Hallo Schrauber,
Hier die FIRST.TXT
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-09-2013
Ran by Besitzer (administrator) on BESITZER-PC on 23-09-2013 16:19:05
Running from C:\Users\Besitzer\Desktop\System-Tuning
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
() C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
() C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE
(Microsoft Corporation) C:\Windows\system32\prevhost.exe
==================== Registry (Whitelisted) ==================
HKCU\...\Run: [EPSON SX218 Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGDE.EXE /FU "C:\Windows\TEMP\E_SE82C.tmp" /EF "HKCU"
HKCU\...\Run: [NTRedirect] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Besitzer\AppData\Roaming\BabSolution\Shared\enhancedNT.dll",Run
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1558480 2013-07-26] (APN)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
AppInit_DLLs-x32: c:\progra~3\bitguard\261673~1.238\{c16c1~1\bitguard.dll [2700768 2013-09-13] ()
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xACA15E596EC1CB01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=4010D85D4CB044A2&affID=119360&tsp=4965
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO-x32: Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: No Name - {9cf699ca-2174-4ed8-bec1-ba82095edce0} - No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Besitzer\AppData\Roaming\Mozilla\Firefox\Profiles\eila8wpx.default
FF NewTab: hxxp://www1.delta-search.com/?babsrc=NT_ss&mntrId=4010D85D4CB044A2&affID=119360&tsp=4965
FF SearchEngineOrder.1: Delta Search
FF SelectedSearchEngine: Delta Search
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Deutsches Wörterbuch - C:\Users\Besitzer\AppData\Roaming\Mozilla\Firefox\Profiles\eila8wpx.default\Extensions\de-DE@dictionaries.addons.mozilla.org
FF Extension: Super Start - C:\Users\Besitzer\AppData\Roaming\Mozilla\Firefox\Profiles\eila8wpx.default\Extensions\superstart@enjoyfreeware.org
FF Extension: No Name - C:\Users\Besitzer\AppData\Roaming\Mozilla\Firefox\Profiles\eila8wpx.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKCU\...\Firefox\Extensions: [{4d8c0bcf-07da-4d5b-aebd-c0cbbc8fc0f4}] - C:\Program Files (x86)\LyriXeeker\130.xpi
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.)
R2 BitGuard; C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [3029472 2013-09-13] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-08-20] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-05] (Avira Operations GmbH & Co. KG)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-23 16:03 - 2013-09-23 16:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-09-23 15:55 - 2013-09-23 15:55 - 98663986 _____ C:\Windows\SysWOW64\琮瀀ᰤš
2013-09-23 15:54 - 2013-09-23 15:54 - 00000652 _____ C:\Windows\PFRO.log
2013-09-23 15:54 - 2013-09-23 15:54 - 00000056 _____ C:\Windows\setupact.log
2013-09-23 15:54 - 2013-09-23 15:54 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\File Scout
2013-09-23 15:54 - 2013-09-23 15:54 - 00000000 _____ C:\Windows\setuperr.log
2013-09-19 18:27 - 2013-09-19 18:27 - 00000000 ____D C:\FRST
2013-09-19 17:38 - 2013-09-19 18:06 - 00021424 _____ C:\Windows\wininit.ini
2013-09-19 17:38 - 2013-09-19 17:38 - 00000000 ____D C:\Users\Besitzer\AppData\Local\avgchrome
2013-09-19 16:56 - 2013-09-19 16:56 - 00000000 ____D C:\Program Files (x86)\CleanUP
2013-09-19 16:51 - 2013-09-19 18:32 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-09-19 16:51 - 2013-09-19 16:53 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-09-19 16:51 - 2013-09-19 16:51 - 00000656 _____ C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job
2013-09-19 16:51 - 2013-09-19 16:51 - 00000628 _____ C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2013-09-19 16:51 - 2013-09-19 16:51 - 00000458 _____ C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job
2013-09-19 16:51 - 2009-01-25 13:14 - 00017272 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2013-09-19 16:50 - 2013-09-19 16:50 - 00000000 ____D C:\Program Files\CCleaner
2013-09-19 16:43 - 2013-09-19 16:43 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\OpenOffice
