Farbar Service Scanner Version: 17-01-2015
Ran by Dust (administrator) on 23-05-2015 at 10:20:24
Running from "C:\Programme"
Microsoft Windows XP Home Edition Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Policy:
========================
Security Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Other Services:
==============
File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\afd.sys => File is digitally signed
C:\WINDOWS\system32\Drivers\netbt.sys => File is digitally signed
C:\WINDOWS\system32\Drivers\tcpip.sys => File is digitally signed
C:\WINDOWS\system32\Drivers\ipsec.sys => File is digitally signed
C:\WINDOWS\system32\dnsrslvr.dll => File is digitally signed
C:\WINDOWS\system32\ipnathlp.dll => File is digitally signed
C:\WINDOWS\system32\netman.dll => File is digitally signed
C:\WINDOWS\system32\wbem\WMIsvc.dll => File is digitally signed
C:\WINDOWS\system32\srsvc.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\sr.sys => File is digitally signed
C:\WINDOWS\system32\wscsvc.dll => File is digitally signed
C:\WINDOWS\system32\wbem\WMIsvc.dll => File is digitally signed
C:\WINDOWS\system32\wuauserv.dll => File is digitally signed
C:\WINDOWS\system32\qmgr.dll => File is digitally signed
C:\WINDOWS\system32\es.dll => File is digitally signed
C:\WINDOWS\system32\cryptsvc.dll => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
Extra List:
=======
Gpc(4) IPSec(6) irda(3) NetBT(7) PSched(8) Tcpip(5)
0x09000000060000000100000002000000030000000400000005000000090000000700000008000000
IpSec Tag value is correct.
**** End of log ****
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-05-2015 01 (ATTENTION: ====> FRST version is 17 days old and could be outdated)
Ran by Dust (administrator) on DUST on 23-05-2015 10:21:12
Running from C:\Programme
Loaded Profiles: Dust (Available profiles: Dust & eva)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\Antivirus\sched.exe
() C:\Programme\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\Antivirus\avguard.exe
(APN LLC.) C:\Programme\AskPartnerNetwork\Toolbar\apnmcp.exe
(Autodesk, Inc.) C:\Programme\Autodesk\Content Service\Connect.Service.ContentService.exe
(Apple Computer, Inc.) C:\Programme\Bonjour\mDNSResponder.exe
(SafeNet Inc.) C:\WINDOWS\system32\hasplms.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes Anti-Malware\mbam.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Microsoft Corporation) C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Hewlett-Packard) C:\Programme\HP\HP Software Update\hpwuSchd2.exe
(CANON INC.) C:\Programme\Canon\Quick Menu\CNQMMAIN.EXE
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\My Avira\Avira.OE.Systray.exe
(Oracle Corporation) C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
(APN) C:\Programme\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\Antivirus\avgnt.exe
(Skype Technologies S.A.) C:\Programme\Skype\Phone\Skype.exe
(Akamai Technologies, Inc.) C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Akamai\netsession_win.exe
(Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe
(Dropbox, Inc.) C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Dropbox\bin\Dropbox.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\Antivirus\avshadow.exe
(Akamai Technologies, Inc.) C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Akamai\netsession_win.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqbam08.exe
(CANON INC.) C:\Programme\Canon\Quick Menu\CNQMUPDT.EXE
(CANON INC.) C:\Programme\Canon\Quick Menu\CNQMSWCS.EXE
(Microsoft Corporation) C:\Programme\Microsoft Office\OFFICE11\OUTLOOK.EXE
(Microsoft Corporation) C:\Programme\Microsoft Office\OFFICE11\WINWORD.EXE
(Microsoft Corporation) C:\Programme\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Programme\Internet Explorer\iexplore.exe
(APN LLC.) C:\Programme\AskPartnerNetwork\Toolbar\ServiceLocator.exe
(APN LLC.) C:\Programme\AskPartnerNetwork\Toolbar\Toolbar.exe
(Microsoft Corporation) C:\Programme\Internet Explorer\iexplore.exe
(Farbar) C:\Programme\FSS.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [16855552 2007-10-25] (Realtek Semiconductor Corp.)
