Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Blockandsurf win7 nicht los zu kriegen (https://www.trojaner-board.de/163563-blockandsurf-win7-los-kriegen.html)

hatzi 03.02.2015 22:57

Blockandsurf win7 nicht los zu kriegen
 
Guten Abend,

trotz Norton 360 leider BlockAndSurf gefangen.
Ich hoffe es kann mir jemand helfen.

FRST wirft folgendes aus:
FRST.txt

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2015
Ran by Juergen (administrator) on JUERGEN-NETBOOK on 03-02-2015 22:38:43
Running from C:\Users\Juergen\Downloads
Loaded Profiles: Juergen (Available profiles: Juergen)
Platform: Microsoft Windows 7 Starter  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.6.0.27\ccsvchst.exe
() C:\Program Files\USBLogon\usblonsvc.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.6.0.27\ccsvchst.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Windows\vsnpstd3.exe
() C:\Windows\tsnpstd3.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHTU.EXE
() C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
() C:\Program Files\ownCloud\owncloud.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [USBLogon] => C:\Program Files\USBLogon\usblondetect.exe [12288 2013-10-01] (Quadsoft)
HKLM\...\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\...\Run: [snpstd3] => C:\Windows\vsnpstd3.exe [835584 2007-05-10] ()
HKLM\...\Run: [tsnpstd3] => C:\Windows\tsnpstd3.exe [339968 2009-06-30] ()
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TATIHTU.EXE [220800 2013-08-02] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Run: [ownCloud] => C:\Program Files\ownCloud\owncloud.exe [23416869 2014-12-18] ()
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {42de7e31-5715-11e4-bbee-e0ca947c51af} - E:\LGAutoRun.exe
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {42de7e35-5715-11e4-bbee-e0ca947c51af} - E:\LGAutoRun.exe
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {4f677a70-6ca3-11e4-bbd1-e0ca947c51af} - D:\LGAutoRun.exe
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {4f7c33b7-32af-11e3-b87e-99da9e00c704} - D:\AutoRun.exe
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [  OCError] -> {0960F090-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCErrorShared] -> {0960F091-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOK] -> {0960F092-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOKShared] -> {0960F093-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSync] -> {0960F094-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSyncShared] -> {0960F095-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarning] -> {0960F096-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarningShared] -> {0960F097-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton 360\Engine\20.6.0.27\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton 360\Engine\20.6.0.27\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton 360\Engine\20.6.0.27\buShell.dll (Symantec Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton 360\Engine\20.6.0.27\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Norton 360\Engine\20.6.0.27\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.6.0.27\coIEPlg.dll (Symantec Corporation)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.6.1

FireFox:
========
FF ProfilePath: C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2065253504-3069135328-3144787471-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF Extension: KeeFox - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\keefox@chris.tomlinson [2015-01-15]
FF Extension: Bookmark Favicon Changer - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\bookmarkfaviconchanger@sonthakit.xpi [2013-08-02]
FF Extension: Firebug - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\firebug@software.joehewitt.com.xpi [2013-08-02]
FF Extension: Firepicker - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\firepicker@thedarkone.xpi [2013-08-02]
FF Extension: SQLite Manager - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\SQLiteManager@mrinalkant.blogspot.com.xpi [2014-12-31]
FF Extension: Delete Bookmark Icons - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{04514a2c-a3ab-4f47-8688-55f911b0fe75}.xpi [2013-08-02]
FF Extension: Showcase - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}.xpi [2013-08-02]
FF Extension: Password Exporter - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi [2013-08-02]
FF Extension: Adblock Plus - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-02]
FF Extension: Tab Mix Plus - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2013-08-02]
FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn [2015-02-03]

