Ok anbei die restlichen logfiles, Danke schon mal für die Hilfe :daumenhoc
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=7ea1fd4e091f1b4b821cee769087405a
# engine=14170
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-27 02:26:28
# local_time=2013-06-27 04:26:28 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1799 16775165 100 99 29486 237766478 22267 0
# compatibility_mode=5892 16776574 100 100 35281002 209875916 0 0
# scanned=178765
# found=2
# cleaned=0
# scan_time=3957
sh=6542A2B022BAF5B1357957BCE37BC8C91A662D6D ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.OSI trojan" ac=I fn="C:\Users\Technoplan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\724db3c7-422949d9"
sh=6542A2B022BAF5B1357957BCE37BC8C91A662D6D ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.OSI trojan" ac=I fn="C:\Users\Technoplan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\724db3c7-4fc18de9"
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=7ea1fd4e091f1b4b821cee769087405a
# engine=19070
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-07-08 08:49:18
# local_time=2014-07-08 10:49:18 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode_1='Avira Desktop'
# compatibility_mode=1810 16777213 100 100 8920 31455117 0 0
# compatibility_mode_1=''
# compatibility_mode=5892 16776574 100 100 7242 242342086 0 0
# scanned=287482
# found=27
# cleaned=0
# scan_time=5130
sh=75F4A06A0290B613622C7E10E3B05EE0525C1481 ft=1 fh=e7b99738d4ab1513 vn="MSIL/AdvancedSystemProtector.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\System Speedup\systweakasp.exe.vir"
sh=3191611ECBDEF87FB6079264FF07AD2087620554 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Technoplan\AppData\Roaming\Mozilla\Firefox\Profiles\x1kwq4gw.default\Extensions\6c78cab3-0311-420c-8cc8-d70d7c2e12d0@61a12377-7214-44f1-a183-c0827fed20fa.com\extensionData\plugins\91.js.vir"
sh=592AB851A47C3693876D64FFCBFF1A062BA803E7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\Fraven 1.1\2fed8189-e898-400a-bb56-01610f96d56b.crx"
sh=1BF6C0017BEC46887FC2E263A6723BE7884AF10D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\Fraven 1.1\360-59603.crx"
sh=592AB851A47C3693876D64FFCBFF1A062BA803E7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\Fraven 1.1\59603.crx"
sh=826779D58E0F829A11915EFE0573600445168779 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\Fraven 1.1\59603.xpi"
sh=E14543DB62ABE09F2B563E304BB5844A2591B6C4 ft=1 fh=2bf6e4a32001ff06 vn="Variante von Win32/Toolbar.CrossRider.AI evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\Fraven 1.1\Fraven 1.1-nova.dll"
sh=9CA8EBFF024F34D076C7BFFF92B978D99251DC66 ft=1 fh=03cf8fdbea9a76d3 vn="Variante von Win32/ELEX.AM evtl. unerwünschte Anwendung" ac=I fn="C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe"
sh=4A69CB64B60214C1A66F1FEF587F332CED27C073 ft=1 fh=43574454a5128a07 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\SearchProtect\Main\bin\CltMngSvc.exe.vir"
sh=180E91D83FA14ECDE328A46A3E2E0B6F8C94DBCD ft=1 fh=be1d8e30183e65f6 vn="Variante von Win32/Conduit.SearchProtect.I evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe.vir"
sh=E698C2A7E66483968C0F7C702209FDD810CD443E ft=1 fh=796c794d5bd44ef7 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\SPVC32.dll.vir"
sh=9CA8EBFF024F34D076C7BFFF92B978D99251DC66 ft=1 fh=03cf8fdbea9a76d3 vn="Variante von Win32/ELEX.AM evtl. unerwünschte Anwendung" ac=I fn="C:\Users\All Users\WindowsMangerProtect\ProtectWindowsManager.exe"
