.dll
Lösche Datei: C:\32788R22FWJFW\ffext.pif
Lösche Datei: C:\32788R22FWJFW\FileKill.3XE
Lösche Datei: C:\32788R22FWJFW\files.pif
Lösche Datei: C:\32788R22FWJFW\Fin.dat
Lösche Datei: C:\32788R22FWJFW\FIND3M.bat
Lösche Datei: C:\32788R22FWJFW\firefox.exe
Lösche Datei: C:\32788R22FWJFW\FIXLSP.bat
Lösche Datei: C:\32788R22FWJFW\FIXLSP64.cmd
Lösche Datei: C:\32788R22FWJFW\FKMGen.cmd
Lösche Datei: C:\32788R22FWJFW\fl0.bat
Lösche Datei: C:\32788R22FWJFW\GetHive.cmd
Lösche Datei: C:\32788R22FWJFW\grep.3XE
Lösche Datei: C:\32788R22FWJFW\gsar.3XE
Lösche Datei: C:\32788R22FWJFW\handle.3XE
Lösche Datei: C:\32788R22FWJFW\hidec.3XE
Lösche Datei: C:\32788R22FWJFW\history.bat
Lösche Datei: C:\32788R22FWJFW\hwid.pif
Lösche Datei: C:\32788R22FWJFW\iexplore.exe
Lösche Datei: C:\32788R22FWJFW\image001.gif
Lösche Datei: C:\32788R22FWJFW\Imefile.dat
Lösche Datei: C:\32788R22FWJFW\Install-RC.cmd
Lösche Datei: C:\32788R22FWJFW\iphlpsvc.vista.dat
Lösche Datei: C:\32788R22FWJFW\iphlpsvc.w7.dat
Lösche Datei: C:\32788R22FWJFW\iphlpsvc.w8.dat
Lösche Datei: C:\32788R22FWJFW\katch.cmd
Lösche Datei: C:\32788R22FWJFW\Kill-All.cmd
Lösche Datei: C:\32788R22FWJFW\KNetSvcs.vbs
Lösche Datei: C:\32788R22FWJFW\Ksvchost.vbs
Lösche Datei: C:\32788R22FWJFW\Lang.bat
Lösche Datei: C:\32788R22FWJFW\License\Curl - license.txt
Lösche Datei: C:\32788R22FWJFW\License\dumphive-license.txt
Lösche Datei: C:\32788R22FWJFW\License\EXTRACT.TXT
Lösche Datei: C:\32788R22FWJFW\License\FI - license.txt
Lösche Datei: C:\32788R22FWJFW\License\firefox.exe
Lösche Datei: C:\32788R22FWJFW\License\iexplore.exe
Lösche Datei: C:\32788R22FWJFW\License\mtee.txt
Lösche Datei: C:\32788R22FWJFW\License\ncmd.cfxxe
Lösche Datei: C:\32788R22FWJFW\License\pv_5_2_2.zip
Lösche Datei: C:\32788R22FWJFW\License\streamtools.zip
Lösche Datei: C:\32788R22FWJFW\License\UnxUtilsDist.com
Lösche Datei: C:\32788R22FWJFW\License\UnxUtilsDist.html
Lösche Datei: C:\32788R22FWJFW\License\UnxUtilsDist.pif
Lösche Datei: C:\32788R22FWJFW\License\Zip - license.txt
Entferne Verzeichnis: C:\32788R22FWJFW\License\
Lösche Datei: C:\32788R22FWJFW\List-B.bat
Lösche Datei: C:\32788R22FWJFW\List-C.bat
Lösche Datei: C:\32788R22FWJFW\List-D.bat
Lösche Datei: C:\32788R22FWJFW\List.bat
Lösche Datei: C:\32788R22FWJFW\lnkread.vbs
Lösche Datei: C:\32788R22FWJFW\LocalAppDataFile.cfx
Lösche Datei: C:\32788R22FWJFW\LocalAppDataFolder.cfx
Lösche Datei: C:\32788R22FWJFW\LocalService.dat
Lösche Datei: C:\32788R22FWJFW\LocalServiceNetworkRestricted.dat
Lösche Datei: C:\32788R22FWJFW\LocalSettingsFile.cfx
Lösche Datei: C:\32788R22FWJFW\LocalSettingsFolder.cfx
Lösche Datei: C:\32788R22FWJFW\LocalSystemNetworkRestricted.dat
Lösche Datei: C:\32788R22FWJFW\mbr.3XE
Lösche Datei: C:\32788R22FWJFW\mbr.chk
Lösche Datei: C:\32788R22FWJFW\md5sum.pif
Lösche Datei: C:\32788R22FWJFW\md5sum00.pif
Lösche Datei: C:\32788R22FWJFW\MDWht.dat
Lösche Datei: C:\32788R22FWJFW\MoveIt.bat
Lösche Datei: C:\32788R22FWJFW\MpsSvc.dat
Lösche Datei: C:\32788R22FWJFW\mtee.3XE
Lösche Datei: C:\32788R22FWJFW\mynul.dat
Lösche Datei: C:\32788R22FWJFW\MZChanged.dat
Lösche Datei: C:\32788R22FWJFW\ncmd.com
Lösche Datei: C:\32788R22FWJFW\ndis_combofix.dat
Lösche Datei: C:\32788R22FWJFW\ND_.bat
Lösche Datei: C:\32788R22FWJFW\ND_64.bat
Lösche Datei: C:\32788R22FWJFW\netsvc.bad.dat
Lösche Datei: C:\32788R22FWJFW\netsvc.dat
Lösche Datei: C:\32788R22FWJFW\netsvc.vista.dat
Lösche Datei: C:\32788R22FWJFW\netsvc.xp.dat
Lösche Datei: C:\32788R22FWJFW\NetworkService.dat
Lösche Datei: C:\32788R22FWJFW\nir.pif
Lösche Datei: C:\32788R22FWJFW\NirCmd.3XE
Lösche Datei: C:\32788R22FWJFW\NirCmd.chm
Lösche Datei: C:\32788R22FWJFW\NirCmdC.3XE
Lösche Datei: C:\32788R22FWJFW\NT-OS.cmd
Entferne Verzeichnis: C:\32788R22FWJFW\N_\
Lösche Datei: C:\32788R22FWJFW\OSid.vbs
Lösche Datei: C:\32788R22FWJFW\P.cmd
Lösche Datei: C:\32788R22FWJFW\pausep.3XE
Lösche Datei: C:\32788R22FWJFW\PersonalFile.cfx
Lösche Datei: C:\32788R22FWJFW\PersonalFolder.cfx
Lösche Datei: C:\32788R22FWJFW\pev.3XE
Lösche Datei: C:\32788R22FWJFW\pevb.3XE
Lösche Datei: C:\32788R22FWJFW\Policies.dat
Lösche Datei: C:\32788R22FWJFW\powp.dat
Lösche Datei: C:\32788R22FWJFW\Prep.inf
Lösche Datei: C:\32788R22FWJFW\ProfilesFile.cfx
Lösche Datei: C:\32788R22FWJFW\ProfilesFolder.cfx
Lösche Datei: C:\32788R22FWJFW\ProgramsFile.cfx
Lösche Datei: C:\32788R22FWJFW\ProgramsFolder.cfx
Lösche Datei: C:\32788R22FWJFW\Purity.dat
Lösche Datei: C:\32788R22FWJFW\PV.3XE
Lösche Datei: C:\32788R22FWJFW\pv.com
Lösche Datei: C:\32788R22FWJFW\rar_sfx.cmd
Lösche Datei: C:\32788R22FWJFW\RCLink.dat
Lösche Datei: C:\32788R22FWJFW\REGDACL.sed
Lösche Datei: C:\32788R22FWJFW\RegDo.sed
Lösche Datei: C:\32788R22FWJFW\region.dat
Lösche Datei: C:\32788R22FWJFW\RegScan.cmd
Lösche Datei: C:\32788R22FWJFW\RegScan64.cmd
Lösche Datei: C:\32788R22FWJFW\restore_pt.vbs
Lösche Datei: C:\32788R22FWJFW\Rkey.cmd
Lösche Datei: C:\32788R22FWJFW\rmbr.3XE
Lösche Datei: C:\32788R22FWJFW\rogues.dat
Lösche Datei: C:\32788R22FWJFW\run2.sed
Lösche Datei: C:\32788R22FWJFW\Rust.str
Lösche Datei: C:\32788R22FWJFW\s0rt.3XE
Lösche Datei: C:\32788R22FWJFW\safeboot.dat
Lösche Datei: C:\32788R22FWJFW\safeboot.def.dat
Lösche Datei: C:\32788R22FWJFW\safeboot.def.vista.dat
Lösche Datei: C:\32788R22FWJFW\Safeboot.def.w7.dat
Lösche Datei: C:\32788R22FWJFW\Safeboot.def.w8.dat
Lösche Datei: C:\32788R22FWJFW\sed.3XE
Lösche Datei: C:\32788R22FWJFW\SetEnvmt.bat
Lösche Datei: C:\32788R22FWJFW\setpath.3XE
Lösche Datei: C:\32788R22FWJFW\setpath_N.cmd
Lösche Datei: C:\32788R22FWJFW\ShAccess.dat
Lösche Datei: C:\32788R22FWJFW\SnapShot.cmd
Lösche Datei: C:\32788R22FWJFW\sqlite3.3XE
Lösche Datei: C:\32788R22FWJFW\SRestore.cmd
Lösche Datei: C:\32788R22FWJFW\srizbi.md5
Lösche Datei: C:\32788R22FWJFW\StartMenuFile.cfx
Lösche Datei: C:\32788R22FWJFW\StartMenuFolder.cfx
Lösche Datei: C:\32788R22FWJFW\StartUpFile.cfx
Lösche Datei: C:\32788R22FWJFW\SuppScan.cmd
Lösche Datei: C:\32788R22FWJFW\SvcDrv.vbs
Lösche Datei: C:\32788R22FWJFW\svchost.dat
Lösche Datei: C:\32788R22FWJFW\svchost.vista.dat
Lösche Datei: C:\32788R22FWJFW\svchost.vista.x64.dat
Lösche Datei: C:\32788R22FWJFW\svchost.w7.dat
Lösche Datei: C:\32788R22FWJFW\svchost.w7.x64.dat
Lösche Datei: C:\32788R22FWJFW\svchost.w8.dat
Lösche Datei: C:\32788R22FWJFW\svchost.w8.x64.dat
Lösche Datei: C:\32788R22FWJFW\svc_wht.dat
Lösche Datei: C:\32788R22FWJFW\swreg.3XE
Lösche Datei: C:\32788R22FWJFW\swsc.3XE
Lösche Datei: C:\32788R22FWJFW\swxcacls.3XE
Lösche Datei: C:\32788R22FWJFW\system_ini.dat
Lösche Datei: C:\32788R22FWJFW\tail.3XE
Lösche Datei: C:\32788R22FWJFW\TemplatesFile.cfx
Lösche Datei: C:\32788R22FWJFW\TemplatesFolder.cfx
Lösche Datei: C:\32788R22FWJFW\toolbar.sed
Lösche Datei: C:\32788R22FWJFW\UndoW7_XP.dat
Lösche Datei: C:\32788R22FWJFW\Update-CF.cmd
Lösche Datei: C:\32788R22FWJFW\VBR.pif
Lösche Datei: C:\32788R22FWJFW\VInfo
Lösche Datei: C:\32788R22FWJFW\VInfo2
Lösche Datei: C:\32788R22FWJFW\VINFO3
Lösche Datei: C:\32788R22FWJFW\Vipev.dat
Lösche Datei: C:\32788R22FWJFW\Vista.krl
Lösche Datei: C:\32788R22FWJFW\Vista.mac
Lösche Datei: C:\32788R22FWJFW\vistaMcode.dat
Lösche Datei: C:\32788R22FWJFW\vistareg.dat
Lösche Datei: C:\32788R22FWJFW\vun.dat
Lösche Datei: C:\32788R22FWJFW\VwinTemp.dacl
Lösche Datei: C:\32788R22FWJFW\w7Mcode.dat
Lösche Datei: C:\32788R22FWJFW\w7reg.dat
Lösche Datei: C:\32788R22FWJFW\w8reg.dat
Lösche Datei: C:\32788R22FWJFW\Wmi_rem.vbs
Lösche Datei: C:\32788R22FWJFW\w_sock.dll
Lösche Datei: C:\32788R22FWJFW\xpmcode.dat
Lösche Datei: C:\32788R22FWJFW\xpreg.dat
Lösche Datei: C:\32788R22FWJFW\XPSBoot.reg
Lösche Datei: C:\32788R22FWJFW\zDomain.dat
Lösche Datei: C:\32788R22FWJFW\zhsvc.dat
Lösche Datei: C:\32788R22FWJFW\zip.3XE
Dekomprimiere: 023.dat
Dekomprimiere: 023v.dat
Dekomprimiere: 023w7.dat
Dekomprimiere: 023w8.dat
Dekomprimiere: AWF.cmd
Dekomprimiere: ActiveDrv.vbs
Dekomprimiere: AppDataFile.cfx
Dekomprimiere: AppDataFolder.cfx
Dekomprimiere: Assoc.cmd
Dekomprimiere: Auto-RC.cmd
Dekomprimiere: BFE.dat
Dekomprimiere: Boot-Rk.cmd
Dekomprimiere: Boot.bat
Dekomprimiere: BootDrv.vbs
Dekomprimiere: CF-Script.cmd
Dekomprimiere: Catch-sub.cmd
Dekomprimiere: Combo-Fix.sys
Dekomprimiere: ComboFix-Download.3XE
Dekomprimiere: Combobatch.bat
Dekomprimiere: Create.cmd
Dekomprimiere: Creg.dat
Dekomprimiere: CregC.cmd
Dekomprimiere: CregC.dat
Dekomprimiere: DPF.str
Dekomprimiere: DelClsid.bat
Dekomprimiere: DelClsid64.bat
Dekomprimiere: DesktopFile.cfx
Dekomprimiere: Dnl.dat
Dekomprimiere: DrvRun.vbs
Dekomprimiere: ERDNT.e_e
Dekomprimiere: ERDNTDOS.LOC
Dekomprimiere: ERDNTWIN.LOC
Dekomprimiere: ERUNT.3XE
Dekomprimiere: ERUNT.LOC
Dekomprimiere: Exe.reg
Dekomprimiere: FD-SV.cmd
Dekomprimiere: FIND3M.bat
Dekomprimiere: FIXLSP.bat
Dekomprimiere: FIXLSP64.cmd
Dekomprimiere: FKMGen.cmd
Dekomprimiere: FavoriteFolder.cfx
Dekomprimiere: FavoritesFile.cfx
Dekomprimiere: FileKill.3XE
Dekomprimiere: Fin.dat
Dekomprimiere: GetHive.cmd
Dekomprimiere: Imefile.dat
Dekomprimiere: Install-RC.cmd
Dekomprimiere: KNetSvcs.vbs
Dekomprimiere: Kill-All.cmd
Dekomprimiere: Ksvchost.vbs
Dekomprimiere: Lang.bat
Dekomprimiere: List-B.bat
Dekomprimiere: List-C.bat
Dekomprimiere: List-D.bat
Dekomprimiere: List.bat
Dekomprimiere: LocalAppDataFile.cfx
Dekomprimiere: LocalAppDataFolder.cfx
Dekomprimiere: LocalService.dat
Dekomprimiere: LocalServiceNetworkRestricted.dat
Dekomprimiere: LocalSettingsFile.cfx
Dekomprimiere: LocalSettingsFolder.cfx
Dekomprimiere: LocalSystemNetworkRestricted.dat
Dekomprimiere: MDWht.dat
Dekomprimiere: MZChanged.dat
Dekomprimiere: MoveIt.bat
Dekomprimiere: MpsSvc.dat
Dekomprimiere: ND_.bat
Dekomprimiere: ND_64.bat
Dekomprimiere: NT-OS.cmd
Dekomprimiere: NetworkService.dat
Dekomprimiere: NirCmd.3XE
Dekomprimiere: NirCmd.chm
Dekomprimiere: NirCmdC.3XE
Dekomprimiere: NirScript.dat
Dekomprimiere: OSid.vbs
Dekomprimiere: P.cmd
Dekomprimiere: PV.3XE
Dekomprimiere: PersonalFile.cfx
Dekomprimiere: PersonalFolder.cfx
Dekomprimiere: Policies.dat
Dekomprimiere: Prep.inf
Dekomprimiere: ProfilesFile.cfx
Dekomprimiere: ProfilesFolder.cfx
Dekomprimiere: ProgramsFile.cfx
Dekomprimiere: ProgramsFolder.cfx
Dekomprimiere: Purity.dat
Dekomprimiere: RCLink.dat
Dekomprimiere: REGDACL.sed
Dekomprimiere: RegDo.sed
Dekomprimiere: RegScan.cmd
Dekomprimiere: RegScan64.cmd
Dekomprimiere: Rkey.cmd
Dekomprimiere: Rust.str
Dekomprimiere: SRestore.cmd
Dekomprimiere: Safeboot.def.w7.dat
Dekomprimiere: Safeboot.def.w8.dat
Dekomprimiere: SetEnvmt.bat
Dekomprimiere: ShAccess.dat
Dekomprimiere: SnapShot.cmd
Dekomprimiere: StartMenuFile.cfx
Dekomprimiere: StartMenuFolder.cfx
Dekomprimiere: StartUpFile.cfx
Dekomprimiere: SuppScan.cmd
Dekomprimiere: SvcDrv.vbs
Dekomprimiere: TemplatesFile.cfx
Dekomprimiere: TemplatesFolder.cfx
Dekomprimiere: UndoW7_XP.dat
Dekomprimiere: Update-CF.cmd
Dekomprimiere: VBR.pif
Dekomprimiere: VINFO3
Dekomprimiere: VInfo
Dekomprimiere: VInfo2
Dekomprimiere: Vipev.dat
Dekomprimiere: VwinTemp.dacl
Dekomprimiere: Wmi_rem.vbs
Dekomprimiere: XPSBoot.reg
Dekomprimiere: appinit.bad
Dekomprimiere: asp.str
Dekomprimiere: av.cmd
Dekomprimiere: av.vbs
Dekomprimiere: badclsid.c
Dekomprimiere: c.bat
Dekomprimiere: catchme.3XE
Dekomprimiere: clsid.c
Dekomprimiere: dd.3XE
Dekomprimiere: ddsDo.sed
Dekomprimiere: dumphive.3XE
Dekomprimiere: embedded.sed
Dekomprimiere: extract.3XE
Dekomprimiere: ffdefstr.dll
Dekomprimiere: ffext.pif
Dekomprimiere: files.pif
Dekomprimiere: firefox.exe
Dekomprimiere: fl0.bat
Dekomprimiere: grep.3XE
Dekomprimiere: gsar.3XE
Dekomprimiere: handle.3XE
Dekomprimiere: hidec.3XE
Dekomprimiere: history.bat
Dekomprimiere: hwid.pif
Dekomprimiere: iexplore.exe
Dekomprimiere: image001.gif
Dekomprimiere: iphlpsvc.vista.dat
Dekomprimiere: iphlpsvc.w7.dat
Dekomprimiere: iphlpsvc.w8.dat
Dekomprimiere: katch.cmd
Dekomprimiere: lnkread.vbs
Dekomprimiere: mbr.3XE
Dekomprimiere: mbr.chk
Dekomprimiere: md5sum.pif
Dekomprimiere: md5sum00.pif
Dekomprimiere: mtee.3XE
Dekomprimiere: mynul.dat
Dekomprimiere: ncmd.com
Dekomprimiere: ndis_combofix.dat
Dekomprimiere: netsvc.bad.dat
Dekomprimiere: netsvc.dat
Dekomprimiere: netsvc.vista.dat
Dekomprimiere: netsvc.xp.dat
Dekomprimiere: nir.pif
Dekomprimiere: pausep.3XE
Dekomprimiere: pev.3XE
Dekomprimiere: pevb.3XE
Dekomprimiere: powp.dat
Dekomprimiere: pv.com
Dekomprimiere: region.dat
Dekomprimiere: restore_pt.vbs
Dekomprimiere: rmbr.3XE
Dekomprimiere: rogues.dat
Dekomprimiere: run2.sed
Dekomprimiere: s0rt.3XE
Dekomprimiere: safeboot.dat
Dekomprimiere: safeboot.def.dat
Dekomprimiere: safeboot.def.vista.dat
Dekomprimiere: sed.3XE
Dekomprimiere: setpath.3XE
Dekomprimiere: sqlite3.3XE
Dekomprimiere: srizbi.md5
Dekomprimiere: svc_wht.dat
Dekomprimiere: svchost.dat
Dekomprimiere: svchost.vista.dat
Dekomprimiere: svchost.vista.x64.dat
Dekomprimiere: svchost.w7.dat
Dekomprimiere: svchost.w7.x64.dat
Dekomprimiere: svchost.w8.dat
Dekomprimiere: svchost.w8.x64.dat
Dekomprimiere: swreg.3XE
Dekomprimiere: swsc.3XE
Dekomprimiere: swxcacls.3XE
Dekomprimiere: system_ini.dat
Dekomprimiere: tail.3XE
Dekomprimiere: toolbar.sed
Dekomprimiere: vistaMcode.dat
Dekomprimiere: vistareg.dat
Dekomprimiere: vun.dat
Dekomprimiere: w7Mcode.dat
Dekomprimiere: w7reg.dat
Dekomprimiere: w8reg.dat
Dekomprimiere: w_sock.dll
Dekomprimiere: xpmcode.dat
Dekomprimiere: xpreg.dat
Dekomprimiere: zDomain.dat
Dekomprimiere: zhsvc.dat
Dekomprimiere: zip.3XE
Zielverzeichnis: C:\32788R22FWJFW\EN-US
Dekomprimiere: iexplore.exe
Zielverzeichnis: C:\32788R22FWJFW\License
Dekomprimiere: Curl - license.txt
Dekomprimiere: EXTRACT.TXT
Dekomprimiere: FI - license.txt
Dekomprimiere: UnxUtilsDist.com
Dekomprimiere: UnxUtilsDist.html
Dekomprimiere: UnxUtilsDist.pif
Dekomprimiere: Zip - license.txt
Dekomprimiere: dumphive-license.txt
Dekomprimiere: firefox.exe
Dekomprimiere: iexplore.exe
Dekomprimiere: mtee.txt
Dekomprimiere: ncmd.cfxxe
Dekomprimiere: pv_5_2_2.zip
Dekomprimiere: streamtools.zip
Zielverzeichnis: C:\32788R22FWJFW\N_
Zielverzeichnis: C:\32788R22FWJFW

Nach über einer Stunde habei ich das Ganze dann abgebrochen.
Ein Neustart hat auch nicht geholfen. Das Ganze stoppte auch wieder hier. Oder brauche ich einfach mehr Geduld, ich hab einfach wenig (eigentlich keine) Ahnung, von dem was ich hier mache ;-)

Habe unter C: noch eine "seltsame" Datei gesehen:
{2B69C873-DB034A58-B8A7-5B501B86D93D}

Grüße

Sabine 99:heulen:

schrauber 29.06.2013 08:55

Hi,

Combofix löschen und neu laden. Dann nochmal versuchen und zwar so (Combofix muss auf dem Desktop liegen):

Windows-Taste+R drücken, schreibe

"%userprofile%\desktop\Combofix.exe" /KillAll

und drücke Enter.

Sabine99 29.06.2013 09:22

Hi Schrauber,

habe alles gemacht, wie beschrieben.
Combofix stoppt wieder an der gleichen Stelle, und nun?

Grüße und Danke für Deine Geduld

Sabine99

schrauber 29.06.2013 11:36

Dann jetzt anders:

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

Sabine99 29.06.2013 12:50

Hi Schrauber,

das hat jetzt einwandfrei geklappt.
Anbei das log.file
Code:

13:32:19.0917 4784  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
13:32:20.0203 4784  ============================================================
13:32:20.0203 4784  Current date / time: 2013/06/29 13:32:20.0203
13:32:20.0203 4784  SystemInfo:
13:32:20.0203 4784 
13:32:20.0203 4784  OS Version: 6.0.6002 ServicePack: 2.0
13:32:20.0203 4784  Product type: Workstation
13:32:20.0203 4784  ComputerName: *****-PC
13:32:20.0204 4784  UserName: *****
13:32:20.0204 4784  Windows directory: C:\Windows
13:32:20.0204 4784  System windows directory: C:\Windows
13:32:20.0204 4784  Processor architecture: Intel x86
13:32:20.0204 4784  Number of processors: 4
13:32:20.0204 4784  Page size: 0x1000
13:32:20.0204 4784  Boot type: Normal boot
13:32:20.0204 4784  ============================================================
13:32:22.0579 4784  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:32:22.0608 4784  ============================================================
13:32:22.0608 4784  \Device\Harddisk0\DR0:
13:32:22.0609 4784  MBR partitions:
13:32:22.0609 4784  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x37B8418F
13:32:22.0632 4784  \Device\Harddisk0\DR0\Partition2: MBR, Type 0xB, StartLBA 0x37B8420D, BlocksNum 0x2800A34
13:32:22.0632 4784  ============================================================
13:32:22.0663 4784  C: <-> \Device\Harddisk0\DR0\Partition1
13:32:22.0663 4784  D: <-> \Device\Harddisk0\DR0\Partition2
13:32:22.0664 4784  ============================================================
13:32:22.0664 4784  Initialize success
13:32:22.0664 4784  ============================================================
13:33:47.0959 6000  ============================================================
13:33:47.0959 6000  Scan started
13:33:47.0959 6000  Mode: Manual; SigCheck; TDLFS;
13:33:47.0959 6000  ============================================================
13:33:48.0942 6000  ================ Scan system memory ========================
13:33:48.0942 6000  System memory - ok
13:33:48.0942 6000  ================ Scan services =============================
13:33:49.0192 6000  [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI            C:\Windows\system32\drivers\acpi.sys
13:33:49.0332 6000  ACPI - ok
13:33:50.0128 6000  [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
13:33:50.0159 6000  AdobeARMservice - ok
13:33:50.0533 6000  [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
13:33:50.0549 6000  AdobeFlashPlayerUpdateSvc - ok
13:33:50.0736 6000  [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
13:33:50.0752 6000  adp94xx - ok
13:33:50.0861 6000  [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci        C:\Windows\system32\drivers\adpahci.sys
13:33:50.0892 6000  adpahci - ok
13:33:50.0939 6000  [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
13:33:50.0954 6000  adpu160m - ok
13:33:51.0048 6000  [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320        C:\Windows\system32\drivers\adpu320.sys
13:33:51.0110 6000  adpu320 - ok
13:33:51.0298 6000  [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
13:33:51.0329 6000  AeLookupSvc - ok
13:33:51.0547 6000  [ 3911B972B55FEA0478476B2E777B29FA ] AFD            C:\Windows\system32\drivers\afd.sys
13:33:51.0734 6000  AFD - ok
13:33:51.0859 6000  [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
13:33:51.0922 6000  aic78xx - ok
13:33:51.0984 6000  [ A1545B731579895D8CC44FC0481C1192 ] ALG            C:\Windows\System32\alg.exe
13:33:52.0312 6000  ALG - ok
13:33:52.0421 6000  [ 496EDA16A127AC9A38BB285BEF17DBB5 ] aliide          C:\Windows\system32\drivers\aliide.sys
13:33:52.0436 6000  aliide - ok
13:33:52.0686 6000  [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
13:33:52.0702 6000  amdagp - ok
13:33:52.0764 6000  [ 6F65F4147C54398D7280B18CEBBED215 ] amdide          C:\Windows\system32\drivers\amdide.sys
13:33:52.0780 6000  amdide - ok
13:33:52.0889 6000  [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7          C:\Windows\system32\drivers\amdk7.sys
13:33:53.0294 6000  AmdK7 - ok
13:33:53.0357 6000  [ 0CA0071DA4315B00FC1328CA86B425DA ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
13:33:53.0404 6000  AmdK8 - ok
13:33:53.0560 6000  [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo        C:\Windows\System32\appinfo.dll
13:33:53.0700 6000  Appinfo - ok
13:33:53.0934 6000  [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
13:33:53.0950 6000  Apple Mobile Device - ok
13:33:54.0028 6000  [ 5F673180268BB1FDB69C99B6619FE379 ] arc            C:\Windows\system32\drivers\arc.sys
13:33:54.0043 6000  arc - ok
13:33:54.0152 6000  [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
13:33:54.0168 6000  arcsas - ok
13:33:54.0605 6000  [ 40C145F12FF461A0220303BDA134F598 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
13:33:54.0620 6000  aspnet_state - ok
13:33:54.0745 6000  [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
13:33:54.0792 6000  AsyncMac - ok
13:33:54.0901 6000  [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi          C:\Windows\system32\drivers\atapi.sys
13:33:54.0917 6000  atapi - ok
13:33:55.0088 6000  [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:33:55.0229 6000  AudioEndpointBuilder - ok
13:33:55.0291 6000  [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv        C:\Windows\System32\Audiosrv.dll
13:33:55.0322 6000  Audiosrv - ok
13:33:55.0494 6000  [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep            C:\Windows\system32\drivers\Beep.sys
13:33:55.0619 6000  Beep - ok
13:33:55.0806 6000  [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE            C:\Windows\System32\bfe.dll
13:33:55.0884 6000  BFE - ok
13:33:56.0258 6000  [ 6C6AC7CA8A034C15C52B35189BAD58EE ] BHDrvx86        C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130531.001\BHDrvx86.sys
13:33:56.0305 6000  BHDrvx86 - ok
13:33:56.0383 6000  [ 93952506C6D67330367F7E7934B6A02F ] BITS            C:\Windows\System32\qmgr.dll
13:33:56.0477 6000  BITS - ok
13:33:56.0477 6000  blbdrive - ok
13:33:56.0555 6000  [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
13:33:56.0586 6000  Bonjour Service - ok
13:33:56.0617 6000  [ 35F376253F687BDE63976CCB3F2108CA ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
13:33:56.0664 6000  bowser - ok
13:33:56.0695 6000  [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
13:33:56.0742 6000  BrFiltLo - ok
13:33:56.0758 6000  [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
13:33:56.0789 6000  BrFiltUp - ok
13:33:56.0929 6000  [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser        C:\Windows\System32\browser.dll
13:33:56.0960 6000  Browser - ok
13:33:57.0038 6000  [ B304E75CFF293029EDDF094246747113 ] Brserid        C:\Windows\system32\drivers\brserid.sys
13:33:57.0179 6000  Brserid - ok
13:33:57.0226 6000  [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
13:33:57.0272 6000  BrSerWdm - ok
13:33:57.0304 6000  [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
13:33:57.0397 6000  BrUsbMdm - ok
13:33:57.0397 6000  [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
13:33:57.0444 6000  BrUsbSer - ok
13:33:57.0506 6000  [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
13:33:57.0553 6000  BTHMODEM - ok
13:33:57.0647 6000  [ 3BEE52611F22C9C0023A98A4425E084F ] ccSet_N360      C:\Windows\system32\drivers\N360\1404000.028\ccSetx86.sys
13:33:57.0662 6000  ccSet_N360 - ok
13:33:57.0709 6000  [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
13:33:57.0756 6000  cdfs - ok
13:33:57.0803 6000  [ 6B4BFFB9BECD728097024276430DB314 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
13:33:57.0834 6000  cdrom - ok
13:33:57.0881 6000  [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc    C:\Windows\System32\certprop.dll
13:33:57.0896 6000  CertPropSvc - ok
13:33:57.0943 6000  [ D7FCFE79CF770886FEF1EAD247A2C660 ] CH375          C:\Windows\system32\Drivers\CH375WDM.SYS
13:33:57.0974 6000  CH375 - ok
13:33:57.0990 6000  [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass        C:\Windows\system32\drivers\circlass.sys
13:33:58.0052 6000  circlass - ok
13:33:58.0162 6000  [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS            C:\Windows\system32\CLFS.sys
13:33:58.0193 6000  CLFS - ok
13:33:58.0224 6000  [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:33:58.0240 6000  clr_optimization_v2.0.50727_32 - ok
13:33:58.0286 6000  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:33:58.0302 6000  clr_optimization_v4.0.30319_32 - ok
13:33:58.0427 6000  [ 59172A0724F2AB769F31D61B0571D75B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
13:33:58.0458 6000  cmdide - ok
13:33:58.0552 6000  [ 82B8C91D327CFECF76CB58716F7D4997 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
13:33:58.0567 6000  Compbatt - ok
13:33:58.0567 6000  COMSysApp - ok
13:33:58.0583 6000  [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
13:33:58.0598 6000  crcdisk - ok
13:33:58.0614 6000  [ 22A7F883508176489F559EE745B5BF5D ] Crusoe          C:\Windows\system32\drivers\crusoe.sys
13:33:58.0676 6000  Crusoe - ok
13:33:58.0723 6000  [ 3EDE4C1F9672C972479201544969ADCB ] CryptSvc        C:\Windows\system32\cryptsvc.dll
13:33:58.0754 6000  CryptSvc - ok
13:33:58.0801 6000  [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch      C:\Windows\system32\rpcss.dll
13:33:58.0848 6000  DcomLaunch - ok
13:33:58.0864 6000  [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
13:33:58.0895 6000  DfsC - ok
13:33:58.0973 6000  [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR            C:\Windows\system32\DFSR.exe
13:33:59.0082 6000  DFSR - ok
13:33:59.0144 6000  [ 9028559C132146FB75EB7ACF384B086A ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
13:33:59.0176 6000  Dhcp - ok
13:33:59.0222 6000  [ 5D4AEFC3386920236A548271F8F1AF6A ] disk            C:\Windows\system32\drivers\disk.sys
13:33:59.0238 6000  disk - ok
13:33:59.0285 6000  [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache        C:\Windows\System32\dnsrslvr.dll
13:33:59.0316 6000  Dnscache - ok
13:33:59.0332 6000  [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc        C:\Windows\System32\dot3svc.dll
13:33:59.0394 6000  dot3svc - ok
13:33:59.0425 6000  [ 4F59C172C094E1A1D46463A8DC061CBD ] Dot4            C:\Windows\system32\DRIVERS\Dot4.sys
13:33:59.0456 6000  Dot4 - ok
13:33:59.0472 6000  [ 80BF3BA09F6F2523C8F6B7CC6DBF7BD5 ] Dot4Print      C:\Windows\system32\DRIVERS\Dot4Prt.sys
13:33:59.0519 6000  Dot4Print - ok
13:33:59.0534 6000  [ C55004CA6B419B6695970DFE849B122F ] dot4usb        C:\Windows\system32\DRIVERS\dot4usb.sys
13:33:59.0581 6000  dot4usb - ok
13:33:59.0612 6000  [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS            C:\Windows\system32\dps.dll
13:33:59.0659 6000  DPS - ok
13:33:59.0675 6000  [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
13:33:59.0706 6000  drmkaud - ok
13:33:59.0737 6000  [ 5DE0FAEC9E5D1AAE74F8568897891A01 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
13:33:59.0784 6000  DXGKrnl - ok
13:33:59.0815 6000  [ 476D9F2F0789CDE89ACEE2A2FB21EC5A ] e1express      C:\Windows\system32\DRIVERS\e1e6032.sys
13:33:59.0831 6000  e1express - ok
13:33:59.0878 6000  [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60          C:\Windows\system32\DRIVERS\E1G60I32.sys
13:33:59.0909 6000  E1G60 - ok
13:33:59.0940 6000  [ C0B95E40D85CD807D614E264248A45B9 ] EapHost        C:\Windows\System32\eapsvc.dll
13:33:59.0956 6000  EapHost - ok
13:34:00.0002 6000  [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache          C:\Windows\system32\drivers\ecache.sys
13:34:00.0018 6000  Ecache - ok
13:34:00.0080 6000  [ 85B8B4032A895A746D46A288A9B30DED ] eeCtrl          C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
13:34:00.0096 6000  eeCtrl - ok
13:34:00.0158 6000  [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
13:34:00.0190 6000  ehRecvr - ok
13:34:00.0205 6000  [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched        C:\Windows\ehome\ehsched.exe
13:34:00.0236 6000  ehSched - ok
13:34:00.0252 6000  [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart        C:\Windows\ehome\ehstart.dll
13:34:00.0268 6000  ehstart - ok
13:34:00.0283 6000  [ E8F3F21A71720C84BCF423B80028359F ] elxstor        C:\Windows\system32\drivers\elxstor.sys
13:34:00.0314 6000  elxstor - ok
13:34:00.0346 6000  [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
13:34:00.0439 6000  EMDMgmt - ok
13:34:00.0470 6000  [ B5A8A04A6E5B4E86B95B1553AA918F5F ] EraserUtilRebootDrv C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
13:34:00.0486 6000  EraserUtilRebootDrv - ok
13:34:00.0533 6000  [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem    C:\Windows\system32\es.dll
13:34:00.0564 6000  EventSystem - ok
13:34:00.0595 6000  [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat          C:\Windows\system32\drivers\exfat.sys
13:34:00.0658 6000  exfat - ok
13:34:00.0689 6000  [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
13:34:00.0720 6000  fastfat - ok
13:34:00.0751 6000  [ 63BDADA84951B9C03E641800E176898A ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
13:34:00.0814 6000  fdc - ok
13:34:00.0845 6000  [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost        C:\Windows\system32\fdPHost.dll
13:34:00.0892 6000  fdPHost - ok
13:34:00.0954 6000  [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub        C:\Windows\system32\fdrespub.dll
13:34:01.0001 6000  FDResPub - ok
13:34:01.0016 6000  [ B2B2C38E916184FF8523C7439DDD417F ] FETNDIS        C:\Windows\system32\DRIVERS\fetnd5.sys
13:34:01.0063 6000  FETNDIS - ok
13:34:01.0063 6000  [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
13:34:01.0079 6000  FileInfo - ok
13:34:01.0094 6000  [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
13:34:01.0110 6000  Filetrace - ok
13:34:01.0126 6000  [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
13:34:01.0157 6000  flpydisk - ok
13:34:01.0188 6000  [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
13:34:01.0204 6000  FltMgr - ok
13:34:01.0266 6000  [ 8CE364388C8ECA59B14B539179276D44 ] FontCache      C:\Windows\system32\FntCache.dll
13:34:01.0328 6000  FontCache - ok
13:34:01.0391 6000  [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:34:01.0406 6000  FontCache3.0.0.0 - ok
13:34:01.0422 6000  [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
13:34:01.0500 6000  Fs_Rec - ok
13:34:01.0500 6000  [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
13:34:01.0516 6000  gagp30kx - ok
13:34:01.0547 6000  [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:34:01.0562 6000  GEARAspiWDM - ok
13:34:01.0609 6000  [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc          C:\Windows\System32\gpsvc.dll
13:34:01.0672 6000  gpsvc - ok
13:34:01.0750 6000  [ F02A533F517EB38333CB12A9E8963773 ] gupdate        C:\Program Files\Google\Update\GoogleUpdate.exe
13:34:01.0765 6000  gupdate - ok
13:34:01.0781 6000  [ F02A533F517EB38333CB12A9E8963773 ] gupdatem        C:\Program Files\Google\Update\GoogleUpdate.exe
13:34:01.0796 6000  gupdatem - ok
13:34:01.0828 6000  [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
13:34:01.0843 6000  gusvc - ok
13:34:01.0874 6000  [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:34:01.0921 6000  HdAudAddService - ok
13:34:01.0952 6000  [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
13:34:02.0030 6000  HDAudBus - ok
13:34:02.0046 6000  [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth          C:\Windows\system32\drivers\hidbth.sys
13:34:02.0124 6000  HidBth - ok
13:34:02.0140 6000  [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr          C:\Windows\system32\drivers\hidir.sys
13:34:02.0218 6000  HidIr - ok
13:34:02.0249 6000  [ 84067081F3318162797385E11A8F0582 ] hidserv        C:\Windows\System32\hidserv.dll
13:34:02.0280 6000  hidserv - ok
13:34:02.0296 6000  [ CCA4B519B17E23A00B826C55716809CC ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
13:34:02.0311 6000  HidUsb - ok
13:34:02.0342 6000  [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc          C:\Windows\system32\kmsvc.dll
13:34:02.0374 6000  hkmsvc - ok
13:34:02.0389 6000  [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
13:34:02.0405 6000  HpCISSs - ok
13:34:02.0514 6000  [ 0A3C6AA4A9FC38C20BA4EAC2C3351C05 ] hpqcxs08        C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
13:34:02.0530 6000  hpqcxs08 ( UnsignedFile.Multi.Generic ) - warning
13:34:02.0530 6000  hpqcxs08 - detected UnsignedFile.Multi.Generic (1)
13:34:02.0561 6000  [ 7DA3211AC63EDD90B8ECA1CA1ABFD43B ] hpqddsvc        C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
13:34:02.0561 6000  hpqddsvc ( UnsignedFile.Multi.Generic ) - warning
13:34:02.0561 6000  hpqddsvc - detected UnsignedFile.Multi.Generic (1)
13:34:02.0592 6000  [ 14229263AA19C704E0D6D2E7404A8455 ] HPSLPSVC        C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL
13:34:02.0639 6000  HPSLPSVC ( UnsignedFile.Multi.Generic ) - warning
13:34:02.0639 6000  HPSLPSVC - detected UnsignedFile.Multi.Generic (1)
13:34:02.0701 6000  [ F870AA3E254628EBEAFE754108D664DE ] HTTP            C:\Windows\system32\drivers\HTTP.sys
13:34:02.0764 6000  HTTP - ok
13:34:02.0795 6000  [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
13:34:02.0810 6000  i2omp - ok
13:34:02.0842 6000  [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
13:34:02.0873 6000  i8042prt - ok
13:34:02.0888 6000  [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
13:34:02.0904 6000  iaStorV - ok
13:34:02.0982 6000  [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc          C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:34:03.0029 6000  idsvc - ok
13:34:03.0107 6000  [ 404FB2AAF532BC7BBACC8880BE401C74 ] IDSVix86        C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130621.001\IDSvix86.sys
13:34:03.0122 6000  IDSVix86 - ok
13:34:03.0154 6000  [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
13:34:03.0169 6000  iirsp - ok
13:34:03.0200 6000  [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT          C:\Windows\System32\ikeext.dll
13:34:03.0263 6000  IKEEXT - ok
13:34:03.0341 6000  [ 622FCF264119F7DF127BE353F796B319 ] InboxAce_1gService C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe
13:34:03.0356 6000  InboxAce_1gService - ok
13:34:03.0356 6000  IntcAzAudAddService - ok
13:34:03.0388 6000  [ E5EA1C17DA5065032E346591FF64F3AF ] intelide        C:\Windows\system32\drivers\intelide.sys
13:34:03.0403 6000  intelide - ok
13:34:03.0434 6000  [ 224191001E78C89DFA78924C3EA595FF ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
13:34:03.0466 6000  intelppm - ok
13:34:03.0481 6000  [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
13:34:03.0528 6000  IPBusEnum - ok
13:34:03.0544 6000  [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:34:03.0590 6000  IpFilterDriver - ok
13:34:03.0637 6000  [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
13:34:03.0653 6000  iphlpsvc - ok
13:34:03.0653 6000  IpInIp - ok
13:34:03.0668 6000  [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
13:34:03.0700 6000  IPMIDRV - ok
13:34:03.0715 6000  [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
13:34:03.0762 6000  IPNAT - ok
13:34:03.0809 6000  [ FE56897B27ED266F9C4E7D90A0B5DA47 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
13:34:03.0824 6000  iPod Service - ok
13:34:03.0840 6000  [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
13:34:03.0871 6000  IRENUM - ok
13:34:03.0887 6000  [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
13:34:03.0887 6000  isapnp - ok
13:34:03.0918 6000  [ 232FA340531D940AAC623B121A595034 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
13:34:03.0934 6000  iScsiPrt - ok
13:34:03.0949 6000  [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
13:34:03.0965 6000  iteatapi - ok
13:34:03.0965 6000  [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid        C:\Windows\system32\drivers\iteraid.sys
13:34:03.0980 6000  iteraid - ok
13:34:03.0996 6000  [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
13:34:04.0012 6000  kbdclass - ok
13:34:04.0043 6000  [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
13:34:04.0058 6000  kbdhid - ok
13:34:04.0074 6000  [ A3E186B4B935905B829219502557314E ] KeyIso          C:\Windows\system32\lsass.exe
13:34:04.0090 6000  KeyIso - ok
13:34:04.0136 6000  [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
13:34:04.0152 6000  KSecDD - ok
13:34:04.0199 6000  [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm          C:\Windows\system32\msdtckrm.dll
13:34:04.0230 6000  KtmRm - ok
13:34:04.0261 6000  [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer    C:\Windows\System32\srvsvc.dll
13:34:04.0324 6000  LanmanServer - ok
13:34:04.0355 6000  [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:34:04.0402 6000  LanmanWorkstation - ok
13:34:04.0402 6000  [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
13:34:04.0464 6000  lltdio - ok
13:34:04.0480 6000  [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
13:34:04.0511 6000  lltdsvc - ok
13:34:04.0526 6000  [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts        C:\Windows\System32\lmhsvc.dll
13:34:04.0558 6000  lmhosts - ok
13:34:04.0589 6000  [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
13:34:04.0604 6000  LSI_FC - ok
13:34:04.0620 6000  [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
13:34:04.0620 6000  LSI_SAS - ok
13:34:04.0636 6000  [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
13:34:04.0651 6000  LSI_SCSI - ok
13:34:04.0682 6000  [ 8F5C7426567798E62A3B3614965D62CC ] luafv          C:\Windows\system32\drivers\luafv.sys
13:34:04.0729 6000  luafv - ok
13:34:04.0760 6000  [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
13:34:04.0776 6000  Mcx2Svc - ok
13:34:04.0792 6000  [ D153B14FC6598EAE8422A2037553ADCE ] megasas        C:\Windows\system32\drivers\megasas.sys
13:34:04.0792 6000  megasas - ok
13:34:04.0823 6000  [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS          C:\Windows\system32\mmcss.dll
13:34:04.0854 6000  MMCSS - ok
13:34:04.0870 6000  [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem          C:\Windows\system32\drivers\modem.sys
13:34:04.0901 6000  Modem - ok
13:34:04.0932 6000  [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
13:34:04.0994 6000  monitor - ok
13:34:05.0026 6000  [ 5BF6A1326A335C5298477754A506D263 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
13:34:05.0057 6000  mouclass - ok
13:34:05.0072 6000  [ 93B8D4869E12CFBE663915502900876F ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
13:34:05.0150 6000  mouhid - ok
13:34:05.0260 6000  [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
13:34:05.0306 6000  MountMgr - ok
13:34:05.0338 6000  [ 583A41F26278D9E0EA548163D6139397 ] mpio            C:\Windows\system32\drivers\mpio.sys
13:34:05.0353 6000  mpio - ok
13:34:05.0369 6000  [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
13:34:05.0384 6000  mpsdrv - ok
13:34:05.0416 6000  [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc          C:\Windows\system32\mpssvc.dll
13:34:05.0447 6000  MpsSvc - ok
13:34:05.0462 6000  [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
13:34:05.0478 6000  Mraid35x - ok
13:34:05.0478 6000  [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
13:34:05.0494 6000  MRxDAV - ok
13:34:05.0509 6000  [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
13:34:05.0540 6000  mrxsmb - ok
13:34:05.0572 6000  [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:34:05.0587 6000  mrxsmb10 - ok
13:34:05.0603 6000  [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:34:05.0618 6000  mrxsmb20 - ok
13:34:05.0665 6000  [ 5457DCFA7C0DA43522F4D9D4049C1472 ] msahci          C:\Windows\system32\drivers\msahci.sys
13:34:05.0681 6000  msahci - ok
13:34:05.0696 6000  [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
13:34:05.0696 6000  msdsm - ok
13:34:05.0728 6000  [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC          C:\Windows\System32\msdtc.exe
13:34:05.0774 6000  MSDTC - ok
13:34:05.0806 6000  [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
13:34:05.0837 6000  Msfs - ok
13:34:05.0852 6000  [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
13:34:05.0868 6000  msisadrv - ok
13:34:05.0884 6000  [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
13:34:05.0930 6000  MSiSCSI - ok
13:34:05.0930 6000  msiserver - ok
13:34:05.0977 6000  [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
13:34:06.0008 6000  MSKSSRV - ok
13:34:06.0040 6000  [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
13:34:06.0055 6000  MSPCLOCK - ok
13:34:06.0071 6000  [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
13:34:06.0102 6000  MSPQM - ok
13:34:06.0118 6000  [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
13:34:06.0133 6000  MsRPC - ok
13:34:06.0149 6000  [ E384487CB84BE41D09711C30CA79646C ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
13:34:06.0164 6000  mssmbios - ok
13:34:06.0164 6000  [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
13:34:06.0196 6000  MSTEE - ok
13:34:06.0227 6000  [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup            C:\Windows\system32\Drivers\mup.sys
13:34:06.0227 6000  Mup - ok
13:34:06.0305 6000  [ 1BF9D6476061B31CD7FC2BF848529A56 ] N360            C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
13:34:06.0320 6000  N360 - ok
13:34:06.0352 6000  [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent        C:\Windows\system32\qagentRT.dll
13:34:06.0367 6000  napagent - ok
13:34:06.0414 6000  [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
13:34:06.0430 6000  NativeWifiP - ok
13:34:06.0461 6000  [ CE2156DF796D41614AB60E68D107D573 ] NAVENG          C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVENG.SYS
13:34:06.0476 6000  NAVENG - ok
13:34:06.0539 6000  [ 19CEB8F4EC8C800A53D0B67E658E0367 ] NAVEX15        C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVEX15.SYS
13:34:06.0632 6000  NAVEX15 - ok
13:34:06.0695 6000  [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS            C:\Windows\system32\drivers\ndis.sys
13:34:06.0742 6000  NDIS - ok
13:34:06.0757 6000  [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
13:34:06.0804 6000  NdisTapi - ok
13:34:06.0820 6000  [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
13:34:06.0866 6000  Ndisuio - ok
13:34:06.0882 6000  [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
13:34:06.0913 6000  NdisWan - ok
13:34:06.0929 6000  [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
13:34:06.0960 6000  NDProxy - ok
13:34:07.0085 6000  [ 6D4028D458EAAA1782099750790DC8C9 ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
13:34:07.0116 6000  Nero BackItUp Scheduler 3 - ok
13:34:07.0147 6000  [ 2969D26EEE289BE7422AA46FC55F4E38 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
13:34:07.0147 6000  Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
13:34:07.0147 6000  Net Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
13:34:07.0163 6000  [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
13:34:07.0194 6000  NetBIOS - ok
13:34:07.0225 6000  [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
13:34:07.0288 6000  netbt - ok
13:34:07.0303 6000  [ A3E186B4B935905B829219502557314E ] Netlogon        C:\Windows\system32\lsass.exe
13:34:07.0319 6000  Netlogon - ok
13:34:07.0334 6000  [ C8052711DAECC48B982434C5116CA401 ] Netman          C:\Windows\System32\netman.dll
13:34:07.0366 6000  Netman - ok
13:34:07.0397 6000  [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm        C:\Windows\System32\netprofm.dll
13:34:07.0428 6000  netprofm - ok
13:34:07.0459 6000  [ 2E812881EC96E80EAE304877ED90206B ] netr28u        C:\Windows\system32\DRIVERS\netr28u.sys
13:34:07.0522 6000  netr28u - ok
13:34:07.0553 6000  [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
13:34:07.0568 6000  NetTcpPortSharing - ok
13:34:07.0615 6000  [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
13:34:07.0631 6000  nfrd960 - ok
13:34:07.0646 6000  [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc          C:\Windows\System32\nlasvc.dll
13:34:07.0693 6000  NlaSvc - ok
13:34:07.0771 6000  [ D36107465E716CF2335A25C54B6D11C2 ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
13:34:07.0787 6000  NMIndexingService - ok
13:34:07.0802 6000  [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
13:34:07.0849 6000  Npfs - ok
13:34:07.0880 6000  [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi            C:\Windows\system32\nsisvc.dll
13:34:07.0927 6000  nsi - ok
13:34:07.0958 6000  [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
13:34:08.0005 6000  nsiproxy - ok
13:34:08.0052 6000  [ 2C1121F2B87E9A6B12485DF53CD848C7 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
13:34:08.0114 6000  Ntfs - ok
13:34:08.0130 6000  [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi      C:\Windows\system32\drivers\ntrigdigi.sys
13:34:08.0192 6000  ntrigdigi - ok
13:34:08.0192 6000  [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null            C:\Windows\system32\drivers\Null.sys
13:34:08.0224 6000  Null - ok
13:34:08.0426 6000  [ B69E6F70CE1151C8D62ABC9DEF64DFBE ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
13:34:08.0723 6000  nvlddmkm - ok
13:34:08.0754 6000  [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
13:34:08.0770 6000  nvraid - ok
13:34:08.0785 6000  [ 9E0BA19A28C498A6D323D065DB76DFFC ] nvstor          C:\Windows\system32\drivers\nvstor.sys
13:34:08.0801 6000  nvstor - ok
13:34:08.0863 6000  [ E4284FCF99FEA13A7E1836F87AE356F6 ] nvsvc          C:\Windows\system32\nvvsvc.exe
13:34:08.0894 6000  nvsvc - ok
13:34:09.0019 6000  [ 03E60E0BFA53ED15DC984FA34B44BB0F ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
13:34:09.0066 6000  nvUpdatusService - ok
13:34:09.0082 6000  [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
13:34:09.0097 6000  nv_agp - ok
13:34:09.0097 6000  NwlnkFlt - ok
13:34:09.0113 6000  NwlnkFwd - ok
13:34:09.0175 6000  [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv          C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
13:34:09.0191 6000  odserv - ok
13:34:09.0238 6000  [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
13:34:09.0269 6000  ohci1394 - ok
13:34:09.0300 6000  [ 5A432A042DAE460ABE7199B758E8606C ] ose            C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:34:09.0331 6000  ose - ok
13:34:09.0362 6000  [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc        C:\Windows\system32\p2psvc.dll
13:34:09.0456 6000  p2pimsvc - ok
13:34:09.0472 6000  [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc          C:\Windows\system32\p2psvc.dll
13:34:09.0503 6000  p2psvc - ok
13:34:09.0550 6000  [ 0FA9B5055484649D63C303FE404E5F4D ] Parport        C:\Windows\system32\DRIVERS\parport.sys
13:34:09.0612 6000  Parport - ok
13:34:09.0628 6000  [ B9C2B89F08670E159F7181891E449CD9 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
13:34:09.0643 6000  partmgr - ok
13:34:09.0659 6000  [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm          C:\Windows\system32\DRIVERS\parvdm.sys
13:34:09.0706 6000  Parvdm - ok
13:34:09.0737 6000  [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc          C:\Windows\System32\pcasvc.dll
13:34:09.0768 6000  PcaSvc - ok
13:34:09.0799 6000  [ 941DC1D19E7E8620F40BBC206981EFDB ] pci            C:\Windows\system32\drivers\pci.sys
13:34:09.0815 6000  pci - ok
13:34:09.0846 6000  [ 304048C2565A803D091CCA1AC945F593 ] pciide          C:\Windows\system32\drivers\pciide.sys
13:34:09.0862 6000  pciide - ok
13:34:09.0877 6000  [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
13:34:09.0893 6000  pcmcia - ok
13:34:09.0940 6000  [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
13:34:10.0018 6000  PEAUTH - ok
13:34:10.0096 6000  [ 9F2F541C52CD7A452E235E885F7D95DE ] Ph3xIB32        C:\Windows\system32\DRIVERS\Ph3xIB32.sys
13:34:10.0189 6000  Ph3xIB32 - ok
13:34:10.0252 6000  [ B1689DF169143F57053F795390C99DB3 ] pla            C:\Windows\system32\pla.dll
13:34:10.0314 6000  pla - ok
13:34:10.0392 6000  [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
13:34:10.0423 6000  PlugPlay - ok
13:34:10.0439 6000  [ BAFC9706BDF425A02B66468AB2605C59 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
13:34:10.0439 6000  Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
13:34:10.0439 6000  Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
13:34:10.0454 6000  [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
13:34:10.0486 6000  PNRPAutoReg - ok
13:34:10.0501 6000  [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc        C:\Windows\system32\p2psvc.dll
13:34:10.0532 6000  PNRPsvc - ok
13:34:10.0579 6000  [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
13:34:10.0610 6000  PolicyAgent - ok
13:34:10.0642 6000  [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
13:34:10.0673 6000  PptpMiniport - ok
13:34:10.0673 6000  [ 0E3CEF5D28B40CF273281D620C50700A ] Processor      C:\Windows\system32\drivers\processr.sys
13:34:10.0735 6000  Processor - ok
13:34:10.0766 6000  [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc        C:\Windows\system32\profsvc.dll
13:34:10.0798 6000  ProfSvc - ok
13:34:10.0798 6000  [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
13:34:10.0813 6000  ProtectedStorage - ok
13:34:10.0860 6000  [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
13:34:10.0891 6000  PSched - ok
13:34:10.0954 6000  [ CCDAC889326317792480C0A67156A1EC ] ql2300          C:\Windows\system32\drivers\ql2300.sys
13:34:10.0985 6000  ql2300 - ok
13:34:11.0000 6000  [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
13:34:11.0016 6000  ql40xx - ok
13:34:11.0032 6000  [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE          C:\Windows\system32\qwave.dll
13:34:11.0047 6000  QWAVE - ok
13:34:11.0063 6000  [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
13:34:11.0078 6000  QWAVEdrv - ok
13:34:11.0141 6000  [ E642B131FB74CAF4BB8A014F31113142 ] R300            C:\Windows\system32\DRIVERS\atikmdag.sys
13:34:11.0266 6000  R300 - ok
13:34:11.0328 6000  [ 81BEBBFFE45855B7FAF204C517FBEEF1 ] RalinkRegistryWriter C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe
13:34:11.0328 6000  RalinkRegistryWriter - ok
13:34:11.0344 6000  [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
13:34:11.0390 6000  RasAcd - ok
13:34:11.0422 6000  [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto        C:\Windows\System32\rasauto.dll
13:34:11.0437 6000  RasAuto - ok
13:34:11.0453 6000  [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
13:34:11.0500 6000  Rasl2tp - ok
13:34:11.0546 6000  [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan          C:\Windows\System32\rasmans.dll
13:34:11.0578 6000  RasMan - ok
13:34:11.0609 6000  [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
13:34:11.0624 6000  RasPppoe - ok
13:34:11.0656 6000  [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
13:34:11.0671 6000  RasSstp - ok
13:34:11.0702 6000  [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
13:34:11.0718 6000  rdbss - ok
13:34:11.0718 6000  [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
13:34:11.0749 6000  RDPCDD - ok
13:34:11.0780 6000  [ E8BD98D46F2ED77132BA927FCCB47D8B ] rdpdr          C:\Windows\system32\drivers\rdpdr.sys
13:34:11.0827 6000  rdpdr - ok
13:34:11.0827 6000  [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
13:34:11.0858 6000  RDPENCDD - ok
13:34:11.0905 6000  [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
13:34:11.0936 6000  RDPWD - ok
13:34:11.0952 6000  [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess    C:\Windows\System32\mprdim.dll
13:34:11.0983 6000  RemoteAccess - ok
13:34:12.0014 6000  [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry  C:\Windows\system32\regsvc.dll
13:34:12.0046 6000  RemoteRegistry - ok
13:34:12.0108 6000  [ 17E0BEF5CA5C9CE52CC8082AC6EBC449 ] RichVideo      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
13:34:12.0124 6000  RichVideo - ok
13:34:12.0139 6000  [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator      C:\Windows\system32\locator.exe
13:34:12.0170 6000  RpcLocator - ok
13:34:12.0217 6000  [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs          C:\Windows\system32\rpcss.dll
13:34:12.0248 6000  RpcSs - ok
13:34:12.0264 6000  [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
13:34:12.0311 6000  rspndr - ok
13:34:12.0311 6000  [ A3E186B4B935905B829219502557314E ] SamSs          C:\Windows\system32\lsass.exe
13:34:12.0326 6000  SamSs - ok
13:34:12.0342 6000  [ 3CE8F073A557E172B330109436984E30 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
13:34:12.0358 6000  sbp2port - ok
13:34:12.0389 6000  [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
13:34:12.0420 6000  SCardSvr - ok
13:34:12.0451 6000  [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule        C:\Windows\system32\schedsvc.dll
13:34:12.0514 6000  Schedule - ok
13:34:12.0529 6000  [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc    C:\Windows\System32\certprop.dll
13:34:12.0545 6000  SCPolicySvc - ok
13:34:12.0560 6000  [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
13:34:12.0592 6000  SDRSVC - ok
13:34:12.0607 6000  [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
13:34:12.0654 6000  secdrv - ok
13:34:12.0670 6000  [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon        C:\Windows\system32\seclogon.dll
13:34:12.0701 6000  seclogon - ok
13:34:12.0716 6000  [ A9BBAB5759771E523F55563D6CBE140F ] SENS            C:\Windows\System32\sens.dll
13:34:12.0748 6000  SENS - ok
13:34:12.0763 6000  [ CE9EC966638EF0B10B864DDEDF62A099 ] Serenum        C:\Windows\system32\DRIVERS\serenum.sys
13:34:12.0810 6000  Serenum - ok
13:34:12.0857 6000  [ 6D663022DB3E7058907784AE14B69898 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
13:34:12.0872 6000  Serial - ok
13:34:12.0888 6000  [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
13:34:12.0919 6000  sermouse - ok
13:34:12.0919 6000  [ D2193326F729B163125610DBF3E17D57 ] SessionEnv      C:\Windows\system32\sessenv.dll
13:34:12.0950 6000  SessionEnv - ok
13:34:12.0950 6000  [ 103B79418DA647736EE95645F305F68A ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
13:34:12.0997 6000  sffdisk - ok
13:34:12.0997 6000  [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
13:34:13.0028 6000  sffp_mmc - ok
13:34:13.0044 6000  [ 9CFA05FCFCB7124E69CFC812B72F9614 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
13:34:13.0091 6000  sffp_sd - ok
13:34:13.0106 6000  [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
13:34:13.0153 6000  sfloppy - ok
13:34:13.0184 6000  [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
13:34:13.0216 6000  SharedAccess - ok
13:34:13.0247 6000  [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:34:13.0309 6000  ShellHWDetection - ok
13:34:13.0309 6000  [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
13:34:13.0325 6000  SiSRaid2 - ok
13:34:13.0340 6000  [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
13:34:13.0356 6000  SiSRaid4 - ok
13:34:13.0450 6000  [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc          C:\Windows\system32\SLsvc.exe
13:34:13.0637 6000  slsvc - ok
13:34:13.0668 6000  [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify      C:\Windows\system32\SLUINotify.dll
13:34:13.0715 6000  SLUINotify - ok
13:34:13.0762 6000  [ 7B75299A4D201D6A6533603D6914AB04 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
13:34:13.0777 6000  Smb - ok
13:34:13.0808 6000  [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
13:34:13.0824 6000  SNMPTRAP - ok
13:34:13.0855 6000  [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr          C:\Windows\system32\drivers\spldr.sys
13:34:13.0871 6000  spldr - ok
13:34:13.0886 6000  [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler        C:\Windows\System32\spoolsv.exe
13:34:13.0949 6000  Spooler - ok
13:34:13.0996 6000  [ C743E384E9EFCA10B41C60D406DE39C0 ] SRTSP          C:\Windows\System32\Drivers\N360\1404000.028\SRTSP.SYS
13:34:14.0042 6000  SRTSP - ok
13:34:14.0074 6000  [ FE9BD381778A344F0E39AE2D5E607D7F ] SRTSPX          C:\Windows\system32\drivers\N360\1404000.028\SRTSPX.SYS
13:34:14.0089 6000  SRTSPX - ok
13:34:14.0120 6000  [ 41987F9FC0E61ADF54F581E15029AD91 ] srv            C:\Windows\system32\DRIVERS\srv.sys
13:34:14.0152 6000  srv - ok
13:34:14.0183 6000  [ FF33AFF99564B1AA534F58868CBE41EF ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
13:34:14.0198 6000  srv2 - ok
13:34:14.0308 6000  [ BF94A7553EF257D70CB2287BF7A3BCE1 ] srvcPVR        C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe
13:34:14.0354 6000  srvcPVR ( UnsignedFile.Multi.Generic ) - warning
13:34:14.0354 6000  srvcPVR - detected UnsignedFile.Multi.Generic (1)
13:34:14.0370 6000  [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
13:34:14.0401 6000  srvnet - ok
13:34:14.0417 6000  [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
13:34:14.0464 6000  SSDPSRV - ok
13:34:14.0495 6000  [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc        C:\Windows\system32\sstpsvc.dll
13:34:14.0542 6000  SstpSvc - ok
13:34:14.0588 6000  [ 5A19667A580B1CE886EAF968B9743F45 ] Stereo Service  C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
13:34:14.0620 6000  Stereo Service - ok
13:34:14.0666 6000  [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc          C:\Windows\System32\wiaservc.dll
13:34:14.0744 6000  stisvc - ok
13:34:14.0776 6000  [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
13:34:14.0791 6000  swenum - ok
13:34:14.0822 6000  [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv          C:\Windows\System32\swprv.dll
13:34:14.0885 6000  swprv - ok
13:34:14.0916 6000  [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
13:34:14.0932 6000  Symc8xx - ok
13:34:14.0963 6000  [ 5A193E5E0F0A776430E5D62A051C1E16 ] SymDS          C:\Windows\system32\drivers\N360\1404000.028\SYMDS.SYS
13:34:14.0978 6000  SymDS - ok
13:34:15.0025 6000  [ 1773FB2920EBB3A8BAD0360618091470 ] SymEFA          C:\Windows\system32\drivers\N360\1404000.028\SYMEFA.SYS
13:34:15.0056 6000  SymEFA - ok
13:34:15.0119 6000  [ F50D81D3E0C7A353F205562B89CD06D6 ] SymEvent        C:\Windows\system32\Drivers\SYMEVENT.SYS
13:34:15.0134 6000  SymEvent - ok
13:34:15.0166 6000  [ 3DAAD401453F5A46CAE076F9D9D1458E ] SymIM          C:\Windows\system32\DRIVERS\SymIMv.sys
13:34:15.0181 6000  SymIM - ok
13:34:15.0228 6000  [ 8C9B9036E301A9965CF15BEC91C58A12 ] SymIRON        C:\Windows\system32\drivers\N360\1404000.028\Ironx86.SYS
13:34:15.0244 6000  SymIRON - ok
13:34:15.0259 6000  [ C834343C3A23DC9BC3AA752F0CAFD04B ] SYMTDIv        C:\Windows\System32\Drivers\N360\1404000.028\SYMTDIV.SYS
13:34:15.0290 6000  SYMTDIv - ok
13:34:15.0322 6000  [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
13:34:15.0337 6000  Sym_hi - ok
13:34:15.0353 6000  [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
13:34:15.0368 6000  Sym_u3 - ok
13:34:15.0400 6000  [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain        C:\Windows\system32\sysmain.dll
13:34:15.0478 6000  SysMain - ok
13:34:15.0509 6000  [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:34:15.0524 6000  TabletInputService - ok
13:34:15.0556 6000  [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv        C:\Windows\System32\tapisrv.dll
13:34:15.0587 6000  TapiSrv - ok
13:34:15.0618 6000  [ CB05822CD9CC6C688168E113C603DBE7 ] TBS            C:\Windows\System32\tbssvc.dll
13:34:15.0665 6000  TBS - ok
13:34:15.0712 6000  [ 548E198BAE21EFC21F8B5F0C1728AD27 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
13:34:15.0758 6000  Tcpip - ok
13:34:15.0774 6000  [ 548E198BAE21EFC21F8B5F0C1728AD27 ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
13:34:15.0821 6000  Tcpip6 - ok
13:34:15.0852 6000  [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
13:34:15.0868 6000  tcpipreg - ok
13:34:15.0883 6000  [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
13:34:15.0914 6000  TDPIPE - ok
13:34:15.0961 6000  [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
13:34:15.0992 6000  TDTCP - ok
13:34:16.0024 6000  [ 76B06EB8A01FC8624D699E7045303E54 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
13:34:16.0039 6000  tdx - ok
13:34:16.0070 6000  [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
13:34:16.0086 6000  TermDD - ok
13:34:16.0102 6000  [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService    C:\Windows\System32\termsrv.dll
13:34:16.0148 6000  TermService - ok
13:34:16.0180 6000  [ C7230FBEE14437716701C15BE02C27B8 ] Themes          C:\Windows\system32\shsvcs.dll
13:34:16.0211 6000  Themes - ok
13:34:16.0242 6000  [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER    C:\Windows\system32\mmcss.dll
13:34:16.0258 6000  THREADORDER - ok
13:34:16.0273 6000  [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks          C:\Windows\System32\trkwks.dll
13:34:16.0304 6000  TrkWks - ok
13:34:16.0351 6000  [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:34:16.0398 6000  TrustedInstaller - ok
13:34:16.0429 6000  [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
13:34:16.0445 6000  tssecsrv - ok
13:34:16.0476 6000  [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
13:34:16.0492 6000  tunmp - ok
13:34:16.0507 6000  [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
13:34:16.0538 6000  tunnel - ok
13:34:16.0570 6000  [ C3ADE15414120033A36C0F293D4A4121 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
13:34:16.0585 6000  uagp35 - ok
13:34:16.0616 6000  [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
13:34:16.0632 6000  udfs - ok
13:34:16.0663 6000  [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
13:34:16.0694 6000  UI0Detect - ok
13:34:16.0710 6000  [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
13:34:16.0726 6000  uliagpkx - ok
13:34:16.0741 6000  [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci        C:\Windows\system32\drivers\uliahci.sys
13:34:16.0757 6000  uliahci - ok
13:34:16.0772 6000  [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata          C:\Windows\system32\drivers\ulsata.sys
13:34:16.0788 6000  UlSata - ok
13:34:16.0804 6000  [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
13:34:16.0804 6000  ulsata2 - ok
13:34:16.0819 6000  [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
13:34:16.0850 6000  umbus - ok
13:34:16.0882 6000  [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost        C:\Windows\System32\upnphost.dll
13:34:16.0897 6000  upnphost - ok
13:34:16.0928 6000  [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
13:34:16.0960 6000  usbccgp - ok
13:34:16.0960 6000  [ E9476E6C486E76BC4898074768FB7131 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
13:34:16.0991 6000  usbcir - ok
13:34:17.0022 6000  [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
13:34:17.0038 6000  usbehci - ok
13:34:17.0069 6000  [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
13:34:17.0100 6000  usbhub - ok
13:34:17.0131 6000  [ 38DBC7DD6CC5A72011F187425384388B ] usbohci        C:\Windows\system32\drivers\usbohci.sys
13:34:17.0178 6000  usbohci - ok
13:34:17.0209 6000  [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
13:34:17.0240 6000  usbprint - ok
13:34:17.0272 6000  [ A508C9BD8724980512136B039BBA65E9 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
13:34:17.0287 6000  usbscan - ok
13:34:17.0303 6000  [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:34:17.0318 6000  USBSTOR - ok
13:34:17.0334 6000  [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
13:34:17.0365 6000  usbuhci - ok
13:34:17.0459 6000  [ 622FCF264119F7DF127BE353F796B319 ] UtilityChest_49Service C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe
13:34:17.0474 6000  UtilityChest_49Service - ok
13:34:17.0490 6000  [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms          C:\Windows\System32\uxsms.dll
13:34:17.0537 6000  UxSms - ok
13:34:17.0568 6000  [ CD88D1B7776DC17A119049742EC07EB4 ] vds            C:\Windows\System32\vds.exe
13:34:17.0599 6000  vds - ok
13:34:17.0615 6000  [ 87B06E1F30B749A114F74622D013F8D4 ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
13:34:17.0646 6000  vga - ok
13:34:17.0677 6000  [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave        C:\Windows\System32\drivers\vga.sys
13:34:17.0708 6000  VgaSave - ok
13:34:17.0724 6000  [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp          C:\Windows\system32\drivers\viaagp.sys
13:34:17.0740 6000  viaagp - ok
13:34:17.0740 6000  [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7          C:\Windows\system32\drivers\viac7.sys
13:34:17.0802 6000  ViaC7 - ok
13:34:17.0833 6000  [ 7AA7EC9A08DC2C39649C413B1A26E298 ] viaide          C:\Windows\system32\drivers\viaide.sys
13:34:17.0849 6000  viaide - ok
13:34:17.0864 6000  [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
13:34:17.0896 6000  volmgr - ok
13:34:17.0911 6000  [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
13:34:17.0942 6000  volmgrx - ok
13:34:17.0974 6000  [ 786DB5771F05EF300390399F626BF30A ] volsnap        C:\Windows\system32\drivers\volsnap.sys
13:34:17.0989 6000  volsnap - ok
13:34:18.0005 6000  [ D984439746D42B30FC65A4C3546C6829 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
13:34:18.0020 6000  vsmraid - ok
13:34:18.0067 6000  [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS            C:\Windows\system32\vssvc.exe
13:34:18.0145 6000  VSS - ok
13:34:18.0176 6000  [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time        C:\Windows\system32\w32time.dll
13:34:18.0208 6000  W32Time - ok
13:34:18.0208 6000  [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
13:34:18.0286 6000  WacomPen - ok
13:34:18.0332 6000  [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
13:34:18.0348 6000  Wanarp - ok
13:34:18.0364 6000  [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
13:34:18.0379 6000  Wanarpv6 - ok
13:34:18.0410 6000  [ 0A716C08CB13C3A8F4F51E882DBF7416 ] wanatw          C:\Windows\system32\DRIVERS\wanatw4.sys
13:34:18.0442 6000  wanatw - ok
13:34:18.0473 6000  [ A3CD60FD826381B49F03832590E069AF ] wcncsvc        C:\Windows\System32\wcncsvc.dll
13:34:18.0488 6000  wcncsvc - ok
13:34:18.0520 6000  [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:34:18.0551 6000  WcsPlugInService - ok
13:34:18.0582 6000  [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd              C:\Windows\system32\drivers\wd.sys
13:34:18.0598 6000  Wd - ok
13:34:18.0644 6000  [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
13:34:18.0660 6000  Wdf01000 - ok
13:34:18.0691 6000  [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost  C:\Windows\system32\wdi.dll
13:34:18.0722 6000  WdiServiceHost - ok
13:34:18.0722 6000  [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost  C:\Windows\system32\wdi.dll
13:34:18.0754 6000  WdiSystemHost - ok
13:34:18.0769 6000  [ 04C37D8107320312FBAE09926103D5E2 ] WebClient      C:\Windows\System32\webclnt.dll
13:34:18.0800 6000  WebClient - ok
13:34:18.0832 6000  [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc          C:\Windows\system32\wecsvc.dll
13:34:18.0847 6000  Wecsvc - ok
13:34:18.0863 6000  [ 670FF720071ED741206D69BD995EA453 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
13:34:18.0894 6000  wercplsupport - ok
13:34:18.0910 6000  [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc          C:\Windows\System32\WerSvc.dll
13:34:18.0941 6000  WerSvc - ok
13:34:18.0988 6000  [ 4575AA12561C5648483403541D0D7F2B ] WinDefend      C:\Program Files\Windows Defender\mpsvc.dll
13:34:19.0019 6000  WinDefend - ok
13:34:19.0019 6000  WinHttpAutoProxySvc - ok
13:34:19.0066 6000  [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
13:34:19.0081 6000  Winmgmt - ok
13:34:19.0144 6000  [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM          C:\Windows\system32\WsmSvc.dll
13:34:19.0175 6000  WinRM - ok
13:34:19.0253 6000  [ 30FC6E5448D0CBAAA95280EEEF7FEDAE ] WinUSB          C:\Windows\system32\DRIVERS\WinUSB.sys
13:34:19.0300 6000  WinUSB - ok
13:34:19.0331 6000  [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc        C:\Windows\System32\wlansvc.dll
13:34:19.0393 6000  Wlansvc - ok
13:34:19.0424 6000  [ 701A9F884A294327E9141D73746EE279 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
13:34:19.0471 6000  WmiAcpi - ok
13:34:19.0502 6000  [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
13:34:19.0549 6000  wmiApSrv - ok
13:34:19.0612 6000  [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc  C:\Program Files\Windows Media Player\wmpnetwk.exe
13:34:19.0658 6000  WMPNetworkSvc - ok
13:34:19.0721 6000  [ 017695393AFFFED8DE58ABD1B085BE6D ] WMZuneComm      C:\Program Files\Zune\WMZuneComm.exe
13:34:19.0752 6000  WMZuneComm - ok
13:34:19.0768 6000  [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
13:34:19.0830 6000  WPCSvc - ok
13:34:19.0846 6000  [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
13:34:19.0908 6000  WPDBusEnum - ok
13:34:19.0955 6000  [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
13:34:19.0986 6000  WpdUsb - ok
13:34:20.0095 6000  [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:34:20.0142 6000  WPFFontCache_v0400 - ok
13:34:20.0173 6000  [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
13:34:20.0204 6000  ws2ifsl - ok
13:34:20.0236 6000  [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc          C:\Windows\system32\wscsvc.dll
13:34:20.0251 6000  wscsvc - ok
13:34:20.0251 6000  WSearch - ok
13:34:20.0329 6000  [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv        C:\Windows\system32\wuaueng.dll
13:34:20.0438 6000  wuauserv - ok
13:34:20.0485 6000  [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
13:34:20.0532 6000  WudfPf - ok
13:34:20.0548 6000  [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
13:34:20.0563 6000  WUDFRd - ok
13:34:20.0610 6000  [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
13:34:20.0626 6000  wudfsvc - ok
13:34:20.0641 6000  [ 6BBF7A3BAB8FFDCCF82057FA2AAE2B7B ] XUIF            C:\Windows\system32\Drivers\x10ufx2.sys
13:34:20.0657 6000  XUIF - ok
13:34:20.0828 6000  [ 1076DF9ADE4E13EA3BF39D2165AEB903 ] ZuneNetworkSvc  C:\Program Files\Zune\ZuneNss.exe
13:34:21.0140 6000  ZuneNetworkSvc - ok
13:34:21.0187 6000  [ DE1CDB333A402B279F04D627122FA08E ] ZuneWlanCfgSvc  C:\Program Files\Zune\ZuneWlanCfgSvc.exe
13:34:21.0218 6000  ZuneWlanCfgSvc - ok
13:34:21.0218 6000  ================ Scan global ===============================
13:34:21.0281 6000  [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
13:34:21.0312 6000  [ A508314231C49AEE86987CEA3EAECAD1 ] C:\Windows\system32\winsrv.dll
13:34:21.0343 6000  [ A508314231C49AEE86987CEA3EAECAD1 ] C:\Windows\system32\winsrv.dll
13:34:21.0359 6000  [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
13:34:21.0374 6000  [Global] - ok
13:34:21.0374 6000  ================ Scan MBR ==================================
13:34:21.0374 6000  [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
13:34:21.0952 6000  \Device\Harddisk0\DR0 - ok
13:34:21.0952 6000  ================ Scan VBR ==================================
13:34:21.0952 6000  [ 05E6BBA7B2D8DC676912B28E6940D7C8 ] \Device\Harddisk0\DR0\Partition1
13:34:21.0952 6000  \Device\Harddisk0\DR0\Partition1 - ok
13:34:21.0967 6000  [ CD7BA2ED635FD4CD78F86901F5AA14F4 ] \Device\Harddisk0\DR0\Partition2
13:34:21.0967 6000  \Device\Harddisk0\DR0\Partition2 - ok
13:34:21.0967 6000  ============================================================
13:34:21.0967 6000  Scan finished
13:34:21.0967 6000  ============================================================
13:34:21.0967 3868  Detected object count: 6
13:34:21.0967 3868  Actual detected object count: 6
13:43:09.0872 3868  hpqcxs08 ( UnsignedFile.Multi.Generic ) - skipped by user
13:43:09.0872 3868  hpqcxs08 ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:43:09.0872 3868  hpqddsvc ( UnsignedFile.Multi.Generic ) - skipped by user
13:43:09.0872 3868  hpqddsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:43:09.0872 3868  HPSLPSVC ( UnsignedFile.Multi.Generic ) - skipped by user
13:43:09.0872 3868  HPSLPSVC ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:43:09.0872 3868  Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
13:43:09.0872 3868  Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:43:09.0872 3868  Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
13:43:09.0872 3868  Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:43:09.0872 3868  srvcPVR ( UnsignedFile.Multi.Generic ) - skipped by user
13:43:09.0872 3868  srvcPVR ( UnsignedFile.Multi.Generic ) - User select action: Skip



Grüße

Sabine99

schrauber 29.06.2013 14:45

Ok, frisches FRST log bitte :)

Sabine99 29.06.2013 14:49

Anbei
FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-06-2013 02
Ran by ***** (administrator) on 29-06-2013 15:46:44
Running from C:\Users\*****\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(COMPANYVERS_NAME) C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe
(COMPANYVERS_NAME) C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Lexware GmbH & Co. KG) C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe
(ODSoft multimedia) C:\Program Files\Sceneo\AbsolutTV\Services\ODSBC\ODSBCApp.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(VER_COMPANY_NAME) C:\Program Files\InboxAce_1g\bar\1.bin\1gbrmon.exe
(VER_COMPANY_NAME) C:\Program Files\UtilityChest_49\bar\1.bin\49brmon.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Hewlett-Packard Co.) C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RaUI.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Kaspersky Lab ZAO) C:\Users\*****\Desktop\tdsskiller.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [UpdatePPShortCut] "C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\PowerProducer" update "Software\CyberLink\PowerProducer\4.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM\...\Run: [Windows Defender] %programfiles%\windows defender\msascui.exe -hide [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [LexwareInfoService] c:\program files\common files\lexware\update manager\lxupdatemanager.exe /autostart [339240 2008-11-03] (Lexware GmbH & Co. KG)
HKLM\...\Run: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\nbkeyscan.exe" [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [RemoteControl] "c:\program files\homecinema\powerdvd\pdvdserv.exe" [71216 2007-02-09] (Cyberlink Corp.)
HKLM\...\Run: [TVBroadcast] c:\program files\sceneo\absoluttv\services\odsbc\odsbcapp.exe [797696 2007-08-08] (ODSoft multimedia)
HKLM\...\Run: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe [90112 2006-11-29] (Ulead Systems, Inc.)
HKLM\...\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [InboxAce Search Scope Monitor] "C:\PROGRA~1\INBOXA~2\bar\1.bin\1gsrchmn.exe" /m=2 /w /h [44784 2013-06-23] (MindSpark)
HKLM\...\Run: [InboxAce_1g Browser Plugin Loader] C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbrmon.exe [30096 2013-06-23] (VER_COMPANY_NAME)
HKLM\...\Run: [Utility Chest Search Scope Monitor] "C:\PROGRA~1\UTILIT~2\bar\1.bin\49srchmn.exe" /m=2 /w /h [44784 2013-06-25] (MindSpark)
HKLM\...\Run: [UtilityChest_49 Browser Plugin Loader] C:\PROGRA~1\UTILIT~2\bar\1.bin\49brmon.exe [30096 2013-06-25] (VER_COMPANY_NAME)
HKCU\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\nmbgmonitor.exe" [202024 2007-10-15] (Nero AG)
HKCU\...\Run: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autorun [1233920 2009-04-11] (Microsoft Corporation)
HKCU\...\Run: [SearchEngineProtection] C:\Program Files\GamesBar\update\SearchEngineProtection.exe [x]
HKCU\...\Run: [AOL Dialer] C:\Program Files\Common Files\AOL\ACS\AOlDial.exe [x]
HKCU\...\Policies\system: [disableregistrytools] 0
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)

