Hallo,
hier die Daten der Scans Code:
# AdwCleaner v3.205 - Bericht erstellt am 29/04/2014 um 16:47:30
# Aktualisiert 28/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Homebase - HOMEBASE-PC
# Gestartet von : C:\Users\Homebase\Desktop\adwcleaner.exe
# Option : Suchen
***** [ Dienste ] *****
Dienst Gefunden : APNMCP
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\Homebase\AppData\Local\Temp\Uninstall.exe
Datei Gefunden : C:\Users\Public\Desktop\eBay.lnk
Ordner Gefunden : C:\Program Files (x86)\AskPartnerNetwork
Ordner Gefunden : C:\Users\Homebase\AppData\Local\Temp\apn
Ordner Gefunden : C:\Users\Homebase\AppData\Local\Temp\OCS
Ordner Gefunden : C:\Windows\SysWOW64\AI_RecycleBin
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\APN PIP
Schlüssel Gefunden : HKCU\Software\AskPartnerNetwork
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : [x64] HKCU\Software\APN PIP
Schlüssel Gefunden : [x64] HKCU\Software\AskPartnerNetwork
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : [x64] HKCU\Software\OCS
Schlüssel Gefunden : HKLM\Software\AskPartnerNetwork
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gefunden : HKLM\Software\PIP
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v
[ Datei : C:\Users\Homebase\AppData\Roaming\Mozilla\Firefox\Profiles\2aa1726f.default\prefs.js ]
-\\ Google Chrome v34.0.1847.116
[ Datei : C:\Users\Homebase\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gefunden [Search Provider] : hxxp://www.search.ask.com/web?tpid=ORJ-V7C&o=APN11412&pf=V7&p2=%5EBBK%5EOSJ000%5EYY%5EDE&gct=&itbv=12.7.0.15&doi=2014-01-15&apn_uid=34637084-F1CB-44C5-811C-221A7BF2D867&apn_ptnrs=BBK&apn_dtid=%5EOSJ000%5EYY%5EDE&apn_dbr=cr_31.0.1650.63&psv=&trgb=CR&tbv=&crxv=&q={searchTerms}
Gefunden [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof
*************************
AdwCleaner[R0].txt - [3015 octets] - [29/04/2014 16:47:30]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3075 octets] ########## Code:
# AdwCleaner v3.205 - Bericht erstellt am 29/04/2014 um 16:51:28
# Aktualisiert 28/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Homebase - HOMEBASE-PC
# Gestartet von : C:\Users\Homebase\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : APNMCP
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\AskPartnerNetwork
Ordner Gelöscht : C:\Windows\SysWOW64\AI_RecycleBin
Ordner Gelöscht : C:\Users\Homebase\AppData\Local\Temp\apn
Ordner Gelöscht : C:\Users\Homebase\AppData\Local\Temp\OCS
Datei Gelöscht : C:\Users\Homebase\AppData\Local\Temp\Uninstall.exe
Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\AskPartnerNetwork
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\Software\AskPartnerNetwork
Schlüssel Gelöscht : HKLM\Software\PIP
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v
[ Datei : C:\Users\Homebase\AppData\Roaming\Mozilla\Firefox\Profiles\2aa1726f.default\prefs.js ]
-\\ Google Chrome v34.0.1847.116
[ Datei : C:\Users\Homebase\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://www.search.ask.com/web?tpid=ORJ-V7C&o=APN11412&pf=V7&p2=%5EBBK%5EOSJ000%5EYY%5EDE&gct=&itbv=12.7.0.15&doi=2014-01-15&apn_uid=34637084-F1CB-44C5-811C-221A7BF2D867&apn_ptnrs=BBK&apn_dtid=%5EOSJ000%5EYY%5EDE&apn_dbr=cr_31.0.1650.63&psv=&trgb=CR&tbv=&crxv=&q={searchTerms}
Gelöscht [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof
*************************
AdwCleaner[R0].txt - [3179 octets] - [29/04/2014 16:47:30]
AdwCleaner[S0].txt - [2814 octets] - [29/04/2014 16:51:28]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2874 octets] ########## Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.04.2014
Suchlauf-Zeit: 17:42:39
Logdatei: Malware.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.29.04
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Homebase
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 261264
Verstrichene Zeit: 38 Min, 22 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 0
(No malicious items detected)
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
Zoek.exe v5.0.0.0 Updated 14-April-2014
Tool run by Homebase on 29.04.2014 at 17:49:28,62.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Homebase\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
29.04.2014 17:52:53 Zoek.exe System Restore Point Created Succesfully.
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Homebase\AppData\Roaming\Mozilla\Firefox\Profiles\2aa1726f.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.t-online.de/");
Added to C:\Users\Homebase\AppData\Roaming\Mozilla\Firefox\Profiles\2aa1726f.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Homebase\AppData\Roaming\Thunderbird\Profiles\oavy8tpn.default\prefs.js:
Added to C:\Users\Homebase\AppData\Roaming\Thunderbird\Profiles\oavy8tpn.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
==== Deleting Files \ Folders ======================
C:\PROGRA~3\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} deleted
C:\PROGRA~3\eSellerate deleted
C:\PROGRA~3\AskPartnerNetwork deleted
C:\PROGRA~3\APN deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG SafeGuard toolbar deleted
==== Firefox Extensions ======================
ProfilePath: C:\Users\Homebase\AppData\Roaming\Thunderbird\Profiles\oavy8tpn.default
- Wrterbuch Deutsch de-DE Hunspell-untersttzt - %ProfilePath%\extensions\de_DE@dicts.j3e.de
==== Firefox Plugins ======================
Profilepath: C:\Users\Homebase\AppData\Roaming\Mozilla\Firefox\Profiles\2aa1726f.default
D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17
626791785FF2A338575E8AF0563D8333 - C:\Windows\npMSDM.dll - Microsoft Download Manager Plugin
15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
pljcgbedjplidkdjahbaalanadmjfgop - C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-V7C\CRX\ToolbarCR.crx[]
Bubble Santa - Homebase\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbokbbbgkgifjmmbokbdiimcffphbgha
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://mysearch.avg.com?cid={E986FF59-008C-4CF5-A930-A8636F7EF3C6}&mid=d7fceee7cbdf47d384b2d16809195146-5f53863a53511d47fe9a66a7463bd4aaca807f23&lang=de&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-04-20 19:47:00&v=18.0.5.292&pid=safeguard&sg=&sap=hp"
"Default_Page_URL"="hxxp://www.google.com/ig/redirectdomain?brand=SNYT&bmod=EU01"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="hxxp://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
{AFB4D376-D858-409B-A6E3-9B9D65BDDFF2} Unknown Url="Not_Found"
{D6A57B83-A815-4DC9-8803-CFF052CC82CF} Google Url="hxxp://www.google.de/search?hl=de&q={searchTerms}&meta"
==== Reset Google Chrome ======================