HKLM\...\Run: [SkyTel] => C:\WINDOWS\SkyTel.EXE [1826816 2007-10-11] (Realtek Semiconductor Corp.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [HP Software Update] => C:\Programme\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM\...\Run: [Autodesk Sync] => C:\Programme\Autodesk\Autodesk Sync\AdSync.exe [383424 2012-02-06] (Autodesk, Inc.)
HKLM\...\Run: [CanonQuickMenu] => C:\Programme\Canon\Quick Menu\CNQMMAIN.EXE [1282632 2013-07-23] (CANON INC.)
HKLM\...\Run: [upt4pc_en_7.exe] => C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\fst_de_69\upt4pc_en_7.exe -runhelper
HKLM\...\Run: [Avira Systray] => C:\Programme\Avira\My Avira\Avira.OE.Systray.exe [164656 2014-08-27] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM\...\Run: [ApnTBMon] => C:\Programme\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1934744 2015-01-31] (APN)
HKLM\...\Run: [avgnt] => C:\Programme\Avira\Antivirus\avgnt.exe [728312 2015-04-16] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Adobe ARM] => C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [Malwarebytes Anti-Exploit] => C:\Programme\Malwarebytes Anti-Exploit\mbae.exe
HKU\S-1-5-21-1275210071-926492609-682003330-1004\...\Run: [Skype] => C:\Programme\Skype\Phone\Skype.exe [17351304 2011-10-13] (Skype Technologies S.A.)
HKU\S-1-5-21-1275210071-926492609-682003330-1004\...\Run: [Akamai NetSession Interface] => C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Akamai\netsession_win.exe [4673432 2014-10-30] (Akamai Technologies, Inc.)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\HP Digital Imaging Monitor.lnk [2009-03-06]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Dokumente und Einstellungen\Dust\Startmenü\Programme\Autostart\Dropbox.lnk [2013-11-27]
ShortcutTarget: Dropbox.lnk -> C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2012-02-07] (Autodesk, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1275210071-926492609-682003330-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:2602;https=127.0.0.1:2602;
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
HKU\S-1-5-21-1275210071-926492609-682003330-1004\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/?gws_rd=ssl
URLSearchHook: HKU\S-1-5-21-1275210071-926492609-682003330-1004 - SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Programme\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.)
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1275210071-926492609-682003330-1004 -> DefaultScope {F81A849A-5230-46C3-97B6-E1155ABFD2AF} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1275210071-926492609-682003330-1004 -> {B757DBB4-5B78-4F4A-8482-1C40A2183B90} URL = hxxp://www.search.ask.com/web?tpid=ORJ-SPE&o=APN11406&pf=V7&p2=^BBE^OSJ000^YY^DE&gct=sb&itbv=12.24.1.51&apn_uid=249BBB60-AEDF-40BE-AC76-F1480E99B6CC&apn_ptnrs=BBE&apn_dtid=^OSJ000^YY^DE&apn_dbr=ie&doi=2015-05-13&trgb=IE&q={searchTerms}&psv=&pt=tb
SearchScopes: HKU\S-1-5-21-1275210071-926492609-682003330-1004 -> {F81A849A-5230-46C3-97B6-E1155ABFD2AF} URL = https://www.google.com/search?q={searchTerms}
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Programme\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06] (Hewlett-Packard Co.)
BHO: Search App by Ask -> {4F524A2D-5350-4500-76A7-7A786E7484D7} -> C:\Programme\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll [2015-01-31] (APN LLC.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Programme\Java\jre1.8.0_45\bin\ssv.dll [2015-05-13] (Oracle Corporation)
BHO: LeapFTP Internet Explorer Hook -> {A5479DA1-7843-43A7-B5C0-BE342C77B629} -> C:\Programme\LeapFTP 3.0\lftpie.dll [2008-07-14] (LeapWare)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10] (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Programme\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-13] (Oracle Corporation)
BHO: No Name -> {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} -> C:\Programme\PicLensIE\cooliris.dll [2009-04-30] (Cooliris Inc.)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Programme\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06] (Hewlett-Packard Co.)
