Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU (https://www.trojaner-board.de/147779-virus-avira-geupdated-verbraucht-sehr-viel-cpu.html)

schrauber 08.02.2014 14:18

Kannste mir davon nen Screenshot machen?

Kriega 11.02.2014 22:31

Bitteschön :)

schrauber 12.02.2014 18:24

Du startest mit Revo ja den Photoshop Uninstaller, dann kommt die Meldung. WEnn Du das aber abbricht sollte dir Revo anbieten das Teil selbst zu deinstallieren bzw alle Reste zu entfernen.

Kriega 12.02.2014 19:29

Ja das stimmt. Er macht dann noch so einen Scan und listet ganz viele Sachen auf, die er löschen möchte. Für mich sah das aber so aus als würde er auch ganz andere Dateien von anderen Programmen löschen wollen. Somit habe ich das dann auch abgebrochen. :/

schrauber 13.02.2014 21:35

Lass ihn das mal suchen und mache nen Screenshot davon :)

Kriega 02.03.2014 17:21

Ist eine lange Liste

schrauber 03.03.2014 14:18

Wenn die Suche auf Moderat steht kannste das alles löschen lassen.

Kriega 08.03.2014 12:44

Naja... hab das jetzt gemacht, aber mein Vlc-Player und mein CCleaner sind schon mal nicht mehr aufzufinden und vieles anderes musste ich erstmal wieder als standart Programm festlegen. Aber sonst ist alles gut

Na toll... jetzt nach dem Neustart geht gar nichts mehr. Nicht mal mehr das SnippingTool
Der Microsoft Security Client hat auch den Error Code 0x80073b01
Bei iTunes kommt nicht korrekt installiert und reparieren kann es das auch nicht usw

Kriega 08.03.2014 13:15

WIndows Updates gehen auch nicht mehr

schrauber 09.03.2014 07:41

Downloade dir bitte Windows Repair (All In One) von hier.


Bitte ein frisches FRST log, und:

Downloade dir bitte Farbar Service Scanner Farbar Service Scanner
  • Starte das Tool mit Doppelklick auf die FSS.exe
  • Gehe sicher, dass folgende Optionen angehakt sind.
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Klicke auf Scan.
  • Wenn das Tool fertig ist, wird es eine FSS.txt in dem Verzeichnis erstellen, wo das Tool gelaufen ist.

Poste bitte den Inhalt hier.



Kriega 09.03.2014 13:32

Das nimmt nie ein Ende oder?^^


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-03-2014 01
Ran by Emilio (administrator) on EMILIOS-HP-PC on 09-03-2014 13:15:25
Running from C:\Users\Emilio\Desktop\FRST-OlderVersion
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forums

==================== Processes (Whitelisted) =================

(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\system32\IProsetMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Spotify Ltd) C:\Users\Emilio\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Dropbox, Inc.) C:\Users\Emilio\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MpCmdRun.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
HKLM\...\Run: [HPSYSDRV] - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\HPSYSDRV.EXE [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [Avira Systray] - C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [172624 2014-02-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-25] (Avira Operations GmbH & Co. KG)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-02-25] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3513785353-2090306979-4278820556-1000\...\Run: [Spotify Web Helper] - C:\Users\Emilio\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-02-02] (Spotify Ltd)
Startup: C:\Users\Emilio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Emilio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=CMDTDFJS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=CMDTDFJS
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=CMDTDFJS
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll" No File
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll" No File
Toolbar: HKLM-x32 - No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-4300-7A786E7484D7} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5-x64 07 C:\Program Files\Bonjour\mdnsNSP.dll File Not found ()
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

