xamecknuf | 25.10.2013 21:29 | Hallo , Der eset hat nix gefunden, anbei der securitychek wollte nicht, der frst:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-10-2013 01
Ran by Max Funcke (administrator) on ALDIPC on 25-10-2013 20:16:46
Running from C:\Users\Max Funcke\Downloads
Microsoft Windows 7 Home Premium (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(REINER SCT) C:\Windows\system32\cjpcsc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Mozilla Corporation) C:\Users\Max Funcke\AppData\Local\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Users\Max Funcke\AppData\Local\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
() G:\SecurityCheck.exe
(Microsoft Corporation) C:\Windows\system32\cmd.exe
(Farbar) C:\Users\Max Funcke\Downloads\FRST(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [LexwareInfoService] - C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKU\Default User\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] ()
HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [ 2009-10-23] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {4B485EF4-889E-4A2D-98F9-ED6CEDE22D33} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MEDTDF&pc=MAMD&src=IE-SearchBox
SearchScopes: HKCU - {4B485EF4-889E-4A2D-98F9-ED6CEDE22D33} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MEDTDF&pc=MAMD&src=IE-SearchBox
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {8C3887BA-3367-4297-B288-13472BD407E4} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Winsock: Catalog9 01 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 02 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 03 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 04 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 05 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 06 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 07 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 08 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 09 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 10 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 11 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 12 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 13 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 14 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 15 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 16 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 18 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 19 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 29 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 30 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 000000000100 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000101 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000102 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000103 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000104 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000105 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000106 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000107 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000108 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000109 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000110 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Max Funcke\AppData\Roaming\Mozilla\Firefox\Profiles\rkxjz51e.default
FF DefaultSearchEngine: Startpage HTTPS - Deutsch
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Max Funcke\AppData\Roaming\Mozilla\Firefox\Profiles\rkxjz51e.default\searchplugins\ixquick-https---deutsch.xml
FF SearchPlugin: C:\Users\Max Funcke\AppData\Roaming\Mozilla\Firefox\Profiles\rkxjz51e.default\searchplugins\startpage-https---deutsch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\googledesktop.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Max Funcke\AppData\Roaming\Mozilla\Firefox\Profiles\rkxjz51e.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF StartMenuInternet: FIREFOX.EXE - C:\Users\Max Funcke\AppData\Local\Mozilla Firefox\firefox.exe
========================== Services (Whitelisted) =================
S2 AcronisOSSReinstallSvc; C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe [2232296 2012-02-17] ()
R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [619408 2009-11-06] (Acronis)
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [948296 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 cjpcsc; C:\Windows\system32\cjpcsc.exe [514128 2012-03-19] (REINER SCT)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S4 BsFileScan; C:\Program Files\BullGuard Ltd\BullGuard\BsFileScan.dll [x]
S4 BsMailProxy; C:\Program Files\BullGuard Ltd\BullGuard\BsMailProxy\BsMailProxy.dll [x]
S4 BsMain; C:\Program Files\BullGuard Ltd\BullGuard\BsMain.dll [x]
S4 BsScanner; C:\Program Files\BullGuard Ltd\BullGuard\BullGuardScanner.exe [x]
S4 BsUpdate; C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe [x]
==================== Drivers (Whitelisted) ====================
R1 AFW; C:\Windows\System32\DRIVERS\afw.sys [29208 2012-02-17] (Agnitum Ltd.)
R3 afwcore; C:\Windows\System32\DRIVERS\afwcore.sys [318488 2012-02-17] (Agnitum Ltd.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 BdSpy; C:\Windows\System32\DRIVERS\BdSpy.sys [55888 2012-02-17] (BullGuard Ltd.)
R1 bizVSerial; C:\Windows\System32\drivers\bizVSerialNT.sys [14949 2007-05-31] (franson.biz)
S3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [28144 2012-02-17] (REINER SCT)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2012-02-17] (Microsoft Corporation)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [38400 2012-02-17] (Samsung Electronics Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [16472 2010-08-16] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [11104 2010-08-16] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-10-09] (Avira GmbH)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2011-03-14] (Samsung Electronics)
R0 tdrpman251; C:\Windows\System32\DRIVERS\tdrpm251.sys [902432 2012-02-19] (Acronis)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2012-02-17] (Microsoft Corporation)
S3 catchme; \??\C:\Users\MAXFUN~1\AppData\Local\Temp\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-25 20:16 - 2013-10-25 20:15 - 01088113 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST(1).exe
2013-10-25 20:11 - 2013-10-25 20:12 - 00000448 _____ C:\Users\Max Funcke\Desktop\SecurityCheck.exe.lnk
2013-10-25 20:04 - 2013-10-25 20:04 - 00891167 _____ C:\Users\Max Funcke\Downloads\SecurityCheck.exe
2013-10-25 16:39 - 2013-10-25 16:39 - 02347384 _____ (ESET) C:\Users\Max Funcke\Downloads\esetsmartinstaller_enu.exe
2013-10-25 12:38 - 2013-10-25 12:38 - 01088113 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST.exe
2013-10-25 12:30 - 2013-10-25 12:30 - 00001401 _____ C:\Users\Max Funcke\Desktop\JRT.txt
2013-10-25 12:28 - 2013-10-25 12:28 - 01033335 _____ (Thisisu) C:\Users\Max Funcke\Downloads\JRT.exe
2013-10-25 12:28 - 2013-10-25 12:28 - 00000000 ____D C:\Windows\ERUNT
2013-10-25 12:18 - 2013-10-25 12:21 - 00000000 ____D C:\AdwCleaner
2013-10-25 12:18 - 2013-10-25 12:18 - 01060070 _____ C:\Users\Max Funcke\Downloads\adwcleaner.exe
2013-10-25 11:56 - 2013-10-25 11:56 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\Users\Max Funcke\AppData\Roaming\Malwarebytes
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-25 11:56 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-23 17:45 - 2013-10-23 17:45 - 00014235 _____ C:\ComboFix.txt
2013-10-23 17:36 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-23 17:36 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-23 17:36 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-23 17:33 - 2013-10-23 17:45 - 00000000 ____D C:\Qoobox
