Starlett | 12.07.2013 19:04 | Danke für deine schnelle Antwort. Hier sind die beiden Dateien:
FRST:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-07-2013 01
Ran by Saskia (administrator) on 12-07-2013 19:57:15
Running from C:\Users\Saskia\Downloads
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ICQ) C:\Users\Saskia\AppData\Roaming\ICQM\icq.exe
() C:\Program Files (x86)\Rebit\rebit.exe
(CM&V Hackbart) C:\Program Files (x86)\DVBViewer TE2\DVBViewerTE.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Java\jre6\bin\jusched.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(TechniSat Digital, S.A.) C:\Program Files (x86)\TechniSat DVB\bin\Server4PC.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
() E:\Program Files (x86)\phonostar-Player\phonostarTimer.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Apple Inc.) E:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(TechniSat Digital, S.A.) C:\Program Files (x86)\TechniSat DVB\bin\Server4PC.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(hxxp://www.mp3vcr.com/) E:\Program Files (x86)\MP3VCR\mp3vcr.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\avscan.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
==================== Registry (Whitelisted) ==================
HKCU\...\Run: [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1475584 2010-11-20] (Microsoft Corporation)
HKCU\...\Run: [icq] - C:\Users\Saskia\AppData\Roaming\ICQM\icq.exe -CU [27598184 2013-04-22] (ICQ)
HKCU\...\Run: [rebit] - "C:\Program Files (x86)\Rebit\rebit.exe" [3991456 2010-03-21] ()
HKCU\...\Run: [phonostar-PlayerTimer] - "C:\Users\Saskia\AppData\Roaming\Microsoft\Eersisli\eersisli.exe" /c E:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [x]
HKCU\...\Run: [owbpq] - "C:\Users\Saskia\AppData\Roaming\Microsoft\Eersisli\eersisli.exe" [x]
HKLM-x32\...\Run: [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345144 2013-06-27] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" [148888 2013-04-21] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [TkBellExe] - "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot [295512 2013-04-21] (RealNetworks, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - "E:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [x]
HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [x]
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized [522744 2012-06-07] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [iTunesHelper] - "E:\Program Files (x86)\iTunes\iTunesHelper.exe" [x]
HKU\Default\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
Startup: C:\ProgramData\Start Menu\Programs\Startup\DVBViewer TE2.lnk
ShortcutTarget: DVBViewer TE2.lnk -> C:\Program Files (x86)\DVBViewer TE2\DVBViewerTE.exe (CM&V Hackbart)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Server4PC.lnk
ShortcutTarget: Server4PC.lnk -> C:\Program Files (x86)\TechniSat DVB\bin\Server4PC.exe (TechniSat Digital, S.A.)
Startup: C:\Users\Saskia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
DPF: HKLM-x32 {538793D5-659C-4639-A56C-A179AD87ED44} vpnweb.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab
Handler: msdaipp - No CLSID Value -
Handler-x32: msdaipp - No CLSID Value -
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 0.0.0.0
FireFox:
========
FF ProfilePath: C:\Users\Saskia\AppData\Roaming\Mozilla\Firefox\Profiles\svwlanym.default
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - E:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @real.com/nppl3260;version=16.0.1.18 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.1.18 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - E:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @phonostar.de/phonostar-Player - E:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll ( )
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: FoxyProxy Basic - C:\Users\Saskia\AppData\Roaming\Mozilla\Firefox\Profiles\svwlanym.default\Extensions\foxyproxy@eric.h.jung
FF Extension: DownloadHelper - C:\Users\Saskia\AppData\Roaming\Mozilla\Firefox\Profiles\svwlanym.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [{DAC3F861-B30D-40dd-9166-F4E75327FAC7}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\
FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG)
S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-06-13] (Freemake)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-03-06] ()
