Floydian | 13.08.2014 10:35 | Hier die logs.
checkup: Code:
Results of screen317's Security Check version 0.99.86
Windows Vista x86 (UAC is enabled)
Out of date service pack!!
Internet Explorer 7 Out of date! ``````````````Antivirus/Firewall Check:``````````````
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````
Out of date HijackThis installed!
Spybot - Search & Destroy
HijackThis 2.0.2
Java(TM) 6 Update 33
Java 7 Update 51
Java(TM) 6 Update 7
Java version out of Date!
Adobe Flash Player 14.0.0.145
Adobe Reader 8 Adobe Reader out of Date!
Mozilla Firefox (31.0)
Google Chrome 35.0.1916.114
Google Chrome 36.0.1985.125 ````````Process Check: objlist.exe by Laurent````````
Windows Defender MSASCui.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamscheduler.exe
Windows Defender MSASCui.exe
OnlineDiagnostic TestManager TestHandler.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast AvastUI.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: % ````````````````````End of Log``````````````````````
Fixlog: Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:13-08-2014
Ran by root at 2014-08-13 11:09:20 Run:1
Running from C:\Users\Ulrike\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
"C:\Users\Ulrike\AppData\Local\VirtualStore\Program Files\Movies Toolbar\Datamngr"
"C:\Users\Ulrike\AppData\Roaming\Mozilla\Firefox\Profiles\5g0nvvjw.default\extensions\{0AF2132C-D508-1D6C-F240-7AAAB6C9E66D}"
"C:\Users\Ulrike\Downloads\m4a-to-mp3-70converter.exe"
cmd: type "C:\Users\Ulrike\AppData\Roaming\Mozilla\Firefox\Profiles\5g0nvvjw.default\prefs.js"
emptytemp:
*****************
C:\Users\Ulrike\AppData\Local\VirtualStore\Program Files\Movies Toolbar\Datamngr => Moved successfully.
C:\Users\Ulrike\AppData\Roaming\Mozilla\Firefox\Profiles\5g0nvvjw.default\extensions\{0AF2132C-D508-1D6C-F240-7AAAB6C9E66D} => Moved successfully.
C:\Users\Ulrike\Downloads\m4a-to-mp3-70converter.exe => Moved successfully.
========= type "C:\Users\Ulrike\AppData\Roaming\Mozilla\Firefox\Profiles\5g0nvvjw.default\prefs.js" =========
# Mozilla User Preferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
*/
user_pref("accessibility.typeaheadfind.flashBar", 0);
user_pref("app.update.lastUpdateTime.addon-background-update-timer", 1407756897);
user_pref("app.update.lastUpdateTime.background-update-timer", 1407756777);
user_pref("app.update.lastUpdateTime.blocklist-background-update-timer", 1407757017);
user_pref("app.update.lastUpdateTime.browser-cleanup-thumbnails", 1407832735);
user_pref("app.update.lastUpdateTime.experiments-update-timer", 1407761478);
user_pref("app.update.lastUpdateTime.microsummary-generator-update-timer", 1340132817);
user_pref("app.update.lastUpdateTime.search-engine-update-timer", 1407832615);
user_pref("app.update.service.errors", 1);
user_pref("browser.cache.disk.capacity", 358400);
user_pref("browser.cache.disk.smart_size.first_run", false);
user_pref("browser.cache.disk.smart_size.use_old_max", false);
user_pref("browser.cache.disk.smart_size_cached_value", 358400);
user_pref("browser.cache.frecency_experiment", 3);
user_pref("browser.download.dir", "C:\\Users\\Ulrike\\Downloads");
user_pref("browser.download.importedFromSqlite", true);
user_pref("browser.download.lastDir", "C:\\Users\\Ulrike\\Pictures");
user_pref("browser.download.manager.alertOnEXEOpen", true);
user_pref("browser.download.panel.shown", true);
user_pref("browser.migration.version", 22);
user_pref("browser.newtabpage.storageVersion", 1);
user_pref("browser.pagethumbnails.storage_version", 3);
user_pref("browser.places.importDefaults", false);
user_pref("browser.places.migratePostDataAnnotations", false);
user_pref("browser.places.smartBookmarksVersion", 7);
user_pref("browser.places.updateRecentTagsUri", false);
user_pref("browser.rights.3.shown", true);
user_pref("browser.safebrowsing.enabled", false);
user_pref("browser.safebrowsing.malware.enabled", false);
user_pref("browser.sessionstore.upgradeBackup.latestBuildID", "20140716183446");
user_pref("browser.slowStartup.averageTime", 0);
user_pref("browser.slowStartup.samples", 0);
user_pref("browser.startup.homepage", "https://www.google.de/");
user_pref("browser.startup.homepage_override.buildID", "20140716183446");
user_pref("browser.startup.homepage_override.mstone", "31.0");
user_pref("browser.syncPromoViewsLeftMap", "{\"passwords\":0}");