sh=C88DAF3FB5D3FEC090233FF251F7F0CFC73EF4CD ft=1 fh=b74c7f4df627386b vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\AppData\Roaming\Mozilla\Firefox\Profiles\x1kwq4gw.default\extensions\{fcd9923a-9c24-d7ca-af1d-94ac42151b2b}\components\SmartbarFireFoxRemotePlugin_25.dll"
sh=4B9D59EFA89F628628CE74083961743D56E460C7 ft=1 fh=8e9074b2b2075a48 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\AppData\Roaming\Mozilla\Firefox\Profiles\x1kwq4gw.default\extensions\{fcd9923a-9c24-d7ca-af1d-94ac42151b2b}\components\SmartbarFireFoxRemotePlugin_26.dll"
sh=7290509DD9B7F8DCFA781334EBEFF3E5D4C58C5C ft=1 fh=0aae782d31fb93bd vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\AppData\Roaming\Mozilla\Firefox\Profiles\x1kwq4gw.default\extensions\{fcd9923a-9c24-d7ca-af1d-94ac42151b2b}\components\SmartbarFireFoxRemotePlugin_27.dll"
sh=32602D4077332EE0F75304C87434755510F768FD ft=1 fh=4d22cbd3b33f2e9e vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\AppData\Roaming\Mozilla\Firefox\Profiles\x1kwq4gw.default\extensions\{fcd9923a-9c24-d7ca-af1d-94ac42151b2b}\components\SmartbarFireFoxRemotePlugin_28.dll"
sh=A5517659524BFD05ABEF457FE26F1D0E80D3EF85 ft=1 fh=af4585d56f4a69b5 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\AppData\Roaming\Mozilla\Firefox\Profiles\x1kwq4gw.default\extensions\{fcd9923a-9c24-d7ca-af1d-94ac42151b2b}\components\SmartbarFireFoxRemotePlugin_29.dll"
sh=36E31354BDEA960B9E966413460C3CB81036C629 ft=1 fh=107c58d6ba93a4af vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\AppData\Roaming\Mozilla\Firefox\Profiles\x1kwq4gw.default\extensions\{fcd9923a-9c24-d7ca-af1d-94ac42151b2b}\components\SmartbarFireFoxRemotePlugin_30.dll"
sh=052C0EB59109F3B2FD782E4B0A6AC614F09F77D4 ft=0 fh=0000000000000000 vn="Win32/JoyDownloader.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\Downloads\Programm vom 13.11.zip"
sh=1A9C2CE8C1F539AC8546D67C9F924AEA8D2A84C2 ft=1 fh=d348c3328e970e39 vn="Win32/MyPCBackup.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\Downloads\3BB6tmp\cloud_backup_setup.exe"
sh=F65EAECC41208781EEBEB27546273293C29C9957 ft=1 fh=a430c7f8a70141ed vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Technoplan\Downloads\3C55tmp\freesofttoday.exe"
sh=8B553FC78AB4575C972AC27B91F755C9800E067D ft=1 fh=f11d65cf0ffebec1 vn="Win32/VOPackage.J evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\Downloads\3C76tmp\vopackage.exe"
sh=C2A9E3C1153C1E248164A257CBD2DACB9211A0CC ft=1 fh=9cfea4062905bd6b vn="Variante von Win32/ELEX.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\Downloads\3CC6tmp\lly_omiga-plus.exe"
sh=1A9C2CE8C1F539AC8546D67C9F924AEA8D2A84C2 ft=1 fh=d348c3328e970e39 vn="Win32/MyPCBackup.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\Downloads\49F9tmp\cloud_backup_setup.exe"
sh=F65EAECC41208781EEBEB27546273293C29C9957 ft=1 fh=a430c7f8a70141ed vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Technoplan\Downloads\4A98tmp\freesofttoday.exe"
sh=8B553FC78AB4575C972AC27B91F755C9800E067D ft=1 fh=f11d65cf0ffebec1 vn="Win32/VOPackage.J evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\Downloads\4AC8tmp\vopackage.exe"
sh=C2A9E3C1153C1E248164A257CBD2DACB9211A0CC ft=1 fh=9cfea4062905bd6b vn="Variante von Win32/ELEX.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Technoplan\Downloads\4B18tmp\lly_omiga-plus.exe"
Results of screen317's Security Check version 0.99.85
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date! (On Access scanning
disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Java(TM) 6 Update 22
Java version out of Date!
