Sherif952 | 08.02.2014 18:24 | Mannomann, das hat aber bis jetzt jede Menge Staunen hervorgerufen. Ich hoffe, dass alles so richtig war, wie Du es beschrieben hast! Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=b008d7b85c064c41a3f2b44e30ebb655
# engine=16991
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-08 01:52:09
# local_time=2014-02-08 02:52:09 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=5122 16777214 66 93 2353060 141702687 0 0
# compatibility_mode=5892 16776573 100 100 109107 229400257 0 0
# scanned=164139
# found=0
# cleaned=0
# scan_time=5119 viele Grüße
Sherif952
Sodele, hier der Rest: Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=b008d7b85c064c41a3f2b44e30ebb655
# engine=16991
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-08 01:52:09
# local_time=2014-02-08 02:52:09 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=5122 16777214 66 93 2353060 141702687 0 0
# compatibility_mode=5892 16776573 100 100 109107 229400257 0 0
# scanned=164139
# found=0
# cleaned=0
# scan_time=5119 Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2014.02.08.04
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Ulrich :: ULRICH-PC [Administrator]
Schutz: Aktiviert
08.02.2014 15:35:20
mbam-log-2014-02-08 (15-35-20).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 238596
Laufzeit: 7 Minute(n), 20 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) Es scheint, als ob alles so weit entfernt ist. Was mache ich jetzt mit den teilweise noch gespeicherten Dateien (Malwarepytes z.b.).
Und ich denke, Firewall und Virenscanner kann ich wieder hochfahren,, oder???
Viele Grüße und besten Dank:applaus:
Sherif952
Justalmente habe ich bemerkt, dass ich noch einen FRST-Auszug schuldig bin, das müsste dieser sein:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 07-02-2014
Ran by Ulrich (administrator) on ULRICH-PC on 08-02-2014 18:16:14
Running from C:\Users\Ulrich\Downloads
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Realtek Semiconductor) C:\Windows\RTKAUDIOSERVICE.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corp.) C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(PC Drivers Headquarters) C:\Program Files\Driver Restore\Driver Restore\DriverRestore.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Google Inc.) C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Sony Corporation) C:\Program Files\sony\VAIO Update 4\VAIOUpdt.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesApp32.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\Platform\McUICnt.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [mcui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [516912 2013-09-24] (McAfee, Inc.)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6703648 2009-07-24] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [2296600 2013-07-31] (Logitech, Inc.)
HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [Bing Bar] - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe [243544 2010-04-27] (Microsoft Corp.)
HKLM\...\Run: [Microsoft Default Manager] - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [288088 2009-11-11] (Microsoft Corporation)
HKLM\...\Run: [hpqSRMon] - C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM\...\Run: [Nero MediaHome 4] - C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe [5178664 2010-10-26] (Nero AG)
HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-12-23] (DivX, LLC)
HKLM\...\Run: [NvBackend] - C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [mcpltui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [516912 2013-09-24] (McAfee, Inc.)
Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll (Sony Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3991109205-4196775496-539255635-1000\...\Run: [NSUFloatingUI] - C:\Program Files\Sony\Network Utility\LANUtil.exe [270336 2008-11-22] (Sony Corporation)
HKU\S-1-5-21-3991109205-4196775496-539255635-1000\...\Run: [Driver Restore] - C:\Program Files\Driver Restore\Driver Restore\DriverRestore.exe [3988856 2013-09-19] (PC Drivers Headquarters)
HKU\S-1-5-21-3991109205-4196775496-539255635-1000\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3991109205-4196775496-539255635-1000\...\Run: [] - [X]
HKU\S-1-5-21-3991109205-4196775496-539255635-1000\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3991109205-4196775496-539255635-1000\...\MountPoints2: {d3397ce4-687c-11e3-a29e-00214fb4f5a3} - I:\Startme.exe
IFEO\Acrobat.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\acrodist.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\bttray.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\excel.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\msoxmled.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\mstore.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\neromediahome.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\offdiag.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\ois.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\onenote.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\photoshop elements 6.0.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\photoshopelementseditor.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\photoshopelementsorganizer.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\powerpnt.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\pptview.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\skype.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\windvd.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO\winword.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