Chrome:
=======
CHR HomePage:
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\pdf.dll ()
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Extension: (Google Docs) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-16]
CHR Extension: (Google Drive) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-16]
CHR Extension: (WOT) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-02-02]
CHR Extension: (YouTube) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-16]
CHR Extension: (Adblock Plus) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-03-17]
CHR Extension: (Google-Suche) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-16]
CHR Extension: (Youtube Video Downloader) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpbkobkodledeibpmilbmnpfolihcnla [2013-06-08]
CHR Extension: (Avira Browser Safety) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-03-08]
CHR Extension: (Youtube Series Downloader) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\jghmjoeoeedipbgbgofflfgcfpineanf [2013-06-08]
CHR Extension: (SmallringFX DarkBlue Theme) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfijmgohofmpjlcgmjplbpmkpchdhpk [2013-03-16]
CHR Extension: (V-bates) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\khldgopgjjapmbkgflpoclebjjmkmbnk [2013-06-26]
CHR Extension: (Download Youtube as mp3) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\mepapnoaejebkkpkpacihjlfekoggahp [2013-10-05]
CHR Extension: (Privacy Palette) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjkcflkplhgpebknipkekjggglimnone [2013-03-17]
CHR Extension: (Google Wallet) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-06]
CHR Extension: (Google Mail) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-16]
CHR HKLM-x32\...\Chrome\Extension: [ajadlheagenmmedmhaoafgkdenfilcme] - C:\Program Files (x86)\BetterSurf\BetterSurfPlusV1\ch\BetterSurfPlusV1.crx [2013-03-16]
CHR HKLM-x32\...\Chrome\Extension: [ieghcpafofcpcjmacgknimjbimfcdfoc] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta804\ch\VideoPlayerV3beta804.crx [2013-03-16]
CHR HKLM-x32\...\Chrome\Extension: [iiahmooinmkibiblfkgkcckfabbkmojp] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha246\ch\WebexpEnhancedV1alpha246.crx [2013-03-16]
CHR HKLM-x32\...\Chrome\Extension: [pcoohmdcpejoeggdnihdfhohjgdbllgm] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7C\CRX\ToolbarCR.crx [2013-03-16]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [117328 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1134624 2012-07-18] (PDF Complete Inc)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1223704 2013-02-07] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660504 2013-02-07] (Secunia)
S2 AERTFilters; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [X]
S2 Bonjour Service; "C:\Program Files\Bonjour\mDNSResponder.exe" [X]
S2 Intel(R) Capability Licensing Service Interface; "c:\Program Files\Intel\iCLS Client\HeciServer.exe" [X]
S3 osppsvc; "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" [X]
S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [X]