C:\Users\Homebase\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Homebase\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-86059236-1335926366-3320298591-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFB4D376-D858-409B-A6E3-9B9D65BDDFF2} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pljcgbedjplidkdjahbaalanadmjfgop deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Homebase\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Homebase\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Homebase\AppData\Local\Mozilla\Firefox\Profiles\2aa1726f.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Homebase\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache is not empty, a reboot is needed
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=26 folders=13 1404211 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Homebase\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Homebase\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found
"C:\Users\Homebase\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DRK9HRCT\cdn.zopim.com" not found
==== EOF on 29.04.2014 at 18:17:05,49 ======================
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-04-2014
Ran by Homebase (administrator) on HOMEBASE-PC on 29-04-2014 18:26:13
Running from C:\Users\Homebase\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Adobe Systems Incorporated) c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(InterVideo) c:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Sony Corporation) C:\Program Files\sony\Network Utility\NSUService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft) C:\Program Files (x86)\SMA\Sunny Explorer\SMA.Multicasting.IGMP.QuerierService.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GdBgInx64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GDKBFltExe32.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio64.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Sony Corporation) C:\Program Files\sony\Network Utility\LANUtil.exe
(Advanced Micro Devices Inc.) c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apntex.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files (x86)\SystemTuner 2012\BoostService.exe
(mobile concepts) C:\Program Files (x86)\SystemTuner 2012\smartsvc.exe
(mobile concepts GmbH) C:\Program Files (x86)\SystemTuner 2012\STDefragService.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [152576 2008-07-18] (Alps Electric Co., Ltd.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [6956576 2009-01-06] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-01-06] (Realtek Semiconductor Corp.)
HKLM-x32\...\Run: [AML] => C:\Program Files (x86)\Sony\VAIO Launcher\AML.exe [1101824 2009-03-09] (Sony)
HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2009-03-02] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [1724728 2013-12-19] (G Data Software AG)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\program files (x86)\g data\internetsecurity\avkkid\avkcks.exe,C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe
Winlogon\Notify\VESWinlogon-x32: VESWinlogon.dll [X]
HKU\S-1-5-21-86059236-1335926366-3320298591-1000\...\Run: [NSUFloatingUI] => C:\Program Files\Sony\Network Utility\LANUtil.exe [334848 2008-12-21] (Sony Corporation)
==================== Internet (Whitelisted) ====================
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
SearchScopes: HKLM - DefaultScope {AFB4D376-D858-409B-A6E3-9B9D65BDDFF2} URL =
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SNYT
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - {D6A57B83-A815-4DC9-8803-CFF052CC82CF} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll ()
BHO-x32: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
BHO-x32: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll ()
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: HKLM-x32 {B479199A-1242-4E3C-AD81-7F0DF801B4AE} hxxp://download.microsoft.com/download/C/9/C/C9C3D86D-84AC-4AF0-8584-842756A66467/MicrosoftDownloadManager.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Homebase\AppData\Roaming\Mozilla\Firefox\Profiles\2aa1726f.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @videolan.org/vlc,version=2.1.0-pre1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/DownloadManager,version=1.1 - C:\Windows\ ()
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\Homebase\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-22]
CHR Extension: (Google Drive) - C:\Users\Homebase\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-22]
CHR Extension: (YouTube) - C:\Users\Homebase\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-22]
CHR Extension: (Google-Suche) - C:\Users\Homebase\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-22]
CHR Extension: (Google Wallet) - C:\Users\Homebase\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-22]
CHR Extension: (Google Mail) - C:\Users\Homebase\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-22]
==================== Services (Whitelisted) =================
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2008-08-01] (ArcSoft Inc.)
R2 AppBoosterService; C:\Program Files (x86)\SystemTuner 2012\BoostService.exe [1552000 2011-09-20] ()
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2244728 2014-02-12] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe [2723400 2014-03-25] (G Data Software AG)
R3 GDFwSvc; C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [2992760 2014-01-30] (G Data Software AG)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700024 2014-02-03] (G Data Software AG)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 NSUService; C:\Program Files\sony\Network Utility\NSUService.exe [361472 2008-12-21] (Sony Corporation)
S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [114688 2009-01-08] (Sony Corporation)
R2 SMA.Multicasting.IGMP.QuerierService.exe; C:\Program Files (x86)\SMA\Sunny Explorer\SMA.Multicasting.IGMP.QuerierService.exe [21152 2014-03-18] (Microsoft)
R2 SmartSvcWMP; C:\Program Files (x86)\SystemTuner 2012\smartsvc.exe [3975808 2011-09-20] (mobile concepts)
S3 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-02-05] (Sony Corporation)
S3 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-02-05] (Sony Corporation)
R2 SysTunerDSrvc; C:\Program Files (x86)\SystemTuner 2012\STDefragService.exe [3995776 2011-09-20] (mobile concepts GmbH)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-01-21] (Sony Corporation)
R2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [5184872 2009-01-14] (Sony Corporation)
R3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-01-21] (Sony Corporation)
R2 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-01-21] (Sony Corporation)
==================== Drivers (Whitelisted) ====================
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2008-04-24] (ArcSoft, Inc.)