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-04-21] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-04-21] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-04-21] (Avira Operations GmbH & Co. KG)
R3 SKYNET; C:\Windows\System32\DRIVERS\SkyNET_AMD64.SYS [615440 2009-09-11] (TechniSat Digital, S.A.)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-12 19:56 - 2013-07-12 19:56 - 01778143 _____ (Farbar) C:\Users\Saskia\Downloads\FRST64.exe
2013-07-12 19:56 - 2013-07-12 19:56 - 00000000 ____D C:\FRST
2013-07-12 17:44 - 2013-07-12 17:44 - 00003594 _____ C:\Windows\System32\Tasks\mxseersisliupd
2013-07-12 16:59 - 2013-07-12 16:59 - 00000786 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-12 16:59 - 2013-07-12 16:59 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Malwarebytes
2013-07-12 16:59 - 2013-07-12 16:59 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-12 16:58 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-07-12 16:56 - 2013-07-12 16:56 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Saskia\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-12 16:20 - 2013-07-12 16:23 - 00003360 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3721828272-3184620602-2136171468-1001
2013-07-12 14:46 - 2013-07-12 14:46 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3 VCR
2013-07-12 14:46 - 2011-03-24 08:11 - 00659264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSComCt2.ocx
2013-07-12 14:46 - 2009-03-24 11:52 - 00155984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COMDLG32.OCX
2013-07-12 14:46 - 2004-03-09 00:00 - 00132880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSInet.ocx
2013-07-12 14:46 - 2004-03-09 00:00 - 00124688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mswinsck.ocx
2013-07-12 14:46 - 2000-05-27 00:00 - 01388544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.004
2013-07-12 14:46 - 1999-02-08 01:00 - 00326656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.005
2013-07-12 14:46 - 1998-10-06 00:00 - 00598288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.000
2013-07-12 14:46 - 1998-10-06 00:00 - 00164112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.001
2013-07-12 14:46 - 1998-10-06 00:00 - 00147728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.002
2013-07-12 14:46 - 1998-10-06 00:00 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.003
2013-07-12 13:49 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-12 13:49 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-12 13:49 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-12 13:49 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-12 13:49 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-12 13:49 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-12 13:49 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-12 13:49 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-12 13:49 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-12 13:49 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-12 13:49 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-12 13:49 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-12 13:49 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-12 13:49 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-12 13:49 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-12 13:49 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-12 13:49 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-12 13:49 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-12 13:49 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-12 13:49 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-12 13:49 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-12 13:49 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-12 13:49 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-12 13:49 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-12 13:49 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-12 13:49 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-12 13:49 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-12 13:49 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-12 13:49 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-12 13:49 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-12 13:49 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-11 11:55 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 11:55 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 11:55 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-11 11:55 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 11:55 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-11 11:55 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-11 11:55 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files\iTunes