2013-09-19 16:39 - 2013-09-19 16:39 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-09-19 16:39 - 2013-09-19 16:39 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-19 16:26 - 2013-09-19 16:26 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-19 16:26 - 2013-09-19 16:26 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Mozilla
2013-09-19 15:50 - 2013-09-23 16:19 - 00000000 ____D C:\Users\Besitzer\Desktop\System-Tuning
2013-09-17 11:15 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-17 11:15 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-17 11:15 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-17 11:15 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-17 11:15 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-17 11:15 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-17 11:15 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-17 11:15 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-17 11:15 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-17 11:15 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-17 11:15 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-17 11:15 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-17 11:15 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-17 11:15 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-17 11:15 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-17 11:15 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-17 11:15 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-17 11:15 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-17 11:15 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-17 11:15 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-17 11:15 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-17 11:15 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-17 11:15 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-17 11:15 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-17 11:15 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-17 11:15 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-17 11:15 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-17 11:15 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-17 11:15 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-17 11:15 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-17 11:15 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-17 11:03 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-17 11:03 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-17 11:03 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-17 11:03 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-17 11:03 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-17 11:03 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-17 11:03 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-17 11:03 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-17 11:03 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-17 11:03 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-17 11:03 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-17 11:03 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-17 11:03 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-17 11:03 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-17 11:03 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-17 11:03 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-17 11:03 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-17 11:03 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-17 11:03 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-17 11:03 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-17 11:03 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-17 11:03 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-17 11:02 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-17 11:02 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-17 11:02 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-17 11:02 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-17 11:02 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-15 10:18 - 2013-09-15 10:18 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
2013-09-15 10:18 - 2013-09-15 10:18 - 00000000 ____D C:\ProgramData\BitGuard
2013-09-09 17:54 - 2013-09-09 18:03 - 00003436 _____ C:\Windows\System32\Tasks\BrowserDefendert
2013-09-04 16:07 - 2013-09-23 16:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-04 16:07 - 2013-09-23 16:02 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Thunderbird