Startup: C:\Users\NeroMediaHomeUser.4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Uninstall LastPass RunOnce.lnk
ShortcutTarget: Uninstall LastPass RunOnce.lnk -> C:\Users\NeroMediaHomeUser.4\AppData\Roaming\lpuninstall.exe (LastPass)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.sonystyle-europe.com?csint=140016340
hxxp://www.club-vaio.com/vbc/ebay/index.html
hxxp://www.club-vaio.com/vbc
URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {478479A2-3AD5-2CEE-60C1-4FD37C789637} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=
SearchScopes: HKCU - DefaultScope {478479A2-3AD5-2CEE-60C1-4FD37C789637} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=&rlz=1I7SNYK_de
SearchScopes: HKCU - {178BA626-A10F-4BC4-A2B6-4547C9E50DDF} URL =
SearchScopes: HKCU - {478479A2-3AD5-2CEE-60C1-4FD37C789637} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=&rlz=1I7SNYK_de
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll (Microsoft Corporation)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM - @C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR DefaultSearchKeyword: google.de_
CHR DefaultSearchURL: hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=&rlz=1I7SNYK_de
CHR DefaultNewTabURL:
CHR Extension: (Google Docs) - C:\Users\Ulrich\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-27]
CHR Extension: (Google Drive) - C:\Users\Ulrich\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-27]
CHR Extension: (YouTube) - C:\Users\Ulrich\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-27]
CHR Extension: (Google-Suche) - C:\Users\Ulrich\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-27]
CHR Extension: (SiteAdvisor) - C:\Users\Ulrich\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2014-01-27]
CHR Extension: (Google Wallet) - C:\Users\Ulrich\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-27]
CHR Extension: (Google Mail) - C:\Users\Ulrich\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-27]
CHR HKLM\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Ulrich\AppData\Local\foxtab_speeddial.crx [2014-01-29]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx [2013-05-01]
CHR HKCU\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Ulrich\AppData\Local\foxtab_speeddial.crx [2014-01-29]
========================== Services (Whitelisted) =================
R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S4 AdobeActiveFileMonitor6.0; c:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [124832 2007-09-11] ()
R2 HomeNetSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [145088 2013-11-28] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [471592 2013-08-02] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [643608 2013-11-26] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [169320 2013-11-04] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [172416 2013-11-04] (McAfee, Inc.)
S4 NeroMediaHomeService.4; C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe [517416 2010-10-26] (Nero AG)
S4 NSUService; C:\Program Files\sony\Network Utility\NSUService.exe [303104 2008-11-22] (Sony Corporation)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
S4 SPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [77824 2008-05-20] (Sony Corporation)
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe [1742136 2013-12-18] (TuneUp Software)
S4 VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [73728 2008-09-08] (Sony Corporation)
S4 VAIO Event Service; C:\Program Files\sony\VAIO Event Service\VESMgr.exe [203616 2008-10-17] (Sony Corporation)
S4 VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [415584 2008-10-17] (Sony Corporation)
S4 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [369952 2008-10-01] (Sony Corporation)
S4 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [279848 2008-09-08] (Sony Corporation)
S4 VzCdbSvc; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2008-09-08] (Sony Corporation)
==================== Drivers (Whitelisted) ====================
R3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [60920 2013-11-04] (McAfee, Inc.)
S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [13904 2011-05-06] ()
R3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [147912 2013-09-23] (McAfee, Inc.)
R3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [28312 2013-05-23] (Logitech, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R2 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [133992 2013-11-04] (McAfee, Inc.)
R2 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [236000 2013-11-04] (McAfee, Inc.)
S3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [65928 2013-11-04] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [365416 2013-11-04] (McAfee, Inc.)
R2 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [572528 2013-11-04] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [319808 2013-11-26] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [80752 2013-11-26] (McAfee, Inc.)
R2 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [213392 2013-11-04] (McAfee, Inc.)