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-02-25] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-02-25] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
S3 IFCoEMP; C:\Windows\system32\drivers\ifM60x64.sys [348944 2011-06-15] (Intel(R) Corporation)
S3 IFCoEVB; C:\Windows\system32\drivers\ifP60X64.sys [70928 2011-06-15] (Intel(R) Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-02-07] (Secunia)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-09 11:38 - 2014-03-09 11:59 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Windows NT
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Windows Journal
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Windows Defender
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\MSBuild
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\DVD Maker
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Common Files\System
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Common Files\Services
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-03-09 11:05 - 2014-03-09 11:05 - 00003408 _____ () C:\bootsqm.dat
2014-03-09 10:55 - 2014-03-09 10:56 - 00000000 ____D () C:\Users\Emilio\Desktop\Tweaking.com - Windows Repair
2014-03-09 10:53 - 2014-03-09 10:53 - 03098210 _____ () C:\Users\Emilio\Downloads\tweaking.com_windows_repair_aio.zip
2014-03-08 13:25 - 2014-03-08 13:25 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\Avira
2014-03-08 13:24 - 2014-02-25 11:41 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-03-08 13:24 - 2014-02-25 11:41 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-03-08 13:24 - 2014-02-25 11:41 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-03-08 13:22 - 2014-03-08 13:24 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-03-08 13:22 - 2014-03-08 13:22 - 04051872 _____ (Avira Operations GmbH & Co. KG) C:\Users\Emilio\Downloads\avira_de_av___ws.exe
2014-03-08 13:22 - 2014-03-08 13:22 - 00001139 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-03-08 13:22 - 2014-03-08 13:22 - 00000000 ____D () C:\ProgramData\Package Cache
2014-03-08 13:13 - 2014-03-08 13:13 - 00110415 _____ () C:\Users\Emilio\Desktop\10008378_637721742948409_1319656406_n.zip
2014-03-08 13:12 - 2014-03-08 13:12 - 00000000 ____D () C:\Users\Emilio\AppData\Local\WinZip
2014-03-08 12:55 - 2014-03-08 19:01 - 00004242 _____ () C:\Windows\IE9_main.log
2014-03-08 12:51 - 2014-03-08 12:51 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-03-08 12:51 - 2014-03-08 12:51 - 00000000 ____D () C:\Program Files\iTunes
2014-03-07 20:28 - 2014-03-07 20:28 - 00002151 _____ () C:\Users\Public\Desktop\WinZip.lnk
2014-03-07 20:28 - 2014-03-07 20:28 - 00000000 ____D () C:\Program Files\WinZip
2014-03-07 20:23 - 2014-03-07 20:23 - 46956032 _____ () C:\Users\Emilio\Downloads\wz180gev-64.msi
2014-03-02 18:47 - 2014-03-02 18:47 - 01064488 _____ (BillP Studios) C:\Users\Emilio\Downloads\wpsetup.exe
2014-03-02 17:49 - 2014-03-02 18:35 - 141656540 _____ () C:\Users\Emilio\Downloads\TS-DBDEN.part5.rar
2014-03-02 17:19 - 2014-03-08 12:51 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-03-02 17:19 - 2014-03-08 12:51 - 00000000 ____D () C:\Program Files\iPod
2014-03-02 17:19 - 2014-03-02 17:19 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-03-02 17:17 - 2014-03-02 17:17 - 00944308 _____ () C:\Users\Emilio\Desktop\Screenshots.zip
2014-03-02 17:14 - 2014-03-02 17:15 - 00000000 ____D () C:\Users\Emilio\Desktop\Neuer Ordner (3)
2014-02-16 20:49 - 2014-02-16 20:49 - 00198742 _____ () C:\Users\Emilio\Downloads\extension_1_0_0_10.crx
2014-02-15 00:52 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-15 00:52 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-15 00:52 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-15 00:52 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-15 00:52 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-15 00:52 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-15 00:52 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-15 00:52 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-15 00:52 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-15 00:52 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-15 00:52 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-15 00:52 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-15 00:52 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-15 00:52 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-15 00:52 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-15 00:52 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-15 00:52 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-15 00:52 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-15 00:52 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-15 00:52 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-15 00:52 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-15 00:52 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-15 00:52 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-15 00:52 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-15 00:52 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-15 00:52 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-15 00:52 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-15 00:52 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-15 00:52 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-15 00:52 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-15 00:52 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-15 00:52 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-15 00:52 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-15 00:52 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-15 00:52 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-15 00:52 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-15 00:52 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-15 00:52 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-15 00:52 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-15 00:52 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-15 00:52 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-14 23:26 - 2014-02-14 23:38 - 305247075 _____ () C:\Users\Emilio\Downloads\Texture Pack by DvizehEdits.rar
2014-02-14 14:21 - 2014-02-14 14:21 - 00006124 _____ () C:\Users\Emilio\Downloads\circo.zip
2014-02-14 14:17 - 2014-02-14 14:17 - 00013475 _____ () C:\Users\Emilio\Downloads\dotboundary.zip
2014-02-14 14:11 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-14 14:11 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-14 14:11 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-14 14:11 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-14 14:11 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-14 14:11 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-14 14:11 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-14 14:11 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-14 14:11 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-14 14:11 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-14 14:11 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-14 14:11 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-14 14:11 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-14 14:11 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-14 14:11 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-14 14:11 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-14 14:11 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-14 14:11 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-14 14:11 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-14 14:11 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-14 14:11 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-14 14:11 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-14 14:11 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-14 14:11 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-14 14:11 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-14 14:11 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-14 14:11 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-14 14:11 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-13 00:12 - 2014-02-13 00:12 - 05330264 _____ (Apple Inc.) C:\Users\Emilio\Downloads\WindowsMigrationAssistantSetup.exe
2014-02-13 00:12 - 2014-02-13 00:12 - 05330264 _____ (Apple Inc.) C:\Users\Emilio\Downloads\WindowsMigrationAssistantSetup (1).exe
2014-02-07 20:27 - 2014-02-07 20:27 - 00003274 _____ () C:\Windows\System32\Tasks\{49FC3A0D-8090-4E54-9355-7E03E799FA7C}
2014-02-07 19:12 - 2014-02-07 19:12 - 00001270 _____ () C:\Users\Emilio\Desktop\Revo Uninstaller.lnk
2014-02-07 19:12 - 2014-02-07 19:12 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-02-07 12:08 - 2014-02-07 23:50 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-02-07 11:04 - 2014-03-09 12:33 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-07 11:04 - 2014-03-02 16:34 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-07 11:04 - 2014-03-02 16:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-07 11:04 - 2014-03-02 16:34 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater

==================== One Month Modified Files and Folders =======

2014-03-09 13:15 - 2014-02-02 15:07 - 00000000 ____D () C:\FRST
2014-03-09 13:15 - 2014-01-26 15:39 - 00000000 ____D () C:\Users\Emilio\Desktop\FRST-OlderVersion
2014-03-09 13:08 - 2013-03-16 15:05 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-09 13:08 - 2013-03-16 15:05 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-09 13:08 - 2013-01-03 04:47 - 00000000 ____D () C:\ProgramData\PDFC
2014-03-09 12:33 - 2014-02-07 11:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-09 12:07 - 2013-03-16 23:01 - 01356628 _____ () C:\Windows\WindowsUpdate.log
2014-03-09 12:07 - 2009-07-14 05:45 - 00016768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-09 12:07 - 2009-07-14 05:45 - 00016768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-09 12:06 - 2013-03-16 14:14 - 00061240 _____ () C:\Users\Emilio\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-09 12:06 - 2013-01-03 04:19 - 00686006 _____ () C:\Windows\system32\perfh007.dat
2014-03-09 12:06 - 2013-01-03 04:19 - 00145580 _____ () C:\Windows\system32\perfc007.dat
2014-03-09 12:06 - 2009-07-14 06:13 - 01622164 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-09 12:05 - 2013-03-16 20:31 - 00000000 ___RD () C:\Users\Emilio\Dropbox
2014-03-09 12:05 - 2013-03-16 20:19 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\Dropbox
2014-03-09 12:01 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-09 12:00 - 2014-02-01 22:14 - 00249880 _____ () C:\Windows\PFRO.log
2014-03-09 12:00 - 2014-02-01 22:14 - 00001064 _____ () C:\Windows\setupact.log
2014-03-09 12:00 - 2009-07-14 05:45 - 00285824 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-09 11:59 - 2014-03-09 11:38 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2014-03-09 11:58 - 2009-07-14 03:34 - 00000439 _____ () C:\Windows\win.ini
2014-03-09 11:36 - 2013-04-01 23:26 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\Spotify
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Windows NT
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Windows Journal
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Windows Defender
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\MSBuild
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\DVD Maker
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Common Files\System
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Common Files\Services
2014-03-09 11:27 - 2014-03-09 11:27 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-03-09 11:05 - 2014-03-09 11:05 - 00003408 _____ () C:\bootsqm.dat
2014-03-09 10:56 - 2014-03-09 10:55 - 00000000 ____D () C:\Users\Emilio\Desktop\Tweaking.com - Windows Repair
2014-03-09 10:53 - 2014-03-09 10:53 - 03098210 _____ () C:\Users\Emilio\Downloads\tweaking.com_windows_repair_aio.zip
2014-03-08 19:01 - 2014-03-08 12:55 - 00004242 _____ () C:\Windows\IE9_main.log
2014-03-08 18:15 - 2013-03-16 17:30 - 00000000 ____D () C:\Users\Emilio\AppData\Local\PMB Files
2014-03-08 18:15 - 2013-03-16 17:29 - 00000000 ____D () C:\ProgramData\PMB Files
2014-03-08 13:45 - 2013-04-05 20:27 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\Skype
2014-03-08 13:25 - 2014-03-08 13:25 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\Avira
2014-03-08 13:24 - 2014-03-08 13:22 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-03-08 13:24 - 2014-01-03 12:21 - 00000000 ____D () C:\ProgramData\Avira
2014-03-08 13:22 - 2014-03-08 13:22 - 04051872 _____ (Avira Operations GmbH & Co. KG) C:\Users\Emilio\Downloads\avira_de_av___ws.exe
2014-03-08 13:22 - 2014-03-08 13:22 - 00001139 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-03-08 13:22 - 2014-03-08 13:22 - 00000000 ____D () C:\ProgramData\Package Cache
2014-03-08 13:13 - 2014-03-08 13:13 - 00110415 _____ () C:\Users\Emilio\Desktop\10008378_637721742948409_1319656406_n.zip
2014-03-08 13:12 - 2014-03-08 13:12 - 00000000 ____D () C:\Users\Emilio\AppData\Local\WinZip
2014-03-08 13:12 - 2013-01-03 04:47 - 00000000 ____D () C:\ProgramData\WinZip
2014-03-08 12:51 - 2014-03-08 12:51 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-03-08 12:51 - 2014-03-08 12:51 - 00000000 ____D () C:\Program Files\iTunes