2013-09-04 16:07 - 2013-09-04 16:07 - 00002090 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2013-09-04 16:07 - 2013-09-04 16:07 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Thunderbird
2013-09-04 16:07 - 2013-09-04 16:07 - 00000000 ____D C:\ProgramData\Mozilla
==================== One Month Modified Files and Folders =======
2013-09-23 16:19 - 2013-09-19 15:50 - 00000000 ____D C:\Users\Besitzer\Desktop\System-Tuning
2013-09-23 16:03 - 2013-09-23 16:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-09-23 16:03 - 2013-09-04 16:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-23 16:02 - 2013-09-04 16:07 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Thunderbird
2013-09-23 16:02 - 2009-07-14 06:45 - 00014800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-23 16:02 - 2009-07-14 06:45 - 00014800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-23 16:01 - 2009-07-14 19:58 - 00653928 _____ C:\Windows\system32\perfh007.dat
2013-09-23 16:01 - 2009-07-14 19:58 - 00129800 _____ C:\Windows\system32\perfc007.dat
2013-09-23 16:01 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-23 16:00 - 2011-01-28 00:05 - 01429670 _____ C:\Windows\WindowsUpdate.log
2013-09-23 15:57 - 2011-02-06 15:36 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-23 15:56 - 2011-02-06 15:36 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Google
2013-09-23 15:55 - 2013-09-23 15:55 - 98663986 _____ C:\Windows\SysWOW64\琮瀀ᰤš
2013-09-23 15:54 - 2013-09-23 15:54 - 00000652 _____ C:\Windows\PFRO.log
2013-09-23 15:54 - 2013-09-23 15:54 - 00000056 _____ C:\Windows\setupact.log
2013-09-23 15:54 - 2013-09-23 15:54 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\File Scout
2013-09-23 15:54 - 2013-09-23 15:54 - 00000000 _____ C:\Windows\setuperr.log
2013-09-23 15:54 - 2013-08-05 15:51 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-23 15:54 - 2013-08-05 15:36 - 00000906 _____ C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job
2013-09-23 15:54 - 2013-08-05 15:35 - 00000394 _____ C:\Windows\Tasks\LyricXeeker Update.job
2013-09-23 15:54 - 2011-02-06 15:36 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-23 15:54 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-19 18:41 - 2013-08-05 15:36 - 00000910 _____ C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job
2013-09-19 18:38 - 2013-08-05 15:51 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-19 18:38 - 2013-08-05 15:51 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-19 18:38 - 2013-08-05 15:51 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-09-19 18:36 - 2013-08-05 15:36 - 00000302 _____ C:\Windows\Tasks\Dealply.job
2013-09-19 18:32 - 2013-09-19 16:51 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-09-19 18:27 - 2013-09-19 18:27 - 00000000 ____D C:\FRST
2013-09-19 18:06 - 2013-09-19 17:38 - 00021424 _____ C:\Windows\wininit.ini
2013-09-19 18:04 - 2009-07-14 06:45 - 00297656 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-19 17:38 - 2013-09-19 17:38 - 00000000 ____D C:\Users\Besitzer\AppData\Local\avgchrome
2013-09-19 17:08 - 2011-02-06 15:03 - 00064768 _____ C:\Users\Besitzer\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-19 17:04 - 2011-01-28 00:01 - 00000000 ____D C:\Windows\Panther
2013-09-19 16:56 - 2013-09-19 16:56 - 00000000 ____D C:\Program Files (x86)\CleanUP
2013-09-19 16:53 - 2013-09-19 16:51 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-09-19 16:53 - 2011-04-23 09:53 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Adobe
2013-09-19 16:51 - 2013-09-19 16:51 - 00000656 _____ C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job
2013-09-19 16:51 - 2013-09-19 16:51 - 00000628 _____ C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2013-09-19 16:51 - 2013-09-19 16:51 - 00000458 _____ C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job
2013-09-19 16:50 - 2013-09-19 16:50 - 00000000 ____D C:\Program Files\CCleaner
2013-09-19 16:43 - 2013-09-19 16:43 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\OpenOffice
2013-09-19 16:39 - 2013-09-19 16:39 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-09-19 16:39 - 2013-09-19 16:39 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-19 16:38 - 2011-01-27 17:11 - 00000000 ___RD C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-19 16:26 - 2013-09-19 16:26 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-19 16:26 - 2013-09-19 16:26 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Mozilla