Toolbar: HKLM - Search App by Ask - {4F524A2D-5350-4500-76A7-7A786E7484D7} - C:\Programme\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll [2015-01-31] (APN LLC.)
Toolbar: HKU\S-1-5-21-1275210071-926492609-682003330-1004 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File
Toolbar: HKU\S-1-5-21-1275210071-926492609-682003330-1004 -> Search App by Ask - {4F524A2D-5350-4500-76A7-7A786E7484D7} - C:\Programme\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll [2015-01-31] (APN LLC.)
DPF: {0D9392CD-A784-4FCA-9342-0F75F7D7C8CB} hxxp://www.cltnet.de/login/dplaunch.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2003-07-11] (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2003-07-11] (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2003-07-11] (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2003-07-11] (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2003-07-11] (Microsoft Corporation)
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll [2007-12-28] (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2003-07-11] (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\SYSTEM\OLE DB\msdaipp.dll [2003-07-11] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10] (Skype Technologies S.A.)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
Winsock: Catalog5 04 C:\Programme\Bonjour\mdnsNSP.dll [94208 2006-02-28] (Apple Computer, Inc.)
Winsock: Catalog9 01 C:\Programme\Avira\Antivirus\avsda.dll [507984 2015-05-16] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Programme\Avira\Antivirus\avsda.dll [507984 2015-05-16] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 21 C:\Programme\Avira\Antivirus\avsda.dll [507984 2015-05-16] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Mozilla\Firefox\Profiles\bq0opndw.default
FF NetworkProxy: "no_proxies_on", "*.local"
FF Plugin: @canon.com/EPPEX -> C:\Programme\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Programme\Google\Picasa3\npPicasa3.dll No File
FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\WINDOWS\system32\npDeployJava1.dll [2013-07-09] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Programme\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-13] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Programme\Microsoft Silverlight\npctrl.1.0.30716.0.dll [2008-07-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Programme\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Programme\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin: Adobe Reader -> C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-10-07]
FF Extension: No Name - C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Mozilla\Firefox\Profiles\bq0opndw.default\extensions\{f8353751-55b8-4258-fd48-33ef1876eb2c} [Not Found]
FF Extension: No Name - C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Mozilla\Firefox\Profiles\bq0opndw.default\extensions\CUFCV96103896@VLCZ37079202.com [Not Found]
FF Extension: No Name - C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Mozilla\Firefox\Profiles\bq0opndw.default\extensions\d5c23cb6-d0cf-4815-8acb-cf20d763e92f@gmail.com [Not Found]
FF Extension: No Name - C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Mozilla\Firefox\Profiles\bq0opndw.default\extensions\ff806580-6db3-4c09-ba06-d6caf0e99172@8453cb25-7fef-4ed5-8934-b08be5605617.com [Not Found]
FF Extension: No Name - C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.stunde-des-hoechsten.de/de/gebet/gebetsanliegen-lesen.html", "hxxp://www.google.de/"
CHR Profile: C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-28]
CHR Extension: (Google Drive) - C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-28]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-08]
CHR Extension: (YouTube) - C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-28]
CHR Extension: (Google Search) - C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-28]
CHR Extension: (Skype Click to Call) - C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-06-28]
CHR Extension: (Google Wallet) - C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-28]
CHR Extension: (Gmail) - C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-28]
CHR HKLM\...\Chrome\Extension: [aaaangmfdabjilefmognkgcebjgcojek] - C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\APN\GoogleCRXs\aaaangmfdabjilefmognkgcebjgcojek_7.14.1.0.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Programme\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-10-10]