Chrome:
=======
CHR Profile: C:\Users\Juergen\AppData\Local\Google\Chrome\User Data\default
CHR HKLM\...\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files\Norton 360\Engine\20.6.0.27\Exts\Chrome.crx [2014-12-09]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 N360; C:\Program Files\Norton 360\Engine\20.6.0.27\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 USBLogonService; C:\Program Files\USBLogon\usblonsvc.exe [12288 2013-10-01] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20150106.001\BHDrvx86.sys [1164504 2015-01-06] (Symantec Corporation)
R3 btwampfl; C:\Windows\system32\drivers\btwampfl.sys [508632 2015-01-16] (Broadcom Corporation.)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1406000.01B\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [378672 2014-12-13] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [111408 2014-12-13] (Symantec Corporation)
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20150130.001\IDSvix86.sys [503000 2015-01-13] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20150202.034\NAVENG.SYS [95704 2015-01-26] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20150202.034\NAVEX15.SYS [1636696 2015-01-26] (Symantec Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
S3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10526464 2009-07-03] (Sonix Co. Ltd.)
R3 SRTSP; C:\Windows\System32\Drivers\N360\1406000.01B\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1406000.01B\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1406000.01B\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1406000.01B\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-08-04] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1406000.01B\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360\1406000.01B\SYMNETS.SYS [339544 2013-04-25] (Symantec Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-03 22:38 - 2015-02-03 22:39 - 00014650 _____ () C:\Users\Juergen\Downloads\FRST.txt
2015-02-03 22:38 - 2015-02-03 22:38 - 01122304 _____ (Farbar) C:\Users\Juergen\Downloads\FRST.exe
2015-02-03 22:38 - 2015-02-03 22:38 - 00000000 ____D () C:\FRST
2015-02-03 22:17 - 2015-02-03 22:17 - 00000559 _____ () C:\Users\Juergen\Desktop\fixlist.txt
2015-02-03 22:16 - 2015-02-03 22:16 - 00000559 _____ () C:\Users\Juergen\Desktop\filelist.txt
2015-02-03 21:31 - 2015-02-03 21:31 - 11225840 _____ (SurfRight B.V.) C:\Users\Juergen\Downloads\hitmanpro_x64.exe
2015-02-03 21:06 - 2015-02-03 22:07 - 00000000 ____D () C:\AdwCleaner
2015-02-03 21:05 - 2015-02-03 21:05 - 02194432 _____ () C:\Users\Juergen\Downloads\adwcleaner_4.109.exe
2015-02-03 20:22 - 2015-02-03 21:38 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-03 20:21 - 2015-02-03 20:21 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-03 20:21 - 2015-02-03 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-03 20:21 - 2015-02-03 20:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-03 20:21 - 2015-02-03 20:21 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-02-03 20:21 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-03 20:21 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-03 20:21 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-03 20:20 - 2015-02-03 20:20 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Juergen\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-03 19:41 - 2015-02-03 19:41 - 00000000 ____D () C:\Users\Juergen\AppData\Local\FreeOCR
2015-02-03 19:35 - 2015-02-03 20:37 - 00000000 ____D () C:\FreeOCR
2015-02-03 19:35 - 2007-03-10 10:11 - 02680320 _____ (HiComponents) C:\Windows\system32\ImageEnXLibrary.ocx
2015-02-03 19:33 - 2015-02-03 19:33 - 00000000 ____D () C:\Program Files\Temp
2015-02-03 19:32 - 2015-02-03 19:32 - 00414625 _____ ( ) C:\Users\Juergen\Downloads\FreeOCR-5.02.exe
2015-02-03 19:32 - 2015-02-03 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2015-02-03 19:31 - 2015-02-03 19:32 - 00000000 ____D () C:\Program Files\PDFCreator
2015-02-03 19:31 - 2015-01-22 16:14 - 00098488 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2015-02-03 19:26 - 2015-02-03 19:26 - 27721680 _____ (pdfforge ) C:\Users\Juergen\Downloads\PDFCreator-2_0_2-setup.exe
2015-01-28 22:25 - 2015-01-28 22:25 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-01-28 22:25 - 2015-01-28 22:21 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2015-01-28 22:25 - 2015-01-28 22:21 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2015-01-28 22:25 - 2015-01-28 22:21 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-01-28 22:23 - 2015-01-28 22:23 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-01-18 21:05 - 2015-01-18 21:06 - 00000000 ____D () C:\Users\Juergen\ownCloudBoule
2015-01-18 20:59 - 2015-01-18 20:59 - 46286392 _____ (ownCloud) C:\Users\Juergen\Downloads\ownCloud-1.7.1.4382-setup(1).exe
2015-01-18 20:05 - 2014-12-11 18:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-18 20:05 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-01-18 11:03 - 2015-01-18 16:34 - 00001372 _____ () C:\Users\Juergen\Desktop\Dapile wecken.lnk
2015-01-18 11:00 - 2015-01-18 11:00 - 00000000 ____D () C:\Users\Juergen\AppData\Local\www.oette.info
2015-01-18 10:59 - 2015-01-18 10:59 - 00077936 _____ (Gammadyne Corporation) C:\Users\Juergen\Downloads\wol.exe
2015-01-18 10:55 - 2015-01-18 10:55 - 00000000 ____H () C:\Users\Juergen\Documents\Default.rdp
2015-01-18 10:46 - 2015-01-18 10:46 - 01964729 _____ () C:\Users\Juergen\Downloads\WOL2.7z
2015-01-18 00:30 - 2015-01-18 00:30 - 00039424 _____ () C:\Users\Juergen\Desktop\Hessen.xls
2015-01-18 00:25 - 2015-01-18 00:25 - 00035672 _____ () C:\Users\Juergen\Desktop\Mappe1.txt
2015-01-17 23:09 - 2015-01-17 23:09 - 00004290 _____ () C:\Users\Juergen\Desktop\karte_hessen.html
2015-01-17 23:08 - 2015-01-17 23:08 - 00004290 _____ () C:\Users\Juergen\Downloads\karte_hessen.html
2015-01-17 22:44 - 2015-01-17 22:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-01-17 22:44 - 2015-01-17 22:44 - 00000000 ____D () C:\Program Files\7-Zip
2015-01-17 22:40 - 2015-01-17 22:40 - 01110476 _____ () C:\Users\Juergen\Downloads\7z920.exe
2015-01-17 22:39 - 2015-01-17 22:39 - 01376768 _____ () C:\Users\Juergen\Downloads\7z920-x64.msi
2015-01-17 22:26 - 2015-01-17 22:26 - 00196096 _____ () C:\Users\Juergen\Desktop\DM-Meldung_2014.xls
2015-01-17 10:54 - 2013-10-02 00:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-01-17 10:53 - 2013-10-02 01:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-01-17 10:53 - 2013-10-02 01:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-01-17 10:53 - 2013-10-02 01:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-01-17 10:53 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-01-17 10:53 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-01-17 10:53 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-01-17 10:53 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-01-17 10:53 - 2013-10-01 23:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-01-17 10:53 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-01-17 00:47 - 2015-01-17 00:49 - 00004270 _____ () C:\Users\Juergen\Desktop\karte_hallen.html
2015-01-16 16:31 - 2015-01-17 01:48 - 00284672 _____ () C:\Users\Juergen\Desktop\d5c41_joodb_spielorte-1.xls
2015-01-16 16:18 - 2015-01-16 16:18 - 00171501 _____ () C:\Users\Juergen\Downloads\d5c41_joodb_spielorte.csv
2015-01-16 14:53 - 2015-01-16 14:57 - 00004305 _____ () C:\Users\Juergen\Desktop\karte_gesamt.html
2015-01-16 08:47 - 2015-01-16 08:47 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
2015-01-16 08:46 - 2015-01-16 08:46 - 00000000 ____D () C:\Users\Juergen\Documents\Bluetooth-Exchange-Ordner
2015-01-16 08:46 - 2015-01-16 08:46 - 00000000 ____D () C:\Users\Juergen\AppData\Local\Broadcom
2015-01-16 08:46 - 2015-01-16 08:35 - 00508632 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwampfl.sys
2015-01-16 08:39 - 2015-01-16 08:39 - 00001125 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Problem Report.lnk
2015-01-16 08:38 - 2015-01-16 08:35 - 00175144 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys
2015-01-16 08:38 - 2015-01-16 08:35 - 00152400 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys
2015-01-16 08:38 - 2015-01-16 08:35 - 00033832 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys
2015-01-16 08:38 - 2015-01-16 08:35 - 00018728 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwrchid.sys
2015-01-16 08:36 - 2015-01-16 08:36 - 00000000 ____D () C:\Program Files\WIDCOMM
2015-01-16 08:23 - 2015-01-16 08:23 - 04171576 _____ (Broadcom Corporation.) C:\Users\Juergen\Downloads\SetupBtwDownloadSE.exe
2015-01-15 23:31 - 2014-12-19 03:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-15 23:31 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-01-15 23:31 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-15 23:30 - 2014-12-19 02:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-15 23:30 - 2014-12-06 04:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-15 00:08 - 2015-01-15 00:08 - 00771699 _____ () C:\Users\Juergen\Desktop\OpenLayers.js
2015-01-14 23:54 - 2015-01-14 23:54 - 00014336 _____ () C:\Users\Juergen\Desktop\pois.xls
2015-01-14 23:27 - 2015-01-15 00:03 - 00000701 _____ () C:\Users\Juergen\Desktop\dbcsv.php
2015-01-14 23:27 - 2015-01-14 23:29 - 00000207 _____ () C:\Users\Juergen\Desktop\dbconnect.php
2015-01-14 23:26 - 2015-01-15 00:17 - 00004251 _____ () C:\Users\Juergen\Desktop\karte.html
2015-01-14 23:25 - 2015-01-14 23:25 - 00258079 _____ () C:\Users\Juergen\Desktop\basic.html
2015-01-11 15:46 - 2015-01-18 21:02 - 00000981 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ownCloud.lnk
2015-01-11 15:45 - 2015-01-11 15:46 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-11 15:41 - 2015-01-11 15:43 - 46286392 _____ (ownCloud) C:\Users\Juergen\Downloads\ownCloud-1.7.1.4382-setup.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-03 22:32 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-02-03 22:18 - 2013-10-06 19:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-03 22:15 - 2009-07-14 05:34 - 00016352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-03 22:15 - 2009-07-14 05:34 - 00016352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-03 22:13 - 2013-07-30 17:54 - 01865468 _____ () C:\Windows\WindowsUpdate.log
2015-02-03 22:08 - 2010-11-20 22:48 - 00137298 _____ () C:\Windows\PFRO.log
2015-02-03 22:08 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-03 22:08 - 2009-07-14 05:39 - 00045827 _____ () C:\Windows\setupact.log
2015-02-03 20:58 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system
2015-02-03 20:40 - 2013-11-18 21:26 - 00000000 ____D () C:\Users\Juergen\ownCloud
2015-02-03 20:38 - 2013-12-09 20:21 - 00000000 ____D () C:\Program Files\Free mp3 Wma Converter
2015-02-03 07:00 - 2013-08-01 07:05 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-01-28 22:27 - 2014-01-29 21:09 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-28 22:22 - 2014-10-18 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-01-28 22:21 - 2014-10-18 08:53 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2015-01-28 22:20 - 2014-08-18 12:29 - 00000000 ____D () C:\Program Files\Java
2015-01-25 10:40 - 2013-08-03 15:56 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-01-25 10:40 - 2013-08-03 15:56 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-01-20 21:08 - 2014-08-18 12:36 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\vlc
2015-01-20 19:47 - 2014-08-19 12:48 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\dvdcss
2015-01-20 19:43 - 2010-11-20 22:01 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-18 21:03 - 2013-11-18 21:25 - 00000000 ____D () C:\Users\Juergen\AppData\Local\ownCloud
2015-01-18 21:02 - 2013-11-18 21:25 - 00000000 ____D () C:\Program Files\ownCloud
2015-01-18 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-01-18 11:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-01-18 10:49 - 2013-08-02 10:14 - 00000000 ___RD () C:\Users\Juergen\Desktop\Programme
2015-01-17 11:05 - 2009-07-14 03:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-17 11:04 - 2011-03-20 08:51 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE
2015-01-16 08:01 - 2013-08-24 01:37 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\Mp3tag
2015-01-15 23:39 - 2013-08-02 09:17 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-15 23:32 - 2013-07-31 21:58 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-15 23:28 - 2013-08-25 09:04 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\foobar2000
2015-01-11 16:58 - 2014-12-13 12:36 - 00000000 ____D () C:\Users\Juergen\Desktop\Desktop Ablage 20141213
2015-01-04 09:54 - 2014-12-29 22:51 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\FileZilla

