Zitat:
Zitat von schrauber
(Beitrag 1181259)
poste mal ein frisches FRST log. |
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-10-2013
Ran by opa (administrator) on DELL-PC on 25-10-2013 10:16:07
Running from C:\Users\opa\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
() C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Frogmore Computer Services Ltd) C:\Program Files (x86)\Print Distributor 4\pd3service.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(www.shadowexplorer.com) C:\Program Files (x86)\ShadowExplorer\sesvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(lucky leap) C:\Program Files (x86)\lucky leap\updateluckyleap.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(YouSendit Inc.) C:\Program Files (x86)\YouSendIt Desktop App\YSIAgent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(OrdinarySoft) C:\Program Files\Start Menu X\StartMenuX.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Network Associates Technology, Inc.) C:\Program Files (x86)\Network Associates\PGP\PGPtray.exe
(Thornsoft Development, Inc.) C:\Program Files (x86)\ClipMate5\ClipMt53.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
() C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files (x86)\SpamPal\spampal.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Akamai Technologies, Inc.) C:\Users\opa\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\opa\AppData\Local\Akamai\netsession_win.exe
(lucky leap) C:\Program Files (x86)\lucky leap\bin\utilluckyleap.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\net.exe
(Microsoft Corporation) C:\Windows\SysWOW64\net1.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2370856 2010-09-24] (Synaptics Incorporated)
HKLM\...\Run: [FreeFallProtection] - C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686704 2010-12-17] ()
HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] ()
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-11-01] (Intel(R) Corporation)
HKLM\...\Run: [Yousendit Sync Agent] - C:\Program Files (x86)\YouSendIt Desktop App\YSIAgent.exe [5344376 2012-05-23] (YouSendit Inc.)
HKLM\...\Run: [DellStage] - C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj [483424 2012-02-01] ()
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7284328 2011-08-30] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-16] (Realtek Semiconductor)
HKLM-x32\...\RunOnce: [Launcher] - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe [163040 2010-08-12] (Softthinks)
HKLM-x32\...\RunOnce: [DSUpdateLauncher] - "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe" [161088 2010-07-21] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Screenpresso] - C:\Users\opa\AppData\Local\LearnPulse\Screenpresso\Screenpresso.exe [8646160 2013-10-13] (Learnpulse)
HKCU\...\Run: [StartMenuX] - C:\Program Files\Start Menu X\StartMenuX.exe [7671104 2013-09-28] (OrdinarySoft)
HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\opa\AppData\Local\Akamai\netsession_win.exe [4441920 2012-10-09] (Akamai Technologies, Inc.)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20472992 2013-10-02] (Skype Technologies S.A.)
HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [487562 2010-08-20] (Creative Technology Ltd)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [RoxWatchTray] - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048 2011-09-16] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [AccuWeatherWidget] - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj [2835443 2012-02-01] ()
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-05] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2249352 2013-06-27] (Microsoft Corp.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\Administrator\...\Run: [VistaStartMenu] - "C:\Program Files (x86)\Vista Start Menu\VistaStartMenu.exe"
HKU\Administrator\...\Run: [XSubst] - C:\totalcmd\Xsubst\XSubst.exe [274432 2008-10-11] (Luke Filewalker Productions)
HKU\Administrator\...\Run: [Screenpresso] - C:\Users\opa\AppData\Local\LearnPulse\Screenpresso\Screenpresso.exe [8646160 2013-10-13] (Learnpulse)
HKU\Administrator\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20472992 2013-10-02] (Skype Technologies S.A.)
HKU\Administrator\...\Run: [StartMenuX] - C:\Program Files\Start Menu X\StartMenuX.exe [7671104 2013-09-28] (OrdinarySoft)
HKU\UpdatusUser\...\Run: [VistaStartMenu] - C:\Program Files (x86)\Vista Start Menu\VistaStartMenu.exe
HKU\UpdatusUser\...\Run: [XSubst] - C:\totalcmd\Xsubst\XSubst.exe [274432 2008-10-11] (Luke Filewalker Productions)
HKU\UpdatusUser\...\Run: [Screenpresso] - C:\Users\opa\AppData\Local\LearnPulse\Screenpresso\Screenpresso.exe [8646160 2013-10-13] (Learnpulse)
HKU\UpdatusUser\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20472992 2013-10-02] (Skype Technologies S.A.)
HKU\UpdatusUser\...\Run: [StartMenuX] - C:\Program Files\Start Menu X\StartMenuX.exe [7671104 2013-09-28] (OrdinarySoft)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\Windows\SysWOW64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Überwachungstool für die Intel® Turbo-Boost-Technik 2.0.lnk
ShortcutTarget: Überwachungstool für die Intel® Turbo-Boost-Technik 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
Startup: C:\Users\opa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ClipMate53.lnk
ShortcutTarget: ClipMate53.lnk -> C:\Program Files (x86)\ClipMate5\ClipMt53.exe (Thornsoft Development, Inc.)
