ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=86e51a005a88184ea1dfffb5f60ed7ca
# engine=16796
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-01-25 05:35:13
# local_time=2014-01-25 06:35:13 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 95979 142301163 0 0
# scanned=240424
# found=1
# cleaned=0
# scan_time=21377
sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll.vir"
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=86e51a005a88184ea1dfffb5f60ed7ca
# engine=16940
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-04 10:32:51
# local_time=2014-02-04 11:32:51 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 15624 143183021 0 0
# scanned=67
# found=0
# cleaned=0
# scan_time=56
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=86e51a005a88184ea1dfffb5f60ed7ca
# engine=16946
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-05 08:20:20
# local_time=2014-02-05 09:20:20 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 97673 143261470 0 0
# scanned=239642
# found=0
# cleaned=0
# scan_time=29733
Results of screen317's Security Check version 0.99.79
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 51
Adobe Flash Player 12.0.0.43
Flash Player out of Date!
Mozilla Firefox (27.0)
Mozilla Thunderbird (17.0.8)
````````Process Check: objlist.exe by Laurent````````
TOSHIBA Toshiba Online Product Information TOPI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-02-2014
Ran by kindnata (administrator) on KINDNATA-TOSH on 06-02-2014 00:15:40
Running from C:\Users\kindnata\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\TOPI.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 2.4\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 2.4\program\soffice.bin
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(ArcSoft, Inc.) C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
() C:\Users\kindnata\Downloads\SecurityCheck.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Farbar) C:\Users\kindnata\Downloads\FRST64(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2009-08-03] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba TEMPRO] - C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1050000 2009-08-06] (Toshiba Europe GmbH)
HKLM\...\Run: [TosNC] - C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [596328 2009-08-06] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] - C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [35160 2009-08-06] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [497504 2009-08-05] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [909624 2009-08-05] (TOSHIBA Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7982112 2009-07-28] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [SmartFaceVWatcher] - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-07-29] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba Registration] - C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [134032 2009-07-30] (Toshiba Europe GmbH)
HKLM-x32\...\Run: [SVPWUTIL] - C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [352256 2009-08-12] (TOSHIBA)
HKLM-x32\...\Run: [HWSetup] - C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [423936 2009-06-02] (TOSHIBA Electronics, Inc.)
HKLM-x32\...\Run: [KeNotify] - C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34088 2009-01-13] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [TWebCamera] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2446648 2009-08-11] (TOSHIBA CORPORATION.)
HKLM-x32\...\Run: [ToshibaServiceStation] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1294136 2009-08-17] (TOSHIBA Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [309688 2012-10-11] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [160840 2012-05-07] (Geek Software GmbH)
HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [ArcSoft MediaImpression Monitor] - C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe [73728 2010-11-12] (ArcSoft, Inc.)
HKLM-x32\...\Run: [NPSStartup] - [X]
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKU\.DEFAULT\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe [6203296 2009-08-12] (TOSHIBA)
HKU\S-1-5-21-1766860481-2032816165-3171172483-1000\...\Run: [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe [6203296 2009-08-12] (TOSHIBA)