StartMenuInternet: Chrome.7PJGQCDPPEBVE77SFQGWOPEMSE - C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Chrome\Application\chrome.exe
Opera:
=======
OPR Extension: (video MediaPlayer) - C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Opera Software\Opera Stable\Extensions\dnaojefanpmakfgcaliphepgoiiafmpf [2014-06-28]
OPR Extension: (Fraven 1.1) - C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Opera Software\Opera Stable\Extensions\hcpdbkoonabfhfkeiaanphdfonombbpb [2014-06-28]
OPR Extension: (HDV1.6) - C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Opera Software\Opera Stable\Extensions\jgielablfighaafogapfgpnlieaajbgk [2014-06-28]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 Adobe LM Service; C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2009-03-06] (Adobe Systems) [File not signed]
R2 AdobeActiveFileMonitor4.0; C:\Programme\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe [102400 2005-10-03] () [File not signed]
S2 AntiVirMailService; C:\Programme\Avira\Antivirus\avmailc.exe [825856 2015-04-16] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Programme\Avira\Antivirus\sched.exe [434424 2015-04-16] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Programme\Avira\Antivirus\avguard.exe [434424 2015-04-16] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Programme\Avira\Antivirus\AVWEBGRD.EXE [1186040 2015-04-16] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Programme\AskPartnerNetwork\Toolbar\apnmcp.exe [177560 2015-01-31] (APN LLC.)
R2 Autodesk Content Service; C:\Programme\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.)
S2 Avira.OE.ServiceHost; C:\Programme\Avira\My Avira\Avira.OE.ServiceHost.exe [160048 2014-08-27] (Avira Operations GmbH & Co. KG)
R2 Bonjour Service; C:\Programme\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [File not signed]
S3 FLEXnet Licensing Service; C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1044816 2014-03-29] (Flexera Software, Inc.)
R2 hasplms; C:\WINDOWS\system32\hasplms.exe [4609928 2013-08-09] (SafeNet Inc.)
R3 hpqcxs08; C:\Programme\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Programme\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 MBAMScheduler; C:\Programme\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Programme\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S2 MSSQL$SQLEXPRESS; c:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29178224 2007-02-10] (Microsoft Corporation)
S4 MSSQLServerADHelper; c:\Programme\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45272 2005-10-14] (Microsoft Corporation)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [89136 2003-07-28] (Microsoft Corporation)
S4 SQLBrowser; c:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe [242544 2007-02-10] (Microsoft Corporation)
R2 SQLWriter; c:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe [89968 2007-02-10] (Microsoft Corporation)
R2 TeamViewer8; C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe [4150112 2013-06-13] (TeamViewer GmbH)
S2 gupdate; "C:\Programme\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Programme\Google\Update\GoogleUpdate.exe" /medsvc [X]
S3 gusvc; "C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aksfridge; C:\WINDOWS\System32\DRIVERS\aksfridge.sys [376200 2013-08-09] (SafeNet Inc.)
S3 akshasp; C:\WINDOWS\System32\DRIVERS\akshasp.sys [244040 2013-08-09] (SafeNet Inc.)
S3 akshhl; C:\WINDOWS\System32\DRIVERS\akshhl.sys [53192 2013-08-09] (SafeNet Inc.)
S3 aksusb; C:\WINDOWS\System32\DRIVERS\aksusb.sys [296200 2013-08-09] (SafeNet Inc.)
R2 ASCTRM; C:\WINDOWS\system32\Drivers\ASCTRM.sys [8552 2009-03-05] (Windows (R) 2000 DDK provider)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [107400 2015-04-16] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [136216 2015-04-16] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\System32\DRIVERS\avkmgr.sys [37896 2015-04-16] (Avira Operations GmbH & Co. KG)
S3 BVRPMPR5; C:\WINDOWS\system32\drivers\BVRPMPR5.SYS [49904 2008-06-18] (Avanquest Software) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 DCamUSBSQTECH; C:\WINDOWS\System32\Drivers\SQcaptur.sys [29744 2003-10-28] (Service & Quality Technology.) [File not signed]
R2 hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [608648 2013-08-09] (SafeNet Inc.)