Startup: C:\Users\opa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpamPal.lnk
ShortcutTarget: SpamPal.lnk -> C:\Program Files (x86)\SpamPal\spampal.exe ()
Startup: C:\Users\opa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Überwachungstool für die Intel® Turbo-Boost-Technik 2.0.lnk
ShortcutTarget: Überwachungstool für die Intel® Turbo-Boost-Technik 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://dsl-start.computerbild.de/?ie=10
hxxp://www.google.de/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {1FEA2C30-9E62-4562-8AA4-BBFEEAFB2E16} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {1FEA2C30-9E62-4562-8AA4-BBFEEAFB2E16} URL =
SearchScopes: HKCU - {1FEA2C30-9E62-4562-8AA4-BBFEEAFB2E16} URL =
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: lucky leap - {d77aa852-def3-43cb-a3f5-bd679de72f32} - C:\Program Files (x86)\lucky leap\luckyleapbho.dll (luckyleap)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} hxxp://support.euro.dell.com/systemprofiler/SysProExe.CAB
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{E6DED57B-F633-4D0B-BA0E-45011A00027C}: [NameServer]8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
FireFox:
========
FF ProfilePath: C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default
FF SearchEngineOrder.3: Bing
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @parallelgraphics.com/Cortona - C:\Program Files (x86)\Common Files\ParallelGraphics\Cortona\npcortona.dll (ParallelGraphics)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\searchplugins\bing-.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Deutsches Wörterbuch - C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\Extensions\de-DE@dictionaries.addons.mozilla.org
FF Extension: Wörterbuch Deutsch (de-DE), Hunspell-unterstützt - C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\Extensions\de_DE@dicts.j3e.de
FF Extension: Super Start - C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\Extensions\superstart@enjoyfreeware.org
FF Extension: bing.search.for.firefox - C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\Extensions\bing.search.for.firefox@firefox.bing.xpi
FF Extension: firefox - C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\Extensions\firefox@luckyleap.net.xpi
FF Extension: notreal.ccoptions - C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\Extensions\notreal.ccoptions@environmentalchemistry.com.xpi
FF Extension: No Name - C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\Extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi
FF Extension: No Name - C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\Extensions\{20C3BDFF-DA68-468d-8D9A-F5A6C76B0F9E}.xpi
FF Extension: No Name - C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\Extensions\{398e77b8-2304-11dc-8314-0800200c9a66}.xpi
FF Extension: No Name - C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\Extensions\{D46E8522-6E86-44b1-A622-58C0668AD78E}.xpi
FF Extension: No Name - C:\Users\opa\AppData\Roaming\Mozilla\Firefox\Profiles\wzftofpt.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
Chrome:
=======
CHR HomePage: hxxp://feed.snapdo.com/?publisher=Somoto&dpid=Somoto&co=DE&userid=4348e4b5-64ae-8a56-f783-d79d02386c4e&searchtype=hp&installDate=21/10/2013
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=Somoto&dpid=Somoto&co=DE&userid=4348e4b5-64ae-8a56-f783-d79d02386c4e&searchtype=hp&installDate=21/10/2013"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Cortona3D Viewer) - C:\Program Files (x86)\Common Files\ParallelGraphics\Cortona\npcortona.dll (ParallelGraphics)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Windows Live\u00C2 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Extension: (Speed Test Analysis) - C:\Users\opa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb\1.0.0.4_0
CHR Extension: (Skype Click to Call) - C:\Users\opa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0
CHR HKLM-x32\...\Chrome\Extension: [eiimolhnbbbdagljikeckdkldgemmmlj] - C:\Program Files (x86)\lucky leap\eiimolhnbbbdagljikeckdkldgemmmlj.crx
CHR HKLM-x32\...\Chrome\Extension: [kckgnnipheglejoddfhekdjpbdbinhmb] - C:\Users\opa\AppData\Roaming\SpeedTestAnalysis\speedtestanalysis.crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-05] (Avira Operations GmbH & Co. KG)
R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-27] (Microsoft Corp.)
S3 COMSysApp; C:\Windows\SysWow64\dllhost.exe [7168 2009-07-14] (Microsoft Corporation)
R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-10-07] ()
S3 msiserver; C:\Windows\SysWow64\msiexec.exe [73216 2010-11-21] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-11-01] ()
R2 Print Distributor 4; C:\\Program Files (x86)\\Print Distributor 4\\pd3service.exe [869112 2009-09-24] (Frogmore Computer Services Ltd)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.)
S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP4c\RpcAgentSrv.exe [68760 2009-06-13] (SiSoftware)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
S3 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-10-14] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-10-14] (Secunia)
R2 sesvc; C:\Program Files (x86)\ShadowExplorer\sesvc.exe [9216 2011-01-02] (www.shadowexplorer.com)
R2 Update lucky leap; C:\Program Files (x86)\lucky leap\updateluckyleap.exe [65312 2013-10-03] (lucky leap)
R2 Util lucky leap; C:\Program Files (x86)\lucky leap\bin\utilluckyleap.exe [65312 2013-10-25] (lucky leap)
R2 WSearch; C:\Windows\SysWow64\SearchIndexer.exe [427520 2011-05-04] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 AVer7231_x64; C:\Windows\System32\DRIVERS\AVer7231_x64.sys [1799808 2010-06-11] (AVerMedia TECHNOLOGIES, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-05-01] (Avira Operations GmbH & Co. KG)
S3 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769816 2011-07-09] (www.ext2fsd.com)
R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [284008 2012-10-08] (NVIDIA Corporation)
S3 NvStUSB; C:\Windows\system32\drivers\nvstusb.sys [121960 2011-01-31] ()
S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-10-14] (Secunia)
S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP4c\WNt500x64\Sandra.sys [23112 2009-08-07] (SiSoftware)
R1 se64a; C:\Windows\System32\Drivers\se64a.sys [14032 2007-05-03] (EnTech Taiwan)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [105816 2012-10-26] (Oracle Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 AVFSFilter; system32\DRIVERS\avfsfilter.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S2 PGPmemlock; \??\C:\Windows\system32\drivers\PGPmemlock.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-25 10:12 - 2013-10-25 10:13 - 00031917 _____ C:\Users\opa\Desktop\Addition.txt
2013-10-25 10:12 - 2013-10-25 10:12 - 00000000 ____D C:\FRST
2013-10-25 10:10 - 2013-10-25 10:10 - 01955412 _____ (Farbar) C:\Users\opa\Desktop\FRST64.exe