==================== Files in the root of some directories =======

2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Ambience
2013-12-05 20:12 - 2013-12-05 20:12 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Ambient
2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Analog Mono
2013-12-05 20:07 - 2013-12-05 20:07 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Audio Units
2013-12-05 21:07 - 2013-12-05 21:07 - 0003584 _____ () C:\Users\Juergen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-08-04 10:14 - 2013-08-04 10:14 - 0000600 _____ () C:\Users\Juergen\AppData\Local\PUTTY.RND
2014-11-15 16:21 - 2014-11-15 16:21 - 0000218 _____ () C:\Users\Juergen\AppData\Local\recently-used.xbel
2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\ProgramData\Analog Swirl
2013-12-05 20:12 - 2013-12-05 20:12 - 0000268 ___RH () C:\ProgramData\Analog Sync
2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\ProgramData\Animals
2013-12-05 20:12 - 2013-12-05 20:12 - 0000012 ___RH () C:\ProgramData\Basic Track
2013-12-05 20:09 - 2013-12-05 20:09 - 0000012 ___RH () C:\ProgramData\Bass
2013-12-05 20:07 - 2013-12-05 20:09 - 0000012 ___RH () C:\ProgramData\BSD
2013-12-05 20:07 - 2013-12-05 20:07 - 0000012 ___RH () C:\ProgramData\ColorSync
2013-12-05 20:07 - 2013-12-05 20:08 - 0000020 ____H () C:\ProgramData\PKP_DLeo.DAT
2013-12-05 20:12 - 2014-01-25 13:02 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT
2013-12-05 20:09 - 2014-11-12 09:25 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT
2013-12-05 20:09 - 2014-11-12 09:35 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT

Some content of TEMP:
====================
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.dll
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.exe
C:\Users\Juergen\AppData\Local\Temp\DE83F836-32DF-FEC7-3997-961617D0D8B7.exe
C:\Users\Juergen\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Juergen\AppData\Local\Temp\Quarantine.exe
C:\Users\Juergen\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-14 22:51

==================== End Of Log ============================

--- --- ---

Addition.txt
Zitat:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-02-2015
Ran by Juergen at 2015-02-03 22:40:25
Running from C:\Users\Juergen\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton 360 Online (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton 360 Online (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton 360 Online (Disabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Acoustica Standard Edition 5.0 (HKLM\...\Acoustica Standard Edition_is1) (Version: 5.0 - Acon AS)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Amazon MP3-Downloader 1.0.18 (HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC)
AppInventor Setup (HKLM\...\AppInventor Setup) (Version: 2.2 - Massachusetts Institute of Technology)
Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.4852 - CDBurnerXP)
Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
Download Navigator (HKLM\...\{E728441A-7820-4B1C-87C9-DE7BE37B2953}) (Version: 1.1.0 - SEIKO EPSON CORPORATION)
ElsterFormular (HKLM\...\ElsterFormular) (Version: 14.4.20130909 - Landesfinanzdirektion Thüringen)
EPSON BX535WD Series Printer Uninstall (HKLM\...\EPSON BX535WD Series) (Version: - SEIKO EPSON Corporation)
Epson Easy Photo Print 2 (HKLM\...\{FFF841F3-9A15-4F61-BD16-C19F132E5A27}) (Version: 2.3.0.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2)
Epson Event Manager (HKLM\...\{FA9D303D-0FB2-49C7-9397-8E6B11EA892D}) (Version: 2.50.0001 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.4j - SEIKO EPSON CORPORATION)
Extended Asian Language font pack for Adobe Reader XI (HKLM\...\{AC76BA86-7AD7-2530-0000-A00000000004}) (Version: 11.0.0 - Adobe Systems Incorporated)
FFmpeg v0.6.2 for Audacity (HKLM\...\FFmpeg for Audacity_is1) (Version: - )
FileZilla Client 3.9.0.6 (HKLM\...\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse)
FLAC 1.2.1b (remove only) (HKLM\...\FLAC) (Version: 1.2.1b - Xiph.org)
foobar2000 v1.3 (HKLM\...\foobar2000) (Version: 1.3 - Peter Pawlowski)
FreeFileSync 6.8 (HKLM\...\FreeFileSync) (Version: 6.8 - Zenju)
Freemake Audio Converter Version 1.1.0 (HKLM\...\Freemake Audio Converter_is1) (Version: 1.1.0 - Ellora Assets Corporation)
Frontplatten Designer (HKLM\...\Frontplatten Designer) (Version: 4.3.1 - Schaeffer AG)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
inSSIDer Home (HKLM\...\{9E54E4AE-B67A-4925-8E92-0E1F9817FD73}) (Version: 3.1.2.1 - MetaGeek, LLC)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.14.10.2117 - Intel Corporation)
iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Kinovea (HKLM\...\Kinovea) (Version: 0.8.15 - Kinovea) <==== ATTENTION!
LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version: - )
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM\...\{90110407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
MiniTool Partition Wizard Home Edition 8.1.1 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.)
Mozilla Firefox 35.0.1 (x86 de) (HKLM\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mp3tag v2.64 (HKLM\...\Mp3tag) (Version: v2.64 - Florian Heidenreich)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nikon Message Center 2 (HKLM\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon)
Nikon Movie Editor (HKLM\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.8.0 - Nikon)
Norton 360 (HKLM\...\N360) (Version: 20.6.0.27 - Symantec Corporation)
Notepad++ (HKLM\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
ownCloud (HKLM\...\ownCloud) (Version: 1.7.1.4382 - ownCloud)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.2 - pdfforge)
Picture Control Utility (HKLM\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.4.15 - Nikon)
Softsqueeze 3.9b2 (HKLM\...\Softsqueeze 3.9b2) (Version: - Ralph Irving)
Trust Webcam (HKLM\...\{ECD03DA7-5952-406A-8156-5F0C93618D1F}) (Version: 5.18.1211.103 - Sonix)
USBLogon 1.6.2.3 (HKLM\...\{E7D9D138-7DFA-441A-B1A9-703193C5D6D3}_is1) (Version: 1.6.2.3 - Quadsoft)
ViewNX 2 (HKLM\...\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.8.2 - Nikon)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WIDCOMM Bluetooth Software (HKLM\...\{A1439D4F-FD46-47F2-A1D3-FEE097C29A09}) (Version: 6.5.1.5800 - Broadcom Corporation)
WinRAR 4.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{3f04dadf-6ea4-44d1-a507-03cad176f443}\InprocServer32 -> C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)

==================== Restore Points =========================

15-01-2015 23:31:24 Windows Update
16-01-2015 08:38:24 Broadcom BTW Restore Point
17-01-2015 09:17:28 Windows Update
18-01-2015 20:05:50 Windows Update
18-01-2015 21:01:25 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
03-02-2015 21:26:44 Norton 360 Registry Clean

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {06B6DDAB-AAB0-4D0B-B52A-F905DE9B6A9F} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files\Norton 360\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {196C89FF-F3D9-448B-B7C1-92B1A0935C07} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton 360\Engine\20.6.0.27\WSCStub.exe [2014-12-06] (Symantec Corporation)
Task: {485B4A61-78AF-4C9E-A9CC-B8529DC8CE1B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated)
Task: {65FAAE39-54E7-4A39-B113-451EEB66F7D5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {850628D5-9DE8-48E0-A6CF-EF448C6902A6} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files\Norton 360\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {CB7C8110-39F3-4E02-B442-E083E9851C10} - System32\Tasks\{945E7209-E1C4-479E-A68B-7B35F0A2E979} => pcalua.exe -a C:\Users\Juergen\Downloads\softsqueeze_windows_3_9b2.exe -d C:\Users\Juergen\Downloads