user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-page-button\",\"print-button\",\"history-panelmenu\",\"fullscreen-button\",\"find-button\",\"preferences-button\",\"add-ons-button\",\"developer-button\"],\"addon-bar\":[\"addonbar-closebutton\",\"status-bar\"],\"PersonalToolbar\":[\"personal-bookmarks\"],\"nav-bar\":[\"unified-back-forward-button\",\"urlbar-container\",\"reload-button\",\"stop-button\",\"search-container\",\"downloads-button\",\"home-button\",\"bookmarks-menu-button\",\"webrtc-status-button\",\"social-share-button\",\"wrc-toolbar-button\",\"window-controls\"],\"TabsToolbar\":[\"tabbrowser-tabs\",\"new-tab-button\",\"alltabs-button\",\"tabs-closebutton\"],\"toolbar-menubar\":[\"menubar-items\"]},\"seen\":[],\"dirtyAreaCache\":[\"PersonalToolbar\",\"nav-bar\",\"TabsToolbar\",\"toolbar-menubar\",\"PanelUI-contents\",\"addon-bar\"],\"newElementCount\":0}");
user_pref("browser.uitour.whitelist.add.260", "");
user_pref("datareporting.healthreport.lastDataSubmissionFailureTime", "1398878568629");
user_pref("datareporting.healthreport.lastDataSubmissionRequestedTime", "1407756481628");
user_pref("datareporting.healthreport.lastDataSubmissionSuccessfulTime", "1407756483874");
user_pref("datareporting.healthreport.nextDataSubmissionTime", "1407842883874");
user_pref("datareporting.healthreport.service.firstRun", true);
user_pref("datareporting.policy.dataSubmissionPolicyAccepted", true);
user_pref("datareporting.policy.dataSubmissionPolicyAcceptedVersion", 1);
user_pref("datareporting.policy.dataSubmissionPolicyNotifiedTime", "1389099855340");
user_pref("datareporting.policy.dataSubmissionPolicyResponseTime", "1389100005787");
user_pref("datareporting.policy.dataSubmissionPolicyResponseType", "accepted-info-bar-dismissed");
user_pref("datareporting.policy.firstRunTime", "1388412224938");
user_pref("datareporting.sessions.current.activeTicks", 72);
user_pref("datareporting.sessions.current.clean", true);
user_pref("datareporting.sessions.current.firstPaint", 51971);
user_pref("datareporting.sessions.current.main", 45789);
user_pref("datareporting.sessions.current.sessionRestored", 53677);
user_pref("datareporting.sessions.current.startTime", "1407832446651");
user_pref("datareporting.sessions.current.totalTime", 742);
user_pref("datareporting.sessions.currentIndex", 234);
user_pref("datareporting.sessions.previous.230", "{\"s\":1407756406476,\"a\":498,\"t\":4251,\"c\":true,\"m\":7127,\"fp\":12372,\"sr\":12880}");
user_pref("datareporting.sessions.previous.231", "{\"s\":1407761340884,\"a\":148,\"t\":6778,\"c\":true,\"m\":2330,\"fp\":12031,\"sr\":20623}");
user_pref("datareporting.sessions.previous.232", "{\"s\":1407779111934,\"a\":10,\"t\":121,\"c\":true,\"m\":14878,\"fp\":28873,\"sr\":30670}");
user_pref("datareporting.sessions.previous.233", "{\"s\":1407779561607,\"a\":55,\"t\":328,\"c\":true,\"m\":3314,\"fp\":6723,\"sr\":7457}");
user_pref("datareporting.sessions.prunedIndex", 229);
user_pref("devtools.telemetry.tools.opened.version", "{\"DEVTOOLS_WEBCONSOLE_OPENED_PER_USER_FLAG\":\"28.0\"}");
user_pref("dom.mozApps.used", true);
user_pref("extensions.blocklist.pingCountTotal", 335);
user_pref("extensions.blocklist.pingCountVersion", -1);
user_pref("extensions.bootstrappedAddons", "{}");
user_pref("extensions.databaseSchema", 16);
user_pref("extensions.enabledAddons", "wrc%40avast.com:9.0.2016.82,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:31.0");
user_pref("extensions.enabledItems", "wrc@avast.com:7.0.1426,{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11");
user_pref("extensions.getAddons.databaseSchema", 5);
user_pref("extensions.hotfix.lastVersion", "20140527.01.3");
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"c:\\\\Windows\\\\Microsoft.NET\\\\Framework\\\\v3.5\\\\Windows Presentation Foundation\\\\DotNetAssistantExtension\",\"mtime\":1251990138675,\"rdfTime\":1232707720000},\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":1396691575661,\"rdfTime\":1396691557010}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1407760549422,\"rdfTime\":1407760549078}}},{\"name\":\"app-profile\",\"addons\":{\"{0AF2132C-D508-1D6C-F240-7AAAB6C9E66D}\":{\"descriptor\":\"C:\\\\Users\\\\Ulrike\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\5g0nvvjw.default\\\\extensions\\\\{0AF2132C-D508-1D6C-F240-7AAAB6C9E66D}\",\"mtime\":1401121280155,\"rdfTime\":1398506879637},\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"C:\\\\Users\\\\Ulrike\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\5g0nvvjw.default\\\\extensions\\\\{20a82645-c095-46ed-80e3-08825760534b}.xpi\",\"mtime\":1340454796262}}}]");