HKU\S-1-5-21-1766860481-2032816165-3171172483-1000\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [843208 2012-11-01] (Samsung)
HKU\S-1-5-21-1766860481-2032816165-3171172483-1000\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe [580096 2012-10-09] (Samsung Electronics)
HKU\S-1-5-21-1766860481-2032816165-3171172483-1000\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [966072 2012-10-11] (Samsung)
HKU\S-1-5-21-1766860481-2032816165-3171172483-1000\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [843208 2012-11-01] (Samsung)
HKU\S-1-5-21-1766860481-2032816165-3171172483-1000\...\MountPoints2: {531494ed-e571-11e1-ac79-705ab674edbf} - F:\MI.exe
HKU\S-1-5-21-1766860481-2032816165-3171172483-1000\...\MountPoints2: {d7cc15ce-cb87-11df-ae04-705ab674edbf} - F:\LaunchU3.exe -a
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\kindnata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DOGS CLOCK.lnk
ShortcutTarget: DOGS CLOCK.lnk -> C:\Program Files (x86)\DOGS CLOCK\DOGS CLOCK.exe (No File)
Startup: C:\Users\kindnata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\kindnata\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\kindnata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
ShortcutTarget: OpenOffice.org 2.4.lnk -> C:\Program Files (x86)\OpenOffice.org 2.4\program\quickstart.exe ()
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.msn.com/?ocid=U218DHP&pc=U218
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {19D6E013-942B-41F7-8F2B-917F5E9A1541} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2
SearchScopes: HKCU - {535AB885-C9DA-4920-B0E8-BB10F9CEFF1C} URL = hxxp://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms}
BHO: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: HKLM-x32 {888078C6-70B2-4F88-8EE7-1F50DDEA6120} https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\kindnata\AppData\Roaming\Mozilla\Firefox\Profiles\9bbok3an.default
FF NewTab: chrome://lightning/content/newtab.html
FF Homepage: hxxp://www.uni-freiburg.de/
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\kindnata\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np32dsw.dll (Macromedia, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF SearchPlugin: C:\Users\kindnata\AppData\Roaming\Mozilla\Firefox\Profiles\9bbok3an.default\searchplugins\amazon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-21]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2013-05-22]
FF HKLM-x32\...\Firefox\Extensions: [lightningnewtab@gmail.com] - C:\Users\kindnata\AppData\Roaming\Mozilla\Firefox\Profiles\9bbok3an.default\extensions\lightningnewtab@gmail.com.xpi
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ []
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchProvider: nationzoom
CHR DefaultSearchURL: hxxp://www.google.com
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx []
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17]
CHR HKLM-x32\...\Chrome\Extension: [piehhloihgjjiomhieeddiidpekaajio] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Chrome\ChromePicker.crx [2013-05-22]
CHR HKLM-x32\...\Chrome\Extension: [pkndmigholgfjlniaohblojbhgjbkakn] - C:\Users\kindnata\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx [2014-01-24]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 Radio.fx; C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe [3673944 2011-11-18] ()
R2 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [116104 2009-08-06] (Toshiba Europe GmbH)
==================== Drivers (Whitelisted) ====================
R2 acedrv09; C:\Windows\system32\drivers\acedrv09.sys [294720 2012-03-30] (Protect Software GmbH)
R2 acedrv10; C:\Windows\system32\drivers\acedrv10.sys [277904 2012-03-23] (Protect Software GmbH)
R2 acehlp09; C:\Windows\system32\drivers\acehlp09.sys [195248 2012-03-30] (Protect Software GmbH)
R2 acehlp10; C:\Windows\system32\drivers\acehlp10.sys [228000 2012-03-23] (Protect Software GmbH)
R1 cbfs3; C:\Windows\system32\drivers\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
R3 HPKBx64; C:\Windows\System32\DRIVERS\HPKBx64.sys [73600 2006-11-07] (Hewlett-Packard Company)
R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [446976 2009-08-20] (Realtek Semiconductor Corporation )