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2014-10-11 12:06 - 2014-10-11 12:06 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-10-16 10:15 - 2014-10-16 10:15 - 00035328 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2014-05-24 17:41 - 2014-05-24 17:41 - 00091648 _____ () C:\Program Files\FileZilla FTP Client\libgcc_s_sjlj-1.dll
2014-05-24 17:41 - 2014-05-24 17:41 - 00892416 _____ () C:\Program Files\FileZilla FTP Client\libstdc++-6.dll
2013-11-04 13:23 - 2013-10-01 17:11 - 00012288 _____ () C:\Program Files\USBLogon\usblonsvc.exe
2014-12-09 16:50 - 2012-05-30 07:51 - 00699280 ____R () C:\PROGRAM FILES\NORTON 360\ENGINE\20.6.0.27\wincfi39.dll
2014-12-17 12:44 - 2014-12-17 12:44 - 00046592 _____ () C:\Program Files\ownCloud\shellext\OCUtil_x86.dll
2014-11-30 14:14 - 2007-05-10 13:18 - 00835584 _____ () C:\Windows\vsnpstd3.exe
2014-11-30 14:14 - 2009-06-30 16:20 - 00339968 _____ () C:\Windows\tsnpstd3.exe
2013-05-22 19:50 - 2013-05-22 19:50 - 00400704 _____ () C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
2014-12-18 12:53 - 2014-12-18 12:53 - 23416869 _____ () C:\Program Files\ownCloud\owncloud.exe
2014-12-18 12:53 - 2014-12-18 12:53 - 03044905 _____ () C:\Program Files\ownCloud\libocsync.dll
2014-09-24 09:23 - 2014-09-24 09:23 - 00158048 _____ () C:\Program Files\ownCloud\libneon-27.dll
2014-09-21 23:32 - 2014-09-21 23:32 - 00084012 _____ () C:\Program Files\ownCloud\zlib1.dll
2014-09-22 02:45 - 2014-09-22 02:45 - 00095790 _____ () C:\Program Files\ownCloud\libgcc_s_sjlj-1.dll
2014-09-22 02:13 - 2014-09-22 02:13 - 00172695 _____ () C:\Program Files\ownCloud\libproxy.dll
2014-09-22 02:11 - 2014-09-22 02:11 - 00042626 _____ () C:\Program Files\ownCloud\libmodman.dll
2014-09-22 02:45 - 2014-09-22 02:45 - 00847430 _____ () C:\Program Files\ownCloud\libstdc++-6.dll
2014-09-22 01:05 - 2014-09-22 01:05 - 01150984 _____ () C:\Program Files\ownCloud\libxml2-2.dll
2014-09-22 01:10 - 2014-09-22 01:10 - 02164003 _____ () C:\Program Files\ownCloud\icui18n53.dll
2014-09-22 01:10 - 2014-09-22 01:10 - 01288240 _____ () C:\Program Files\ownCloud\icuuc53.dll
2014-09-22 01:10 - 2014-09-22 01:10 - 21540519 _____ () C:\Program Files\ownCloud\icudata53.dll
2014-09-22 01:16 - 2014-09-22 01:16 - 00144533 _____ () C:\Program Files\ownCloud\libpcre16-0.dll
2014-09-22 01:15 - 2014-09-22 01:15 - 01345629 _____ () C:\Program Files\ownCloud\libGLESv2.dll
2014-09-22 00:58 - 2014-09-22 00:58 - 00203567 _____ () C:\Program Files\ownCloud\libpng16-16.dll
2014-12-18 12:53 - 2014-12-18 12:53 - 15901197 _____ () C:\Program Files\ownCloud\libowncloudsync.dll
2014-09-22 01:15 - 2014-09-22 01:15 - 00150916 _____ () C:\Program Files\ownCloud\libEGL.dll
2014-09-22 01:08 - 2014-09-22 01:08 - 00197062 _____ () C:\Program Files\ownCloud\libjpeg-8.dll
2014-09-22 01:13 - 2014-09-22 01:13 - 00646511 _____ () C:\Program Files\ownCloud\libsqlite3-0.dll
2014-09-22 02:28 - 2014-09-22 02:28 - 00247028 _____ () C:\Program Files\ownCloud\libwebp-4.dll
2014-09-22 03:24 - 2014-09-22 03:24 - 00228655 _____ () C:\Program Files\ownCloud\libxslt-1.dll
2014-09-24 08:38 - 2014-09-24 08:38 - 00052119 _____ () C:\Program Files\ownCloud\libqt5keychain.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00702136 _____ () C:\Program Files\ownCloud\platforms\qwindows.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00032568 _____ () C:\Program Files\ownCloud\imageformats\qgif.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00035173 _____ () C:\Program Files\ownCloud\imageformats\qico.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00048436 _____ () C:\Program Files\ownCloud\imageformats\qjpeg.dll
2015-01-28 22:25 - 2015-01-28 22:25 - 03925104 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2015-01-25 10:40 - 2015-01-25 10:40 - 16844976 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Juergen\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Juergen\Desktop\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Public\Downloads\.DS_Store:AFP_AfpInfo

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-2065253504-3069135328-3144787471-500 - Administrator - Disabled)
Gast (S-1-5-21-2065253504-3069135328-3144787471-501 - Limited - Enabled)
Juergen (S-1-5-21-2065253504-3069135328-3144787471-1000 - Administrator - Enabled) => C:\Users\Juergen

==================== Faulty Device Manager Devices =============

Name: Generischer Marvell Yukon 88E8040-PCI-E-Fast-Ethernet-Controller
Description: Generischer Marvell Yukon 88E8040-PCI-E-Fast-Ethernet-Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Marvell
Service: yukonw7
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/03/2015 10:10:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 10:03:13 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (02/03/2015 09:48:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm adwcleaner_4.109.exe, Version 4.1.0.9 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: fa0

Startzeit: 01d03ff1cb531d5a

Endzeit: 31

Anwendungspfad: C:\Users\Juergen\Downloads\adwcleaner_4.109.exe

Berichts-ID:

Error: (02/03/2015 09:31:39 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (02/03/2015 09:14:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 09:00:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 08:41:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 07:02:51 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:20:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 35044267

Error: (02/02/2015 11:20:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 35044267


System errors:
=============
Error: (02/03/2015 10:08:53 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom

Error: (02/03/2015 09:58:59 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:58:49 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:58:42 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:58:26 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:58:21 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:57:58 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:57:53 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/03/2015 09:15:23 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {EA022610-0748-4C24-B229-6C507EBDFDBB}

Error: (02/03/2015 09:12:48 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom


Microsoft Office Sessions:
=========================
Error: (02/03/2015 10:10:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 10:03:13 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Users\Juergen\Downloads\hitmanp ro_x64.exe

Error: (02/03/2015 09:48:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: adwcleaner_4.109.exe4.1.0.9fa001d03ff1cb531d5a31C:\Users\Juergen\Downloads\adwcleaner_4.109.exe

Error: (02/03/2015 09:31:39 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Users\Juergen\Downloads\hitmanp ro_x64.exe

Error: (02/03/2015 09:14:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 09:00:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 08:41:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 07:02:51 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:20:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 35044267

Error: (02/02/2015 11:20:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 35044267


==================== Memory info ===========================

Processor: Intel(R) Atom(TM) CPU N455 @ 1.66GHz
Percentage of memory in use: 44%
Total physical RAM: 2037.3 MB
Available physical RAM: 1126.5 MB
Total Pagefile: 4074.59 MB
Available Pagefile: 3111.82 MB
Total Virtual: 2047.88 MB
Available Virtual: 1901.41 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:119.14 GB) (Free:12.64 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: E91F5269)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=119.1 GB) - (Type=07 NTFS)

==================== End Of Log ============================
Dank im voraus
Jürgen

cosinus 03.02.2015 23:00

Hi,

Virenscanner vor dem Löschen mit den Tools bitte deaktivieren:

Adware/Junkware/Toolbars entfernen

(alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!)

1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




3. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


hatzi 03.02.2015 23:33

SChnelle Hilfe - Vielen Dank
 
Und hier die Files:
AdwCleaner:
AdwCleaner Logfile:
Code:

# AdwCleaner v4.109 - Bericht erstellt am 03/02/2015 um 23:10:38
# Aktualisiert 24/01/2015 von Xplode
# Database : 2015-02-03.1 [Live]
# Betriebssystem : Windows 7 Starter Service Pack 1 (32 bits)
# Benutzername : Juergen - JUERGEN-NETBOOK
# Gestartet von : C:\Users\Juergen\Desktop\AdwCleaner_4.109(1).exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****


***** [ Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17496


-\\ Mozilla Firefox v35.0.1 (x86 de)


-\\ Google Chrome v


*************************

AdwCleaner[R0].txt - [5239 octets] - [03/02/2015 21:06:19]
AdwCleaner[R1].txt - [333 octets] - [03/02/2015 21:43:31]
AdwCleaner[R2].txt - [1238 octets] - [03/02/2015 22:03:26]
AdwCleaner[R3].txt - [1113 octets] - [03/02/2015 23:06:18]
AdwCleaner[S0].txt - [5452 octets] - [03/02/2015 21:11:45]
AdwCleaner[S1].txt - [1308 octets] - [03/02/2015 22:07:53]
AdwCleaner[S2].txt - [1035 octets] - [03/02/2015 23:10:38]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1095 octets] ##########