==================== Internet (Whitelisted) ====================

ProxyServer: 192.168.1.1:80
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
URLSearchHook: (No Name) - {7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
URLSearchHook: (No Name) - {5fdb0cd8-5760-44d1-8d13-a78bf558c3c7} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll (MindSpark)
HKCU SearchScopes: DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
BHO: Search Assistant BHO - {06e05b40-77fa-40b6-9077-ed1a7577b1ef} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
BHO: GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
BHO: Toolbar BHO - {58f7b5ca-1162-42e8-8bbc-d543b4edd780} - C:\PROGRA~1\UTILIT~2\bar\1.bin\49bar.dll (MindSpark)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Search Assistant BHO - {9359da42-06fb-46f2-9e4a-05c05b98a5ef} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll (MindSpark)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Toolbar BHO - {d5a1d22b-9e17-454f-8ecd-83c578fb3983} - C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbar.dll (MindSpark)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - InboxAce - {3775afd7-5921-4571-968f-85a631203d1c} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll (MindSpark)
Toolbar: HKLM - Utility Chest - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -InboxAce - {3775AFD7-5921-4571-968F-85A631203D1C} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll (MindSpark)
Toolbar: HKCU -Utility Chest - {CF67755F-9265-449C-87CF-B945519E073B} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Chrome:
=======
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013"
CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1
CHR Extension: (Norton Identity Protection) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.11.8_0
CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

========================== Services (Whitelisted) =================

R2 InboxAce_1gService; C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe [42504 2013-06-23] (COMPANYVERS_NAME)
R2 N360; C:\Program Files\Norton 360\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation)
R2 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe [75040 2008-09-05] (Ralink Technology, Corp.)
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1681408 2007-08-16] (Buhl Data Service GmbH)
R2 UtilityChest_49Service; C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe [42504 2013-06-25] (COMPANYVERS_NAME)

==================== Drivers (Whitelisted) ====================

R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130531.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
S3 CH375; C:\Windows\System32\Drivers\CH375WDM.SYS [28403 2011-03-14] (www.winchiphead.com)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2013-04-13] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2013-04-13] (Symantec Corporation)
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc.              )
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130621.001\IDSvix86.sys [386720 2013-04-12] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVENG.SYS [93272 2013-05-22] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVEX15.SYS [1611992 2013-05-22] (Symantec Corporation)
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [645120 2008-08-21] (Ralink Technology Corp.)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
S3 SRTSP; C:\Windows\System32\Drivers\N360\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-22] (Symantec Corporation)
R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [36512 2013-03-05] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\N360\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-30] (America Online, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-29 13:30 - 2013-06-29 13:30 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\*****\Desktop\tdsskiller.exe
2013-06-29 10:19 - 2013-06-29 10:19 - 05084379 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe
2013-06-28 18:35 - 2013-06-29 10:20 - 00000000 ___SD C:\32788R22FWJFW
2013-06-28 18:35 - 2013-06-28 18:35 - 00000000 ____D C:\Windows\erdnt
2013-06-27 21:30 - 2013-06-27 21:30 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-06-27 21:25 - 2013-06-27 21:26 - 00013190 ____A C:\AdwCleaner[S2].txt
2013-06-27 21:25 - 2013-06-27 21:25 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-06-27 19:17 - 2013-06-27 19:18 - 01370369 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-06-27 19:15 - 2013-06-27 19:15 - 01370369 ____A (Farbar) C:\Users\*****\Downloads\FRST.exe
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 22:24 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 22:23 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:44 - 2013-06-27 21:22 - 00000000 ____D C:\FRST
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-23 11:24 - 2013-06-23 11:24 - 00000000 ____D C:\Program Files\InboxAce_1g
2013-06-22 23:20 - 2013-06-22 23:20 - 00000000 ____D C:\_OTL
2013-06-22 22:02 - 2013-06-22 22:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 20:31 - 2013-06-27 21:32 - 00000000 ____D C:\JRT
2013-06-22 20:31 - 2013-06-22 20:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 20:25 - 2013-06-22 20:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 20:23 - 2013-06-22 20:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:18 - 2013-06-29 15:36 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-22 20:18 - 2013-06-27 21:24 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-22 20:18 - 2013-06-22 20:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 20:17 - 2013-06-27 18:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:00 - 2013-06-22 20:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 19:58 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:18 - 2012-08-21 13:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2013-06-17 06:17 - 2013-06-17 06:18 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2013-06-17 06:17 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-14 13:38 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-14 13:38 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-14 13:38 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-14 13:38 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-14 13:38 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-14 13:38 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-14 13:38 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-14 13:38 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-14 13:38 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-14 13:38 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-14 13:32 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-14 13:31 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-14 13:31 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-14 13:31 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-14 13:31 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-14 13:31 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-14 13:31 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll

==================== One Month Modified Files and Folders ========

2013-06-29 15:36 - 2013-06-22 20:18 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-29 15:05 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-29 15:05 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-29 14:59 - 2011-11-22 19:11 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-29 14:50 - 2012-08-22 20:11 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-29 14:42 - 2010-01-23 16:48 - 01714691 ____A C:\Windows\WindowsUpdate.log
2013-06-29 13:33 - 2013-02-02 13:52 - 00000524 ____A C:\Users\*****\Desktop\eMail (12).website
2013-06-29 13:30 - 2013-06-29 13:30 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\*****\Desktop\tdsskiller.exe
2013-06-29 13:28 - 2011-11-22 19:11 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-29 13:05 - 2010-01-24 10:55 - 00000000 ____D C:\ProgramData\NVIDIA
2013-06-29 13:05 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-29 10:33 - 2006-11-02 15:01 - 00032530 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-29 10:20 - 2013-06-28 18:35 - 00000000 ___SD C:\32788R22FWJFW
2013-06-29 10:19 - 2013-06-29 10:19 - 05084379 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe
2013-06-29 09:08 - 2010-01-23 17:02 - 01037194 ____A C:\Windows\PFRO.log
2013-06-28 18:35 - 2013-06-28 18:35 - 00000000 ____D C:\Windows\erdnt
2013-06-27 21:32 - 2013-06-22 20:31 - 00000000 ____D C:\JRT
2013-06-27 21:30 - 2013-06-27 21:30 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-06-27 21:26 - 2013-06-27 21:25 - 00013190 ____A C:\AdwCleaner[S2].txt
2013-06-27 21:25 - 2013-06-27 21:25 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-06-27 21:24 - 2013-06-22 20:18 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-27 21:22 - 2013-06-23 11:44 - 00000000 ____D C:\FRST
2013-06-27 21:06 - 2010-12-28 12:53 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-06-27 19:18 - 2013-06-27 19:17 - 01370369 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-06-27 19:15 - 2013-06-27 19:15 - 01370369 ____A (Farbar) C:\Users\*****\Downloads\FRST.exe
2013-06-27 18:59 - 2010-01-26 15:57 - 00002591 ____A C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk
2013-06-27 18:44 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 22:23 - 2013-06-23 22:24 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 22:23 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-23 11:24 - 2013-06-23 11:24 - 00000000 ____D C:\Program Files\InboxAce_1g
2013-06-22 23:20 - 2013-06-22 23:20 - 00000000 ____D C:\_OTL
2013-06-22 22:02 - 2013-06-22 22:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 21:59 - 2010-01-23 17:06 - 00000000 ___AD C:\users\*****
2013-06-22 20:31 - 2013-06-22 20:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 20:25 - 2013-06-22 20:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 20:23 - 2013-06-22 20:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:18 - 2013-06-22 20:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 20:17 - 2011-10-21 13:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:04 - 2011-04-17 19:29 - 00000000 ____D C:\Windows\System32\Drivers\N360
2013-06-22 20:03 - 2011-04-17 19:30 - 00002023 ____A C:\Users\Public\Desktop\Norton 360.lnk
2013-06-22 20:00 - 2013-06-22 20:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 19:58 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-22 19:54 - 2013-01-09 21:21 - 00001935 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-22 19:23 - 2011-04-17 19:30 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS
2013-06-22 19:23 - 2011-04-17 19:30 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:19 - 2012-05-21 20:02 - 00000000 ____D C:\Users\*****\AppData\Roaming\Apple Computer
2013-06-17 06:19 - 2010-01-26 10:43 - 00000000 ____D C:\Users\*****\AppData\Local\Apple Computer
2013-06-17 06:18 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:17 - 2013-06-17 06:09 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-17 06:17 - 2010-02-13 14:59 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-06-17 06:17 - 2010-02-13 14:54 - 00000000 ____D C:\ProgramData\Apple
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2012-05-21 06:11 - 00001690 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2013-06-17 06:09 - 2008-01-23 14:46 - 00000000 ____D C:\Program Files\QuickTime
2013-06-14 17:02 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-06-14 16:48 - 2012-08-22 20:11 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-14 16:48 - 2011-09-04 07:42 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-14 16:43 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-14 13:36 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e

Files to move or delete:
====================
C:\ProgramData\nvModes.dat

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-29 13:20

==================== End Of Log ============================

--- --- ---

--- --- ---


Bis bald

Sabine99

schrauber 29.06.2013 14:54

Fix mit FRST
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
Code:

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Fix Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

Sabine99 29.06.2013 15:11

Hier das fixlog
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-06-2013 02
Ran by ***** at 2013-06-29 16:05:10 Run:2
Running from C:\Users\*****\Desktop
Boot Mode: Normal

==============================================


"C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e" directory move:

Could not move "C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e" directory. => Scheduled to move on reboot.


=========== Result of Scheduled Files to move ===========
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e => Directory could not move.

==== End of Fixlog ====

Sabine99

schrauber 29.06.2013 18:01

Code:

C:\$Recycle.Bin
Neuer FRST Fix mit obigem Inhalt, dann ein frisches FRST log bitte.

Sabine99 29.06.2013 20:27

Hi Schrauber,

anbei das Fixlog

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-06-2013 02
Ran by ***** at 2013-06-29 21:21:48 Run:3
Running from C:\Users\*****\Desktop
Boot Mode: Normal

==============================================


"C:\$Recycle.Bin" directory move:

C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$I021K8C => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$I7L8TRJ.09 => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$IBQSSVL.com_20091105_151755 => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$IBZ9SYV.xls => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$ING0LCQ.xlsx => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$INRDNF4 => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$RBZ9SYV.xls => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$RNG0LCQ.xlsx => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\desktop.ini => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$RNRDNF4\721802_1.tif => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$RNRDNF4\Rechnung_721802.pdf => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$RBQSSVL.com_20091105_151755\h11@vetter-pharma.com_20091105_151755.pdf => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$RBQSSVL.com_20091105_151755\vetter_disclaimer.txt => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$R7L8TRJ.09\QC2977vom07.10.09.pdf => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$R7L8TRJ.09\QC2977vom07.10.09Teil2.pdf => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$R7L8TRJ.09\vetter_disclaimer.txt => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2686624488-3072352348-3050286962-1004\$R021K8C\Antrag BetrGeld.wps => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$I2CHSNP.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$I4XBU9V.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$I6HCH53.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$ID628SG.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$IF1N1NE.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$IFA7A2E.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$IGZGO1Z.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$IIA98OB.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$IKI4KPE.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$ILTD0GC.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$IQ7G8TN.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$ISMFZOB.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$IVN7V7G.lnk => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\desktop.ini => Moved successfully.
Could not move "C:\$Recycle.Bin" directory. => Scheduled to move on reboot.


=========== Result of Scheduled Files to move ===========
C:\$Recycle.Bin => Directory could not move.

==== End of Fixlog ====

Noch einen schönen Abend:party:
Grüße

Sabine99

schrauber 29.06.2013 21:41

Noch ein frisches FRST log bitte :)

Sabine99 30.06.2013 08:30

Hi,

hier ist es.


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-06-2013 02
Ran by ***** (administrator) on 30-06-2013 09:25:59
Running from C:\Users\*****\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(COMPANYVERS_NAME) C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe
(COMPANYVERS_NAME) C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Lexware GmbH & Co. KG) C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe
(ODSoft multimedia) C:\Program Files\Sceneo\AbsolutTV\Services\ODSBC\ODSBCApp.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(VER_COMPANY_NAME) C:\Program Files\InboxAce_1g\bar\1.bin\1gbrmon.exe
(VER_COMPANY_NAME) C:\Program Files\UtilityChest_49\bar\1.bin\49brmon.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Hewlett-Packard Co.) C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RaUI.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Lexware GmbH & Co. KG) C:\Program Files\Common Files\Lexware\LxWebAccess\LxWebAccess.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [UpdatePPShortCut] "C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\PowerProducer" update "Software\CyberLink\PowerProducer\4.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM\...\Run: [Windows Defender] %programfiles%\windows defender\msascui.exe -hide [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [LexwareInfoService] c:\program files\common files\lexware\update manager\lxupdatemanager.exe /autostart [339240 2008-11-03] (Lexware GmbH & Co. KG)
HKLM\...\Run: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\nbkeyscan.exe" [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [RemoteControl] "c:\program files\homecinema\powerdvd\pdvdserv.exe" [71216 2007-02-09] (Cyberlink Corp.)
HKLM\...\Run: [TVBroadcast] c:\program files\sceneo\absoluttv\services\odsbc\odsbcapp.exe [797696 2007-08-08] (ODSoft multimedia)
HKLM\...\Run: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe [90112 2006-11-29] (Ulead Systems, Inc.)
HKLM\...\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [InboxAce Search Scope Monitor] "C:\PROGRA~1\INBOXA~2\bar\1.bin\1gsrchmn.exe" /m=2 /w /h [44784 2013-06-23] (MindSpark)
HKLM\...\Run: [InboxAce_1g Browser Plugin Loader] C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbrmon.exe [30096 2013-06-23] (VER_COMPANY_NAME)
HKLM\...\Run: [Utility Chest Search Scope Monitor] "C:\PROGRA~1\UTILIT~2\bar\1.bin\49srchmn.exe" /m=2 /w /h [44784 2013-06-25] (MindSpark)
HKLM\...\Run: [UtilityChest_49 Browser Plugin Loader] C:\PROGRA~1\UTILIT~2\bar\1.bin\49brmon.exe [30096 2013-06-25] (VER_COMPANY_NAME)
HKCU\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\nmbgmonitor.exe" [202024 2007-10-15] (Nero AG)
HKCU\...\Run: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autorun [1233920 2009-04-11] (Microsoft Corporation)
HKCU\...\Run: [SearchEngineProtection] C:\Program Files\GamesBar\update\SearchEngineProtection.exe [x]
HKCU\...\Run: [AOL Dialer] C:\Program Files\Common Files\AOL\ACS\AOlDial.exe [x]
HKCU\...\Policies\system: [disableregistrytools] 0
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)

==================== Internet (Whitelisted) ====================

ProxyServer: 192.168.1.1:80
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
URLSearchHook: (No Name) - {7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
URLSearchHook: (No Name) - {5fdb0cd8-5760-44d1-8d13-a78bf558c3c7} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll (MindSpark)
HKCU SearchScopes: DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
BHO: Search Assistant BHO - {06e05b40-77fa-40b6-9077-ed1a7577b1ef} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
BHO: GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
BHO: Toolbar BHO - {58f7b5ca-1162-42e8-8bbc-d543b4edd780} - C:\PROGRA~1\UTILIT~2\bar\1.bin\49bar.dll (MindSpark)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Search Assistant BHO - {9359da42-06fb-46f2-9e4a-05c05b98a5ef} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll (MindSpark)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Toolbar BHO - {d5a1d22b-9e17-454f-8ecd-83c578fb3983} - C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbar.dll (MindSpark)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - InboxAce - {3775afd7-5921-4571-968f-85a631203d1c} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll (MindSpark)
Toolbar: HKLM - Utility Chest - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -InboxAce - {3775AFD7-5921-4571-968F-85A631203D1C} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll (MindSpark)
Toolbar: HKCU -Utility Chest - {CF67755F-9265-449C-87CF-B945519E073B} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Chrome:
=======
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013"
CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1
CHR Extension: (Norton Identity Protection) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.11.8_0
CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

========================== Services (Whitelisted) =================

R2 InboxAce_1gService; C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe [42504 2013-06-23] (COMPANYVERS_NAME)
R2 N360; C:\Program Files\Norton 360\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation)
R2 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe [75040 2008-09-05] (Ralink Technology, Corp.)
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1681408 2007-08-16] (Buhl Data Service GmbH)
R2 UtilityChest_49Service; C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe [42504 2013-06-25] (COMPANYVERS_NAME)

==================== Drivers (Whitelisted) ====================

R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130531.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
S3 CH375; C:\Windows\System32\Drivers\CH375WDM.SYS [28403 2011-03-14] (www.winchiphead.com)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2013-04-13] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2013-04-13] (Symantec Corporation)
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc.              )
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130621.001\IDSvix86.sys [386720 2013-04-12] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVENG.SYS [93272 2013-05-22] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVEX15.SYS [1611992 2013-05-22] (Symantec Corporation)
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [645120 2008-08-21] (Ralink Technology Corp.)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
S3 SRTSP; C:\Windows\System32\Drivers\N360\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-22] (Symantec Corporation)
R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [36512 2013-03-05] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\N360\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-30] (America Online, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-29 13:30 - 2013-06-29 13:30 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\*****\Desktop\tdsskiller.exe
2013-06-29 10:19 - 2013-06-29 10:19 - 05084379 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe
2013-06-28 18:35 - 2013-06-29 10:20 - 00000000 ___SD C:\32788R22FWJFW
2013-06-28 18:35 - 2013-06-28 18:35 - 00000000 ____D C:\Windows\erdnt
2013-06-27 21:30 - 2013-06-27 21:30 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-06-27 21:25 - 2013-06-27 21:26 - 00013190 ____A C:\AdwCleaner[S2].txt
2013-06-27 21:25 - 2013-06-27 21:25 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-06-27 19:17 - 2013-06-27 19:18 - 01370369 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-06-27 19:15 - 2013-06-27 19:15 - 01370369 ____A (Farbar) C:\Users\*****\Downloads\FRST.exe
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 22:24 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 22:23 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:44 - 2013-06-29 21:24 - 00000000 ____D C:\FRST
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-23 11:24 - 2013-06-23 11:24 - 00000000 ____D C:\Program Files\InboxAce_1g
2013-06-22 23:20 - 2013-06-22 23:20 - 00000000 ____D C:\_OTL
2013-06-22 22:02 - 2013-06-22 22:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 20:31 - 2013-06-27 21:32 - 00000000 ____D C:\JRT
2013-06-22 20:31 - 2013-06-22 20:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 20:25 - 2013-06-22 20:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 20:23 - 2013-06-22 20:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:18 - 2013-06-29 17:47 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-22 20:18 - 2013-06-27 21:24 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-22 20:18 - 2013-06-22 20:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 20:17 - 2013-06-27 18:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:00 - 2013-06-22 20:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 19:58 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:18 - 2012-08-21 13:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2013-06-17 06:17 - 2013-06-17 06:18 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2013-06-17 06:17 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-14 13:38 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-14 13:38 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-14 13:38 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-14 13:38 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-14 13:38 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-14 13:38 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-14 13:38 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-14 13:38 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-14 13:38 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-14 13:38 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-14 13:32 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-14 13:31 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-14 13:31 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-14 13:31 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-14 13:31 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-14 13:31 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-14 13:31 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll

==================== One Month Modified Files and Folders ========

2013-06-30 09:25 - 2013-02-02 13:52 - 00000524 ____A C:\Users\*****\Desktop\eMail (12).website
2013-06-30 09:24 - 2011-11-22 19:11 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-30 09:24 - 2010-01-23 16:48 - 01760683 ____A C:\Windows\WindowsUpdate.log
2013-06-30 09:19 - 2010-01-24 10:55 - 00000000 ____D C:\ProgramData\NVIDIA
2013-06-30 09:19 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-30 09:19 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-30 09:19 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-29 21:29 - 2006-11-02 15:01 - 00032530 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-29 21:24 - 2013-06-23 11:44 - 00000000 ____D C:\FRST
2013-06-29 17:51 - 2011-11-22 19:11 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-29 17:50 - 2012-08-22 20:11 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-29 17:47 - 2013-06-22 20:18 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-29 13:30 - 2013-06-29 13:30 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\*****\Desktop\tdsskiller.exe
2013-06-29 10:20 - 2013-06-28 18:35 - 00000000 ___SD C:\32788R22FWJFW
2013-06-29 10:19 - 2013-06-29 10:19 - 05084379 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe
2013-06-29 09:08 - 2010-01-23 17:02 - 01037194 ____A C:\Windows\PFRO.log
2013-06-28 18:35 - 2013-06-28 18:35 - 00000000 ____D C:\Windows\erdnt
2013-06-27 21:32 - 2013-06-22 20:31 - 00000000 ____D C:\JRT
2013-06-27 21:30 - 2013-06-27 21:30 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-06-27 21:26 - 2013-06-27 21:25 - 00013190 ____A C:\AdwCleaner[S2].txt
2013-06-27 21:25 - 2013-06-27 21:25 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-06-27 21:24 - 2013-06-22 20:18 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-27 21:06 - 2010-12-28 12:53 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-06-27 19:18 - 2013-06-27 19:17 - 01370369 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-06-27 19:15 - 2013-06-27 19:15 - 01370369 ____A (Farbar) C:\Users\*****\Downloads\FRST.exe
2013-06-27 18:59 - 2010-01-26 15:57 - 00002591 ____A C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk
2013-06-27 18:44 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 22:23 - 2013-06-23 22:24 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 22:23 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-23 11:24 - 2013-06-23 11:24 - 00000000 ____D C:\Program Files\InboxAce_1g
2013-06-22 23:20 - 2013-06-22 23:20 - 00000000 ____D C:\_OTL
2013-06-22 22:02 - 2013-06-22 22:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 21:59 - 2010-01-23 17:06 - 00000000 ___AD C:\users\*****
2013-06-22 20:31 - 2013-06-22 20:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 20:25 - 2013-06-22 20:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 20:23 - 2013-06-22 20:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:18 - 2013-06-22 20:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 20:17 - 2011-10-21 13:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:04 - 2011-04-17 19:29 - 00000000 ____D C:\Windows\System32\Drivers\N360
2013-06-22 20:03 - 2011-04-17 19:30 - 00002023 ____A C:\Users\Public\Desktop\Norton 360.lnk
2013-06-22 20:00 - 2013-06-22 20:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 19:58 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-22 19:54 - 2013-01-09 21:21 - 00001935 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-22 19:23 - 2011-04-17 19:30 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS
2013-06-22 19:23 - 2011-04-17 19:30 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:19 - 2012-05-21 20:02 - 00000000 ____D C:\Users\*****\AppData\Roaming\Apple Computer
2013-06-17 06:19 - 2010-01-26 10:43 - 00000000 ____D C:\Users\*****\AppData\Local\Apple Computer
2013-06-17 06:18 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:17 - 2013-06-17 06:09 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-17 06:17 - 2010-02-13 14:59 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-06-17 06:17 - 2010-02-13 14:54 - 00000000 ____D C:\ProgramData\Apple
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2012-05-21 06:11 - 00001690 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2013-06-17 06:09 - 2008-01-23 14:46 - 00000000 ____D C:\Program Files\QuickTime
2013-06-14 17:02 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-06-14 16:48 - 2012-08-22 20:11 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-14 16:48 - 2011-09-04 07:42 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-14 16:43 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-14 13:36 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e

Files to move or delete:
====================
C:\ProgramData\nvModes.dat

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-29 21:29

==================== End Of Log ============================

--- --- ---


Grüße und eine schönen Sonntag

Sabine99

schrauber 30.06.2013 13:54

Aaargh, ich krieg Pickel :D

Das Ding ist zwar nicht aktiv, aber ich will es weghaben.



Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8)
Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
  • Downloade dir bitte die passende Version des Tools (im Zweifel beide) und speichere diese auf einen USB Stick: FRST 32-Bit | FRST 64-Bit
  • Schließe den USB Stick an das infizierte System an und boote das System in die System Reparatur Option.
  • Scanne jetzt nach der bebilderten Anleitung oder verwende die folgende Kurzanleitung:
Über den Boot Manager:
  • Starte den Rechner neu.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD (auch bei Windows 8 möglich):
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu und starte von der CD.
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen: Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument: Datei > Speichern unter... und wähle Computer.
    Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt, merke ihn dir.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein.
    e:\frst.exe bzw. e:\frst64.exe
    Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks, den du dir gemerkt hast. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Yes und klicke Scan
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier nach Möglichkeit in Code-Tags (Anleitung).

Sabine99 30.06.2013 14:14

Hi Schrauber,
was habe ich mir denn da hartnäckiges eingefangen?!!!
Ich mach mich mal an die Arbeit.
Melde mich dann.
Da ich mit dem Stick zwischen infiziertem PC und Laptop hin und hergewechselt bin, wie hoch ist die Gefahr, dass ich mir meinen Laptop auch verseucht haben?

Grüße
Sabine99

schrauber 30.06.2013 14:27

Gar nicht. ABer wir machen nen kurzen Check des Laptops wenn wir fertig sind :)

ZeroAccess Rootkit. Eigentlich locker zu entfernen, schon hundert mal gemacht, nur dieser Eine Überbleibsel will nicht weg :)

Sabine99 30.06.2013 14:44

Hi Schrauber,

booten mittels CD, da ich auf normalem Weg, keinen Weg zur "Reparatur" gefunden habe. Kann aber durchaus an mir liegen :lach:

Und hier das file:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-06-2013 01
Ran by SYSTEM on 30-06-2013 15:37:29
Running from I:\
Windows Vista (TM) Home Premium (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and Addition.txt log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [UpdatePPShortCut] "C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\PowerProducer" update "Software\CyberLink\PowerProducer\4.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM\...\Run: [Windows Defender] %programfiles%\windows defender\msascui.exe -hide [1008184 2008-01-18] (Microsoft Corporation)
HKLM\...\Run: [LexwareInfoService] c:\program files\common files\lexware\update manager\lxupdatemanager.exe /autostart [339240 2008-11-03] (Lexware GmbH & Co. KG)
HKLM\...\Run: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\nbkeyscan.exe" [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [RemoteControl] "c:\program files\homecinema\powerdvd\pdvdserv.exe" [71216 2007-02-09] (Cyberlink Corp.)
HKLM\...\Run: [TVBroadcast] c:\program files\sceneo\absoluttv\services\odsbc\odsbcapp.exe [797696 2007-08-08] (ODSoft multimedia)
HKLM\...\Run: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe [90112 2006-11-29] (Ulead Systems, Inc.)
HKLM\...\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [InboxAce Search Scope Monitor] "C:\PROGRA~1\INBOXA~2\bar\1.bin\1gsrchmn.exe" /m=2 /w /h [44784 2013-06-23] (MindSpark)
HKLM\...\Run: [InboxAce_1g Browser Plugin Loader] C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbrmon.exe [30096 2013-06-23] (VER_COMPANY_NAME)
HKLM\...\Run: [Utility Chest Search Scope Monitor] "C:\PROGRA~1\UTILIT~2\bar\1.bin\49srchmn.exe" /m=2 /w /h [44784 2013-06-25] (MindSpark)
HKLM\...\Run: [UtilityChest_49 Browser Plugin Loader] C:\PROGRA~1\UTILIT~2\bar\1.bin\49brmon.exe [30096 2013-06-25] (VER_COMPANY_NAME)
HKU\*****\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [ 2008-01-18] (Microsoft Corporation)
HKU\*****\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\nmbgmonitor.exe" [x]
HKU\*****\...\Run: [SearchEngineProtection] C:\Program Files\GamesBar\update\SearchEngineProtection.exe [x]
HKU\*****\...\Run: [AOL Dialer] C:\Program Files\Common Files\AOL\ACS\AOlDial.exe [x]
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)

========================== Services (Whitelisted) =================

S2 InboxAce_1gService; C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe [42504 2013-06-23] (COMPANYVERS_NAME)
S2 N360; C:\Program Files\Norton 360\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation)
S2 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe [75040 2008-09-05] (Ralink Technology, Corp.)
S2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
S2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1681408 2007-08-16] (Buhl Data Service GmbH)
S2 UtilityChest_49Service; C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe [42504 2013-06-25] (COMPANYVERS_NAME)

==================== Drivers (Whitelisted) ====================

S1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130531.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation)
S1 ccSet_N360; C:\Windows\system32\drivers\N360\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
S3 CH375; C:\Windows\System32\Drivers\CH375WDM.SYS [28403 2011-03-13] (www.winchiphead.com)
S1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2013-04-13] (Symantec Corporation)
S3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2013-04-13] (Symantec Corporation)
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc.              )
S1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130621.001\IDSvix86.sys [386720 2013-04-12] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVENG.SYS [93272 2013-05-22] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130621.022\NAVEX15.SYS [1611992 2013-05-22] (Symantec Corporation)
S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [645120 2008-08-21] (Ralink Technology Corp.)
S3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
S3 SRTSP; C:\Windows\System32\Drivers\N360\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
S1 SRTSPX; C:\Windows\system32\drivers\N360\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
S0 SymDS; C:\Windows\System32\drivers\N360\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
S0 SymEFA; C:\Windows\System32\drivers\N360\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-22] (Symantec Corporation)
S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [36512 2013-03-05] (Symantec Corporation)
S1 SymIRON; C:\Windows\system32\drivers\N360\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
S1 SYMTDIv; C:\Windows\System32\Drivers\N360\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-29] (America Online, Inc.)
S3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-29 12:30 - 2013-06-29 12:30 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\*****\Desktop\tdsskiller.exe
2013-06-29 09:19 - 2013-06-29 09:19 - 05084379 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe
2013-06-28 17:35 - 2013-06-29 09:20 - 00000000 ___SD C:\32788R22FWJFW
2013-06-28 17:35 - 2013-06-28 17:35 - 00000000 ____D C:\Windows\erdnt
2013-06-27 20:32 - 2013-06-30 08:26 - 00029395 ____A C:\Users\*****\Desktop\FRST.txt
2013-06-27 20:30 - 2013-06-27 20:30 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-06-27 20:25 - 2013-06-27 20:26 - 00013190 ____A C:\AdwCleaner[S2].txt
2013-06-27 20:25 - 2013-06-27 20:25 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-06-27 18:17 - 2013-06-27 18:18 - 01370369 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-06-27 18:15 - 2013-06-27 18:15 - 01370369 ____A (Farbar) C:\Users\*****\Downloads\FRST.exe
2013-06-25 05:39 - 2013-06-25 05:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 05:39 - 2013-06-25 05:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 21:24 - 2013-06-23 21:23 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 21:23 - 2013-06-23 21:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 10:46 - 2013-06-23 10:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 10:46 - 2013-06-23 10:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 10:44 - 2013-06-29 20:24 - 00000000 ____D C:\FRST
2013-06-23 10:26 - 2013-06-23 10:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 10:26 - 2013-06-23 10:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-23 10:24 - 2013-06-23 10:24 - 00000000 ____D C:\Program Files\InboxAce_1g
2013-06-22 22:20 - 2013-06-22 22:20 - 00000000 ____D C:\_OTL
2013-06-22 21:02 - 2013-06-22 21:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 19:31 - 2013-06-27 20:32 - 00000000 ____D C:\JRT
2013-06-22 19:31 - 2013-06-22 19:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 19:25 - 2013-06-22 19:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 19:23 - 2013-06-22 19:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 19:23 - 2013-06-22 19:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 19:18 - 2013-06-30 10:58 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-22 19:18 - 2013-06-27 20:24 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-22 19:18 - 2013-06-22 19:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 19:17 - 2013-06-27 17:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-22 19:16 - 2013-06-22 19:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 19:08 - 2013-06-22 19:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 19:00 - 2013-06-22 19:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 18:58 - 2013-06-22 18:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-17 05:19 - 2013-06-17 05:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 05:18 - 2012-08-21 12:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2013-06-17 05:17 - 2013-06-17 05:18 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 05:17 - 2013-06-17 05:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 05:13 - 2013-06-17 05:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 05:09 - 2013-06-17 05:17 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-14 12:38 - 2013-05-17 00:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-14 12:38 - 2013-05-16 23:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-14 12:38 - 2013-05-16 23:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-14 12:38 - 2013-05-16 23:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-14 12:38 - 2013-05-16 23:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-14 12:38 - 2013-05-16 23:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-14 12:38 - 2013-05-16 23:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-14 12:38 - 2013-05-16 23:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-14 12:38 - 2013-05-16 23:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-14 12:38 - 2013-05-16 23:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-14 12:38 - 2013-05-16 23:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-14 12:38 - 2013-05-16 23:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-14 12:38 - 2013-05-16 23:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-14 12:38 - 2013-05-16 23:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-14 12:38 - 2013-05-16 23:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-14 12:38 - 2013-05-16 23:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-14 12:32 - 2013-05-08 05:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-14 12:31 - 2013-05-02 23:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-14 12:31 - 2013-05-02 23:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-14 12:31 - 2013-05-02 05:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-14 12:31 - 2013-05-02 05:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-14 12:31 - 2013-04-24 05:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-14 12:31 - 2013-04-24 05:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-14 12:31 - 2013-04-24 05:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-14 12:31 - 2013-04-24 05:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-14 12:31 - 2013-04-24 02:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-14 12:31 - 2013-04-17 13:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll

==================== One Month Modified Files and Folders ========

2013-06-30 14:33 - 2010-01-24 09:55 - 00000000 ____D C:\ProgramData\NVIDIA
2013-06-30 14:33 - 2006-11-02 14:01 - 00032530 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-30 14:33 - 2006-11-02 14:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-30 14:33 - 2006-11-02 13:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-30 14:33 - 2006-11-02 13:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-30 14:17 - 2010-01-23 15:48 - 01777432 ____A C:\Windows\WindowsUpdate.log
2013-06-30 13:51 - 2011-11-22 18:11 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-30 13:50 - 2012-08-22 19:11 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-30 13:45 - 2013-02-02 12:52 - 00000524 ____A C:\Users\*****\Desktop\eMail (12).website
2013-06-30 10:58 - 2013-06-22 19:18 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-30 08:26 - 2013-06-27 20:32 - 00029395 ____A C:\Users\*****\Desktop\FRST.txt
2013-06-30 08:24 - 2011-11-22 18:11 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-29 20:24 - 2013-06-23 10:44 - 00000000 ____D C:\FRST
2013-06-29 12:30 - 2013-06-29 12:30 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\*****\Desktop\tdsskiller.exe
2013-06-29 09:20 - 2013-06-28 17:35 - 00000000 ___SD C:\32788R22FWJFW
2013-06-29 09:19 - 2013-06-29 09:19 - 05084379 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe
2013-06-29 08:08 - 2010-01-23 16:02 - 01037194 ____A C:\Windows\PFRO.log
2013-06-28 17:35 - 2013-06-28 17:35 - 00000000 ____D C:\Windows\erdnt
2013-06-27 20:32 - 2013-06-22 19:31 - 00000000 ____D C:\JRT
2013-06-27 20:30 - 2013-06-27 20:30 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-06-27 20:26 - 2013-06-27 20:25 - 00013190 ____A C:\AdwCleaner[S2].txt
2013-06-27 20:25 - 2013-06-27 20:25 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-06-27 20:24 - 2013-06-22 19:18 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-27 20:06 - 2010-12-28 11:53 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-06-27 18:18 - 2013-06-27 18:17 - 01370369 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-06-27 18:15 - 2013-06-27 18:15 - 01370369 ____A (Farbar) C:\Users\*****\Downloads\FRST.exe
2013-06-27 17:59 - 2010-01-26 14:57 - 00002591 ____A C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk
2013-06-27 17:44 - 2013-06-22 19:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-25 05:39 - 2013-06-25 05:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 05:39 - 2013-06-25 05:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 21:23 - 2013-06-23 21:24 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 21:23 - 2013-06-23 21:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 10:46 - 2013-06-23 10:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 10:46 - 2013-06-23 10:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 10:26 - 2013-06-23 10:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 10:26 - 2013-06-23 10:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-23 10:24 - 2013-06-23 10:24 - 00000000 ____D C:\Program Files\InboxAce_1g
2013-06-22 22:20 - 2013-06-22 22:20 - 00000000 ____D C:\_OTL
2013-06-22 21:02 - 2013-06-22 21:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 20:59 - 2010-01-23 16:06 - 00000000 ___AD C:\users\*****
2013-06-22 19:31 - 2013-06-22 19:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 19:25 - 2013-06-22 19:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 19:23 - 2013-06-22 19:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 19:23 - 2013-06-22 19:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 19:18 - 2013-06-22 19:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 19:17 - 2011-10-21 12:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-22 19:16 - 2013-06-22 19:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 19:08 - 2013-06-22 19:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 19:04 - 2011-04-17 18:29 - 00000000 ____D C:\Windows\System32\Drivers\N360
2013-06-22 19:03 - 2011-04-17 18:30 - 00002023 ____A C:\Users\Public\Desktop\Norton 360.lnk
2013-06-22 19:00 - 2013-06-22 19:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 18:58 - 2013-06-22 18:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-22 18:54 - 2013-01-09 20:21 - 00001935 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-22 18:23 - 2011-04-17 18:30 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS
2013-06-22 18:23 - 2011-04-17 18:30 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT
2013-06-17 05:19 - 2013-06-17 05:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 05:19 - 2012-05-21 19:02 - 00000000 ____D C:\Users\*****\AppData\Roaming\Apple Computer
2013-06-17 05:19 - 2010-01-26 09:43 - 00000000 ____D C:\Users\*****\AppData\Local\Apple Computer
2013-06-17 05:18 - 2013-06-17 05:17 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 05:17 - 2013-06-17 05:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 05:17 - 2013-06-17 05:09 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-17 05:17 - 2010-02-13 13:59 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-06-17 05:17 - 2010-02-13 13:54 - 00000000 ____D C:\ProgramData\Apple
2013-06-17 05:13 - 2013-06-17 05:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 05:09 - 2012-05-21 05:11 - 00001690 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2013-06-17 05:09 - 2008-01-23 13:46 - 00000000 ____D C:\Program Files\QuickTime
2013-06-14 16:02 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-06-14 15:48 - 2012-08-22 19:11 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-14 15:48 - 2011-09-04 06:42 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-14 15:43 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-14 12:36 - 2006-11-02 11:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e

Files to move or delete:
====================
C:\ProgramData\nvModes.dat

==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================


==================== Memory info ===========================

Percentage of memory in use: 14%
Total physical RAM: 3069.56 MB
Available physical RAM: 2629.11 MB
Total Pagefile: 2846.03 MB
Available Pagefile: 2692.86 MB
Total Virtual: 2047.88 MB
Available Virtual: 1979.14 MB

==================== Drives ================================

Drive c: (BOOT) (Fixed) (Total:445.76 GB) (Free:361.42 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (RECOVER) (Fixed) (Total:19.99 GB) (Free:5.22 GB) FAT32
Drive e: (MEDHOPRDEU) (CDROM) (Total:2.41 GB) (Free:0 GB) CDFS
Drive i: (HITMANPRO) (Removable) (Total:0.93 GB) (Free:0.93 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 2BAB359D)
Partition 1: (Active) - (Size=446 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended)

========================================================
Disk: 4 (Size: 962 MB) (Disk ID: 75F5AA57)
Partition 1: (Active) - (Size=957 MB) - (Type=0B)


LastRegBack: 2013-06-30 08:29

==================== End Of Log ============================

--- --- ---

--- --- ---


Und vielen Dank für Deine Hilfe, das große Dankeschön kommt aber noch....

Grüße
Sabine99

schrauber 30.06.2013 16:18

Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
Code:

S2 InboxAce_1gService; C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbarsvc.exe [42504 2013-06-23] (COMPANYVERS_NAME)
2013-06-23 10:24 - 2013-06-23 10:24 - 00000000 ____D C:\Program Files\InboxAce_1g
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e
C:\ProgramData\nvModes.dat

Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Fix Button.
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.


und ein frisches FRST Log aus der Recovery bitte :)

Sabine99 30.06.2013 16:30

Hi,
und hier kommen sie schon.

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 29-06-2013 01
Ran by SYSTEM at 2013-06-30 17:26:28 Run:4
Running from I:\
Boot Mode: Recovery

==============================================

InboxAce_1gService => Service deleted successfully.
C:\Program Files\InboxAce_1g => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-1346077651-4163414706-2657881005-1000\$b3f4bc23f743f11a6c7d77e802656f9e => Directory moved successfully.
C:\ProgramData\nvModes.dat => Moved successfully.