Adobe Flash Player 13.0.0.214
Flash Player out of Date!
Adobe Reader 8
Adobe Reader out of Date!
Mozilla Firefox (30.0)
Google Chrome 35.0.1916.114
Google Chrome 35.0.1916.153
````````Process Check: objlist.exe by Laurent```````` Spybot Teatimer.exe is disabled!
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Empowering Technology eSettings Service capuserv.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-07-2014 01
Ran by Technoplan (administrator) on TECHNOPLAN-PC on 08-07-2014 14:34:41
Running from C:\Users\Technoplan\Desktop
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Fuyu LIMITED) C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
() C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(CyberLink) C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
() C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Egis Incorporated) C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
() C:\MySql\bin\mysqld-nt.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
() C:\Program Files\CB78F643-3729-434F-8C25-F28D15F025F3\SupraSavingsService.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
(Acer Inc.) C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
() C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
(Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
() C:\Acer\Empowering Technology\SysMonitor.exe
(Egis Incorporated) C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
(NVIDIA Corporation) C:\Windows\System32\nvraidservice.exe
(PixelPlanet GmbH) C:\Program Files\PixelPlanet\PdfPrinter 6\PdfPrinterMonitor.exe
(Geek Software GmbH) C:\Program Files\pdf24\pdf24.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Autodesk, Inc.) C:\Program Files\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\Brother\BrStMonW.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Akamai Technologies, Inc.) C:\Users\Technoplan\AppData\Local\Akamai\netsession_win.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Acer Inc.) C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
(Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCtrlCntr.exe
(Acer Inc.) C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Akamai Technologies, Inc.) C:\Users\Technoplan\AppData\Local\Akamai\netsession_win.exe
(Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCcUxSys.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\BrYNSvc.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvSvc] => C:\Windows\system32\nvsvc.dll [86016 2007-12-21] (NVIDIA Corporation)
HKLM\...\Run: [NvCplDaemon] => C:\Windows\system32\NvCpl.dll [8497696 2007-12-21] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] => C:\Windows\system32\NvMcTray.dll [81920 2007-12-21] (NVIDIA Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [5369856 2008-03-26] (Realtek Semiconductor)
HKLM\...\Run: [Acer Empowering Technology Monitor] => C:\Acer\Empowering Technology\SysMonitor.exe [326176 2008-01-09] ()
HKLM\...\Run: [eDataSecurity Loader] => C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [526896 2008-03-05] (Egis Incorporated)
HKLM\...\Run: [PCMMediaSharing] => C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [204908 2008-01-25] ()
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [WarReg_PopUp] => C:\Acer\WR_PopUp\WarReg_PopUp.exe [57344 2006-11-05] (Acer Inc.)
HKLM\...\Run: [NVRaidService] => C:\Windows\system32\nvraidservice.exe [203296 2008-06-06] (NVIDIA Corporation)
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-10-15] (Adobe Systems Incorporated)
HKLM\...\Run: [PixelPlanet PdfPrinter-Monitor] => C:\Program Files\PixelPlanet\PdfPrinter 6\PdfPrinterMonitor.exe [1404808 2009-11-17] (PixelPlanet GmbH)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [PDFPrint] => C:\Program Files\pdf24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [248552 2010-05-14] (Sun Microsystems, Inc.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [750160 2014-06-24] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [ADSK DLMSession] => C:\Program Files\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [1641368 2013-02-01] (Autodesk, Inc.)
HKLM\...\Run: [ControlCenter4] => C:\Program Files\ControlCenter4\BrCcBoot.exe [143360 2012-08-28] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] => C:\Program Files\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKU\S-1-5-21-923770033-2654947890-2156885174-1000\...\Run: [SpybotSD TeaTimer] => C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-923770033-2654947890-2156885174-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Technoplan\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-923770033-2654947890-2156885174-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-923770033-2654947890-2156885174-1000\...\Run: [ChicaPasswordManager] => C:\Program Files\ChicaLogic\Chica Password Manager\stpass.exe [4299624 2012-07-09] (ChicaLogic, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ASETRES.EXE ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
ShortcutTarget: Empowering Technology Launcher.lnk -> C:\Acer\Empowering Technology\eAPLauncher.exe (Acer Inc.)