2014-03-08 12:51 - 2014-03-02 17:19 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-03-08 12:51 - 2014-03-02 17:19 - 00000000 ____D () C:\Program Files\iPod
2014-03-08 12:40 - 2013-03-16 14:11 - 00003954 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{F6BA0110-D05B-4941-A2AC-C1C89CCDA816}
2014-03-08 12:31 - 2013-01-03 04:47 - 00000000 ____D () C:\Program Files\Bonjour
2014-03-07 22:22 - 2013-09-13 16:00 - 00003192 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForEmilio
2014-03-07 22:22 - 2013-09-13 16:00 - 00000336 _____ () C:\Windows\Tasks\HPCeeScheduleForEmilio.job
2014-03-07 20:28 - 2014-03-07 20:28 - 00002151 _____ () C:\Users\Public\Desktop\WinZip.lnk
2014-03-07 20:28 - 2014-03-07 20:28 - 00000000 ____D () C:\Program Files\WinZip
2014-03-07 20:28 - 2013-03-16 14:10 - 00000000 ____D () C:\Users\Emilio
2014-03-07 20:23 - 2014-03-07 20:23 - 46956032 _____ () C:\Users\Emilio\Downloads\wz180gev-64.msi
2014-03-07 19:59 - 2013-01-03 04:40 - 00000000 ____D () C:\Program Files\Intel
2014-03-06 15:15 - 2011-02-11 21:29 - 01595508 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-06 12:14 - 2013-04-01 23:27 - 00000000 ____D () C:\Users\Emilio\AppData\Local\Spotify
2014-03-02 19:06 - 2013-03-25 01:44 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-03-02 19:06 - 2013-03-25 01:44 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-03-02 18:47 - 2014-03-02 18:47 - 01064488 _____ (BillP Studios) C:\Users\Emilio\Downloads\wpsetup.exe
2014-03-02 18:47 - 2014-02-02 15:42 - 00000000 ____D () C:\ProgramData\InstallMate
2014-03-02 18:35 - 2014-03-02 17:49 - 141656540 _____ () C:\Users\Emilio\Downloads\TS-DBDEN.part5.rar
2014-03-02 18:14 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-03-02 17:19 - 2014-03-02 17:19 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-03-02 17:17 - 2014-03-02 17:17 - 00944308 _____ () C:\Users\Emilio\Desktop\Screenshots.zip
2014-03-02 17:15 - 2014-03-02 17:14 - 00000000 ____D () C:\Users\Emilio\Desktop\Neuer Ordner (3)
2014-03-02 16:37 - 2014-02-01 20:58 - 00012292 ____H () C:\Users\Emilio\.DS_Store
2014-03-02 16:34 - 2014-02-07 11:04 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-02 16:34 - 2014-02-07 11:04 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-02 16:34 - 2014-02-07 11:04 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-25 11:41 - 2014-03-08 13:24 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-02-25 11:41 - 2014-03-08 13:24 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-02-25 11:41 - 2014-03-08 13:24 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-02-16 21:32 - 2013-08-17 15:42 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-16 21:31 - 2013-03-29 15:05 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-16 20:49 - 2014-02-16 20:49 - 00198742 _____ () C:\Users\Emilio\Downloads\extension_1_0_0_10.crx
2014-02-15 13:00 - 2013-03-16 15:05 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-15 13:00 - 2013-03-16 15:05 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-14 23:38 - 2014-02-14 23:26 - 305247075 _____ () C:\Users\Emilio\Downloads\Texture Pack by DvizehEdits.rar
2014-02-14 14:21 - 2014-02-14 14:21 - 00006124 _____ () C:\Users\Emilio\Downloads\circo.zip
2014-02-14 14:21 - 2013-03-16 14:51 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\SoftGrid Client
2014-02-14 14:17 - 2014-02-14 14:17 - 00013475 _____ () C:\Users\Emilio\Downloads\dotboundary.zip
2014-02-13 00:12 - 2014-02-13 00:12 - 05330264 _____ (Apple Inc.) C:\Users\Emilio\Downloads\WindowsMigrationAssistantSetup.exe
2014-02-13 00:12 - 2014-02-13 00:12 - 05330264 _____ (Apple Inc.) C:\Users\Emilio\Downloads\WindowsMigrationAssistantSetup (1).exe
2014-02-10 21:40 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-02-10 21:35 - 2013-03-21 23:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-07 23:50 - 2014-02-07 12:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-02-07 20:27 - 2014-02-07 20:27 - 00003274 _____ () C:\Windows\System32\Tasks\{49FC3A0D-8090-4E54-9355-7E03E799FA7C}
2014-02-07 19:12 - 2014-02-07 19:12 - 00001270 _____ () C:\Users\Emilio\Desktop\Revo Uninstaller.lnk
2014-02-07 19:12 - 2014-02-07 19:12 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group