user_pref("extensions.lastAppVersion", "31.0");
user_pref("extensions.lastPlatformVersion", "31.0");
user_pref("extensions.pendingOperations", false);
user_pref("extensions.shownSelectionUI", true);
user_pref("extensions.update.notifyUser", false);
user_pref("extensions.wrc.RulesVersion", "");
user_pref("extensions.wrc.SearchRules./v1/update/rule/foo.bar.style", "some style");
user_pref("extensions.wrc.SearchRules./v1/update/rule/foo.bar.url", "testik.bb");
user_pref("extensions.wrc.SearchRules.atlas.cz.style", ".WRCN {display:none} .results-list .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.atlas.cz.url", "^http\\:\\/\\/searchatlas\\.centrum\\.cz\\/.+");
user_pref("extensions.wrc.SearchRules.atlas.cz\":{.style", ".WRCN {display:none} .results-list .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.atlas.cz\":{.url", "^http\\\\:\\\\/\\\\/searchatlas\\\\.centrum\\\\.cz\\\\/.+");
user_pref("extensions.wrc.SearchRules.atlas.sk.style", ".WRCN {display:none} .katalogSponsorItem .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.atlas.sk.url", "^http\\:\\/\\/hladaj\\.atlas\\.sk\\/.+");
user_pref("extensions.wrc.SearchRules.baidu.com.style", ".WRCN {display:none} .result .f .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.baidu.com.url", "^http\\:\\/\\/www\\.baidu\\.com\\/.*");
user_pref("extensions.wrc.SearchRules.bing.com.style", ".WRCN {display:none} .sb_tlst .WRCN, .sp_pss .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.bing.com.url", "^http(s)?\\:\\/\\/www\\.bing\\.com\\/(.)*");
user_pref("extensions.wrc.SearchRules.centrum.cz.style", ".WRCN {display:none} .results-list h3 > .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.centrum.cz.url", "^http(s)?\\:\\/\\/search\\.centrum\\.cz\\/(.)*");
user_pref("extensions.wrc.SearchRules.centrum.sk.style", ".WRCN {display:none} .katalogSponsorItem .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.centrum.sk.url", "^http\\:\\/\\/search\\.centrum\\.sk\\/.+");
user_pref("extensions.wrc.SearchRules.delicious.com.style", ".WRCN {display:none} .taggedlink + .WRCN, .data .full-url .WRCN, .content .link .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.delicious.com.url", "^http\\:\\/\\/(www\\.)?delicious\\.com\\/(.)*");
user_pref("extensions.wrc.SearchRules.dmoz.org.style", ".WRCN {display:none} ol.site li .WRCN{display:inline !important; background: url(\"IMAGE\") right no-repeat} ol.site li .ref .WRCN {display:none!important}");
user_pref("extensions.wrc.SearchRules.dmoz.org.url", "^http\\:\\/\\/www\\.dmoz\\.org\\/search(.)+");
user_pref("extensions.wrc.SearchRules.excite.com.style", ".WRCN {display:none} .searchResult .resultTitlePane .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.excite.com.url", "^http\\:\\/\\/msxml\\.excite\\.com\\/search\\/.*");
user_pref("extensions.wrc.SearchRules.gazeta.pl.style", ".WRCN {display:none} .results-index HEADER .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.gazeta.pl.url", "^http\\:\\/\\/szukaj\\.gazeta\\.pl\\/.+");
user_pref("extensions.wrc.SearchRules.google.com.style", ".WRCN {display:none} .r .WRCN, .osl .WRCN, .bc .WRCN, .fc .WRCN, #rhsline ol .WRCN {display:inline; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.google.com.url", "^http(s)?\\:\\/\\/((.)+\\.)?google\\.(com|[a-z\\.]{2,})\\/(.)*");
user_pref("extensions.wrc.SearchRules.interia.pl.style", ".WRCN {display:none} .row .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.interia.pl.url", "^http\\:\\/\\/(www\\.)?google\\.interia\\.pl\\/szukaj\\/.+");
user_pref("extensions.wrc.SearchRules.onet.pl.style", ".WRCN {display:none} #main .link .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.onet.pl.url", "^http\\:\\/\\/szukaj\\.onet\\.pl\\/.+");
user_pref("extensions.wrc.SearchRules.paginegialle.it.style", ".WRCN {display:none} .lnkwww + .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.paginegialle.it.url", "^http\\:\\/\\/www\\.paginegialle\\.it\\/pgol\\/.+");
user_pref("extensions.wrc.SearchRules.public.avast.com.style", ".WRCN {display:inline; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.public.avast.com.url", "^http(s)?\\:\\/\\/public\\.avast\\.com\\/(.)*");
user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .b-serp__list .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.rambler.ru.url", "^http\\:\\/\\/nova\\.rambler\\.ru\\/.+");