2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files\iPod
2013-07-05 18:16 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2013-07-05 17:47 - 2013-07-05 17:47 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-07-05 17:46 - 2013-07-05 17:46 - 00000000 ____D C:\Program Files\Bonjour
2013-07-05 17:46 - 2013-07-05 17:46 - 00000000 ____D C:\Program Files (x86)\Bonjour
2013-07-05 17:35 - 2013-07-05 18:14 - 00000000 ____D C:\Users\Saskia\AppData\Local\Audible
2013-07-05 17:35 - 2013-07-05 17:35 - 00255352 _____ (Audible, Inc.) C:\Windows\SysWOW64\awrdscdc.ax
2013-07-05 17:35 - 2013-07-05 17:35 - 00001969 _____ C:\Users\Saskia\Desktop\Audible Manager.lnk
2013-07-05 17:35 - 2003-03-18 21:20 - 01060864 ____N (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2013-07-05 17:35 - 2001-08-17 22:43 - 00024576 ____N (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll
2013-07-05 17:34 - 2013-07-05 17:35 - 00000000 ____D C:\Users\Saskia\Documents\Audible
2013-07-05 17:34 - 2013-07-05 17:35 - 00000000 ____D C:\Program Files (x86)\Audible
2013-07-05 17:09 - 2013-07-05 17:09 - 00000282 _____ C:\Users\Saskia\Downloads\admhelper
2013-07-05 15:36 - 2013-07-05 15:36 - 00000349 _____ C:\Windows\cdplayer.ini
2013-07-05 15:35 - 2013-07-05 15:35 - 00001534 _____ C:\ProgramData\ss.ini
2013-07-05 15:35 - 2013-07-05 15:35 - 00001002 _____ C:\Users\Saskia\Desktop\FreeRIP.lnk
2013-07-05 15:35 - 2013-07-05 15:35 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeRIP
2013-07-05 15:35 - 2013-07-05 15:35 - 00000000 ____D C:\ProgramData\FreeRIP
2013-07-05 15:35 - 2013-07-05 15:35 - 00000000 ____D C:\Program Files (x86)\FreeRIP
2013-07-05 14:45 - 2013-07-05 14:45 - 00000669 _____ C:\Windows\wmsetup.log
2013-06-17 21:00 - 2013-06-17 21:00 - 00000000 ____D C:\Users\Saskia\AppData\Local\FreemakeVideoConverter
2013-06-17 20:49 - 2013-06-17 21:01 - 00000000 ____D C:\Users\Saskia\Documents\Freemake
2013-06-17 20:49 - 2013-06-17 21:00 - 00000000 ____D C:\ProgramData\Freemake
2013-06-17 20:49 - 2013-06-17 20:49 - 00001324 _____ C:\Users\Public\Desktop\Freemake Video Converter.lnk
2013-06-17 20:49 - 2013-06-17 20:49 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2013-06-17 20:49 - 2013-06-17 20:49 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-06-16 15:04 - 2013-06-16 15:04 - 00000000 ____D C:\ProgramData\Gibraltar
2013-06-16 13:55 - 2013-07-04 00:32 - 00000000 ____D C:\Users\Saskia\Documents\Citavi 3
2013-06-16 13:55 - 2013-06-25 21:14 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Swiss Academic Software
2013-06-16 13:54 - 2013-06-16 13:54 - 00001101 _____ C:\Users\Public\Desktop\Citavi 3.lnk
2013-06-15 18:19 - 2013-06-16 13:54 - 00000000 ____D C:\ProgramData\Swiss Academic Software
2013-06-15 17:58 - 2013-06-15 17:58 - 00000000 ____D C:\Users\Saskia\AppData\Local\Cisco
2013-06-15 17:58 - 2013-06-15 17:58 - 00000000 ____D C:\ProgramData\Cisco
2013-06-15 17:58 - 2013-06-15 17:58 - 00000000 ____D C:\Program Files (x86)\Cisco
2013-06-12 22:16 - 2013-05-13 07:51 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-06-12 22:16 - 2013-05-13 07:51 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-06-12 22:16 - 2013-05-13 07:51 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-06-12 22:16 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-06-12 22:16 - 2013-05-13 06:45 - 01160192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 22:16 - 2013-05-13 06:45 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 22:16 - 2013-05-13 06:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 22:16 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-06-12 22:16 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 22:16 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 22:16 - 2013-05-08 08:39 - 01910632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-06-12 22:16 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-06-12 22:16 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-12 01:00 - 2013-07-12 19:49 - 00000380 _____ C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Saskia.job