--- --- ---


JRT:
Zitat:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Starter x86
Ran by Juergen on 03.02.2015 at 23:14:15,82
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Emptied folder: C:\Users\Juergen\AppData\Roaming\mozilla\firefox\profiles\z20qwztm.default\minidumps [46 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.02.2015 at 23:22:13,60
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2015
Ran by Juergen (administrator) on JUERGEN-NETBOOK on 03-02-2015 23:24:42
Running from C:\Users\Juergen\Desktop
Loaded Profiles: Juergen (Available profiles: Juergen)
Platform: Microsoft Windows 7 Starter  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.6.0.27\ccsvchst.exe
() C:\Program Files\USBLogon\usblonsvc.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\20.6.0.27\ccsvchst.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Windows\vsnpstd3.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
() C:\Windows\tsnpstd3.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHTU.EXE
() C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
() C:\Program Files\ownCloud\owncloud.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [USBLogon] => C:\Program Files\USBLogon\usblondetect.exe [12288 2013-10-01] (Quadsoft)
HKLM\...\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\...\Run: [snpstd3] => C:\Windows\vsnpstd3.exe [835584 2007-05-10] ()
HKLM\...\Run: [tsnpstd3] => C:\Windows\tsnpstd3.exe [339968 2009-06-30] ()
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TATIHTU.EXE [220800 2013-08-02] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Run: [ownCloud] => C:\Program Files\ownCloud\owncloud.exe [23416869 2014-12-18] ()
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {42de7e31-5715-11e4-bbee-e0ca947c51af} - E:\LGAutoRun.exe
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {42de7e35-5715-11e4-bbee-e0ca947c51af} - E:\LGAutoRun.exe
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {4f677a70-6ca3-11e4-bbd1-e0ca947c51af} - D:\LGAutoRun.exe
HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\MountPoints2: {4f7c33b7-32af-11e3-b87e-99da9e00c704} - D:\AutoRun.exe
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [  OCError] -> {0960F090-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCErrorShared] -> {0960F091-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOK] -> {0960F092-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOKShared] -> {0960F093-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSync] -> {0960F094-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSyncShared] -> {0960F095-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarning] -> {0960F096-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarningShared] -> {0960F097-F328-48A3-B746-276B1E3C3722} => C:\Program Files\ownCloud\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton 360\Engine\20.6.0.27\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton 360\Engine\20.6.0.27\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton 360\Engine\20.6.0.27\buShell.dll (Symantec Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton 360\Engine\20.6.0.27\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Norton 360\Engine\20.6.0.27\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.6.0.27\coIEPlg.dll (Symantec Corporation)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.6.1

FireFox:
========
FF ProfilePath: C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2065253504-3069135328-3144787471-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF Extension: KeeFox - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\keefox@chris.tomlinson [2015-01-15]
FF Extension: Bookmark Favicon Changer - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\bookmarkfaviconchanger@sonthakit.xpi [2013-08-02]
FF Extension: Firebug - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\firebug@software.joehewitt.com.xpi [2013-08-02]
FF Extension: Firepicker - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\firepicker@thedarkone.xpi [2013-08-02]
FF Extension: SQLite Manager - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\SQLiteManager@mrinalkant.blogspot.com.xpi [2014-12-31]
FF Extension: Delete Bookmark Icons - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{04514a2c-a3ab-4f47-8688-55f911b0fe75}.xpi [2013-08-02]
FF Extension: Showcase - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}.xpi [2013-08-02]
FF Extension: Password Exporter - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi [2013-08-02]
FF Extension: Adblock Plus - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-02]
FF Extension: Tab Mix Plus - C:\Users\Juergen\AppData\Roaming\Mozilla\Firefox\Profiles\z20qwztm.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2013-08-02]
FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn [2015-02-03]