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [57344 2014-04-28] (G Data Software AG)
R3 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [22016 2014-04-28] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [135168 2014-04-28] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [68608 2014-04-28] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64000 2014-04-28] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [107128 2014-04-26] (G Data Software)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [65024 2014-04-28] (G Data Software AG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-29] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R2 risdptsk; C:\Windows\System32\DRIVERS\risdsn64.sys [76288 2008-10-23] (REDC)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-29 18:26 - 2014-04-29 18:26 - 00015176 _____ () C:\Users\Homebase\Desktop\FRST.txt
2014-04-29 18:24 - 2014-04-29 18:24 - 00008433 _____ () C:\Users\Homebase\Desktop\zoek-results.txt
2014-04-29 18:11 - 2014-04-29 17:49 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-04-29 17:51 - 2014-04-29 18:17 - 00008433 _____ () C:\zoek-results.log
2014-04-29 17:49 - 2014-04-29 18:05 - 00000000 ____D () C:\zoek_backup
2014-04-29 17:48 - 2014-04-29 17:48 - 01285120 _____ () C:\Users\Homebase\Desktop\zoek.exe
2014-04-29 17:47 - 2014-04-29 17:47 - 00001153 _____ () C:\Users\Homebase\Desktop\Malware.txt
2014-04-29 17:00 - 2014-04-29 17:00 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-29 17:00 - 2014-04-29 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-29 17:00 - 2014-04-29 17:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-29 17:00 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-29 17:00 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-29 17:00 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-29 16:57 - 2014-04-29 16:57 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Homebase\Downloads\mbam-setup-2.0.1.1004 (3).exe
2014-04-29 16:48 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-04-29 16:47 - 2014-04-29 16:51 - 00000000 ____D () C:\AdwCleaner
2014-04-29 16:45 - 2014-04-29 16:45 - 01310621 _____ () C:\Users\Homebase\Desktop\adwcleaner.exe
2014-04-28 19:26 - 2014-04-28 19:26 - 02061824 _____ (Farbar) C:\Users\Homebase\Desktop\FRST64.exe
2014-04-28 19:14 - 2014-04-29 18:26 - 00000000 ____D () C:\FRST
2014-04-28 17:55 - 2014-04-28 17:55 - 00022016 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDKBFlt64.sys
2014-04-28 17:55 - 2014-04-28 17:55 - 00001978 _____ () C:\Users\Public\Desktop\G Data InternetSecurity.lnk
2014-04-28 17:55 - 2014-04-28 17:55 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_GDKBFlt64_01007.Wdf
2014-04-28 17:55 - 2014-04-28 17:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G Data InternetSecurity
2014-04-28 17:41 - 2014-04-28 17:41 - 00015666 _____ () C:\Users\Homebase\Documents\G Data Protokoll ID 2.html
2014-04-26 22:01 - 2014-04-26 22:01 - 00000000 ____D () C:\Users\Homebase\AppData\Roaming\WMPBooster
2014-04-26 21:59 - 2014-04-26 21:59 - 00107128 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2014-04-26 21:59 - 2014-04-26 21:59 - 00016944 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys
2014-04-26 21:57 - 2014-04-26 21:57 - 00001098 _____ () C:\Users\Public\Desktop\SystemTuner 2012.lnk
2014-04-26 21:57 - 2014-04-26 21:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SystemTuner 2012
2014-04-26 21:57 - 2014-04-26 21:57 - 00000000 ____D () C:\Program Files (x86)\SystemTuner 2012
2014-04-26 21:35 - 2014-04-28 17:55 - 00135168 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2014-04-26 21:35 - 2014-04-28 17:55 - 00068608 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys
2014-04-26 21:35 - 2014-04-28 17:55 - 00065024 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys
2014-04-26 21:35 - 2014-04-28 17:55 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys
2014-04-26 21:35 - 2014-04-28 17:55 - 00057344 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2014-04-26 21:30 - 2014-04-26 21:30 - 00000000 ____D () C:\Program Files (x86)\G Data
2014-04-26 21:12 - 2014-04-28 17:53 - 00000000 ____D () C:\ProgramData\G Data
2014-04-24 18:59 - 2014-04-24 19:00 - 25090430 _____ () C:\Users\Homebase\Downloads\SMA-Connection-Assist-1.0.11.R.exe
2014-04-24 15:32 - 2014-04-24 15:33 - 100285208 _____ (Microsoft Corporation) C:\Users\Homebase\Downloads\msert.exe
2014-04-23 14:48 - 2014-04-29 18:16 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-23 14:47 - 2014-04-23 14:47 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-23 14:46 - 2014-04-23 14:46 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Homebase\Downloads\mbam-setup-2.0.1.1004 (2).exe
2014-04-23 14:45 - 2014-04-23 14:46 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Homebase\Downloads\mbam-setup-2.0.1.1004 (1).exe
2014-04-23 14:44 - 2014-04-23 14:45 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Homebase\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-22 15:14 - 2014-04-22 15:14 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-04-22 15:14 - 2014-04-22 15:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-04-22 15:13 - 2014-04-22 15:14 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-04-22 15:13 - 2014-04-22 15:14 - 00000000 ____D () C:\Program Files\iTunes
2014-04-22 15:13 - 2014-04-22 15:14 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-04-22 15:13 - 2014-04-22 15:13 - 00000000 ____D () C:\Program Files\iPod
2014-04-22 14:55 - 2014-04-22 14:55 - 01071360 _____ (Solid State Networks) C:\Users\Homebase\Downloads\install_flashplayer13x32axau_mssa_aaa_aih.exe
2014-04-22 13:38 - 2014-04-22 13:38 - 00000000 __SHD () C:\Users\Homebase\AppData\Local\EmieUserList
2014-04-22 13:38 - 2014-04-22 13:38 - 00000000 __SHD () C:\Users\Homebase\AppData\Local\EmieSiteList
2014-04-20 20:11 - 2014-04-20 20:12 - 00000000 ____D () C:\Users\Homebase\Downloads\avg_remover4116
2014-04-20 20:10 - 2014-04-20 20:11 - 03453210 _____ () C:\Users\Homebase\Downloads\avg_remover4116.zip
2014-04-20 19:49 - 2014-04-20 19:49 - 00000000 ____D () C:\Users\Homebase\AppData\Local\Geckofx
2014-04-20 19:46 - 2014-04-20 19:46 - 00000000 ____D () C:\Users\Homebase\Documents\SMA
2014-04-20 19:44 - 2014-04-20 19:44 - 00000000 ____D () C:\Users\Homebase\AppData\Roaming\SMA
2014-04-20 19:39 - 2014-04-20 19:39 - 00001094 _____ () C:\Users\Public\Desktop\Sunny Explorer.lnk
2014-04-20 19:39 - 2014-04-20 19:39 - 00000000 ____D () C:\ProgramData\SMA
2014-04-20 19:39 - 2014-04-20 19:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMA
2014-04-20 19:39 - 2014-04-20 19:39 - 00000000 ____D () C:\Program Files (x86)\SMA
2014-04-20 19:35 - 2014-04-20 19:37 - 80650912 _____ (SMA Solar Technology AG) C:\Users\Homebase\Downloads\SunnyExplorerSetup10711R.exe
2014-04-20 14:18 - 2014-04-20 14:36 - 00000375 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-04-19 15:55 - 2014-04-19 15:55 - 04435328 _____ (AVG Technologies) C:\Users\Homebase\Downloads\avg_avct_stb_all_2014_4158_futuretest2.exe