Some content of TEMP:
====================
C:\Users\Emilio\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-02 18:07

==================== End Of Log ============================

--- --- ---

--- --- ---


Zitat:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2014 01
Ran by Emilio at 2014-03-09 13:15:56
Running from C:\Users\Emilio\Desktop\FRST-OlderVersion
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avira (HKLM-x32\...\{7b05af00-d234-4cf0-8cc3-1fcb21da2374}) (Version: 1.0.5168.20630 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.0.5168.20630 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
Avira SearchFree Toolbar (HKLM-x32\...\{41564952-412D-5637-4300-A758B70C0A00}) (Version: 12.10.0.2951 - APN, LLC)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - )
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: - )
Canon IJ Network Scan Utility (HKLM-x32\...\Canon_IJ_Network_Scan_UTILITY) (Version: - )
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: - )
Canon MG5200 series Benutzerregistrierung (HKLM-x32\...\Canon MG5200 series Benutzerregistrierung) (Version: - )
Canon MG5200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series) (Version: - )
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - )
Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 3.28 - Piriform)
CD-LabelPrint (HKLM-x32\...\MediaNavigation.CDLabelPrint) (Version: - )
DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden
Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.)
Eye Candy 4000 (HKLM-x32\...\Eye Candy 4000) (Version: - )
foobar2000 v1.2.9 (HKLM-x32\...\foobar2000) (Version: 1.2.9 - Peter Pawlowski)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.146 - Google Inc.)
Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP Auto (Version: 1.0.12935.3667 - Hewlett-Packard Company) Hidden
HP Customer Experience Enhancements (x32 Version: 6.0.1.8 - Hewlett-Packard) Hidden
HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Postscript Converter (Version: 3.1.3591 - Hewlett-Packard) Hidden
HP Setup (HKLM-x32\...\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15430.4033 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 11.00.0001 - Hewlett-Packard)
iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.3.1427 - Intel Corporation)
Intel(R) Network Connections 16.8.45.1 (HKLM\...\PROSetDX) (Version: 16.8.45.1 - Intel)
Intel(R) Network Connections 16.8.45.1 (Version: 16.8.45.1 - Intel) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.6.245 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games)
Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.5139.5005 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.4.304.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.3.0 - Mozilla)
Mozilla Thunderbird 24.3.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.3.0 (x86 de)) (Version: 24.3.0 - Mozilla)
opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.8 - Pando Networks Inc.)
PDF Complete Corporate Edition (HKLM-x32\...\PDF Complete) (Version: 4.1.9 - PDF Complete, Inc)
Personal dirActor 1.4.1 (HKLM-x32\...\Personal dirActor_is1) (Version: - dirActor UG (haftungsbeschränkt))
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6730 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 5.5.0.5223 - CyberLink Corp.) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Secunia PSI (3.0.0.6005) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.6005 - Secunia)
Security Task Manager 1.8g (HKLM-x32\...\Security Task Manager) (Version: 1.8g - Neuber Software)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Spotify (HKCU\...\Spotify) (Version: 0.9.7.16.g4b197456 - Spotify AB)
SpywareBlaster 5.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC)
TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.19045 - TeamViewer)
Windows-Migrationsassistent (HKLM-x32\...\{1A3A92EC-A218-4FEE-8A51-05BCD409A048}) (Version: 1.0.5.6 - Apple Inc.)
WinPatrol (HKLM\...\{84481A87-2316-4923-8FAB-3BA8CA29323D}) (Version: 30.1.2014 - BillP Studios)
WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WinZip 18.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DF}) (Version: 18.0.10661 - WinZip Computing, S.L. )