2013-06-12 01:00 - 2013-07-12 01:21 - 00002958 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Saskia
2013-06-12 01:00 - 2013-07-12 01:21 - 00000370 _____ C:\Windows\Tasks\ReclaimerUpdateXML_Saskia.job
2013-06-12 01:00 - 2013-07-11 12:13 - 00002962 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Saskia
2013-06-12 01:00 - 2013-07-11 12:13 - 00000374 _____ C:\Windows\Tasks\ReclaimerUpdateFiles_Saskia.job
2013-06-12 01:00 - 2013-06-12 01:00 - 00003612 _____ C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Saskia
2013-06-12 01:00 - 2013-06-12 01:00 - 00002666 _____ C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Saskia
==================== One Month Modified Files and Folders =======
2013-07-12 19:56 - 2013-07-12 19:56 - 01778143 _____ (Farbar) C:\Users\Saskia\Downloads\FRST64.exe
2013-07-12 19:56 - 2013-07-12 19:56 - 00000000 ____D C:\FRST
2013-07-12 19:54 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-12 19:54 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-12 19:49 - 2013-06-12 01:00 - 00000380 _____ C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Saskia.job
2013-07-12 19:49 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-12 19:48 - 2009-07-14 06:51 - 00027896 _____ C:\Windows\setupact.log
2013-07-12 19:47 - 2013-04-21 16:12 - 01538707 _____ C:\Windows\WindowsUpdate.log
2013-07-12 17:44 - 2013-07-12 17:44 - 00003594 _____ C:\Windows\System32\Tasks\mxseersisliupd
2013-07-12 16:59 - 2013-07-12 16:59 - 00000786 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-12 16:59 - 2013-07-12 16:59 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Malwarebytes
2013-07-12 16:59 - 2013-07-12 16:59 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-12 16:56 - 2013-07-12 16:56 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Saskia\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-12 16:23 - 2013-07-12 16:20 - 00003360 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3721828272-3184620602-2136171468-1001
2013-07-12 16:23 - 2013-05-12 00:01 - 00003228 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3721828272-3184620602-2136171468-1001
2013-07-12 16:18 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-12 16:17 - 2009-07-14 06:45 - 00395232 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-12 16:15 - 2009-07-14 20:18 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-12 16:15 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-12 16:15 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-12 14:46 - 2013-07-12 14:46 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3 VCR
2013-07-12 13:52 - 2009-07-14 19:58 - 00653928 _____ C:\Windows\system32\perfh007.dat
2013-07-12 13:52 - 2009-07-14 19:58 - 00129800 _____ C:\Windows\system32\perfc007.dat
2013-07-12 13:52 - 2009-07-14 07:13 - 01518986 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-12 01:21 - 2013-06-12 01:00 - 00002958 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Saskia
2013-07-12 01:21 - 2013-06-12 01:00 - 00000370 _____ C:\Windows\Tasks\ReclaimerUpdateXML_Saskia.job
2013-07-11 22:34 - 2013-04-21 19:57 - 00003338 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3721828272-3184620602-2136171468-1001
2013-07-11 22:34 - 2013-04-21 19:57 - 00003206 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3721828272-3184620602-2136171468-1001
2013-07-11 12:13 - 2013-06-12 01:00 - 00002962 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Saskia
2013-07-11 12:13 - 2013-06-12 01:00 - 00000374 _____ C:\Windows\Tasks\ReclaimerUpdateFiles_Saskia.job
2013-07-05 19:29 - 2013-05-12 01:52 - 00000000 ____D C:\Users\Saskia\AppData\Local\Paint.NET
2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files\iTunes
2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files\iPod
2013-07-05 18:14 - 2013-07-05 17:35 - 00000000 ____D C:\Users\Saskia\AppData\Local\Audible
2013-07-05 17:51 - 2013-05-17 17:47 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Apple Computer
2013-07-05 17:49 - 2013-05-17 17:48 - 00000000 ____D C:\Users\Saskia\AppData\Local\Apple Computer
2013-07-05 17:48 - 2013-05-17 17:45 - 00000000 ____D C:\ProgramData\Apple Computer
2013-07-05 17:47 - 2013-07-05 17:47 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-07-05 17:47 - 2013-05-17 17:44 - 00000000 ____D C:\ProgramData\Apple