Chrome:
=======
CHR Profile: C:\Users\Juergen\AppData\Local\Google\Chrome\User Data\default
CHR HKLM\...\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files\Norton 360\Engine\20.6.0.27\Exts\Chrome.crx [2014-12-09]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 N360; C:\Program Files\Norton 360\Engine\20.6.0.27\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 USBLogonService; C:\Program Files\USBLogon\usblonsvc.exe [12288 2013-10-01] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20150106.001\BHDrvx86.sys [1164504 2015-01-06] (Symantec Corporation)
R3 btwampfl; C:\Windows\system32\drivers\btwampfl.sys [508632 2015-01-16] (Broadcom Corporation.)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1406000.01B\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [378672 2014-12-13] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [111408 2014-12-13] (Symantec Corporation)
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20150130.001\IDSvix86.sys [503000 2015-01-13] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20150202.034\NAVENG.SYS [95704 2015-01-26] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20150202.034\NAVEX15.SYS [1636696 2015-01-26] (Symantec Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
S3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10526464 2009-07-03] (Sonix Co. Ltd.)
R3 SRTSP; C:\Windows\System32\Drivers\N360\1406000.01B\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1406000.01B\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1406000.01B\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1406000.01B\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-08-04] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1406000.01B\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360\1406000.01B\SYMNETS.SYS [339544 2013-04-25] (Symantec Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-03 23:24 - 2015-02-03 23:25 - 00014503 _____ () C:\Users\Juergen\Desktop\FRST.txt
2015-02-03 23:22 - 2015-02-03 23:22 - 00000756 _____ () C:\Users\Juergen\Desktop\JRT.txt
2015-02-03 23:13 - 2015-02-03 23:13 - 01388274 _____ (Thisisu) C:\Users\Juergen\Desktop\JRT.exe
2015-02-03 23:05 - 2015-02-03 23:05 - 02194432 _____ () C:\Users\Juergen\Desktop\AdwCleaner_4.109(1).exe
2015-02-03 22:40 - 2015-02-03 22:41 - 00026758 _____ () C:\Users\Juergen\Downloads\Addition.txt
2015-02-03 22:38 - 2015-02-03 23:24 - 00000000 ____D () C:\FRST
2015-02-03 22:38 - 2015-02-03 22:41 - 00030559 _____ () C:\Users\Juergen\Downloads\FRST.txt
2015-02-03 22:38 - 2015-02-03 22:38 - 01122304 _____ (Farbar) C:\Users\Juergen\Desktop\FRST.exe
2015-02-03 21:31 - 2015-02-03 21:31 - 11225840 _____ (SurfRight B.V.) C:\Users\Juergen\Downloads\hitmanpro_x64.exe
2015-02-03 21:06 - 2015-02-03 23:10 - 00000000 ____D () C:\AdwCleaner
2015-02-03 21:05 - 2015-02-03 21:05 - 02194432 _____ () C:\Users\Juergen\Downloads\adwcleaner_4.109.exe
2015-02-03 20:22 - 2015-02-03 21:38 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-03 20:21 - 2015-02-03 20:21 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-03 20:21 - 2015-02-03 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-03 20:21 - 2015-02-03 20:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-03 20:21 - 2015-02-03 20:21 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-02-03 20:21 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-03 20:21 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-03 20:21 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-03 20:20 - 2015-02-03 20:20 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Juergen\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-03 19:41 - 2015-02-03 19:41 - 00000000 ____D () C:\Users\Juergen\AppData\Local\FreeOCR
2015-02-03 19:35 - 2015-02-03 20:37 - 00000000 ____D () C:\FreeOCR
2015-02-03 19:35 - 2007-03-10 10:11 - 02680320 _____ (HiComponents) C:\Windows\system32\ImageEnXLibrary.ocx
2015-02-03 19:33 - 2015-02-03 19:33 - 00000000 ____D () C:\Program Files\Temp
2015-02-03 19:32 - 2015-02-03 19:32 - 00414625 _____ ( ) C:\Users\Juergen\Downloads\FreeOCR-5.02.exe
2015-02-03 19:32 - 2015-02-03 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2015-02-03 19:31 - 2015-02-03 19:32 - 00000000 ____D () C:\Program Files\PDFCreator
2015-02-03 19:31 - 2015-01-22 16:14 - 00098488 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2015-02-03 19:26 - 2015-02-03 19:26 - 27721680 _____ (pdfforge ) C:\Users\Juergen\Downloads\PDFCreator-2_0_2-setup.exe
2015-01-28 22:25 - 2015-01-28 22:25 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-01-28 22:25 - 2015-01-28 22:21 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2015-01-28 22:25 - 2015-01-28 22:21 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2015-01-28 22:25 - 2015-01-28 22:21 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-01-28 22:23 - 2015-01-28 22:23 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-01-18 21:05 - 2015-01-18 21:06 - 00000000 ____D () C:\Users\Juergen\ownCloudBoule
2015-01-18 20:59 - 2015-01-18 20:59 - 46286392 _____ (ownCloud) C:\Users\Juergen\Downloads\ownCloud-1.7.1.4382-setup(1).exe
2015-01-18 20:05 - 2014-12-11 18:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-18 20:05 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-01-18 11:03 - 2015-01-18 16:34 - 00001372 _____ () C:\Users\Juergen\Desktop\Dapile wecken.lnk
2015-01-18 11:00 - 2015-01-18 11:00 - 00000000 ____D () C:\Users\Juergen\AppData\Local\www.oette.info
2015-01-18 10:59 - 2015-01-18 10:59 - 00077936 _____ (Gammadyne Corporation) C:\Users\Juergen\Downloads\wol.exe
2015-01-18 10:55 - 2015-01-18 10:55 - 00000000 ____H () C:\Users\Juergen\Documents\Default.rdp
2015-01-18 10:46 - 2015-01-18 10:46 - 01964729 _____ () C:\Users\Juergen\Downloads\WOL2.7z
2015-01-18 00:30 - 2015-01-18 00:30 - 00039424 _____ () C:\Users\Juergen\Desktop\Hessen.xls
2015-01-18 00:25 - 2015-01-18 00:25 - 00035672 _____ () C:\Users\Juergen\Desktop\Mappe1.txt
2015-01-17 23:09 - 2015-01-17 23:09 - 00004290 _____ () C:\Users\Juergen\Desktop\karte_hessen.html
2015-01-17 23:08 - 2015-01-17 23:08 - 00004290 _____ () C:\Users\Juergen\Downloads\karte_hessen.html
2015-01-17 22:44 - 2015-01-17 22:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-01-17 22:44 - 2015-01-17 22:44 - 00000000 ____D () C:\Program Files\7-Zip
2015-01-17 22:40 - 2015-01-17 22:40 - 01110476 _____ () C:\Users\Juergen\Downloads\7z920.exe
2015-01-17 22:39 - 2015-01-17 22:39 - 01376768 _____ () C:\Users\Juergen\Downloads\7z920-x64.msi
2015-01-17 22:26 - 2015-01-17 22:26 - 00196096 _____ () C:\Users\Juergen\Desktop\DM-Meldung_2014.xls
2015-01-17 10:54 - 2013-10-02 00:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-01-17 10:53 - 2013-10-02 01:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-01-17 10:53 - 2013-10-02 01:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-01-17 10:53 - 2013-10-02 01:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-01-17 10:53 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-01-17 10:53 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-01-17 10:53 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-01-17 10:53 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-01-17 10:53 - 2013-10-01 23:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-01-17 10:53 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-01-17 00:47 - 2015-01-17 00:49 - 00004270 _____ () C:\Users\Juergen\Desktop\karte_hallen.html
2015-01-16 16:31 - 2015-01-17 01:48 - 00284672 _____ () C:\Users\Juergen\Desktop\d5c41_joodb_spielorte-1.xls
2015-01-16 16:18 - 2015-01-16 16:18 - 00171501 _____ () C:\Users\Juergen\Downloads\d5c41_joodb_spielorte.csv
2015-01-16 14:53 - 2015-01-16 14:57 - 00004305 _____ () C:\Users\Juergen\Desktop\karte_gesamt.html
2015-01-16 08:47 - 2015-01-16 08:47 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
2015-01-16 08:46 - 2015-01-16 08:46 - 00000000 ____D () C:\Users\Juergen\Documents\Bluetooth-Exchange-Ordner
2015-01-16 08:46 - 2015-01-16 08:46 - 00000000 ____D () C:\Users\Juergen\AppData\Local\Broadcom
2015-01-16 08:46 - 2015-01-16 08:35 - 00508632 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwampfl.sys
2015-01-16 08:39 - 2015-01-16 08:39 - 00001125 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Problem Report.lnk
2015-01-16 08:38 - 2015-01-16 08:35 - 00175144 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys
2015-01-16 08:38 - 2015-01-16 08:35 - 00152400 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys
2015-01-16 08:38 - 2015-01-16 08:35 - 00033832 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys
2015-01-16 08:38 - 2015-01-16 08:35 - 00018728 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwrchid.sys
2015-01-16 08:36 - 2015-01-16 08:36 - 00000000 ____D () C:\Program Files\WIDCOMM
2015-01-16 08:23 - 2015-01-16 08:23 - 04171576 _____ (Broadcom Corporation.) C:\Users\Juergen\Downloads\SetupBtwDownloadSE.exe
2015-01-15 23:31 - 2014-12-19 03:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-15 23:31 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-01-15 23:31 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-15 23:30 - 2014-12-19 02:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-15 23:30 - 2014-12-06 04:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-15 00:08 - 2015-01-15 00:08 - 00771699 _____ () C:\Users\Juergen\Desktop\OpenLayers.js
2015-01-14 23:54 - 2015-01-14 23:54 - 00014336 _____ () C:\Users\Juergen\Desktop\pois.xls
2015-01-14 23:27 - 2015-01-15 00:03 - 00000701 _____ () C:\Users\Juergen\Desktop\dbcsv.php
2015-01-14 23:27 - 2015-01-14 23:29 - 00000207 _____ () C:\Users\Juergen\Desktop\dbconnect.php
2015-01-14 23:26 - 2015-01-15 00:17 - 00004251 _____ () C:\Users\Juergen\Desktop\karte.html
2015-01-14 23:25 - 2015-01-14 23:25 - 00258079 _____ () C:\Users\Juergen\Desktop\basic.html
2015-01-11 15:46 - 2015-01-18 21:02 - 00000981 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ownCloud.lnk
2015-01-11 15:45 - 2015-01-11 15:46 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-11 15:41 - 2015-01-11 15:43 - 46286392 _____ (ownCloud) C:\Users\Juergen\Downloads\ownCloud-1.7.1.4382-setup.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-03 23:18 - 2013-10-06 19:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-03 23:18 - 2009-07-14 05:34 - 00016352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-03 23:18 - 2009-07-14 05:34 - 00016352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-03 23:15 - 2013-07-30 17:54 - 01871724 _____ () C:\Windows\WindowsUpdate.log
2015-02-03 23:11 - 2010-11-20 22:48 - 00137608 _____ () C:\Windows\PFRO.log
2015-02-03 23:11 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-03 23:11 - 2009-07-14 05:39 - 00045883 _____ () C:\Windows\setupact.log
2015-02-03 22:32 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-02-03 20:58 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system
2015-02-03 20:40 - 2013-11-18 21:26 - 00000000 ____D () C:\Users\Juergen\ownCloud
2015-02-03 20:38 - 2013-12-09 20:21 - 00000000 ____D () C:\Program Files\Free mp3 Wma Converter
2015-02-03 07:00 - 2013-08-01 07:05 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-01-28 22:27 - 2014-01-29 21:09 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-28 22:22 - 2014-10-18 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-01-28 22:21 - 2014-10-18 08:53 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2015-01-28 22:20 - 2014-08-18 12:29 - 00000000 ____D () C:\Program Files\Java
2015-01-25 10:40 - 2013-08-03 15:56 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-01-25 10:40 - 2013-08-03 15:56 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-01-20 21:08 - 2014-08-18 12:36 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\vlc
2015-01-20 19:47 - 2014-08-19 12:48 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\dvdcss
2015-01-20 19:43 - 2010-11-20 22:01 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-18 21:03 - 2013-11-18 21:25 - 00000000 ____D () C:\Users\Juergen\AppData\Local\ownCloud
2015-01-18 21:02 - 2013-11-18 21:25 - 00000000 ____D () C:\Program Files\ownCloud
2015-01-18 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-01-18 11:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-01-18 10:49 - 2013-08-02 10:14 - 00000000 ___RD () C:\Users\Juergen\Desktop\Programme
2015-01-17 11:05 - 2009-07-14 03:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-17 11:04 - 2011-03-20 08:51 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE
2015-01-16 08:01 - 2013-08-24 01:37 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\Mp3tag
2015-01-15 23:39 - 2013-08-02 09:17 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-15 23:32 - 2013-07-31 21:58 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-15 23:28 - 2013-08-25 09:04 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\foobar2000
2015-01-11 16:58 - 2014-12-13 12:36 - 00000000 ____D () C:\Users\Juergen\Desktop\Desktop Ablage 20141213
2015-01-04 09:54 - 2014-12-29 22:51 - 00000000 ____D () C:\Users\Juergen\AppData\Roaming\FileZilla