2013-09-19 16:26 - 2013-08-05 15:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-19 15:50 - 2011-01-27 17:11 - 00000000 ___RD C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-17 11:15 - 2013-08-18 09:29 - 00000000 ____D C:\Windows\system32\MRT
2013-09-17 11:13 - 2011-01-27 17:46 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-15 10:18 - 2013-09-15 10:18 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
2013-09-15 10:18 - 2013-09-15 10:18 - 00000000 ____D C:\ProgramData\BitGuard
2013-09-09 18:03 - 2013-09-09 17:54 - 00003436 _____ C:\Windows\System32\Tasks\BrowserDefendert
2013-09-04 16:07 - 2013-09-04 16:07 - 00002090 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2013-09-04 16:07 - 2013-09-04 16:07 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Thunderbird
2013-09-04 16:07 - 2013-09-04 16:07 - 00000000 ____D C:\ProgramData\Mozilla
2013-09-04 16:07 - 2013-08-05 15:34 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Mozilla
2013-09-04 15:34 - 2011-02-06 15:36 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-04 14:27 - 2013-08-05 15:33 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-26 19:23 - 2013-08-05 15:35 - 00003048 _____ C:\Windows\System32\Tasks\LyricXeeker Update
Some content of TEMP:
====================
C:\Users\Besitzer\AppData\Local\Temp\setup_fsu_cid.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-03-19 17:08
==================== End Of Log ============================ --- --- ---
--- --- ---
Und hier die ADDITION.TXT Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-09-2013
Ran by Besitzer at 2013-09-19 18:29:00
Running from C:\Users\Besitzer\Desktop\System-Tuning
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168)
Adobe Reader X (10.1.7) - Deutsch (x32 Version: 10.1.7)
Avira Free Antivirus (x32 Version: 13.0.0.4052)
Avira SearchFree Toolbar plus Web Protection (x32 Version: 12.2.2.663)
CCleaner (Version: 4.05)
CleanUp & Shutdown (x32 Version: 2.1208)
Druckerdeinstallation für EPSON SX218 Series
Epson Easy Photo Print 2 (x32 Version: 2.2.3.1)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (x32 Version: 1.00.0000)
Google Chrome (x32 Version: 29.0.1547.76)
Google Earth (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.153)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0)
Mozilla Maintenance Service (x32 Version: 24.0)
Mozilla Thunderbird 17.0.8 (x86 de) (x32 Version: 17.0.8)
OpenOffice 4.0.0 (x32 Version: 4.00.9702)
Spybot - Search & Destroy (x32 Version: 2.1.21)
Total Commander (Remove or Repair) (x32 Version: 8.01)
TP-LINK Wireless Client Utility (x32 Version: 7.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
==================== Restore Points =========================
30-08-2013 09:49:01 Windows Update
04-09-2013 12:31:06 Windows Update
08-09-2013 08:43:21 Windows Update
17-09-2013 08:56:14 Windows Update
17-09-2013 09:08:45 Windows Update
19-09-2013 14:34:58 Installed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
19-09-2013 14:36:13 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
19-09-2013 14:38:02 OpenOffice 4.0.0 wird installiert
19-09-2013 15:09:36 Windows Defender Checkpoint
19-09-2013 15:39:22 S
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {02656BD8-C0C5-4675-9967-6E2FFA456D00} - System32\Tasks\BrowserDefendert => Sc.exe start BrowserDefendert
Task: {03FAED76-9C8F-4F48-94B4-496CACBC0D89} - System32\Tasks\BitGuard => Sc.exe start BitGuard
Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started
Task: {0566A653-524F-49BF-B428-5B45762EFB8D} - System32\Tasks\Dealply => C:\Users\Besitzer\AppData\Roaming\Dealply\UpdateProc\UpdateTask.exe [2013-04-12] ()
Task: {41CE86D2-00D3-44ED-8F07-D76583CD18FE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-06] (Google Inc.)
Task: {581418A1-7850-4EA7-A8BF-BBAE8B16258E} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {6A066036-D188-4D5B-9B2A-5FF8A3736B88} - System32\Tasks\LyricXeeker Update => C:\Program Files (x86)\LyriXeeker\LyriXupdate.exe
Task: {7670F0F5-F66E-47A2-982E-1BD514AE1EB7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-06] (Google Inc.)