2013-10-23 17:33 - 2013-10-23 17:44 - 00000000 ____D C:\Windows\erdnt
2013-10-23 17:29 - 2013-10-23 17:32 - 00001373 _____ C:\Users\Max Funcke\Desktop\ComboFix.exe.lnk
2013-10-22 19:13 - 2013-10-22 19:13 - 00000000 ____D C:\FRST
2013-10-22 19:10 - 2013-10-22 19:10 - 00000094 _____ C:\Users\Max Funcke\AppData\Roaming\WB.CFG
2013-10-22 11:12 - 2013-10-22 19:09 - 00000890 _____ C:\Users\Max Funcke\daemonprocess.txt
2013-10-22 11:12 - 2013-10-22 11:27 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Mobogenie
2013-10-22 11:12 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\Documents\Mobogenie
2013-10-22 11:12 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\cache
2013-10-21 16:59 - 2013-10-21 16:59 - 00707880 _____ C:\Users\Max Funcke\Downloads\DownloadManagerSetup(1).exe
2013-10-21 16:58 - 2013-10-21 16:58 - 00707880 _____ C:\Users\Max Funcke\Downloads\DownloadManagerSetup.exe
2013-10-18 15:37 - 2013-10-18 15:40 - 00005006 _____ C:\Users\Max Funcke\Desktop\Windows Compatibility Report.htm
2013-10-10 14:48 - 2013-10-10 14:48 - 00001993 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-10-02 14:38 - 2013-10-02 14:38 - 00281896 _____ (Mozilla) C:\Users\Max Funcke\Downloads\Firefox Setup Stub 24.0.exe
2013-10-01 14:03 - 2013-03-02 07:06 - 00981504 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-01 14:03 - 2013-03-02 07:05 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-01 14:03 - 2013-03-02 07:05 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 06032384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 00606208 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 11019776 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 02077184 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-01 14:03 - 2013-03-02 06:03 - 00386048 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-10-01 14:03 - 2013-03-02 05:30 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-10-01 14:03 - 2013-03-02 05:29 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-01 14:03 - 2013-03-02 05:29 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-10-01 13:34 - 2013-10-01 13:34 - 237088386 _____ C:\Windows\MEMORY.DMP
2013-10-01 13:34 - 2013-10-01 13:34 - 00143840 _____ C:\Windows\Minidump\100113-20420-01.dmp
2013-09-26 10:52 - 2013-09-26 10:52 - 97892804 _____ C:\Windows\system32\虖ꟁᬌd
2013-09-25 16:07 - 2013-10-25 12:28 - 00000326 _____ C:\Windows\Tasks\WFSRUCH.job
2013-09-25 16:07 - 2013-09-25 16:07 - 00263680 __RSH C:\Windows\system32\taskengg.dll
==================== One Month Modified Files and Folders =======
2013-10-25 20:15 - 2013-10-25 20:16 - 01088113 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST(1).exe
2013-10-25 20:12 - 2013-10-25 20:11 - 00000448 _____ C:\Users\Max Funcke\Desktop\SecurityCheck.exe.lnk
2013-10-25 20:04 - 2013-10-25 20:04 - 00891167 _____ C:\Users\Max Funcke\Downloads\SecurityCheck.exe
2013-10-25 19:49 - 2013-05-29 16:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-25 19:33 - 2010-09-30 13:01 - 01087095 _____ C:\Windows\WindowsUpdate.log
2013-10-25 19:33 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\tracing
2013-10-25 19:24 - 2010-11-04 15:19 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-25 16:39 - 2013-10-25 16:39 - 02347384 _____ (ESET) C:\Users\Max Funcke\Downloads\esetsmartinstaller_enu.exe
2013-10-25 16:37 - 2010-06-29 15:26 - 01621294 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-25 16:35 - 2010-11-04 15:19 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-25 12:38 - 2013-10-25 12:38 - 01088113 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST.exe
2013-10-25 12:31 - 2009-07-14 06:34 - 00009888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-25 12:31 - 2009-07-14 06:34 - 00009888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-25 12:30 - 2013-10-25 12:30 - 00001401 _____ C:\Users\Max Funcke\Desktop\JRT.txt
2013-10-25 12:28 - 2013-10-25 12:28 - 01033335 _____ (Thisisu) C:\Users\Max Funcke\Downloads\JRT.exe
2013-10-25 12:28 - 2013-10-25 12:28 - 00000000 ____D C:\Windows\ERUNT
2013-10-25 12:28 - 2013-09-25 16:07 - 00000326 _____ C:\Windows\Tasks\WFSRUCH.job
2013-10-25 12:23 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-25 12:23 - 2009-07-14 06:39 - 00008004 _____ C:\Windows\setupact.log
2013-10-25 12:21 - 2013-10-25 12:18 - 00000000 ____D C:\AdwCleaner
2013-10-25 12:18 - 2013-10-25 12:18 - 01060070 _____ C:\Users\Max Funcke\Downloads\adwcleaner.exe
2013-10-25 12:14 - 2010-10-23 18:00 - 00000000 ____D C:\Windows\pss
2013-10-25 12:14 - 2010-09-30 18:17 - 00557048 _____ C:\Windows\PFRO.log
2013-10-25 11:56 - 2013-10-25 11:56 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\Users\Max Funcke\AppData\Roaming\Malwarebytes
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-23 17:45 - 2013-10-23 17:45 - 00014235 _____ C:\ComboFix.txt
2013-10-23 17:45 - 2013-10-23 17:33 - 00000000 ____D C:\Qoobox
2013-10-23 17:45 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-10-23 17:44 - 2013-10-23 17:33 - 00000000 ____D C:\Windows\erdnt
2013-10-23 17:43 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2013-10-23 17:32 - 2013-10-23 17:29 - 00001373 _____ C:\Users\Max Funcke\Desktop\ComboFix.exe.lnk
2013-10-22 19:13 - 2013-10-22 19:13 - 00000000 ____D C:\FRST
2013-10-22 19:10 - 2013-10-22 19:10 - 00000094 _____ C:\Users\Max Funcke\AppData\Roaming\WB.CFG
2013-10-22 19:09 - 2013-10-22 11:12 - 00000890 _____ C:\Users\Max Funcke\daemonprocess.txt
2013-10-22 11:27 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Mobogenie
2013-10-22 11:12 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\Documents\Mobogenie
2013-10-22 11:12 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\cache
2013-10-22 11:12 - 2010-09-30 13:08 - 00000000 ____D C:\Users\Max Funcke
2013-10-21 16:59 - 2013-10-21 16:59 - 00707880 _____ C:\Users\Max Funcke\Downloads\DownloadManagerSetup(1).exe
2013-10-21 16:58 - 2013-10-21 16:58 - 00707880 _____ C:\Users\Max Funcke\Downloads\DownloadManagerSetup.exe
2013-10-21 16:21 - 2010-10-15 11:50 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Google
2013-10-18 16:55 - 2012-02-17 18:07 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-18 15:41 - 2012-02-04 08:35 - 00013668 _____ C:\Windows\diagwrn.xml
2013-10-18 15:41 - 2012-02-04 08:35 - 00001908 _____ C:\Windows\diagerr.xml
2013-10-18 15:40 - 2013-10-18 15:37 - 00005006 _____ C:\Users\Max Funcke\Desktop\Windows Compatibility Report.htm
2013-10-18 15:31 - 2009-07-14 06:39 - 00000000 _____ C:\Windows\setuperr.log
2013-10-15 11:30 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2013-10-14 17:38 - 2010-10-08 11:56 - 00000000 ____D C:\Users\Max Funcke\Documents\ChessBase
2013-10-14 17:21 - 2010-06-30 11:55 - 00000000 ____D C:\ProgramData\Adobe
2013-10-12 12:34 - 2010-06-30 10:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-10 14:49 - 2010-09-30 15:29 - 00000000 ____D C:\Users\Max Funcke\AppData\Roaming\Adobe
2013-10-10 14:48 - 2013-10-10 14:48 - 00001993 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-10-10 14:48 - 2010-10-06 16:36 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Adobe
2013-10-10 14:47 - 2010-06-30 11:55 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-10 14:47 - 2010-06-30 11:55 - 00000000 ____D C:\Program Files\Adobe
2013-10-10 13:51 - 2013-05-29 16:51 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2013-10-10 13:51 - 2013-02-14 13:53 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-10 13:51 - 2011-09-13 10:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-10 12:06 - 2010-06-30 10:36 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-10 12:06 - 2009-07-14 04:04 - 00000687 _____ C:\Windows\win.ini