R3 irsir; C:\WINDOWS\System32\DRIVERS\irsir.sys [18688 2001-08-17] (Microsoft Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [119512 2015-05-23] (Malwarebytes Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [57856 2006-07-11] (NVIDIA Corporation)
R0 nvgts; C:\WINDOWS\System32\DRIVERS\nvgts.sys [102400 2007-08-09] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [20480 2006-07-11] (NVIDIA Corporation)
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [28520 2015-04-16] (Avira GmbH)
S3 wanatw; C:\WINDOWS\System32\DRIVERS\wanatw4.sys [33588 2003-01-10] (America Online, Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CFcatchme; \??\C:\ComboFix\CFcatchme.sys [X]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U3 TlntSvr; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-23 10:21 - 2015-05-23 10:21 - 00000000 ____D () C:\FRST
2015-05-22 09:37 - 2015-05-22 09:37 - 00000109 _____ () C:\WINDOWS\nmp.log
2015-05-19 14:15 - 2015-05-23 10:20 - 00002303 _____ () C:\Programme\FSS.txt
2015-05-19 14:14 - 2015-05-19 14:14 - 00415232 _____ (Farbar) C:\Programme\FSS.exe
2015-05-18 09:34 - 2015-05-18 09:34 - 00000657 _____ () C:\Dokumente und Einstellungen\Dust\Desktop\Verknüpfung mit mbae-setup-1.06.1.1019.exe.lnk
2015-05-18 09:33 - 2015-05-18 09:33 - 00000657 _____ () C:\Dokumente und Einstellungen\Dust\Desktop\Verknüpfung mit esetsmartinstaller_deu.exe.lnk
2015-05-18 09:33 - 2015-05-18 09:33 - 00000627 _____ () C:\Dokumente und Einstellungen\Dust\Desktop\Verknüpfung mit AdwCleaner_4.203.exe.lnk
2015-05-16 16:15 - 2015-05-16 16:28 - 00000000 ___HD () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJMIG
2015-05-16 16:14 - 2015-05-16 16:14 - 00001720 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Canon My Image Garden.lnk
2015-05-16 11:25 - 2015-05-16 12:08 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes Anti-Exploit
2015-05-16 11:24 - 2015-05-16 11:24 - 03020968 _____ (Malwarebytes ) C:\Programme\mbae-setup-1.06.1.1019.exe
2015-05-16 11:20 - 2015-05-16 11:20 - 00001804 _____ () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Adobe Reader XI.lnk
2015-05-16 11:20 - 2015-05-16 11:20 - 00001756 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader XI.lnk
2015-05-16 11:16 - 2015-05-16 11:16 - 01126608 _____ (Adobe Systems Incorporated) C:\Programme\reader11xp_de_ra_install.exe
2015-05-16 11:10 - 2015-05-16 11:10 - 00000000 ____D () C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Avira
2015-05-16 11:09 - 2015-05-16 11:09 - 00001701 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Avira Antivirus.lnk
2015-05-16 11:08 - 2015-04-16 15:23 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2015-05-16 11:08 - 2015-04-16 15:23 - 00107400 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2015-05-16 11:08 - 2015-04-16 15:23 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2015-05-16 11:08 - 2015-04-16 15:23 - 00028520 _____ (Avira GmbH) C:\WINDOWS\system32\Drivers\ssmdrv.sys
2015-05-16 11:06 - 2015-05-16 11:06 - 207437104 _____ () C:\Programme\avira_antivirus_de-de.exe
2015-05-14 09:16 - 2015-05-23 10:13 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-05-14 09:16 - 2015-05-14 09:16 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-05-14 09:16 - 2015-05-14 09:16 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-05-13 09:08 - 2015-05-13 09:23 - 00000000 ____D () C:\b99aa6df9624a994d69e