user_pref("extensions.wrc.SearchRules.scroogle.org.style", "a + .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat} {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.scroogle.org.url", "^http\\:\\/\\/www\\.scroogle\\.org\\/.*");
user_pref("extensions.wrc.SearchRules.seznam.cz.style", ".WRCN {display:none} #results .WRCN, .sklik-title > .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.seznam.cz.url", "^http(s)?\\:\\/\\/search\\.seznam\\.cz\\/(.)*");
user_pref("extensions.wrc.SearchRules.sky.com.style", ".WRCN {display:none} #results h3 .WRCN, #sponsored_top h3 .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.sky.com.url", "^http\\:\\/\\/search\\.sky\\.com/.+");
user_pref("extensions.wrc.SearchRules.slashdot.org.style", ".WRCN {display:none} .body i .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.slashdot.org.url", "^http\\:\\/\\/slashdot\\.org\\/.*");
user_pref("extensions.wrc.SearchRules.stackoverflow.com.style", ".WRCN {display:none} .post-text .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}\"}");
user_pref("extensions.wrc.SearchRules.stackoverflow.com.url", "^http\\:\\/\\/stackoverflow\\.com\\/.+");
user_pref("extensions.wrc.SearchRules.terra.com.br.style", ".WRCN {display:none} #searchResultsDiv .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.terra.com.br.url", "^http\\:\\/\\/buscador\\.terra\\.com\\.br\\/.+");
user_pref("extensions.wrc.SearchRules.tiscali.it.style", ".WRCN {display:none} .katalogSponsorItem .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.tiscali.it.url", "^http\\:\\/\\/search\\.tiscali\\.it\\/.+");
user_pref("extensions.wrc.SearchRules.uol.com.br.style", ".WRCN {display:none} #results dt .WRCN, #results .link .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat} #results .link .similar .WRCN {display: none!important}");
user_pref("extensions.wrc.SearchRules.uol.com.br.url", "^http\\:\\/\\/(.\\.)?busca\\.uol\\.com\\.br\\/.+");
user_pref("extensions.wrc.SearchRules.virgilio.it.style", ".WRCN {display:none} .record .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat} .risultati .record .sponsor + .WRCN {display: none!important}");
user_pref("extensions.wrc.SearchRules.virgilio.it.url", "^http\\:\\/\\/ricerca\\.virgilio\\.it\\/.+");
user_pref("extensions.wrc.SearchRules.virginmedia.com.style", ".WRCN {display:none} .result .title + .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.virginmedia.com.url", "^http\\:\\/\\/search\\.virginmedia\\.com\\/.+");
user_pref("extensions.wrc.SearchRules.whereis.com.style", ".WRCN {display:none} .priority_url .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.whereis.com.url", "^http\\:\\/\\/www\\.whereis\\.com\\/.*");
user_pref("extensions.wrc.SearchRules.wp.pl.style", ".WRCN {display:none} .res .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.wp.pl.url", "^http\\:\\/\\/szukaj\\.wp\\.pl\\/.+");
user_pref("extensions.wrc.SearchRules.yahoo.com.style", ".WRCN {display:none} .sm-hd .WRCN, .sm-links .WRCN, .res h3 > .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.yahoo.com.url", "^http(s)?\\:\\/\\/((.)+\\.)?search\\.yahoo\\.com\\/(.)*");
user_pref("extensions.wrc.SearchRules.yandex.ru.style", ".WRCN {display:none} .b-serp-item__title-link + .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.yandex.ru.url", "^http\\:\\/\\/yandex\\.ru\\/.+");
user_pref("extensions.wrc.SearchRules.yell.com.style", ".WRCN {display:none} .advert-content .WRCN, .other-cta .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat} .advert-content .star + .WRCN, .advert-content .logoImg + .WRCN, .other-cta .shareLink + .WRCN {display: none!important}");
user_pref("extensions.wrc.SearchRules.yell.com.url", "^http\\:\\/\\/www\\.yell\\.com\\/.+");
user_pref("extensions.wrc.SearchRules.zoznam.sk.style", ".WRCN {display:none} .box_content .link_right .link_title + .WRCN, .gsc-title .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
user_pref("extensions.wrc.SearchRules.zoznam.sk.url", "^http\\:\\/\\/www\\.zoznam\\.sk\\/.+");
user_pref("font.internaluseonly.changed", true);
user_pref("gecko.buildID", "20140716183446");
user_pref("gecko.mstone", "31.0");
user_pref("general.useragent.extra.microsoftdotnet", "(.NET CLR 3.5.30729)");
user_pref("idle.lastDailyNotification", 1407760018);
user_pref("intl.charsetmenu.browser.cache", "windows-1252, ISO-8859-15, ISO-8859-1, us-ascii, UTF-8");
user_pref("network.cookie.prefsMigrated", true);
user_pref("pdfjs.migrationVersion", 2);