==== End of Fixlog ====


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-06-2013 01
Ran by SYSTEM on 30-06-2013 17:27:12
Running from I:\
Windows Vista (TM) Home Premium (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and Addition.txt log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [UpdatePPShortCut] "C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\PowerProducer" update "Software\CyberLink\PowerProducer\4.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM\...\Run: [Windows Defender] %programfiles%\windows defender\msascui.exe -hide [1008184 2008-01-18] (Microsoft Corporation)
HKLM\...\Run: [LexwareInfoService] c:\program files\common files\lexware\update manager\lxupdatemanager.exe /autostart [339240 2008-11-03] (Lexware GmbH & Co. KG)
HKLM\...\Run: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\nbkeyscan.exe" [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [RemoteControl] "c:\program files\homecinema\powerdvd\pdvdserv.exe" [71216 2007-02-09] (Cyberlink Corp.)
HKLM\...\Run: [TVBroadcast] c:\program files\sceneo\absoluttv\services\odsbc\odsbcapp.exe [797696 2007-08-08] (ODSoft multimedia)
HKLM\...\Run: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe [90112 2006-11-29] (Ulead Systems, Inc.)
HKLM\...\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [InboxAce Search Scope Monitor] "C:\PROGRA~1\INBOXA~2\bar\1.bin\1gsrchmn.exe" /m=2 /w /h [x]
HKLM\...\Run: [InboxAce_1g Browser Plugin Loader] C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbrmon.exe [x]
HKLM\...\Run: [Utility Chest Search Scope Monitor] "C:\PROGRA~1\UTILIT~2\bar\1.bin\49srchmn.exe" /m=2 /w /h [44784 2013-06-25] (MindSpark)
HKLM\...\Run: [UtilityChest_49 Browser Plugin Loader] C:\PROGRA~1\UTILIT~2\bar\1.bin\49brmon.exe [30096 2013-06-25] (VER_COMPANY_NAME)
HKU\*****\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [ 2008-01-18] (Microsoft Corporation)
HKU\*****\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\nmbgmonitor.exe" [x]
HKU\*****\...\Run: [SearchEngineProtection] C:\Program Files\GamesBar\update\SearchEngineProtection.exe [x]
HKU\*****\...\Run: [AOL Dialer] C:\Program Files\Common Files\AOL\ACS\AOlDial.exe [x]
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)

========================== Services (Whitelisted) =================

S2 N360; C:\Program Files\Norton 360\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation)
S2 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe [75040 2008-09-05] (Ralink Technology, Corp.)
S2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
S2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1681408 2007-08-16] (Buhl Data Service GmbH)
S2 UtilityChest_49Service; C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe [42504 2013-06-25] (COMPANYVERS_NAME)

==================== Drivers (Whitelisted) ====================

S1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130620.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation)
S1 ccSet_N360; C:\Windows\system32\drivers\N360\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
S3 CH375; C:\Windows\System32\Drivers\CH375WDM.SYS [28403 2011-03-13] (www.winchiphead.com)
S1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2013-04-13] (Symantec Corporation)
S3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2013-04-13] (Symantec Corporation)
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc.              )
S1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130628.001\IDSvix86.sys [386720 2013-04-12] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130629.007\NAVENG.SYS [93272 2013-05-22] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130629.007\NAVEX15.SYS [1611992 2013-05-22] (Symantec Corporation)
S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [645120 2008-08-21] (Ralink Technology Corp.)
S3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
S3 SRTSP; C:\Windows\System32\Drivers\N360\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
S1 SRTSPX; C:\Windows\system32\drivers\N360\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
S0 SymDS; C:\Windows\System32\drivers\N360\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
S0 SymEFA; C:\Windows\System32\drivers\N360\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-22] (Symantec Corporation)
S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [36512 2013-03-05] (Symantec Corporation)
S1 SymIRON; C:\Windows\system32\drivers\N360\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
S1 SYMTDIv; C:\Windows\System32\Drivers\N360\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-29] (America Online, Inc.)
S3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-29 12:30 - 2013-06-29 12:30 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\*****\Desktop\tdsskiller.exe
2013-06-29 09:19 - 2013-06-29 09:19 - 05084379 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe
2013-06-28 17:35 - 2013-06-29 09:20 - 00000000 ___SD C:\32788R22FWJFW
2013-06-28 17:35 - 2013-06-28 17:35 - 00000000 ____D C:\Windows\erdnt
2013-06-27 20:32 - 2013-06-30 08:26 - 00029395 ____A C:\Users\*****\Desktop\FRST.txt
2013-06-27 20:30 - 2013-06-27 20:30 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-06-27 20:25 - 2013-06-27 20:26 - 00013190 ____A C:\AdwCleaner[S2].txt
2013-06-27 20:25 - 2013-06-27 20:25 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-06-27 18:17 - 2013-06-27 18:18 - 01370369 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-06-27 18:15 - 2013-06-27 18:15 - 01370369 ____A (Farbar) C:\Users\*****\Downloads\FRST.exe
2013-06-25 05:39 - 2013-06-25 05:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 05:39 - 2013-06-25 05:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 21:24 - 2013-06-23 21:23 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 21:23 - 2013-06-23 21:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 10:46 - 2013-06-23 10:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 10:46 - 2013-06-23 10:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 10:44 - 2013-06-29 20:24 - 00000000 ____D C:\FRST
2013-06-23 10:26 - 2013-06-23 10:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 10:26 - 2013-06-23 10:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-22 22:20 - 2013-06-22 22:20 - 00000000 ____D C:\_OTL
2013-06-22 21:02 - 2013-06-22 21:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 19:31 - 2013-06-27 20:32 - 00000000 ____D C:\JRT
2013-06-22 19:31 - 2013-06-22 19:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 19:25 - 2013-06-22 19:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 19:23 - 2013-06-22 19:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 19:23 - 2013-06-22 19:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 19:18 - 2013-06-30 15:52 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-22 19:18 - 2013-06-27 20:24 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-22 19:18 - 2013-06-22 19:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 19:17 - 2013-06-27 17:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-22 19:16 - 2013-06-22 19:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 19:08 - 2013-06-22 19:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 19:00 - 2013-06-22 19:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 18:58 - 2013-06-22 18:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-17 05:19 - 2013-06-17 05:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 05:18 - 2012-08-21 12:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2013-06-17 05:17 - 2013-06-17 05:18 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 05:17 - 2013-06-17 05:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 05:13 - 2013-06-17 05:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 05:09 - 2013-06-17 05:17 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-14 12:38 - 2013-05-17 00:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-14 12:38 - 2013-05-16 23:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-14 12:38 - 2013-05-16 23:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-14 12:38 - 2013-05-16 23:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-14 12:38 - 2013-05-16 23:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-14 12:38 - 2013-05-16 23:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-14 12:38 - 2013-05-16 23:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-14 12:38 - 2013-05-16 23:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-14 12:38 - 2013-05-16 23:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-14 12:38 - 2013-05-16 23:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-14 12:38 - 2013-05-16 23:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-14 12:38 - 2013-05-16 23:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-14 12:38 - 2013-05-16 23:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-14 12:38 - 2013-05-16 23:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-14 12:38 - 2013-05-16 23:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-14 12:38 - 2013-05-16 23:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-14 12:32 - 2013-05-08 05:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-14 12:31 - 2013-05-02 23:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-14 12:31 - 2013-05-02 23:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-14 12:31 - 2013-05-02 05:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-14 12:31 - 2013-05-02 05:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-14 12:31 - 2013-04-24 05:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-14 12:31 - 2013-04-24 05:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-14 12:31 - 2013-04-24 05:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-14 12:31 - 2013-04-24 05:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-14 12:31 - 2013-04-24 02:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-14 12:31 - 2013-04-17 13:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll

==================== One Month Modified Files and Folders ========

2013-06-30 16:22 - 2010-01-23 15:48 - 01785487 ____A C:\Windows\WindowsUpdate.log
2013-06-30 16:22 - 2006-11-02 14:01 - 00032530 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-30 16:22 - 2006-11-02 14:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-30 16:22 - 2006-11-02 13:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-30 16:22 - 2006-11-02 13:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-30 16:16 - 2011-11-22 18:11 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-30 15:52 - 2013-06-22 19:18 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-30 15:51 - 2011-11-22 18:11 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-30 15:50 - 2012-08-22 19:11 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-30 15:21 - 2010-01-24 09:55 - 00000000 ____D C:\ProgramData\NVIDIA
2013-06-30 13:45 - 2013-02-02 12:52 - 00000524 ____A C:\Users\*****\Desktop\eMail (12).website
2013-06-30 08:26 - 2013-06-27 20:32 - 00029395 ____A C:\Users\*****\Desktop\FRST.txt
2013-06-29 20:24 - 2013-06-23 10:44 - 00000000 ____D C:\FRST
2013-06-29 12:30 - 2013-06-29 12:30 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\*****\Desktop\tdsskiller.exe
2013-06-29 09:20 - 2013-06-28 17:35 - 00000000 ___SD C:\32788R22FWJFW
2013-06-29 09:19 - 2013-06-29 09:19 - 05084379 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe
2013-06-29 08:08 - 2010-01-23 16:02 - 01037194 ____A C:\Windows\PFRO.log
2013-06-28 17:35 - 2013-06-28 17:35 - 00000000 ____D C:\Windows\erdnt
2013-06-27 20:32 - 2013-06-22 19:31 - 00000000 ____D C:\JRT
2013-06-27 20:30 - 2013-06-27 20:30 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-06-27 20:26 - 2013-06-27 20:25 - 00013190 ____A C:\AdwCleaner[S2].txt
2013-06-27 20:25 - 2013-06-27 20:25 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-06-27 20:24 - 2013-06-22 19:18 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-27 20:06 - 2010-12-28 11:53 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-06-27 18:18 - 2013-06-27 18:17 - 01370369 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-06-27 18:15 - 2013-06-27 18:15 - 01370369 ____A (Farbar) C:\Users\*****\Downloads\FRST.exe
2013-06-27 17:59 - 2010-01-26 14:57 - 00002591 ____A C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk
2013-06-27 17:44 - 2013-06-22 19:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-25 05:39 - 2013-06-25 05:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 05:39 - 2013-06-25 05:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 21:23 - 2013-06-23 21:24 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 21:23 - 2013-06-23 21:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 10:46 - 2013-06-23 10:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 10:46 - 2013-06-23 10:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 10:26 - 2013-06-23 10:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 10:26 - 2013-06-23 10:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-22 22:20 - 2013-06-22 22:20 - 00000000 ____D C:\_OTL
2013-06-22 21:02 - 2013-06-22 21:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 20:59 - 2010-01-23 16:06 - 00000000 ___AD C:\users\*****
2013-06-22 19:31 - 2013-06-22 19:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 19:25 - 2013-06-22 19:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 19:23 - 2013-06-22 19:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 19:23 - 2013-06-22 19:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 19:18 - 2013-06-22 19:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 19:17 - 2011-10-21 12:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-22 19:16 - 2013-06-22 19:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 19:08 - 2013-06-22 19:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 19:04 - 2011-04-17 18:29 - 00000000 ____D C:\Windows\System32\Drivers\N360
2013-06-22 19:03 - 2011-04-17 18:30 - 00002023 ____A C:\Users\Public\Desktop\Norton 360.lnk
2013-06-22 19:00 - 2013-06-22 19:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 18:58 - 2013-06-22 18:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-22 18:54 - 2013-01-09 20:21 - 00001935 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-22 18:23 - 2011-04-17 18:30 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS
2013-06-22 18:23 - 2011-04-17 18:30 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT
2013-06-17 05:19 - 2013-06-17 05:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 05:19 - 2012-05-21 19:02 - 00000000 ____D C:\Users\*****\AppData\Roaming\Apple Computer
2013-06-17 05:19 - 2010-01-26 09:43 - 00000000 ____D C:\Users\*****\AppData\Local\Apple Computer
2013-06-17 05:18 - 2013-06-17 05:17 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 05:17 - 2013-06-17 05:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 05:17 - 2013-06-17 05:09 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-17 05:17 - 2010-02-13 13:59 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-06-17 05:17 - 2010-02-13 13:54 - 00000000 ____D C:\ProgramData\Apple
2013-06-17 05:13 - 2013-06-17 05:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 05:09 - 2012-05-21 05:11 - 00001690 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2013-06-17 05:09 - 2008-01-23 13:46 - 00000000 ____D C:\Program Files\QuickTime
2013-06-14 16:02 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-06-14 15:48 - 2012-08-22 19:11 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-14 15:48 - 2011-09-04 06:42 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-14 15:43 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-14 12:36 - 2006-11-02 11:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe

==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================


==================== Memory info ===========================

Percentage of memory in use: 14%
Total physical RAM: 3069.56 MB
Available physical RAM: 2626.97 MB
Total Pagefile: 2846.03 MB
Available Pagefile: 2691.01 MB
Total Virtual: 2047.88 MB
Available Virtual: 1965.6 MB

==================== Drives ================================

Drive c: (BOOT) (Fixed) (Total:445.76 GB) (Free:361.41 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (RECOVER) (Fixed) (Total:19.99 GB) (Free:5.22 GB) FAT32
Drive e: (MEDHOPRDEU) (CDROM) (Total:2.41 GB) (Free:0 GB) CDFS
Drive i: (HITMANPRO) (Removable) (Total:0.93 GB) (Free:0.93 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 2BAB359D)
Partition 1: (Active) - (Size=446 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended)

========================================================
Disk: 4 (Size: 962 MB) (Disk ID: 75F5AA57)
Partition 1: (Active) - (Size=957 MB) - (Type=0B)


LastRegBack: 2013-06-30 15:36

==================== End Of Log ============================

--- --- ---

--- --- ---


Ich hoffe, jetzt sind alle Reste weg.

Grüße

Sabine99

schrauber 30.06.2013 19:45

Ooooh, bitte mal nen frischen FRST Scan aus dem normalen Windows :)

Sabine99 30.06.2013 19:52

Hi Schrauber,

hier ist sie, normales Windows, du machst mich ein bisschen nervös (ooooh -positiv oder negativ?)


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-06-2013 02
Ran by ***** (administrator) on 30-06-2013 20:48:23
Running from C:\Users\*****\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe
(COMPANYVERS_NAME) C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Microsoft Corporation) C:\Windows\system32\userinit.exe
(Lexware GmbH & Co. KG) C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe
(ODSoft multimedia) C:\Program Files\Sceneo\AbsolutTV\Services\ODSBC\ODSBCApp.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(VER_COMPANY_NAME) C:\Program Files\UtilityChest_49\bar\1.bin\49brmon.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Hewlett-Packard Co.) C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RaUI.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Lexware GmbH & Co. KG) C:\Program Files\Common Files\Lexware\LxWebAccess\LxWebAccess.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [UpdatePPShortCut] "C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\PowerProducer" update "Software\CyberLink\PowerProducer\4.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM\...\Run: [Windows Defender] %programfiles%\windows defender\msascui.exe -hide [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [LexwareInfoService] c:\program files\common files\lexware\update manager\lxupdatemanager.exe /autostart [339240 2008-11-03] (Lexware GmbH & Co. KG)
HKLM\...\Run: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\nbkeyscan.exe" [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [RemoteControl] "c:\program files\homecinema\powerdvd\pdvdserv.exe" [71216 2007-02-09] (Cyberlink Corp.)
HKLM\...\Run: [TVBroadcast] c:\program files\sceneo\absoluttv\services\odsbc\odsbcapp.exe [797696 2007-08-08] (ODSoft multimedia)
HKLM\...\Run: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe [90112 2006-11-29] (Ulead Systems, Inc.)
HKLM\...\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [InboxAce Search Scope Monitor] "C:\PROGRA~1\INBOXA~2\bar\1.bin\1gsrchmn.exe" /m=2 /w /h [x]
HKLM\...\Run: [InboxAce_1g Browser Plugin Loader] C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbrmon.exe [x]
HKLM\...\Run: [Utility Chest Search Scope Monitor] "C:\PROGRA~1\UTILIT~2\bar\1.bin\49srchmn.exe" /m=2 /w /h [44784 2013-06-25] (MindSpark)
HKLM\...\Run: [UtilityChest_49 Browser Plugin Loader] C:\PROGRA~1\UTILIT~2\bar\1.bin\49brmon.exe [30096 2013-06-25] (VER_COMPANY_NAME)
HKCU\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\nmbgmonitor.exe" [202024 2007-10-15] (Nero AG)
HKCU\...\Run: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autorun [1233920 2009-04-11] (Microsoft Corporation)
HKCU\...\Run: [SearchEngineProtection] C:\Program Files\GamesBar\update\SearchEngineProtection.exe [x]
HKCU\...\Run: [AOL Dialer] C:\Program Files\Common Files\AOL\ACS\AOlDial.exe [x]
HKCU\...\Policies\system: [disableregistrytools] 0
MountPoints2: {efcd0c81-082c-11df-b5e6-806e6f6e6963} - H:\setup.exe
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)

==================== Internet (Whitelisted) ====================

ProxyServer: 192.168.1.1:80
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
URLSearchHook: (No Name) - {7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
URLSearchHook: (No Name) - {5fdb0cd8-5760-44d1-8d13-a78bf558c3c7} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll No File
HKCU SearchScopes: DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
BHO: Search Assistant BHO - {06e05b40-77fa-40b6-9077-ed1a7577b1ef} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
BHO: GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
BHO: Toolbar BHO - {58f7b5ca-1162-42e8-8bbc-d543b4edd780} - C:\PROGRA~1\UTILIT~2\bar\1.bin\49bar.dll (MindSpark)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Search Assistant BHO - {9359da42-06fb-46f2-9e4a-05c05b98a5ef} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll No File
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Toolbar BHO - {d5a1d22b-9e17-454f-8ecd-83c578fb3983} - C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbar.dll No File
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - InboxAce - {3775afd7-5921-4571-968f-85a631203d1c} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll No File
Toolbar: HKLM - Utility Chest - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -InboxAce - {3775AFD7-5921-4571-968F-85A631203D1C} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll No File
Toolbar: HKCU -Utility Chest - {CF67755F-9265-449C-87CF-B945519E073B} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Chrome:
=======
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013"
CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1
CHR Extension: (Norton Identity Protection) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.11.8_0
CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

========================== Services (Whitelisted) =================

R2 N360; C:\Program Files\Norton 360\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation)
R2 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe [75040 2008-09-05] (Ralink Technology, Corp.)
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1681408 2007-08-16] (Buhl Data Service GmbH)
R2 UtilityChest_49Service; C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe [42504 2013-06-25] (COMPANYVERS_NAME)

==================== Drivers (Whitelisted) ====================

R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130620.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
S3 CH375; C:\Windows\System32\Drivers\CH375WDM.SYS [28403 2011-03-14] (www.winchiphead.com)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2013-04-13] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2013-04-13] (Symantec Corporation)
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc.              )
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130628.001\IDSvix86.sys [386720 2013-04-12] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130629.007\NAVENG.SYS [93272 2013-05-22] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130629.007\NAVEX15.SYS [1611992 2013-05-22] (Symantec Corporation)
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [645120 2008-08-21] (Ralink Technology Corp.)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
S3 SRTSP; C:\Windows\System32\Drivers\N360\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-22] (Symantec Corporation)
R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [36512 2013-03-05] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\N360\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-30] (America Online, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-29 13:30 - 2013-06-29 13:30 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\*****\Desktop\tdsskiller.exe
2013-06-29 10:19 - 2013-06-29 10:19 - 05084379 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe
2013-06-28 18:35 - 2013-06-29 10:20 - 00000000 ___SD C:\32788R22FWJFW
2013-06-28 18:35 - 2013-06-28 18:35 - 00000000 ____D C:\Windows\erdnt
2013-06-27 21:30 - 2013-06-27 21:30 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-06-27 21:25 - 2013-06-27 21:26 - 00013190 ____A C:\AdwCleaner[S2].txt
2013-06-27 21:25 - 2013-06-27 21:25 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-06-27 19:17 - 2013-06-27 19:18 - 01370369 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-06-27 19:15 - 2013-06-27 19:15 - 01370369 ____A (Farbar) C:\Users\*****\Downloads\FRST.exe
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 22:24 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 22:23 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:44 - 2013-06-29 21:24 - 00000000 ____D C:\FRST
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-22 23:20 - 2013-06-22 23:20 - 00000000 ____D C:\_OTL
2013-06-22 22:02 - 2013-06-22 22:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 20:31 - 2013-06-27 21:32 - 00000000 ____D C:\JRT
2013-06-22 20:31 - 2013-06-22 20:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 20:25 - 2013-06-22 20:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 20:23 - 2013-06-22 20:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:18 - 2013-06-30 16:52 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-22 20:18 - 2013-06-27 21:24 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-22 20:18 - 2013-06-22 20:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 20:17 - 2013-06-27 18:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:00 - 2013-06-22 20:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 19:58 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:18 - 2012-08-21 13:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2013-06-17 06:17 - 2013-06-17 06:18 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2013-06-17 06:17 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-14 13:38 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-14 13:38 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-14 13:38 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-14 13:38 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-14 13:38 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-14 13:38 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-14 13:38 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-14 13:38 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-14 13:38 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-14 13:38 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-14 13:32 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-14 13:31 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-14 13:31 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-14 13:31 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-14 13:31 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-14 13:31 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-14 13:31 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll

==================== One Month Modified Files and Folders ========

2013-06-30 20:48 - 2011-11-22 19:11 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-30 20:47 - 2010-01-24 10:55 - 00000000 ____D C:\ProgramData\NVIDIA
2013-06-30 20:47 - 2010-01-23 17:02 - 01040940 ____A C:\Windows\PFRO.log
2013-06-30 20:47 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-30 20:47 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-30 20:47 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-30 17:22 - 2010-01-23 16:48 - 01785487 ____A C:\Windows\WindowsUpdate.log
2013-06-30 17:22 - 2006-11-02 15:01 - 00032530 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-30 16:52 - 2013-06-22 20:18 - 00000332 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-06-30 16:51 - 2011-11-22 19:11 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-30 16:50 - 2012-08-22 20:11 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-30 14:45 - 2013-02-02 13:52 - 00000524 ____A C:\Users\*****\Desktop\eMail (12).website
2013-06-29 21:24 - 2013-06-23 11:44 - 00000000 ____D C:\FRST
2013-06-29 13:30 - 2013-06-29 13:30 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\*****\Desktop\tdsskiller.exe
2013-06-29 10:20 - 2013-06-28 18:35 - 00000000 ___SD C:\32788R22FWJFW
2013-06-29 10:19 - 2013-06-29 10:19 - 05084379 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe
2013-06-28 18:35 - 2013-06-28 18:35 - 00000000 ____D C:\Windows\erdnt
2013-06-27 21:32 - 2013-06-22 20:31 - 00000000 ____D C:\JRT
2013-06-27 21:30 - 2013-06-27 21:30 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-06-27 21:26 - 2013-06-27 21:25 - 00013190 ____A C:\AdwCleaner[S2].txt
2013-06-27 21:25 - 2013-06-27 21:25 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-06-27 21:24 - 2013-06-22 20:18 - 00000000 ____D C:\Program Files\PC Speed Up
2013-06-27 21:06 - 2010-12-28 12:53 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-06-27 19:18 - 2013-06-27 19:17 - 01370369 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-06-27 19:15 - 2013-06-27 19:15 - 01370369 ____A (Farbar) C:\Users\*****\Downloads\FRST.exe
2013-06-27 18:59 - 2010-01-26 15:57 - 00002591 ____A C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk
2013-06-27 18:44 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 22:23 - 2013-06-23 22:24 - 00890839 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-06-23 22:23 - 2013-06-23 22:23 - 00890839 ____A C:\Users\*****\Downloads\SecurityCheck.exe
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-22 23:20 - 2013-06-22 23:20 - 00000000 ____D C:\_OTL
2013-06-22 22:02 - 2013-06-22 22:02 - 00080210 ____A C:\OTL.Txt
2013-06-22 21:59 - 2010-01-23 17:06 - 00000000 ___AD C:\users\*****
2013-06-22 20:31 - 2013-06-22 20:31 - 00000000 ____D C:\Users\*****\Documents\PCSpeedUp
2013-06-22 20:25 - 2013-06-22 20:25 - 00002059 ____A C:\Users\*****\Desktop\Search.lnk
2013-06-22 20:23 - 2013-06-22 20:23 - 01110476 ____A C:\Users\*****\Desktop\7zip.exe
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:18 - 2013-06-22 20:18 - 00000809 ____A C:\Users\*****\Desktop\PC Speed Up.lnk
2013-06-22 20:17 - 2011-10-21 13:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:04 - 2011-04-17 19:29 - 00000000 ____D C:\Windows\System32\Drivers\N360
2013-06-22 20:03 - 2011-04-17 19:30 - 00002023 ____A C:\Users\Public\Desktop\Norton 360.lnk
2013-06-22 20:00 - 2013-06-22 20:00 - 00043012 ____A C:\AdwCleaner[S1].txt
2013-06-22 19:58 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-22 19:54 - 2013-01-09 21:21 - 00001935 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-22 19:23 - 2011-04-17 19:30 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS
2013-06-22 19:23 - 2011-04-17 19:30 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:19 - 2012-05-21 20:02 - 00000000 ____D C:\Users\*****\AppData\Roaming\Apple Computer
2013-06-17 06:19 - 2010-01-26 10:43 - 00000000 ____D C:\Users\*****\AppData\Local\Apple Computer
2013-06-17 06:18 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:17 - 2013-06-17 06:09 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-17 06:17 - 2010-02-13 14:59 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-06-17 06:17 - 2010-02-13 14:54 - 00000000 ____D C:\ProgramData\Apple
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2012-05-21 06:11 - 00001690 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2013-06-17 06:09 - 2008-01-23 14:46 - 00000000 ____D C:\Program Files\QuickTime
2013-06-14 17:02 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-06-14 16:48 - 2012-08-22 20:11 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-14 16:48 - 2011-09-04 07:42 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-14 16:43 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-14 13:36 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-30 16:36

==================== End Of Log ============================

--- --- ---


Grüße

Sabine99

schrauber 30.06.2013 19:57

100% positiv :D

Fertig :)

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.


Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.

Sabine99 30.06.2013 20:40

Hi Schrauber,
super, dann arbeite ich mich mal durch Deine Liste. Der PC ist jetzt wieder sicher? Ich mach nämlich auch online Banking damit.

Naja, jetzt habe ich eben gelernt, dass regelmäßige updates von Windows und Norton auch nicht reichen
Ich hab noch mitbekommen, dass Norton den PC langsam macht, was würdest Du mir denn empfehlen? Und wie bekomm ich das denn komplett von meinem PC.

Wir wollten noch einen scan von meinem Laptop machen :taenzer:
Der hat als Betriebssystem Windows 7 home Edition.
Aber erst morgen oder so.

Also nochmals vielen Dank für Deine Hilfe:dankeschoen:


Ohne Dich wäre ich ganzschön aufgeschmissen gewesen.

Sabine99

PS: Irgendwie finde ich die Combofix.exe nicht, auch das Notepad geht so nicht. Ich hatte aber Probleme beim installieren und es auch nicht benutzt, kann ich es einfach so in den Papierkorb schieben und löschen? Mache dann morgen weiter...:confused:

schrauber 01.07.2013 07:39

Las einfach Delfix laufen, das entfernt auch Combofix.

Banking nur mit ChipTan oder höher.

FRST Logs vom laptop bitte. :)

Sabine99 01.07.2013 17:16

HI Schrauber,

anbei FRST vom Laptop, sollte eigentlich (hoffentlich) nichts sein, da wir mit dem bis auf die letzten 2 Wochen selten im Netz waren:


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-06-2013 03
Ran by ***** (administrator) on 01-07-2013 18:11:51
Running from C:\Users\*****\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
() C:\windows\SysWOW64\Rezip.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
(Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
(AOL LLC) c:\program files (x86)\aol\aol toolbar 4.0\AolTbServer.exe
(Microsoft Corporation) C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Adobe Systems, Inc.) C:\windows\SysWow64\Macromed\Flash\FlashUtil9f.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [9644576 2009-12-15] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2074408 2010-02-26] (Synaptics Incorporated)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup [16413288 2010-02-10] (NVIDIA Corporation)
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-04-26] (Google Inc.)
MountPoints2: {3d82f461-6aa4-11e0-be41-00038a000015} - F:\AutoRun.exe
MountPoints2: {3d82f46f-6aa4-11e0-be41-00038a000015} - F:\AutoRun.exe
HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-06-03] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePDRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [91432 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe" [50472 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0" [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2009-07-21] (CyberLink Corp.)
HKLM-x32\...\Run: [APLangApp] "C:\Program Files (x86)\AnyPC Client\APLangApp.exe" [13312 2009-11-20] (DoctorSoft)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime [98304 2011-04-19] (Apple Computer, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.mywebsearch.com/index.jhtml?n=77DE8857&p2=^ZO^xdm071^YY^de&ptb=D97F0AC6-4413-4C40-871C-2B11E34E28B4&si=EL_UT_GER_11
URLSearchHook: (No Name) - {1CFFA392-0898-4b1c-89D1-6E98F9D8EF78} -  No File
SearchScopes: HKLM-x32 - {84dc9f6c-c9a5-4c64-ab67-d6ef60f963c8} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZO^xdm071^YY^de&si=EL_UT_GER_11&ptb=D97F0AC6-4413-4C40-871C-2B11E34E28B4&ind=2013061914&n=77fce31a&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=26A578E4005D23FF&affID=119357&tt=180613_10&tsp=4918
SearchScopes: HKCU - {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = hxxp://suche.aol.de/suche/web/search.jsp?q={searchTerms}
SearchScopes: HKCU - {84dc9f6c-c9a5-4c64-ab67-d6ef60f963c8} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZO^xdm071^YY^de&si=EL_UT_GER_11&ptb=D97F0AC6-4413-4C40-871C-2B11E34E28B4&ind=2013061914&n=77fce31a&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://int.search-results.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=360&chn=retail&geo=DE&ver=5
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} -  No File
BHO-x32: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coIEPlg.dll (Symantec Corporation)
BHO-x32: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files (x86)\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKCU - No Name - {DE9C389F-3316-41A7-809B-AA305ED9D922} -  No File
Toolbar: HKCU - No Name - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} -  No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9737BF33-AC5F-4930-BBC0-1A3182B820F8}: [NameServer]193.189.244.225 193.189.244.206

==================== Services (Whitelisted) =================

R2 N360; C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe [130008 2011-04-17] (Symantec Corporation)
R2 Rezip; C:\windows\SysWOW64\Rezip.exe [311296 2009-03-05] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-07] ()
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [x]

==================== Drivers (Whitelisted) ====================

R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\BASHDefs\20130620.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\BASHDefs\20130620.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
R3 CryptOSD; C:\Windows\System32\DRIVERS\CryptOSD.sys [431488 2009-06-25] (Phoenix Technologies)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-15] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-15] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-03-15] (Symantec Corporation)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\IPSDefs\20130628.001\IDSvia64.sys [513184 2013-06-15] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\IPSDefs\20130628.001\IDSvia64.sys [513184 2013-06-15] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130629.007\ENG64.SYS [126040 2013-06-23] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130629.007\ENG64.SYS [126040 2013-06-23] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130629.007\EX64.SYS [2098776 2013-06-23] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130629.007\EX64.SYS [2098776 2013-06-23] (Symantec Corporation)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-06-24] (Windows (R) 2003 DDK 3790 provider)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-06-24] (Windows (R) 2003 DDK 3790 provider)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\0502020.003\SRTSP64.SYS [744568 2011-03-31] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\0502020.003\SRTSPX64.SYS [40568 2011-03-31] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\0502020.003\SYMDS64.SYS [450680 2011-01-27] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\0502020.003\SYMEFA64.SYS [912504 2011-03-15] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2011-05-14] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\0502020.003\Ironx64.SYS [171128 2010-11-16] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\0502020.003\SYMNETS.SYS [386168 2011-04-21] (Symantec Corporation)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
S2 ASCTRM; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-01 18:11 - 2013-07-01 18:11 - 00023556 ____A C:\Users\*****\Desktop\Addition.txt
2013-07-01 18:10 - 2013-07-01 18:10 - 01933758 ____A (Farbar) C:\Users\*****\Desktop\FRST64.exe
2013-07-01 18:10 - 2013-07-01 18:10 - 00000000 ____D C:\FRST
2013-06-30 22:12 - 2012-08-23 16:13 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\rdpudd.dll
2013-06-30 22:12 - 2012-08-23 16:10 - 00019456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys
2013-06-30 22:12 - 2012-08-23 16:07 - 00057856 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys
2013-06-30 22:12 - 2012-08-23 15:47 - 00046592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-06-30 22:12 - 2012-08-23 15:46 - 00016896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-06-30 22:12 - 2012-08-23 15:41 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
2013-06-30 22:12 - 2012-08-23 15:40 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2013-06-30 22:12 - 2012-08-23 15:24 - 00015360 ____A (Microsoft Corporation) C:\Windows\System32\RdpGroupPolicyExtension.dll
2013-06-30 22:12 - 2012-08-23 15:20 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\MsRdpWebAccess.dll
2013-06-30 22:12 - 2012-08-23 15:18 - 00037376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-06-30 22:12 - 2012-08-23 15:17 - 00018432 ____A (Microsoft Corporation) C:\Windows\System32\wksprtPS.dll
2013-06-30 22:12 - 2012-08-23 15:06 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll
2013-06-30 22:12 - 2012-08-23 14:52 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll
2013-06-30 22:12 - 2012-08-23 13:20 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe
2013-06-30 22:12 - 2012-08-23 13:15 - 00269312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-06-30 22:12 - 2012-08-23 13:14 - 00384000 ____A (Microsoft Corporation) C:\Windows\System32\wksprt.exe
2013-06-30 22:12 - 2012-08-23 13:12 - 00192000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-06-30 22:12 - 2012-08-23 12:54 - 00322560 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll
2013-06-30 22:12 - 2012-08-23 12:51 - 00228864 ____A (Microsoft Corporation) C:\Windows\System32\rdpendp_winip.dll
2013-06-30 22:12 - 2012-08-23 12:39 - 01048064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-06-30 22:12 - 2012-08-23 12:22 - 01123840 ____A (Microsoft Corporation) C:\Windows\System32\mstsc.exe
2013-06-30 22:12 - 2012-08-23 11:51 - 03174912 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2013-06-30 22:12 - 2012-08-23 10:19 - 04916224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-06-30 22:12 - 2012-08-23 10:13 - 05773824 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2013-06-30 22:09 - 2013-06-30 22:09 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-06-30 22:08 - 2012-08-24 20:13 - 00154480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2013-06-30 22:08 - 2012-08-24 20:09 - 00458712 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2013-06-30 22:08 - 2012-08-24 20:05 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-06-30 22:08 - 2012-08-24 20:03 - 01448448 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2013-06-30 22:08 - 2012-08-24 18:57 - 00247808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-06-30 22:08 - 2012-08-24 18:57 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-06-30 22:08 - 2012-08-24 18:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-06-30 22:08 - 2012-05-04 13:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2013-06-30 22:08 - 2012-05-04 11:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2013-06-23 16:59 - 2013-07-01 17:59 - 00001364 ____A C:\Windows\setupact.log
2013-06-23 16:59 - 2013-06-30 16:35 - 00028342 ____A C:\Windows\PFRO.log
2013-06-23 16:59 - 2013-06-23 16:59 - 00000000 ____A C:\Windows\setuperr.log
2013-06-23 11:25 - 2013-06-23 11:25 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-Q2-TTL.DAT
2013-06-22 15:35 - 2013-06-22 15:35 - 00000000 ____A C:\Users\*****\defogger_reenable
2013-06-22 14:37 - 2013-06-29 13:56 - 00000898 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-06-22 14:36 - 2013-06-28 19:01 - 00000000 ____D C:\Program Files (x86)\CoolLyrics
2013-06-22 14:33 - 2013-06-22 14:33 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-06-22 14:02 - 2013-06-22 14:06 - 00000000 ____D C:\ProgramData\HitmanPro
2013-06-22 13:58 - 2013-06-22 13:58 - 00000000 ___AD C:\Program Files (x86)\InboxAce_1gEI
2013-06-22 13:23 - 2013-06-29 14:23 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-TTL.DAT
2013-06-22 12:46 - 2013-07-01 18:00 - 00000480 ____A C:\Windows\Tasks\SpeedMaxPc Registration3.job
2013-06-22 12:46 - 2013-06-23 16:58 - 00000000 ____D C:\Users\*****\Desktop\SpeedMaxPc
2013-06-22 12:46 - 2013-06-22 13:02 - 00000438 ____A C:\Windows\Tasks\SpeedMaxPc Update3.job
2013-06-22 12:46 - 2013-06-22 13:02 - 00000404 ____A C:\Windows\Tasks\SpeedMaxPc.job
2013-06-22 12:46 - 2013-06-22 12:46 - 00000692 ____A C:\Users\*****\Desktop\SpeedMaxPc.lnk
2013-06-22 12:46 - 2013-06-22 12:46 - 00000000 ____D C:\Users\*****\AppData\Roaming\SpeedMaxPc
2013-06-22 12:46 - 2013-06-22 12:46 - 00000000 ____D C:\Users\*****\AppData\Roaming\DriverCure
2013-06-22 12:46 - 2013-06-22 12:46 - 00000000 ____D C:\ProgramData\SpeedMaxPc
2013-06-19 21:36 - 2013-06-19 21:36 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-19 21:23 - 2013-06-30 22:23 - 00000308 ____A C:\Windows\Tasks\DSite.job
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Users\*****\AppData\Roaming\DSite
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Users\*****\AppData\Roaming\Babylon
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Users\*****\AppData\Roaming\BabSolution
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\ProgramData\Babylon
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-19 20:53 - 2013-06-19 20:53 - 00000000 ____D C:\Users\*****\AppData\Roaming\Tific
2013-06-19 20:22 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-19 20:22 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-19 20:22 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-19 20:22 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-19 20:22 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-19 20:22 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-19 20:21 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-19 20:21 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-19 20:21 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-19 20:21 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-19 20:21 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-19 20:21 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-19 20:21 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-19 20:21 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-18 20:02 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-18 20:02 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-18 20:02 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-18 20:02 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-18 20:02 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-18 20:02 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-18 20:02 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-18 20:02 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-18 20:02 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-18 20:02 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-18 20:02 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-18 20:02 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-18 20:02 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-18 20:02 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-18 20:02 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-18 20:02 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-18 20:02 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-18 20:02 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-18 20:02 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-06-18 20:02 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-06-18 20:02 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-06-18 20:02 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-18 20:02 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-06-18 20:02 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-06-18 20:02 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-06-18 20:02 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-06-18 20:02 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-06-18 20:02 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-06-18 20:02 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-06-18 20:02 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-06-18 20:02 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-06-18 20:02 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-06-18 20:02 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll

==================== One Month Modified Files and Folders =======

2013-07-01 18:11 - 2013-07-01 18:11 - 00023556 ____A C:\Users\*****\Desktop\Addition.txt
2013-07-01 18:10 - 2013-07-01 18:10 - 01933758 ____A (Farbar) C:\Users\*****\Desktop\FRST64.exe
2013-07-01 18:10 - 2013-07-01 18:10 - 00000000 ____D C:\FRST
2013-07-01 18:07 - 2009-07-14 06:45 - 00013936 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-01 18:07 - 2009-07-14 06:45 - 00013936 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-01 18:03 - 2010-04-26 10:14 - 01186725 ____A C:\Windows\WindowsUpdate.log
2013-07-01 18:00 - 2013-06-22 12:46 - 00000480 ____A C:\Windows\Tasks\SpeedMaxPc Registration3.job
2013-07-01 18:00 - 2011-02-06 13:32 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-01 17:59 - 2013-06-23 16:59 - 00001364 ____A C:\Windows\setupact.log
2013-07-01 17:59 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-30 22:23 - 2013-06-19 21:23 - 00000308 ____A C:\Windows\Tasks\DSite.job
2013-06-30 22:20 - 2009-07-14 06:45 - 00353120 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-30 22:18 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-06-30 22:11 - 2010-05-26 02:01 - 00654166 ____A C:\Windows\System32\perfh007.dat
2013-06-30 22:11 - 2010-05-26 02:01 - 00130006 ____A C:\Windows\System32\perfc007.dat
2013-06-30 22:11 - 2009-07-14 07:13 - 01519874 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-30 22:09 - 2013-06-30 22:09 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-06-30 21:34 - 2011-02-06 13:32 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-30 16:35 - 2013-06-23 16:59 - 00028342 ____A C:\Windows\PFRO.log
2013-06-29 17:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-29 14:23 - 2013-06-22 13:23 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-TTL.DAT
2013-06-29 13:56 - 2013-06-22 14:37 - 00000898 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-06-28 19:01 - 2013-06-22 14:36 - 00000000 ____D C:\Program Files (x86)\CoolLyrics
2013-06-23 21:04 - 2013-03-23 18:04 - 00000000 ____D C:\Users\*****\AppData\Local\Microsoft Games
2013-06-23 16:59 - 2013-06-23 16:59 - 00000000 ____A C:\Windows\setuperr.log
2013-06-23 16:58 - 2013-06-22 12:46 - 00000000 ____D C:\Users\*****\Desktop\SpeedMaxPc
2013-06-23 11:25 - 2013-06-23 11:25 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-Q2-TTL.DAT
2013-06-22 22:26 - 2011-02-06 13:28 - 00000000 ____D C:\Users\*****\AppData\Local\Google
2013-06-22 16:19 - 2011-07-10 10:17 - 00001425 ____A C:\0
2013-06-22 15:35 - 2013-06-22 15:35 - 00000000 ____A C:\Users\*****\defogger_reenable
2013-06-22 15:35 - 2011-01-31 22:09 - 00000000 ____D C:\users\*****
2013-06-22 14:33 - 2013-06-22 14:33 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-06-22 14:06 - 2013-06-22 14:02 - 00000000 ____D C:\ProgramData\HitmanPro
2013-06-22 13:58 - 2013-06-22 13:58 - 00000000 ___AD C:\Program Files (x86)\InboxAce_1gEI
2013-06-22 13:02 - 2013-06-22 12:46 - 00000438 ____A C:\Windows\Tasks\SpeedMaxPc Update3.job
2013-06-22 13:02 - 2013-06-22 12:46 - 00000404 ____A C:\Windows\Tasks\SpeedMaxPc.job
2013-06-22 12:57 - 2011-04-19 21:01 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-06-22 12:57 - 2011-04-19 20:51 - 00000000 ____D C:\Windows\SysWOW64\QuickTime
2013-06-22 12:57 - 2011-04-19 20:51 - 00000000 ____D C:\ProgramData\QuickTime
2013-06-22 12:57 - 2011-02-06 14:37 - 00000000 ____D C:\ProgramData\Norton
2013-06-22 12:57 - 2010-04-26 10:43 - 00000000 ____D C:\ProgramData\Partner
2013-06-22 12:57 - 2009-08-02 04:27 - 00000000 ____D C:\Windows\Panther
2013-06-22 12:57 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default
2013-06-22 12:46 - 2013-06-22 12:46 - 00000692 ____A C:\Users\*****\Desktop\SpeedMaxPc.lnk
2013-06-22 12:46 - 2013-06-22 12:46 - 00000000 ____D C:\Users\*****\AppData\Roaming\SpeedMaxPc
2013-06-22 12:46 - 2013-06-22 12:46 - 00000000 ____D C:\Users\*****\AppData\Roaming\DriverCure
2013-06-22 12:46 - 2013-06-22 12:46 - 00000000 ____D C:\ProgramData\SpeedMaxPc
2013-06-19 21:36 - 2013-06-19 21:36 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Users\*****\AppData\Roaming\DSite
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Users\*****\AppData\Roaming\Babylon
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Users\*****\AppData\Roaming\BabSolution
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\ProgramData\Babylon
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-19 20:53 - 2013-06-19 20:53 - 00000000 ____D C:\Users\*****\AppData\Roaming\Tific
2013-06-08 16:08 - 2013-06-19 20:21 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-19 20:21 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-19 20:21 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-19 20:21 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-19 20:21 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-19 20:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-19 20:21 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-19 20:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-02 17:11 - 2013-03-16 18:56 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe

Files to move or delete:
====================
C:\ProgramData\FullRemove.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-29 16:33

==================== End Of Log ============================

--- --- ---

--- --- ---


und die Addition:

Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-06-2013 03
Ran by ***** at 2013-07-01 18:12:09
Running from C:\Users\*****\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

 Update for Microsoft Office 2007 (KB2508958) (x32)
7-Zip 4.65 (x32)
Adobe Flash Player ActiveX (x32 Version: 9.0.124.0)
Adobe Reader 9.1 - Deutsch (x32 Version: 9.1.0)
Alice Greenfingers (x32)
AnyPC Client (x32 Version: 1.0.0.25)
AOL Mail and AIM Gadget (x32 Version: 1.0.0)
AOL Meine Fotos Bildschirmschoner (x32)
Atheros Client Installation Program (x32 Version: 1.0.2.1119)
BatteryLifeExtender (x32 Version: 1.0.1)
Bonbon Quest (x32)
Cake Mania (x32)
Compatibility Pack für 2007 Office System (x32 Version: 12.0.6612.1000)
CyberLink DVD Suite (x32 Version: 6.0.2806)
CyberLink LabelPrint (x32 Version: 2.5.1916)
CyberLink Power2Go (x32 Version: 6.0.3108a)
CyberLink PowerDirector (x32 Version: 7.0.3213)
CyberLink PowerDVD 8 (x32 Version: 8.0.2815b)
CyberLink PowerProducer (x32 Version: 5.0.1.1812)
CyberLink YouCam (x32 Version: 2.0.3625)
Daycare Nightmare (x32)
Easy Display Manager (x32 Version: 3.0)
Easy Network Manager (x32 Version: 4.2.8)
Easy SpeedUp Manager (x32 Version: 3.0.0.5)
EasyBatteryManager (x32 Version: 4.0.0.3)
Flip Words (x32)
Galapago (x32)
Game Pack (x32 Version: 6.3.1.1)
Gem Shop (x32)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0)
Google Toolbar for Internet Explorer (x32 Version: 7.5.4209.2358)
Google Update Helper (x32 Version: 1.3.21.145)
Insaniquarium Deluxe (x32)
Intel(R) Rapid Storage Technology (x32 Version: 9.5.4.1001)
Intel(R) Turbo Boost Technology Driver (x32 Version: 01.01.01.1007)
Junk Mail filter update (x32 Version: 14.0.8089.726)
Learn2 Player (Uninstall Only) (x32)
Mahjong Escape Ancient China (x32)
Marvell Miniport Driver (x32 Version: 11.22.3.3)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Choice Guard (x32 Version: 2.0.48.0)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint Viewer 2007 (German) (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Suite Activation Assistant (x32 Version: 2.9)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Works (x32 Version: 9.7.0621)
Mobile Partner (x32 Version: 16.002.03.01.40)
MSVCRT (x32 Version: 14.0.1468.721)
Norton 360 (x32 Version: 5.2.2.3)
NVIDIA Drivers (Version: 1.4)
NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0)
NVIDIA Install Application (Version: 2.1002.109.718)
QuickTime (x32)
RealPlayer Basic (x32)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6003)
REALTEK Wireless LAN Software (x32 Version: 0133.09.1202)
Samsung Recovery Solution 4 (x32 Version: 4.0.0.6)
Samsung R-Series (x32 Version: 1.0)
Samsung Support Center (x32 Version: 1.1.0)
Samsung Update Plus (x32 Version: 2.0)
Slingo (x32)
SpeedMaxPc (x32 Version: 3.1.6.0)
Synaptics Pointing Device Driver (Version: 15.0.10.0)
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Update for Microsoft Office Word 2007 (KB974631) (x32)
Update for Zip Opener (HKCU)
Update für Microsoft Office Excel 2007 Help (KB963678) (x32)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32)
Update für Microsoft Office Word 2007 Help (KB963665) (x32)
User Guide (x32 Version: 1.0)
Viewpoint Media Player (x32)
Windows Live Anmelde-Assistent (x32 Version: 5.000.818.5)
Windows Live Call (x32 Version: 14.0.8064.0206)
Windows Live Communications Platform (x32 Version: 14.0.8064.206)
Windows Live Essentials (x32 Version: 14.0.8089.0726)
Windows Live Essentials (x32 Version: 14.0.8089.726)
Windows Live Family Safety (Version: 14.0.8093.805)
Windows Live Fotogalerie (x32 Version: 14.0.8081.709)
Windows Live Mail (x32 Version: 14.0.8089.0726)
Windows Live Messenger (x32 Version: 14.0.8089.0726)
Windows Live Movie Maker (x32 Version: 14.0.8091.0730)
Windows Live Sync (x32 Version: 14.0.8089.726)
Windows Live Writer (x32 Version: 14.0.8089.0726)
Windows Live-Uploadtool (x32 Version: 14.0.8014.1029)

==================== Restore Points  =========================

22-06-2013 10:56:10 SpeedMaxPc Backup
22-06-2013 15:33:46 SpeedMaxPc Backup
23-06-2013 14:57:49 SpeedMaxPc Backup
23-06-2013 19:41:06 Windows Update
30-06-2013 17:49:58 Norton 360 Registry Clean
30-06-2013 20:08:40 Windows Update

==================== Scheduled Tasks (whitelisted) =============

Task: {0E2EFDA6-77DB-4459-825E-C112DA8FBA09} - System32\Tasks\SpeedMaxPc => C:\Users\*****\Desktop\SpeedMaxPc\SpeedMaxPc.exe [2013-03-13] (SpeedMaxPc)
Task: {19CC413D-BC66-4EB2-BEB7-9DEF79BCE287} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2009-11-04] (Samsung Electronics Co., Ltd.)
Task: {1BE6628C-9EB4-4414-A24E-FFB6C616B262} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {1E9629D8-D3B9-4213-8EAA-ED42CE39402F} - System32\Tasks\Symantec\Norton Error Analyzer 5.2.2.3 => C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\SymErr.exe [2012-06-08] (Symantec Corporation)
Task: {234931D2-633B-4BAC-A805-1F0187FF5EC4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-06] (Google Inc.)
Task: {295E8677-BAC1-49DA-899C-B6BE51ABC077} - System32\Tasks\QtraxPlayer => C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe [2013-01-24] (Microsoft Corporation)
Task: {2CAC840C-88E6-4B9D-A96E-01D36193C02F} - System32\Tasks\Symantec\Norton Error Processor 5.2.2.3 => C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\SymErr.exe [2012-06-08] (Symantec Corporation)
Task: {34EF141E-7D50-400C-9A5C-8DACFAA75A20} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2009-11-19] (Samsung Electronics. Co. Ltd.)
Task: {434576E0-E121-4132-87A1-46AB21DB0D49} - System32\Tasks\APSchedulerC => C:\Program Files (x86)\AnyPC Client\APLanMgrC.exe [2009-11-20] (DoctorSoft)
Task: {56E25516-EAC3-40A1-AECD-57A2DEBFB56B} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation)
Task: {570D23AB-AB48-4C96-9D64-55DE4860E855} - System32\Tasks\SpeedMaxPc Update3 => C:\Program Files (x86)\Common Files\SpeedMaxPc\UUS3\Update3.exe [2013-03-13] (SpeedMaxPc)
Task: {661C0A17-A793-42E0-B66B-EE69EEDF5000} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-06] (Google Inc.)
Task: {796AD053-1F9C-4CDD-8061-EA9ABB63BDB2} - System32\Tasks\EasyBatteryManager => %ProgramFiles(x86)%\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe No File
Task: {7DC0065F-DD26-43B8-BE70-BD62D4682A57} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe No File
Task: {7F8A1AA7-AEA4-4B30-AB2F-0E2596B0B401} - System32\Tasks\EPUpdater => C:\Users\HEGGEN~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [2013-06-06] ()
Task: {80003C4A-C600-433B-B5C3-1A328A876DB3} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation)
Task: {8067921D-B86A-4C86-8F12-CD0EE2AAD107} - System32\Tasks\SamsungSupportCenter => %programfiles(x86)%\Samsung\Samsung Support Center\SSCKbdHk.exe No File
Task: {81DC64DF-1CB2-4FC8-BBC9-D24EEF9EBB40} - System32\Tasks\DSite => C:\Users\HEGGEN~1\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE [2013-06-19] ()
Task: {84C8830E-14C6-4DA2-A462-03A034B1CABF} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1087647220-443236407-352421928-1000
Task: {86BEEE8B-7D99-4E9F-955B-04A8AAF89D08} - System32\Tasks\0 => C:\program files\internet explorer\iexplore.exe [2013-05-17] (Microsoft Corporation)
Task: {88534FDD-00FB-495C-9054-D382C63E3662} - System32\Tasks\4786 => C:\Windows\System32\wscript.exe [2009-07-14] (Microsoft Corporation)
Task: {8E70D459-DA4A-4256-80DC-C8F337232F33} - System32\Tasks\{1D8CACDD-252D-45EC-B902-1D5300A4CB1C} => C:\Program Files (x86)\AOL 9.0\aol.exe No File
Task: {8FB535E4-6337-4B24-9FE6-CE98E8A06CDA} - System32\Tasks\{E2016C3B-ABA0-44B7-9197-B9E765D93E72} => C:\Program Files (x86)\AOL 9.0 VR\aol.exe No File
Task: {92771263-ACB9-4FDA-B3FC-EE3381DA704D} - System32\Tasks\{E89D77F2-DAF5-43DA-B03B-2531B6078BFF} => C:\Program Files (x86)\AOL 9.0 VR\aol.exe No File
Task: {929C129C-8C60-4AC3-A1DD-4DD5A6389B51} - System32\Tasks\SpeedMaxPc Registration3 => C:\windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation)
Task: {C0B10714-1B48-4DEB-85AF-E08418E4D64E} - System32\Tasks\{33E221D8-0BF4-4AB5-94C3-12AA6EAEF43E} => C:\Program Files (x86)\AOL 9.0\aol.exe No File
Task: {D1E74A13-3F54-49E2-8F74-EBF359044531} - System32\Tasks\advSRS4 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2010-01-19] (SEC)
Task: {DC072DCE-F82C-4DCA-AF06-3FCD0C66318C} - System32\Tasks\{133D515A-7053-441E-AB7B-7644AB9BCEBC} => C:\Program Files (x86)\AOL 9.0 VR\aol.exe No File
Task: {DFBE31C6-8FDD-4FF8-930D-7184586D5B35} - System32\Tasks\EasySpeedUpManager => %programfiles(x86)%\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe No File
Task: C:\windows\Tasks\DSite.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\SpeedMaxPc Registration3.job => C:\windows\system32\rundll32.exe
Task: C:\windows\Tasks\SpeedMaxPc Update3.job => C:\Program Files (x86)\Common Files\SpeedMaxPc\UUS3\Update3.exe
Task: C:\windows\Tasks\SpeedMaxPc.job => C:\Users\*****\Desktop\SpeedMaxPc\SpeedMaxPc.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/30/2013 03:27:58 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/29/2013 04:34:39 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile  WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (06/27/2013 07:17:03 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/25/2013 08:13:40 PM) (Source: Iminent) (User: )
Description: Unexpected exception.

System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.NullReferenceException: Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt.
  bei Iminent.Mediator.Server.ApplicationService.<>c__DisplayClassa.<WarmUp>b__9(Composite composite)
  --- Ende der internen Ausnahmestapelüberwachung ---
  bei System.RuntimeMethodHandle._InvokeMethodFast(IRuntimeMethodInfo method, Object target, Object[] arguments, SignatureStruct& sig, MethodAttributes methodAttributes, RuntimeType typeOwner)
  bei System.RuntimeMethodHandle.InvokeMethodFast(IRuntimeMethodInfo method, Object target, Object[] arguments, Signature sig, MethodAttributes methodAttributes, RuntimeType typeOwner)
  bei System.Reflection.RuntimeMethodInfo.Invoke(Object obj, BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture, Boolean skipVisibilityChecks)
  bei System.Delegate.DynamicInvokeImpl(Object[] args)
  bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback, Object args, Int32 numArgs)
  bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(Object source, Delegate method, Object args, Int32 numArgs, Delegate catchHandler)

Error: (06/24/2013 06:06:02 AM) (Source: Application Hang) (User: )
Description: Programm IEXPLORE.EXE, Version 10.0.9200.16611 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 3c0

Startzeit: 01ce709011ce30da

Endzeit: 32

Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Berichts-ID:

Error: (06/23/2013 10:23:59 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/23/2013 10:19:56 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/23/2013 10:02:42 PM) (Source: Application Hang) (User: )
Description: Programm IEXPLORE.EXE, Version 10.0.9200.16611 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1218

Startzeit: 01ce704c8b0ba9b4

Endzeit: 15

Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Berichts-ID:

Error: (06/23/2013 05:01:44 PM) (Source: Windows Search Service) (User: )
Description: Fehler beim Erstellen des neuen Suchindex durch Windows Search. Interner Fehler <4, 0x8004117f, Fehler beim Hinzufügen des Projekts: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects>.

Error: (06/23/2013 05:01:44 PM) (Source: Windows Search Service) (User: )
Description: Der Jet-Eigenschaftenspeicher kann von Windows Search nicht geöffnet werden.


Details:
        0x%08x (0x8004117f - Der Inhaltsindexserver kann wegen eines Datenbankfehlers keine Daten aktualisieren oder auf sie zugreifen. Beenden Sie den Suchdienst, und starten Sie ihn erneut. Wenn das Problem weiterhin besteht, setzen Sie den Inhaltsindex zurück, und crawlen Sie ihn erneut. In manchen Fällen muss der Inhaltsindex möglicherweise gelöscht und erneut erstellt werden.  (HRESULT : 0x8004117f))


System errors:
=============
Error: (07/01/2013 05:59:49 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (07/01/2013 05:59:49 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "ASCTRM" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1275

Error: (07/01/2013 05:59:49 PM) (Source: Application Popup) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\ASCTRM.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.

Error: (07/01/2013 06:02:44 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (07/01/2013 06:02:44 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "ASCTRM" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1275

Error: (07/01/2013 06:02:44 AM) (Source: Application Popup) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\ASCTRM.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.

Error: (06/30/2013 10:20:45 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (06/30/2013 10:20:45 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "ASCTRM" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1275

Error: (06/30/2013 10:20:45 PM) (Source: Application Popup) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\ASCTRM.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.

Error: (06/30/2013 04:36:17 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Percentage of memory in use: 39%
Total physical RAM: 3956.55 MB
Available physical RAM: 2375.66 MB
Total Pagefile: 7911.29 MB
Available Pagefile: 6096.64 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:270.4 GB) (Free:227.66 GB) NTFS (Disk=0 Partition=3)
Drive d: () (Fixed) (Total:180.27 GB) (Free:180.17 GB) NTFS (Disk=0 Partition=4)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: C760B073)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=270 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=180 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Danke und Grüße

Sabine99

schrauber 01.07.2013 19:13

Leider doch.

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


Sabine99 01.07.2013 19:47

Hi Schrauber,
und hier die gewünschten Files:

log adwear cleaner:

Code:

# AdwCleaner v2.303 - Datei am 01/07/2013 um 20:24:39 erstellt
# Aktualisiert am 08/06/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : ***** - ROSEN15
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\*****\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\windows\Tasks\DSite.job
Ordner Gelöscht : C:\Program Files (x86)\Common Files\SpeedMaxPc
Ordner Gelöscht : C:\Program Files (x86)\Viewpoint
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\SpeedMaxPc
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\ProgramData\Viewpoint
Ordner Gelöscht : C:\Users\*****\AppData\LocalLow\Toolbar4
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\DriverCure
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\DSite
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedMaxPc
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\SpeedMaxPc
Ordner Gelöscht : C:\Users\*****\Desktop\SpeedMaxPc

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\BabSolution
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\SpeedMaxPC
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4B5C-9287-DA72D38F4FE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\Software\Iminent
Schlüssel Gelöscht : HKLM\Software\MetaStream
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
Schlüssel Gelöscht : HKLM\Software\SpeedMaxPC
Schlüssel Gelöscht : HKLM\Software\Viewpoint
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Tarma Installer
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]

***** [Internet Browser] *****

-\\ Internet Explorer v10.0.9200.16611

Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://home.mywebsearch.com/index.jhtml?n=77DE8857&p2=^ZO^xdm071^YY^de&ptb=D97F0AC6-4413-4C40-871C-2B11E34E28B4&si=EL_UT_GER_11 --> hxxp://www.google.com

*************************

AdwCleaner[S1].txt - [13458 octets] - [01/07/2013 20:24:39]

########## EOF - C:\AdwCleaner[S1].txt - [13519 octets] ##########

und das JRT:

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Home Premium x64
Ran by ***** on 01.07.2013 at 20:34:31,06
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{84dc9f6c-c9a5-4c64-ab67-d6ef60f963c8}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{84dc9f6c-c9a5-4c64-ab67-d6ef60f963c8}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Users\*****\appdata\local\iac"
Successfully deleted: [Folder] "C:\Users\*****\appdata\locallow\iac"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.07.2013 at 20:38:26,88
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Bis bald

Sabine99

schrauber 01.07.2013 19:50

Downloade dir bitte Rogue Killer von hier.
  • Speichere das Tool auf deinem Desktop !
  • Schließe alle laufenden Programme.
  • Starte die RogueKiller.exe
  • Warte bis Prescan abgeschlossen erscheint und klicke dann auf Scannen.
  • Wenn der Scan beendet wurde, klicke auf Bericht und poste diesen hier.
  • Du findest die Logdatei RKreport[1].txt auch auf deinem Desktop.
http://i121.photobucket.com/albums/o...iller/TRK2.png


Gleich danach, wenn Roguekiller gescannt hat, auf Löschen klicken, beide Logfiles und ein frisches FRST log posten :)

Sabine99 01.07.2013 20:15

Hi Schrauber,

das geht heut ja richtig schnell

1. Logfile:

Code:

RogueKiller V8.6.1 [Jun 17 2013] durch Tigzy
mail: tigzyRK<at>gmail<dot>com

mail : tigzyRK<at>gmail<dot>com
Kommentare : hxxp://www.geekstogo.com/forum/files/file/413-roguekiller/
Webseite : hxxp://tigzy.geekstogo.com/roguekiller.php
Blog : hxxp://tigzyrk.blogspot.com/

Betriebssystem : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Gestartet in : Normaler Modus
Benutzer : ***** [Admin Rechte]
Funktion : Scannen -- Datum : 07/01/2013 21:01:44
| ARK || FAK || MBR |

¤¤¤ Böswillige Prozesse : 0 ¤¤¤

¤¤¤ Registry-Einträge : 7 ¤¤¤
[DNS] HKLM\[...]\CCSet\[...]\{9737BF33-AC5F-4930-BBC0-1A3182B820F8} : NameServer (193.189.244.225 193.189.244.206) -> GEFUNDEN
[DNS] HKLM\[...]\CS001\[...]\{9737BF33-AC5F-4930-BBC0-1A3182B820F8} : NameServer (193.189.244.225 193.189.244.206) -> GEFUNDEN
[DNS] HKLM\[...]\CS002\[...]\{9737BF33-AC5F-4930-BBC0-1A3182B820F8} : NameServer (193.189.244.225 193.189.244.206) -> GEFUNDEN
[HJ POL] HKCU\[...]\System : DisableTaskMgr (0) -> GEFUNDEN
[HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> GEFUNDEN
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> GEFUNDEN
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> GEFUNDEN

¤¤¤ Geplante Tasks : 4 ¤¤¤
[V1][SUSP PATH] SpeedMaxPc.job : C:\Users\*****\Desktop\SpeedMaxPc\SpeedMaxPc.exe - -scan [x] -> GEFUNDEN
[V2][ROGUE ST] 4786 : wscript.exe - C:\Users\HEGGEN~1\AppData\Local\Temp\launchie.vbs //B -> GEFUNDEN
[V2][SUSP PATH] EPUpdater : C:\Users\HEGGEN~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [x] -> GEFUNDEN
[V2][SUSP PATH] SpeedMaxPc : C:\Users\*****\Desktop\SpeedMaxPc\SpeedMaxPc.exe - -scan [x] -> GEFUNDEN

¤¤¤ Autostart-Einträge : 0 ¤¤¤

¤¤¤ Web-Browsern : 0 ¤¤¤

¤¤¤ Bestimmte Dateien / Ordner: ¤¤¤

¤¤¤ Treiber : [NICHT GELADEN] ¤¤¤

¤¤¤ Externe Hives: ¤¤¤

¤¤¤ Infektion :  ¤¤¤

¤¤¤ Hosts-Datei: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR überprüfen: ¤¤¤

+++++ PhysicalDrive0: Hitachi HTS545050B9A300 +++++
--- User ---
[MBR] 5f376de65b3a95857c1f1c50bcb042ef
[BSP] 1125a08c4893addf1067300760f1ca47 : KIWI Image system MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 15360 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 31459328 | Size: 100 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 31664128 | Size: 276885 Mo
3 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 598724608 | Size: 184593 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Abgeschlossen : << RKreport[0]_S_07012013_210144.txt >>
RKreport[0]_S_07012013_205820.txt

2.Logfile (vor dem löschen)

Code:

RogueKiller V8.6.1 [Jun 17 2013] durch Tigzy
mail: tigzyRK<at>gmail<dot>com

mail : tigzyRK<at>gmail<dot>com
Kommentare : hxxp://www.geekstogo.com/forum/files/file/413-roguekiller/
Webseite : hxxp://tigzy.geekstogo.com/roguekiller.php
Blog : hxxp://tigzyrk.blogspot.com/

Betriebssystem : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Gestartet in : Normaler Modus
Benutzer : ***** [Admin Rechte]
Funktion : Scannen -- Datum : 07/01/2013 21:01:44
| ARK || FAK || MBR |

¤¤¤ Böswillige Prozesse : 0 ¤¤¤

¤¤¤ Registry-Einträge : 7 ¤¤¤
[DNS] HKLM\[...]\CCSet\[...]\{9737BF33-AC5F-4930-BBC0-1A3182B820F8} : NameServer (193.189.244.225 193.189.244.206) -> GEFUNDEN
[DNS] HKLM\[...]\CS001\[...]\{9737BF33-AC5F-4930-BBC0-1A3182B820F8} : NameServer (193.189.244.225 193.189.244.206) -> GEFUNDEN
[DNS] HKLM\[...]\CS002\[...]\{9737BF33-AC5F-4930-BBC0-1A3182B820F8} : NameServer (193.189.244.225 193.189.244.206) -> GEFUNDEN
[HJ POL] HKCU\[...]\System : DisableTaskMgr (0) -> GEFUNDEN
[HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> GEFUNDEN
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> GEFUNDEN
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> GEFUNDEN

¤¤¤ Geplante Tasks : 4 ¤¤¤
[V1][SUSP PATH] SpeedMaxPc.job : C:\Users\*****\Desktop\SpeedMaxPc\SpeedMaxPc.exe - -scan [x] -> GEFUNDEN
[V2][ROGUE ST] 4786 : wscript.exe - C:\Users\HEGGEN~1\AppData\Local\Temp\launchie.vbs //B -> GEFUNDEN
[V2][SUSP PATH] EPUpdater : C:\Users\HEGGEN~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [x] -> GEFUNDEN
[V2][SUSP PATH] SpeedMaxPc : C:\Users\*****\Desktop\SpeedMaxPc\SpeedMaxPc.exe - -scan [x] -> GEFUNDEN

¤¤¤ Autostart-Einträge : 0 ¤¤¤

¤¤¤ Web-Browsern : 0 ¤¤¤

¤¤¤ Bestimmte Dateien / Ordner: ¤¤¤

¤¤¤ Treiber : [NICHT GELADEN] ¤¤¤

¤¤¤ Externe Hives: ¤¤¤

¤¤¤ Infektion :  ¤¤¤

¤¤¤ Hosts-Datei: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR überprüfen: ¤¤¤

+++++ PhysicalDrive0: Hitachi HTS545050B9A300 +++++
--- User ---
[MBR] 5f376de65b3a95857c1f1c50bcb042ef
[BSP] 1125a08c4893addf1067300760f1ca47 : KIWI Image system MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 15360 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 31459328 | Size: 100 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 31664128 | Size: 276885 Mo
3 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 598724608 | Size: 184593 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Abgeschlossen : << RKreport[0]_S_07012013_210144.txt >>
RKreport[0]_S_07012013_205820.txt

und FRST:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-06-2013 03
Ran by ***** (administrator) on 01-07-2013 21:03:09
Running from C:\Users\*****\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
() C:\windows\SysWOW64\Rezip.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
(Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
(Microsoft Corporation) C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
(AOL LLC) c:\program files (x86)\aol\aol toolbar 4.0\AolTbServer.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Microsoft Corporation) C:\windows\SysWOW64\notepad.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [9644576 2009-12-15] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2074408 2010-02-26] (Synaptics Incorporated)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup [16413288 2010-02-10] (NVIDIA Corporation)
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-04-26] (Google Inc.)
MountPoints2: {3d82f461-6aa4-11e0-be41-00038a000015} - F:\AutoRun.exe
MountPoints2: {3d82f46f-6aa4-11e0-be41-00038a000015} - F:\AutoRun.exe
HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-06-03] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePDRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [91432 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe" [50472 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0" [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2009-07-21] (CyberLink Corp.)
HKLM-x32\...\Run: [APLangApp] "C:\Program Files (x86)\AnyPC Client\APLangApp.exe" [13312 2009-11-20] (DoctorSoft)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime [98304 2011-04-19] (Apple Computer, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
URLSearchHook: (No Name) - {1CFFA392-0898-4b1c-89D1-6E98F9D8EF78} -  No File
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} -  No File
BHO-x32: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coIEPlg.dll (Symantec Corporation)
BHO-x32: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files (x86)\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKCU - No Name - {DE9C389F-3316-41A7-809B-AA305ED9D922} -  No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9737BF33-AC5F-4930-BBC0-1A3182B820F8}: [NameServer]193.189.244.225 193.189.244.206

==================== Services (Whitelisted) =================

R2 N360; C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe [130008 2011-04-17] (Symantec Corporation)
R2 Rezip; C:\windows\SysWOW64\Rezip.exe [311296 2009-03-05] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-07] ()
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [x]

==================== Drivers (Whitelisted) ====================

R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\BASHDefs\20130620.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\BASHDefs\20130620.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
R3 CryptOSD; C:\Windows\System32\DRIVERS\CryptOSD.sys [431488 2009-06-25] (Phoenix Technologies)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-15] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-15] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-03-15] (Symantec Corporation)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\IPSDefs\20130628.001\IDSvia64.sys [513184 2013-06-15] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\IPSDefs\20130628.001\IDSvia64.sys [513184 2013-06-15] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130701.001\ENG64.SYS [126040 2013-06-23] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130701.001\ENG64.SYS [126040 2013-06-23] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130701.001\EX64.SYS [2098776 2013-06-23] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130701.001\EX64.SYS [2098776 2013-06-23] (Symantec Corporation)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-06-24] (Windows (R) 2003 DDK 3790 provider)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-06-24] (Windows (R) 2003 DDK 3790 provider)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\0502020.003\SRTSP64.SYS [744568 2011-03-31] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\0502020.003\SRTSPX64.SYS [40568 2011-03-31] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\0502020.003\SYMDS64.SYS [450680 2011-01-27] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\0502020.003\SYMEFA64.SYS [912504 2011-03-15] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2011-05-14] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\0502020.003\Ironx64.SYS [171128 2010-11-16] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\0502020.003\SYMNETS.SYS [386168 2011-04-21] (Symantec Corporation)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
S2 ASCTRM; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-01 21:02 - 2013-07-01 21:02 - 00002887 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208_3.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002887 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002746 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_210144_2.txt
2013-07-01 21:01 - 2013-07-01 21:01 - 00002746 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_210144.txt
2013-07-01 20:59 - 2013-07-01 20:59 - 00002689 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_205820_1.txt
2013-07-01 20:58 - 2013-07-01 20:58 - 00002713 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_205820.txt
2013-07-01 20:56 - 2013-07-01 21:02 - 00000000 ____D C:\Users\*****\Desktop\RK_Quarantine
2013-07-01 20:55 - 2013-07-01 20:55 - 00909312 ____A C:\Users\*****\Downloads\RogueKiller_8.6.1.exe
2013-07-01 20:55 - 2013-07-01 20:55 - 00909312 ____A C:\Users\*****\Desktop\RogueKiller_8.6.1.exe
2013-07-01 20:39 - 2013-07-01 20:39 - 00001057 ____A C:\Users\*****\Desktop\JRT1.txt
2013-07-01 20:38 - 2013-07-01 20:38 - 00001081 ____A C:\Users\*****\Desktop\JRT.txt
2013-07-01 20:34 - 2013-07-01 20:34 - 00000000 ____D C:\Windows\ERUNT
2013-07-01 20:32 - 2013-07-01 20:33 - 00000000 ____D C:\JRT
2013-07-01 20:32 - 2013-07-01 20:32 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-07-01 20:29 - 2013-07-01 20:29 - 00013413 ____A C:\Users\*****\Desktop\AdwCleaner[S1].txt
2013-07-01 20:24 - 2013-07-01 20:24 - 00013493 ____A C:\AdwCleaner[S1].txt
2013-07-01 20:23 - 2013-07-01 20:23 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-07-01 18:11 - 2013-07-01 18:12 - 00023557 ____A C:\Users\*****\Desktop\Addition.txt
2013-07-01 18:10 - 2013-07-01 18:10 - 01933758 ____A (Farbar) C:\Users\*****\Desktop\FRST64.exe
2013-07-01 18:10 - 2013-07-01 18:10 - 00000000 ____D C:\FRST
2013-06-30 22:12 - 2012-08-23 16:13 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\rdpudd.dll
2013-06-30 22:12 - 2012-08-23 16:10 - 00019456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys
2013-06-30 22:12 - 2012-08-23 16:07 - 00057856 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys
2013-06-30 22:12 - 2012-08-23 15:47 - 00046592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-06-30 22:12 - 2012-08-23 15:46 - 00016896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-06-30 22:12 - 2012-08-23 15:41 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
2013-06-30 22:12 - 2012-08-23 15:40 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2013-06-30 22:12 - 2012-08-23 15:24 - 00015360 ____A (Microsoft Corporation) C:\Windows\System32\RdpGroupPolicyExtension.dll
2013-06-30 22:12 - 2012-08-23 15:20 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\MsRdpWebAccess.dll
2013-06-30 22:12 - 2012-08-23 15:18 - 00037376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-06-30 22:12 - 2012-08-23 15:17 - 00018432 ____A (Microsoft Corporation) C:\Windows\System32\wksprtPS.dll
2013-06-30 22:12 - 2012-08-23 15:06 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll
2013-06-30 22:12 - 2012-08-23 14:52 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll
2013-06-30 22:12 - 2012-08-23 13:20 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe
2013-06-30 22:12 - 2012-08-23 13:15 - 00269312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-06-30 22:12 - 2012-08-23 13:14 - 00384000 ____A (Microsoft Corporation) C:\Windows\System32\wksprt.exe
2013-06-30 22:12 - 2012-08-23 13:12 - 00192000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-06-30 22:12 - 2012-08-23 12:54 - 00322560 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll
2013-06-30 22:12 - 2012-08-23 12:51 - 00228864 ____A (Microsoft Corporation) C:\Windows\System32\rdpendp_winip.dll
2013-06-30 22:12 - 2012-08-23 12:39 - 01048064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-06-30 22:12 - 2012-08-23 12:22 - 01123840 ____A (Microsoft Corporation) C:\Windows\System32\mstsc.exe
2013-06-30 22:12 - 2012-08-23 11:51 - 03174912 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2013-06-30 22:12 - 2012-08-23 10:19 - 04916224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-06-30 22:12 - 2012-08-23 10:13 - 05773824 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2013-06-30 22:09 - 2013-06-30 22:09 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-06-30 22:08 - 2012-08-24 20:13 - 00154480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2013-06-30 22:08 - 2012-08-24 20:09 - 00458712 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2013-06-30 22:08 - 2012-08-24 20:05 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-06-30 22:08 - 2012-08-24 20:03 - 01448448 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2013-06-30 22:08 - 2012-08-24 18:57 - 00247808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-06-30 22:08 - 2012-08-24 18:57 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-06-30 22:08 - 2012-08-24 18:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-06-30 22:08 - 2012-05-04 13:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2013-06-30 22:08 - 2012-05-04 11:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2013-06-23 16:59 - 2013-07-01 20:25 - 00001420 ____A C:\Windows\setupact.log
2013-06-23 16:59 - 2013-06-30 16:35 - 00028342 ____A C:\Windows\PFRO.log
2013-06-23 16:59 - 2013-06-23 16:59 - 00000000 ____A C:\Windows\setuperr.log
2013-06-23 11:25 - 2013-06-23 11:25 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-Q2-TTL.DAT
2013-06-22 15:35 - 2013-06-22 15:35 - 00000000 ____A C:\Users\*****\defogger_reenable
2013-06-22 14:37 - 2013-06-29 13:56 - 00000898 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-06-22 14:36 - 2013-06-28 19:01 - 00000000 ____D C:\Program Files (x86)\CoolLyrics
2013-06-22 14:33 - 2013-06-22 14:33 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-06-22 14:02 - 2013-06-22 14:06 - 00000000 ____D C:\ProgramData\HitmanPro
2013-06-22 13:58 - 2013-06-22 13:58 - 00000000 ___AD C:\Program Files (x86)\InboxAce_1gEI
2013-06-22 13:23 - 2013-07-01 18:38 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-TTL.DAT
2013-06-22 12:46 - 2013-07-01 18:00 - 00000480 ____A C:\Windows\Tasks\SpeedMaxPc Registration3.job
2013-06-22 12:46 - 2013-06-22 13:02 - 00000438 ____A C:\Windows\Tasks\SpeedMaxPc Update3.job
2013-06-22 12:46 - 2013-06-22 12:46 - 00000692 ____A C:\Users\*****\Desktop\SpeedMaxPc.lnk
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-19 20:53 - 2013-06-19 20:53 - 00000000 ____D C:\Users\*****\AppData\Roaming\Tific
2013-06-19 20:22 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-19 20:22 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-19 20:22 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-19 20:22 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-19 20:22 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-19 20:22 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-19 20:21 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-19 20:21 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-19 20:21 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-19 20:21 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-19 20:21 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-19 20:21 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-19 20:21 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-19 20:21 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-18 20:02 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-18 20:02 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-18 20:02 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-18 20:02 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-18 20:02 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-18 20:02 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-18 20:02 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-18 20:02 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-18 20:02 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-18 20:02 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-18 20:02 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-18 20:02 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-18 20:02 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-18 20:02 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-18 20:02 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-18 20:02 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-18 20:02 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-18 20:02 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-18 20:02 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-06-18 20:02 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-06-18 20:02 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-06-18 20:02 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-18 20:02 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-06-18 20:02 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-06-18 20:02 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-06-18 20:02 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-06-18 20:02 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-06-18 20:02 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-06-18 20:02 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-06-18 20:02 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-06-18 20:02 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-06-18 20:02 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-06-18 20:02 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll

==================== One Month Modified Files and Folders =======

2013-07-01 21:02 - 2013-07-01 21:02 - 00002887 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208_3.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002887 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002746 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_210144_2.txt
2013-07-01 21:02 - 2013-07-01 20:56 - 00000000 ____D C:\Users\*****\Desktop\RK_Quarantine
2013-07-01 21:01 - 2013-07-01 21:01 - 00002746 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_210144.txt
2013-07-01 20:59 - 2013-07-01 20:59 - 00002689 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_205820_1.txt
2013-07-01 20:58 - 2013-07-01 20:58 - 00002713 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_205820.txt
2013-07-01 20:55 - 2013-07-01 20:55 - 00909312 ____A C:\Users\*****\Downloads\RogueKiller_8.6.1.exe
2013-07-01 20:55 - 2013-07-01 20:55 - 00909312 ____A C:\Users\*****\Desktop\RogueKiller_8.6.1.exe
2013-07-01 20:39 - 2013-07-01 20:39 - 00001057 ____A C:\Users\*****\Desktop\JRT1.txt
2013-07-01 20:38 - 2013-07-01 20:38 - 00001081 ____A C:\Users\*****\Desktop\JRT.txt
2013-07-01 20:34 - 2013-07-01 20:34 - 00000000 ____D C:\Windows\ERUNT
2013-07-01 20:33 - 2013-07-01 20:32 - 00000000 ____D C:\JRT
2013-07-01 20:33 - 2011-02-06 13:32 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-01 20:33 - 2009-07-14 06:45 - 00013936 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-01 20:33 - 2009-07-14 06:45 - 00013936 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-01 20:32 - 2013-07-01 20:32 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-07-01 20:29 - 2013-07-01 20:29 - 00013413 ____A C:\Users\*****\Desktop\AdwCleaner[S1].txt
2013-07-01 20:26 - 2011-02-06 13:32 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-01 20:26 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-01 20:25 - 2013-06-23 16:59 - 00001420 ____A C:\Windows\setupact.log
2013-07-01 20:25 - 2010-04-26 10:14 - 01195746 ____A C:\Windows\WindowsUpdate.log
2013-07-01 20:24 - 2013-07-01 20:24 - 00013493 ____A C:\AdwCleaner[S1].txt
2013-07-01 20:23 - 2013-07-01 20:23 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-07-01 18:38 - 2013-06-22 13:23 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-TTL.DAT
2013-07-01 18:23 - 2010-05-26 02:01 - 00654346 ____A C:\Windows\System32\perfh007.dat
2013-07-01 18:23 - 2010-05-26 02:01 - 00130186 ____A C:\Windows\System32\perfc007.dat
2013-07-01 18:23 - 2009-07-14 07:13 - 01498510 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-01 18:12 - 2013-07-01 18:11 - 00023557 ____A C:\Users\*****\Desktop\Addition.txt
2013-07-01 18:10 - 2013-07-01 18:10 - 01933758 ____A (Farbar) C:\Users\*****\Desktop\FRST64.exe
2013-07-01 18:10 - 2013-07-01 18:10 - 00000000 ____D C:\FRST
2013-07-01 18:00 - 2013-06-22 12:46 - 00000480 ____A C:\Windows\Tasks\SpeedMaxPc Registration3.job
2013-06-30 22:20 - 2009-07-14 06:45 - 00353120 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-30 22:18 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-06-30 22:09 - 2013-06-30 22:09 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-06-30 16:35 - 2013-06-23 16:59 - 00028342 ____A C:\Windows\PFRO.log
2013-06-29 17:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-29 13:56 - 2013-06-22 14:37 - 00000898 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-06-28 19:01 - 2013-06-22 14:36 - 00000000 ____D C:\Program Files (x86)\CoolLyrics
2013-06-23 21:04 - 2013-03-23 18:04 - 00000000 ____D C:\Users\*****\AppData\Local\Microsoft Games
2013-06-23 16:59 - 2013-06-23 16:59 - 00000000 ____A C:\Windows\setuperr.log
2013-06-23 11:25 - 2013-06-23 11:25 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-Q2-TTL.DAT
2013-06-22 22:26 - 2011-02-06 13:28 - 00000000 ____D C:\Users\*****\AppData\Local\Google
2013-06-22 16:19 - 2011-07-10 10:17 - 00001425 ____A C:\0
2013-06-22 15:35 - 2013-06-22 15:35 - 00000000 ____A C:\Users\*****\defogger_reenable
2013-06-22 15:35 - 2011-01-31 22:09 - 00000000 ____D C:\users\*****
2013-06-22 14:33 - 2013-06-22 14:33 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-06-22 14:06 - 2013-06-22 14:02 - 00000000 ____D C:\ProgramData\HitmanPro
2013-06-22 13:58 - 2013-06-22 13:58 - 00000000 ___AD C:\Program Files (x86)\InboxAce_1gEI
2013-06-22 13:02 - 2013-06-22 12:46 - 00000438 ____A C:\Windows\Tasks\SpeedMaxPc Update3.job
2013-06-22 12:57 - 2011-04-19 21:01 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-06-22 12:57 - 2011-04-19 20:51 - 00000000 ____D C:\Windows\SysWOW64\QuickTime
2013-06-22 12:57 - 2011-04-19 20:51 - 00000000 ____D C:\ProgramData\QuickTime
2013-06-22 12:57 - 2011-02-06 14:37 - 00000000 ____D C:\ProgramData\Norton
2013-06-22 12:57 - 2009-08-02 04:27 - 00000000 ____D C:\Windows\Panther
2013-06-22 12:57 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default
2013-06-22 12:46 - 2013-06-22 12:46 - 00000692 ____A C:\Users\*****\Desktop\SpeedMaxPc.lnk
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-19 20:53 - 2013-06-19 20:53 - 00000000 ____D C:\Users\*****\AppData\Roaming\Tific
2013-06-08 16:08 - 2013-06-19 20:21 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-19 20:21 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-19 20:21 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-19 20:21 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-19 20:21 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-19 20:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-19 20:21 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-19 20:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-02 17:11 - 2013-03-16 18:56 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe

Files to move or delete:
====================
C:\ProgramData\FullRemove.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-29 16:33

==================== End Of Log ============================

--- --- ---

--- --- ---


Tschüß
Sabine99

schrauber 02.07.2013 07:22

Hast Du RogueKiller löschen lassen? Ich glabe nicht ;)

Also nochmal Pre-Scan, Scan und dann löschen lassen, Logfile posten und frisches FRST Log bitte :)

Sabine99 02.07.2013 17:07

ja, Du hast Recht, beim ersten mal nicht, dann hab ich es gesehen und nochmal gemacht :-)
auch mit löschen, hoffe ich habe die files nicht durcheinander gebracht,
habe es jetzt eben nochmal laufen lassen...