2013-10-25 08:49 - 2013-10-25 08:49 - 102895398 _____ C:\Windows\SysWOW64\氞⍢ᤴ”
2013-10-25 08:48 - 2013-10-25 08:48 - 00000022 _____ C:\Windows\S.dirmngr
2013-10-25 08:47 - 2013-10-25 08:47 - 00000056 _____ C:\Windows\setupact.log
2013-10-25 08:47 - 2013-10-25 08:47 - 00000000 _____ C:\Windows\setuperr.log
2013-10-24 11:36 - 2013-10-24 11:36 - 00000726 _____ C:\Users\opa\Desktop\DelFix.txt
2013-10-24 11:36 - 2013-10-24 11:36 - 00000726 _____ C:\DelFix.txt
2013-10-24 09:33 - 2013-10-24 09:33 - 00000000 ____D C:\Users\opa\AppData\Local\WinZip
2013-10-24 09:33 - 2013-10-24 09:33 - 00000000 ____D C:\ProgramData\WinZip
2013-10-24 09:33 - 2013-10-24 09:33 - 00000000 ____D C:\Program Files (x86)\WinZip
2013-10-23 20:16 - 2013-10-23 20:16 - 00000872 _____ C:\Users\opa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Temp File Cleaner.lnk
2013-10-23 20:16 - 2013-10-23 20:16 - 00000842 _____ C:\Users\opa\Desktop\Temp File Cleaner.lnk
2013-10-23 20:16 - 2013-10-23 20:16 - 00000000 ____D C:\Users\opa\AppData\Roaming\addpcs
2013-10-23 20:16 - 2013-10-23 20:16 - 00000000 ____D C:\Program Files\Temp File Cleaner
2013-10-23 20:15 - 2013-10-25 08:52 - 00000000 ____D C:\Program Files (x86)\lucky leap
2013-10-23 17:45 - 2013-10-23 17:45 - 00000000 ____D C:\Program Files\jameica
2013-10-23 17:17 - 2013-10-23 17:17 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-23 17:17 - 2013-10-23 17:17 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-23 17:17 - 2013-10-23 17:17 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-23 17:17 - 2013-10-23 17:17 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-10-23 17:17 - 2013-10-23 17:17 - 00000000 ____D C:\Program Files\Java
2013-10-23 17:14 - 2013-10-23 17:17 - 00000000 ____D C:\ProgramData\Oracle
2013-10-23 17:14 - 2013-10-23 17:14 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-23 17:14 - 2013-10-23 17:14 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-23 17:14 - 2013-10-23 17:14 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-23 17:14 - 2013-10-23 17:14 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-23 16:42 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2013-10-23 16:36 - 2013-10-23 16:37 - 00000085 _____ C:\Windows\wininit.ini
2013-10-22 19:25 - 2013-10-23 13:27 - 00000000 ____D C:\Users\opa\AppData\Local\FileTypeAssistant
2013-10-22 19:16 - 2013-10-25 10:14 - 00000000 ____D C:\ProgramData\boost_interprocess
2013-10-22 19:13 - 2013-10-22 19:13 - 00000000 ____D C:\Windows\ERUNT
2013-10-22 11:30 - 2013-10-22 12:17 - 00000000 ____D C:\Windows\erdnt
2013-10-21 17:30 - 2013-10-21 17:30 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2013-10-21 17:07 - 2013-10-21 17:07 - 00001687 _____ C:\Users\opa\Desktop\Becky!-Help.lnk
2013-10-21 15:40 - 2013-10-21 15:41 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP
2013-10-21 14:57 - 2013-10-21 14:57 - 00000000 _____ C:\autoexec.bat
2013-10-21 11:28 - 2013-10-21 16:12 - 00000000 ____D C:\Users\opa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat
2013-10-21 11:27 - 2013-10-21 11:27 - 00002380 _____ C:\Users\opa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2013-10-21 11:26 - 2013-10-21 11:26 - 00003238 _____ C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart
2013-10-21 10:49 - 2013-10-21 10:49 - 00025106 _____ C:\Windows\SysWOW64\opa.reg
2013-10-20 14:28 - 2013-10-20 14:28 - 00000000 ____D C:\Program Files\Movie Maker
2013-10-20 14:28 - 2013-10-20 14:28 - 00000000 ____D C:\drmsoft
2013-10-19 15:46 - 2013-10-19 15:46 - 00000000 ____D C:\Users\opa\AppData\Roaming\Malwarebytes
2013-10-19 15:45 - 2013-10-19 15:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-19 15:45 - 2013-10-19 15:45 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-19 15:45 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-18 17:42 - 2013-09-06 14:27 - 00238352 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2013-10-18 17:42 - 2013-09-06 14:25 - 00119056 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2013-10-18 17:24 - 2013-10-18 17:24 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-10-18 15:44 - 2013-10-18 15:44 - 00000000 ____D C:\Users\opa\AppData\Local\Secunia PSI
2013-10-17 13:42 - 2013-10-17 13:42 - 00002036 _____ C:\Users\opa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autostart - Verknüpfung.lnk
2013-10-14 12:04 - 2013-10-14 12:04 - 00018456 _____ (Secunia) C:\Windows\system32\Drivers\psi_mf_amd64.sys
2013-10-13 18:31 - 2013-10-23 17:47 - 00001418 _____ C:\Users\opa\Desktop\Homebanking mit jameica-win64-Hibiscus.lnk
2013-10-13 18:26 - 2013-10-13 18:28 - 00000128 _____ C:\Users\opa\.jameica.properties
2013-10-13 12:35 - 2013-09-04 03:37 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-13 12:35 - 2013-09-04 03:37 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-13 12:35 - 2013-09-04 03:37 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-13 12:35 - 2013-09-04 03:37 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-13 12:35 - 2013-09-04 03:37 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-13 12:35 - 2013-09-04 03:37 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-13 12:35 - 2013-09-04 03:37 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-13 12:05 - 2013-10-13 12:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-10-13 12:01 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-13 12:01 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-13 12:01 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-13 12:01 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-13 12:01 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-13 12:01 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-13 12:01 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-13 12:01 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-13 12:01 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-13 12:01 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-13 12:01 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-13 12:01 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-13 12:01 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-13 12:01 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-13 12:01 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-13 12:01 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-13 12:01 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-13 12:01 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-13 12:01 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-13 12:01 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-13 12:01 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-13 12:01 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-13 12:01 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-13 12:01 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-13 12:01 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-13 12:01 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-13 12:01 