2014-04-16 12:16 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-16 12:16 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-16 12:15 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-16 12:15 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-16 12:15 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-16 12:15 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-16 12:15 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-16 12:15 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-16 12:15 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-16 12:15 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-16 12:15 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-16 12:15 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-16 12:15 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-16 12:15 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-16 12:15 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-16 12:15 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-16 12:15 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-16 12:15 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-16 12:15 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-16 12:15 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-16 12:15 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-16 12:15 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-16 12:15 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-16 12:15 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-16 12:15 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-16 12:15 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-16 12:15 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-16 12:15 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-16 12:15 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-16 12:15 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-16 12:15 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-16 12:15 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-16 12:15 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-04-16 12:15 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-16 12:15 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-16 12:15 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-16 12:15 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-16 12:15 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-04-16 12:15 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-16 12:15 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-16 12:15 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-16 12:15 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-16 12:15 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-16 12:15 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-16 12:15 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-16 12:15 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-16 12:15 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-16 12:15 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-14 09:11 - 2014-04-14 09:27 - 00000000 ____D () C:\Users\Homebase\Documents\Mails bis 14.04.2014
2014-04-09 08:48 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 08:48 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 08:48 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 08:48 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 08:48 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 08:48 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 08:48 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 08:48 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 08:48 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 08:48 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 08:48 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 08:48 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 08:48 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 08:48 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 08:48 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 08:48 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 08:48 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
==================== One Month Modified Files and Folders =======
2014-04-29 18:26 - 2014-04-29 18:26 - 00015176 _____ () C:\Users\Homebase\Desktop\FRST.txt
2014-04-29 18:26 - 2014-04-28 19:14 - 00000000 ____D () C:\FRST
2014-04-29 18:24 - 2014-04-29 18:24 - 00008433 _____ () C:\Users\Homebase\Desktop\zoek-results.txt
2014-04-29 18:23 - 2013-06-12 23:07 - 00011216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-29 18:23 - 2013-06-12 23:07 - 00011216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-29 18:20 - 2013-09-02 20:34 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-29 18:20 - 2013-09-02 20:34 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-29 18:20 - 2013-09-02 20:34 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-29 18:20 - 2013-09-02 20:34 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-29 18:20 - 2013-06-12 23:35 - 02036924 _____ () C:\Windows\WindowsUpdate.log
2014-04-29 18:17 - 2014-04-29 17:51 - 00008433 _____ () C:\zoek-results.log
2014-04-29 18:16 - 2014-04-23 14:48 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-29 18:15 - 2013-12-22 15:54 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-29 18:15 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-29 18:14 - 2013-06-12 23:23 - 06639882 _____ () C:\Windows\PFRO.log
2014-04-29 18:14 - 2009-07-14 06:51 - 00898153 _____ () C:\Windows\setupact.log
2014-04-29 18:05 - 2014-04-29 17:49 - 00000000 ____D () C:\zoek_backup
2014-04-29 18:02 - 2013-12-22 15:54 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-29 17:49 - 2014-04-29 18:11 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-04-29 17:48 - 2014-04-29 17:48 - 01285120 _____ () C:\Users\Homebase\Desktop\zoek.exe
2014-04-29 17:47 - 2014-04-29 17:47 - 00001153 _____ () C:\Users\Homebase\Desktop\Malware.txt
2014-04-29 17:00 - 2014-04-29 17:00 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-29 17:00 - 2014-04-29 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-29 17:00 - 2014-04-29 17:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-29 16:57 - 2014-04-29 16:57 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Homebase\Downloads\mbam-setup-2.0.1.1004 (3).exe
2014-04-29 16:51 - 2014-04-29 16:47 - 00000000 ____D () C:\AdwCleaner
2014-04-29 16:45 - 2014-04-29 16:45 - 01310621 _____ () C:\Users\Homebase\Desktop\adwcleaner.exe
2014-04-28 19:26 - 2014-04-28 19:26 - 02061824 _____ (Farbar) C:\Users\Homebase\Desktop\FRST64.exe
2014-04-28 17:55 - 2014-04-28 17:55 - 00022016 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDKBFlt64.sys
2014-04-28 17:55 - 2014-04-28 17:55 - 00001978 _____ () C:\Users\Public\Desktop\G Data InternetSecurity.lnk
2014-04-28 17:55 - 2014-04-28 17:55 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_GDKBFlt64_01007.Wdf
2014-04-28 17:55 - 2014-04-28 17:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G Data InternetSecurity
2014-04-28 17:55 - 2014-04-26 21:35 - 00135168 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2014-04-28 17:55 - 2014-04-26 21:35 - 00068608 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys
2014-04-28 17:55 - 2014-04-26 21:35 - 00065024 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys
2014-04-28 17:55 - 2014-04-26 21:35 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys
2014-04-28 17:55 - 2014-04-26 21:35 - 00057344 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2014-04-28 17:54 - 2009-03-20 12:34 - 00019734 _____ () C:\Windows\DPINST.LOG