2015-05-13 08:58 - 2015-05-13 08:58 - 00000000 ____D () C:\Programme\AskPartnerNetwork
2015-05-13 08:58 - 2015-05-13 08:58 - 00000000 ____D () C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\AskPartnerNetwork
2015-05-13 08:58 - 2015-05-13 08:58 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AskPartnerNetwork
2015-05-13 08:58 - 2015-05-13 08:58 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\APN
2015-05-13 08:57 - 2013-07-09 19:00 - 00867240 _____ (Oracle Corporation) C:\WINDOWS\system32\npDeployJava1.dll
2015-05-13 08:57 - 2013-07-09 19:00 - 00789416 _____ (Oracle Corporation) C:\WINDOWS\system32\deployJava1.dll
2015-05-13 08:56 - 2015-05-13 08:56 - 00000000 ____D () C:\Programme\Gemeinsame Dateien\Java
2015-05-13 08:55 - 2015-05-13 08:55 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Java
2015-05-13 08:54 - 2015-05-13 08:58 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Oracle
2015-05-13 08:53 - 2015-05-13 08:53 - 00561760 _____ (Oracle Corporation) C:\Programme\JavaSetup8u45.exe
2015-05-12 12:52 - 2015-05-12 12:52 - 00852630 _____ () C:\Programme\SecurityCheck.exe
2015-05-12 10:24 - 2015-05-12 10:24 - 02347384 _____ (ESET) C:\Programme\esetsmartinstaller_deu.exe
2015-05-11 17:37 - 2015-05-22 09:06 - 00000000 ____D () C:\ebay
2015-05-11 17:37 - 2015-05-11 17:37 - 00000000 ____D () C:\Dokumente und Einstellungen\Dust\Eigene Dateien\Updater
2015-05-10 14:52 - 2015-05-10 14:52 - 00000000 ____D () C:\RegBackup
2015-05-10 14:51 - 2015-05-10 14:51 - 02720307 _____ (Thisisu) C:\Programme\JRT.exe
2015-05-10 14:40 - 2015-05-10 14:40 - 02204160 _____ () C:\Programme\AdwCleaner_4.203.exe
2015-05-10 09:26 - 2015-05-10 09:26 - 00002271 _____ () C:\Dokumente und Einstellungen\Dust\Desktop\mbam.txt
2015-05-10 08:35 - 2015-05-23 09:55 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-05-10 08:35 - 2015-05-10 08:35 - 00000791 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-10 08:35 - 2015-05-10 08:35 - 00000000 ____D () C:\Programme\Malwarebytes Anti-Malware
2015-05-10 08:35 - 2015-05-10 08:35 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes Anti-Malware
2015-05-10 08:35 - 2015-04-14 09:37 - 00120024 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-05-10 08:35 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-05-10 08:34 - 2015-05-10 08:34 - 21546080 _____ (Malwarebytes Corporation ) C:\Programme\mbam-setup-2.1.6.1022.exe
2015-05-08 09:55 - 2015-05-13 09:12 - 00000931 _____ () C:\Dokumente und Einstellungen\Dust\Desktop\Revo Uninstaller.lnk
2015-05-08 09:55 - 2015-05-13 09:12 - 00000000 ____D () C:\Programme\VS Revo Group
2015-05-08 09:54 - 2015-05-08 09:54 - 02623656 _____ (VS Revo Group Ltd.) C:\Programme\revosetup95.exe
2015-05-07 12:33 - 2015-05-07 12:36 - 00084189 _____ () C:\Programme\Addition.txt
2015-05-07 12:29 - 2015-05-23 10:22 - 00026956 _____ () C:\Programme\FRST.txt
2015-05-07 12:11 - 2015-05-07 12:11 - 01141248 _____ (Farbar) C:\Programme\FRST.exe
2015-05-07 11:04 - 2015-05-07 11:04 - 00090112 _____ () C:\WINDOWS\Minidump\Mini050715-02.dmp
2015-05-07 10:24 - 2015-05-07 10:24 - 00090112 _____ () C:\WINDOWS\Minidump\Mini050715-01.dmp
2015-05-07 09:55 - 2015-05-07 09:55 - 00000689 _____ () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Opera.lnk