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesDriver32.sys [12320 2013-09-18] (TuneUp Software)
S3 wmvad_simple; C:\Windows\System32\drivers\wmvad.sys [17408 2010-12-10] (WonderMedia Technologies, Inc.)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 MHIKEY10; System32\Drivers\MHIKEY10.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-08 18:16 - 2014-02-08 18:16 - 00000000 ____D () C:\Users\Ulrich\Downloads\FRST-OlderVersion
2014-02-08 15:25 - 2014-02-08 15:25 - 00987425 _____ () C:\Users\Ulrich\Downloads\SecurityCheck.exe
2014-02-07 17:36 - 2014-02-07 17:53 - 296325680 _____ () C:\Users\Ulrich\Documents\Das größte Musikfestival Schottlands Edinburgh Military Tattoo 2010.flv
2014-02-07 16:14 - 2014-02-07 16:16 - 35581428 _____ () C:\Users\Ulrich\Documents\Highland Cathedral live @ Flensburg (Musikschau Schottland).flv
2014-02-07 16:07 - 2014-02-07 16:52 - 28644376 _____ () C:\Users\Ulrich\Documents\Highland Cathedral Musikschau der Nationen 2008 Das perfekte Finale.flv
2014-02-07 15:59 - 2014-02-07 16:00 - 06897166 _____ () C:\Users\Ulrich\Documents\Amazing Grace @ Basel Tattoo 2009.flv
2014-02-07 15:53 - 2014-02-07 15:55 - 27163102 _____ () C:\Users\Ulrich\Documents\Massed Pipes and Drums am Berlin Tattoo 2011 in der O2 World.flv
2014-02-07 15:51 - 2014-02-07 15:52 - 19650071 _____ () C:\Users\Ulrich\Documents\Arrival [HD].flv
2014-02-07 12:03 - 2014-02-07 12:03 - 00001850 _____ () C:\Users\Ulrich\Downloads\JRT.txt
2014-02-07 11:58 - 2014-02-07 11:58 - 00000000 ____D () C:\Windows\ERUNT
2014-02-07 11:55 - 2014-02-07 11:56 - 01037530 _____ (Thisisu) C:\Users\Ulrich\Downloads\JRT.exe
2014-02-07 10:24 - 2014-02-07 10:24 - 01166132 _____ () C:\Users\Ulrich\Downloads\adwcleaner.exe
2014-02-07 09:36 - 2014-02-07 09:36 - 00000912 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-07 09:36 - 2014-02-07 09:36 - 00000000 ____D () C:\Users\Ulrich\AppData\Roaming\Malwarebytes
2014-02-07 09:36 - 2014-02-07 09:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-07 09:36 - 2014-02-07 09:36 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-02-07 09:36 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-07 09:34 - 2014-02-07 09:34 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ulrich\Downloads\mbam-setup-1.75.0.1300.exe
2014-02-07 09:16 - 2014-02-07 09:31 - 00000000 ____D () C:\Users\Ulrich\AppData\Roaming\Nico Mak Computing
2014-01-29 12:06 - 2014-01-29 12:07 - 00032896 _____ () C:\Users\Ulrich\Downloads\Addition.txt
2014-01-29 12:05 - 2014-02-08 18:16 - 00018645 _____ () C:\Users\Ulrich\Downloads\FRST.txt
2014-01-29 12:05 - 2014-02-08 18:16 - 00000000 ____D () C:\FRST
2014-01-29 09:52 - 2014-02-08 18:16 - 01136640 _____ (Farbar) C:\Users\Ulrich\Downloads\FRST.exe
2014-01-29 09:36 - 2014-02-05 08:46 - 00000204 _____ () C:\Users\Ulrich\AppData\Roaming\WB.CFG
2014-01-29 09:36 - 2014-02-01 10:28 - 00000005 _____ () C:\Users\Ulrich\AppData\Roaming\WBPU-TTL.DAT
2014-01-29 09:36 - 2014-01-29 09:36 - 00000000 ____D () C:\Users\Ulrich\AppData\Roaming\0D0S1L2Z1P1B
2014-01-29 09:35 - 2014-02-08 17:46 - 00000292 _____ () C:\Windows\Tasks\FoxTab.job
2014-01-29 09:35 - 2014-02-07 09:51 - 00000000 ____D () C:\Users\Ulrich\AppData\Roaming\DigitalSites
2014-01-29 09:35 - 2014-01-29 09:35 - 00369548 _____ () C:\Users\Ulrich\AppData\Local\foxtab_speeddial.crx
2014-01-29 09:35 - 2014-01-29 09:35 - 00000000 ____D () C:\Users\Ulrich\AppData\Roaming\FoxTab
2014-01-29 09:35 - 2014-01-29 09:35 - 00000000 ____D () C:\Program Files\Foxtab
2014-01-27 16:17 - 2014-01-27 16:20 - 00003304 _____ () C:\Windows\ie8_main.log