2014-04-28 17:53 - 2014-04-26 21:12 - 00000000 ____D () C:\ProgramData\G Data
2014-04-28 17:41 - 2014-04-28 17:41 - 00015666 _____ () C:\Users\Homebase\Documents\G Data Protokoll ID 2.html
2014-04-26 22:01 - 2014-04-26 22:01 - 00000000 ____D () C:\Users\Homebase\AppData\Roaming\WMPBooster
2014-04-26 21:59 - 2014-04-26 21:59 - 00107128 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2014-04-26 21:59 - 2014-04-26 21:59 - 00016944 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys
2014-04-26 21:57 - 2014-04-26 21:57 - 00001098 _____ () C:\Users\Public\Desktop\SystemTuner 2012.lnk
2014-04-26 21:57 - 2014-04-26 21:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SystemTuner 2012
2014-04-26 21:57 - 2014-04-26 21:57 - 00000000 ____D () C:\Program Files (x86)\SystemTuner 2012
2014-04-26 21:55 - 2013-06-15 16:04 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-04-26 21:49 - 2013-06-13 07:39 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-04-26 21:30 - 2014-04-26 21:30 - 00000000 ____D () C:\Program Files (x86)\G Data
2014-04-24 19:00 - 2014-04-24 18:59 - 25090430 _____ () C:\Users\Homebase\Downloads\SMA-Connection-Assist-1.0.11.R.exe
2014-04-24 15:33 - 2014-04-24 15:32 - 100285208 _____ (Microsoft Corporation) C:\Users\Homebase\Downloads\msert.exe
2014-04-23 14:47 - 2014-04-23 14:47 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-23 14:46 - 2014-04-23 14:46 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Homebase\Downloads\mbam-setup-2.0.1.1004 (2).exe
2014-04-23 14:46 - 2014-04-23 14:45 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Homebase\Downloads\mbam-setup-2.0.1.1004 (1).exe
2014-04-23 14:45 - 2014-04-23 14:44 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Homebase\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-22 20:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-22 20:10 - 2009-07-14 19:58 - 00699552 _____ () C:\Windows\system32\perfh007.dat
2014-04-22 20:10 - 2009-07-14 19:58 - 00149660 _____ () C:\Windows\system32\perfc007.dat
2014-04-22 20:10 - 2009-07-14 07:13 - 01620152 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-22 15:14 - 2014-04-22 15:14 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-04-22 15:14 - 2014-04-22 15:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-04-22 15:14 - 2014-04-22 15:13 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-04-22 15:14 - 2014-04-22 15:13 - 00000000 ____D () C:\Program Files\iTunes
2014-04-22 15:14 - 2014-04-22 15:13 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-04-22 15:13 - 2014-04-22 15:13 - 00000000 ____D () C:\Program Files\iPod
2014-04-22 15:07 - 2013-12-30 20:54 - 00000000 ____D () C:\ProgramData\Apple
2014-04-22 14:55 - 2014-04-22 14:55 - 01071360 _____ (Solid State Networks) C:\Users\Homebase\Downloads\install_flashplayer13x32axau_mssa_aaa_aih.exe
2014-04-22 13:38 - 2014-04-22 13:38 - 00000000 __SHD () C:\Users\Homebase\AppData\Local\EmieUserList
2014-04-22 13:38 - 2014-04-22 13:38 - 00000000 __SHD () C:\Users\Homebase\AppData\Local\EmieSiteList
2014-04-20 20:12 - 2014-04-20 20:11 - 00000000 ____D () C:\Users\Homebase\Downloads\avg_remover4116
2014-04-20 20:11 - 2014-04-20 20:10 - 03453210 _____ () C:\Users\Homebase\Downloads\avg_remover4116.zip
2014-04-20 19:49 - 2014-04-20 19:49 - 00000000 ____D () C:\Users\Homebase\AppData\Local\Geckofx
2014-04-20 19:46 - 2014-04-20 19:46 - 00000000 ____D () C:\Users\Homebase\Documents\SMA
2014-04-20 19:44 - 2014-04-20 19:44 - 00000000 ____D () C:\Users\Homebase\AppData\Roaming\SMA
2014-04-20 19:39 - 2014-04-20 19:39 - 00001094 _____ () C:\Users\Public\Desktop\Sunny Explorer.lnk
2014-04-20 19:39 - 2014-04-20 19:39 - 00000000 ____D () C:\ProgramData\SMA
2014-04-20 19:39 - 2014-04-20 19:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMA
2014-04-20 19:39 - 2014-04-20 19:39 - 00000000 ____D () C:\Program Files (x86)\SMA
2014-04-20 19:37 - 2014-04-20 19:35 - 80650912 _____ (SMA Solar Technology AG) C:\Users\Homebase\Downloads\SunnyExplorerSetup10711R.exe
2014-04-20 14:36 - 2014-04-20 14:18 - 00000375 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-04-19 20:25 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-04-19 16:00 - 2013-06-15 16:05 - 00000000 ____D () C:\Users\Homebase\AppData\Roaming\TuneUp Software
2014-04-19 15:55 - 2014-04-19 15:55 - 04435328 _____ (AVG Technologies) C:\Users\Homebase\Downloads\avg_avct_stb_all_2014_4158_futuretest2.exe
2014-04-16 12:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-14 09:27 - 2014-04-14 09:11 - 00000000 ____D () C:\Users\Homebase\Documents\Mails bis 14.04.2014
2014-04-11 15:42 - 2013-12-22 15:55 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-10 14:34 - 2013-08-01 15:44 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-10 14:34 - 2013-06-12 20:26 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-10 14:30 - 2013-06-13 11:27 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-05 18:57 - 2013-12-22 15:54 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-05 18:57 - 2013-12-22 15:54 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-03 09:51 - 2014-04-29 17:00 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-29 17:00 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-29 17:00 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 09:35 - 2013-06-12 23:57 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-22 20:44
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-04-2014
Ran by Homebase at 2014-04-29 18:27:48
Running from C:\Users\Homebase\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: G Data InternetSecurity (Enabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0}
AS: G Data InternetSecurity (Enabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: G Data Personal Firewall (Disabled) {6C670636-4D2B-B121-ACA7-9DAF938FCB8B}
==================== Installed Programs ======================
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.206 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.206 - Adobe Systems Incorporated)
Adobe Photoshop Elements 7.0 (HKLM-x32\...\Adobe Photoshop Elements 7) (Version: 7.0.1 - Adobe Systems Incorporated)
Adobe Photoshop Elements 7.0 (x32 Version: 7.0.1 - Adobe Systems Incorporated) Hidden
Adobe Premiere Elements 7.0 (HKLM-x32\...\PremElem70) (Version: 7.0.1 - Adobe Systems Incorporated)
Adobe Premiere Elements 7.0 (x32 Version: 7.0.1 - Adobe Systems Incorporated) Hidden
Adobe Premiere Elements 7.0 Templates (HKLM-x32\...\PremElem70Templates) (Version: 7.0.0 - Adobe Systems Incorporated)
Adobe Premiere Elements 7.0 Templates (x32 Version: 7.0.0 - Adobe Systems Incorporated) Hidden
Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Alps Pointing-device for VAIO (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: - )
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft Magic-i Visual Effects 2 (HKLM-x32\...\{7BB90344-0647-468E-925A-7F69F7983421}) (Version: 2.0.1.39 - ArcSoft)
ArcSoft WebCam Companion 2 (HKLM-x32\...\{9973498D-EA29-4A68-BE0B-C88D6E03E928}) (Version: - ArcSoft)
Ask Toolbar (HKLM-x32\...\{4F524A2D-5637-4300-76A7-A758B70C0A06}) (Version: 12.10.6.48 - APN, LLC) <==== ATTENTION
ATI Catalyst Install Manager (HKLM\...\{97A2310E-F75D-27D5-9167-B1A464637C47}) (Version: 3.0.710.0 - ATI Technologies, Inc.)