==================== Files in the root of some directories =======

2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Ambience
2013-12-05 20:12 - 2013-12-05 20:12 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Ambient
2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Analog Mono
2013-12-05 20:07 - 2013-12-05 20:07 - 0000268 ___RH () C:\Users\Juergen\AppData\Roaming\Audio Units
2013-12-05 21:07 - 2013-12-05 21:07 - 0003584 _____ () C:\Users\Juergen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-08-04 10:14 - 2013-08-04 10:14 - 0000600 _____ () C:\Users\Juergen\AppData\Local\PUTTY.RND
2014-11-15 16:21 - 2014-11-15 16:21 - 0000218 _____ () C:\Users\Juergen\AppData\Local\recently-used.xbel
2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\ProgramData\Analog Swirl
2013-12-05 20:12 - 2013-12-05 20:12 - 0000268 ___RH () C:\ProgramData\Analog Sync
2013-12-05 20:09 - 2013-12-05 20:09 - 0000268 ___RH () C:\ProgramData\Animals
2013-12-05 20:12 - 2013-12-05 20:12 - 0000012 ___RH () C:\ProgramData\Basic Track
2013-12-05 20:09 - 2013-12-05 20:09 - 0000012 ___RH () C:\ProgramData\Bass
2013-12-05 20:07 - 2013-12-05 20:09 - 0000012 ___RH () C:\ProgramData\BSD
2013-12-05 20:07 - 2013-12-05 20:07 - 0000012 ___RH () C:\ProgramData\ColorSync
2013-12-05 20:07 - 2013-12-05 20:08 - 0000020 ____H () C:\ProgramData\PKP_DLeo.DAT
2013-12-05 20:12 - 2014-01-25 13:02 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT
2013-12-05 20:09 - 2014-11-12 09:25 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT
2013-12-05 20:09 - 2014-11-12 09:35 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT

Some content of TEMP:
====================
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.dll
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.exe
C:\Users\Juergen\AppData\Local\Temp\DE83F836-32DF-FEC7-3997-961617D0D8B7.exe
C:\Users\Juergen\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Juergen\AppData\Local\Temp\Quarantine.exe
C:\Users\Juergen\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-14 22:51

==================== End Of Log ============================

--- --- ---


Addition:
Zitat:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-02-2015
Ran by Juergen at 2015-02-03 23:26:15
Running from C:\Users\Juergen\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton 360 Online (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton 360 Online (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton 360 Online (Disabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Acoustica Standard Edition 5.0 (HKLM\...\Acoustica Standard Edition_is1) (Version: 5.0 - Acon AS)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Amazon MP3-Downloader 1.0.18 (HKU\S-1-5-21-2065253504-3069135328-3144787471-1000\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC)
AppInventor Setup (HKLM\...\AppInventor Setup) (Version: 2.2 - Massachusetts Institute of Technology)
Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.4852 - CDBurnerXP)
Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
Download Navigator (HKLM\...\{E728441A-7820-4B1C-87C9-DE7BE37B2953}) (Version: 1.1.0 - SEIKO EPSON CORPORATION)
ElsterFormular (HKLM\...\ElsterFormular) (Version: 14.4.20130909 - Landesfinanzdirektion Thüringen)
EPSON BX535WD Series Printer Uninstall (HKLM\...\EPSON BX535WD Series) (Version: - SEIKO EPSON Corporation)
Epson Easy Photo Print 2 (HKLM\...\{FFF841F3-9A15-4F61-BD16-C19F132E5A27}) (Version: 2.3.0.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2)
Epson Event Manager (HKLM\...\{FA9D303D-0FB2-49C7-9397-8E6B11EA892D}) (Version: 2.50.0001 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.4j - SEIKO EPSON CORPORATION)
Extended Asian Language font pack for Adobe Reader XI (HKLM\...\{AC76BA86-7AD7-2530-0000-A00000000004}) (Version: 11.0.0 - Adobe Systems Incorporated)
FFmpeg v0.6.2 for Audacity (HKLM\...\FFmpeg for Audacity_is1) (Version: - )
FileZilla Client 3.9.0.6 (HKLM\...\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse)
FLAC 1.2.1b (remove only) (HKLM\...\FLAC) (Version: 1.2.1b - Xiph.org)
foobar2000 v1.3 (HKLM\...\foobar2000) (Version: 1.3 - Peter Pawlowski)
FreeFileSync 6.8 (HKLM\...\FreeFileSync) (Version: 6.8 - Zenju)
Freemake Audio Converter Version 1.1.0 (HKLM\...\Freemake Audio Converter_is1) (Version: 1.1.0 - Ellora Assets Corporation)
Frontplatten Designer (HKLM\...\Frontplatten Designer) (Version: 4.3.1 - Schaeffer AG)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
inSSIDer Home (HKLM\...\{9E54E4AE-B67A-4925-8E92-0E1F9817FD73}) (Version: 3.1.2.1 - MetaGeek, LLC)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.14.10.2117 - Intel Corporation)
iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Kinovea (HKLM\...\Kinovea) (Version: 0.8.15 - Kinovea) <==== ATTENTION!
LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version: - )
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM\...\{90110407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
MiniTool Partition Wizard Home Edition 8.1.1 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.)
Mozilla Firefox 35.0.1 (x86 de) (HKLM\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mp3tag v2.64 (HKLM\...\Mp3tag) (Version: v2.64 - Florian Heidenreich)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nikon Message Center 2 (HKLM\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon)
Nikon Movie Editor (HKLM\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.8.0 - Nikon)
Norton 360 (HKLM\...\N360) (Version: 20.6.0.27 - Symantec Corporation)
Notepad++ (HKLM\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
ownCloud (HKLM\...\ownCloud) (Version: 1.7.1.4382 - ownCloud)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.2 - pdfforge)
Picture Control Utility (HKLM\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.4.15 - Nikon)
Softsqueeze 3.9b2 (HKLM\...\Softsqueeze 3.9b2) (Version: - Ralph Irving)
Trust Webcam (HKLM\...\{ECD03DA7-5952-406A-8156-5F0C93618D1F}) (Version: 5.18.1211.103 - Sonix)
USBLogon 1.6.2.3 (HKLM\...\{E7D9D138-7DFA-441A-B1A9-703193C5D6D3}_is1) (Version: 1.6.2.3 - Quadsoft)
ViewNX 2 (HKLM\...\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.8.2 - Nikon)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WIDCOMM Bluetooth Software (HKLM\...\{A1439D4F-FD46-47F2-A1D3-FEE097C29A09}) (Version: 6.5.1.5800 - Broadcom Corporation)
WinRAR 4.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{3f04dadf-6ea4-44d1-a507-03cad176f443}\InprocServer32 -> C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2065253504-3069135328-3144787471-1000_Classes\CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)

==================== Restore Points =========================

15-01-2015 23:31:24 Windows Update
16-01-2015 08:38:24 Broadcom BTW Restore Point
17-01-2015 09:17:28 Windows Update
18-01-2015 20:05:50 Windows Update
18-01-2015 21:01:25 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
03-02-2015 21:26:44 Norton 360 Registry Clean

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {06B6DDAB-AAB0-4D0B-B52A-F905DE9B6A9F} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files\Norton 360\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {196C89FF-F3D9-448B-B7C1-92B1A0935C07} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton 360\Engine\20.6.0.27\WSCStub.exe [2014-12-06] (Symantec Corporation)
Task: {485B4A61-78AF-4C9E-A9CC-B8529DC8CE1B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated)
Task: {65FAAE39-54E7-4A39-B113-451EEB66F7D5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {850628D5-9DE8-48E0-A6CF-EF448C6902A6} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files\Norton 360\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {CB7C8110-39F3-4E02-B442-E083E9851C10} - System32\Tasks\{945E7209-E1C4-479E-A68B-7B35F0A2E979} => pcalua.exe -a C:\Users\Juergen\Downloads\softsqueeze_windows_3_9b2.exe -d C:\Users\Juergen\Downloads