2013-10-10 11:33 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-10-06 14:52 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Help
2013-10-03 15:54 - 2012-08-30 12:43 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-02 14:43 - 2013-08-17 11:40 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Mozilla Firefox
2013-10-02 14:43 - 2013-02-28 19:04 - 00001233 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-10-02 14:43 - 2010-09-30 18:38 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Mozilla
2013-10-02 14:38 - 2013-10-02 14:38 - 00281896 _____ (Mozilla) C:\Users\Max Funcke\Downloads\Firefox Setup Stub 24.0.exe
2013-10-01 16:15 - 2013-05-06 12:01 - 00067680 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-10-01 16:15 - 2012-10-09 18:02 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-10-01 16:15 - 2012-10-09 18:02 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-10-01 16:15 - 2012-10-09 18:02 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-10-01 13:35 - 2010-09-30 13:01 - 00000000 ____D C:\Recovery
2013-10-01 13:35 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\Recovery
2013-10-01 13:34 - 2013-10-01 13:34 - 237088386 _____ C:\Windows\MEMORY.DMP
2013-10-01 13:34 - 2013-10-01 13:34 - 00143840 _____ C:\Windows\Minidump\100113-20420-01.dmp
2013-10-01 13:34 - 2010-10-09 18:40 - 00000000 ____D C:\Windows\Minidump
2013-09-26 10:52 - 2013-09-26 10:52 - 97892804 _____ C:\Windows\system32\虖ꟁᬌd
2013-09-25 16:07 - 2013-09-25 16:07 - 00263680 __RSH C:\Windows\system32\taskengg.dll
Some content of TEMP:
====================
C:\Users\Max Funcke\AppData\Local\Temp\avgnt.exe
C:\Users\Max Funcke\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-25 19:51
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Brauchst Du noch was?
Gruß Max
Hallo Schrauber, es gab ein Problem, jetzt hab ich, glaube ich doch geschafft.(Der Eset Testlog ist verschütt gegangen, war aber komplett negativ (nach 2,5 Stunden)
Du meldest Dichsicher wieder, fehlt noch etwas?
Schönes Wochenende xamecknuf
Security Log Code:
Results of screen317's Security Check version 0.99.74
Windows 7 x86 (UAC is disabled!)
Out of date service pack!! ``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Avira Desktop
Antivirus up to date! `````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
Java(TM) 6 Update 21
Java version out of Date!
Adobe Flash Player 11.9.900.117
Adobe Reader 9
Adobe Reader XI
Mozilla Firefox (24.0) ````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
Frst Test:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-10-2013
Ran by Max Funcke (administrator) on ALDIPC on 25-10-2013 22:06:44
Running from C:\Users\Max Funcke\Downloads
Microsoft Windows 7 Home Premium (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(REINER SCT) C:\Windows\system32\cjpcsc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
() G:\SecurityCheck.exe
(Microsoft Corporation) C:\Windows\system32\cmd.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Mozilla Corporation) C:\Users\Max Funcke\AppData\Local\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\Max Funcke\Downloads\FRST(2).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [LexwareInfoService] - C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] ()
HKU\Default\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [ 2009-10-23] ()
HKU\Default User\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] ()
HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [ 2009-10-23] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {4B485EF4-889E-4A2D-98F9-ED6CEDE22D33} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MEDTDF&pc=MAMD&src=IE-SearchBox
SearchScopes: HKCU - {4B485EF4-889E-4A2D-98F9-ED6CEDE22D33} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MEDTDF&pc=MAMD&src=IE-SearchBox
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {8C3887BA-3367-4297-B288-13472BD407E4} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Winsock: Catalog9 01 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 02 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 03 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 04 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 05 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 06 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 07 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 08 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 09 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 10 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 11 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 12 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 13 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 14 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 15 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 16 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 18 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 19 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 29 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 30 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 000000000100 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000101 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000102 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000103 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000104 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000105 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000106 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000107 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000108 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000109 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000110 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Max Funcke\AppData\Roaming\Mozilla\Firefox\Profiles\rkxjz51e.default
FF DefaultSearchEngine: Startpage HTTPS - Deutsch
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Max Funcke\AppData\Roaming\Mozilla\Firefox\Profiles\rkxjz51e.default\searchplugins\ixquick-https---deutsch.xml
FF SearchPlugin: C:\Users\Max Funcke\AppData\Roaming\Mozilla\Firefox\Profiles\rkxjz51e.default\searchplugins\startpage-https---deutsch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\googledesktop.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: adblockplus - C:\Users\Max Funcke\AppData\Roaming\Mozilla\Firefox\Profiles\rkxjz51e.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF StartMenuInternet: FIREFOX.EXE - C:\Users\Max Funcke\AppData\Local\Mozilla Firefox\firefox.exe
========================== Services (Whitelisted) =================
S2 AcronisOSSReinstallSvc; C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe [2232296 2012-02-17] ()
R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [619408 2009-11-06] (Acronis)
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [948296 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 cjpcsc; C:\Windows\system32\cjpcsc.exe [514128 2012-03-19] (REINER SCT)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S4 BsFileScan; C:\Program Files\BullGuard Ltd\BullGuard\BsFileScan.dll [x]
S4 BsMailProxy; C:\Program Files\BullGuard Ltd\BullGuard\BsMailProxy\BsMailProxy.dll [x]
S4 BsMain; C:\Program Files\BullGuard Ltd\BullGuard\BsMain.dll [x]
S4 BsScanner; C:\Program Files\BullGuard Ltd\BullGuard\BullGuardScanner.exe [x]
S4 BsUpdate; C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe [x]
==================== Drivers (Whitelisted) ====================
R1 AFW; C:\Windows\System32\DRIVERS\afw.sys [29208 2012-02-17] (Agnitum Ltd.)