AVM FRITZ!Box Dokumentation (HKLM-x32\...\AVMFBox) (Version: - AVM Berlin)
AVM FRITZ!Box Druckeranschluss (HKLM-x32\...\AVMFBoxPrinter) (Version: - AVM Berlin)
Bino (HKLM-x32\...\Bino) (Version: 1.4.2 - The Bino developers)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Brother MFL-Pro Suite DCP-385C (HKLM-x32\...\{48D082B9-18F6-4426-AFAC-8B6A3E7021B1}) (Version: 1.0.1.0 - Brother Industries, Ltd.)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2009.0302.2147.39080 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2009.0302.2147.39080 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2009.0302.2147.39080 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2009.0302.2147.39080 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2009.0302.2147.39080 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.0302.2147.39080 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2009.0302.2147.39080 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2009.0302.2147.39080 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Czech (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Danish (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Dutch (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help English (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Finnish (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help French (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help German (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Greek (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Italian (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Japanese (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Korean (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Polish (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Russian (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Spanish (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Swedish (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Thai (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
CCC Help Turkish (x32 Version: 2009.0302.2146.39080 - ATI) Hidden
ccc-core-static (x32 Version: 2009.0302.2147.39080 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2009.0302.2147.39080 - ATI) Hidden
Choice Guard (x32 Version: 1.2.87.0 - Microsoft Corporation) Hidden
Click to Disc (HKLM-x32\...\{68A69CFF-130D-4CDE-AB0E-7374ECB144C8}) (Version: 1.2.60.13210 - Sony Corporation)
Click to Disc (x32 Version: 1.2.60.13210 - Sony Corporation) Hidden
Click to Disc Editor (HKLM-x32\...\InstallShield_{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}) (Version: 2.0.00 - Sony Corporation)
Click to Disc Editor (x32 Version: 2.0.00 - Sony Corporation) Hidden
Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Dolby Control Center (HKLM\...\{D035FBF6-FDEF-487D-89CA-6F9DD07B783F}) (Version: 1.2.0702 - Dolby)
G Data InternetSecurity (HKLM-x32\...\{85203592-3610-4FB9-AA11-15B2255B5A12}) (Version: 25.0.1.2 - G Data Software AG)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden
HDAUDIO SoftV92 Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200) (Version: - )
Intel PROSet Wireless (Version: - ) Hidden
Intel(R) PROSet/Wireless WiFi-Software (HKLM\...\{52A7C6A6-6B88-47D1-922E-9F8A7E089E6A}) (Version: 12.01.1000 - Intel(R) Corporation)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
Me&My VAIO (HKLM-x32\...\{76D7CCD6-8369-405C-B494-5F34FAE67249}) (Version: 1.2.0.14020 - Sony Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Download Manager (HKLM-x32\...\{654977DB-0001-0002-0001-EABD228DDE8B}) (Version: 1.2.1 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{62F7DA7E-CCCB-439C-A760-00C3926E761F}) (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.4.0 - Mozilla)
Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla)
MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Music Transfer (HKLM-x32\...\{CE2121C6-C94D-4A73-8EA4-6943F33EE335}) (Version: 1.3.01.13160 - Sony Corporation)
Norton Online Backup aktivieren (HKLM-x32\...\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 1.0.2046 - Symantec)
OpenMG Secure Module 5.3.00 (HKLM-x32\...\InstallShield_{DEF97A70-C67D-41E1-837C-6462C97A6F65}) (Version: 5.3.00.13080 - Sony Corporation)
OpenMG Secure Module 5.3.00 (x32 Version: 5.3.00.13080 - Sony Corporation) Hidden
OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
Primo (x32 Version: 1.00.0000 - Your Company Name) Hidden
PrintKey2000 (HKLM-x32\...\PrintKey2000) (Version: - )
Ravensburger tiptoi (HKLM-x32\...\Ravensburger tiptoi) (Version: - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5759 - Realtek Semiconductor Corp.)
Regi (Version: 1.00.0000 - InterVideo Inc.) Hidden
Roxio Central Audio (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Central Copy (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Central Core (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Central Data (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Central Tools (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Easy Media Creator 10 LJ (HKLM-x32\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.1 - Roxio)
Roxio Easy Media Creator Home (x32 Version: 10.1.311 - Roxio) Hidden
Runtime (x32 Version: 1.00.0000 - Your Company Name) Hidden
Setting Utility Series (HKLM-x32\...\{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}) (Version: 4.3.0.14120 - Sony Corporation)
Skins (x32 Version: 2009.0302.2147.39080 - ATI) Hidden
SmartSound Quicktracks for Premiere Elements (HKLM-x32\...\InstallShield_{F6234880-85BE-4DCB-8A45-1FF85A1A8552}) (Version: 3.11.3090 - SmartSound Software Inc)