ShellIconOverlayIdentifiers: Symbol-Overlay-Steuerprogramm für AutoCAD Digitale Signaturen -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - No Name - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - No File
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.254
Tcpip\..\Interfaces\{2FC76DB2-719C-4570-9177-8E5A30E0FE49}: [NameServer]192.168.0.254
FireFox:
========
FF ProfilePath: C:\Users\Technoplan\AppData\Roaming\Mozilla\Firefox\Profiles\x1kwq4gw.default
FF NewTab: chrome://quick_start/content/index.html
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @eleco.com/o2cplayer - C:\Program Files\Eleco\o2c Player\npO2CPlayer.DLL (ELECO Software GmbH)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.5.1 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: DoNotTrackMe: Online Privacy Protection - C:\Users\Technoplan\AppData\Roaming\Mozilla\Firefox\Profiles\x1kwq4gw.default\Extensions\donottrackplus@abine.com [2014-07-01]
FF Extension: SafeFinder Smartbar - C:\Users\Technoplan\AppData\Roaming\Mozilla\Firefox\Profiles\x1kwq4gw.default\Extensions\{fcd9923a-9c24-d7ca-af1d-94ac42151b2b} [2014-07-01]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-02-17]
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR NewTab: "chrome-extension://pelmeidfhdlhlbjimpabfcbnnojbboma/index.html"
CHR DefaultSearchKeyword: trovi.search
CHR DefaultSearchProvider: Trovi search
CHR DefaultSearchURL: hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325582&octid=EB_ORIGINAL_CTID&ISID=M3308A735-F0B4-4C54-814C-869FC68BAEF2&SearchSource=58&CUI=&UM=2&UP=SP6C183687-747D-462E-B5ED-991192CDFEDD&q={searchTerms}&SSPV=
CHR Extension: (Google Wallet) - C:\Users\Technoplan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-30]
CHR Extension: (No Name) - C:\Users\Technoplan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [2014-06-30]
CHR StartMenuInternet: Google Chrome - chrome.exe
========================== Services (Whitelisted) =================
R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 Acer HomeMedia Connect Service; C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [269448 2008-01-25] (CyberLink) [File not signed]
R2 AcerMemUsageCheckService; C:\Acer\Empowering Technology\ePerformance\MemCheck.exe [28672 2007-10-17] () [File not signed]
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-06-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1028688 2014-06-24] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [165784 2014-06-23] (APN LLC.)
S3 bepldr6PixelPlanetService; C:\Program Files\Common Files\BCL Technologies\PixelPlanet6\bepldr.exe [172032 2009-10-05] () [File not signed]
R3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
R2 eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [500784 2008-03-05] (Egis Incorporated)
R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE [102400 2006-04-18] (SEIKO EPSON CORPORATION) [File not signed]
R2 eRecoveryService; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [57344 2007-09-10] (Acer Inc.) [File not signed]
R2 eSettingsService; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [24576 2007-12-19] () [File not signed]
S2 gupdate1c9a6d0297c578d; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-03-17] (Google Inc.)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
S2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MSSQL$GW; C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
R2 MySQL; C:\MySql\bin\mysqld-nt.exe [2179072 2004-05-29] () [File not signed]
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [262247 2006-07-19] () [File not signed]
R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 SupraSavingsService; C:\Program Files\CB78F643-3729-434F-8C25-F28D15F025F3\SupraSavingsService.exe [151040 2014-06-25] () [File not signed]
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [535936 2014-06-30] (Fuyu LIMITED)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [97648 2014-06-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG)
R2 int15; C:\Acer\Empowering Technology\eRecovery\int15.sys [15392 2007-07-03] (Acer, Inc.)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation)