2013-07-05 17:46 - 2013-07-05 17:46 - 00000000 ____D C:\Program Files\Bonjour
2013-07-05 17:46 - 2013-07-05 17:46 - 00000000 ____D C:\Program Files (x86)\Bonjour
2013-07-05 17:35 - 2013-07-05 17:35 - 00255352 _____ (Audible, Inc.) C:\Windows\SysWOW64\awrdscdc.ax
2013-07-05 17:35 - 2013-07-05 17:35 - 00001969 _____ C:\Users\Saskia\Desktop\Audible Manager.lnk
2013-07-05 17:35 - 2013-07-05 17:34 - 00000000 ____D C:\Users\Saskia\Documents\Audible
2013-07-05 17:35 - 2013-07-05 17:34 - 00000000 ____D C:\Program Files (x86)\Audible
2013-07-05 17:09 - 2013-07-05 17:09 - 00000282 _____ C:\Users\Saskia\Downloads\admhelper
2013-07-05 15:36 - 2013-07-05 15:36 - 00000349 _____ C:\Windows\cdplayer.ini
2013-07-05 15:35 - 2013-07-05 15:35 - 00001534 _____ C:\ProgramData\ss.ini
2013-07-05 15:35 - 2013-07-05 15:35 - 00001002 _____ C:\Users\Saskia\Desktop\FreeRIP.lnk
2013-07-05 15:35 - 2013-07-05 15:35 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeRIP
2013-07-05 15:35 - 2013-07-05 15:35 - 00000000 ____D C:\ProgramData\FreeRIP
2013-07-05 15:35 - 2013-07-05 15:35 - 00000000 ____D C:\Program Files (x86)\FreeRIP
2013-07-05 15:02 - 2013-05-17 17:31 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\vlc
2013-07-05 14:45 - 2013-07-05 14:45 - 00000669 _____ C:\Windows\wmsetup.log
2013-07-04 00:32 - 2013-06-16 13:55 - 00000000 ____D C:\Users\Saskia\Documents\Citavi 3
2013-06-27 13:10 - 2013-05-07 20:43 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-06-26 15:52 - 2013-05-12 02:10 - 00001069 _____ C:\Users\Public\Desktop\Paint.NET.lnk
2013-06-25 21:14 - 2013-06-16 13:55 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Swiss Academic Software
2013-06-18 13:43 - 2013-04-21 16:42 - 00005458 _____ C:\Windows\PFRO.log
2013-06-17 21:01 - 2013-06-17 20:49 - 00000000 ____D C:\Users\Saskia\Documents\Freemake
2013-06-17 21:00 - 2013-06-17 21:00 - 00000000 ____D C:\Users\Saskia\AppData\Local\FreemakeVideoConverter
2013-06-17 21:00 - 2013-06-17 20:49 - 00000000 ____D C:\ProgramData\Freemake
2013-06-17 20:49 - 2013-06-17 20:49 - 00001324 _____ C:\Users\Public\Desktop\Freemake Video Converter.lnk
2013-06-17 20:49 - 2013-06-17 20:49 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2013-06-17 20:49 - 2013-06-17 20:49 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-06-16 15:04 - 2013-06-16 15:04 - 00000000 ____D C:\ProgramData\Gibraltar
2013-06-16 13:54 - 2013-06-16 13:54 - 00001101 _____ C:\Users\Public\Desktop\Citavi 3.lnk
2013-06-16 13:54 - 2013-06-15 18:19 - 00000000 ____D C:\ProgramData\Swiss Academic Software
2013-06-15 17:58 - 2013-06-15 17:58 - 00000000 ____D C:\Users\Saskia\AppData\Local\Cisco
2013-06-15 17:58 - 2013-06-15 17:58 - 00000000 ____D C:\ProgramData\Cisco
2013-06-15 17:58 - 2013-06-15 17:58 - 00000000 ____D C:\Program Files (x86)\Cisco
2013-06-12 01:43 - 2013-07-12 13:49 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 01:43 - 2013-07-12 13:49 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 01:43 - 2013-07-12 13:49 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 01:43 - 2013-07-12 13:49 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 01:43 - 2013-07-12 13:49 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 01:43 - 2013-07-12 13:49 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 01:43 - 2013-07-12 13:49 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-12 01:42 - 2013-07-12 13:49 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 01:42 - 2013-07-12 13:49 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 01:42 - 2013-07-12 13:49 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-12 01:42 - 2013-07-12 13:49 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-12 01:42 - 2013-07-12 13:49 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-12 01:42 - 2013-07-12 13:49 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-12 01:26 - 2013-07-12 13:49 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-06-12 01:26 - 2013-07-12 13:49 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-06-12 01:26 - 2013-07-12 13:49 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-06-12 01:25 - 2013-07-12 13:49 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-06-12 01:25 - 2013-07-12 13:49 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-06-12 01:25 - 2013-07-12 13:49 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-06-12 01:25 - 2013-07-12 13:49 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-06-12 