R3 afwcore; C:\Windows\System32\DRIVERS\afwcore.sys [318488 2012-02-17] (Agnitum Ltd.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 BdSpy; C:\Windows\System32\DRIVERS\BdSpy.sys [55888 2012-02-17] (BullGuard Ltd.)
R1 bizVSerial; C:\Windows\System32\drivers\bizVSerialNT.sys [14949 2007-05-31] (franson.biz)
S3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [28144 2012-02-17] (REINER SCT)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [38400 2012-02-17] (Samsung Electronics Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [16472 2010-08-16] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [11104 2010-08-16] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-10-09] (Avira GmbH)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2011-03-14] (Samsung Electronics)
R0 tdrpman251; C:\Windows\System32\DRIVERS\tdrpm251.sys [902432 2012-02-19] (Acronis)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2012-02-17] (Microsoft Corporation)
S3 catchme; \??\C:\Users\MAXFUN~1\AppData\Local\Temp\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-25 22:06 - 2013-10-25 22:06 - 01088465 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST(2).exe
2013-10-25 20:16 - 2013-10-25 20:15 - 01088113 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST(1).exe
2013-10-25 20:11 - 2013-10-25 20:12 - 00000448 _____ C:\Users\Max Funcke\Desktop\SecurityCheck.exe.lnk
2013-10-25 20:04 - 2013-10-25 20:04 - 00891167 _____ C:\Users\Max Funcke\Downloads\SecurityCheck.exe
2013-10-25 16:39 - 2013-10-25 16:39 - 02347384 _____ (ESET) C:\Users\Max Funcke\Downloads\esetsmartinstaller_enu.exe
2013-10-25 12:38 - 2013-10-25 12:38 - 01088113 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST.exe
2013-10-25 12:30 - 2013-10-25 12:30 - 00001401 _____ C:\Users\Max Funcke\Desktop\JRT.txt
2013-10-25 12:28 - 2013-10-25 12:28 - 01033335 _____ (Thisisu) C:\Users\Max Funcke\Downloads\JRT.exe
2013-10-25 12:28 - 2013-10-25 12:28 - 00000000 ____D C:\Windows\ERUNT
2013-10-25 12:18 - 2013-10-25 12:21 - 00000000 ____D C:\AdwCleaner
2013-10-25 12:18 - 2013-10-25 12:18 - 01060070 _____ C:\Users\Max Funcke\Downloads\adwcleaner.exe
2013-10-25 11:56 - 2013-10-25 11:56 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\Users\Max Funcke\AppData\Roaming\Malwarebytes
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-25 11:56 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-23 17:45 - 2013-10-23 17:45 - 00014235 _____ C:\ComboFix.txt
2013-10-23 17:36 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-23 17:36 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-23 17:36 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-23 17:33 - 2013-10-23 17:45 - 00000000 ____D C:\Qoobox
2013-10-23 17:33 - 2013-10-23 17:44 - 00000000 ____D C:\Windows\erdnt
2013-10-23 17:29 - 2013-10-23 17:32 - 00001373 _____ C:\Users\Max Funcke\Desktop\ComboFix.exe.lnk
2013-10-22 19:13 - 2013-10-22 19:13 - 00000000 ____D C:\FRST
2013-10-22 19:10 - 2013-10-22 19:10 - 00000094 _____ C:\Users\Max Funcke\AppData\Roaming\WB.CFG
2013-10-22 11:12 - 2013-10-22 19:09 - 00000890 _____ C:\Users\Max Funcke\daemonprocess.txt
2013-10-22 11:12 - 2013-10-22 11:27 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Mobogenie
2013-10-22 11:12 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\Documents\Mobogenie
2013-10-22 11:12 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\cache
2013-10-21 16:59 - 2013-10-21 16:59 - 00707880 _____ C:\Users\Max Funcke\Downloads\DownloadManagerSetup(1).exe
2013-10-21 16:58 - 2013-10-21 16:58 - 00707880 _____ C:\Users\Max Funcke\Downloads\DownloadManagerSetup.exe
2013-10-18 15:37 - 2013-10-18 15:40 - 00005006 _____ C:\Users\Max Funcke\Desktop\Windows Compatibility Report.htm
2013-10-10 14:48 - 2013-10-10 14:48 - 00001993 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-10-02 14:38 - 2013-10-02 14:38 - 00281896 _____ (Mozilla) C:\Users\Max Funcke\Downloads\Firefox Setup Stub 24.0.exe
2013-10-01 14:03 - 2013-03-02 07:06 - 00981504 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-01 14:03 - 2013-03-02 07:05 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-01 14:03 - 2013-03-02 07:05 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 06032384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 00606208 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 11019776 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 02077184 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-01 14:03 - 2013-03-02 06:03 - 00386048 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-10-01 14:03 - 2013-03-02 05:30 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-10-01 14:03 - 2013-03-02 05:29 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-01 14:03 - 2013-03-02 05:29 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-10-01 13:34 - 2013-10-01 13:34 - 237088386 _____ C:\Windows\MEMORY.DMP
2013-10-01 13:34 - 2013-10-01 13:34 - 00143840 _____ C:\Windows\Minidump\100113-20420-01.dmp
2013-09-26 10:52 - 2013-09-26 10:52 - 97892804 _____ C:\Windows\system32\虖ꟁᬌd
2013-09-25 16:07 - 2013-10-25 21:47 - 00000326 _____ C:\Windows\Tasks\WFSRUCH.job
2013-09-25 16:07 - 2013-09-25 16:07 - 00263680 __RSH C:\Windows\system32\taskengg.dll
==================== One Month Modified Files and Folders =======
2013-10-25 22:06 - 2013-10-25 22:06 - 01088465 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST(2).exe
2013-10-25 21:55 - 2009-07-14 06:34 - 00009888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-25 21:55 - 2009-07-14 06:34 - 00009888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-25 21:52 - 2010-09-30 13:01 - 01094249 _____ C:\Windows\WindowsUpdate.log
2013-10-25 21:49 - 2013-05-29 16:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-25 21:48 - 2010-11-04 15:19 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-25 21:47 - 2013-09-25 16:07 - 00000326 _____ C:\Windows\Tasks\WFSRUCH.job