SmartSound Quicktracks for Premiere Elements (x32 Version: 3.11.3090 - SmartSound Software Inc) Hidden
Software Info for Me&My VAIO (HKLM-x32\...\{69C8B1E3-2665-4A0F-B049-67746E5C4CE3}) (Version: 1.0.0.14020 - Sony Corporation)
SonicStage Mastering Studio (HKLM-x32\...\{6332AFF1-9D9A-429C-AA03-F82749FA4F49}) (Version: 2.6 - Sony Corporation)
SonicStage Mastering Studio Plugins (HKLM-x32\...\{9C1C8A04-F8CA-4472-A92D-4288CE32DE86}) (Version: 2.5 - Sony Corporation)
Sony Home Network Library (HKLM-x32\...\{D03D02D8-AB64-4785-A48E-5AA8B0FB8C14}) (Version: 1.4.0.14050 - Sony Corporation)
Sony Home Network Library (x32 Version: 1.4.0.14050 - Sony Corporation) Hidden
Sony Picture Utility (HKLM-x32\...\{D5068583-D569-468B-9755-5FBF5848F46F}) (Version: 4.2.12.14260 - Sony Corporation)
Sony Video Shared Library (HKLM-x32\...\{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}) (Version: 3.5.00 - Sony Corporation)
Sunny Explorer (HKLM-x32\...\{74BA5B29-15A6-4640-8FD9-535DA42ECDD7}) (Version: 1.7.11 - SMA Solar Technology AG)
SystemTuner 2012 (HKLM-x32\...\SystemTuner2012_is1) (Version: - WMP)
Unterstützung für VAIO-Präsentation (HKLM-x32\...\{2018C019-30D9-4240-8C01-0865C10DCF5A}) (Version: 1.2.0.12240 - Sony Corporation)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
VAIO Content Folder Setting (HKLM-x32\...\{23825B69-36DF-4DAD-9CFD-118D11D80F16}) (Version: 2.3.0.12220 - Sony Corporation)
VAIO Content Folder Watcher (HKLM-x32\...\{327B75F0-92AF-420A-988F-FA596A218E0B}) (Version: 1.1.0.13140 - Sony Corporation)
VAIO Content Folder Watcher (x32 Version: 1.1.0.13140 - Sony Corporation) Hidden
VAIO Content Metadata Intelligent Analyzing Manager (HKLM-x32\...\{BFD85D24-D4F3-4CCC-B518-D7C4FC29C76D}) (Version: 3.4.0.13192 - Sony Corporation)
VAIO Content Metadata Intelligent Analyzing Manager (x32 Version: 3.4.0.13192 - Sony Corporation) Hidden
VAIO Content Metadata Manager Setting (HKLM-x32\...\{EADE97A7-E7AA-43FD-A042-92A68E0187A6}) (Version: 3.4.0.13160 - Sony Corporation)
VAIO Content Metadata Manager Setting (x32 Version: 3.4.0.13160 - Sony Corporation) Hidden
VAIO Content Metadata XML Interface Library (HKLM-x32\...\{E3453B1B-C91B-4C48-B046-8DF635DD46F2}) (Version: 3.4.0.13160 - Sony Corporation)
VAIO Content Metadata XML Interface Library (x32 Version: 3.4.0.13160 - Sony Corporation) Hidden
VAIO Control Center (HKLM-x32\...\{72042FA6-5609-489F-A8EA-3C2DD650F667}) (Version: 3.3.0.12240 - Sony Corporation)
VAIO Data Restore Tool (HKLM-x32\...\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}) (Version: 1.1.00.13080 - Sony Corporation)
VAIO DVD Menu Data Basic (HKLM-x32\...\{596BED91-A1D8-4DF1-8CD1-1C777F7588AC}) (Version: 1.0.00.08130 - Sony Corporation)
VAIO Edit Components (x32 Version: 6.5 - Sony Corporation) Hidden
VAIO Edit Components 6.5 (HKLM-x32\...\{B7C03E84-AF46-42F4-809D-D4127D9086D0}) (Version: 6.5 - Sony Corporation)
VAIO Energie Verwaltung (HKLM-x32\...\{5F5867F0-2D23-4338-A206-01A76C823924}) (Version: 3.3.0.12190 - Sony Corporation)
VAIO Entertainment Platform (HKLM-x32\...\{6B1F20F2-6321-4669-A58C-33DF8E7517FF}) (Version: 3.4.0.13210 - Sony Corporation)
VAIO Entertainment Platform (x32 Version: 3.4.0.13210 - Sony Corporation) Hidden
VAIO Event Service (HKLM-x32\...\{C7477742-DDB4-43E5-AC8D-0259E1E661B1}) (Version: 4.3.0.13190 - Sony Corporation)
VAIO Launcher (HKLM-x32\...\{15D5C238-4C2E-4AEA-A66D-D6989A4C586B}) (Version: 2.3.0.15090 - Sony Corporation)
VAIO Marketing Tools (HKLM-x32\...\MarketingTools) (Version: - Sony Corporation)
VAIO Media plus (HKLM-x32\...\{8DE50158-80AA-4FF2-9E9F-0A7C46F71FCD}) (Version: 1.4.0.14050 - Sony Corporation)
VAIO Media plus Opening Movie (HKLM-x32\...\{9238E8A4-BEBA-43A3-B926-769BDBF194C5}) (Version: 1.2.0.09100 - Sony Corporation)
VAIO Movie Story (HKLM-x32\...\{B25563A0-41F4-4A81-A6C1-6DBC0911B1F3}) (Version: 1.4.00.13080 - Sony Corporation)
VAIO Movie Story (x32 Version: 1.4.00.13080 - Sony Corporation) Hidden
VAIO Movie Story Template Data (HKLM-x32\...\{6FA8BA2C-052B-4072-B8E2-2302C268BE9E}) (Version: 1.4.00.13080 - Sony Corporation)
VAIO MusicBox (HKLM-x32\...\{D613E659-6503-42A8-9617-4F599061EAD5}) (Version: 2.2.0.13091 - Sony Corporation)
VAIO MusicBox Sample Music (HKLM-x32\...\{98FC7A64-774B-49B5-B046-4B4EBC053FA9}) (Version: 1.1.00.14140 - Sony Corporation)
VAIO Original Function Setting (HKLM-x32\...\{A63E7492-A0BC-4BB9-89A7-352965222380}) (Version: 1.5.01.10310 - Sony Corporation)
VAIO Smart Network (HKLM-x32\...\{3B659FAD-E772-44A3-B7E7-560FF084669F}) (Version: 2.3.0.12210 - Sony Corporation)
VAIO Update 4 (HKLM-x32\...\{83CDA18E-0BF3-4ACA-872C-B4CDABF2360E}) (Version: 4.1.0.12180 - Sony Corporation)
VAIO Wallpaper Contents (HKLM-x32\...\{D60F97EC-EF06-4E1E-B0D1-C2CBABA62FA3}) (Version: 1.3.0.10310 - Sony Corporation)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.1.0-pre1 (HKLM\...\VLC media player) (Version: 2.1.0-pre1 - VideoLAN)
WIDCOMM Bluetooth Software (HKLM\...\{D239B547-8B20-4BDE-888D-C9CCA823FFD8}) (Version: 6.2.0.7600 - Broadcom Corporation)
Windows 7 Upgrade Advisor (HKLM-x32\...\{9A4D182C-35C7-4791-8484-4304EBC9101A}) (Version: 2.0.5000.0 - Microsoft Corporation)
Windows Live Anmelde-Assistent (HKLM-x32\...\{B5BCBD49-202F-4238-8398-D83D423A48B4}) (Version: 5.000.817.1 - Microsoft Corporation)
Windows Live Call (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8050.1202 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden
Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
WinDVD BD for VAIO (HKLM-x32\...\InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}) (Version: 8.0-B9.727 - InterVideo Inc.)