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-13 12:01 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-13 12:01 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-13 12:01 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-13 12:01 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-10 08:49 - 2013-09-14 03:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-10 08:49 - 2013-09-08 04:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-10 08:49 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-10 08:49 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-10-10 08:49 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-10 08:49 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-10 08:49 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-10 08:49 - 2013-08-29 04:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-10 08:49 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-10 08:49 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-10 08:49 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-10 08:49 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-10 08:49 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-10-10 08:49 - 2013-08-29 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-10 08:49 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-10-10 08:49 - 2013-08-29 02:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-10 08:49 - 2013-08-29 02:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-10 08:49 - 2013-08-29 02:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-10 08:49 - 2013-08-29 02:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-10 08:49 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-10 08:49 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-10 08:49 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-10 08:49 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 08:49 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 08:49 - 2013-07-12 12:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-10 08:49 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-10 08:49 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-10 08:49 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-10 08:49 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-10 08:49 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-10-10 08:49 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-10-10 08:49 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-10 08:49 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-10 08:49 - 2013-07-03 06:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-10 08:49 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-10 08:49 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-10 08:49 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-10 08:49 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-10 08:49 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-10 08:49 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-10 08:49 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-10 08:49 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-10 08:49 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-10 08:49 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-10 08:49 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-10 08:49 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-10 08:49 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-05 19:09 - 2013-10-05 19:09 - 00002214 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-09-26 16:36 - 2013-09-26 16:36 - 00000000 ____D C:\Users\opa\Documents\ProcAlyzer Dumps
2013-09-26 16:21 - 2012-02-04 19:00 - 00000858 _____ C:\Windows\system32\Drivers\etc\hosts.20130926-162147.backup
2013-09-26 16:20 - 2012-02-04 19:00 - 00000858 _____ C:\Windows\system32\Drivers\etc\hosts.20130926-162031.backup
==================== One Month Modified Files and Folders =======
2013-10-25 10:14 - 2013-10-22 19:16 - 00000000 ____D C:\ProgramData\boost_interprocess
2013-10-25 10:13 - 2013-10-25 10:12 - 00031917 _____ C:\Users\opa\Desktop\Addition.txt
2013-10-25 10:13 - 2011-06-24 13:21 - 00000000 ____D C:\Users\opa\AppData\Roaming\Skype
2013-10-25 10:12 - 2013-10-25 10:12 - 00000000 ____D C:\FRST
2013-10-25 10:10 - 2013-10-25 10:10 - 01955412 _____ (Farbar) C:\Users\opa\Desktop\FRST64.exe
2013-10-25 10:08 - 2011-07-17 18:00 - 00000000 ____D C:\Users\opa\Documents\Becky
2013-10-25 10:06 - 2011-06-24 22:57 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-25 09:58 - 2012-08-17 19:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-25 09:55 - 2011-06-20 05:00 - 01117975 _____ C:\Windows\WindowsUpdate.log
2013-10-25 08:57 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-25 08:57 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-25 08:54 - 2010-11-21 08:50 - 00699666 _____ C:\Windows\system32\perfh007.dat
2013-10-25 08:54 - 2010-11-21 08:50 - 00149774 _____ C:\Windows\system32\perfc007.dat
2013-10-25 08:54 - 2009-07-14 07:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-25 08:52 - 2013-10-23 20:15 - 00000000 ____D C:\Program Files (x86)\lucky leap
2013-10-25 08:51 - 2012-11-13 12:07 - 00000000 ____D C:\Users\opa\AppData\Local\Akamai
2013-10-25 08:49 - 2013-10-25 08:49 - 102895398 _____ C:\Windows\SysWOW64\氞⍢ᤴ”
2013-10-25 08:49 - 2013-07-04 08:46 - 00000000 ____D C:\Program Files (x86)\File Type Assistant
2013-10-25 08:49 - 2011-06-23 13:41 - 00000000 ____D C:\Users\opa\AppData\Local\SoftThinks
2013-10-25 08:48 - 2013-10-25 08:48 - 00000022 _____ C:\Windows\S.dirmngr
2013-10-25 08:48 - 2011-06-24 22:57 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-25 08:47 - 2013-10-25 08:47 - 00000056 _____ C:\Windows\setupact.log
2013-10-25 08:47 - 2013-10-25 08:47 - 00000000 _____ C:\Windows\setuperr.log
2013-10-25 08:47 - 2011-06-20 04:59 - 00000000 ____D C:\ProgramData\NVIDIA
2013-10-25 08:47 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-24 15:21 - 2011-07-03 11:44 - 00000000 ___RD C:\Users\opa\Desktop\System-Tuning
2013-10-24 11:46 - 2011-07-19 17:45 - 00000000 ____D C:\Users\opa\AppData\Roaming\gnupg
2013-10-24 11:36 - 2013-10-24 11:36 - 00000726 _____ C:\Users\opa\Desktop\DelFix.txt
2013-10-24 11:36 - 2013-10-24 11:36 - 00000726 _____ C:\DelFix.txt
2013-10-24 09:33 - 2013-10-24 09:33 - 00000000 ____D C:\Users\opa\AppData\Local\WinZip
2013-10-24 09:33 - 2013-10-24 09:33 - 00000000 ____D C:\ProgramData\WinZip
2013-10-24 09:33 - 2013-10-24 09:33 - 00000000 ____D C:\Program Files (x86)\WinZip
2013-10-23 20:16 - 2013-10-23 20:16 - 00000872 _____ C:\Users\opa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Temp File Cleaner.lnk
2013-10-23 20:16 - 2013-10-23 20:16 - 00000842 _____ C:\Users\opa\Desktop\Temp File Cleaner.lnk
2013-10-23 20:16 - 2013-10-23 20:16 - 00000000 ____D C:\Users\opa\AppData\Roaming\addpcs
2013-10-23 20:16 - 2013-10-23 20:16 - 00000000 ____D C:\Program Files\Temp File Cleaner