2013-10-25 21:47 - 2010-09-30 18:17 - 00557854 _____ C:\Windows\PFRO.log
2013-10-25 21:47 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-25 21:47 - 2009-07-14 06:39 - 00008060 _____ C:\Windows\setupact.log
2013-10-25 20:22 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\tracing
2013-10-25 20:15 - 2013-10-25 20:16 - 01088113 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST(1).exe
2013-10-25 20:12 - 2013-10-25 20:11 - 00000448 _____ C:\Users\Max Funcke\Desktop\SecurityCheck.exe.lnk
2013-10-25 20:04 - 2013-10-25 20:04 - 00891167 _____ C:\Users\Max Funcke\Downloads\SecurityCheck.exe
2013-10-25 19:24 - 2010-11-04 15:19 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-25 16:39 - 2013-10-25 16:39 - 02347384 _____ (ESET) C:\Users\Max Funcke\Downloads\esetsmartinstaller_enu.exe
2013-10-25 16:37 - 2010-06-29 15:26 - 01621294 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-25 12:38 - 2013-10-25 12:38 - 01088113 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST.exe
2013-10-25 12:30 - 2013-10-25 12:30 - 00001401 _____ C:\Users\Max Funcke\Desktop\JRT.txt
2013-10-25 12:28 - 2013-10-25 12:28 - 01033335 _____ (Thisisu) C:\Users\Max Funcke\Downloads\JRT.exe
2013-10-25 12:28 - 2013-10-25 12:28 - 00000000 ____D C:\Windows\ERUNT
2013-10-25 12:21 - 2013-10-25 12:18 - 00000000 ____D C:\AdwCleaner
2013-10-25 12:18 - 2013-10-25 12:18 - 01060070 _____ C:\Users\Max Funcke\Downloads\adwcleaner.exe
2013-10-25 12:14 - 2010-10-23 18:00 - 00000000 ____D C:\Windows\pss
2013-10-25 11:56 - 2013-10-25 11:56 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\Users\Max Funcke\AppData\Roaming\Malwarebytes
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-23 17:45 - 2013-10-23 17:45 - 00014235 _____ C:\ComboFix.txt
2013-10-23 17:45 - 2013-10-23 17:33 - 00000000 ____D C:\Qoobox
2013-10-23 17:45 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-10-23 17:44 - 2013-10-23 17:33 - 00000000 ____D C:\Windows\erdnt
2013-10-23 17:43 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2013-10-23 17:32 - 2013-10-23 17:29 - 00001373 _____ C:\Users\Max Funcke\Desktop\ComboFix.exe.lnk
2013-10-22 19:13 - 2013-10-22 19:13 - 00000000 ____D C:\FRST
2013-10-22 19:10 - 2013-10-22 19:10 - 00000094 _____ C:\Users\Max Funcke\AppData\Roaming\WB.CFG
2013-10-22 19:09 - 2013-10-22 11:12 - 00000890 _____ C:\Users\Max Funcke\daemonprocess.txt
2013-10-22 11:27 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Mobogenie
2013-10-22 11:12 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\Documents\Mobogenie
2013-10-22 11:12 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\cache
2013-10-22 11:12 - 2010-09-30 13:08 - 00000000 ____D C:\Users\Max Funcke
2013-10-21 16:59 - 2013-10-21 16:59 - 00707880 _____ C:\Users\Max Funcke\Downloads\DownloadManagerSetup(1).exe
2013-10-21 16:58 - 2013-10-21 16:58 - 00707880 _____ C:\Users\Max Funcke\Downloads\DownloadManagerSetup.exe
2013-10-21 16:21 - 2010-10-15 11:50 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Google
2013-10-18 16:55 - 2012-02-17 18:07 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-18 15:41 - 2012-02-04 08:35 - 00013668 _____ C:\Windows\diagwrn.xml
2013-10-18 15:41 - 2012-02-04 08:35 - 00001908 _____ C:\Windows\diagerr.xml
2013-10-18 15:40 - 2013-10-18 15:37 - 00005006 _____ C:\Users\Max Funcke\Desktop\Windows Compatibility Report.htm
2013-10-18 15:31 - 2009-07-14 06:39 - 00000000 _____ C:\Windows\setuperr.log
2013-10-15 11:30 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2013-10-14 17:38 - 2010-10-08 11:56 - 00000000 ____D C:\Users\Max Funcke\Documents\ChessBase
2013-10-14 17:21 - 2010-06-30 11:55 - 00000000 ____D C:\ProgramData\Adobe
2013-10-12 12:34 - 2010-06-30 10:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-10 14:49 - 2010-09-30 15:29 - 00000000 ____D C:\Users\Max Funcke\AppData\Roaming\Adobe
2013-10-10 14:48 - 2013-10-10 14:48 - 00001993 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-10-10 14:48 - 2010-10-06 16:36 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Adobe
2013-10-10 14:47 - 2010-06-30 11:55 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-10 14:47 - 2010-06-30 11:55 - 00000000 ____D C:\Program Files\Adobe
2013-10-10 13:51 - 2013-05-29 16:51 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2013-10-10 13:51 - 2013-02-14 13:53 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-10 13:51 - 2011-09-13 10:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-10 12:06 - 2010-06-30 10:36 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-10 12:06 - 2009-07-14 04:04 - 00000687 _____ C:\Windows\win.ini
2013-10-10 11:33 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-10-06 14:52 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Help
2013-10-03 15:54 - 2012-08-30 12:43 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-02 14:43 - 2013-08-17 11:40 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Mozilla Firefox
2013-10-02 14:43 - 2013-02-28 19:04 - 00001233 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-10-02 14:43 - 2010-09-30 18:38 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Mozilla
2013-10-02 14:38 - 2013-10-02 14:38 - 00281896 _____ (Mozilla) C:\Users\Max Funcke\Downloads\Firefox Setup Stub 24.0.exe
2013-10-01 16:15 - 2013-05-06 12:01 - 00067680 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-10-01 16:15 - 2012-10-09 18:02 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-10-01 16:15 - 2012-10-09 18:02 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-10-01 16:15 - 2012-10-09 18:02 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-10-01 13:35 - 2010-09-30 13:01 - 00000000 ____D C:\Recovery
2013-10-01 13:35 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\Recovery
2013-10-01 13:34 - 2013-10-01 13:34 - 237088386 _____ C:\Windows\MEMORY.DMP