Kann es sein, dass mein Norton stört? Ich habe es nicht deaktiviert.

anbei die files
vor dem löschen:
Code:

RogueKiller V8.6.1 [Jun 17 2013] durch Tigzy
mail: tigzyRK<at>gmail<dot>com

mail : tigzyRK<at>gmail<dot>com
Kommentare : hxxp://www.geekstogo.com/forum/files/file/413-roguekiller/
Webseite : hxxp://tigzy.geekstogo.com/roguekiller.php
Blog : hxxp://tigzyrk.blogspot.com/

Betriebssystem : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Gestartet in : Normaler Modus
Benutzer : ***** [Admin Rechte]
Funktion : Scannen -- Datum : 07/02/2013 17:58:30
| ARK || FAK || MBR |

¤¤¤ Böswillige Prozesse : 0 ¤¤¤

¤¤¤ Registry-Einträge : 3 ¤¤¤
[DNS] HKLM\[...]\CCSet\[...]\{9737BF33-AC5F-4930-BBC0-1A3182B820F8} : NameServer (193.189.244.225 193.189.244.206) -> GEFUNDEN
[DNS] HKLM\[...]\CS001\[...]\{9737BF33-AC5F-4930-BBC0-1A3182B820F8} : NameServer (193.189.244.225 193.189.244.206) -> GEFUNDEN
[DNS] HKLM\[...]\CS002\[...]\{9737BF33-AC5F-4930-BBC0-1A3182B820F8} : NameServer (193.189.244.225 193.189.244.206) -> GEFUNDEN

¤¤¤ Geplante Tasks : 0 ¤¤¤

¤¤¤ Autostart-Einträge : 0 ¤¤¤

¤¤¤ Web-Browsern : 0 ¤¤¤

¤¤¤ Bestimmte Dateien / Ordner: ¤¤¤

¤¤¤ Treiber : [NICHT GELADEN] ¤¤¤

¤¤¤ Externe Hives: ¤¤¤

¤¤¤ Infektion :  ¤¤¤

¤¤¤ Hosts-Datei: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR überprüfen: ¤¤¤

+++++ PhysicalDrive0: Hitachi HTS545050B9A300 +++++
--- User ---
[MBR] 5f376de65b3a95857c1f1c50bcb042ef
[BSP] 1125a08c4893addf1067300760f1ca47 : KIWI Image system MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 15360 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 31459328 | Size: 100 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 31664128 | Size: 276885 Mo
3 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 598724608 | Size: 184593 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Abgeschlossen : << RKreport[0]_S_07022013_175830.txt >>
RKreport[0]_D_07012013_210208.txt;RKreport[0]_S_07012013_205820.txt;RKreport[0]_S_07012013_210144.txt

nach dem löschen:

Code:

RogueKiller V8.6.1 [Jun 17 2013] durch Tigzy
mail: tigzyRK<at>gmail<dot>com

mail : tigzyRK<at>gmail<dot>com
Kommentare : hxxp://www.geekstogo.com/forum/files/file/413-roguekiller/
Webseite : hxxp://tigzy.geekstogo.com/roguekiller.php
Blog : hxxp://tigzyrk.blogspot.com/

Betriebssystem : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Gestartet in : Normaler Modus
Benutzer : ***** [Admin Rechte]
Funktion : Entfernen -- Datum : 07/02/2013 18:00:42
| ARK || FAK || MBR |

¤¤¤ Böswillige Prozesse : 0 ¤¤¤

¤¤¤ Registry-Einträge : 3 ¤¤¤
[DNS] HKLM\[...]\CCSet\[...]\{9737BF33-AC5F-4930-BBC0-1A3182B820F8} : NameServer (193.189.244.225 193.189.244.206) -> NICHT ENTFERNT, DNS REPARIEREN BENUTZEN
[DNS] HKLM\[...]\CS001\[...]\{9737BF33-AC5F-4930-BBC0-1A3182B820F8} : NameServer (193.189.244.225 193.189.244.206) -> NICHT ENTFERNT, DNS REPARIEREN BENUTZEN
[DNS] HKLM\[...]\CS002\[...]\{9737BF33-AC5F-4930-BBC0-1A3182B820F8} : NameServer (193.189.244.225 193.189.244.206) -> NICHT ENTFERNT, DNS REPARIEREN BENUTZEN

¤¤¤ Geplante Tasks : 0 ¤¤¤

¤¤¤ Autostart-Einträge : 0 ¤¤¤

¤¤¤ Web-Browsern : 0 ¤¤¤

¤¤¤ Bestimmte Dateien / Ordner: ¤¤¤

¤¤¤ Treiber : [NICHT GELADEN] ¤¤¤

¤¤¤ Externe Hives: ¤¤¤

¤¤¤ Infektion :  ¤¤¤

¤¤¤ Hosts-Datei: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR überprüfen: ¤¤¤

+++++ PhysicalDrive0: Hitachi HTS545050B9A300 +++++
--- User ---
[MBR] 5f376de65b3a95857c1f1c50bcb042ef
[BSP] 1125a08c4893addf1067300760f1ca47 : KIWI Image system MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 15360 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 31459328 | Size: 100 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 31664128 | Size: 276885 Mo
3 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 598724608 | Size: 184593 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Abgeschlossen : << RKreport[0]_D_07022013_180042.txt >>
RKreport[0]_D_07012013_210208.txt;RKreport[0]_S_07012013_205820.txt;RKreport[0]_S_07012013_210144.txt
RKreport[0]_S_07022013_175830.txt

und das neue FRST


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-06-2013 03
Ran by ***** (administrator) on 02-07-2013 18:02:14
Running from C:\Users\*****\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
() C:\windows\SysWOW64\Rezip.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
(Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
(AOL LLC) c:\program files (x86)\aol\aol toolbar 4.0\AolTbServer.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Adobe Systems, Inc.) C:\windows\SysWow64\Macromed\Flash\FlashUtil9f.exe
(Microsoft Corporation) C:\windows\System32\MsSpellCheckingFacility.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [9644576 2009-12-15] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2074408 2010-02-26] (Synaptics Incorporated)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup [16413288 2010-02-10] (NVIDIA Corporation)
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-04-26] (Google Inc.)
MountPoints2: {3d82f461-6aa4-11e0-be41-00038a000015} - F:\AutoRun.exe
MountPoints2: {3d82f46f-6aa4-11e0-be41-00038a000015} - F:\AutoRun.exe
HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-06-03] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePDRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [91432 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe" [50472 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0" [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2009-07-21] (CyberLink Corp.)
HKLM-x32\...\Run: [APLangApp] "C:\Program Files (x86)\AnyPC Client\APLangApp.exe" [13312 2009-11-20] (DoctorSoft)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime [98304 2011-04-19] (Apple Computer, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
URLSearchHook: (No Name) - {1CFFA392-0898-4b1c-89D1-6E98F9D8EF78} -  No File
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} -  No File
BHO-x32: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coIEPlg.dll (Symantec Corporation)
BHO-x32: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files (x86)\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKCU - No Name - {DE9C389F-3316-41A7-809B-AA305ED9D922} -  No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9737BF33-AC5F-4930-BBC0-1A3182B820F8}: [NameServer]193.189.244.225 193.189.244.206

==================== Services (Whitelisted) =================

R2 N360; C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe [130008 2011-04-17] (Symantec Corporation)
R2 Rezip; C:\windows\SysWOW64\Rezip.exe [311296 2009-03-05] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-07] ()
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [x]

==================== Drivers (Whitelisted) ====================

R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\BASHDefs\20130620.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\BASHDefs\20130620.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
R3 CryptOSD; C:\Windows\System32\DRIVERS\CryptOSD.sys [431488 2009-06-25] (Phoenix Technologies)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-15] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-15] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-03-15] (Symantec Corporation)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\IPSDefs\20130628.001\IDSvia64.sys [513184 2013-06-15] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\IPSDefs\20130628.001\IDSvia64.sys [513184 2013-06-15] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130701.001\ENG64.SYS [126040 2013-06-23] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130701.001\ENG64.SYS [126040 2013-06-23] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130701.001\EX64.SYS [2098776 2013-06-23] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130701.001\EX64.SYS [2098776 2013-06-23] (Symantec Corporation)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-06-24] (Windows (R) 2003 DDK 3790 provider)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-06-24] (Windows (R) 2003 DDK 3790 provider)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\0502020.003\SRTSP64.SYS [744568 2011-03-31] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\0502020.003\SRTSPX64.SYS [40568 2011-03-31] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\0502020.003\SYMDS64.SYS [450680 2011-01-27] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\0502020.003\SYMEFA64.SYS [912504 2011-03-15] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2011-05-14] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\0502020.003\Ironx64.SYS [171128 2010-11-16] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\0502020.003\SYMNETS.SYS [386168 2011-04-21] (Symantec Corporation)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
S2 ASCTRM; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-02 18:01 - 2013-07-02 18:01 - 00002185 ____A C:\Users\*****\Desktop\RKreport[0]_D_07022013_180042_Di_2.txt
2013-07-02 18:00 - 2013-07-02 18:00 - 00002193 ____A C:\Users\*****\Desktop\RKreport[0]_D_07022013_180042.txt
2013-07-02 18:00 - 2013-07-02 18:00 - 00002057 ____A C:\Users\*****\Desktop\RKreport[0]_S_07022013_175830_Di_1.txt
2013-07-02 17:58 - 2013-07-02 17:58 - 00002065 ____A C:\Users\*****\Desktop\RKreport[0]_S_07022013_175830.txt
2013-07-01 21:08 - 2013-07-01 21:08 - 00002863 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208_3_korr.txt
2013-07-01 21:04 - 2013-07-01 21:04 - 00034835 ____A C:\Users\*****\Desktop\FRST_neu.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002887 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208_3.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002887 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002746 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_210144_2.txt
2013-07-01 21:01 - 2013-07-01 21:01 - 00002746 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_210144.txt
2013-07-01 20:59 - 2013-07-01 20:59 - 00002689 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_205820_1.txt
2013-07-01 20:58 - 2013-07-01 20:58 - 00002713 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_205820.txt
2013-07-01 20:56 - 2013-07-01 21:02 - 00000000 ____D C:\Users\*****\Desktop\RK_Quarantine
2013-07-01 20:55 - 2013-07-01 20:55 - 00909312 ____A C:\Users\*****\Downloads\RogueKiller_8.6.1.exe
2013-07-01 20:55 - 2013-07-01 20:55 - 00909312 ____A C:\Users\*****\Desktop\RogueKiller_8.6.1.exe
2013-07-01 20:39 - 2013-07-01 20:39 - 00001057 ____A C:\Users\*****\Desktop\JRT1.txt
2013-07-01 20:38 - 2013-07-01 20:38 - 00001081 ____A C:\Users\*****\Desktop\JRT.txt
2013-07-01 20:34 - 2013-07-01 20:34 - 00000000 ____D C:\Windows\ERUNT
2013-07-01 20:32 - 2013-07-01 20:33 - 00000000 ____D C:\JRT
2013-07-01 20:32 - 2013-07-01 20:32 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-07-01 20:29 - 2013-07-01 20:29 - 00013413 ____A C:\Users\*****\Desktop\AdwCleaner[S1].txt
2013-07-01 20:24 - 2013-07-01 20:24 - 00013493 ____A C:\AdwCleaner[S1].txt
2013-07-01 20:23 - 2013-07-01 20:23 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-07-01 18:11 - 2013-07-01 18:12 - 00023557 ____A C:\Users\*****\Desktop\Addition.txt
2013-07-01 18:10 - 2013-07-01 18:10 - 01933758 ____A (Farbar) C:\Users\*****\Desktop\FRST64.exe
2013-07-01 18:10 - 2013-07-01 18:10 - 00000000 ____D C:\FRST
2013-06-30 22:12 - 2012-08-23 16:13 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\rdpudd.dll
2013-06-30 22:12 - 2012-08-23 16:10 - 00019456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys
2013-06-30 22:12 - 2012-08-23 16:07 - 00057856 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys
2013-06-30 22:12 - 2012-08-23 15:47 - 00046592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-06-30 22:12 - 2012-08-23 15:46 - 00016896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-06-30 22:12 - 2012-08-23 15:41 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
2013-06-30 22:12 - 2012-08-23 15:40 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2013-06-30 22:12 - 2012-08-23 15:24 - 00015360 ____A (Microsoft Corporation) C:\Windows\System32\RdpGroupPolicyExtension.dll
2013-06-30 22:12 - 2012-08-23 15:20 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\MsRdpWebAccess.dll
2013-06-30 22:12 - 2012-08-23 15:18 - 00037376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-06-30 22:12 - 2012-08-23 15:17 - 00018432 ____A (Microsoft Corporation) C:\Windows\System32\wksprtPS.dll
2013-06-30 22:12 - 2012-08-23 15:06 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll
2013-06-30 22:12 - 2012-08-23 14:52 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll
2013-06-30 22:12 - 2012-08-23 13:20 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe
2013-06-30 22:12 - 2012-08-23 13:15 - 00269312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-06-30 22:12 - 2012-08-23 13:14 - 00384000 ____A (Microsoft Corporation) C:\Windows\System32\wksprt.exe
2013-06-30 22:12 - 2012-08-23 13:12 - 00192000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-06-30 22:12 - 2012-08-23 12:54 - 00322560 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll
2013-06-30 22:12 - 2012-08-23 12:51 - 00228864 ____A (Microsoft Corporation) C:\Windows\System32\rdpendp_winip.dll
2013-06-30 22:12 - 2012-08-23 12:39 - 01048064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-06-30 22:12 - 2012-08-23 12:22 - 01123840 ____A (Microsoft Corporation) C:\Windows\System32\mstsc.exe
2013-06-30 22:12 - 2012-08-23 11:51 - 03174912 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2013-06-30 22:12 - 2012-08-23 10:19 - 04916224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-06-30 22:12 - 2012-08-23 10:13 - 05773824 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2013-06-30 22:09 - 2013-06-30 22:09 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-06-30 22:08 - 2012-08-24 20:13 - 00154480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2013-06-30 22:08 - 2012-08-24 20:09 - 00458712 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2013-06-30 22:08 - 2012-08-24 20:05 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-06-30 22:08 - 2012-08-24 20:03 - 01448448 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2013-06-30 22:08 - 2012-08-24 18:57 - 00247808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-06-30 22:08 - 2012-08-24 18:57 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-06-30 22:08 - 2012-08-24 18:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-06-30 22:08 - 2012-05-04 13:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2013-06-30 22:08 - 2012-05-04 11:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2013-06-23 16:59 - 2013-07-02 17:47 - 00001532 ____A C:\Windows\setupact.log
2013-06-23 16:59 - 2013-06-30 16:35 - 00028342 ____A C:\Windows\PFRO.log
2013-06-23 16:59 - 2013-06-23 16:59 - 00000000 ____A C:\Windows\setuperr.log
2013-06-23 11:25 - 2013-06-23 11:25 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-Q2-TTL.DAT
2013-06-22 15:35 - 2013-06-22 15:35 - 00000000 ____A C:\Users\*****\defogger_reenable
2013-06-22 14:37 - 2013-06-29 13:56 - 00000898 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-06-22 14:36 - 2013-06-28 19:01 - 00000000 ____D C:\Program Files (x86)\CoolLyrics
2013-06-22 14:33 - 2013-06-22 14:33 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-06-22 14:02 - 2013-06-22 14:06 - 00000000 ____D C:\ProgramData\HitmanPro
2013-06-22 13:58 - 2013-06-22 13:58 - 00000000 ___AD C:\Program Files (x86)\InboxAce_1gEI
2013-06-22 13:23 - 2013-07-01 18:38 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-TTL.DAT
2013-06-22 12:46 - 2013-07-02 18:00 - 00000480 ____A C:\Windows\Tasks\SpeedMaxPc Registration3.job
2013-06-22 12:46 - 2013-06-22 13:02 - 00000438 ____A C:\Windows\Tasks\SpeedMaxPc Update3.job
2013-06-22 12:46 - 2013-06-22 12:46 - 00000692 ____A C:\Users\*****\Desktop\SpeedMaxPc.lnk
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-19 20:53 - 2013-06-19 20:53 - 00000000 ____D C:\Users\*****\AppData\Roaming\Tific
2013-06-19 20:22 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-19 20:22 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-19 20:22 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-19 20:22 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-19 20:22 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-19 20:22 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-19 20:21 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-19 20:21 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-19 20:21 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-19 20:21 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-19 20:21 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-19 20:21 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-19 20:21 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-19 20:21 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-18 20:02 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-18 20:02 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-18 20:02 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-18 20:02 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-18 20:02 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-18 20:02 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-18 20:02 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-18 20:02 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-18 20:02 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-18 20:02 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-18 20:02 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-18 20:02 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-18 20:02 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-18 20:02 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-18 20:02 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-18 20:02 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-18 20:02 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-18 20:02 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-18 20:02 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-06-18 20:02 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-06-18 20:02 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-06-18 20:02 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-18 20:02 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-06-18 20:02 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-06-18 20:02 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-06-18 20:02 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-06-18 20:02 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-06-18 20:02 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-06-18 20:02 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-06-18 20:02 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-06-18 20:02 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-06-18 20:02 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-06-18 20:02 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll

==================== One Month Modified Files and Folders =======

2013-07-02 18:01 - 2013-07-02 18:01 - 00002185 ____A C:\Users\*****\Desktop\RKreport[0]_D_07022013_180042_Di_2.txt
2013-07-02 18:00 - 2013-07-02 18:00 - 00002193 ____A C:\Users\*****\Desktop\RKreport[0]_D_07022013_180042.txt
2013-07-02 18:00 - 2013-07-02 18:00 - 00002057 ____A C:\Users\*****\Desktop\RKreport[0]_S_07022013_175830_Di_1.txt
2013-07-02 18:00 - 2013-06-22 12:46 - 00000480 ____A C:\Windows\Tasks\SpeedMaxPc Registration3.job
2013-07-02 17:58 - 2013-07-02 17:58 - 00002065 ____A C:\Users\*****\Desktop\RKreport[0]_S_07022013_175830.txt
2013-07-02 17:55 - 2009-07-14 06:45 - 00013936 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-02 17:55 - 2009-07-14 06:45 - 00013936 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-02 17:49 - 2011-02-06 13:32 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-02 17:47 - 2013-06-23 16:59 - 00001532 ____A C:\Windows\setupact.log
2013-07-02 17:47 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-02 06:38 - 2010-04-26 10:14 - 01225684 ____A C:\Windows\WindowsUpdate.log
2013-07-02 06:33 - 2011-02-06 13:32 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-01 21:08 - 2013-07-01 21:08 - 00002863 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208_3_korr.txt
2013-07-01 21:04 - 2013-07-01 21:04 - 00034835 ____A C:\Users\*****\Desktop\FRST_neu.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002887 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208_3.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002887 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002746 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_210144_2.txt
2013-07-01 21:02 - 2013-07-01 20:56 - 00000000 ____D C:\Users\*****\Desktop\RK_Quarantine
2013-07-01 21:01 - 2013-07-01 21:01 - 00002746 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_210144.txt
2013-07-01 20:59 - 2013-07-01 20:59 - 00002689 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_205820_1.txt
2013-07-01 20:58 - 2013-07-01 20:58 - 00002713 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_205820.txt
2013-07-01 20:55 - 2013-07-01 20:55 - 00909312 ____A C:\Users\*****\Downloads\RogueKiller_8.6.1.exe
2013-07-01 20:55 - 2013-07-01 20:55 - 00909312 ____A C:\Users\*****\Desktop\RogueKiller_8.6.1.exe
2013-07-01 20:39 - 2013-07-01 20:39 - 00001057 ____A C:\Users\*****\Desktop\JRT1.txt
2013-07-01 20:38 - 2013-07-01 20:38 - 00001081 ____A C:\Users\*****\Desktop\JRT.txt
2013-07-01 20:34 - 2013-07-01 20:34 - 00000000 ____D C:\Windows\ERUNT
2013-07-01 20:33 - 2013-07-01 20:32 - 00000000 ____D C:\JRT
2013-07-01 20:32 - 2013-07-01 20:32 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-07-01 20:29 - 2013-07-01 20:29 - 00013413 ____A C:\Users\*****\Desktop\AdwCleaner[S1].txt
2013-07-01 20:24 - 2013-07-01 20:24 - 00013493 ____A C:\AdwCleaner[S1].txt
2013-07-01 20:23 - 2013-07-01 20:23 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-07-01 18:38 - 2013-06-22 13:23 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-TTL.DAT
2013-07-01 18:23 - 2010-05-26 02:01 - 00654346 ____A C:\Windows\System32\perfh007.dat
2013-07-01 18:23 - 2010-05-26 02:01 - 00130186 ____A C:\Windows\System32\perfc007.dat
2013-07-01 18:23 - 2009-07-14 07:13 - 01498510 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-01 18:12 - 2013-07-01 18:11 - 00023557 ____A C:\Users\*****\Desktop\Addition.txt
2013-07-01 18:10 - 2013-07-01 18:10 - 01933758 ____A (Farbar) C:\Users\*****\Desktop\FRST64.exe
2013-07-01 18:10 - 2013-07-01 18:10 - 00000000 ____D C:\FRST
2013-06-30 22:20 - 2009-07-14 06:45 - 00353120 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-30 22:18 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-06-30 22:09 - 2013-06-30 22:09 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-06-30 16:35 - 2013-06-23 16:59 - 00028342 ____A C:\Windows\PFRO.log
2013-06-29 17:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-29 13:56 - 2013-06-22 14:37 - 00000898 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-06-28 19:01 - 2013-06-22 14:36 - 00000000 ____D C:\Program Files (x86)\CoolLyrics
2013-06-23 21:04 - 2013-03-23 18:04 - 00000000 ____D C:\Users\*****\AppData\Local\Microsoft Games
2013-06-23 16:59 - 2013-06-23 16:59 - 00000000 ____A C:\Windows\setuperr.log
2013-06-23 11:25 - 2013-06-23 11:25 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-Q2-TTL.DAT
2013-06-22 22:26 - 2011-02-06 13:28 - 00000000 ____D C:\Users\*****\AppData\Local\Google
2013-06-22 16:19 - 2011-07-10 10:17 - 00001425 ____A C:\0
2013-06-22 15:35 - 2013-06-22 15:35 - 00000000 ____A C:\Users\*****\defogger_reenable
2013-06-22 15:35 - 2011-01-31 22:09 - 00000000 ____D C:\users\*****
2013-06-22 14:33 - 2013-06-22 14:33 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-06-22 14:06 - 2013-06-22 14:02 - 00000000 ____D C:\ProgramData\HitmanPro
2013-06-22 13:58 - 2013-06-22 13:58 - 00000000 ___AD C:\Program Files (x86)\InboxAce_1gEI
2013-06-22 13:02 - 2013-06-22 12:46 - 00000438 ____A C:\Windows\Tasks\SpeedMaxPc Update3.job
2013-06-22 12:57 - 2011-04-19 21:01 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-06-22 12:57 - 2011-04-19 20:51 - 00000000 ____D C:\Windows\SysWOW64\QuickTime
2013-06-22 12:57 - 2011-04-19 20:51 - 00000000 ____D C:\ProgramData\QuickTime
2013-06-22 12:57 - 2011-02-06 14:37 - 00000000 ____D C:\ProgramData\Norton
2013-06-22 12:57 - 2009-08-02 04:27 - 00000000 ____D C:\Windows\Panther
2013-06-22 12:57 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default
2013-06-22 12:46 - 2013-06-22 12:46 - 00000692 ____A C:\Users\*****\Desktop\SpeedMaxPc.lnk
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-19 20:53 - 2013-06-19 20:53 - 00000000 ____D C:\Users\*****\AppData\Roaming\Tific
2013-06-08 16:08 - 2013-06-19 20:21 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-19 20:21 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-19 20:21 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-19 20:21 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-19 20:21 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-19 20:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-19 20:21 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-19 20:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-02 17:11 - 2013-03-16 18:56 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe

Files to move or delete:
====================
C:\ProgramData\FullRemove.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-29 16:33

==================== End Of Log ============================

--- --- ---

--- --- ---




Grüße
Sabine99

schrauber 02.07.2013 18:24

Schon besser :)

Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop.
Schließe nun alle offenen Programme und trenne Dich von dem Internet.
Doppelklick auf die TFC.exe und drücke auf Start.
Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen.



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte.

Sabine99 03.07.2013 19:34

Hallo Schrauber,

und hier sind die files:

ESET:
Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=02038412319e3b4cb42310ef9806a2e6
# engine=14241
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-07-02 08:29:45
# local_time=2013-07-02 10:29:45 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=3589 16777213 100 80 8083362 123459481 0 0
# compatibility_mode=5893 16776574 100 94 9343647 124426835 0 0
# scanned=75652
# found=0
# cleaned=0
# scan_time=2484
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=02038412319e3b4cb42310ef9806a2e6
# engine=14256
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-07-03 06:22:21
# local_time=2013-07-03 08:22:21 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=3589 16777213 100 80 8162118 123538237 0 0
# compatibility_mode=5893 16776574 100 94 9426003 124505591 0 0
# scanned=137929
# found=0
# cleaned=0
# scan_time=4363

Security check:

Code:

Results of screen317's Security Check version 0.99.68 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 10 
``````````````Antivirus/Firewall Check:``````````````
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 Adobe Reader 9 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent```````` 
 Norton ccSvcHst.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````

FRST:


FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-06-2013 03
Ran by ***** (administrator) on 03-07-2013 20:29:18
Running from C:\Users\*****\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
() C:\windows\SysWOW64\Rezip.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
(AOL LLC) c:\program files (x86)\aol\aol toolbar 4.0\AolTbServer.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Microsoft Corporation) C:\windows\System32\MsSpellCheckingFacility.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [9644576 2009-12-15] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2074408 2010-02-26] (Synaptics Incorporated)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup [16413288 2010-02-10] (NVIDIA Corporation)
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-04-26] (Google Inc.)
MountPoints2: {3d82f461-6aa4-11e0-be41-00038a000015} - F:\AutoRun.exe
MountPoints2: {3d82f46f-6aa4-11e0-be41-00038a000015} - F:\AutoRun.exe
HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-06-03] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePDRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [91432 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe" [50472 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0" [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2009-07-21] (CyberLink Corp.)
HKLM-x32\...\Run: [APLangApp] "C:\Program Files (x86)\AnyPC Client\APLangApp.exe" [13312 2009-11-20] (DoctorSoft)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime [98304 2011-04-19] (Apple Computer, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
URLSearchHook: (No Name) - {1CFFA392-0898-4b1c-89D1-6E98F9D8EF78} -  No File
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} -  No File
BHO-x32: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coIEPlg.dll (Symantec Corporation)
BHO-x32: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files (x86)\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKCU - No Name - {DE9C389F-3316-41A7-809B-AA305ED9D922} -  No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9737BF33-AC5F-4930-BBC0-1A3182B820F8}: [NameServer]193.189.244.225 193.189.244.206

==================== Services (Whitelisted) =================

R2 N360; C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe [130008 2011-04-17] (Symantec Corporation)
R2 Rezip; C:\windows\SysWOW64\Rezip.exe [311296 2009-03-05] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-07] ()
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [x]

==================== Drivers (Whitelisted) ====================

R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\BASHDefs\20130620.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\BASHDefs\20130620.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
R3 CryptOSD; C:\Windows\System32\DRIVERS\CryptOSD.sys [431488 2009-06-25] (Phoenix Technologies)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-15] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-15] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-03-15] (Symantec Corporation)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\IPSDefs\20130629.001\IDSvia64.sys [513184 2013-06-15] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\IPSDefs\20130629.001\IDSvia64.sys [513184 2013-06-15] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130702.002\ENG64.SYS [126040 2013-06-23] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130702.002\ENG64.SYS [126040 2013-06-23] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130702.002\EX64.SYS [2098776 2013-06-23] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\VirusDefs\20130702.002\EX64.SYS [2098776 2013-06-23] (Symantec Corporation)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-06-24] (Windows (R) 2003 DDK 3790 provider)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-06-24] (Windows (R) 2003 DDK 3790 provider)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\0502020.003\SRTSP64.SYS [744568 2011-03-31] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\0502020.003\SRTSPX64.SYS [40568 2011-03-31] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\0502020.003\SYMDS64.SYS [450680 2011-01-27] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\0502020.003\SYMEFA64.SYS [912504 2011-03-15] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2011-05-14] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\0502020.003\Ironx64.SYS [171128 2010-11-16] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\0502020.003\SYMNETS.SYS [386168 2011-04-21] (Symantec Corporation)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
S2 ASCTRM; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-03 20:28 - 2013-07-03 20:28 - 00000698 ____A C:\Users\*****\Desktop\checkup.txt
2013-07-03 20:26 - 2013-07-03 20:26 - 00890988 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-07-02 21:44 - 2013-07-02 21:44 - 02347384 ____A (ESET) C:\Users\*****\Desktop\esetsmartinstaller_enu.exe
2013-07-02 19:38 - 2013-07-02 19:38 - 00448512 ____A (OldTimer Tools) C:\Users\*****\Desktop\TFC.exe
2013-07-02 18:03 - 2013-07-02 18:03 - 00036355 ____A C:\Users\*****\Desktop\FRST_Di 1.txt
2013-07-02 18:01 - 2013-07-02 18:01 - 00002185 ____A C:\Users\*****\Desktop\RKreport[0]_D_07022013_180042_Di_2.txt
2013-07-02 18:00 - 2013-07-02 18:00 - 00002193 ____A C:\Users\*****\Desktop\RKreport[0]_D_07022013_180042.txt
2013-07-02 18:00 - 2013-07-02 18:00 - 00002057 ____A C:\Users\*****\Desktop\RKreport[0]_S_07022013_175830_Di_1.txt
2013-07-02 17:58 - 2013-07-02 17:58 - 00002065 ____A C:\Users\*****\Desktop\RKreport[0]_S_07022013_175830.txt
2013-07-01 21:08 - 2013-07-01 21:08 - 00002863 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208_3_korr.txt
2013-07-01 21:04 - 2013-07-01 21:04 - 00034835 ____A C:\Users\*****\Desktop\FRST_neu.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002887 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208_3.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002887 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002746 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_210144_2.txt
2013-07-01 21:01 - 2013-07-01 21:01 - 00002746 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_210144.txt
2013-07-01 20:59 - 2013-07-01 20:59 - 00002689 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_205820_1.txt
2013-07-01 20:58 - 2013-07-01 20:58 - 00002713 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_205820.txt
2013-07-01 20:56 - 2013-07-01 21:02 - 00000000 ____D C:\Users\*****\Desktop\RK_Quarantine
2013-07-01 20:55 - 2013-07-01 20:55 - 00909312 ____A C:\Users\*****\Downloads\RogueKiller_8.6.1.exe
2013-07-01 20:55 - 2013-07-01 20:55 - 00909312 ____A C:\Users\*****\Desktop\RogueKiller_8.6.1.exe
2013-07-01 20:39 - 2013-07-01 20:39 - 00001057 ____A C:\Users\*****\Desktop\JRT1.txt
2013-07-01 20:38 - 2013-07-01 20:38 - 00001081 ____A C:\Users\*****\Desktop\JRT.txt
2013-07-01 20:34 - 2013-07-01 20:34 - 00000000 ____D C:\Windows\ERUNT
2013-07-01 20:32 - 2013-07-01 20:33 - 00000000 ____D C:\JRT
2013-07-01 20:32 - 2013-07-01 20:32 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-07-01 20:29 - 2013-07-01 20:29 - 00013413 ____A C:\Users\*****\Desktop\AdwCleaner[S1].txt
2013-07-01 20:24 - 2013-07-01 20:24 - 00013493 ____A C:\AdwCleaner[S1].txt
2013-07-01 20:23 - 2013-07-01 20:23 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-07-01 18:11 - 2013-07-01 18:12 - 00023557 ____A C:\Users\*****\Desktop\Addition.txt
2013-07-01 18:10 - 2013-07-01 18:10 - 01933758 ____A (Farbar) C:\Users\*****\Desktop\FRST64.exe
2013-07-01 18:10 - 2013-07-01 18:10 - 00000000 ____D C:\FRST
2013-06-30 22:12 - 2012-08-23 16:13 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\rdpudd.dll
2013-06-30 22:12 - 2012-08-23 16:10 - 00019456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys
2013-06-30 22:12 - 2012-08-23 16:07 - 00057856 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys
2013-06-30 22:12 - 2012-08-23 15:47 - 00046592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-06-30 22:12 - 2012-08-23 15:46 - 00016896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-06-30 22:12 - 2012-08-23 15:41 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
2013-06-30 22:12 - 2012-08-23 15:40 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2013-06-30 22:12 - 2012-08-23 15:24 - 00015360 ____A (Microsoft Corporation) C:\Windows\System32\RdpGroupPolicyExtension.dll
2013-06-30 22:12 - 2012-08-23 15:20 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\MsRdpWebAccess.dll
2013-06-30 22:12 - 2012-08-23 15:18 - 00037376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-06-30 22:12 - 2012-08-23 15:17 - 00018432 ____A (Microsoft Corporation) C:\Windows\System32\wksprtPS.dll
2013-06-30 22:12 - 2012-08-23 15:06 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll
2013-06-30 22:12 - 2012-08-23 14:52 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll
2013-06-30 22:12 - 2012-08-23 13:20 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe
2013-06-30 22:12 - 2012-08-23 13:15 - 00269312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-06-30 22:12 - 2012-08-23 13:14 - 00384000 ____A (Microsoft Corporation) C:\Windows\System32\wksprt.exe
2013-06-30 22:12 - 2012-08-23 13:12 - 00192000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-06-30 22:12 - 2012-08-23 12:54 - 00322560 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll
2013-06-30 22:12 - 2012-08-23 12:51 - 00228864 ____A (Microsoft Corporation) C:\Windows\System32\rdpendp_winip.dll
2013-06-30 22:12 - 2012-08-23 12:39 - 01048064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-06-30 22:12 - 2012-08-23 12:22 - 01123840 ____A (Microsoft Corporation) C:\Windows\System32\mstsc.exe
2013-06-30 22:12 - 2012-08-23 11:51 - 03174912 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2013-06-30 22:12 - 2012-08-23 10:19 - 04916224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-06-30 22:12 - 2012-08-23 10:13 - 05773824 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2013-06-30 22:09 - 2013-06-30 22:09 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-06-30 22:08 - 2012-08-24 20:13 - 00154480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2013-06-30 22:08 - 2012-08-24 20:09 - 00458712 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2013-06-30 22:08 - 2012-08-24 20:05 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-06-30 22:08 - 2012-08-24 20:03 - 01448448 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2013-06-30 22:08 - 2012-08-24 18:57 - 00247808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-06-30 22:08 - 2012-08-24 18:57 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-06-30 22:08 - 2012-08-24 18:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-06-30 22:08 - 2012-05-04 13:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2013-06-30 22:08 - 2012-05-04 11:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2013-06-23 16:59 - 2013-07-02 21:37 - 00001588 ____A C:\Windows\setupact.log
2013-06-23 16:59 - 2013-06-30 16:35 - 00028342 ____A C:\Windows\PFRO.log
2013-06-23 16:59 - 2013-06-23 16:59 - 00000000 ____A C:\Windows\setuperr.log
2013-06-23 11:25 - 2013-06-23 11:25 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-Q2-TTL.DAT
2013-06-22 15:35 - 2013-06-22 15:35 - 00000000 ____A C:\Users\*****\defogger_reenable
2013-06-22 14:37 - 2013-06-29 13:56 - 00000898 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-06-22 14:36 - 2013-06-28 19:01 - 00000000 ____D C:\Program Files (x86)\CoolLyrics
2013-06-22 14:33 - 2013-06-22 14:33 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-06-22 14:02 - 2013-06-22 14:06 - 00000000 ____D C:\ProgramData\HitmanPro
2013-06-22 13:58 - 2013-06-22 13:58 - 00000000 ___AD C:\Program Files (x86)\InboxAce_1gEI
2013-06-22 13:23 - 2013-07-01 18:38 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-TTL.DAT
2013-06-22 12:46 - 2013-07-03 18:21 - 00000480 ____A C:\Windows\Tasks\SpeedMaxPc Registration3.job
2013-06-22 12:46 - 2013-06-22 13:02 - 00000438 ____A C:\Windows\Tasks\SpeedMaxPc Update3.job
2013-06-22 12:46 - 2013-06-22 12:46 - 00000692 ____A C:\Users\*****\Desktop\SpeedMaxPc.lnk
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-19 20:53 - 2013-06-19 20:53 - 00000000 ____D C:\Users\*****\AppData\Roaming\Tific
2013-06-19 20:22 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-19 20:22 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-19 20:22 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-19 20:22 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-19 20:22 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-19 20:22 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-19 20:22 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-19 20:22 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-19 20:21 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-19 20:21 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-19 20:21 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-19 20:21 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-19 20:21 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-19 20:21 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-19 20:21 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-19 20:21 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-19 20:21 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-18 20:02 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-18 20:02 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-18 20:02 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-18 20:02 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-18 20:02 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-18 20:02 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-18 20:02 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-18 20:02 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-18 20:02 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-18 20:02 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-18 20:02 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-18 20:02 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-18 20:02 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-18 20:02 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-18 20:02 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-18 20:02 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-18 20:02 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-18 20:02 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-18 20:02 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-06-18 20:02 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-06-18 20:02 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-06-18 20:02 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-18 20:02 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-06-18 20:02 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-06-18 20:02 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-06-18 20:02 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-06-18 20:02 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-06-18 20:02 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-06-18 20:02 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-06-18 20:02 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-06-18 20:02 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-06-18 20:02 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-06-18 20:02 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll

==================== One Month Modified Files and Folders =======

2013-07-03 20:28 - 2013-07-03 20:28 - 00000698 ____A C:\Users\*****\Desktop\checkup.txt
2013-07-03 20:26 - 2013-07-03 20:26 - 00890988 ____A C:\Users\*****\Desktop\SecurityCheck.exe
2013-07-03 20:13 - 2010-04-26 10:14 - 01247466 ____A C:\Windows\WindowsUpdate.log
2013-07-03 19:33 - 2011-02-06 13:32 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-03 18:35 - 2011-02-06 13:32 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-03 18:21 - 2013-06-22 12:46 - 00000480 ____A C:\Windows\Tasks\SpeedMaxPc Registration3.job
2013-07-02 21:45 - 2009-07-14 06:45 - 00013936 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-02 21:45 - 2009-07-14 06:45 - 00013936 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-02 21:44 - 2013-07-02 21:44 - 02347384 ____A (ESET) C:\Users\*****\Desktop\esetsmartinstaller_enu.exe
2013-07-02 21:44 - 2010-05-26 02:01 - 00654346 ____A C:\Windows\System32\perfh007.dat
2013-07-02 21:44 - 2010-05-26 02:01 - 00130186 ____A C:\Windows\System32\perfc007.dat
2013-07-02 21:44 - 2009-07-14 07:13 - 01498510 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-02 21:37 - 2013-06-23 16:59 - 00001588 ____A C:\Windows\setupact.log
2013-07-02 21:37 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-02 19:38 - 2013-07-02 19:38 - 00448512 ____A (OldTimer Tools) C:\Users\*****\Desktop\TFC.exe
2013-07-02 18:03 - 2013-07-02 18:03 - 00036355 ____A C:\Users\*****\Desktop\FRST_Di 1.txt
2013-07-02 18:01 - 2013-07-02 18:01 - 00002185 ____A C:\Users\*****\Desktop\RKreport[0]_D_07022013_180042_Di_2.txt
2013-07-02 18:00 - 2013-07-02 18:00 - 00002193 ____A C:\Users\*****\Desktop\RKreport[0]_D_07022013_180042.txt
2013-07-02 18:00 - 2013-07-02 18:00 - 00002057 ____A C:\Users\*****\Desktop\RKreport[0]_S_07022013_175830_Di_1.txt
2013-07-02 17:58 - 2013-07-02 17:58 - 00002065 ____A C:\Users\*****\Desktop\RKreport[0]_S_07022013_175830.txt
2013-07-01 21:08 - 2013-07-01 21:08 - 00002863 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208_3_korr.txt
2013-07-01 21:04 - 2013-07-01 21:04 - 00034835 ____A C:\Users\*****\Desktop\FRST_neu.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002887 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208_3.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002887 ____A C:\Users\*****\Desktop\RKreport[0]_D_07012013_210208.txt
2013-07-01 21:02 - 2013-07-01 21:02 - 00002746 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_210144_2.txt
2013-07-01 21:02 - 2013-07-01 20:56 - 00000000 ____D C:\Users\*****\Desktop\RK_Quarantine
2013-07-01 21:01 - 2013-07-01 21:01 - 00002746 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_210144.txt
2013-07-01 20:59 - 2013-07-01 20:59 - 00002689 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_205820_1.txt
2013-07-01 20:58 - 2013-07-01 20:58 - 00002713 ____A C:\Users\*****\Desktop\RKreport[0]_S_07012013_205820.txt
2013-07-01 20:55 - 2013-07-01 20:55 - 00909312 ____A C:\Users\*****\Downloads\RogueKiller_8.6.1.exe
2013-07-01 20:55 - 2013-07-01 20:55 - 00909312 ____A C:\Users\*****\Desktop\RogueKiller_8.6.1.exe
2013-07-01 20:39 - 2013-07-01 20:39 - 00001057 ____A C:\Users\*****\Desktop\JRT1.txt
2013-07-01 20:38 - 2013-07-01 20:38 - 00001081 ____A C:\Users\*****\Desktop\JRT.txt
2013-07-01 20:34 - 2013-07-01 20:34 - 00000000 ____D C:\Windows\ERUNT
2013-07-01 20:33 - 2013-07-01 20:32 - 00000000 ____D C:\JRT
2013-07-01 20:32 - 2013-07-01 20:32 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\*****\Desktop\JRT.exe
2013-07-01 20:29 - 2013-07-01 20:29 - 00013413 ____A C:\Users\*****\Desktop\AdwCleaner[S1].txt
2013-07-01 20:24 - 2013-07-01 20:24 - 00013493 ____A C:\AdwCleaner[S1].txt
2013-07-01 20:23 - 2013-07-01 20:23 - 00648201 ____A C:\Users\*****\Desktop\adwcleaner.exe
2013-07-01 18:38 - 2013-06-22 13:23 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-TTL.DAT
2013-07-01 18:12 - 2013-07-01 18:11 - 00023557 ____A C:\Users\*****\Desktop\Addition.txt
2013-07-01 18:10 - 2013-07-01 18:10 - 01933758 ____A (Farbar) C:\Users\*****\Desktop\FRST64.exe
2013-07-01 18:10 - 2013-07-01 18:10 - 00000000 ____D C:\FRST
2013-06-30 22:20 - 2009-07-14 06:45 - 00353120 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-30 22:18 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-06-30 22:09 - 2013-06-30 22:09 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-06-30 16:35 - 2013-06-23 16:59 - 00028342 ____A C:\Windows\PFRO.log
2013-06-29 17:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-29 13:56 - 2013-06-22 14:37 - 00000898 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-06-28 19:01 - 2013-06-22 14:36 - 00000000 ____D C:\Program Files (x86)\CoolLyrics
2013-06-23 21:04 - 2013-03-23 18:04 - 00000000 ____D C:\Users\*****\AppData\Local\Microsoft Games
2013-06-23 16:59 - 2013-06-23 16:59 - 00000000 ____A C:\Windows\setuperr.log
2013-06-23 11:25 - 2013-06-23 11:25 - 00000005 ____A C:\Users\*****\AppData\Roaming\WBPU-Q2-TTL.DAT
2013-06-22 22:26 - 2011-02-06 13:28 - 00000000 ____D C:\Users\*****\AppData\Local\Google
2013-06-22 16:19 - 2011-07-10 10:17 - 00001425 ____A C:\0
2013-06-22 15:35 - 2013-06-22 15:35 - 00000000 ____A C:\Users\*****\defogger_reenable
2013-06-22 15:35 - 2011-01-31 22:09 - 00000000 ____D C:\users\*****
2013-06-22 14:33 - 2013-06-22 14:33 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-06-22 14:06 - 2013-06-22 14:02 - 00000000 ____D C:\ProgramData\HitmanPro
2013-06-22 13:58 - 2013-06-22 13:58 - 00000000 ___AD C:\Program Files (x86)\InboxAce_1gEI
2013-06-22 13:02 - 2013-06-22 12:46 - 00000438 ____A C:\Windows\Tasks\SpeedMaxPc Update3.job
2013-06-22 12:57 - 2011-04-19 21:01 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-06-22 12:57 - 2011-04-19 20:51 - 00000000 ____D C:\Windows\SysWOW64\QuickTime
2013-06-22 12:57 - 2011-04-19 20:51 - 00000000 ____D C:\ProgramData\QuickTime
2013-06-22 12:57 - 2011-02-06 14:37 - 00000000 ____D C:\ProgramData\Norton
2013-06-22 12:57 - 2009-08-02 04:27 - 00000000 ____D C:\Windows\Panther
2013-06-22 12:57 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default
2013-06-22 12:46 - 2013-06-22 12:46 - 00000692 ____A C:\Users\*****\Desktop\SpeedMaxPc.lnk
2013-06-19 21:23 - 2013-06-19 21:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-19 20:53 - 2013-06-19 20:53 - 00000000 ____D C:\Users\*****\AppData\Roaming\Tific
2013-06-08 16:08 - 2013-06-19 20:21 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-19 20:21 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-19 20:21 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-19 20:21 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-19 20:21 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-19 20:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-19 20:21 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-19 20:21 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-19 20:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb

Files to move or delete:
====================
C:\ProgramData\FullRemove.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-29 16:33

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

--- --- ---


Grüße

Sabine99

schrauber 03.07.2013 20:37

Fix mit FRST
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
Code:

C:\Program Files (x86)\CoolLyrics
C:\ProgramData\FullRemove.exe

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Fix Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Wie läuft der Rechner? :)

Sabine99 03.07.2013 20:45

HI Schrauber,

der Rechner läuft gut und ich finde auch im Netz schneller.

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 30-06-2013 03
Ran by ***** at 2013-07-03 21:43:53 Run:1
Running from C:\Users\*****\Desktop
Boot Mode: Normal
==============================================

C:\Program Files (x86)\CoolLyrics => Moved successfully.
C:\ProgramData\FullRemove.exe => Moved successfully.

==== End of Fixlog ====

Grüße

Sabine99

schrauber 03.07.2013 20:50

Fertig :)

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.


Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.

Sabine99 03.07.2013 20:55

HI Schrauber,

danke

Grüße

Sabine99

schrauber 03.07.2013 20:56

Büdde :)

Sabine99 04.07.2013 05:29

Hi Schrauber,
nachdem ich von Norton nicht mehr überzeugt bin, möchte ich es komplett von meinen beiden Rechnern entfernen und eine andere Firewall/Virenscanner aufspielen.
Wie mach ich das, kannst Dir aussuchen welchen zuerst. ;-)

Grüße und Danke

Sabine99

schrauber 04.07.2013 07:37

Hi,

http://filepony.de/download-norton_uninstaller/

Das sollte alles von Norton entfernen :)

Sabine99 06.07.2013 11:33

Hallo Schrauber,

leider hat mein neuer Virenscanner ein paar Funde gemeldet.

1. Beim Installieren Trace.File.Lottso(A) Im Ordner zu einem online Spiel, dass ich früher mal öfter gespielt habe... (das habe ich jetzt auf der Quarantäneliste)

und jetzt bei einem kompletten System scan noch folgende:

2. Trace.file.locker(A); Trace.File.White.Smoke(A) und der Ordner wurde bereits 2010 angelegt. 2 Traces sowie in Windows.old GenPack:Trojan.Bohmini.B(B)

Das war es.

Was ist hiervon kritisch und muß entfernt werden? Es ist nur mein PC betroffen, der Laptop ist jetzt sauber....

Hier noch das file:
Code:

Emsisoft Anti-Malware - Version 8.0
Letztes Update: 06.07.2013 11:00:35
Benutzerkonto: *****-PC\*****

Scan Einstellungen:

Scan Methode: Detail Scan
Objekte: Rootkits, Speicher, Traces, C:\, D:\

Riskware-Erkennung: Aus
Archiv Scan: An
ADS Scan: An
Dateitypen-Filter: Aus
Erweitertes Caching: An
Direkter Festplattenzugriff: Aus

Scan Beginn:        06.07.2013 11:02:52
C:\Users\*****\AppData\Roaming\Microsoft\Windows\Templates\2433f433        gefunden: Trace.File.Locker (A)
C:\Program Files\WhiteSmoke\        gefunden: Trace.File.WhiteSmoke (A)
C:\Users\*****\AppData\Roaming\WhiteSmoke\        gefunden: Trace.File.WhiteSmoke (A)
C:\Users\*****\AppData\Roaming\WhiteSmoke\stat.log        gefunden: Trace.File.WhiteSmoke (A)
C:\Windows.old\Windows\Temp\28HjeErn.exe -> (Embedded EXE g)        gefunden: GenPack:Trojan.Bohmini.B (B)

Gescannt        634547
Gefunden        5

Scan Ende:        06.07.2013 12:24:27
Scan Zeit:        1:21:35

Danke für Deine weitere Hilfe

Sabine99

schrauber 06.07.2013 11:37

Hoi :)

poste mal ein frisches FRST log :)

Sabine99 06.07.2013 12:02

Hallo Schrauber,

und hier kommen sie schon ;-)

FRST:


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-07-2013
Ran by ***** (administrator) on 06-07-2013 12:57:13
Running from C:\Users\*****\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Emsisoft GmbH) C:\Program Files\Online Armor\OAcat.exe
(Emsisoft GmbH) C:\Program Files\Online Armor\oasrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Secunia) C:\Program Files\Secunia\PSI\PSIA.exe
(Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe
(COMPANYVERS_NAME) C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Lexware GmbH & Co. KG) C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe
(ODSoft multimedia) C:\Program Files\Sceneo\AbsolutTV\Services\ODSBC\ODSBCApp.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(VER_COMPANY_NAME) C:\Program Files\UtilityChest_49\bar\1.bin\49brmon.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Emsisoft GmbH) C:\Program Files\Online Armor\oaui.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(BillP Studios) C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
(Hewlett-Packard Co.) C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RaUI.exe
(Emsisoft GmbH) C:\Program Files\Online Armor\OAhlp.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2start.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [UpdatePPShortCut] "C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\PowerProducer" update "Software\CyberLink\PowerProducer\4.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM\...\Run: [Windows Defender] %programfiles%\windows defender\msascui.exe -hide [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [LexwareInfoService] c:\program files\common files\lexware\update manager\lxupdatemanager.exe /autostart [339240 2008-11-03] (Lexware GmbH & Co. KG)
HKLM\...\Run: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\nbkeyscan.exe" [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [RemoteControl] "c:\program files\homecinema\powerdvd\pdvdserv.exe" [71216 2007-02-09] (Cyberlink Corp.)
HKLM\...\Run: [TVBroadcast] c:\program files\sceneo\absoluttv\services\odsbc\odsbcapp.exe [797696 2007-08-08] (ODSoft multimedia)
HKLM\...\Run: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe [90112 2006-11-29] (Ulead Systems, Inc.)
HKLM\...\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [InboxAce Search Scope Monitor] "C:\PROGRA~1\INBOXA~2\bar\1.bin\1gsrchmn.exe" /m=2 /w /h [x]
HKLM\...\Run: [InboxAce_1g Browser Plugin Loader] C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbrmon.exe [x]
HKLM\...\Run: [Utility Chest Search Scope Monitor] "C:\PROGRA~1\UTILIT~2\bar\1.bin\49srchmn.exe" /m=2 /w /h [44784 2013-06-25] (MindSpark)
HKLM\...\Run: [UtilityChest_49 Browser Plugin Loader] C:\PROGRA~1\UTILIT~2\bar\1.bin\49brmon.exe [30096 2013-06-25] (VER_COMPANY_NAME)
HKLM\...\Run: [NortonSupport] "C:\Program Files\Norton 360\Engine\20.4.0.40\symerr.exe" /supportreboot [x]
HKLM\...\Run: [emsisoft anti-malware] "c:\program files\emsisoft anti-malware\a2guard.exe" /d=60 [2928040 2013-07-02] (Emsisoft GmbH)
HKLM\...\Run: [@OnlineArmor GUI] "C:\Program Files\Online Armor\oaui.exe" [2415104 2012-10-02] (Emsisoft GmbH)
HKCU\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\nmbgmonitor.exe" [202024 2007-10-15] (Nero AG)
HKCU\...\Run: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autorun [1233920 2009-04-11] (Microsoft Corporation)
HKCU\...\Run: [SearchEngineProtection] C:\Program Files\GamesBar\update\SearchEngineProtection.exe [x]
HKCU\...\Run: [AOL Dialer] C:\Program Files\Common Files\AOL\ACS\AOlDial.exe [x]
HKCU\...\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot [423144 2013-04-27] (BillP Studios)
HKCU\...\Policies\system: [disableregistrytools] 0
MountPoints2: {efcd0c81-082c-11df-b5e6-806e6f6e6963} - H:\setup.exe
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)

==================== Internet (Whitelisted) ====================

ProxyServer: 192.168.1.1:80
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
URLSearchHook: (No Name) - {7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
URLSearchHook: (No Name) - {5fdb0cd8-5760-44d1-8d13-a78bf558c3c7} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll No File
HKCU SearchScopes: DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
BHO: Search Assistant BHO - {06e05b40-77fa-40b6-9077-ed1a7577b1ef} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
BHO: GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
BHO: Toolbar BHO - {58f7b5ca-1162-42e8-8bbc-d543b4edd780} - C:\PROGRA~1\UTILIT~2\bar\1.bin\49bar.dll (MindSpark)
BHO: No Name - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -  No File
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Search Assistant BHO - {9359da42-06fb-46f2-9e4a-05c05b98a5ef} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll No File
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Toolbar BHO - {d5a1d22b-9e17-454f-8ecd-83c578fb3983} - C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbar.dll No File
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll No File
Toolbar: HKLM - InboxAce - {3775afd7-5921-4571-968f-85a631203d1c} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll No File
Toolbar: HKLM - Utility Chest - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -InboxAce - {3775AFD7-5921-4571-968F-85A631203D1C} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll No File
Toolbar: HKCU -Utility Chest - {CF67755F-9265-449C-87CF-B945519E073B} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095}
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
ShellExecuteHooks: OA Shell Helper - {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\PROGRA~1\ONLINE~1\oaevent.dll [366440 2012-10-02] (Emsisoft GmbH)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\sgcqplk5.default
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @InboxAce_1g.com/Plugin - C:\Program Files\InboxAce_1g\bar\1.bin\NP1gStub.dll No File
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @UtilityChest_49.com/Plugin - C:\Program Files\UtilityChest_49\bar\1.bin\NP49Stub.dll (MindSpark)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2
FF HKLM\...\Firefox\Extensions: [1gffxtbr@InboxAce_1g.com] C:\Program Files\InboxAce_1g\bar\1.bin
FF HKLM\...\Firefox\Extensions: [49ffxtbr@UtilityChest_49.com] C:\Program Files\UtilityChest_49\bar\1.bin
FF Extension: Utility Chest - C:\Program Files\UtilityChest_49\bar\1.bin
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2

Chrome:
=======
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013"
CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1
CHR Extension: (Norton Identity Protection) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.11.8_0
CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [2938408 2013-07-02] (Emsisoft GmbH)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 OAcat; C:\Program Files\Online Armor\OAcat.exe [216072 2012-10-02] (Emsisoft GmbH)
R2 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe [75040 2008-09-05] (Ralink Technology, Corp.)
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1227800 2013-04-18] (Secunia)
S2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [659992 2013-04-18] (Secunia)
R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1681408 2007-08-16] (Buhl Data Service GmbH)
R2 SvcOnlineArmor; C:\Program Files\Online Armor\oasrv.exe [4463864 2012-10-02] (Emsisoft GmbH)
R2 UtilityChest_49Service; C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe [42504 2013-06-25] (COMPANYVERS_NAME)

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [54072 2012-04-30] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [37856 2012-04-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
S3 CH375; C:\Windows\System32\Drivers\CH375WDM.SYS [28403 2011-03-14] (www.winchiphead.com)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50208 2013-07-02] (Emsisoft GmbH)
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc.              )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [645120 2008-08-21] (Ralink Technology Corp.)
R1 OADevice; C:\Windows\system32\drivers\OADriver.sys [208320 2012-10-02] ()
R1 oahlpXX; C:\Windows\system32\drivers\oahlp32.sys [44992 2012-10-02] ()
R1 OAmon; C:\Windows\system32\drivers\OAmon.sys [27648 2012-10-02] (Emsisoft)
R3 OAnet; C:\Windows\System32\DRIVERS\oanet.sys [31768 2012-10-02] (Emsisoft)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-04-18] (Secunia)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-30] (America Online, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130704.002\NAVENG.SYS [x]
S3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130704.002\NAVEX15.SYS [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S1 SRTSP; \SystemRoot\system32\drivers\N360\1404000.028\SRTSP.SYS [x]
S1 SymIM; system32\DRIVERS\SymIMv.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-06 12:57 - 2013-07-06 12:57 - 00000000 ____D C:\FRST
2013-07-06 12:54 - 2013-07-06 12:55 - 01373373 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-07-04 21:30 - 2013-07-04 21:42 - 00000000 ____D C:\ProgramData\OnlineArmor
2013-07-04 21:30 - 2013-07-04 21:30 - 00000000 ____D C:\Users\*****\AppData\Roaming\OnlineArmor
2013-07-04 21:28 - 2013-07-06 11:02 - 00000000 ____D C:\Program Files\Online Armor
2013-07-04 21:28 - 2012-10-02 15:03 - 00044992 ____A C:\Windows\System32\Drivers\oahlp32.sys
2013-07-04 21:28 - 2012-10-02 15:02 - 00208320 ____A C:\Windows\System32\Drivers\OADriver.sys
2013-07-04 21:28 - 2012-10-02 15:02 - 00031768 ____A (Emsisoft) C:\Windows\System32\Drivers\OAnet.sys
2013-07-04 21:28 - 2012-10-02 15:02 - 00027648 ____A (Emsisoft) C:\Windows\System32\Drivers\OAmon.sys
2013-07-04 21:27 - 2013-07-06 12:57 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-07-04 21:27 - 2013-07-04 21:27 - 00000852 ____A C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-07-04 21:27 - 2013-07-04 21:27 - 00000000 ____D C:\Users\*****\Documents\Anti-Malware
2013-07-04 21:26 - 2013-07-04 21:26 - 221077448 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftInternetSecuritySetup(1).exe
2013-07-04 20:32 - 2013-07-04 20:49 - 221077448 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftInternetSecuritySetup.exe
2013-07-04 20:31 - 2013-07-04 20:48 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(4).exe
2013-07-04 20:31 - 2013-07-04 20:48 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(3).exe
2013-07-04 20:30 - 2013-07-04 20:48 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(1).exe
2013-07-04 20:30 - 2013-07-04 20:46 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup.exe
2013-07-04 20:30 - 2013-07-04 20:45 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(2).exe
2013-07-04 20:02 - 2013-07-04 20:02 - 00867880 ____A C:\Users\*****\Downloads\Norton20_Removal_Tool(1).exe
2013-07-04 19:59 - 2013-07-04 20:01 - 00269952 ____A C:\Windows\msxml4-KB2758694-enu.LOG
2013-07-04 19:58 - 2013-07-04 19:59 - 00867880 ____A C:\Users\*****\Downloads\Norton20_Removal_Tool.exe
2013-07-01 21:20 - 2013-07-01 21:21 - 00000000 ____D C:\Users\*****\Desktop\wot_safe_surfing-20130515-fx
2013-07-01 20:17 - 2013-07-01 20:17 - 00000209 ____A C:\Users\*****\Desktop\AOL.de Kostenlose Email, Nachrichten & Wetter, Finanzen , Sport und Star-News auf AOL.de.URL
2013-07-01 19:58 - 2013-07-01 19:58 - 02434048 ____A C:\Users\*****\Downloads\msxml.msi
2013-07-01 19:58 - 2013-07-01 19:58 - 02434048 ____A C:\Users\*****\Downloads\msxml(1).msi
2013-07-01 19:49 - 2013-07-01 19:49 - 00000000 ____D C:\Users\*****\AppData\Local\Secunia PSI
2013-07-01 19:28 - 2013-07-01 19:28 - 00448512 ____A (OldTimer Tools) C:\Users\*****\Downloads\TFC.exe
2013-07-01 19:22 - 2013-07-03 18:59 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-07-01 19:22 - 2013-07-01 19:57 - 00000810 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-01 19:22 - 2013-07-01 19:22 - 00000000 ____D C:\Users\*****\AppData\Roaming\Mozilla
2013-07-01 19:22 - 2013-07-01 19:22 - 00000000 ____D C:\Users\*****\AppData\Local\Mozilla
2013-07-01 19:22 - 2013-07-01 19:22 - 00000000 ____D C:\ProgramData\Mozilla
2013-07-01 19:18 - 2013-07-01 19:18 - 00376576 ____A C:\Users\*****\Desktop\wot_safe_surfing-20130515-fx.zip
2013-07-01 19:12 - 2013-07-01 19:12 - 00140125 ____A C:\Users\*****\Desktop\hosts.zip
2013-07-01 18:44 - 2013-07-01 18:44 - 00000000 ____D C:\ProgramData\Licenses
2013-07-01 18:44 - 2013-07-01 18:43 - 00867240 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-07-01 18:44 - 2013-07-01 18:43 - 00263592 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-07-01 18:44 - 2013-07-01 18:43 - 00175016 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-07-01 18:44 - 2013-07-01 18:43 - 00175016 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-07-01 18:44 - 2013-07-01 18:43 - 00094632 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
2013-07-01 18:43 - 2013-07-01 18:49 - 00000000 ____D C:\Program Files\SpywareBlaster
2013-07-01 18:43 - 2013-07-01 18:43 - 04095448 ____A (BrightFort LLC                                              ) C:\Users\*****\Downloads\spywareblastersetup50.exe
2013-07-01 18:43 - 2013-07-01 18:43 - 00000840 ____A C:\Users\Public\Desktop\SpywareBlaster.lnk
2013-07-01 18:41 - 2013-07-01 21:20 - 00000000 ____D C:\ProgramData\InstallMate
2013-07-01 18:41 - 2013-07-01 18:41 - 00000000 ____D C:\Users\*****\AppData\Roaming\WinPatrol
2013-07-01 18:41 - 2013-07-01 18:41 - 00000000 ____D C:\Program Files\BillP Studios
2013-07-01 18:40 - 2013-07-01 18:40 - 00906440 ____A (BillP Studios) C:\Users\*****\Desktop\wpsetup.exe
2013-07-01 18:39 - 2013-07-01 18:39 - 00906440 ____A (BillP Studios) C:\Users\*****\Downloads\wpsetup.exe
2013-07-01 18:35 - 2013-07-01 18:35 - 00000870 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-01 18:35 - 2013-07-01 18:35 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes
2013-07-01 18:35 - 2013-07-01 18:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-01 18:35 - 2013-07-01 18:35 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-01 18:35 - 2013-04-04 14:50 - 00022856 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-07-01 18:34 - 2013-07-01 18:34 - 10285040 ____A (Malwarebytes Corporation                                    ) C:\Users\*****\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-01 18:33 - 2013-07-01 18:33 - 00000000 ____D C:\Program Files\Secunia
2013-07-01 18:20 - 2013-07-01 18:20 - 00000000 ____D C:\Windows\ERUNT
2013-06-28 18:35 - 2013-06-28 18:35 - 00000000 ____D C:\Windows\erdnt
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:17 - 2013-06-27 18:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 19:58 - 2013-07-01 18:19 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:18 - 2012-08-21 13:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2013-06-17 06:17 - 2013-06-17 06:18 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2013-06-17 06:17 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-14 13:38 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-14 13:38 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-14 13:38 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-14 13:38 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-14 13:38 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-14 13:38 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-14 13:38 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-14 13:38 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-14 13:38 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-14 13:38 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-14 13:32 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-14 13:31 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-14 13:31 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-14 13:31 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-14 13:31 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-14 13:31 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-14 13:31 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll

==================== One Month Modified Files and Folders ========

2013-07-06 12:57 - 2013-07-06 12:57 - 00000000 ____D C:\FRST
2013-07-06 12:57 - 2013-07-04 21:27 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-07-06 12:55 - 2013-07-06 12:54 - 01373373 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-07-06 12:55 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-06 12:55 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-06 12:51 - 2011-11-22 19:11 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-06 12:50 - 2012-08-22 20:11 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-06 11:02 - 2013-07-04 21:28 - 00000000 ____D C:\Program Files\Online Armor
2013-07-06 11:01 - 2010-10-10 13:04 - 00000000 ____D C:\Users\*****\AppData\Roaming\WhiteSmoke
2013-07-06 11:01 - 2010-01-23 16:48 - 01988564 ____A C:\Windows\WindowsUpdate.log
2013-07-06 10:56 - 2011-11-22 19:11 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-06 10:56 - 2010-01-24 10:55 - 00000000 ____D C:\ProgramData\NVIDIA
2013-07-06 10:56 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-04 22:23 - 2006-11-02 15:01 - 00032534 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-04 21:42 - 2013-07-04 21:30 - 00000000 ____D C:\ProgramData\OnlineArmor
2013-07-04 21:30 - 2013-07-04 21:30 - 00000000 ____D C:\Users\*****\AppData\Roaming\OnlineArmor
2013-07-04 21:29 - 2010-01-23 17:06 - 00000000 ___AD C:\users\*****
2013-07-04 21:27 - 2013-07-04 21:27 - 00000852 ____A C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-07-04 21:27 - 2013-07-04 21:27 - 00000000 ____D C:\Users\*****\Documents\Anti-Malware
2013-07-04 21:26 - 2013-07-04 21:26 - 221077448 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftInternetSecuritySetup(1).exe
2013-07-04 20:49 - 2013-07-04 20:32 - 221077448 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftInternetSecuritySetup.exe
2013-07-04 20:48 - 2013-07-04 20:31 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(4).exe
2013-07-04 20:48 - 2013-07-04 20:31 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(3).exe
2013-07-04 20:48 - 2013-07-04 20:30 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(1).exe
2013-07-04 20:46 - 2013-07-04 20:30 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup.exe
2013-07-04 20:45 - 2013-07-04 20:30 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(2).exe
2013-07-04 20:19 - 2010-01-23 17:02 - 01324818 ____A C:\Windows\PFRO.log
2013-07-04 20:17 - 2010-01-24 11:16 - 00000000 ____D C:\ProgramData\Symantec
2013-07-04 20:17 - 2010-01-24 11:15 - 00000000 ____D C:\ProgramData\Norton
2013-07-04 20:02 - 2013-07-04 20:02 - 00867880 ____A C:\Users\*****\Downloads\Norton20_Removal_Tool(1).exe
2013-07-04 20:01 - 2013-07-04 19:59 - 00269952 ____A C:\Windows\msxml4-KB2758694-enu.LOG
2013-07-04 19:59 - 2013-07-04 19:58 - 00867880 ____A C:\Users\*****\Downloads\Norton20_Removal_Tool.exe
2013-07-03 19:16 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-07-03 18:59 - 2013-07-01 19:22 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-07-01 21:58 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-01 21:21 - 2013-07-01 21:20 - 00000000 ____D C:\Users\*****\Desktop\wot_safe_surfing-20130515-fx
2013-07-01 21:20 - 2013-07-01 18:41 - 00000000 ____D C:\ProgramData\InstallMate
2013-07-01 20:17 - 2013-07-01 20:17 - 00000209 ____A C:\Users\*****\Desktop\AOL.de Kostenlose Email, Nachrichten & Wetter, Finanzen , Sport und Star-News auf AOL.de.URL
2013-07-01 20:14 - 2010-01-26 15:52 - 00002633 ____A C:\Users\*****\Desktop\Microsoft Office PowerPoint 2007.lnk
2013-07-01 20:12 - 2012-08-07 19:40 - 00000000 ____D C:\Program Files\EcrSystem
2013-07-01 19:59 - 2007-09-26 14:08 - 00000000 ____D C:\Program Files\MSXML 4.0
2013-07-01 19:58 - 2013-07-01 19:58 - 02434048 ____A C:\Users\*****\Downloads\msxml.msi
2013-07-01 19:58 - 2013-07-01 19:58 - 02434048 ____A C:\Users\*****\Downloads\msxml(1).msi
2013-07-01 19:57 - 2013-07-01 19:22 - 00000810 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-01 19:57 - 2011-10-21 13:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-07-01 19:51 - 2010-12-28 12:53 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-07-01 19:49 - 2013-07-01 19:49 - 00000000 ____D C:\Users\*****\AppData\Local\Secunia PSI
2013-07-01 19:28 - 2013-07-01 19:28 - 00448512 ____A (OldTimer Tools) C:\Users\*****\Downloads\TFC.exe
2013-07-01 19:22 - 2013-07-01 19:22 - 00000000 ____D C:\Users\*****\AppData\Roaming\Mozilla
2013-07-01 19:22 - 2013-07-01 19:22 - 00000000 ____D C:\Users\*****\AppData\Local\Mozilla
2013-07-01 19:22 - 2013-07-01 19:22 - 00000000 ____D C:\ProgramData\Mozilla
2013-07-01 19:18 - 2013-07-01 19:18 - 00376576 ____A C:\Users\*****\Desktop\wot_safe_surfing-20130515-fx.zip
2013-07-01 19:12 - 2013-07-01 19:12 - 00140125 ____A C:\Users\*****\Desktop\hosts.zip
2013-07-01 18:49 - 2013-07-01 18:43 - 00000000 ____D C:\Program Files\SpywareBlaster
2013-07-01 18:44 - 2013-07-01 18:44 - 00000000 ____D C:\ProgramData\Licenses
2013-07-01 18:43 - 2013-07-01 18:44 - 00867240 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-07-01 18:43 - 2013-07-01 18:44 - 00263592 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-07-01 18:43 - 2013-07-01 18:44 - 00175016 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-07-01 18:43 - 2013-07-01 18:44 - 00175016 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-07-01 18:43 - 2013-07-01 18:44 - 00094632 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
2013-07-01 18:43 - 2013-07-01 18:43 - 04095448 ____A (BrightFort LLC                                              ) C:\Users\*****\Downloads\spywareblastersetup50.exe
2013-07-01 18:43 - 2013-07-01 18:43 - 00000840 ____A C:\Users\Public\Desktop\SpywareBlaster.lnk
2013-07-01 18:43 - 2010-06-23 08:47 - 00789416 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-07-01 18:43 - 2010-01-23 18:54 - 00000000 ____D C:\Program Files\Java
2013-07-01 18:41 - 2013-07-01 18:41 - 00000000 ____D C:\Users\*****\AppData\Roaming\WinPatrol
2013-07-01 18:41 - 2013-07-01 18:41 - 00000000 ____D C:\Program Files\BillP Studios
2013-07-01 18:40 - 2013-07-01 18:40 - 00906440 ____A (BillP Studios) C:\Users\*****\Desktop\wpsetup.exe
2013-07-01 18:39 - 2013-07-01 18:39 - 00906440 ____A (BillP Studios) C:\Users\*****\Downloads\wpsetup.exe
2013-07-01 18:35 - 2013-07-01 18:35 - 00000870 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-01 18:35 - 2013-07-01 18:35 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes
2013-07-01 18:35 - 2013-07-01 18:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-01 18:35 - 2013-07-01 18:35 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-01 18:34 - 2013-07-01 18:34 - 10285040 ____A (Malwarebytes Corporation                                    ) C:\Users\*****\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-01 18:33 - 2013-07-01 18:33 - 00000000 ____D C:\Program Files\Secunia
2013-07-01 18:20 - 2013-07-01 18:20 - 00000000 ____D C:\Windows\ERUNT
2013-07-01 18:19 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-30 21:49 - 2012-05-21 20:02 - 00000000 ____D C:\Users\*****\AppData\Roaming\Apple Computer
2013-06-28 18:35 - 2013-06-28 18:35 - 00000000 ____D C:\Windows\erdnt
2013-06-27 18:59 - 2010-01-26 15:57 - 00002591 ____A C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk
2013-06-27 18:44 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:04 - 2011-04-17 19:29 - 00000000 ____D C:\Windows\System32\Drivers\N360
2013-06-22 19:54 - 2013-01-09 21:21 - 00001935 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:19 - 2010-01-26 10:43 - 00000000 ____D C:\Users\*****\AppData\Local\Apple Computer
2013-06-17 06:18 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:17 - 2013-06-17 06:09 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-17 06:17 - 2010-02-13 14:59 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-06-17 06:17 - 2010-02-13 14:54 - 00000000 ____D C:\ProgramData\Apple
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2012-05-21 06:11 - 00001690 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2013-06-17 06:09 - 2008-01-23 14:46 - 00000000 ____D C:\Program Files\QuickTime
2013-06-14 16:48 - 2012-08-22 20:11 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-14 16:48 - 2011-09-04 07:42 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-14 16:43 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-14 13:36 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-06 12:13

==================== End Of Log ============================

--- --- ---

--- --- ---


Addition:
Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 04-07-2013
Ran by ***** at 2013-07-06 12:58:20
Running from C:\Users\*****\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

 Update for Microsoft Office 2007 (KB2508958)
32 Bit HP CIO Components Installer (Version: 3.1.1)
6500_E709_eDocs (Version: 1.00.0000)
6500_E709_Help (Version: 1.00.0000)
6500_E709a (Version: 50.0.165.000)
7-Zip 9.20
Adobe Flash Player 11 ActiveX (Version: 11.7.700.224)
Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7)
Apple Application Support (Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (Version: 2.1.3.127)
Bonjour (Version: 3.0.0.10)
bpd_scan (Version: 3.00.0000)
BPDSoftware (Version: 50.0.165.000)
BPDSoftware_Ini (Version: 1.00.0000)
BufferChm (Version: 120.0.194.000)
Cisco EAP-FAST Module (Version: 2.1.6)
Cisco LEAP Module (Version: 1.0.12)
Cisco PEAP Module (Version: 1.0.13)
Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000)
CVE-2012-4969
Destination Component (Version: 110.0.0.0)
DeviceDiscovery (Version: 120.0.194.000)
DocMgr (Version: 120.0.000.000)
DocProc (Version: 12.0.0.0)
ElsterFormular-Upgrade (Version: 13.3.0.9066)
Emsisoft Anti-Malware (Version: 8.0)
Fax (Version: 120.0.194.000)
FreePDF (Remove only)
GamesBar (W) (Version: 3.2.0.36)
Google Chrome (Version: 27.0.1453.116)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.5.4209.2358)
Google Update Helper (Version: 1.3.21.145)
GPBaseService2 (Version: 130.0.371.000)
GPL Ghostscript (Version: 9.02)
HP Customer Participation Program 12.0 (Version: 12.0)
HP Document Manager 2.0 (Version: 2.0)
HP Imaging Device Functions 12.0 (Version: 12.0)
HP Officejet 6500 E709 Series (Version: 12.0)
HP Smart Web Printing (Version: 4.05)
HP Solution Center 13.0 (Version: 13.0)
HPDiagnosticAlert (Version: 1.00.0000)
HPProductAssistant (Version: 130.0.371.000)
HPSSupply (Version: 120.0.194.000)
iCloud (Version: 2.1.2.8)
InboxAce Toolbar
Intel(R) PRO Network Connections 12.2.41.0 (Version: 12.2.41.0)
iTunes (Version: 11.0.4.4)
Java 7 Update 25 (Version: 7.0.250)
Jewel Quest Deluxe (HKCU Version: 1.0.0)
Jewel Quest Solitaire Deluxe (HKCU Version: 1.0.0)
Lexware buchhalter 2008 (Version: 13.00.00.0090)
Lexware buchhalter 2010 (Version: 15.10.00.0010)
Lexware buchhalter Aktualisierung Februar 2008, Version 13.10 (Version: 13.10.00.0015)
Lexware Elster (Version: 10.10.00.0110)
Lexware Info Service (Version: 2.61.00.0033)
MakeDisc (Version: 3.0.2516)
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
MarketResearch (Version: 120.0.226.000)
MCE Software Encoder 1.1 (Version: 1.1.0.1918)
MediaShow (Version: 3.0.4325)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2698023)
Microsoft .NET Framework 1.1 Security Update (KB2742597)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1)
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft VC9 runtime libraries (Version: 2.0.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Works (Version: 9.7.0621)
Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0)
Mozilla Firefox 22.0 (x86 de) (Version: 22.0)
Mozilla Maintenance Service (Version: 22.0)
MSVCSetup (Version: 1.00.0000)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (Version: 4.30.2100.0)
Nero 8 Essentials (Version: 8.10.284)
neroxml (Version: 1.0.0)
Network (Version: 120.0.194.000)
NVIDIA 3D Vision Controller Driver (Version: 280.10)
NVIDIA 3D Vision Controller-Treiber 280.10 (Version: 280.10)
NVIDIA 3D Vision Treiber 311.06 (Version: 311.06)
NVIDIA Grafiktreiber 311.06 (Version: 311.06)
NVIDIA Install Application (Version: 2.1002.108.688)
NVIDIA PhysX (Version: 9.10.0514)
NVIDIA PhysX-Systemsoftware 9.10.0514 (Version: 9.10.0514)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.1106)
NVIDIA Systemsteuerung 311.06 (Version: 311.06)
NVIDIA Update 1.11.3 (Version: 1.11.3)
NVIDIA Update Components (Version: 1.11.3)
OCR Software by I.R.I.S. 12.0 (Version: 12.0)
Online Armor 6.0 (Version: 6.0)
PhotoNow! (Version: 1.0.4310)
PowerDirector (Version: 6.5.2209a)
PowerDVD (Version: 7.0.3118.0)
PowerProducer (Version: 4.2.2504)
ProductContext (Version: 50.0.165.000)
PVSonyDll (Version: 1.00.0001)
QuickTime (Version: 7.74.80.86)
Ralink RT2870 Wireless LAN Card (Version: 1.0.4.0)
RedMon - Redirection Port Monitor
RENESIS® Player Browser Plugins (Version: 1.1.1)
RTC Client API v1.2 (Version: 1.2.0000)
Scan (Version: 12.0.0.0)
Sceneo AbsolutTV
Secunia PSI (3.0.0.7009) (Version: 3.0.0.7009)
Servicepack Datumsaktualisierung (Version: 1.00.00.0005)
Shop for HP Supplies (Version: 12)
SmartWebPrinting (Version: 120.0.194.000)
Snap.Do (Version: 1.28.1.10797)
Snap.Do Engine (HKCU Version: 1.28.1.10797)
SolutionCenter (Version: 130.0.373.000)
SpywareBlaster 5.0 (Version: 5.0.0)
Status (Version: 120.0.194.000)
Toolbox (Version: 120.0.194.000)
TrayApp (Version: 120.0.194.000)
Ulead PhotoImpact 12 (Version: 12.0)
UnloadSupport (Version: 11.0.0)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB2836940) (Version: 1)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update für Microsoft Office Excel 2007 Help (KB963678)
Update für Microsoft Office Powerpoint 2007 Help (KB963669)
Update für Microsoft Office Word 2007 Help (KB963665)
Utility Chest Toolbar
VCRedistSetup (Version: 1.0.0)
WebReg (Version: 120.0.194.000)
Windows Mobile Device Updater Component (Version: 04.08.2345.00)
WinPatrol (Version: 28.1.2013.0)
Zune (Version: 04.08.2345.00)
Zune Language Pack (CHS) (Version: 04.08.2345.00)
Zune Language Pack (CHT) (Version: 04.08.2345.00)
Zune Language Pack (CSY) (Version: 04.08.2345.00)
Zune Language Pack (DAN) (Version: 04.08.2345.00)
Zune Language Pack (DEU) (Version: 04.08.2345.00)
Zune Language Pack (ELL) (Version: 04.08.2345.00)
Zune Language Pack (ESP) (Version: 04.08.2345.00)
Zune Language Pack (FIN) (Version: 04.08.2345.00)
Zune Language Pack (FRA) (Version: 04.08.2345.00)
Zune Language Pack (HUN) (Version: 04.08.2345.00)
Zune Language Pack (IND) (Version: 04.08.2345.00)
Zune Language Pack (ITA) (Version: 04.08.2345.00)
Zune Language Pack (JPN) (Version: 04.08.2345.00)
Zune Language Pack (KOR) (Version: 04.08.2345.00)
Zune Language Pack (MSL) (Version: 04.08.2345.00)
Zune Language Pack (NLD) (Version: 04.08.2345.00)
Zune Language Pack (NOR) (Version: 04.08.2345.00)
Zune Language Pack (PLK) (Version: 04.08.2345.00)
Zune Language Pack (PTB) (Version: 04.08.2345.00)
Zune Language Pack (PTG) (Version: 04.08.2345.00)
Zune Language Pack (RUS) (Version: 04.08.2345.00)
Zune Language Pack (SVE) (Version: 04.08.2345.00)

==================== Restore Points  =========================

04-07-2013 19:29:40 Gerätetreiber-Paketinstallation: TLEM Netzwerkdienst

==================== Hosts content: ==========================

2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {18998898-BEE2-40C0-B357-9ACD9D09D1BE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-14] (Adobe Systems Incorporated)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {447514A3-9452-4789-B411-E5C65175D705} - System32\Tasks\Start Registry Reviver => C:\Program Files\Reviversoft\Registry Reviver\RegistryReviver.exe No File
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation)
Task: {47BBF07F-2C14-478D-B834-588812EC701A} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files\Norton 360\Engine\20.4.0.40\SymErr.exe No File
Task: {511E17BB-0D4E-43E2-894B-6B425BA47C5E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {62A78C06-6A05-4F07-B631-0693ED935194} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation)
Task: {6C23F747-DA4B-492C-9E9D-F32949CE0893} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton 360\Engine\20.4.0.40\WSCStub.exe No File
Task: {95E2B338-1161-4814-9680-A7C997C5AF55} - System32\Tasks\BrowserDefendert => C:\Windows\system32\sc.exe [2006-11-02] (Microsoft Corporation)
Task: {9B38F5FE-9F6E-4FE0-A34A-3F013E6C755D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-11-22] (Google Inc.)
Task: {9CADA731-EECC-44E1-B935-EC53FA3E530F} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - ***** => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {A3C560AA-B9A0-450B-9167-A98E5E35A8E4} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files\Norton 360\Engine\20.4.0.40\SymErr.exe No File
Task: {A4944DD7-4B0D-403F-A359-0CE4E495459C} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe No File
Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation)
Task: {BFCCF36D-4D87-4DE7-8EE1-97209975D68F} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {C2D128C7-930F-4E34-BD90-D8EB71A4ADAD} - System32\Tasks\EPUpdater => C:\Users\HEGGEN~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe No File
Task: {DF89FF18-14C6-47BA-A108-E5BBA33E9277} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-11-22] (Google Inc.)
Task: {E040D26E-843B-4749-9F2E-F9E2EBAE488B} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Faulty Device Manager Devices =============

Name: SM-Bus-Controller
Description: SM-Bus-Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Flash HS-CF
Description: Flash HS-CF
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Generic
Service: WUDFRd
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.

Name: Flash HS-MS/SD
Description: Flash HS-MS/SD
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Generic
Service: WUDFRd
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.

Name: Flash HS-SM
Description: Flash HS-SM
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Generic
Service: WUDFRd
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/04/2013 08:03:02 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\*****\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\SGCQPLK5.DEFAULT\SAFEBROWSING-TO_DELETE> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
        Ein an das System angeschlossenes Gerät funktioniert nicht.  (0x8007001f)

Error: (07/04/2013 08:03:02 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\*****\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\SGCQPLK5.DEFAULT\SAFEBROWSING-BACKUP> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
        Ein an das System angeschlossenes Gerät funktioniert nicht.  (0x8007001f)

Error: (07/04/2013 08:01:18 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen einer Routine auf einem Volumeschattenkopieanbieter "{b5946137-7b9f-4925-af80-51abd60b20d5}" ist ein Fehler aufgetreten. Routinedetails PostFinalCommitSnapshots({64f5b06e-afed-4f35-8a62-8488d5dd72fb}, 1) [hr = 0x80042308].


Vorgang:
  Asynchroner Vorgang wird ausgeführt

Kontext:
  Aktueller Status: DoSnapshotSet

Error: (07/04/2013 08:01:18 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Volume bzw. Datenträger ist nicht richtig angeschlossen oder wurde nicht gefunden.
Fehlerkontext: DeviceIoControl(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1 - 00000148,0x0053c198,0019C948,0,0019B940,4096,[0]).


Vorgang:
  PostFinalCommitSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Error: (07/04/2013 07:59:17 PM) (Source: Application Hang) (User: )
Description: Programm psi.exe, Version 3.0.0.7009 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen.
Prozess-ID: 153c
Anfangszeit: 01ce78dfe74e5650
Zeitpunkt der Beendigung: 812

Error: (07/04/2013 07:59:12 PM) (Source: Application Hang) (User: )
Description: Programm psi.exe, Version 3.0.0.7009 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen.
Prozess-ID: d20
Anfangszeit: 01ce78dfe6a5d1b0
Zeitpunkt der Beendigung: 0

Error: (07/01/2013 07:51:46 PM) (Source: Application Error) (User: )
Description: Fehlerhafte Anwendung fpassist.exe, Version 3.20.0.81, Zeitstempel 0x4cbc9a6f, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset 0x761f9d1f,
Prozess-ID 0xc58, Anwendungsstartzeit fpassist.exe0.

Error: (07/01/2013 07:50:02 PM) (Source: Application Error) (User: )
Description: Fehlerhafte Anwendung PSIA.exe, Version 3.0.0.7009, Zeitstempel 0x516fefa1, fehlerhaftes Modul ntdll.dll, Version 6.0.6002.18541, Zeitstempel 0x4ec3e3d5, Ausnahmecode 0xc0000005, Fehleroffset 0x00067410,
Prozess-ID 0x590, Anwendungsstartzeit PSIA.exe0.

Error: (07/01/2013 07:49:42 PM) (Source: Application Hang) (User: )
Description: Programm psi.exe, Version 3.0.0.7009 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen.
Prozess-ID: db4
Anfangszeit: 01ce76834ecc99e0
Zeitpunkt der Beendigung: 78

Error: (07/01/2013 06:20:53 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.


Vorgang:
  Generatordaten werden gesammelt

Kontext:
  Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
  Generatorname: System Writer
  Generatorinstanz-ID: {432ea787-100c-47e3-81fa-316c703fcd58}


System errors:
=============
Error: (07/06/2013 10:59:04 AM) (Source: Service Control Manager) (User: )
Description: NVIDIA Update Service Daemon%%1069

Error: (07/06/2013 10:59:04 AM) (Source: Service Control Manager) (User: )
Description: nvUpdatusService.\UpdatusUser%%1330

Error: (07/06/2013 10:57:32 AM) (Source: Service Control Manager) (User: )
Description: SRTSP
SymIM

Error: (07/04/2013 10:19:11 PM) (Source: Service Control Manager) (User: )
Description: NVIDIA Update Service Daemon%%1069

Error: (07/04/2013 10:19:11 PM) (Source: Service Control Manager) (User: )
Description: nvUpdatusService.\UpdatusUser%%1330

Error: (07/04/2013 10:18:59 PM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "ROSEN15",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{00474469-B692-4865-B66F-D807289F19-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (07/04/2013 10:17:50 PM) (Source: Service Control Manager) (User: )
Description: SRTSP
SymIM

Error: (07/04/2013 09:43:00 PM) (Source: Service Control Manager) (User: )
Description: NVIDIA Update Service Daemon%%1069

Error: (07/04/2013 09:43:00 PM) (Source: Service Control Manager) (User: )
Description: nvUpdatusService.\UpdatusUser%%1330

Error: (07/04/2013 09:41:35 PM) (Source: Service Control Manager) (User: )
Description: SRTSP
SymIM


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Percentage of memory in use: 56%
Total physical RAM: 3069.45 MB
Available physical RAM: 1344 MB
Total Pagefile: 6367.94 MB
Available Pagefile: 4271.21 MB
Total Virtual: 2047.88 MB
Available Virtual: 1883.97 MB

==================== Drives ================================

Drive c: (BOOT) (Fixed) (Total:445.76 GB) (Free:357.88 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVER) (Fixed) (Total:19.99 GB) (Free:5.22 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 2BAB359D)
Partition 1: (Active) - (Size=446 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended)

==================== End Of Log ============================

Jetzt bin ich aber gespannt :aufsmaul:

Viele Grüße

Sabine99

schrauber 06.07.2013 14:55

Fix mit FRST
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
Code:

C:\Users\*****\AppData\Roaming\Microsoft\Windows\Templates\2433f433
C:\Program Files\WhiteSmoke
C:\Users\*****\AppData\Roaming\WhiteSmoke
C:\Windows.old
HKCU\...\Run: [SearchEngineProtection] C:\Program Files\GamesBar\update\SearchEngineProtection.exe [x]
HKCU\...\Run: [AOL Dialer] C:\Program Files\Common Files\AOL\ACS\AOlDial.exe [x]
ProxyServer: 192.168.1.1:80
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.4.0.40\coIEPlg.dll No File
Toolbar: HKLM - InboxAce - {3775afd7-5921-4571-968f-85a631203d1c} - C:\Program Files\InboxAce_1g\bar\1.bin\1gbar.dll No File
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013"
S3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130704.002\NAVENG.SYS [x]
S3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130704.002\NAVEX15.SYS [x]
2013-07-04 20:17 - 2010-01-24 11:15 - 00000000 ____D C:\ProgramData\Norton

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Fix Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

Sabine99 06.07.2013 15:21

Hallo Schrauber,

und hier das file:
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 04-07-2013
Ran by ***** at 2013-07-06 16:13:47 Run:2
Running from C:\Users\*****\Desktop
Boot Mode: Normal

==============================================

"C:\Users\*****\AppData\Roaming\Microsoft\Windows\Templates\2433f433" => File/Directory not found.
"C:\Program Files\WhiteSmoke" => File/Directory not found.
"C:\Users\*****\AppData\Roaming\WhiteSmoke" => File/Directory not found.
"C:\Windows.old" => File/Directory not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\SearchEngineProtection => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\AOL Dialer => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value deleted successfully.
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{3775afd7-5921-4571-968f-85a631203d1c} => Value deleted successfully.
HKCR\CLSID\{3775afd7-5921-4571-968f-85a631203d1c} => Key deleted successfully.
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013 ==> The Chrome "Settings" can be used to fix the entry.
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013" ==> The Chrome "Settings" can be used to fix the entry.
NAVENG => Service deleted successfully.
NAVEX15 => Service deleted successfully.

"C:\ProgramData\Norton" directory move:

C:\ProgramData\Norton\FSDUI-2011-04-17-19h22m41s.log => Moved successfully.
C:\ProgramData\Norton\FSDUI-2011-04-17-19h29m40s.log => Moved successfully.
C:\ProgramData\Norton\FSDUI-2013-04-14-14h50m47s.log => Moved successfully.
C:\ProgramData\Norton\FSDUI-2013-04-14-14h50m50s.log => Moved successfully.
C:\ProgramData\Norton\FSDUI-2013-04-14-15h00m58s.log => Moved successfully.
C:\ProgramData\Norton\symdata.xml => Moved successfully.
C:\ProgramData\Norton\telemetry.txt => Moved successfully.
C:\ProgramData\Norton\URLS-{N360203036-SHPD-FSD33017}-S-1-5-21-1346077651-4163414706-2657881005-1000.txt => Moved successfully.
C:\ProgramData\Norton\URLS-{N360620009-SHPD-FSD25037}-0.txt => Moved successfully.
C:\ProgramData\Norton\URLS-{N360621005-SHPD-FSD25037}-0.txt => Moved successfully.
C:\ProgramData\Norton\URLS-{N360S_prod_1.6.18_5.0.2.1}-1.txt => Moved successfully.
C:\ProgramData\Norton\URLS-{NIS_prod_UPG_1.5.30_18.1.0.37}-1.txt => Moved successfully.
C:\ProgramData\Norton\{N360620009-SHPD-FSD25037}-0.dat => Moved successfully.
C:\ProgramData\Norton\{N360621005-SHPD-FSD25037}-0.dat => Moved successfully.
C:\ProgramData\Norton\{N360S_prod_1.6.18_5.0.2.1}-1.dat => Moved successfully.
C:\ProgramData\Norton\{NIS_prod_UPG_1.5.30_18.1.0.37}-1.log => Moved successfully.
C:\ProgramData\Norton\{B7B64E4E-97E8-48AA-AF62-F11B5FF9819D}\common.dat => Moved successfully.
C:\ProgramData\Norton\{B7B64E4E-97E8-48AA-AF62-F11B5FF9819D}\5449AE24CA6CB82D53A9B2BC0159B884\shared_1.0.dat => Moved successfully.
C:\ProgramData\Norton\{086A63F0-6B13-4F29-9695-134E7A01E963}\LC.INI => Moved successfully.
C:\ProgramData\Norton\00000082\KeyHist.dat => Moved successfully.
C:\ProgramData\Norton\00000082\0000012a\key.txt => Moved successfully.
C:\ProgramData\Norton\00000082\0000012a\00000657\cltLMS1.dat => Moved successfully.
C:\ProgramData\Norton\00000082\0000012a\00000657\cltLMS2.dat => Moved successfully.
C:\ProgramData\Norton\00000082\00000123\cltupgrade.dat => Moved successfully.
C:\ProgramData\Norton\00000082\00000123\key.txt => Moved successfully.
C:\ProgramData\Norton\00000082\00000123\000005e0\cltLMS1.dat => Moved successfully.
C:\ProgramData\Norton\00000082\00000123\000005e0\cltLMS2.dat => Moved successfully.
C:\ProgramData\Norton\00000082\00000121\cltupgrade.dat => Moved successfully.
C:\ProgramData\Norton\00000082\00000121\key.txt => Moved successfully.
C:\ProgramData\Norton\00000082\00000121\000005d6\cltLMS1.dat => Moved successfully.
C:\ProgramData\Norton\00000082\00000121\000005d6\cltLMS2.dat => Moved successfully.
C:\ProgramData\Norton\00000082\00000114\key.txt => Moved successfully.
C:\ProgramData\Norton\00000082\00000114\000004e7\cltLMS1.dat => Moved successfully.
C:\ProgramData\Norton\00000082\00000114\000004e7\cltLMS2.dat => Moved successfully.
C:\ProgramData\Norton\00000082\000000fb\cltupgrade.dat => Moved successfully.
C:\ProgramData\Norton\00000082\000000fb\key.txt => Moved successfully.
C:\ProgramData\Norton\00000082\000000fb\000002bf\cltLMS1.dat => Moved successfully.
C:\ProgramData\Norton\00000082\000000fb\000002bf\cltLMS2.dat => Moved successfully.
Could not move "C:\ProgramData\Norton" directory. => Scheduled to move on reboot.


=========== Result of Scheduled Files to move ===========
"C:\ProgramData\Norton" => Directory could not move.

==== End of Fixlog ====


Was hat es eigentlich mit window.old auf sich?

Beim Neustart, kam die Meldung "Aufgabenplanungsmodul funktioniert nicht mehr"

Bis später

Sabine99

schrauber 06.07.2013 17:31

Kommt die immer noch? Bitte ein frisches FRST log.

Windows.old entsteht wenn Du Windows neu installierst, aber ohne zu formatieren über die alte version drüber. Oder bei nem Upgrade von Vista auf 7 oder so.
Das ist dein komplettes altes Windows. Eventuell noch mit Seuche drin, auf jeden Fall en Speicherplatz-Fresser.

Sabine99 06.07.2013 17:46

Hallo Schrauber,

anbei das neue FRST.


FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-07-2013
Ran by ***** (administrator) on 06-07-2013 18:41:56
Running from C:\Users\*****\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Emsisoft GmbH) C:\Program Files\Online Armor\OAcat.exe
(Emsisoft GmbH) C:\Program Files\Online Armor\oasrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Secunia) C:\Program Files\Secunia\PSI\PSIA.exe
(Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe
(COMPANYVERS_NAME) C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Lexware GmbH & Co. KG) C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(ODSoft multimedia) C:\Program Files\Sceneo\AbsolutTV\Services\ODSBC\ODSBCApp.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(VER_COMPANY_NAME) C:\Program Files\UtilityChest_49\bar\1.bin\49brmon.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Emsisoft GmbH) C:\Program Files\Online Armor\oaui.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Emsisoft GmbH) C:\Program Files\Online Armor\OAhlp.exe
(BillP Studios) C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Hewlett-Packard Co.) C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RaUI.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\Windows\system32\Taskmgr.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [UpdatePPShortCut] "C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\HomeCinema\PowerProducer" update "Software\CyberLink\PowerProducer\4.0" [222504 2008-01-04] (CyberLink Corp.)
HKLM\...\Run: [Windows Defender] %programfiles%\windows defender\msascui.exe -hide [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [LexwareInfoService] c:\program files\common files\lexware\update manager\lxupdatemanager.exe /autostart [339240 2008-11-03] (Lexware GmbH & Co. KG)
HKLM\...\Run: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\nbkeyscan.exe" [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [RemoteControl] "c:\program files\homecinema\powerdvd\pdvdserv.exe" [71216 2007-02-09] (Cyberlink Corp.)
HKLM\...\Run: [TVBroadcast] c:\program files\sceneo\absoluttv\services\odsbc\odsbcapp.exe [797696 2007-08-08] (ODSoft multimedia)
HKLM\...\Run: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe [90112 2006-11-29] (Ulead Systems, Inc.)
HKLM\...\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM\...\Run: [InboxAce Search Scope Monitor] "C:\PROGRA~1\INBOXA~2\bar\1.bin\1gsrchmn.exe" /m=2 /w /h [x]
HKLM\...\Run: [InboxAce_1g Browser Plugin Loader] C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbrmon.exe [x]
HKLM\...\Run: [Utility Chest Search Scope Monitor] "C:\PROGRA~1\UTILIT~2\bar\1.bin\49srchmn.exe" /m=2 /w /h [44784 2013-06-25] (MindSpark)
HKLM\...\Run: [UtilityChest_49 Browser Plugin Loader] C:\PROGRA~1\UTILIT~2\bar\1.bin\49brmon.exe [30096 2013-06-25] (VER_COMPANY_NAME)
HKLM\...\Run: [NortonSupport] "C:\Program Files\Norton 360\Engine\20.4.0.40\symerr.exe" /supportreboot [x]
HKLM\...\Run: [emsisoft anti-malware] "c:\program files\emsisoft anti-malware\a2guard.exe" /d=60 [2928040 2013-07-02] (Emsisoft GmbH)
HKLM\...\Run: [@OnlineArmor GUI] "C:\Program Files\Online Armor\oaui.exe" [2415104 2012-10-02] (Emsisoft GmbH)
HKCU\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\nmbgmonitor.exe" [202024 2007-10-15] (Nero AG)
HKCU\...\Run: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autorun [1233920 2009-04-11] (Microsoft Corporation)
HKCU\...\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot [423144 2013-04-27] (BillP Studios)
HKCU\...\Policies\system: [disableregistrytools] 0
MountPoints2: {efcd0c81-082c-11df-b5e6-806e6f6e6963} - H:\setup.exe
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
URLSearchHook: (No Name) - {7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
URLSearchHook: (No Name) - {5fdb0cd8-5760-44d1-8d13-a78bf558c3c7} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll No File
HKCU SearchScopes: DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
BHO: Search Assistant BHO - {06e05b40-77fa-40b6-9077-ed1a7577b1ef} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
BHO: GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
BHO: Toolbar BHO - {58f7b5ca-1162-42e8-8bbc-d543b4edd780} - C:\PROGRA~1\UTILIT~2\bar\1.bin\49bar.dll (MindSpark)
BHO: No Name - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -  No File
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Search Assistant BHO - {9359da42-06fb-46f2-9e4a-05c05b98a5ef} - C:\Program Files\InboxAce_1g\bar\1.bin\1gSrcAs.dll No File
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Toolbar BHO - {d5a1d22b-9e17-454f-8ecd-83c578fb3983} - C:\PROGRA~1\INBOXA~2\bar\1.bin\1gbar.dll No File
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - GamesBar (W) - {2e94b700-eafb-4c9e-a696-77200aa3f89b} - C:\Program Files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll ()
Toolbar: HKLM - Utility Chest - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -No Name - {3775AFD7-5921-4571-968F-85A631203D1C} -  No File
Toolbar: HKCU -Utility Chest - {CF67755F-9265-449C-87CF-B945519E073B} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095}
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
ShellExecuteHooks: OA Shell Helper - {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\PROGRA~1\ONLINE~1\oaevent.dll [366440 2012-10-02] (Emsisoft GmbH)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\sgcqplk5.default
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @InboxAce_1g.com/Plugin - C:\Program Files\InboxAce_1g\bar\1.bin\NP1gStub.dll No File
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @UtilityChest_49.com/Plugin - C:\Program Files\UtilityChest_49\bar\1.bin\NP49Stub.dll (MindSpark)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2
FF HKLM\...\Firefox\Extensions: [1gffxtbr@InboxAce_1g.com] C:\Program Files\InboxAce_1g\bar\1.bin
FF HKLM\...\Firefox\Extensions: [49ffxtbr@UtilityChest_49.com] C:\Program Files\UtilityChest_49\bar\1.bin
FF Extension: Utility Chest - C:\Program Files\UtilityChest_49\bar\1.bin
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2

Chrome:
=======
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=TJ&userid=dea475c8-3714-4b9c-9dc7-bc9f234f8bb6&searchtype=hp&installDate=22/06/2013"
CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1
CHR Extension: (Norton Identity Protection) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.11.8_0
CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [2938408 2013-07-02] (Emsisoft GmbH)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 OAcat; C:\Program Files\Online Armor\OAcat.exe [216072 2012-10-02] (Emsisoft GmbH)
R2 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe [75040 2008-09-05] (Ralink Technology, Corp.)
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1227800 2013-04-18] (Secunia)
S2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [659992 2013-04-18] (Secunia)
R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1681408 2007-08-16] (Buhl Data Service GmbH)
R2 SvcOnlineArmor; C:\Program Files\Online Armor\oasrv.exe [4463864 2012-10-02] (Emsisoft GmbH)
R2 UtilityChest_49Service; C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe [42504 2013-06-25] (COMPANYVERS_NAME)

==================== Drivers (Whitelisted) ====================

R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [54072 2012-04-30] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [37856 2012-04-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH)
S3 CH375; C:\Windows\System32\Drivers\CH375WDM.SYS [28403 2011-03-14] (www.winchiphead.com)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50208 2013-07-02] (Emsisoft GmbH)
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc.              )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [645120 2008-08-21] (Ralink Technology Corp.)
R1 OADevice; C:\Windows\system32\drivers\OADriver.sys [208320 2012-10-02] ()
R1 oahlpXX; C:\Windows\system32\drivers\oahlp32.sys [44992 2012-10-02] ()
R1 OAmon; C:\Windows\system32\drivers\OAmon.sys [27648 2012-10-02] (Emsisoft)
R3 OAnet; C:\Windows\System32\DRIVERS\oanet.sys [31768 2012-10-02] (Emsisoft)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1131136 2007-04-03] (Philips Semiconductors GmbH)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-04-18] (Secunia)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-30] (America Online, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S1 SRTSP; \SystemRoot\system32\drivers\N360\1404000.028\SRTSP.SYS [x]
S1 SymIM; system32\DRIVERS\SymIMv.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-06 12:58 - 2013-07-06 12:58 - 00022676 ____A C:\Users\*****\Desktop\Addition.txt
2013-07-06 12:57 - 2013-07-06 16:17 - 00000000 ____D C:\FRST
2013-07-06 12:54 - 2013-07-06 12:55 - 01373373 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-07-04 21:30 - 2013-07-04 21:42 - 00000000 ____D C:\ProgramData\OnlineArmor
2013-07-04 21:30 - 2013-07-04 21:30 - 00000000 ____D C:\Users\*****\AppData\Roaming\OnlineArmor
2013-07-04 21:28 - 2013-07-06 11:02 - 00000000 ____D C:\Program Files\Online Armor
2013-07-04 21:28 - 2012-10-02 15:03 - 00044992 ____A C:\Windows\System32\Drivers\oahlp32.sys
2013-07-04 21:28 - 2012-10-02 15:02 - 00208320 ____A C:\Windows\System32\Drivers\OADriver.sys
2013-07-04 21:28 - 2012-10-02 15:02 - 00031768 ____A (Emsisoft) C:\Windows\System32\Drivers\OAnet.sys
2013-07-04 21:28 - 2012-10-02 15:02 - 00027648 ____A (Emsisoft) C:\Windows\System32\Drivers\OAmon.sys
2013-07-04 21:27 - 2013-07-06 18:41 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-07-04 21:27 - 2013-07-04 21:27 - 00000852 ____A C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-07-04 21:27 - 2013-07-04 21:27 - 00000000 ____D C:\Users\*****\Documents\Anti-Malware
2013-07-04 21:26 - 2013-07-04 21:26 - 221077448 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftInternetSecuritySetup(1).exe
2013-07-04 20:32 - 2013-07-04 20:49 - 221077448 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftInternetSecuritySetup.exe
2013-07-04 20:31 - 2013-07-04 20:48 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(4).exe
2013-07-04 20:31 - 2013-07-04 20:48 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(3).exe
2013-07-04 20:30 - 2013-07-04 20:48 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(1).exe
2013-07-04 20:30 - 2013-07-04 20:46 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup.exe
2013-07-04 20:30 - 2013-07-04 20:45 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(2).exe
2013-07-04 20:02 - 2013-07-04 20:02 - 00867880 ____A C:\Users\*****\Downloads\Norton20_Removal_Tool(1).exe
2013-07-04 19:59 - 2013-07-04 20:01 - 00269952 ____A C:\Windows\msxml4-KB2758694-enu.LOG
2013-07-04 19:58 - 2013-07-04 19:59 - 00867880 ____A C:\Users\*****\Downloads\Norton20_Removal_Tool.exe
2013-07-01 21:20 - 2013-07-01 21:21 - 00000000 ____D C:\Users\*****\Desktop\wot_safe_surfing-20130515-fx
2013-07-01 20:17 - 2013-07-01 20:17 - 00000209 ____A C:\Users\*****\Desktop\AOL.de Kostenlose Email, Nachrichten & Wetter, Finanzen , Sport und Star-News auf AOL.de.URL
2013-07-01 19:58 - 2013-07-01 19:58 - 02434048 ____A C:\Users\*****\Downloads\msxml.msi
2013-07-01 19:58 - 2013-07-01 19:58 - 02434048 ____A C:\Users\*****\Downloads\msxml(1).msi
2013-07-01 19:49 - 2013-07-01 19:49 - 00000000 ____D C:\Users\*****\AppData\Local\Secunia PSI
2013-07-01 19:28 - 2013-07-01 19:28 - 00448512 ____A (OldTimer Tools) C:\Users\*****\Downloads\TFC.exe
2013-07-01 19:22 - 2013-07-03 18:59 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-07-01 19:22 - 2013-07-01 19:57 - 00000810 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-01 19:22 - 2013-07-01 19:22 - 00000000 ____D C:\Users\*****\AppData\Roaming\Mozilla
2013-07-01 19:22 - 2013-07-01 19:22 - 00000000 ____D C:\Users\*****\AppData\Local\Mozilla
2013-07-01 19:22 - 2013-07-01 19:22 - 00000000 ____D C:\ProgramData\Mozilla
2013-07-01 19:18 - 2013-07-01 19:18 - 00376576 ____A C:\Users\*****\Desktop\wot_safe_surfing-20130515-fx.zip
2013-07-01 19:12 - 2013-07-01 19:12 - 00140125 ____A C:\Users\*****\Desktop\hosts.zip
2013-07-01 18:44 - 2013-07-01 18:44 - 00000000 ____D C:\ProgramData\Licenses
2013-07-01 18:44 - 2013-07-01 18:43 - 00867240 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-07-01 18:44 - 2013-07-01 18:43 - 00263592 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-07-01 18:44 - 2013-07-01 18:43 - 00175016 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-07-01 18:44 - 2013-07-01 18:43 - 00175016 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-07-01 18:44 - 2013-07-01 18:43 - 00094632 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
2013-07-01 18:43 - 2013-07-01 18:49 - 00000000 ____D C:\Program Files\SpywareBlaster
2013-07-01 18:43 - 2013-07-01 18:43 - 04095448 ____A (BrightFort LLC                                              ) C:\Users\*****\Downloads\spywareblastersetup50.exe
2013-07-01 18:43 - 2013-07-01 18:43 - 00000840 ____A C:\Users\Public\Desktop\SpywareBlaster.lnk
2013-07-01 18:41 - 2013-07-01 21:20 - 00000000 ____D C:\ProgramData\InstallMate
2013-07-01 18:41 - 2013-07-01 18:41 - 00000000 ____D C:\Users\*****\AppData\Roaming\WinPatrol
2013-07-01 18:41 - 2013-07-01 18:41 - 00000000 ____D C:\Program Files\BillP Studios
2013-07-01 18:40 - 2013-07-01 18:40 - 00906440 ____A (BillP Studios) C:\Users\*****\Desktop\wpsetup.exe
2013-07-01 18:39 - 2013-07-01 18:39 - 00906440 ____A (BillP Studios) C:\Users\*****\Downloads\wpsetup.exe
2013-07-01 18:35 - 2013-07-01 18:35 - 00000870 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-01 18:35 - 2013-07-01 18:35 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes
2013-07-01 18:35 - 2013-07-01 18:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-01 18:35 - 2013-07-01 18:35 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-01 18:35 - 2013-04-04 14:50 - 00022856 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-07-01 18:34 - 2013-07-01 18:34 - 10285040 ____A (Malwarebytes Corporation                                    ) C:\Users\*****\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-01 18:33 - 2013-07-01 18:33 - 00000000 ____D C:\Program Files\Secunia
2013-07-01 18:20 - 2013-07-01 18:20 - 00000000 ____D C:\Windows\ERUNT
2013-06-28 18:35 - 2013-06-28 18:35 - 00000000 ____D C:\Windows\erdnt
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:17 - 2013-06-27 18:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 19:58 - 2013-07-01 18:19 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:18 - 2012-08-21 13:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2013-06-17 06:17 - 2013-06-17 06:18 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2013-06-17 06:17 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-14 13:38 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-14 13:38 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-14 13:38 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-14 13:38 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-14 13:38 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-14 13:38 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-14 13:38 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-14 13:38 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-14 13:38 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-14 13:38 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-14 13:38 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-14 13:38 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-14 13:38 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-14 13:32 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-14 13:31 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-14 13:31 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-14 13:31 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-14 13:31 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-14 13:31 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-14 13:31 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-14 13:31 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll

==================== One Month Modified Files and Folders ========

2013-07-06 18:41 - 2013-07-04 21:27 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-07-06 18:40 - 2010-01-23 16:48 - 02005731 ____A C:\Windows\WindowsUpdate.log
2013-07-06 18:36 - 2011-11-22 19:11 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-06 18:35 - 2010-01-24 10:55 - 00000000 ____D C:\ProgramData\NVIDIA
2013-07-06 18:35 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-06 18:35 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-06 18:35 - 2006-11-02 14:47 - 00003264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-06 18:34 - 2006-11-02 15:01 - 00032534 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-06 17:51 - 2011-11-22 19:11 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-06 17:50 - 2012-08-22 20:11 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-06 16:17 - 2013-07-06 12:57 - 00000000 ____D C:\FRST
2013-07-06 16:16 - 2010-12-28 12:53 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps
2013-07-06 16:13 - 2010-01-24 11:15 - 00000000 ____D C:\ProgramData\Norton
2013-07-06 12:58 - 2013-07-06 12:58 - 00022676 ____A C:\Users\*****\Desktop\Addition.txt
2013-07-06 12:55 - 2013-07-06 12:54 - 01373373 ____A (Farbar) C:\Users\*****\Desktop\FRST.exe
2013-07-06 11:02 - 2013-07-04 21:28 - 00000000 ____D C:\Program Files\Online Armor
2013-07-04 21:42 - 2013-07-04 21:30 - 00000000 ____D C:\ProgramData\OnlineArmor
2013-07-04 21:30 - 2013-07-04 21:30 - 00000000 ____D C:\Users\*****\AppData\Roaming\OnlineArmor
2013-07-04 21:29 - 2010-01-23 17:06 - 00000000 ___AD C:\users\*****
2013-07-04 21:27 - 2013-07-04 21:27 - 00000852 ____A C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-07-04 21:27 - 2013-07-04 21:27 - 00000000 ____D C:\Users\*****\Documents\Anti-Malware
2013-07-04 21:26 - 2013-07-04 21:26 - 221077448 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftInternetSecuritySetup(1).exe
2013-07-04 20:49 - 2013-07-04 20:32 - 221077448 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftInternetSecuritySetup.exe
2013-07-04 20:48 - 2013-07-04 20:31 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(4).exe
2013-07-04 20:48 - 2013-07-04 20:31 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(3).exe
2013-07-04 20:48 - 2013-07-04 20:30 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(1).exe
2013-07-04 20:46 - 2013-07-04 20:30 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup.exe
2013-07-04 20:45 - 2013-07-04 20:30 - 190580728 ____A (Emsisoft GmbH                                              ) C:\Users\*****\Downloads\EmsisoftAntiMalwareSetup(2).exe
2013-07-04 20:19 - 2010-01-23 17:02 - 01324818 ____A C:\Windows\PFRO.log
2013-07-04 20:17 - 2010-01-24 11:16 - 00000000 ____D C:\ProgramData\Symantec
2013-07-04 20:02 - 2013-07-04 20:02 - 00867880 ____A C:\Users\*****\Downloads\Norton20_Removal_Tool(1).exe
2013-07-04 20:01 - 2013-07-04 19:59 - 00269952 ____A C:\Windows\msxml4-KB2758694-enu.LOG
2013-07-04 19:59 - 2013-07-04 19:58 - 00867880 ____A C:\Users\*****\Downloads\Norton20_Removal_Tool.exe
2013-07-03 19:16 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-07-03 18:59 - 2013-07-01 19:22 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-07-01 21:58 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-01 21:21 - 2013-07-01 21:20 - 00000000 ____D C:\Users\*****\Desktop\wot_safe_surfing-20130515-fx
2013-07-01 21:20 - 2013-07-01 18:41 - 00000000 ____D C:\ProgramData\InstallMate
2013-07-01 20:17 - 2013-07-01 20:17 - 00000209 ____A C:\Users\*****\Desktop\AOL.de Kostenlose Email, Nachrichten & Wetter, Finanzen , Sport und Star-News auf AOL.de.URL
2013-07-01 20:14 - 2010-01-26 15:52 - 00002633 ____A C:\Users\*****\Desktop\Microsoft Office PowerPoint 2007.lnk
2013-07-01 20:12 - 2012-08-07 19:40 - 00000000 ____D C:\Program Files\EcrSystem
2013-07-01 19:59 - 2007-09-26 14:08 - 00000000 ____D C:\Program Files\MSXML 4.0
2013-07-01 19:58 - 2013-07-01 19:58 - 02434048 ____A C:\Users\*****\Downloads\msxml.msi
2013-07-01 19:58 - 2013-07-01 19:58 - 02434048 ____A C:\Users\*****\Downloads\msxml(1).msi
2013-07-01 19:57 - 2013-07-01 19:22 - 00000810 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-01 19:57 - 2011-10-21 13:08 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-07-01 19:49 - 2013-07-01 19:49 - 00000000 ____D C:\Users\*****\AppData\Local\Secunia PSI
2013-07-01 19:28 - 2013-07-01 19:28 - 00448512 ____A (OldTimer Tools) C:\Users\*****\Downloads\TFC.exe
2013-07-01 19:22 - 2013-07-01 19:22 - 00000000 ____D C:\Users\*****\AppData\Roaming\Mozilla
2013-07-01 19:22 - 2013-07-01 19:22 - 00000000 ____D C:\Users\*****\AppData\Local\Mozilla
2013-07-01 19:22 - 2013-07-01 19:22 - 00000000 ____D C:\ProgramData\Mozilla
2013-07-01 19:18 - 2013-07-01 19:18 - 00376576 ____A C:\Users\*****\Desktop\wot_safe_surfing-20130515-fx.zip
2013-07-01 19:12 - 2013-07-01 19:12 - 00140125 ____A C:\Users\*****\Desktop\hosts.zip
2013-07-01 18:49 - 2013-07-01 18:43 - 00000000 ____D C:\Program Files\SpywareBlaster
2013-07-01 18:44 - 2013-07-01 18:44 - 00000000 ____D C:\ProgramData\Licenses
2013-07-01 18:43 - 2013-07-01 18:44 - 00867240 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-07-01 18:43 - 2013-07-01 18:44 - 00263592 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-07-01 18:43 - 2013-07-01 18:44 - 00175016 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-07-01 18:43 - 2013-07-01 18:44 - 00175016 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-07-01 18:43 - 2013-07-01 18:44 - 00094632 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
2013-07-01 18:43 - 2013-07-01 18:43 - 04095448 ____A (BrightFort LLC                                              ) C:\Users\*****\Downloads\spywareblastersetup50.exe
2013-07-01 18:43 - 2013-07-01 18:43 - 00000840 ____A C:\Users\Public\Desktop\SpywareBlaster.lnk
2013-07-01 18:43 - 2010-06-23 08:47 - 00789416 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-07-01 18:43 - 2010-01-23 18:54 - 00000000 ____D C:\Program Files\Java
2013-07-01 18:41 - 2013-07-01 18:41 - 00000000 ____D C:\Users\*****\AppData\Roaming\WinPatrol
2013-07-01 18:41 - 2013-07-01 18:41 - 00000000 ____D C:\Program Files\BillP Studios
2013-07-01 18:40 - 2013-07-01 18:40 - 00906440 ____A (BillP Studios) C:\Users\*****\Desktop\wpsetup.exe
2013-07-01 18:39 - 2013-07-01 18:39 - 00906440 ____A (BillP Studios) C:\Users\*****\Downloads\wpsetup.exe
2013-07-01 18:35 - 2013-07-01 18:35 - 00000870 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-01 18:35 - 2013-07-01 18:35 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes
2013-07-01 18:35 - 2013-07-01 18:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-01 18:35 - 2013-07-01 18:35 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-01 18:34 - 2013-07-01 18:34 - 10285040 ____A (Malwarebytes Corporation                                    ) C:\Users\*****\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-01 18:33 - 2013-07-01 18:33 - 00000000 ____D C:\Program Files\Secunia
2013-07-01 18:20 - 2013-07-01 18:20 - 00000000 ____D C:\Windows\ERUNT
2013-07-01 18:19 - 2013-06-22 19:58 - 00000680 ____A C:\Users\*****\AppData\Local\d3d9caps.dat
2013-06-30 21:49 - 2012-05-21 20:02 - 00000000 ____D C:\Users\*****\AppData\Roaming\Apple Computer
2013-06-28 18:35 - 2013-06-28 18:35 - 00000000 ____D C:\Windows\erdnt
2013-06-27 18:59 - 2010-01-26 15:57 - 00002591 ____A C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk
2013-06-27 18:44 - 2013-06-22 20:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Users\*****\AppData\Local\UtilityChest_49
2013-06-25 06:39 - 2013-06-25 06:39 - 00000000 ____D C:\Program Files\UtilityChest_49
2013-06-23 11:46 - 2013-06-23 11:46 - 00032092 ____A C:\Users\*****\Documents\FRST.txt
2013-06-23 11:46 - 2013-06-23 11:46 - 00019001 ____A C:\Users\*****\Documents\Addition.txt
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\InboxAce_1g
2013-06-23 11:26 - 2013-06-23 11:26 - 00000000 ____D C:\Users\*****\AppData\Local\IAC
2013-06-22 20:23 - 2013-06-22 20:23 - 00000000 ____D C:\Program Files\7-Zip
2013-06-22 20:16 - 2013-06-22 20:16 - 00000000 ____D C:\Users\*****\AppData\Roaming\Opera
2013-06-22 20:08 - 2013-06-22 20:08 - 00006252 ____A C:\Windows\System32\PerfStringBackup.TMP
2013-06-22 20:04 - 2011-04-17 19:29 - 00000000 ____D C:\Windows\System32\Drivers\N360
2013-06-22 19:54 - 2013-01-09 21:21 - 00001935 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-17 06:19 - 2013-06-17 06:19 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-17 06:19 - 2010-01-26 10:43 - 00000000 ____D C:\Users\*****\AppData\Local\Apple Computer
2013-06-17 06:18 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iTunes
2013-06-17 06:17 - 2013-06-17 06:17 - 00000000 ____D C:\Program Files\iPod
2013-06-17 06:17 - 2013-06-17 06:09 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-17 06:17 - 2010-02-13 14:59 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-06-17 06:17 - 2010-02-13 14:54 - 00000000 ____D C:\ProgramData\Apple
2013-06-17 06:13 - 2013-06-17 06:13 - 00000000 ____D C:\Program Files\Bonjour
2013-06-17 06:09 - 2012-05-21 06:11 - 00001690 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2013-06-17 06:09 - 2008-01-23 14:46 - 00000000 ____D C:\Program Files\QuickTime
2013-06-14 16:48 - 2012-08-22 20:11 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-14 16:48 - 2011-09-04 07:42 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-14 16:43 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-14 13:36 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-06 18:41

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---


Heißt das, dass ich Windows.old wenn wir fertig sind einfach löschen kann?
Die Meldung kommt nicht mehr, habe eben neu gestartet.

Grüße
Sabine99

schrauber 06.07.2013 17:55

Genau :)

Wie kann ich den Ordner "Windows.old" entfernen?

Sabine99 06.07.2013 18:27

HI Schrauber,

vielleicht bin ich je ein bischen dumm, aber ich finde keine Möglichkeit Systemdateien zu bereinigen.
Zuerst kommt nur eigene Dateien oder alle Benutzer, danach erscheinen nur zwei Registerkarten: Datenträgerbereinigung und weitere Optionen. Von Systemdateien bereinigen finde ich leider nichts. Bin vielleicht einfach blind?

Grüße

Sabine99

schrauber 07.07.2013 06:08

Mach mir mal bitte nen Screenshot von dem was Du siehst :)

Sabine99 07.07.2013 09:55

Liste der Anhänge anzeigen (Anzahl: 1)
Hallo Schrauber,

ich habe gerade bemerkt, dass der link für windows 7 war, ich habe auf dem PC Vista.
Brauchst Du den screen shot noch, sorry, das hab ich gestern nicht bemerkt.

Ich füge ihn einfach mal ein.



Grüße
Sabine99

schrauber 07.07.2013 10:10

Versuch das mal, aber in der Regel geht es auf allen Betriebssystemen gleich :)

Entfernen des Windows.old-Ordners, der generiert wird, wenn Sie eine benutzerdefinierte Installation von Windows Vista so durchführen

Sabine99 07.07.2013 10:28

Hallo Schrauber,

ich habe es jetzt nach der anderen Aleitung versucht. Ich finde auch hier keine früheren Windows Installationen. Kann es sein, dass es nicht funktioniert, da sich Windows.old nun unter C:FRST in Quarantäne befindet?

Sorry für meine "dummen" Fragen.

Sabine99

schrauber 07.07.2013 10:32

Ja wenn der Ordner C:\Windows.old gar nicht mehr da ist kanns auch nit gehen :)


Alle Zeitangaben in WEZ +1. Es ist jetzt 11:58 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20