user_pref("pdfjs.previousHandler.alwaysAskBeforeHandling", true);
user_pref("pdfjs.previousHandler.preferredAction", 4);
user_pref("places.database.lastMaintenance", 1407756482);
user_pref("places.history.expiration.transient_current_max_pages", 53632);
user_pref("plugin.disable_full_page_plugin_for_types", "application/pdf");
user_pref("plugin.importedState", true);
user_pref("print.print_printer", "Canon iP1600");
user_pref("print.printer_Canon_iP1600.print_bgcolor", false);
user_pref("print.printer_Canon_iP1600.print_bgimages", false);
user_pref("print.printer_Canon_iP1600.print_command", "");
user_pref("print.printer_Canon_iP1600.print_downloadfonts", false);
user_pref("print.printer_Canon_iP1600.print_edge_bottom", 0);
user_pref("print.printer_Canon_iP1600.print_edge_left", 0);
user_pref("print.printer_Canon_iP1600.print_edge_right", 0);
user_pref("print.printer_Canon_iP1600.print_edge_top", 0);
user_pref("print.printer_Canon_iP1600.print_evenpages", true);
user_pref("print.printer_Canon_iP1600.print_footercenter", "");
user_pref("print.printer_Canon_iP1600.print_footerleft", "&PT");
user_pref("print.printer_Canon_iP1600.print_footerright", "&D");
user_pref("print.printer_Canon_iP1600.print_headercenter", "");
user_pref("print.printer_Canon_iP1600.print_headerleft", "&T");
user_pref("print.printer_Canon_iP1600.print_headerright", "&U");
user_pref("print.printer_Canon_iP1600.print_in_color", true);
user_pref("print.printer_Canon_iP1600.print_margin_bottom", "0.5");
user_pref("print.printer_Canon_iP1600.print_margin_left", "0.5");
user_pref("print.printer_Canon_iP1600.print_margin_right", "0.5");
user_pref("print.printer_Canon_iP1600.print_margin_top", "0.5");
user_pref("print.printer_Canon_iP1600.print_oddpages", true);
user_pref("print.printer_Canon_iP1600.print_orientation", 0);
user_pref("print.printer_Canon_iP1600.print_pagedelay", 500);
user_pref("print.printer_Canon_iP1600.print_paper_data", 9);
user_pref("print.printer_Canon_iP1600.print_paper_height", " 11,00");
user_pref("print.printer_Canon_iP1600.print_paper_size_type", 0);
user_pref("print.printer_Canon_iP1600.print_paper_size_unit", 1);
user_pref("print.printer_Canon_iP1600.print_paper_width", " 8,50");
user_pref("print.printer_Canon_iP1600.print_reversed", false);
user_pref("print.printer_Canon_iP1600.print_scaling", " 1,00");
user_pref("print.printer_Canon_iP1600.print_shrink_to_fit", true);
user_pref("print.printer_Canon_iP1600.print_to_file", false);
user_pref("print.printer_Canon_iP1600.print_to_filename", "");
user_pref("print.printer_Canon_iP1600.print_unwriteable_margin_bottom", 0);
user_pref("print.printer_Canon_iP1600.print_unwriteable_margin_left", 0);
user_pref("print.printer_Canon_iP1600.print_unwriteable_margin_right", 0);
user_pref("print.printer_Canon_iP1600.print_unwriteable_margin_top", 0);
user_pref("privacy.clearOnShutdown.cookies", false);
user_pref("privacy.clearOnShutdown.sessions", false);
user_pref("privacy.cpd.offlineApps", true);
user_pref("privacy.sanitize.migrateFx3Prefs", true);
user_pref("privacy.sanitize.timeSpan", 0);
user_pref("security.warn_entering_weak", false);
user_pref("security.warn_entering_weak.show_once", false);
user_pref("security.warn_submit_insecure", false);
user_pref("security.warn_submit_insecure.show_once", false);
user_pref("security.warn_viewing_mixed", false);
user_pref("security.warn_viewing_mixed.show_once", false);
user_pref("services.sync.clients.lastSync", "0");
user_pref("services.sync.clients.lastSyncLocal", "0");
user_pref("services.sync.declinedEngines", "");
user_pref("services.sync.globalScore", 0);
user_pref("services.sync.migrated", true);
user_pref("services.sync.nextSync", 0);
user_pref("services.sync.tabs.lastSync", "0");
user_pref("services.sync.tabs.lastSyncLocal", "0");
user_pref("storage.vacuum.last.index", 0);
user_pref("storage.vacuum.last.places.sqlite", 1407760020);
user_pref("toolkit.startup.last_success", 1407832492);
user_pref("toolkit.telemetry.previousBuildID", "20140716183446");
user_pref("toolkit.telemetry.prompted", 2);
user_pref("toolkit.telemetry.rejected", true);
user_pref("urlclassifier.keyupdatetime.https://sb-ssl.google.com/safebrowsing/newkey", 1297517042);
user_pref("xpinstall.whitelist.add", "");
user_pref("xpinstall.whitelist.add.103", "");
user_pref("xpinstall.whitelist.add.180", "");
user_pref("xpinstall.whitelist.add.36", "");
========= End of CMD: =========
EmptyTemp: => Removed 2 GB temporary data.
The system needed a reboot.