R1 netfilter; C:\Windows\System32\drivers\netfilter.sys [47488 2014-06-12] (NetFilterSDK.com) [File not signed]
R3 NTIDrvr; C:\Windows\System32\DRIVERS\NTIDrvr.sys [6144 2008-03-21] (NewTech Infosystems, Inc.) [File not signed]
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-09] (Avira GmbH)
R2 tvicport; C:\Windows\system32\drivers\tvicport.sys [14544 2007-11-06] (EnTech Taiwan) [File not signed]
R2 zntport; C:\Windows\system32\drivers\zntport.sys [6080 2007-11-06] (Zeal SoftStudio) [File not signed]
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S1 netfilter2; system32\drivers\netfilter2.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-08 14:34 - 2014-07-08 14:34 - 00001161 _____ () C:\Users\Technoplan\Desktop\checkup.txt
2014-07-08 14:34 - 2014-07-08 14:34 - 00000000 ____D () C:\Users\Technoplan\Desktop\FRST-OlderVersion
2014-07-08 09:12 - 2014-07-08 09:12 - 00854390 _____ () C:\Users\Technoplan\Desktop\SecurityCheck.exe
2014-07-08 09:08 - 2014-07-08 09:09 - 02347384 _____ (ESET) C:\Users\Technoplan\Desktop\esetsmartinstaller_deu.exe
2014-07-03 15:45 - 2014-07-03 15:45 - 00001513 _____ () C:\Users\Technoplan\Desktop\JRT.txt
2014-07-03 15:32 - 2014-07-03 15:32 - 01016261 _____ (Thisisu) C:\Users\Technoplan\Desktop\JRT.exe
2014-07-03 15:11 - 2014-07-08 08:37 - 00000000 ____D () C:\Program Files\SupraSavings
2014-07-03 15:06 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-07-03 15:05 - 2014-07-03 15:10 - 00000000 ____D () C:\AdwCleaner
2014-07-03 15:04 - 2014-07-03 15:04 - 01346519 _____ () C:\Users\Technoplan\Desktop\adwcleaner_3.214.exe
2014-07-03 13:19 - 2014-07-08 09:00 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-03 13:19 - 2014-07-03 13:19 - 00000903 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-03 13:19 - 2014-07-03 13:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-03 13:19 - 2014-07-03 13:19 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-03 13:19 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-03 13:19 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-03 13:19 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-03 13:08 - 2014-07-03 13:16 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Technoplan\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-02 14:07 - 2014-07-02 14:07 - 00018873 _____ () C:\ComboFix.txt
2014-07-02 13:47 - 2014-07-02 14:07 - 00000000 ____D () C:\Qoobox
2014-07-02 13:47 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-02 13:47 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-02 13:47 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-02 13:47 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-02 13:47 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-02 13:47 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-02 13:47 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-02 13:47 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-02 13:45 - 2014-07-02 13:45 - 05212874 ____R (Swearware) C:\Users\Technoplan\Desktop\ComboFix.exe
2014-07-02 13:17 - 2014-07-02 13:17 - 00001061 _____ () C:\Users\Technoplan\Desktop\Revo Uninstaller.lnk
2014-07-02 13:17 - 2014-07-02 13:17 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-07-02 13:16 - 2014-07-02 13:16 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Technoplan\Desktop\revosetup95.exe
2014-07-01 10:13 - 2014-07-08 14:34 - 00018758 _____ () C:\Users\Technoplan\Desktop\FRST.txt
2014-07-01 10:12 - 2014-07-08 14:34 - 01074688 _____ (Farbar) C:\Users\Technoplan\Desktop\FRST.exe
2014-07-01 10:12 - 2014-07-08 14:34 - 00000000 ____D () C:\FRST
2014-07-01 09:52 - 2014-07-01 09:52 - 00001089 _____ () C:\Users\Public\Desktop\Chica Password Manager 2.0.lnk
2014-07-01 09:52 - 2014-07-01 09:52 - 00000000 ___SD () C:\Users\Technoplan\Documents\Chica Passwords
2014-07-01 09:52 - 2014-07-01 09:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ChicaLogic
2014-07-01 09:52 - 2014-07-01 09:52 - 00000000 ____D () C:\Program Files\ChicaLogic
2014-07-01 09:52 - 2014-07-01 09:52 - 00000000 ____D () C:\Program Files\CB78F643-3729-434F-8C25-F28D15F025F3
2014-07-01 09:45 - 2012-07-25 12:03 - 00017136 _____ () C:\Windows\system32\sasnative32.exe