2013-10-01 13:34 - 2013-10-01 13:34 - 00143840 _____ C:\Windows\Minidump\100113-20420-01.dmp
2013-10-01 13:34 - 2010-10-09 18:40 - 00000000 ____D C:\Windows\Minidump
2013-09-26 10:52 - 2013-09-26 10:52 - 97892804 _____ C:\Windows\system32\虖ꟁᬌd
2013-09-25 16:07 - 2013-09-25 16:07 - 00263680 __RSH C:\Windows\system32\taskengg.dll
Some content of TEMP:
====================
C:\Users\Max Funcke\AppData\Local\Temp\avgnt.exe
C:\Users\Max Funcke\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-25 19:51
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
HI, Schrauber, nach frst update neuen Log:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-10-2013
Ran by Max Funcke (administrator) on ALDIPC on 25-10-2013 22:21:48
Running from C:\Users\Max Funcke\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5SJWFKMY
Microsoft Windows 7 Home Premium (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(REINER SCT) C:\Windows\system32\cjpcsc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
() G:\SecurityCheck.exe
(Microsoft Corporation) C:\Windows\system32\cmd.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Farbar) C:\Users\Max Funcke\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5SJWFKMY\FRST[1].exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [LexwareInfoService] - C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKU\Default User\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] ()
HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [ 2009-10-23] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {4B485EF4-889E-4A2D-98F9-ED6CEDE22D33} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MEDTDF&pc=MAMD&src=IE-SearchBox
SearchScopes: HKCU - {4B485EF4-889E-4A2D-98F9-ED6CEDE22D33} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MEDTDF&pc=MAMD&src=IE-SearchBox
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {8C3887BA-3367-4297-B288-13472BD407E4} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Winsock: Catalog9 01 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 02 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 03 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 04 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 05 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 06 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 07 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 08 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 09 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 10 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 11 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 12 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 13 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 14 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 15 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 16 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 18 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 19 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 29 C:\Windows\system32\BGLsp.dll [148816] (BullGuard Ltd.)
Winsock: Catalog9 30 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 000000000100 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000101 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000102 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000103 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000104 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000105 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000106 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000107 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000108 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000109 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 000000000110 %SystemRoot%\system32\mswsock.dll [232448] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Max Funcke\AppData\Roaming\Mozilla\Firefox\Profiles\rkxjz51e.default
FF DefaultSearchEngine: Startpage HTTPS - Deutsch
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Max Funcke\AppData\Roaming\Mozilla\Firefox\Profiles\rkxjz51e.default\searchplugins\ixquick-https---deutsch.xml
FF SearchPlugin: C:\Users\Max Funcke\AppData\Roaming\Mozilla\Firefox\Profiles\rkxjz51e.default\searchplugins\startpage-https---deutsch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\googledesktop.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: adblockplus - C:\Users\Max Funcke\AppData\Roaming\Mozilla\Firefox\Profiles\rkxjz51e.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF StartMenuInternet: FIREFOX.EXE - C:\Users\Max Funcke\AppData\Local\Mozilla Firefox\firefox.exe
========================== Services (Whitelisted) =================
S2 AcronisOSSReinstallSvc; C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe [2232296 2012-02-17] ()
R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [619408 2009-11-06] (Acronis)
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [948296 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 cjpcsc; C:\Windows\system32\cjpcsc.exe [514128 2012-03-19] (REINER SCT)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S4 BsFileScan; C:\Program Files\BullGuard Ltd\BullGuard\BsFileScan.dll [x]
S4 BsMailProxy; C:\Program Files\BullGuard Ltd\BullGuard\BsMailProxy\BsMailProxy.dll [x]
S4 BsMain; C:\Program Files\BullGuard Ltd\BullGuard\BsMain.dll [x]
S4 BsScanner; C:\Program Files\BullGuard Ltd\BullGuard\BullGuardScanner.exe [x]
S4 BsUpdate; C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe [x]
==================== Drivers (Whitelisted) ====================
R1 AFW; C:\Windows\System32\DRIVERS\afw.sys [29208 2012-02-17] (Agnitum Ltd.)
R3 afwcore; C:\Windows\System32\DRIVERS\afwcore.sys [318488 2012-02-17] (Agnitum Ltd.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 BdSpy; C:\Windows\System32\DRIVERS\BdSpy.sys [55888 2012-02-17] (BullGuard Ltd.)