01:25 - 2013-07-12 13:49 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-06-12 01:25 - 2013-07-12 13:49 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-06-12 01:25 - 2013-07-12 13:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-06-12 01:25 - 2013-07-12 13:49 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-06-12 01:25 - 2013-07-12 13:49 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-06-12 01:25 - 2013-07-12 13:49 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-06-12 01:25 - 2013-07-12 13:49 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-06-12 01:00 - 2013-06-12 01:00 - 00003612 _____ C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Saskia
2013-06-12 01:00 - 2013-06-12 01:00 - 00002666 _____ C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Saskia
2013-06-12 00:51 - 2013-07-12 13:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-12 00:50 - 2013-07-12 13:49 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-04-21 16:09
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-07-2013 01
Ran by Saskia at 2013-07-12 19:57:55
Running from C:\Users\Saskia\Downloads
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.169)
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.169)
Adobe Reader XI (11.0.02) - Deutsch (x32 Version: 11.0.02)
Apple Application Support (x32 Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (x32 Version: 2.1.3.127)
AudibleManager (x32 Version: 1995521262.48.56.35196138)
Avira Free Antivirus (x32 Version: 13.0.0.3737)
Bonjour (Version: 3.0.0.10)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.0.08057)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.0.08057)
Citavi (x32 Version: 3.4.0.2)
DVBViewer TE2 (x32)
Freemake Video Converter Version 4.0.1 (x32 Version: 4.0.1)
FreeRIP 3.92 (x32 Version: 3.92)
ICQ 8.0 (build 6017) (HKCU Version: 8.0.6017.0)
iTunes (Version: 11.0.4.4)
Java(TM) 6 Update 12 (x32 Version: 6.0.120)
K-Lite Codec Pack 6.4.0 (Full) (x32 Version: 6.4.0)
MainConcept DTV Decoder Standard (x32 Version: 1.5.0.2)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Office Professional Edition 2003 (x32 Version: 11.0.6361.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 20.0.1 (x86 de) (x32 Version: 20.0.1)
MP3 VCR (x32)
OpenOffice.org 3.4.1 (x32 Version: 3.41.9593)
Paint.NET v3.5.10 (Version: 3.60.0)
phonostar-Player Version 3.02.9 (x32)
QuickTime (x32 Version: 7.73.80.64)
RealDownloader (x32 Version: 1.3.1)
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0)
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0)
RealPlayer (x32 Version: 16.0.0)
RealUpgrade 1.1 (x32 Version: 1.1.0)
Rebit (x32)
rosoft .NET Framework 4 Client Profile (Version: 4.0.30319)
TechniSat DVB-PC TV Star (x32 Version: 4.3.3)
Technisat DVB-VC80 Redistributable Modules (x32 Version: 1.0.0)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
Visual C++ 9.0 CRT (x86) WinSXS MSM (x32 Version: 9.0)
VLC media player 2.0.6 (x32 Version: 2.0.6)
==================== Restore Points =========================
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {0665A4C6-A23D-482E-A69A-73CD82F5D5A4} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {18C04D8E-208A-4BF4-9049-B4AB3FEA3FFB} - System32\Tasks\mxseersisliupd => C:\Windows\system32\cscript.exe [2009-07-14] (Microsoft Corporation)
Task: {1DDFBE5A-8337-49A7-8CF4-A0FD621E546A} - System32\Tasks\RNUpgradeHelperLogonPrompt_Saskia => C:\Users\Saskia\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\rnupgagent.exe [2013-06-11] (RealNetworks, Inc.)
Task: {32DD899A-174B-4FD4-ABCD-88FD18310BC7} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3721828272-3184620602-2136171468-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-03-06] (RealNetworks, Inc.)
Task: {33B2D400-A2D0-4637-897E-68FF4F883D3E} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3721828272-3184620602-2136171468-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2013-03-06] (RealNetworks, Inc.)
Task: {43AAEF64-9F30-45F4-B540-0C56BF5CBF16} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3721828272-3184620602-2136171468-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-03-06] (RealNetworks, Inc.)
Task: {74792081-7704-4183-AE4B-AA89E72985D9} - System32\Tasks\RNUpgradeHelperResumePrompt_Saskia => C:\Users\Saskia\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\rnupgagent.exe [2013-06-11] (RealNetworks, Inc.)