2014-07-01 09:43 - 2014-07-03 15:10 - 00000880 _____ () C:\Users\Technoplan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-07-01 09:43 - 2014-07-03 15:10 - 00000850 _____ () C:\Users\Technoplan\Desktop\Search.lnk
2014-06-30 13:15 - 2014-06-30 13:15 - 00000000 ____D () C:\ProgramData\TEMP
2014-06-30 13:10 - 2014-06-30 13:10 - 00000000 ____D () C:\Users\Technoplan\AppData\Local\com
2014-06-30 13:10 - 2014-06-30 13:10 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-06-30 13:07 - 2014-07-03 08:24 - 00000000 ____D () C:\Program Files\Fraven 1.1
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\4B18tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\4AF7tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\4AC8tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\4A98tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\4A58tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\4A29tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\49F9tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\49D9tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3CC6tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3C96tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3C76tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3C55tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3C26tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3C05tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3BB6tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3B87tmp
2014-06-25 09:48 - 2014-06-25 11:39 - 00000000 ____D () C:\Users\Technoplan\Desktop\petry
2014-06-25 09:11 - 2014-06-25 09:12 - 09044888 _____ () C:\Users\Technoplan\Desktop\Abschlussprojekt fertig inkl. Durchbruchplan.zip
2014-06-24 09:28 - 2014-06-25 10:29 - 00000000 ____D () C:\Users\Technoplan\Desktop\Ball
2014-06-24 09:20 - 2014-06-24 09:20 - 00469723 _____ () C:\Users\Technoplan\Desktop\Abschlussprojekt elektro Sebastian Ball.zip
2014-06-18 09:18 - 2014-06-18 09:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-12 21:05 - 2014-06-12 21:05 - 00047488 _____ (NetFilterSDK.com) C:\Windows\system32\Drivers\netfilter.sys
2014-06-11 14:53 - 2014-06-11 14:54 - 00338708 _____ () C:\Users\Technoplan\Downloads\Wohnhaus
2014-06-11 08:20 - 2014-05-28 18:39 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 08:20 - 2014-05-28 18:38 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 08:20 - 2014-05-28 18:33 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 08:20 - 2014-05-28 18:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 08:20 - 2014-05-28 18:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 08:20 - 2014-05-28 18:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-06-11 08:20 - 2014-05-28 18:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 08:20 - 2014-05-28 18:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 08:20 - 2014-05-28 18:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-11 08:20 - 2014-05-28 18:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 08:20 - 2014-05-28 18:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-11 08:20 - 2014-05-28 18:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 08:20 - 2014-05-28 18:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-11 08:20 - 2014-05-28 18:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-06-11 08:20 - 2014-05-28 18:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 08:20 - 2014-05-28 18:29 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 08:20 - 2014-05-28 18:29 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-06-11 08:20 - 2014-05-28 18:29 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-06-11 08:20 - 2014-05-28 18:28 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 08:20 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 08:20 - 2014-04-05 04:42 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 08:20 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 08:20 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-11 08:19 - 2014-05-28 18:48 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 08:19 - 2014-05-28 18:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