S3 ss_bserd; C:\Windows\System32\DRIVERS\ss_bserd.sys [128000 2009-09-19] (MCCI Corporation)
S3 AVFSFilter; system32\DRIVERS\avfsfilter.sys [X]
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]
S3 RTL8192cu; system32\DRIVERS\rtwlanu.sys [X]
S3 rtlss; System32\Drivers\rtlss.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-06 00:15 - 2014-02-06 00:15 - 02082304 _____ (Farbar) C:\Users\kindnata\Downloads\FRST64(1).exe
2014-02-06 00:10 - 2014-02-06 00:10 - 00987425 _____ () C:\Users\kindnata\Downloads\SecurityCheck.exe
2014-02-05 23:52 - 2014-02-05 23:52 - 00007888 _____ () C:\Windows\IE11_main.log
2014-02-05 23:52 - 2014-02-05 23:52 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-02-05 23:49 - 2014-02-05 23:49 - 65446536 _____ (Microsoft Corporation) C:\Users\kindnata\Downloads\EIE11_DE-DE_WOL_WIN764.EXE
2014-02-05 13:03 - 2014-02-05 13:03 - 02347384 _____ (ESET) C:\Users\kindnata\Downloads\esetsmartinstaller_enu.exe
2014-02-05 13:00 - 2014-02-05 13:00 - 00001158 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-02-05 13:00 - 2014-02-05 13:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-05 12:56 - 2014-02-05 12:56 - 00283120 _____ (Mozilla) C:\Users\kindnata\Downloads\Firefox Setup Stub 27.0.exe
2014-02-02 22:17 - 2014-02-06 00:15 - 00020986 _____ () C:\Users\kindnata\Downloads\FRST.txt
2014-02-02 22:17 - 2014-02-02 22:17 - 02080256 _____ (Farbar) C:\Users\kindnata\Downloads\FRST64.exe
2014-02-02 22:00 - 2014-02-02 22:01 - 01037068 _____ (Thisisu) C:\Users\kindnata\Downloads\JRT.exe
2014-02-01 18:13 - 2014-02-01 21:32 - 00000000 ____D () C:\AdwCleaner
2014-01-31 15:39 - 2014-02-06 00:15 - 00000000 ____D () C:\FRST
2014-01-26 10:43 - 2014-02-01 21:37 - 00000000 ____D () C:\Windows\ERUNT
2014-01-26 10:43 - 2014-01-26 10:45 - 00001915 _____ () C:\DelFix.txt
2014-01-26 10:37 - 2014-01-26 10:36 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-26 10:36 - 2014-01-26 10:36 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-26 10:36 - 2014-01-26 10:36 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-26 10:36 - 2014-01-26 10:36 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-25 12:35 - 2014-02-06 00:09 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-01-24 21:52 - 2014-02-04 23:24 - 00007820 _____ () C:\Windows\PFRO.log
2014-01-24 21:08 - 2014-01-24 21:08 - 00000000 ____D () C:\Users\kindnata\AppData\Roaming\Malwarebytes
2014-01-24 21:08 - 2014-01-24 21:08 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-01-24 16:28 - 2014-02-05 23:54 - 00002824 _____ () C:\Windows\setupact.log
2014-01-24 16:28 - 2014-01-24 16:28 - 00000000 _____ () C:\Windows\setuperr.log
2014-01-24 16:22 - 2014-02-05 23:58 - 00478299 _____ () C:\Windows\WindowsUpdate.log
2014-01-24 15:59 - 2014-01-24 15:59 - 00003098 _____ () C:\Windows\System32\Tasks\{BE72C562-6A22-43FE-883B-521A86C7CFB4}
2014-01-24 11:22 - 2014-01-24 11:22 - 00000000 ____D () C:\Windows\system32\log
2014-01-24 10:31 - 2014-01-24 10:31 - 00003874 _____ () C:\Windows\System32\Tasks\BrowserSafeguard Update Task
2014-01-24 10:30 - 2014-01-28 16:32 - 00000000 ____D () C:\ProgramData\IePluginService
2014-01-24 10:27 - 2014-01-24 10:27 - 00000120 ___RH () C:\Users\kindnata\Downloads\Stinger.opt
2014-01-24 10:20 - 2014-01-24 10:27 - 00000000 ____D () C:\Program Files (x86)\stinger
2014-01-24 08:24 - 2014-01-24 08:24 - 00001790 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-01-24 08:23 - 2014-01-24 08:24 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-24 08:23 - 2014-01-24 08:24 - 00000000 ____D () C:\Program Files\iTunes
2014-01-24 08:23 - 2014-01-24 08:24 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-01-24 08:23 - 2014-01-24 08:23 - 00000000 ____D () C:\Program Files\iPod
2014-01-16 12:44 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-16 12:44 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-16 12:44 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-16 12:44 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-16 12:44 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-16 12:44 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-16 12:44 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-16 12:44 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-16 12:44 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-08 08:24 - 2014-01-08 08:24 - 00000000 ____D () C:\Users\kindnata\Desktop\Fotos