Task: {7483C4A5-0C0C-4CE2-9E35-822D2D5EA639} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3721828272-3184620602-2136171468-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-03-06] (RealNetworks, Inc.)
Task: {8287F17C-DC90-4084-8EBA-2B95A2C3A7D1} - System32\Tasks\ReclaimerUpdateXML_Saskia => C:\Users\Saskia\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\rnupgagent.exe [2013-06-11] (RealNetworks, Inc.)
Task: {A2D214DE-7C18-4089-BAC3-F1693EB9A5A8} - System32\Tasks\ReclaimerUpdateFiles_Saskia => C:\Users\Saskia\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\rnupgagent.exe [2013-06-11] (RealNetworks, Inc.)
Task: {C54A017D-F11E-4B99-9C35-8A4EBC7D36C0} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3721828272-3184620602-2136171468-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-03-06] (RealNetworks, Inc.)
Task: C:\Windows\Tasks\ReclaimerUpdateFiles_Saskia.job => C:\Users\Saskia\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\rnupgagent.exe
Task: C:\Windows\Tasks\ReclaimerUpdateXML_Saskia.job => C:\Users\Saskia\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\rnupgagent.exe
Task: C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Saskia.job => C:\Users\Saskia\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\rnupgagent.exe
==================== Faulty Device Manager Devices =============
Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/12/2013 07:52:43 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16635, Zeitstempel: 0x51b7a921
Name des fehlerhaften Moduls: urlmon.dll, Version: 10.0.9200.16635, Zeitstempel: 0x51b7aa82
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00047fe5
ID des fehlerhaften Prozesses: 0x1038
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (07/12/2013 07:50:41 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (07/12/2013 07:50:14 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Error: (07/12/2013 07:47:06 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16635, Zeitstempel: 0x51b7a921
Name des fehlerhaften Moduls: urlmon.dll, Version: 10.0.9200.16635, Zeitstempel: 0x51b7aa82
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000a72b
ID des fehlerhaften Prozesses: 0x12d0
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (07/12/2013 07:47:05 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16635, Zeitstempel: 0x51b7a921
Name des fehlerhaften Moduls: urlmon.dll, Version: 10.0.9200.16635, Zeitstempel: 0x51b7aa82
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000a72b
ID des fehlerhaften Prozesses: 0x11d0
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (07/12/2013 07:47:05 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16635, Zeitstempel: 0x51b7a921
Name des fehlerhaften Moduls: urlmon.dll, Version: 10.0.9200.16635, Zeitstempel: 0x51b7aa82
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000a72b
ID des fehlerhaften Prozesses: 0x187c
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (07/12/2013 07:47:05 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16635, Zeitstempel: 0x51b7a921
Name des fehlerhaften Moduls: urlmon.dll, Version: 10.0.9200.16635, Zeitstempel: 0x51b7aa82
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000a72b
ID des fehlerhaften Prozesses: 0x1e8c
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (07/12/2013 07:47:05 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16635, Zeitstempel: 0x51b7a921
Name des fehlerhaften Moduls: urlmon.dll, Version: 10.0.9200.16635, Zeitstempel: 0x51b7aa82
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000a72b
ID des fehlerhaften Prozesses: 0x1ecc
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (07/12/2013 07:47:05 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16635, Zeitstempel: 0x51b7a921
Name des fehlerhaften Moduls: urlmon.dll, Version: 10.0.9200.16635, Zeitstempel: 0x51b7aa82
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000a72b
ID des fehlerhaften Prozesses: 0x21d8
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (07/12/2013 07:47:05 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16635, Zeitstempel: 0x51b7a921
Name des fehlerhaften Moduls: urlmon.dll, Version: 10.0.9200.16635, Zeitstempel: 0x51b7aa82
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000a72b
ID des fehlerhaften Prozesses: 0x238
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
System errors:
=============
Error: (07/12/2013 07:49:52 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Freemake Improver" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (07/12/2013 07:49:52 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Freemake Improver erreicht.