2013-10-23 18:09 - 2012-02-17 16:02 - 00000000 ____D C:\Users\opa\.jameica
2013-10-23 17:52 - 2012-02-15 17:27 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-23 17:47 - 2013-10-13 18:31 - 00001418 _____ C:\Users\opa\Desktop\Homebanking mit jameica-win64-Hibiscus.lnk
2013-10-23 17:45 - 2013-10-23 17:45 - 00000000 ____D C:\Program Files\jameica
2013-10-23 17:17 - 2013-10-23 17:17 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-23 17:17 - 2013-10-23 17:17 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-23 17:17 - 2013-10-23 17:17 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-23 17:17 - 2013-10-23 17:17 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-10-23 17:17 - 2013-10-23 17:17 - 00000000 ____D C:\Program Files\Java
2013-10-23 17:17 - 2013-10-23 17:14 - 00000000 ____D C:\ProgramData\Oracle
2013-10-23 17:14 - 2013-10-23 17:14 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-23 17:14 - 2013-10-23 17:14 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-23 17:14 - 2013-10-23 17:14 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-23 17:14 - 2013-10-23 17:14 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-23 16:42 - 2013-09-16 09:35 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-10-23 16:42 - 2013-09-16 09:34 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-10-23 16:37 - 2013-10-23 16:36 - 00000085 _____ C:\Windows\wininit.ini
2013-10-23 14:05 - 2013-06-21 10:08 - 00003440 _____ C:\Windows\System32\Tasks\PCDEventLauncherTask
2013-10-23 13:27 - 2013-10-22 19:25 - 00000000 ____D C:\Users\opa\AppData\Local\FileTypeAssistant
2013-10-22 19:13 - 2013-10-22 19:13 - 00000000 ____D C:\Windows\ERUNT
2013-10-22 18:12 - 2012-08-17 19:10 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-22 18:12 - 2012-04-07 17:59 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-22 18:12 - 2011-06-24 22:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-22 14:01 - 2011-07-06 18:54 - 00000000 ____D C:\Users\opa\AppData\Local\Apps\2.0
2013-10-22 13:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-10-22 12:19 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-10-22 12:17 - 2013-10-22 11:30 - 00000000 ____D C:\Windows\erdnt
2013-10-22 12:16 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-10-22 09:46 - 2011-07-06 18:54 - 00000000 ____D C:\Users\opa\AppData\Local\Deployment
2013-10-21 18:01 - 2011-06-20 12:26 - 00000000 ____D C:\Program Files (x86)\Dell
2013-10-21 17:52 - 2012-12-15 13:51 - 00000000 ____D C:\Alte Downloads fuer WINDOWS98
2013-10-21 17:30 - 2013-10-21 17:30 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2013-10-21 17:07 - 2013-10-21 17:07 - 00001687 _____ C:\Users\opa\Desktop\Becky!-Help.lnk
2013-10-21 16:12 - 2013-10-21 11:28 - 00000000 ____D C:\Users\opa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat
2013-10-21 15:41 - 2013-10-21 15:40 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP
2013-10-21 14:57 - 2013-10-21 14:57 - 00000000 _____ C:\autoexec.bat
2013-10-21 11:28 - 2011-06-23 13:35 - 00000000 ____D C:\Users\opa
2013-10-21 11:27 - 2013-10-21 11:27 - 00002380 _____ C:\Users\opa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2013-10-21 11:26 - 2013-10-21 11:26 - 00003238 _____ C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart
2013-10-21 10:49 - 2013-10-21 10:49 - 00025106 _____ C:\Windows\SysWOW64\opa.reg
2013-10-20 14:28 - 2013-10-20 14:28 - 00000000 ____D C:\Program Files\Movie Maker
2013-10-20 14:28 - 2013-10-20 14:28 - 00000000 ____D C:\drmsoft
2013-10-20 11:03 - 2011-07-22 13:58 - 00000000 ____D C:\Users\opa\AppData\Roaming\XnView
2013-10-20 10:57 - 2011-08-28 20:16 - 00000000 ____D C:\Program Files\Ext2Fsd
2013-10-19 18:40 - 2012-08-19 09:21 - 00000000 ____D C:\Program Files\Start Menu X
2013-10-19 17:46 - 2012-08-19 09:21 - 00000000 ____D C:\ProgramData\StartMenuX
2013-10-19 16:35 - 2013-09-05 11:55 - 00133576 _____ C:\Users\opa\AppData\Local\ars.cache
2013-10-19 15:46 - 2013-10-19 15:46 - 00000000 ____D C:\Users\opa\AppData\Roaming\Malwarebytes
2013-10-19 15:45 - 2013-10-19 15:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-19 15:45 - 2013-10-19 15:45 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-18 17:56 - 2011-06-20 12:40 - 00000000 ____D C:\ProgramData\Sonic
2013-10-18 17:47 - 2012-12-10 16:42 - 00000000 ____D C:\Program Files (x86)\WinImage
2013-10-18 17:46 - 2013-03-09 17:23 - 00000000 ____D C:\Users\opa\AppData\Roaming\vlc
2013-10-18 17:43 - 2012-12-10 15:58 - 00000000 ____D C:\Users\opa\.VirtualBox
2013-10-18 17:37 - 2011-07-17 11:54 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-10-18 17:24 - 2013-10-18 17:24 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-10-18 17:01 - 2011-02-11 19:13 - 00000000 ____D C:\Windows\panther
2013-10-18 16:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-10-18 15:44 - 2013-10-18 15:44 - 00000000 ____D C:\Users\opa\AppData\Local\Secunia PSI
2013-10-18 15:01 - 2011-06-24 22:57 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-18 15:01 - 2011-06-24 22:57 - 00003848 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-17 19:04 - 2013-03-09 16:44 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-17 13:51 - 2011-06-23 13:42 - 00000000 ___RD C:\Users\opa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-17 13:42 - 2013-10-17 13:42 - 00002036 _____ C:\Users\opa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autostart - Verknüpfung.lnk
2013-10-15 16:27 - 2012-02-16 16:12 - 00000000 ____D C:\Windows\SysWOW64\Adobe
2013-10-14 16:26 - 2013-02-11 20:27 - 00001092 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk
2013-10-14 16:20 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-14 12:04 - 2013-10-14 12:04 - 00018456 _____ (Secunia) C:\Windows\system32\Drivers\psi_mf_amd64.sys
2013-10-14 11:02 - 2013-07-24 13:54 - 00001650 _____ C:\Users\Public\Desktop\EditPad Lite 7.lnk
2013-10-13 18:28 - 2013-10-13 18:26 - 00000128 _____ C:\Users\opa\.jameica.properties
2013-10-13 13:03 - 2013-07-04 08:33 - 00000000 ____D C:\Users\opa\Documents\EFSoftware
2013-10-13 13:03 - 2012-08-12 11:42 - 00000000 ____D C:\Program Files\EF Commander
2013-10-13 12:11 - 2009-07-14 06:45 - 00377040 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-13 12:10 - 2012-05-28 10:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-13 12:05 - 2013-10-13 12:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-10-13 12:04 - 2011-02-11 12:22 - 01594892 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-13 12:00 - 2013-08-03 15:51 - 00000000 ____D C:\Windows\system32\MRT
2013-10-13 11:57 - 2011-06-23 14:11 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-10 08:56 - 2011-06-20 12:24 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-10 08:56 - 2011-06-20 12:23 - 00000000 ____D C:\ProgramData\Skype
2013-10-05 19:09 - 2013-10-05 19:09 - 00002214 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-10-03 12:08 - 2011-07-22 13:52 - 00000000 ____D C:\Program Files (x86)\XnView