WinDVD BD for VAIO (x32 Version: 8.0-B9.727 - InterVideo Inc.) Hidden
==================== Restore Points =========================
03-02-2014 12:34:53 Windows-Sicherung
05-02-2014 19:07:51 Windows Update
09-02-2014 13:20:44 Windows Update
09-02-2014 19:16:35 Windows-Sicherung
12-02-2014 18:24:31 Windows Update
13-02-2014 09:45:48 Windows Update
18-02-2014 16:23:07 Windows Update
18-02-2014 16:23:13 Windows-Sicherung
18-02-2014 16:48:23 Windows Update
22-02-2014 13:18:18 Windows Update
24-02-2014 19:28:30 Windows-Sicherung
25-02-2014 20:10:45 Windows Update
25-02-2014 20:52:36 Windows Update
01-03-2014 07:20:04 Windows Update
02-03-2014 19:38:29 Windows-Sicherung
04-03-2014 17:59:20 Windows Update
08-03-2014 19:27:13 Windows Update
09-03-2014 18:00:24 Windows-Sicherung
11-03-2014 19:35:20 Windows Update
11-03-2014 20:07:40 Windows Update
16-03-2014 13:57:24 Windows Update
16-03-2014 18:44:09 Windows-Sicherung
18-03-2014 20:18:38 Windows Update
25-03-2014 13:45:07 Windows-Sicherung
25-03-2014 13:45:07 Windows Update
29-03-2014 12:49:04 Windows Update
30-03-2014 17:01:25 Windows-Sicherung
02-04-2014 13:39:26 Windows Update
04-04-2014 03:28:07 Windows Update
07-04-2014 13:02:38 Windows-Sicherung
07-04-2014 13:04:11 Windows Update
10-04-2014 12:27:32 Windows Update
14-04-2014 07:15:42 Windows-Sicherung
14-04-2014 18:13:17 Windows Update
16-04-2014 10:13:56 Windows Update
19-04-2014 12:54:55 Windows Update
19-04-2014 13:58:20 Installed AVG 2014
19-04-2014 13:58:52 Installed AVG 2014
20-04-2014 17:38:11 Installed Sunny Explorer
20-04-2014 17:52:40 Windows-Sicherung
22-04-2014 13:07:09 Windows Update
26-04-2014 09:54:49 Windows Update
26-04-2014 19:52:23 TuneUp Utilities 2013 wird entfernt
26-04-2014 19:55:01 TuneUp Utilities Language Pack (de-DE) wird entfernt
28-04-2014 15:18:05 Windows-Sicherung
29-04-2014 14:48:24 Windows Update
29-04-2014 15:52:10 zoek.exe restore point
==================== Hosts content: ==========================
2006-11-02 14:34 - 2006-09-18 23:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {029C2596-564F-4804-A115-A18A6DC582B1} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {1A4C7F07-81A4-4C9E-8544-A3F46A46C570} - System32\Tasks\SONY\Me&My VAIO\Me&My VAIO => C:\Program Files (x86)\Sony\Me&My VAIO\QLGuide.exe
Task: {1D6A8E1A-AECC-4410-8ED3-8193E9AB8DEB} - System32\Tasks\SONY\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe [2008-12-18] (Sony Corporation)
Task: {40788288-D641-4072-AB7E-6B7529483377} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-29] (Adobe Systems Incorporated)
Task: {6202C9C6-01E7-4801-B109-4DBB5820B0F6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-22] (Google Inc.)
Task: {712C6861-2B14-4E72-92BA-22B6921FE2B7} - System32\Tasks\Microsoft\Windows\Wired\GatherWiredInfo => C:\Windows\system32\gatherWiredInfo.vbs
Task: {72402F98-D786-4942-A27C-D112EFF973D5} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {77A44354-0E57-42D4-BB3B-E5A2C49B2E03} - System32\Tasks\{C2D5381C-703C-4F20-B0DF-33E4E37C7F7B} => C:\Program Files (x86)\Convar\SmartRecovery\SMR.exe
Task: {7D9659A6-9EC5-482B-921F-96B4C56E49DE} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {862F3259-BD3E-4584-B3F3-19BBD10F3F91} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-22] (Google Inc.)
Task: {D93DEE0A-A92D-4033-BD52-43BD742E427B} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated)
Task: {DE045570-9F03-4AF1-97F4-354E840F6460} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2007-09-06 10:27 - 2007-09-06 10:27 - 01331712 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2008-08-20 16:42 - 2008-08-20 16:42 - 00335360 _____ () C:\Program Files\Intel\WiFi\bin\IWMSPROV.DLL
2013-12-19 04:42 - 2013-12-19 04:42 - 00350840 ____N () C:\Program Files (x86)\Common Files\G Data\AVKProxy\PktIcpt2x64.dll
2013-06-12 23:16 - 2013-06-12 23:16 - 00014848 _____ () C:\Windows\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll
2008-11-25 10:19 - 2008-11-25 10:19 - 01193472 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Implementation\64\wbocx.ocx
2008-08-26 11:41 - 2008-08-26 11:41 - 00016384 ____R () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2014-04-26 21:57 - 2011-09-20 10:39 - 01552000 _____ () C:\Program Files (x86)\SystemTuner 2012\BoostService.exe
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-06-12 20:45 - 2009-01-19 12:49 - 00010752 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll
2013-06-12 20:45 - 2009-01-19 12:49 - 00009728 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSubPS.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/29/2014 06:16:27 PM) (Source: VzCdbSvc) (User: )
Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019)
Error: (04/29/2014 06:16:08 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/29/2014 04:54:07 PM) (Source: VzCdbSvc) (User: )
Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019)
Error: (04/29/2014 04:53:57 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/29/2014 04:42:17 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/29/2014 04:42:10 PM) (Source: VzCdbSvc) (User: )
Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019)
Error: (04/28/2014 06:04:00 PM) (Source: VzCdbSvc) (User: )
Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019)
Error: (04/28/2014 06:02:52 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/28/2014 05:10:44 PM) (Source: VzCdbSvc) (User: )
Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019)
Error: (04/28/2014 05:09:22 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (04/29/2014 06:14:55 PM) (Source: atikmdag) (User: )
Description: Display is not active
Error: (04/29/2014 06:14:55 PM) (Source: atikmdag) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (04/29/2014 06:13:51 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst G Data Personal Firewall konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.
Error: (04/29/2014 06:05:35 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (04/29/2014 06:05:35 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (04/29/2014 06:05:34 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (04/29/2014 06:05:34 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (04/29/2014 06:05:34 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (04/29/2014 04:53:20 PM) (Source: atikmdag) (User: )
Description: Display is not active
Error: (04/29/2014 04:53:20 PM) (Source: atikmdag) (User: )
Description: CPLIB :: General - Invalid Parameter
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 38%
Total physical RAM: 4063.02 MB
Available physical RAM: 2480.36 MB
Total Pagefile: 8124.23 MB
Available Pagefile: 5745.38 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:371.14 GB) (Free:205.2 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 373 GB) (Disk ID: E7498040)
Partition 1: (Not Active) - (Size=1 GB) - (Type=27)
Partition 2: (Active) - (Size=371 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Danke und Gruß
Wapi |