==================== One Month Modified Files and Folders =======
2014-07-08 14:34 - 2014-07-08 14:34 - 00001161 _____ () C:\Users\Technoplan\Desktop\checkup.txt
2014-07-08 14:34 - 2014-07-08 14:34 - 00000000 ____D () C:\Users\Technoplan\Desktop\FRST-OlderVersion
2014-07-08 14:34 - 2014-07-01 10:13 - 00018758 _____ () C:\Users\Technoplan\Desktop\FRST.txt
2014-07-08 14:34 - 2014-07-01 10:12 - 01074688 _____ (Farbar) C:\Users\Technoplan\Desktop\FRST.exe
2014-07-08 14:34 - 2014-07-01 10:12 - 00000000 ____D () C:\FRST
2014-07-08 14:29 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-08 14:29 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-08 14:28 - 2009-07-01 08:14 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-08 14:26 - 2009-02-25 15:50 - 00011146 _____ () C:\Users\Technoplan\Documents\plot.log
2014-07-08 13:42 - 2012-04-05 08:15 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-08 09:12 - 2014-07-08 09:12 - 00854390 _____ () C:\Users\Technoplan\Desktop\SecurityCheck.exe
2014-07-08 09:09 - 2014-07-08 09:08 - 02347384 _____ (ESET) C:\Users\Technoplan\Desktop\esetsmartinstaller_deu.exe
2014-07-08 09:05 - 2008-01-21 09:16 - 00007028 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-08 09:04 - 2008-09-29 18:47 - 02097037 _____ () C:\Windows\WindowsUpdate.log
2014-07-08 09:00 - 2014-07-03 13:19 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-08 08:59 - 2009-07-01 08:14 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-08 08:59 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-08 08:58 - 2008-01-21 04:47 - 21486392 _____ () C:\Windows\PFRO.log
2014-07-08 08:57 - 2006-11-02 15:01 - 00032554 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-08 08:37 - 2014-07-03 15:11 - 00000000 ____D () C:\Program Files\SupraSavings
2014-07-03 15:45 - 2014-07-03 15:45 - 00001513 _____ () C:\Users\Technoplan\Desktop\JRT.txt
2014-07-03 15:32 - 2014-07-03 15:32 - 01016261 _____ (Thisisu) C:\Users\Technoplan\Desktop\JRT.exe
2014-07-03 15:10 - 2014-07-03 15:05 - 00000000 ____D () C:\AdwCleaner
2014-07-03 15:10 - 2014-07-01 09:43 - 00000880 _____ () C:\Users\Technoplan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-07-03 15:10 - 2014-07-01 09:43 - 00000850 _____ () C:\Users\Technoplan\Desktop\Search.lnk
2014-07-03 15:10 - 2013-07-08 13:41 - 00000862 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-07-03 15:10 - 2013-07-08 13:41 - 00000850 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-07-03 15:10 - 2012-08-28 08:31 - 00001071 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-03 15:10 - 2012-08-28 08:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-03 15:10 - 2009-02-17 11:57 - 00000989 _____ () C:\Users\Technoplan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-03 15:04 - 2014-07-03 15:04 - 01346519 _____ () C:\Users\Technoplan\Desktop\adwcleaner_3.214.exe
2014-07-03 13:19 - 2014-07-03 13:19 - 00000903 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-03 13:19 - 2014-07-03 13:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-03 13:19 - 2014-07-03 13:19 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-03 13:19 - 2012-08-30 11:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-03 13:16 - 2014-07-03 13:08 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Technoplan\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-03 08:24 - 2014-06-30 13:07 - 00000000 ____D () C:\Program Files\Fraven 1.1
2014-07-02 14:07 - 2014-07-02 14:07 - 00018873 _____ () C:\ComboFix.txt
2014-07-02 14:07 - 2014-07-02 13:47 - 00000000 ____D () C:\Qoobox
2014-07-02 14:02 - 2006-11-02 12:23 - 00000245 _____ () C:\Windows\system.ini
2014-07-02 13:59 - 2013-06-27 13:48 - 00000000 ____D () C:\Windows\erdnt
2014-07-02 13:59 - 2006-11-02 12:22 - 58982400 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-07-02 13:59 - 2006-11-02 12:22 - 46137344 _____ () C:\Windows\system32\config\COMPON~1.bak