==================== Restore Points =========================

02-03-2014 15:34:15 Windows Update
02-03-2014 15:53:14 Revo Uninstaller's restore point - Adobe Photoshop 6.0
06-03-2014 11:26:41 Windows Update
06-03-2014 14:14:57 Windows Update
07-03-2014 18:49:14 Revo Uninstaller's restore point - Adobe Photoshop 6.0
07-03-2014 19:22:19 Removed WinZip 15.0
07-03-2014 19:24:11 Removed WinZip 15.0
07-03-2014 19:26:13 WinZip 18.0 wird installiert
08-03-2014 11:55:02 Windows Update
08-03-2014 11:56:38 Windows Update
08-03-2014 18:01:20 Windows Update

==================== Hosts content: ==========================

2009-07-14 03:34 - 2014-01-18 12:47 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {1FE790B1-50B5-4CA0-9DFD-AA416E9D0A7B} - \ParetoLogic Registration3 No Task File
Task: {23784219-13A2-4630-B74A-AF88C0DE83AE} - \PC Health Advisor Defrag No Task File
Task: {24CBE55B-C615-43D0-A914-BF36E914A2DE} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {2DD09160-11B3-4594-94D3-6F8F106179BE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {3F7FFABC-3E0F-42F9-B9CE-4FEDAB73F668} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-16] (Google Inc.)
Task: {5D3FC092-5751-439F-9540-0E3ABAE33E02} - System32\Tasks\HPCeeScheduleForEmilio => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {6C118269-6F0A-4D52-8C54-DC51613E422F} - \AdobeFlashPlayerUpdate No Task File
Task: {76E8A057-3D11-4C0C-A573-D5B15C11D96A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-12-12] (Hewlett-Packard Company)
Task: {B9A4EFB7-1CEA-48BE-BF50-34194F8EC1D1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-02] (Adobe Systems Incorporated)
Task: {C9518826-3CE7-4630-9CF8-4F45827AF66F} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {D964CDF1-8C29-476F-8CD4-53389CAE73A6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe
Task: {E2E50C56-69D7-4DDE-8326-BF138DA4A83C} - \BitGuard No Task File
Task: {E442F17C-E888-4116-AAA6-D37CA2E8CF39} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {EFEDEBC1-DE42-4844-A07C-0E19F8833B9E} - \ParetoLogic Update Version3 No Task File
Task: {F3A0430E-5268-41C4-827E-4C6AD587C275} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-16] (Google Inc.)
Task: {F48D84B2-6590-42C7-85F6-246D0E639BBD} - \PC Health Advisor No Task File
Task: {F6C97E66-F294-4835-A3DE-28610BE18645} - \AdobeFlashPlayerUpdate 2 No Task File
Task: {F96D933F-48CE-49DC-A49C-73B7851C55CA} - System32\Tasks\{D81373EA-92C0-47DD-B9F0-DFC44598D9F6} => C:\Program Files\Adobe DE\Photoshop 6.0\Photoshp.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForEmilio.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Loaded Modules (whitelisted) =============

2012-03-20 00:09 - 2012-03-20 00:09 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-03-08 13:24 - 2014-02-25 11:41 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 13:16 - 2014-01-20 13:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-02-24 11:29 - 2014-02-24 11:29 - 00111696 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll
2014-02-24 11:29 - 2014-02-24 11:29 - 00061520 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll
2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\Emilio\AppData\Roaming\Dropbox\bin\libcef.dll
2014-03-08 13:25 - 2014-02-24 11:29 - 00049744 _____ () C:\Users\Emilio\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:5C321E34
AlternateDataStreams: C:\Users\Emilio\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Emilio\Downloads\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo

==================== Safe Mode (whitelisted) ===================


==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (03/09/2014 00:02:18 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown

Error: (03/09/2014 00:02:18 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown

Error: (03/09/2014 11:56:13 AM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICESOFTWAREPROTECTIONPLATFORM\OSPPWMI.MOF

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\SENSORSCPL.MFL

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\OFFLINEFILESWMIPROVIDER_UNINSTALL.MFL

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\OFFLINEFILESWMIPROVIDER.MFL

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\TSCFGWMI.MFL

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\POLPROCL.MFL

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\AUXILIARYDISPLAYCPL.MFL

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt) (User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\POLICMAN.MFL


System errors:
=============
Error: (03/09/2014 00:05:52 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Intel(R) Management and Security Application User Notification Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (03/09/2014 00:05:52 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Intel(R) Management and Security Application User Notification Service erreicht.

Error: (03/09/2014 00:01:29 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Skype Updater erreicht.

Error: (03/09/2014 00:01:26 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Intel(R) Capability Licensing Service Interface" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (03/09/2014 00:01:19 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Bonjour Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (03/09/2014 00:01:17 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Andrea RT Filters Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (03/09/2014 00:00:41 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Realtek Audio Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (03/09/2014 11:12:38 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Intel(R) Management and Security Application User Notification Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (03/09/2014 11:12:38 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Intel(R) Management and Security Application User Notification Service erreicht.

Error: (03/09/2014 11:12:36 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.


Microsoft Office Sessions:
=========================
Error: (03/09/2014 00:02:18 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown

Error: (03/09/2014 00:02:18 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown

Error: (03/09/2014 11:56:13 AM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICESOFTWAREPROTECTIONPLATFORM\OSPPWMI.MOF

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\SENSORSCPL.MFL

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\OFFLINEFILESWMIPROVIDER_UNINSTALL.MFL

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\OFFLINEFILESWMIPROVIDER.MFL

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\TSCFGWMI.MFL

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\POLPROCL.MFL

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\AUXILIARYDISPLAYCPL.MFL

Error: (03/09/2014 11:56:05 AM) (Source: WinMgmt)(User: )
Description: 0x8004401eC:\WINDOWS\SYSTEM32\WBEM\EN-US\POLICMAN.MFL


CodeIntegrity Errors:
===================================
Date: 2014-01-18 12:47:05.660
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2014-01-18 12:47:05.625
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info ===========================

Percentage of memory in use: 24%
Total physical RAM: 3970.95 MB
Available physical RAM: 3010.58 MB
Total Pagefile: 7940.07 MB
Available Pagefile: 6094.79 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:456.62 GB) (Free:316.6 GB) NTFS
Drive d: (HP_RECOVERY) (Fixed) (Total:8.94 GB) (Free:1 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: BA008566)

Partition: GPT Partition Type.

==================== End Of Log ============================
Faber Service Scanner:
Zitat:

Farbar Service Scanner Version: 25-02-2014
Ran by Emilio (administrator) on 09-03-2014 at 13:31:14
Running from "C:\Users\Emilio\Downloads"
Microsoft Windows 7 Professional Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****

schrauber 10.03.2014 12:59

Doch jetzt :)

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

CHR HKLM-x32\...\Chrome\Extension: [pcoohmdcpejoeggdnihdfhohjgdbllgm] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7C\CRX\ToolbarCR.crx [2013-03-16]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.




Fertig :)

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :)

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.

Kriega 10.03.2014 14:58

Danke, aber ein Microsoft Security Essentials funktioniert trotzdem immer noch nicht :/

Zitat:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-03-2014 02
Ran by Emilio at 2014-03-10 14:54:42 Run:1
Running from C:\Users\Emilio\Desktop\FRST-OlderVersion
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
CHR HKLM-x32\...\Chrome\Extension: [pcoohmdcpejoeggdnihdfhohjgdbllgm] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7C\CRX\ToolbarCR.crx [2013-03-16]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
*****************

HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pcoohmdcpejoeggdnihdfhohjgdbllgm => Key deleted successfully.
"C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7C\CRX\ToolbarCR.crx" => File/Directory not found.
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.

==== End of Fixlog ====

schrauber 11.03.2014 09:45

Was genau kommt an Fehlermeldung?

Kriega 11.03.2014 10:57

wenn ich den öffnen will kommt:


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:17 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132