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2014-10-11 12:06 - 2014-10-11 12:06 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-10-16 10:15 - 2014-10-16 10:15 - 00035328 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2014-05-24 17:41 - 2014-05-24 17:41 - 00091648 _____ () C:\Program Files\FileZilla FTP Client\libgcc_s_sjlj-1.dll
2014-05-24 17:41 - 2014-05-24 17:41 - 00892416 _____ () C:\Program Files\FileZilla FTP Client\libstdc++-6.dll
2013-11-04 13:23 - 2013-10-01 17:11 - 00012288 _____ () C:\Program Files\USBLogon\usblonsvc.exe
2014-12-09 16:50 - 2012-05-30 07:51 - 00699280 ____R () C:\PROGRAM FILES\NORTON 360\ENGINE\20.6.0.27\wincfi39.dll
2014-11-30 14:14 - 2007-05-10 13:18 - 00835584 _____ () C:\Windows\vsnpstd3.exe
2014-11-30 14:14 - 2009-06-30 16:20 - 00339968 _____ () C:\Windows\tsnpstd3.exe
2013-05-22 19:50 - 2013-05-22 19:50 - 00400704 _____ () C:\Users\Juergen\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
2014-12-18 12:53 - 2014-12-18 12:53 - 23416869 _____ () C:\Program Files\ownCloud\owncloud.exe
2014-12-18 12:53 - 2014-12-18 12:53 - 03044905 _____ () C:\Program Files\ownCloud\libocsync.dll
2014-09-24 09:23 - 2014-09-24 09:23 - 00158048 _____ () C:\Program Files\ownCloud\libneon-27.dll
2014-09-21 23:32 - 2014-09-21 23:32 - 00084012 _____ () C:\Program Files\ownCloud\zlib1.dll
2014-09-22 02:45 - 2014-09-22 02:45 - 00095790 _____ () C:\Program Files\ownCloud\libgcc_s_sjlj-1.dll
2014-09-22 02:13 - 2014-09-22 02:13 - 00172695 _____ () C:\Program Files\ownCloud\libproxy.dll
2014-09-22 02:11 - 2014-09-22 02:11 - 00042626 _____ () C:\Program Files\ownCloud\libmodman.dll
2014-09-22 02:45 - 2014-09-22 02:45 - 00847430 _____ () C:\Program Files\ownCloud\libstdc++-6.dll
2014-09-22 01:05 - 2014-09-22 01:05 - 01150984 _____ () C:\Program Files\ownCloud\libxml2-2.dll
2014-09-22 01:10 - 2014-09-22 01:10 - 02164003 _____ () C:\Program Files\ownCloud\icui18n53.dll
2014-09-22 01:10 - 2014-09-22 01:10 - 01288240 _____ () C:\Program Files\ownCloud\icuuc53.dll
2014-09-22 01:10 - 2014-09-22 01:10 - 21540519 _____ () C:\Program Files\ownCloud\icudata53.dll
2014-09-22 01:16 - 2014-09-22 01:16 - 00144533 _____ () C:\Program Files\ownCloud\libpcre16-0.dll
2014-09-22 01:15 - 2014-09-22 01:15 - 01345629 _____ () C:\Program Files\ownCloud\libGLESv2.dll
2014-09-22 00:58 - 2014-09-22 00:58 - 00203567 _____ () C:\Program Files\ownCloud\libpng16-16.dll
2014-12-18 12:53 - 2014-12-18 12:53 - 15901197 _____ () C:\Program Files\ownCloud\libowncloudsync.dll
2014-09-22 01:15 - 2014-09-22 01:15 - 00150916 _____ () C:\Program Files\ownCloud\libEGL.dll
2014-09-22 01:08 - 2014-09-22 01:08 - 00197062 _____ () C:\Program Files\ownCloud\libjpeg-8.dll
2014-09-22 01:13 - 2014-09-22 01:13 - 00646511 _____ () C:\Program Files\ownCloud\libsqlite3-0.dll
2014-09-22 02:28 - 2014-09-22 02:28 - 00247028 _____ () C:\Program Files\ownCloud\libwebp-4.dll
2014-09-22 03:24 - 2014-09-22 03:24 - 00228655 _____ () C:\Program Files\ownCloud\libxslt-1.dll
2014-09-24 08:38 - 2014-09-24 08:38 - 00052119 _____ () C:\Program Files\ownCloud\libqt5keychain.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00702136 _____ () C:\Program Files\ownCloud\platforms\qwindows.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00032568 _____ () C:\Program Files\ownCloud\imageformats\qgif.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00035173 _____ () C:\Program Files\ownCloud\imageformats\qico.dll
2014-09-22 11:25 - 2014-09-22 11:25 - 00048436 _____ () C:\Program Files\ownCloud\imageformats\qjpeg.dll
2014-12-17 12:44 - 2014-12-17 12:44 - 00046592 _____ () C:\Program Files\ownCloud\shellext\OCUtil_x86.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Juergen\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Juergen\Desktop\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Public\Downloads\.DS_Store:AFP_AfpInfo

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-2065253504-3069135328-3144787471-500 - Administrator - Disabled)
Gast (S-1-5-21-2065253504-3069135328-3144787471-501 - Limited - Enabled)
Juergen (S-1-5-21-2065253504-3069135328-3144787471-1000 - Administrator - Enabled) => C:\Users\Juergen

==================== Faulty Device Manager Devices =============

Name: Generischer Marvell Yukon 88E8040-PCI-E-Fast-Ethernet-Controller
Description: Generischer Marvell Yukon 88E8040-PCI-E-Fast-Ethernet-Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Marvell
Service: yukonw7
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================

System errors:
=============

Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Processor: Intel(R) Atom(TM) CPU N455 @ 1.66GHz
Percentage of memory in use: 44%
Total physical RAM: 2037.3 MB
Available physical RAM: 1122.94 MB
Total Pagefile: 4074.59 MB
Available Pagefile: 3157.92 MB
Total Virtual: 2047.88 MB
Available Virtual: 1919.73 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:119.14 GB) (Free:12.66 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: E91F5269)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=119.1 GB) - (Type=07 NTFS)

==================== End Of Log ============================
Danke

cosinus 03.02.2015 23:36

(edit: das tool scheint doch ok zu sein, vergiss es, poste gleich neu)


Virenscanner vor dem Fix bitte abdrehen

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
C:\ProgramData\PKP_DLeo.DAT
C:\ProgramData\PKP_DLes.DAT
C:\ProgramData\PKP_DLet.DAT
C:\ProgramData\PKP_DLev.DAT
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.dll
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.exe
C:\Users\Juergen\AppData\Local\Temp\DE83F836-32DF-FEC7-3997-961617D0D8B7.exe
C:\Users\Juergen\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Juergen\AppData\Local\Temp\Quarantine.exe
C:\Users\Juergen\AppData\Local\Temp\sqlite3.dll
EmptyTemp:
Hosts:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


hatzi 03.02.2015 23:42

Keine Ahnung??
 
Also im Infobereich wird mir immer noch ein Benachrichtigungssymbol "BlockAndSurf.exe" angezeigt und im Firefox gibt es immer noch jede Menge Werbung.

Danke

cosinus 03.02.2015 23:47

Fixlog fehlt.

hatzi 03.02.2015 23:54

Überschnitten und Fixlog
 
Meine Nachricht war vor deinem Post. Sorry!
Fixlog:
Zitat:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 01-02-2015
Ran by Juergen at 2015-02-03 23:43:21 Run:1
Running from C:\Users\Juergen\Desktop
Loaded Profiles: Juergen (Available profiles: Juergen)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
C:\ProgramData\PKP_DLeo.DAT
C:\ProgramData\PKP_DLes.DAT
C:\ProgramData\PKP_DLet.DAT
C:\ProgramData\PKP_DLev.DAT
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.dll
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.exe
C:\Users\Juergen\AppData\Local\Temp\DE83F836-32DF-FEC7-3997-961617D0D8B7.exe
C:\Users\Juergen\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Juergen\AppData\Local\Temp\Quarantine.exe
C:\Users\Juergen\AppData\Local\Temp\sqlite3.dll
EmptyTemp:
Hosts:

*****************

HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\iikflkcanblccfahdhdonehdalibjnif" => Key deleted successfully.
C:\ProgramData\PKP_DLeo.DAT => Moved successfully.
C:\ProgramData\PKP_DLes.DAT => Moved successfully.
C:\ProgramData\PKP_DLet.DAT => Moved successfully.
C:\ProgramData\PKP_DLev.DAT => Moved successfully.
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.dll => Moved successfully.
C:\Users\Juergen\AppData\Local\Temp\AF898F0D-56AB-FEB7-F8A8-CD4A184AEE7F.exe => Moved successfully.
C:\Users\Juergen\AppData\Local\Temp\DE83F836-32DF-FEC7-3997-961617D0D8B7.exe => Moved successfully.
C:\Users\Juergen\AppData\Local\Temp\jre-8u31-windows-au.exe => Moved successfully.
C:\Users\Juergen\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Juergen\AppData\Local\Temp\sqlite3.dll => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 469.2 MB temporary data.


The system needed a reboot.

==== End of Fixlog 23:45:54 ====
Zusatz:
Firefox ist wohl clean.

Im Infobereich aber immer noch BAS-Symbol

Aber trotzdem großes Danke für die erste Arbeit.

Danke
Hatzi

cosinus 04.02.2015 00:03

Okay, dann Kontrollscans mit MBAM und ESET bitte:

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset



Alle Zeitangaben in WEZ +1. Es ist jetzt 00:08 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28