==================== One Month Modified Files and Folders =======
2014-02-06 00:16 - 2014-02-02 22:17 - 00020986 _____ () C:\Users\kindnata\Downloads\FRST.txt
2014-02-06 00:15 - 2014-02-06 00:15 - 02082304 _____ (Farbar) C:\Users\kindnata\Downloads\FRST64(1).exe
2014-02-06 00:15 - 2014-01-31 15:39 - 00000000 ____D () C:\FRST
2014-02-06 00:10 - 2014-02-06 00:10 - 00987425 _____ () C:\Users\kindnata\Downloads\SecurityCheck.exe
2014-02-06 00:09 - 2014-01-25 12:35 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-02-06 00:02 - 2009-07-14 05:45 - 00016080 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-06 00:02 - 2009-07-14 05:45 - 00016080 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-05 23:58 - 2014-01-24 16:22 - 00478299 _____ () C:\Windows\WindowsUpdate.log
2014-02-05 23:56 - 2010-05-29 22:07 - 00000000 ____D () C:\Users\kindnata\AppData\Roaming\OpenOffice.org2
2014-02-05 23:54 - 2014-01-24 16:28 - 00002824 _____ () C:\Windows\setupact.log
2014-02-05 23:54 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-05 23:52 - 2014-02-05 23:52 - 00007888 _____ () C:\Windows\IE11_main.log
2014-02-05 23:52 - 2014-02-05 23:52 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-02-05 23:51 - 2012-03-29 18:58 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-05 23:49 - 2014-02-05 23:49 - 65446536 _____ (Microsoft Corporation) C:\Users\kindnata\Downloads\EIE11_DE-DE_WOL_WIN764.EXE
2014-02-05 20:55 - 2010-07-12 19:32 - 00003962 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{1D4BA49D-B8F1-406F-834C-4B4B946202B6}
2014-02-05 20:51 - 2012-03-29 18:58 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-05 20:51 - 2012-03-29 18:58 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-05 20:51 - 2011-10-17 13:18 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-05 13:03 - 2014-02-05 13:03 - 02347384 _____ (ESET) C:\Users\kindnata\Downloads\esetsmartinstaller_enu.exe
2014-02-05 13:00 - 2014-02-05 13:00 - 00001158 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-02-05 13:00 - 2014-02-05 13:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-05 13:00 - 2013-12-21 10:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-05 12:56 - 2014-02-05 12:56 - 00283120 _____ (Mozilla) C:\Users\kindnata\Downloads\Firefox Setup Stub 27.0.exe
2014-02-04 23:24 - 2014-01-24 21:52 - 00007820 _____ () C:\Windows\PFRO.log
2014-02-04 23:24 - 2009-09-08 09:11 - 00000000 ____D () C:\Program Files\Google
2014-02-04 23:24 - 2009-09-08 09:11 - 00000000 ____D () C:\Program Files (x86)\Google
2014-02-04 23:19 - 2009-07-14 18:58 - 00699682 _____ () C:\Windows\system32\perfh007.dat
2014-02-04 23:19 - 2009-07-14 18:58 - 00149790 _____ () C:\Windows\system32\perfc007.dat
2014-02-04 23:19 - 2009-07-14 06:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-04 20:05 - 2010-05-29 17:28 - 00000000 ____D () C:\Users\kindnata\AppData\Local\Google
2014-02-04 20:05 - 2009-09-08 09:11 - 00000000 ____D () C:\ProgramData\Google
2014-02-03 19:31 - 2010-05-30 12:10 - 00000000 ____D () C:\Users\kindnata\AppData\Roaming\Skype
2014-02-02 22:17 - 2014-02-02 22:17 - 02080256 _____ (Farbar) C:\Users\kindnata\Downloads\FRST64.exe
2014-02-02 22:01 - 2014-02-02 22:00 - 01037068 _____ (Thisisu) C:\Users\kindnata\Downloads\JRT.exe
2014-02-02 20:16 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-02-02 09:57 - 2013-11-17 10:50 - 00001543 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2014-02-02 09:57 - 2013-11-17 10:50 - 00001250 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2014-02-02 09:57 - 2013-11-17 10:50 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-02-02 09:56 - 2013-03-02 10:33 - 00000000 ____D () C:\Users\kindnata\AppData\Roaming\DVDVideoSoft
2014-02-01 21:37 - 2014-01-26 10:43 - 00000000 ____D () C:\Windows\ERUNT
2014-02-01 21:32 - 2014-02-01 18:13 - 00000000 ____D () C:\AdwCleaner
2014-01-28 16:32 - 2014-01-24 10:30 - 00000000 ____D () C:\ProgramData\IePluginService
2014-01-26 10:45 - 2014-01-26 10:43 - 00001915 _____ () C:\DelFix.txt