==== End of Fixlog ====
FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:13-08-2014
Ran by root (administrator) on VISTA-SARAH on 13-08-2014 11:30:03
Running from C:\Users\Ulrike\Desktop
Platform: Microsoft® Windows Vista™ Home Premium (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Windows\System32\PSIService.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files\Cyberlink\Shared files\RichVideo.exe
(Apple Inc.) D:\Eigene Dateien Sarah\iTunes\iTunesHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Fujitsu Siemens Computers) C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-4103437458-4055112347-3955121511-1000\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-4103437458-4055112347-3955121511-1000\...\Run: [MBPlayer] => C:\Program Files\MB application\MBPlayer.exe [48640 2006-12-19] (MusicBrigade)
HKU\S-1-5-21-4103437458-4055112347-3955121511-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation)
HKU\S-1-5-21-4103437458-4055112347-3955121511-1000\...\Run: [SpybotSD TeaTimer] => C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-4103437458-4055112347-3955121511-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-4103437458-4055112347-3955121511-1000\...\Run: [EA Core] => C:\Program Files\Electronic Arts\EADM\Core.exe [3325952 2009-03-28] (Electronic Arts)
HKU\S-1-5-21-4103437458-4055112347-3955121511-1000\...\Run: [Logitech Vid] => "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
HKU\S-1-5-21-4103437458-4055112347-3955121511-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-4103437458-4055112347-3955121511-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-4103437458-4055112347-3955121511-1000\...\MountPoints2: {53ba2e18-7129-11de-a368-0019dbf9a6d2} - F:\LaunchU3.exe -a
HKU\S-1-5-21-4103437458-4055112347-3955121511-1002\...\Run: [msnmsgr] => C:\Program Files\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation)
HKU\S-1-5-21-4103437458-4055112347-3955121511-1002\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation)
HKU\S-1-5-21-4103437458-4055112347-3955121511-1002\...\Run: [UpgradeChecker] => C:\Users\Ulrike\AppData\Roaming\Apple\{4918B296-3A37-4B77-BD5B-BBF282120CD2}\UpgradeChecker.exe
HKU\S-1-5-21-4103437458-4055112347-3955121511-1002\...\Run: [iLivid] => "C:\Users\Ulrike\AppData\Local\iLivid\iLivid.exe" -autorun
HKU\S-1-5-21-4103437458-4055112347-3955121511-1002\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-4103437458-4055112347-3955121511-1002\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-4103437458-4055112347-3955121511-1002\...\MountPoints2: {4439ad29-ed98-11df-a55a-0019dbf9a6d2} - E:\USBAutoRun.exe
HKU\S-1-5-21-4103437458-4055112347-3955121511-1002\...\MountPoints2: {a8ec11a8-fb76-11e3-b93a-0019dbf9a6d2} - E:\MotorolaDeviceManagerSetup.exe -a
HKU\S-1-5-21-4103437458-4055112347-3955121511-1002\...\MountPoints2: {c28635ed-43dc-11df-b1b5-0019dbf9a6d2} - E:\Startme.exe
HKU\S-1-5-21-4103437458-4055112347-3955121511-1002\...\MountPoints2: {f0b9cc8f-ad66-11dc-83a4-806e6f6e6963} - V:\Autorun.exe
Startup: C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
ShortcutTarget: Logitech . Produktregistrierung.lnk -> C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe (No File)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
GroupPolicyUsers\S-1-5-21-4103437458-4055112347-3955121511-1003\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-4103437458-4055112347-3955121511-1001\User: Group Policy restriction detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.google.de/
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {B6E35D9F-85C8-4246-9E98-90FAA4ABA14E} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {F9956A95-CA9F-475D-9D72-5A4504AA37B6} URL = hxxp://www.google.de/search?q={searchTerms}
BHO: Adobe PDF Reader -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} hxxp://cdn.scan.onecare.live.com/resource/download/scanner/de-de/wlscctrl2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\..\Interfaces\{5E7022F2-13CB-4FBB-B1E7-A00289EF29EA}: [NameServer]80.69.100.138,141.1.1.1
FireFox:
========
FF ProfilePath: C:\Users\root\AppData\Roaming\Mozilla\Firefox\Profiles\w4fwmrab.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> D:\Eigene Dateien Sarah\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Wortliste von hxxp://tkltrans.sf.net (alte und neue deutsche Rechtschreibung) - C:\Users\root\AppData\Roaming\Mozilla\Firefox\Profiles\w4fwmrab.default\Extensions\de-DE-comb@dictionaries.addons.mozilla.org [2008-10-03]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\root\AppData\Roaming\Mozilla\Firefox\Profiles\w4fwmrab.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2011-02-11]
FF Extension: Skype extension for Firefox - C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED} [2014-08-11]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-08-11]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-16]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-03-04]
Chrome:
=======
CHR HomePage:
CHR Extension: (Google Docs) - C:\Users\root\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-26]
CHR Extension: (Google Wallet) - C:\Users\root\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-26]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-04-05]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-05] (AVAST Software)
S3 FirebirdServerMAGIXInstance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 ProtexisLicensing; c:\Windows\system32\PSIService.exe [174656 2006-11-02] () [File not signed]
R2 RichVideo; C:\Program Files\Cyberlink\Shared files\RichVideo.exe [244904 2008-06-27] () [File not signed]
R2 TestHandler; C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [204800 2006-12-08] (Fujitsu Siemens Computers) [File not signed]
S3 UPnPService; C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [544768 2006-12-14] (Magix AG) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-04-05] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2014-04-05] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-04-05] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [776976 2014-04-05] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [411552 2014-04-05] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2014-04-05] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180760 2014-04-05] ()
R3 FET5X86V; C:\Windows\System32\DRIVERS\fetnd5bv.sys [42496 2007-04-17] (VIA Technologies, Inc. )
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc. )
S4 JRAID; C:\Windows\system32\drivers\jraid.sys [48256 2007-06-13] (JMicron Technology Corp.)
S3 LVPrcMon; C:\Windows\system32\drivers\LVPrcMon.sys [16768 2005-12-09] () [File not signed]
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-08-12] (Malwarebytes Corporation)
S4 viamraid; C:\Windows\system32\drivers\viamraid.sys [102912 2006-11-08] (VIA Technologies inc,.ltd)
R0 ViBus; C:\Windows\System32\DRIVERS\ViBus.sys [16896 2007-03-26] (VIA Technologies, Inc.)