2013-09-26 16:36 - 2013-09-26 16:36 - 00000000 ____D C:\Users\opa\Documents\ProcAlyzer Dumps
Files to move or delete:
====================
C:\ProgramData\PKP_DLdu.DAT
C:\ProgramData\PKP_DLes.DAT
C:\ProgramData\PKP_DLet.DAT
C:\ProgramData\PKP_DLev.DAT
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-22 12:37
==================== End Of Log ============================ --- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-10-2013
Ran by opa at 2013-10-25 10:12:58
Running from C:\Users\opa\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
==================== Installed Programs ======================
40tude Dialog Beta 38 (x32)
AccelerometerP11 (x32 Version: 2.00.11.22)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05)
Adobe Shockwave Player 12.0 (x32 Version: 12.0.4.144)
Advanced Audio FX Engine (x32 Version: 1.12.05)
Agent Ransack Version 1.7.3 (x32)
Ahnenblatt 2.74 (x32 Version: 2.74.0.1)
Akamai NetSession Interface (HKCU)
AVerMedia H339 Hybrid TV Tuner 2.2.64.64 (x32 Version: 2.2.64.64)
Avira Free Antivirus (x32 Version: 13.0.0.4052)
B2 PlugIn - B2Favorites (x32)
B2 PlugIn - Double Click Maximize (x32)
B2 PlugIn - PGPB2 version 0.01.6 (beta 13) (x32)
Becky! Ver.2 (x32)
BILD.de für Windows Media Center (x32 Version: 1.0.0.0)
Bing-Desktop (x32 Version: 1.3.174.0)
Blobby Volley 2.0 Version 0.9c (x32)
CCleaner (Version: 4.05)
CleanUp! (x32)
ClipMate 5.3 (x32)
Complex Evolution 5.1.2 (build 456) (x32)
Cortona3D Viewer (x32 Version: 7.0.188)
D3DX10 (x32 Version: 15.4.2368.0902)
Dell DataSafe Local Backup - Support Software (x32)
Dell DataSafe Local Backup (x32 Version: 9.4.47)
Dell Driver Download Manager (HKCU Version: 2.1.0.0)
Dell Edoc Viewer (Version: 1.0.0)
Dell Getting Started Guide (x32 Version: 1.00.0000)
Dell MusicStage (x32 Version: 1.5.402.0)
Dell PhotoStage (x32 Version: 1.5.0.30)
Dell Stage (x32 Version: 1.7.209.0)
Dell System Detect (HKCU Version: 5.3.1.5)
Dell VideoStage (x32 Version: 1.1.1.1408)
Dell Webcam Central (x32 Version: 2.00.35)
DesktopEarth (x32 Version: 2.1.1)
Deutsche Anleitung für SpamPal (x32)
DirectX 9 Runtime (x32 Version: 1.00.0000)
Dropbox (HKCU Version: 1.2.52)
eBay (x32 Version: 1.4.0)
EditPad Lite DE 7.3.0 (Version: DE 7.3.0)
EF Commander
EPSON PERFECTION V200 PHOTO Handbuch (x32)
EPSON Scan (x32)
Ext2Fsd 0.51 (Version: 0.51)
File Type Assistant (x32 Version: 2013.4.8.0)
Google Chrome (x32 Version: 30.0.1599.101)
Google Earth (x32 Version: 7.1.2.2019)
Google Update Helper (x32 Version: 1.3.21.165)
Gpg4win (2.2.1) (x32 Version: 2.2.1)
GPL Ghostscript (Version: 9.04)
inSSIDer (x32 Version: 2.1.6)
InstallVC90Support (x32 Version: 1.01.0000)
Intel PROSet Wireless
Intel PROSet Wireless (x32)
Intel(R) Control Center (x32 Version: 1.2.1.1007)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2455)
Intel(R) PROSet/Wireless WiFi-Software (Version: 14.03.0000)
Intel(R) WiDi (x32 Version: 2.1.39.0)
Intel(R) Wireless Display
IrfanView (remove only) (x32 Version: 4.36)
Java 3D 1.5.1 (x32 Version: 1.5.1)
Java 7 Update 45 (64-bit) (Version: 7.0.450)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
LibreOffice 4.0 Help Pack (German) (x32 Version: 4.0.5.2)
LibreOffice 4.0.5.2 (x32 Version: 4.0.5.2)
lucky leap 1.0.0 (Version: 1.0.0)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4.5 (Version: 4.5.50709)
Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0)
Mozilla Maintenance Service (x32 Version: 24.0.1)
Mozilla Thunderbird 24.0.1 (x86 de) (x32 Version: 24.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0)
My Dell (Version: 3.4.6308.28)
Nikon Message Center 2 (x32 Version: 2.1.0)
Nikon Movie Editor (x32 Version: 2.2.4)
Nikon Transfer (x32 Version: 1.5.3)
n-tv plus (x32 Version: 7.4.3.0)
NVIDIA 3D Vision Treiber 306.97 (Version: 306.97)
NVIDIA Grafiktreiber 306.97 (Version: 306.97)
NVIDIA HD-Audiotreiber 1.2.24.0 (Version: 1.2.24.0)
NVIDIA Install Application (Version: 2.1002.85.551)
NVIDIA Optimus 1.10.8 (Version: 1.10.8)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.0697)
NVIDIA Systemsteuerung 306.97 (Version: 306.97)
NVIDIA Update 1.10.8 (Version: 1.10.8)
NVIDIA Update Components (Version: 1.10.8)
Oracle VM VirtualBox 4.2.18 (Version: 4.2.18)
PhotoShowExpress (x32 Version: 2.0.063)
Picasa 3 (x32 Version: 3.9)
Picture Control Utility (x32 Version: 1.4.1)
PIXresizer (x32 Version: 2.0.5)
PlayReady PC Runtime amd64 (Version: 1.3.0)
Print Distributor 4 (x32)
Print Distributor 4 DEP Fix
PrintFile (x32)
Quickset64 (Version: 11.0.22)
RBVirtualFolder64Inst (Version: 1.00.0000)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6449)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.1.27.0)
Revo Uninstaller 1.95 (x32 Version: 1.95)
Riot - Radical Image Optimization Tool (x32)
Riot plugin (x32)
Roxio Activation Module (x32 Version: 1.0)
Roxio BackOnTrack (x32 Version: 1.3.3)
Roxio Burn (x32 Version: 1.8)
Roxio Creator Starter (x32 Version: 1.0.439)
Roxio Creator Starter (x32 Version: 12.1.77.0)
Roxio Creator Starter (x32 Version: 5.0.0)
Roxio Express Labeler 3 (x32 Version: 3.2.2)
Roxio File Backup (Version: 1.3.2)
Screenpresso (HKCU Version: 1.4.3.0)
Secunia PSI (3.0.0.8013) (x32 Version: 3.0.0.8013)
ShadowExplorer 0.8 (x32 Version: 0.8.430.0)
SiSoftware Sandra Lite 2012.SP4c (Version: 18.52.2012.6)
Skype Click to Call (x32 Version: 5.10.9560)
Skype™ 6.9 (x32 Version: 6.9.106)
softMCCS (x32)
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0)
SpamAssassin for Windows V (x32)
SpamPal (x32 Version: v1.594)
Spybot - Search & Destroy (x32 Version: 2.2.25)
Start Menu X Version 4.97 (Version: 4.97)
Stellarium 0.12.0 (Version: 0.12.0)
swMSM (x32 Version: 12.0.0.1)
Synaptics Pointing Device Driver (Version: 15.1.15.0)
TeamViewer 8 (x32 Version: 8.0.22298)
Temp File Cleaner (Version: 4.3.0)
Tinypic 3.17a (x32 Version: Tinypic 3.17a)
Total Commander (Remove or Repair) (x32 Version: 7.57a)
Total Commander 64-bit (Remove or Repair) (Version: 8.01)
TreeSize Free V2.7 (x32 Version: 2.7)
Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (Version: 2.1.23.0)
Unlocker 1.9.1-x64 (Version: 1.9.1)
Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1)
Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1)
Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1)
ViewNX 2 (x32 Version: 2.2.5)
VLC media player 2.1.0 (Version: 2.1.0)
Windows Internet Explorer 10 (x32 Version: 10.0)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3508.1109)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3508.1109)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
WinImage (x32)
WinPcap 4.1.2 (x32 Version: 4.1.0.2001)
WinZip 17.5 (x32 Version: 17.5.10480)
XnView 2.05 (x32 Version: 2.05)
YouSendIt Desktop App (Version: 2.0.0.142)
==================== Restore Points =========================
28-09-2013 06:05:14 Windows Update
30-09-2013 18:42:01 Windows-Sicherung
03-10-2013 07:51:36 Windows Update
05-10-2013 17:08:17 Installed Google Earth.