Task: {7AA8519D-A917-40A4-819A-DA3C39D1939F} - System32\Tasks\DealPlyLiveUpdateTaskMachineCore => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe
Task: {86034BB1-69DF-4FED-A024-A72140BAD760} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-19] (Adobe Systems Incorporated)
Task: {A067F96B-9485-47B9-A875-E879605AA441} - System32\Tasks\DealPlyLiveUpdateTaskMachineUA => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe
Task: {A4BF79A6-29CC-4B46-9E2D-B97611E03BA3} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: {E4B08939-A6B1-4B86-8D3E-97A8A9B0346A} - System32\Tasks\DealPlyUpdate => C:\Program
Task: {F20CB7CD-EE1C-4483-801D-4C00E115F4E9} - System32\Tasks\EPUpdater => C:\Users\Besitzer\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe
Task: {FB146951-7E8F-421F-BA29-AE2ABA553B11} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: C:\Windows\Tasks\Dealply.job => C:\Users\Besitzer\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE
Task: C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe
Task: C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\LyricXeeker Update.job => C:\Program Files (x86)\LyriXeeker\LyriXupdate.exe
Task: C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
==================== Loaded Modules (whitelisted) =============
2011-02-06 15:24 - 2009-08-24 11:10 - 00430592 _____ (SEIKO EPSON CORPORATION / CyCom Technology Corp.) C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
2013-09-15 10:18 - 2013-09-13 17:00 - 02700768 _____ () C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll
2013-09-19 16:51 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-09-19 16:51 - 2013-05-16 10:55 - 03643800 _____ (Project JEDI) C:\Program Files (x86)\Spybot - Search & Destroy 2\Jcl150.bpl
2013-09-19 16:51 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2013-09-19 16:26 - 2013-09-11 04:26 - 03279768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) ==========
==================== Faulty Device Manager Devices =============
Name: Microsoft-Adapter für Miniports virtueller WiFis
Description: Microsoft-Adapter für Miniports virtueller WiFis
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Ethernet-Controller
Description: Ethernet-Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (09/19/2013 06:04:49 PM) (Source: ESENT) (User: )
Description: taskhost (1352) WebCacheLocal: Fehler -1811 beim Öffnen von Protokolldatei C:\Users\Besitzer\AppData\Local\Microsoft\Windows\WebCache\V01000D8.log.
Error: (09/19/2013 05:39:29 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddWin32ServiceFiles: Unable to back up image of service DealPly Live-Dienst (dealplylivem) since QueryServiceConfig API failed
System Error:
Das System kann die angegebene Datei nicht finden.
.
Error: (09/19/2013 05:39:29 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddWin32ServiceFiles: Unable to back up image of service DealPly Live-Dienst (dealplylive) since QueryServiceConfig API failed
System Error:
Das System kann die angegebene Datei nicht finden.
.
Error: (09/19/2013 05:37:21 PM) (Source: Application Hang) (User: )
Description: Programm soffice.bin, Version 4.0.9702.500 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1074
Startzeit: 01ceb54db6d93f31
Endzeit: 0
Anwendungspfad: C:\Program Files (x86)\OpenOffice 4\program\soffice.bin
Berichts-ID:
Error: (08/26/2013 07:22:39 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001487
ID des fehlerhaften Prozesses: 0x914
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (08/05/2013 03:36:47 PM) (Source: MsiInstaller) (User: Besitzer-PC)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\GoogleUpdateHelper.msi
Error: (07/06/2013 08:51:54 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16490, Zeitstempel: 0x51959d18
Name des fehlerhaften Moduls: Flash64_10_3_162.ocx, Version: 10.3.162.28, Zeitstempel: 0x4cd9fabd
Ausnahmecode: 0xc000041d
Fehleroffset: 0x00000000001d9203
ID des fehlerhaften Prozesses: 0xc74
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3
Error: (07/06/2013 08:51:51 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16490, Zeitstempel: 0x51959d18
Name des fehlerhaften Moduls: Flash64_10_3_162.ocx, Version: 10.3.162.28, Zeitstempel: 0x4cd9fabd
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000001d9203
ID des fehlerhaften Prozesses: 0xc74
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3
Error: (07/06/2013 08:51:42 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16490, Zeitstempel: 0x51959d18
Name des fehlerhaften Moduls: Flash64_10_3_162.ocx, Version: 10.3.162.28, Zeitstempel: 0x4cd9fabd
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000001d9203
ID des fehlerhaften Prozesses: 0xabc
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3
Error: (07/06/2013 08:51:16 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16490, Zeitstempel: 0x51959d18
Name des fehlerhaften Moduls: Flash64_10_3_162.ocx, Version: 10.3.162.28, Zeitstempel: 0x4cd9fabd
Ausnahmecode: 0xc000041d
Fehleroffset: 0x00000000001d9203
ID des fehlerhaften Prozesses: 0xcf8
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3
System errors:
=============
Error: (09/19/2013 04:51:48 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (09/19/2013 04:51:48 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.