2014-07-02 13:59 - 2006-11-02 12:22 - 25952256 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-07-02 13:59 - 2006-11-02 12:22 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-07-02 13:59 - 2006-11-02 12:22 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-07-02 13:59 - 2006-11-02 12:22 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-07-02 13:45 - 2014-07-02 13:45 - 05212874 ____R (Swearware) C:\Users\Technoplan\Desktop\ComboFix.exe
2014-07-02 13:17 - 2014-07-02 13:17 - 00001061 _____ () C:\Users\Technoplan\Desktop\Revo Uninstaller.lnk
2014-07-02 13:17 - 2014-07-02 13:17 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-07-02 13:16 - 2014-07-02 13:16 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Technoplan\Desktop\revosetup95.exe
2014-07-01 15:32 - 2013-06-20 11:34 - 00000000 ____D () C:\Users\Technoplan\AppData\Local\PokerStars.EU
2014-07-01 09:52 - 2014-07-01 09:52 - 00001089 _____ () C:\Users\Public\Desktop\Chica Password Manager 2.0.lnk
2014-07-01 09:52 - 2014-07-01 09:52 - 00000000 ___SD () C:\Users\Technoplan\Documents\Chica Passwords
2014-07-01 09:52 - 2014-07-01 09:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ChicaLogic
2014-07-01 09:52 - 2014-07-01 09:52 - 00000000 ____D () C:\Program Files\ChicaLogic
2014-07-01 09:52 - 2014-07-01 09:52 - 00000000 ____D () C:\Program Files\CB78F643-3729-434F-8C25-F28D15F025F3
2014-06-30 13:32 - 2009-03-17 09:15 - 00000000 ____D () C:\Users\Technoplan\AppData\Local\Google
2014-06-30 13:15 - 2014-06-30 13:15 - 00000000 ____D () C:\ProgramData\TEMP
2014-06-30 13:10 - 2014-06-30 13:10 - 00000000 ____D () C:\Users\Technoplan\AppData\Local\com
2014-06-30 13:10 - 2014-06-30 13:10 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\4B18tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\4AF7tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\4AC8tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\4A98tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\4A58tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\4A29tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\49F9tmp
2014-06-30 13:04 - 2014-06-30 13:04 - 00000000 ____D () C:\Users\Technoplan\Downloads\49D9tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3CC6tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3C96tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3C76tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3C55tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3C26tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3C05tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3BB6tmp
2014-06-30 13:03 - 2014-06-30 13:03 - 00000000 ____D () C:\Users\Technoplan\Downloads\3B87tmp
2014-06-27 08:17 - 2013-07-09 09:22 - 00000000 ____D () C:\Program Files\AskPartnerNetwork
2014-06-25 11:39 - 2014-06-25 09:48 - 00000000 ____D () C:\Users\Technoplan\Desktop\petry
2014-06-25 10:29 - 2014-06-24 09:28 - 00000000 ____D () C:\Users\Technoplan\Desktop\Ball
2014-06-25 09:12 - 2014-06-25 09:11 - 09044888 _____ () C:\Users\Technoplan\Desktop\Abschlussprojekt fertig inkl. Durchbruchplan.zip
2014-06-24 14:16 - 2013-07-09 09:21 - 00097648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-06-24 09:29 - 2014-05-05 09:54 - 00000000 ____D () C:\Users\Public\Documents\Dendrit
2014-06-24 09:20 - 2014-06-24 09:20 - 00469723 _____ () C:\Users\Technoplan\Desktop\Abschlussprojekt elektro Sebastian Ball.zip
2014-06-24 08:09 - 2013-07-08 13:41 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-06-18 09:18 - 2014-06-18 09:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-17 16:39 - 2004-03-25 12:38 - 00002198 _____ () C:\Windows\RBuilder.ini
2014-06-12 21:05 - 2014-06-12 21:05 - 00047488 _____ (NetFilterSDK.com) C:\Windows\system32\Drivers\netfilter.sys
2014-06-11 16:02 - 2013-08-15 17:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-11 16:00 - 2006-11-02 12:24 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-06-11 14:54 - 2014-06-11 14:53 - 00338708 _____ () C:\Users\Technoplan\Downloads\Wohnhaus
Files to move or delete:
====================
C:\Users\Technoplan\ElsterFormular-12.3.2.6814p.exe
Some content of TEMP:
====================
C:\Users\Technoplan\AppData\Local\temp\avgnt.exe
C:\Users\Technoplan\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-08 09:04
==================== End Of Log ============================
--- --- ---