2014-01-27 09:04 - 2014-02-04 16:52 - 00001969 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-26 13:37 - 2014-01-26 13:37 - 10934856 _____ (LastPass) C:\Users\NeroMediaHomeUser.4\AppData\Roaming\lpuninstall.exe
2014-01-26 13:27 - 2014-02-07 09:56 - 00000000 ____D () C:\ProgramData\WPM
2014-01-24 15:55 - 2013-09-23 13:48 - 00147912 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
2014-01-17 11:55 - 2014-01-17 11:55 - 00001898 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-01-12 13:30 - 2014-01-12 13:30 - 00000000 ____D () C:\Users\Ulrich\Documents\Sony
==================== One Month Modified Files and Folders =======
2014-02-08 18:16 - 2014-02-08 18:16 - 00000000 ____D () C:\Users\Ulrich\Downloads\FRST-OlderVersion
2014-02-08 18:16 - 2014-01-29 12:05 - 00018645 _____ () C:\Users\Ulrich\Downloads\FRST.txt
2014-02-08 18:16 - 2014-01-29 12:05 - 00000000 ____D () C:\FRST
2014-02-08 18:16 - 2014-01-29 09:52 - 01136640 _____ (Farbar) C:\Users\Ulrich\Downloads\FRST.exe
2014-02-08 18:15 - 2012-12-18 11:52 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-08 17:53 - 2012-11-23 12:58 - 00000000 ____D () C:\Users\Ulrich\AppData\Roaming\vlc
2014-02-08 17:46 - 2014-01-29 09:35 - 00000292 _____ () C:\Windows\Tasks\FoxTab.job
2014-02-08 17:42 - 2012-11-13 16:45 - 01613085 _____ () C:\Windows\WindowsUpdate.log
2014-02-08 17:17 - 2013-03-10 13:04 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-08 16:52 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-08 16:52 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-08 15:25 - 2014-02-08 15:25 - 00987425 _____ () C:\Users\Ulrich\Downloads\SecurityCheck.exe
2014-02-08 14:58 - 2013-05-01 08:40 - 00001757 _____ () C:\Users\Public\Desktop\McAfee Internet Security.lnk
2014-02-08 12:53 - 2013-03-10 13:04 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-08 12:52 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-07 18:32 - 2008-11-03 19:36 - 00000012 _____ () C:\Windows\bthservsdp.dat
2014-02-07 18:32 - 2006-11-02 14:01 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-07 17:53 - 2014-02-07 17:36 - 296325680 _____ () C:\Users\Ulrich\Documents\Das größte Musikfestival Schottlands Edinburgh Military Tattoo 2010.flv
2014-02-07 16:52 - 2014-02-07 16:07 - 28644376 _____ () C:\Users\Ulrich\Documents\Highland Cathedral Musikschau der Nationen 2008 Das perfekte Finale.flv
2014-02-07 16:16 - 2014-02-07 16:14 - 35581428 _____ () C:\Users\Ulrich\Documents\Highland Cathedral live @ Flensburg (Musikschau Schottland).flv
2014-02-07 16:00 - 2014-02-07 15:59 - 06897166 _____ () C:\Users\Ulrich\Documents\Amazing Grace @ Basel Tattoo 2009.flv
2014-02-07 15:55 - 2014-02-07 15:53 - 27163102 _____ () C:\Users\Ulrich\Documents\Massed Pipes and Drums am Berlin Tattoo 2011 in der O2 World.flv
2014-02-07 15:52 - 2014-02-07 15:51 - 19650071 _____ () C:\Users\Ulrich\Documents\Arrival [HD].flv
2014-02-07 12:03 - 2014-02-07 12:03 - 00001850 _____ () C:\Users\Ulrich\Downloads\JRT.txt
2014-02-07 11:58 - 2014-02-07 11:58 - 00000000 ____D () C:\Windows\ERUNT
2014-02-07 11:56 - 2014-02-07 11:55 - 01037530 _____ (Thisisu) C:\Users\Ulrich\Downloads\JRT.exe
2014-02-07 10:30 - 2013-11-05 12:47 - 00000000 ____D () C:\AdwCleaner
2014-02-07 10:24 - 2014-02-07 10:24 - 01166132 _____ () C:\Users\Ulrich\Downloads\adwcleaner.exe
2014-02-07 09:57 - 2014-01-07 12:34 - 00038138 _____ () C:\Windows\PFRO.log
2014-02-07 09:56 - 2014-01-26 13:27 - 00000000 ____D () C:\ProgramData\WPM
2014-02-07 09:56 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\tracing
2014-02-07 09:51 - 2014-01-29 09:35 - 00000000 ____D () C:\Users\Ulrich\AppData\Roaming\DigitalSites
2014-02-07 09:36 - 2014-02-07 09:36 - 00000912 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-07 09:36 - 2014-02-07 09:36 - 00000000 ____D () C:\Users\Ulrich\AppData\Roaming\Malwarebytes