R1 bizVSerial; C:\Windows\System32\drivers\bizVSerialNT.sys [14949 2007-05-31] (franson.biz)
S3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [28144 2012-02-17] (REINER SCT)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [38400 2012-02-17] (Samsung Electronics Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [16472 2010-08-16] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [11104 2010-08-16] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-10-09] (Avira GmbH)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2011-03-14] (Samsung Electronics)
R0 tdrpman251; C:\Windows\System32\DRIVERS\tdrpm251.sys [902432 2012-02-19] (Acronis)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2012-02-17] (Microsoft Corporation)
S3 catchme; \??\C:\Users\MAXFUN~1\AppData\Local\Temp\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-25 22:07 - 2013-10-25 22:07 - 00027879 _____ C:\Users\Max Funcke\Downloads\FRST.txt
2013-10-25 22:06 - 2013-10-25 22:06 - 01088465 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST(2).exe
2013-10-25 20:16 - 2013-10-25 20:15 - 01088113 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST(1).exe
2013-10-25 20:11 - 2013-10-25 20:12 - 00000448 _____ C:\Users\Max Funcke\Desktop\SecurityCheck.exe.lnk
2013-10-25 20:04 - 2013-10-25 20:04 - 00891167 _____ C:\Users\Max Funcke\Downloads\SecurityCheck.exe
2013-10-25 16:39 - 2013-10-25 16:39 - 02347384 _____ (ESET) C:\Users\Max Funcke\Downloads\esetsmartinstaller_enu.exe
2013-10-25 12:30 - 2013-10-25 12:30 - 00001401 _____ C:\Users\Max Funcke\Desktop\JRT.txt
2013-10-25 12:28 - 2013-10-25 12:28 - 01033335 _____ (Thisisu) C:\Users\Max Funcke\Downloads\JRT.exe
2013-10-25 12:28 - 2013-10-25 12:28 - 00000000 ____D C:\Windows\ERUNT
2013-10-25 12:18 - 2013-10-25 12:21 - 00000000 ____D C:\AdwCleaner
2013-10-25 12:18 - 2013-10-25 12:18 - 01060070 _____ C:\Users\Max Funcke\Downloads\adwcleaner.exe
2013-10-25 11:56 - 2013-10-25 11:56 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\Users\Max Funcke\AppData\Roaming\Malwarebytes
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-25 11:56 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-23 17:45 - 2013-10-23 17:45 - 00014235 _____ C:\ComboFix.txt
2013-10-23 17:36 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-23 17:36 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-23 17:36 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-23 17:36 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-23 17:33 - 2013-10-23 17:45 - 00000000 ____D C:\Qoobox
2013-10-23 17:33 - 2013-10-23 17:44 - 00000000 ____D C:\Windows\erdnt
2013-10-23 17:29 - 2013-10-23 17:32 - 00001373 _____ C:\Users\Max Funcke\Desktop\ComboFix.exe.lnk
2013-10-22 19:13 - 2013-10-22 19:13 - 00000000 ____D C:\FRST
2013-10-22 19:10 - 2013-10-22 19:10 - 00000094 _____ C:\Users\Max Funcke\AppData\Roaming\WB.CFG
2013-10-22 11:12 - 2013-10-22 19:09 - 00000890 _____ C:\Users\Max Funcke\daemonprocess.txt
2013-10-22 11:12 - 2013-10-22 11:27 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Mobogenie
2013-10-22 11:12 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\Documents\Mobogenie
2013-10-22 11:12 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\cache
2013-10-21 16:59 - 2013-10-21 16:59 - 00707880 _____ C:\Users\Max Funcke\Downloads\DownloadManagerSetup(1).exe
2013-10-21 16:58 - 2013-10-21 16:58 - 00707880 _____ C:\Users\Max Funcke\Downloads\DownloadManagerSetup.exe
2013-10-18 15:37 - 2013-10-18 15:40 - 00005006 _____ C:\Users\Max Funcke\Desktop\Windows Compatibility Report.htm
2013-10-10 14:48 - 2013-10-10 14:48 - 00001993 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-10-02 14:38 - 2013-10-02 14:38 - 00281896 _____ (Mozilla) C:\Users\Max Funcke\Downloads\Firefox Setup Stub 24.0.exe
2013-10-01 14:03 - 2013-03-02 07:06 - 00981504 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-01 14:03 - 2013-03-02 07:05 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-01 14:03 - 2013-03-02 07:05 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 06032384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 00606208 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-10-01 14:03 - 2013-03-02 07:02 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 11019776 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 02077184 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-01 14:03 - 2013-03-02 07:01 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-01 14:03 - 2013-03-02 06:03 - 00386048 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-10-01 14:03 - 2013-03-02 05:30 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-10-01 14:03 - 2013-03-02 05:29 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-01 14:03 - 2013-03-02 05:29 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-10-01 13:34 - 2013-10-01 13:34 - 237088386 _____ C:\Windows\MEMORY.DMP
2013-10-01 13:34 - 2013-10-01 13:34 - 00143840 _____ C:\Windows\Minidump\100113-20420-01.dmp
2013-09-26 10:52 - 2013-09-26 10:52 - 97892804 _____ C:\Windows\system32\虖ꟁᬌd
2013-09-25 16:07 - 2013-10-25 21:47 - 00000326 _____ C:\Windows\Tasks\WFSRUCH.job
2013-09-25 16:07 - 2013-09-25 16:07 - 00263680 __RSH C:\Windows\system32\taskengg.dll
==================== One Month Modified Files and Folders =======
2013-10-25 22:12 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\tracing
2013-10-25 22:07 - 2013-10-25 22:07 - 00027879 _____ C:\Users\Max Funcke\Downloads\FRST.txt
2013-10-25 22:06 - 2013-10-25 22:06 - 01088465 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST(2).exe
2013-10-25 21:55 - 2009-07-14 06:34 - 00009888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-25 21:55 - 2009-07-14 06:34 - 00009888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-25 21:52 - 2010-09-30 13:01 - 01094249 _____ C:\Windows\WindowsUpdate.log
2013-10-25 21:49 - 2013-05-29 16:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-25 21:48 - 2010-11-04 15:19 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-25 21:47 - 2013-09-25 16:07 - 00000326 _____ C:\Windows\Tasks\WFSRUCH.job
2013-10-25 21:47 - 2010-09-30 18:17 - 00557854 _____ C:\Windows\PFRO.log