06-10-2013 18:41:38 Windows-Sicherung
10-10-2013 06:47:53 Windows Update
13-10-2013 09:56:38 Windows Update
13-10-2013 10:35:07 Windows Update
14-10-2013 08:56:18 Windows-Sicherung
18-10-2013 12:51:39 Windows Update
18-10-2013 15:36:45 Installed MSXML 4.0 SP3 Parser
18-10-2013 15:39:39 Installed Java 7 Update 45
18-10-2013 15:41:39 Installed Oracle VM VirtualBox 4.2.18
18-10-2013 16:01:53 Windows Update
21-10-2013 08:12:17 Windows-Sicherung
21-10-2013 12:56:35 Installed SpyHunter
21-10-2013 13:40:01 Removed SpyHunter
21-10-2013 15:31:32 Revo Uninstaller's restore point - Snap.Do Engine
22-10-2013 15:56:32 Windows Update
23-10-2013 15:13:32 Removed Java 7 Update 45
23-10-2013 15:14:00 Installed Java 7 Update 45
23-10-2013 15:17:02 Installed Java 7 Update 45 (64-bit)
24-10-2013 07:32:41 WinZip 17.5 wird installiert
==================== Hosts content: ==========================
2009-07-14 04:34 - 2013-10-22 12:16 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {02FDCC12-55E7-4537-AAA4-46A609E7AF57} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {0879C223-0B0E-443A-9A87-7C3C71C5CF3F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-22] (Adobe Systems Incorporated)
Task: {0FC13E7A-4548-4DA5-AC28-CCD4266F3AA0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-06-24] (Google Inc.)
Task: {10A3203F-42DF-4200-97C1-E3D0C67BC7E7} - System32\Tasks\{E16E6629-9A52-43E0-AB5C-21BE695AD1B4} => Firefox.exe hxxp://ui.skype.com/ui/0/5.9.0.115/de/go/help.faq.installer?LastError=1603
Task: {19B64929-1991-4D1B-9C03-AE4F9B1F50DD} - System32\Tasks\{BE4B010A-99F7-4F70-8E4F-581ADA8EA57F} => C:\Users\opa\Desktop\epson12526.exe
Task: {298BB546-6AB0-4588-88F3-D540BE386260} - System32\Tasks\{2D639511-1F72-45AC-96DF-B82810EFBCCC} => C:\Users\opa\Desktop\epson12526.exe
Task: {2AC6C4FB-CE36-449B-8568-F5CA38A3D390} - System32\Tasks\SystemToolsDailyTest => C:\Windows\System32\uaclauncher.exe
Task: {2B9B0584-2F10-4214-89B1-4283AEDD2047} - System32\Tasks\{773FCA6E-0753-4C1D-B434-0D16CE767BBD} => Firefox.exe hxxp://ui.skype.com/ui/0/5.9.0.115/de/go/help.faq.installer?LastError=1603
Task: {407723EA-8CF0-4CCB-B6CE-5E10D2D7E885} - System32\Tasks\ProgramUpdateCheck => C:\Program Files (x86)\File Type Assistant\TSAssist.exe [2013-04-08] (Trusted Software ApS)
Task: {55132F5B-332E-4D28-9CBF-3C2A549AF1BD} - \Scheduled Update for Ask Toolbar No Task File
Task: {5A67D147-A06C-421D-A4FA-E221644AF261} - System32\Tasks\{EA854FC6-D879-48FA-9603-21FCA95160BA} => Firefox.exe hxxp://ui.skype.com/ui/0/5.9.0.115/de/go/help.faq.installer?LastError=1603
Task: {6A772D2B-58A7-4EF9-838F-4CA1603873CE} - System32\Tasks\SomotoUpdateCheckerAutoStart => C:\Users\opa\AppData\Local\FilesFrog Update Checker\update_checker.exe
Task: {7133F54D-C72F-4AD8-B3E6-06E70DB61F81} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)
Task: {8C0D5592-7EAA-48AF-B58F-3F184E2FF4CB} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2013-09-06] (PC-Doctor, Inc.)
Task: {9D76C84D-41D6-4417-AA48-E28C39BAABB2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-06-24] (Google Inc.)
Task: {A9118DA9-66E0-48DB-A56C-B221B9DF9CBE} - \SpyHunter4Startup No Task File
Task: {A9B485E6-4CF2-413B-AA2F-7F456FB637C7} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21] (Microsoft Corporation)
Task: {AD5CCFA2-3A5B-462D-A9BA-0A6CF1CEAEC1} - System32\Tasks\{D2EA18A5-4DF0-41EA-9615-FBB19CC1E4B4} => Firefox.exe hxxp://ui.skype.com/ui/0/5.9.0.115/de/go/help.faq.installer?LastError=1603
Task: {C409B95F-5060-41C6-A39E-F4D87DFB7B29} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {E0EDDB44-FFD9-4DAD-82CC-F6617308D844} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2013-09-06] (PC-Doctor, Inc.)
Task: {E1A9442E-2C47-403E-9CC3-37B29473CF04} - System32\Tasks\{3B422CCB-E3BF-45E7-99F8-B39E876550EE} => C:\Users\opa\Desktop\epson12526.exe
Task: {E1F2CF8D-538B-42D6-A89C-4EF4DFED7B68} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {E4CAFB85-7179-4B3B-A9C5-CCFEC0AD3B89} - System32\Tasks\{DC5E42E1-0210-41B5-9DC4-7A7573337AFF} => Firefox.exe hxxp://ui.skype.com/ui/0/5.9.0.115/de/go/help.faq.installer?LastError=1603
Task: {E85EBE15-2D56-43AD-9EC8-98D9F2DDE9CA} - System32\Tasks\{ABC933A6-36A7-4D55-8AFD-73BEBAAEB45E} => Firefox.exe hxxp://ui.skype.com/ui/0/5.9.0.115/de/go/help.faq.installer?LastError=1603
Task: {EA866EEF-F406-4FA0-B02A-2E0F4B3D6C22} - System32\Tasks\ProgramRefresh-ATFST => C:\Program Files (x86)\File Type Assistant\tsasetup.exe [2013-04-08] ( )
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2011-06-20 13:39 - 2011-03-07 22:07 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-11-01 13:58 - 2011-11-01 13:58 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2010-11-29 22:04 - 2010-11-29 22:04 - 00403968 _____ () C:\Program Files\Intel\TurboBoost\de\SignalIslandUi.resources.dll
2012-10-16 14:09 - 2012-09-19 19:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2013-10-07 16:49 - 2013-10-07 16:49 - 00221184 _____ () C:\Program Files (x86)\GNU\GnuPG\libksba-8.dll
2013-10-07 16:47 - 2013-10-07 16:47 - 00037888 _____ () C:\Program Files (x86)\GNU\GnuPG\libgpg-error-0.dll
2013-10-07 16:44 - 2013-10-07 16:44 - 00050176 _____ () C:\Program Files (x86)\GNU\GnuPG\libw32pth-0.dll
2013-10-07 16:49 - 2013-10-07 16:49 - 00069632 _____ () C:\Program Files (x86)\GNU\GnuPG\libassuan-0.dll
2013-10-07 16:49 - 2013-10-07 16:49 - 00628224 _____ () C:\Program Files (x86)\GNU\GnuPG\libgcrypt-11.dll
2013-10-23 16:42 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2013-10-23 16:42 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-10-23 16:42 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2013-10-23 16:42 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2013-10-23 16:42 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2011-06-20 12:23 - 2010-08-12 01:19 - 00056544 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STCoreXml.dll
2011-06-20 12:23 - 2010-08-12 01:19 - 00113888 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\PSTVdsDisk.dll
2011-06-20 12:23 - 2010-08-12 01:19 - 00126176 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll
2011-06-20 12:23 - 2010-08-12 01:19 - 01121504 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\LibXml2.dll
2011-06-20 12:23 - 2010-08-12 01:19 - 00077024 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll
2011-06-20 12:23 - 2010-08-12 01:19 - 00232672 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll
2011-06-20 12:23 - 2010-08-12 01:19 - 00072928 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll
2011-06-20 12:23 - 2010-08-12 01:19 - 00109792 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll
2011-06-20 12:23 - 2010-08-12 01:19 - 00119008 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll
2012-02-01 11:44 - 2012-02-01 11:44 - 08151040 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtGui4.dll
2012-02-01 11:44 - 2012-02-01 11:44 - 02278400 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtCore4.dll