Error: (07/12/2013 07:48:57 PM) (Source: atikmdag) (User: )
Description: Display is not active
Error: (07/12/2013 07:48:57 PM) (Source: atikmdag) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (07/12/2013 05:56:37 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Freemake Improver" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (07/12/2013 05:56:37 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Freemake Improver erreicht.
Error: (07/12/2013 05:55:44 PM) (Source: atikmdag) (User: )
Description: Display is not active
Error: (07/12/2013 05:55:44 PM) (Source: atikmdag) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (07/12/2013 05:39:46 PM) (Source: atikmdag) (User: )
Description: Display is not active
Error: (07/12/2013 05:39:46 PM) (Source: atikmdag) (User: )
Description: CPLIB :: General - Invalid Parameter
Microsoft Office Sessions:
=========================
Error: (07/12/2013 07:52:43 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE10.0.9200.1663551b7a921urlmon.dll10.0.9200.1663551b7aa82c000000500047fe5103801ce7f289a28d486C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dlld98918e1-eb1b-11e2-8fc3-0008c9b0d8ed
Error: (07/12/2013 07:50:41 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{EA1FAE0F-2354-4E32-B423-ABAE8E358F91}\recordingmanager.exe
Error: (07/12/2013 07:50:14 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestE:\Program Files (x86)\phonostar-Player\phonostar.exe
Error: (07/12/2013 07:47:06 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE10.0.9200.1663551b7a921urlmon.dll10.0.9200.1663551b7aa82c00000050000a72b12d001ce7f27d25bd041C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dll10a12a97-eb1b-11e2-918f-0008c9b0d8ed
Error: (07/12/2013 07:47:05 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE10.0.9200.1663551b7a921urlmon.dll10.0.9200.1663551b7aa82c00000050000a72b11d001ce7f27d25bd041C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dll1099d77b-eb1b-11e2-918f-0008c9b0d8ed
Error: (07/12/2013 07:47:05 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE10.0.9200.1663551b7a921urlmon.dll10.0.9200.1663551b7aa82c00000050000a72b187c01ce7f27d2601611C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dll109654fe-eb1b-11e2-918f-0008c9b0d8ed
Error: (07/12/2013 07:47:05 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE10.0.9200.1663551b7a921urlmon.dll10.0.9200.1663551b7aa82c00000050000a72b1e8c01ce7f27d25b8220C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dll109347b2-eb1b-11e2-918f-0008c9b0d8ed
Error: (07/12/2013 07:47:05 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE10.0.9200.1663551b7a921urlmon.dll10.0.9200.1663551b7aa82c00000050000a72b1ecc01ce7f27d2593827C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dll1066b8cb-eb1b-11e2-918f-0008c9b0d8ed
Error: (07/12/2013 07:47:05 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE10.0.9200.1663551b7a921urlmon.dll10.0.9200.1663551b7aa82c00000050000a72b21d801ce7f27d25e8f6bC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dll1075fb45-eb1b-11e2-918f-0008c9b0d8ed
Error: (07/12/2013 07:47:05 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE10.0.9200.1663551b7a921urlmon.dll10.0.9200.1663551b7aa82c00000050000a72b23801ce7f27d25b0ceeC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dll1074e9d1-eb1b-11e2-918f-0008c9b0d8ed
==================== Memory info ===========================
Percentage of memory in use: 56%
Total physical RAM: 2047.18 MB
Available physical RAM: 892.98 MB
Total Pagefile: 4094.36 MB
Available Pagefile: 2362.58 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:48.83 GB) (Free:4.96 GB) NTFS (Disk=0 Partition=2)
Drive d: () (Fixed) (Total:48.83 GB) (Free:45.66 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)]
Drive e: () (Fixed) (Total:368.1 GB) (Free:15.4 GB) NTFS (Disk=0 Partition=3)
Drive f: (PUR Schein und Sein) (CDROM) (Total:7.6 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: CC5DCC5D)
Partition 1: (Active) - (Size=49 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=417 GB) - (Type=OF Extended)
==================== End Of Log ============================ Gerade eben hat sich auch mein Antivir gemeldet und hat BDS/Qakbot.A.55 gefunden. Ich hab die Datei jetzt erstmal in Quarantäne verschoben. |