2014-02-07 09:36 - 2014-02-07 09:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-07 09:36 - 2014-02-07 09:36 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-02-07 09:34 - 2014-02-07 09:34 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ulrich\Downloads\mbam-setup-1.75.0.1300.exe
2014-02-07 09:31 - 2014-02-07 09:16 - 00000000 ____D () C:\Users\Ulrich\AppData\Roaming\Nico Mak Computing
2014-02-07 09:13 - 2008-01-21 08:16 - 01567416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-05 17:09 - 2012-11-26 13:24 - 00000000 ____D () C:\Users\Ulrich\AppData\Local\Microsoft Help
2014-02-05 13:47 - 2012-11-26 15:12 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-02-05 13:47 - 2012-11-26 15:12 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-02-05 08:46 - 2014-01-29 09:36 - 00000204 _____ () C:\Users\Ulrich\AppData\Roaming\WB.CFG
2014-02-04 16:52 - 2014-01-27 09:04 - 00001969 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-03 12:02 - 2012-11-13 17:31 - 00000000 ____D () C:\Users\Ulrich
2014-02-01 10:28 - 2014-01-29 09:36 - 00000005 _____ () C:\Users\Ulrich\AppData\Roaming\WBPU-TTL.DAT
2014-01-30 09:09 - 2013-12-29 15:51 - 00004776 _____ () C:\Windows\setupact.log
2014-01-29 12:07 - 2014-01-29 12:06 - 00032896 _____ () C:\Users\Ulrich\Downloads\Addition.txt
2014-01-29 09:36 - 2014-01-29 09:36 - 00000000 ____D () C:\Users\Ulrich\AppData\Roaming\0D0S1L2Z1P1B
2014-01-29 09:35 - 2014-01-29 09:35 - 00369548 _____ () C:\Users\Ulrich\AppData\Local\foxtab_speeddial.crx
2014-01-29 09:35 - 2014-01-29 09:35 - 00000000 ____D () C:\Users\Ulrich\AppData\Roaming\FoxTab
2014-01-29 09:35 - 2014-01-29 09:35 - 00000000 ____D () C:\Program Files\Foxtab
2014-01-28 08:49 - 2008-11-03 21:25 - 00000000 ____D () C:\Program Files\Google
2014-01-27 16:20 - 2014-01-27 16:17 - 00003304 _____ () C:\Windows\ie8_main.log
2014-01-27 10:25 - 2013-01-15 14:06 - 00000000 ____D () C:\ProgramData\DivX
2014-01-27 10:25 - 2012-11-13 16:53 - 00000000 ____D () C:\Program Files\DivX
2014-01-27 09:04 - 2012-11-13 17:31 - 00000000 ____D () C:\Users\Ulrich\AppData\Local\Google
2014-01-26 13:37 - 2014-01-26 13:37 - 10934856 _____ (LastPass) C:\Users\NeroMediaHomeUser.4\AppData\Roaming\lpuninstall.exe
2014-01-21 17:46 - 2013-10-25 17:20 - 00001799 _____ () C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2014-01-20 11:36 - 2012-11-13 17:31 - 00000000 ____D () C:\Users\Ulrich\AppData\Local\Adobe
2014-01-17 14:51 - 2013-11-10 11:34 - 00012037 _____ () C:\Users\Ulrich\Documents\TV-Programmbelegung.xlsx
2014-01-17 13:38 - 2008-11-03 21:23 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-01-17 11:55 - 2014-01-17 11:55 - 00001898 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-01-17 11:54 - 2008-11-03 21:23 - 00000000 ____D () C:\Program Files\Adobe
2014-01-15 14:58 - 2012-11-13 17:00 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-01-15 14:57 - 2013-08-15 16:21 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-15 14:51 - 2006-11-02 11:24 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-01-13 14:48 - 2012-11-14 11:48 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-01-12 17:04 - 2013-05-01 08:39 - 00000000 ____D () C:\Program Files\McAfee
2014-01-12 17:04 - 2012-11-13 16:55 - 00000000 ____D () C:\ProgramData\McAfee
2014-01-12 13:30 - 2014-01-12 13:30 - 00000000 ____D () C:\Users\Ulrich\Documents\Sony
2014-01-12 09:14 - 2012-11-14 11:26 - 00000000 ____D () C:\Program Files\Common Files\Mcafee
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-08 12:59
==================== End Of Log ============================ --- --- ---
--- --- --- |