2004-04-09 16:58 - 2004-04-09 16:58 - 00109056 _____ () C:\Program Files (x86)\SpamPal\lang.dll
2004-10-29 18:48 - 2004-10-29 18:48 - 00077312 _____ () C:\Program Files (x86)\SpamPal\plugins\urlbody\urlbody.dll
2005-10-24 20:08 - 2005-10-24 20:08 - 00047104 _____ () C:\Program Files (x86)\SpamPal\updates.dll
2005-07-20 11:48 - 2005-07-20 11:48 - 00059904 _____ () C:\Program Files (x86)\SpamPal\zlib1.dll
2013-10-25 09:22 - 2013-10-25 09:22 - 00337920 _____ () C:\Program Files (x86)\lucky leap\bin\sqlite3.DLL
2013-09-20 13:53 - 2013-09-20 13:53 - 03279768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-10-13 11:54 - 2013-10-22 18:12 - 16233864 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\Temp:3AC4C770
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\se64a.sys => ""="Driver"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (10/25/2013 08:51:22 AM) (Source: MsiInstaller) (User: DELL-PC)
Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\opa\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.
Error: (10/25/2013 08:50:50 AM) (Source: MsiInstaller) (User: DELL-PC)
Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\opa\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.
Error: (10/25/2013 08:49:04 AM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT)
Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden.
Error: (10/24/2013 05:40:51 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT)
Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden.
Error: (10/24/2013 05:02:22 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT)
Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden.
Error: (10/24/2013 03:34:40 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 24.0.0.5001, Zeitstempel: 0x522fd29f
Name des fehlerhaften Moduls: xul.dll, Version: 24.0.0.5001, Zeitstempel: 0x522fd1a4
Ausnahmecode: 0xc0000005
Fehleroffset: 0x001b72a8
ID des fehlerhaften Prozesses: 0x1100
Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0
Pfad der fehlerhaften Anwendung: firefox.exe1
Pfad des fehlerhaften Moduls: firefox.exe2
Berichtskennung: firefox.exe3
Error: (10/24/2013 03:18:39 PM) (Source: MsiInstaller) (User: DELL-PC)
Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\opa\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.
Error: (10/24/2013 03:18:15 PM) (Source: MsiInstaller) (User: DELL-PC)
Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\opa\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.
Error: (10/24/2013 03:16:03 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT)
Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden.
Error: (10/24/2013 11:39:46 AM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT)
Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden.
System errors:
=============
Error: (10/25/2013 08:51:26 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (10/25/2013 08:51:26 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%1330
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (10/25/2013 08:48:05 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PGPmemlock" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (10/24/2013 05:42:57 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (10/24/2013 05:42:57 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%1330
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (10/24/2013 05:40:28 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PGPmemlock" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (10/24/2013 05:04:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (10/24/2013 05:04:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%1330
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (10/24/2013 05:01:37 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PGPmemlock" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (10/24/2013 05:01:28 PM) (Source: NetBT) (User: )
Description: Es ist ein Initialisierungsfehler aufgetreten, da der Treiber nicht erstellt werden konnte.
Verwenden Sie die Zeichenfolge "8CA982ACBC1B", um die Schnittstelle zu identifizieren, die nicht initialisiert werden
konnte. Sie stellt die MAC-Adresse der Schnittstelle mit dem Initialisierungsfehler oder die
GUID (Globally Unique Interface Identifier) dar, wenn NetBT keine Zuordnung
von der GUID zur MAC-Adresse herstellen konnte. Wenn weder die MAC-Adresse noch die GUID verfügbar
waren, dann stellt die Zeichenfolge einen Clustergerätenamen dar.
Microsoft Office Sessions:
=========================
Error: (10/25/2013 08:51:22 AM) (Source: MsiInstaller)(User: DELL-PC)
Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\opa\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (10/25/2013 08:50:50 AM) (Source: MsiInstaller)(User: DELL-PC)
Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\opa\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (10/25/2013 08:49:04 AM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/24/2013 05:40:51 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/24/2013 05:02:22 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/24/2013 03:34:40 PM) (Source: Application Error)(User: )
Description: firefox.exe24.0.0.5001522fd29fxul.dll24.0.0.5001522fd1a4c0000005001b72a8110001ced0bcff165378C:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\xul.dll086411b7-3cb1-11e3-8a7b-14feb5b65af8
Error: (10/24/2013 03:18:39 PM) (Source: MsiInstaller)(User: DELL-PC)
Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\opa\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (10/24/2013 03:18:15 PM) (Source: MsiInstaller)(User: DELL-PC)
Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\opa\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (10/24/2013 03:16:03 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/24/2013 11:39:46 AM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
CodeIntegrity Errors:
===================================
Date: 2013-10-22 12:16:09.128
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-10-22 12:16:09.038
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 57%
Total physical RAM: 3990.17 MB
Available physical RAM: 1678.24 MB
Total Pagefile: 7978.52 MB
Available Pagefile: 4809.2 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:244.14 GB) (Free:163.86 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATEN) (Fixed) (Total:206.87 GB) (Free:76.48 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 466 GB) (Disk ID: 07F2837E)
Partition 1: (Not Active) - (Size=102 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=244 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=207 GB) - (Type=05)
==================== End Of Log ============================ Zu dem Problem mit CleanUp von Helmut Rohrbeck schreibt dieser:
"... liegt's evtl. an der Ausführung von "regcleanpro"
des Trojaner-Boards. Möglicherweise wurde damit das Ausführen
von *.hta-Dateien mit C:\Windows\System32\mshta.exe deaktiviert
und funktioniert nicht mehr. "
Gruß
Ch. Hanisch |