R0 ViPrt; C:\Windows\System32\DRIVERS\ViPrt.sys [52224 2007-03-26] (VIA Technologies, Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 Lvckap; \??\C:\Windows\system32\drivers\Lvckap.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 PID_0928; system32\DRIVERS\LV561AV.SYS [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-13 11:30 - 2014-08-13 11:30 - 00016832 _____ () C:\Users\Ulrike\Desktop\FRST.txt
2014-08-13 11:09 - 2014-08-13 11:09 - 00000000 ____D () C:\Users\Ulrike\Desktop\FRST-OlderVersion
2014-08-13 11:04 - 2014-08-13 11:01 - 00001461 _____ () C:\Users\Ulrike\Desktop\checkup.txt
2014-08-13 11:01 - 2014-08-13 11:01 - 00001461 _____ () C:\Users\root\Desktop\checkup.txt
2014-08-13 10:48 - 2014-08-13 10:48 - 00854410 _____ () C:\Users\Ulrike\Desktop\SecurityCheck.exe
2014-08-12 20:24 - 2014-08-12 20:24 - 00000000 ____D () C:\Program Files\ESET
2014-08-12 20:19 - 2014-08-12 20:18 - 02347384 _____ (ESET) C:\Users\Ulrike\Desktop\esetsmartinstaller_deu.exe
2014-08-12 20:18 - 2014-08-12 20:18 - 02347384 _____ (ESET) C:\Users\Ulrike\Downloads\esetsmartinstaller_deu.exe
2014-08-12 20:10 - 2014-08-12 20:10 - 00000949 _____ () C:\Users\Ulrike\Desktop\JRT.txt
2014-08-12 20:09 - 2014-08-12 20:09 - 00000949 _____ () C:\Users\root\Desktop\JRT.txt
2014-08-12 19:47 - 2014-08-12 19:47 - 00000000 ____D () C:\Users\root\AppData\Roaming\AVAST Software
2014-08-12 11:03 - 2014-08-12 11:03 - 00000000 ____D () C:\Windows\ERUNT
2014-08-12 11:01 - 2014-08-12 10:53 - 00004330 _____ () C:\Users\Ulrike\Desktop\AdwCleaner[S0].txt
2014-08-12 10:51 - 2014-08-12 10:52 - 00000000 ____D () C:\c13e67303da74dbaeca1
2014-08-12 10:51 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-08-12 10:49 - 2014-08-12 10:53 - 00000000 ____D () C:\AdwCleaner
2014-08-12 10:42 - 2014-08-12 10:42 - 01016261 _____ (Thisisu) C:\Users\Ulrike\Desktop\JRT.exe
2014-08-12 10:41 - 2014-08-12 10:42 - 01016261 _____ (Thisisu) C:\Users\Ulrike\Downloads\JRT.exe
2014-08-12 10:40 - 2014-08-12 10:38 - 01366203 _____ () C:\Users\Ulrike\Desktop\adwcleaner_3.304.exe
2014-08-12 10:38 - 2014-08-12 10:38 - 01366203 _____ () C:\Users\Ulrike\Downloads\adwcleaner_3.304.exe
2014-08-11 14:57 - 2014-08-11 19:52 - 00091802 _____ () C:\Users\Ulrike\Downloads\Addition.txt
2014-08-11 14:55 - 2014-08-13 11:30 - 00000000 ____D () C:\FRST
2014-08-11 14:55 - 2014-08-11 19:52 - 00026178 _____ () C:\Users\Ulrike\Downloads\FRST.txt
2014-08-11 14:53 - 2014-08-13 11:09 - 01092096 _____ (Farbar) C:\Users\Ulrike\Desktop\FRST.exe
2014-08-11 14:35 - 2014-08-11 14:35 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-08-11 13:58 - 2014-08-11 13:58 - 00001921 _____ () C:\Users\Ulrike\Desktop\malware.txt
2014-08-11 11:25 - 2014-08-12 19:50 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-11 11:25 - 2014-08-11 11:25 - 00000905 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-11 11:25 - 2014-08-11 11:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-11 11:24 - 2014-08-11 11:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-11 11:24 - 2014-08-11 11:24 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-08-11 11:24 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-11 11:24 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-11 11:24 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-11 11:21 - 2014-08-11 11:21 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ulrike\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-09 12:08 - 2014-08-09 12:08 - 00155432 _____ () C:\Windows\Minidump\Mini080914-01.dmp
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-13 11:31 - 2014-08-13 11:30 - 00016832 _____ () C:\Users\Ulrike\Desktop\FRST.txt
2014-08-13 11:30 - 2014-08-11 14:55 - 00000000 ____D () C:\FRST
2014-08-13 11:30 - 2007-12-19 15:07 - 00000418 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{562793F0-D950-4A92-BFFB-D396560F5ECA}.job
2014-08-13 11:30 - 2007-12-18 15:43 - 00000418 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{2F7ADF65-47B0-4D3C-A955-AFA893897013}.job
2014-08-13 11:27 - 2009-12-25 16:58 - 00000000 ____D () C:\Users\Ulrike\Tracing
2014-08-13 11:26 - 2014-04-05 11:53 - 00001090 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-13 11:26 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-13 11:26 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-13 11:25 - 2007-10-17 15:56 - 00244790 _____ () C:\Windows\PFRO.log