Error: (07/29/2013 07:29:42 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Google Update Service (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (07/29/2013 07:29:42 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Google Update Service (gupdate) erreicht.
Error: (05/28/2013 11:20:14 AM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{A3C256E0-9013-432D-8121-4990E6B8C2EA}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Error: (05/26/2013 09:54:17 AM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{A3C256E0-9013-432D-8121-4990E6B8C2EA}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Error: (05/26/2013 09:51:20 AM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 26.05.2013 um 09:49:07 unerwartet heruntergefahren.
Error: (05/26/2013 09:42:15 AM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{A3C256E0-9013-432D-8121-4990E6B8C2EA}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Error: (05/25/2013 09:33:37 AM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{A3C256E0-9013-432D-8121-4990E6B8C2EA}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Error: (05/16/2013 10:29:51 AM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{A3C256E0-9013-432D-8121-4990E6B8C2EA}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Microsoft Office Sessions:
=========================
Error: (09/19/2013 06:04:49 PM) (Source: ESENT)(User: )
Description: taskhost1352WebCacheLocal: C:\Users\Besitzer\AppData\Local\Microsoft\Windows\WebCache\V01000D8.log-1811
Error: (09/19/2013 05:39:29 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service DealPly Live-Dienst (dealplylivem) since QueryServiceConfig API failed
System Error:
Das System kann die angegebene Datei nicht finden.
Error: (09/19/2013 05:39:29 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service DealPly Live-Dienst (dealplylive) since QueryServiceConfig API failed
System Error:
Das System kann die angegebene Datei nicht finden.
Error: (09/19/2013 05:37:21 PM) (Source: Application Hang)(User: )
Description: soffice.bin4.0.9702.500107401ceb54db6d93f310C:\Program Files (x86)\OpenOffice 4\program\soffice.bin
Error: (08/26/2013 07:22:39 PM) (Source: Application Error)(User: )
Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c00000050000148791401cea280d2da352bC:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe1af0c53c-0e74-11e3-9b82-8ba73513ed47
Error: (08/05/2013 03:36:47 PM) (Source: MsiInstaller)(User: Besitzer-PC)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\GoogleUpdateHelper.msi(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (07/06/2013 08:51:54 AM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.1649051959d18Flash64_10_3_162.ocx10.3.162.284cd9fabdc000041d00000000001d9203c7401ce7a154af2470eC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\Macromed\Flash\Flash64_10_3_162.ocx8a95a674-e608-11e2-9b9f-f2e6b48c2f2d
Error: (07/06/2013 08:51:51 AM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.1649051959d18Flash64_10_3_162.ocx10.3.162.284cd9fabdc000000500000000001d9203c7401ce7a154af2470eC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\Macromed\Flash\Flash64_10_3_162.ocx88d4a749-e608-11e2-9b9f-f2e6b48c2f2d
Error: (07/06/2013 08:51:42 AM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.1649051959d18Flash64_10_3_162.ocx10.3.162.284cd9fabdc000000500000000001d9203abc01ce7a153c935000C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\Macromed\Flash\Flash64_10_3_162.ocx83c92158-e608-11e2-9b9f-f2e6b48c2f2d
Error: (07/06/2013 08:51:16 AM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.1649051959d18Flash64_10_3_162.ocx10.3.162.284cd9fabdc000041d00000000001d9203cf801ce7a1534c6a090C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\Macromed\Flash\Flash64_10_3_162.ocx73d10734-e608-11e2-9b9f-f2e6b48c2f2d
==================== Memory info ===========================
Percentage of memory in use: 39%
Total physical RAM: 2941.55 MB
Available physical RAM: 1772.49 MB
Total Pagefile: 5881.29 MB
Available Pagefile: 4228.8 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:97.56 GB) (Free:64.37 GB) NTFS
Drive d: () (Fixed) (Total:368.1 GB) (Free:367.97 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: A31BB6C3)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=98 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=368 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Hoffentlich kannst Du damit die Malware beseitigen.
Gruß
Ch. Hanisch |