2013-10-25 21:47 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-25 21:47 - 2009-07-14 06:39 - 00008060 _____ C:\Windows\setupact.log
2013-10-25 20:15 - 2013-10-25 20:16 - 01088113 _____ (Farbar) C:\Users\Max Funcke\Downloads\FRST(1).exe
2013-10-25 20:12 - 2013-10-25 20:11 - 00000448 _____ C:\Users\Max Funcke\Desktop\SecurityCheck.exe.lnk
2013-10-25 20:04 - 2013-10-25 20:04 - 00891167 _____ C:\Users\Max Funcke\Downloads\SecurityCheck.exe
2013-10-25 19:24 - 2010-11-04 15:19 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-25 16:39 - 2013-10-25 16:39 - 02347384 _____ (ESET) C:\Users\Max Funcke\Downloads\esetsmartinstaller_enu.exe
2013-10-25 16:37 - 2010-06-29 15:26 - 01621294 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-25 12:30 - 2013-10-25 12:30 - 00001401 _____ C:\Users\Max Funcke\Desktop\JRT.txt
2013-10-25 12:28 - 2013-10-25 12:28 - 01033335 _____ (Thisisu) C:\Users\Max Funcke\Downloads\JRT.exe
2013-10-25 12:28 - 2013-10-25 12:28 - 00000000 ____D C:\Windows\ERUNT
2013-10-25 12:21 - 2013-10-25 12:18 - 00000000 ____D C:\AdwCleaner
2013-10-25 12:18 - 2013-10-25 12:18 - 01060070 _____ C:\Users\Max Funcke\Downloads\adwcleaner.exe
2013-10-25 12:14 - 2010-10-23 18:00 - 00000000 ____D C:\Windows\pss
2013-10-25 11:56 - 2013-10-25 11:56 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\Users\Max Funcke\AppData\Roaming\Malwarebytes
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-25 11:56 - 2013-10-25 11:56 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-23 17:45 - 2013-10-23 17:45 - 00014235 _____ C:\ComboFix.txt
2013-10-23 17:45 - 2013-10-23 17:33 - 00000000 ____D C:\Qoobox
2013-10-23 17:45 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-10-23 17:44 - 2013-10-23 17:33 - 00000000 ____D C:\Windows\erdnt
2013-10-23 17:43 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2013-10-23 17:32 - 2013-10-23 17:29 - 00001373 _____ C:\Users\Max Funcke\Desktop\ComboFix.exe.lnk
2013-10-22 19:13 - 2013-10-22 19:13 - 00000000 ____D C:\FRST
2013-10-22 19:10 - 2013-10-22 19:10 - 00000094 _____ C:\Users\Max Funcke\AppData\Roaming\WB.CFG
2013-10-22 19:09 - 2013-10-22 11:12 - 00000890 _____ C:\Users\Max Funcke\daemonprocess.txt
2013-10-22 11:27 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Mobogenie
2013-10-22 11:12 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\Documents\Mobogenie
2013-10-22 11:12 - 2013-10-22 11:12 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\cache
2013-10-22 11:12 - 2010-09-30 13:08 - 00000000 ____D C:\Users\Max Funcke
2013-10-21 16:59 - 2013-10-21 16:59 - 00707880 _____ C:\Users\Max Funcke\Downloads\DownloadManagerSetup(1).exe
2013-10-21 16:58 - 2013-10-21 16:58 - 00707880 _____ C:\Users\Max Funcke\Downloads\DownloadManagerSetup.exe
2013-10-21 16:21 - 2010-10-15 11:50 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Google
2013-10-18 16:55 - 2012-02-17 18:07 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-18 15:41 - 2012-02-04 08:35 - 00013668 _____ C:\Windows\diagwrn.xml
2013-10-18 15:41 - 2012-02-04 08:35 - 00001908 _____ C:\Windows\diagerr.xml
2013-10-18 15:40 - 2013-10-18 15:37 - 00005006 _____ C:\Users\Max Funcke\Desktop\Windows Compatibility Report.htm
2013-10-18 15:31 - 2009-07-14 06:39 - 00000000 _____ C:\Windows\setuperr.log
2013-10-15 11:30 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2013-10-14 17:38 - 2010-10-08 11:56 - 00000000 ____D C:\Users\Max Funcke\Documents\ChessBase
2013-10-14 17:21 - 2010-06-30 11:55 - 00000000 ____D C:\ProgramData\Adobe
2013-10-12 12:34 - 2010-06-30 10:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-10 14:49 - 2010-09-30 15:29 - 00000000 ____D C:\Users\Max Funcke\AppData\Roaming\Adobe
2013-10-10 14:48 - 2013-10-10 14:48 - 00001993 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-10-10 14:48 - 2010-10-06 16:36 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Adobe
2013-10-10 14:47 - 2010-06-30 11:55 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-10-10 14:47 - 2010-06-30 11:55 - 00000000 ____D C:\Program Files\Adobe
2013-10-10 13:51 - 2013-05-29 16:51 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2013-10-10 13:51 - 2013-02-14 13:53 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-10 13:51 - 2011-09-13 10:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-10 12:06 - 2010-06-30 10:36 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-10 12:06 - 2009-07-14 04:04 - 00000687 _____ C:\Windows\win.ini
2013-10-10 11:33 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-10-06 14:52 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Help
2013-10-03 15:54 - 2012-08-30 12:43 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-02 14:43 - 2013-08-17 11:40 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Mozilla Firefox
2013-10-02 14:43 - 2013-02-28 19:04 - 00001233 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-10-02 14:43 - 2010-09-30 18:38 - 00000000 ____D C:\Users\Max Funcke\AppData\Local\Mozilla
2013-10-02 14:38 - 2013-10-02 14:38 - 00281896 _____ (Mozilla) C:\Users\Max Funcke\Downloads\Firefox Setup Stub 24.0.exe
2013-10-01 16:15 - 2013-05-06 12:01 - 00067680 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-10-01 16:15 - 2012-10-09 18:02 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-10-01 16:15 - 2012-10-09 18:02 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-10-01 16:15 - 2012-10-09 18:02 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-10-01 13:35 - 2010-09-30 13:01 - 00000000 ____D C:\Recovery
2013-10-01 13:35 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\Recovery
2013-10-01 13:34 - 2013-10-01 13:34 - 237088386 _____ C:\Windows\MEMORY.DMP
2013-10-01 13:34 - 2013-10-01 13:34 - 00143840 _____ C:\Windows\Minidump\100113-20420-01.dmp
2013-10-01 13:34 - 2010-10-09 18:40 - 00000000 ____D C:\Windows\Minidump
2013-09-26 10:52 - 2013-09-26 10:52 - 97892804 _____ C:\Windows\system32\虖ꟁᬌd
2013-09-25 16:07 - 2013-09-25 16:07 - 00263680 __RSH C:\Windows\system32\taskengg.dll
Some content of TEMP:
====================
C:\Users\Max Funcke\AppData\Local\Temp\avgnt.exe
C:\Users\Max Funcke\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-25 19:51
==================== End Of Log ============================ --- --- ---
--- --- ---
Gruß xamecknuf |