2014-08-13 11:25 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-13 11:24 - 2007-12-18 14:48 - 01490653 _____ () C:\Windows\WindowsUpdate.log
2014-08-13 11:24 - 2006-11-02 15:01 - 00032620 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-08-13 11:09 - 2014-08-13 11:09 - 00000000 ____D () C:\Users\Ulrike\Desktop\FRST-OlderVersion
2014-08-13 11:09 - 2014-08-11 14:53 - 01092096 _____ (Farbar) C:\Users\Ulrike\Desktop\FRST.exe
2014-08-13 11:01 - 2014-08-13 11:04 - 00001461 _____ () C:\Users\Ulrike\Desktop\checkup.txt
2014-08-13 11:01 - 2014-08-13 11:01 - 00001461 _____ () C:\Users\root\Desktop\checkup.txt
2014-08-13 10:54 - 2012-07-25 13:31 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-13 10:48 - 2014-08-13 10:48 - 00854410 _____ () C:\Users\Ulrike\Desktop\SecurityCheck.exe
2014-08-13 10:39 - 2014-04-05 11:53 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-12 20:24 - 2014-08-12 20:24 - 00000000 ____D () C:\Program Files\ESET
2014-08-12 20:22 - 2006-11-02 12:33 - 01461736 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-12 20:18 - 2014-08-12 20:19 - 02347384 _____ (ESET) C:\Users\Ulrike\Desktop\esetsmartinstaller_deu.exe
2014-08-12 20:18 - 2014-08-12 20:18 - 02347384 _____ (ESET) C:\Users\Ulrike\Downloads\esetsmartinstaller_deu.exe
2014-08-12 20:10 - 2014-08-12 20:10 - 00000949 _____ () C:\Users\Ulrike\Desktop\JRT.txt
2014-08-12 20:09 - 2014-08-12 20:09 - 00000949 _____ () C:\Users\root\Desktop\JRT.txt
2014-08-12 19:51 - 2014-02-28 10:08 - 00000680 _____ () C:\Users\Ulrike\AppData\Local\d3d9caps.dat
2014-08-12 19:50 - 2014-08-11 11:25 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-12 19:50 - 2007-12-29 17:23 - 00000416 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{D0316E42-18F8-4AD3-98B5-BC660DCACB02}.job
2014-08-12 19:49 - 2014-04-05 11:54 - 00001969 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-12 19:48 - 2009-11-02 15:51 - 00000000 ____D () C:\Users\root\AppData\Roaming\Skype
2014-08-12 19:47 - 2014-08-12 19:47 - 00000000 ____D () C:\Users\root\AppData\Roaming\AVAST Software
2014-08-12 11:03 - 2014-08-12 11:03 - 00000000 ____D () C:\Windows\ERUNT
2014-08-12 10:53 - 2014-08-12 11:01 - 00004330 _____ () C:\Users\Ulrike\Desktop\AdwCleaner[S0].txt
2014-08-12 10:53 - 2014-08-12 10:49 - 00000000 ____D () C:\AdwCleaner
2014-08-12 10:52 - 2014-08-12 10:51 - 00000000 ____D () C:\c13e67303da74dbaeca1
2014-08-12 10:50 - 2013-09-04 14:35 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-12 10:42 - 2014-08-12 10:42 - 01016261 _____ (Thisisu) C:\Users\Ulrike\Desktop\JRT.exe
2014-08-12 10:42 - 2014-08-12 10:41 - 01016261 _____ (Thisisu) C:\Users\Ulrike\Downloads\JRT.exe
2014-08-12 10:38 - 2014-08-12 10:40 - 01366203 _____ () C:\Users\Ulrike\Desktop\adwcleaner_3.304.exe
2014-08-12 10:38 - 2014-08-12 10:38 - 01366203 _____ () C:\Users\Ulrike\Downloads\adwcleaner_3.304.exe
2014-08-11 19:52 - 2014-08-11 14:57 - 00091802 _____ () C:\Users\Ulrike\Downloads\Addition.txt
2014-08-11 19:52 - 2014-08-11 14:55 - 00026178 _____ () C:\Users\Ulrike\Downloads\FRST.txt
2014-08-11 19:42 - 2012-06-23 14:29 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-08-11 14:35 - 2014-08-11 14:35 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-08-11 13:58 - 2014-08-11 13:58 - 00001921 _____ () C:\Users\Ulrike\Desktop\malware.txt
2014-08-11 11:54 - 2012-07-25 13:31 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-08-11 11:54 - 2011-08-08 01:08 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-08-11 11:25 - 2014-08-11 11:25 - 00000905 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-11 11:25 - 2014-08-11 11:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-11 11:24 - 2014-08-11 11:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-11 11:24 - 2014-08-11 11:24 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-08-11 11:21 - 2014-08-11 11:21 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ulrike\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-09 12:08 - 2014-08-09 12:08 - 00155432 _____ () C:\Windows\Minidump\Mini080914-01.dmp
2014-08-09 12:08 - 2009-05-17 17:12 - 156135202 _____ () C:\Windows\MEMORY.DMP
2014-08-09 12:08 - 2009-05-17 17:12 - 00000000 ____D () C:\Windows\Minidump
2014-08-08 18:19 - 2007-12-25 15:10 - 00000848 ___SH () C:\Windows\system32\KGyGaAvL.sys
2014-08-05 09:20 - 2009-10-02 20:26 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-13 10:39
==================== End Of Log ============================ --- --- ---
--- --- --- |