2014-01-26 10:37 - 2013-11-17 11:25 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-26 10:36 - 2014-01-26 10:37 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-26 10:36 - 2014-01-26 10:36 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-26 10:36 - 2014-01-26 10:36 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-26 10:36 - 2014-01-26 10:36 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-24 21:08 - 2014-01-24 21:08 - 00000000 ____D () C:\Users\kindnata\AppData\Roaming\Malwarebytes
2014-01-24 21:08 - 2014-01-24 21:08 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-01-24 16:28 - 2014-01-24 16:28 - 00000000 _____ () C:\Windows\setuperr.log
2014-01-24 16:26 - 2010-05-29 17:05 - 00000000 ____D () C:\Users\kindnata
2014-01-24 16:18 - 2009-09-08 08:58 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-01-24 16:10 - 2012-03-23 20:18 - 00000000 ____D () C:\Users\kindnata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tivola
2014-01-24 16:10 - 2012-03-23 20:11 - 00000000 ____D () C:\Tivola
2014-01-24 16:08 - 2011-12-28 11:04 - 00000444 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-01-24 15:59 - 2014-01-24 15:59 - 00003098 _____ () C:\Windows\System32\Tasks\{BE72C562-6A22-43FE-883B-521A86C7CFB4}
2014-01-24 14:28 - 2009-09-08 09:02 - 00000000 ____D () C:\Program Files (x86)\Java
2014-01-24 11:37 - 2013-05-18 15:59 - 00000000 ____D () C:\Program Files (x86)\FLVPlayer
2014-01-24 11:36 - 2013-05-18 15:59 - 00000000 ____D () C:\Users\kindnata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player
2014-01-24 11:23 - 2010-05-29 17:05 - 00000000 ___RD () C:\Users\kindnata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-24 11:22 - 2014-01-24 11:22 - 00000000 ____D () C:\Windows\system32\log
2014-01-24 10:31 - 2014-01-24 10:31 - 00003874 _____ () C:\Windows\System32\Tasks\BrowserSafeguard Update Task
2014-01-24 10:31 - 2009-09-08 08:34 - 00000000 ____D () C:\Windows\Panther
2014-01-24 10:27 - 2014-01-24 10:27 - 00000120 ___RH () C:\Users\kindnata\Downloads\Stinger.opt
2014-01-24 10:27 - 2014-01-24 10:20 - 00000000 ____D () C:\Program Files (x86)\stinger
2014-01-24 09:45 - 2013-11-24 19:50 - 00000000 ____D () C:\Users\kindnata\AppData\Roaming\Apple Computer
2014-01-24 09:06 - 2013-11-24 19:48 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-01-24 08:24 - 2014-01-24 08:24 - 00001790 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-01-24 08:24 - 2014-01-24 08:23 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-24 08:24 - 2014-01-24 08:23 - 00000000 ____D () C:\Program Files\iTunes
2014-01-24 08:24 - 2014-01-24 08:23 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-01-24 08:23 - 2014-01-24 08:23 - 00000000 ____D () C:\Program Files\iPod
2014-01-24 08:20 - 2013-11-24 19:47 - 00000000 ____D () C:\ProgramData\Apple
2014-01-17 08:04 - 2010-05-30 09:11 - 00000000 ____D () C:\Users\kindnata\AppData\Local\Adobe
2014-01-17 07:46 - 2009-07-14 05:45 - 00459208 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-01-16 20:58 - 2009-09-08 09:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-01-16 20:57 - 2013-08-04 10:20 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-16 20:53 - 2010-06-15 14:03 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-08 08:24 - 2014-01-08 08:24 - 00000000 ____D () C:\Users\kindnata\Desktop\Fotos
Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.5400.dll
Some content of TEMP:
====================
C:\Users\kindnata\AppData\Local\Temp\Foxit Updater.exe
C:\Users\kindnata\AppData\Local\Temp\lhjrwwfz.dll
C:\Users\kindnata\AppData\Local\Temp\Quarantine.exe
C:\Users\kindnata\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\kindnata\AppData\Local\Temp\System.Data.SQLite19272.dll
C:\Users\kindnata\AppData\Local\Temp\System.Data.SQLite24919.dll
C:\Users\kindnata\AppData\Local\Temp\System.Data.SQLite30984.dll
C:\Users\kindnata\AppData\Local\Temp\System.Data.SQLite32514.dll
C:\Users\kindnata\AppData\Local\Temp\System.Data.SQLite59160.dll
C:\Users\kindnata\AppData\Local\Temp\trjdnilq.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-06 18:26
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
Hallo, leider besteht das Problem immer noch. Im Firefox erscheint im Tab "chrome://lightning/content/newtab.html" und dazu ein leeres Fenster!!!!
Es ist zum heulen!!!!
Gruss
kindnata