2015-05-07 09:54 - 2015-05-07 09:54 - 32623176 _____ (Opera Software) C:\Programme\Opera_28.0.1750.51_Setup.exe
2015-05-01 12:10 - 2015-05-06 12:24 - 00000000 ____D () C:\video
2015-04-25 10:21 - 2015-05-07 13:32 - 00000000 ____D () C:\harzausflug0415
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-23 10:22 - 2013-07-08 11:04 - 00000000 ____D () C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp
2015-05-23 10:21 - 2009-03-04 13:18 - 00000000 ___RD () C:\Programme
2015-05-23 10:16 - 2011-12-29 17:37 - 00000000 ____D () C:\allewebprojekte
2015-05-23 09:54 - 2009-03-07 09:48 - 00000000 ____D () C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Google
2015-05-23 09:32 - 2014-12-26 18:27 - 00001086 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-23 09:29 - 2010-02-08 13:58 - 02066585 _____ () C:\WINDOWS\WindowsUpdate.log
2015-05-23 09:27 - 2013-11-27 11:31 - 00000000 ___RD () C:\Dokumente und Einstellungen\Dust\Eigene Dateien\Dropbox
2015-05-23 09:26 - 2013-11-27 11:29 - 00000000 ____D () C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Dropbox
2015-05-23 09:23 - 2014-12-26 18:27 - 00001082 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-23 09:23 - 2014-03-22 15:13 - 00000220 _____ () C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Benachrichtigung – Anmeldung.job
2015-05-23 09:23 - 2013-07-08 11:04 - 00000000 ____D () C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\temp
2015-05-23 09:23 - 2009-03-04 13:49 - 00182038 _____ () C:\WINDOWS\system32\nvapps.xml
2015-05-23 09:23 - 2009-03-04 13:34 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-23 09:23 - 2009-03-04 13:20 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-05-23 09:23 - 2009-03-04 13:20 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2015-05-22 17:16 - 2013-12-02 19:26 - 08898664 _____ () C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-1275210071-926492609-682003330-1004-0.dat
2015-05-22 17:16 - 2013-12-02 19:26 - 00338438 _____ () C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat
2015-05-22 17:16 - 2009-03-04 13:37 - 00000300 ___SH () C:\Dokumente und Einstellungen\Dust\ntuser.ini
2015-05-22 17:16 - 2009-03-04 13:37 - 00000000 ____D () C:\Dokumente und Einstellungen\Dust
2015-05-22 17:16 - 2009-03-04 13:34 - 00032108 _____ () C:\WINDOWS\SchedLgU.Txt
2015-05-22 09:50 - 2009-07-23 16:51 - 00002607 _____ () C:\Dokumente und Einstellungen\Dust\Desktop\Microsoft Office Outlook 2003.lnk
2015-05-22 09:37 - 2009-03-04 13:17 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme
2015-05-22 09:04 - 2008-04-14 14:00 - 00000766 _____ () C:\WINDOWS\win.ini
2015-05-22 09:01 - 2009-03-04 13:42 - 00000000 _____ () C:\WINDOWS\system32\nmp.log
2015-05-21 12:18 - 2013-07-05 12:55 - 00000664 _____ () C:\WINDOWS\system32\d3d9caps.dat
2015-05-21 12:01 - 2009-03-04 13:37 - 00000000 ___RD () C:\Dokumente und Einstellungen\Dust\Startmenü\Programme
2015-05-18 09:17 - 2009-03-06 18:14 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Adobe
2015-05-17 17:21 - 2015-02-15 13:40 - 00000000 ____D () C:\bilderpapa2
2015-05-16 16:11 - 2009-03-07 12:35 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Canon Utilities
2015-05-16 11:57 - 2009-03-06 18:45 - 00000000 ____D () C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\Adobe
2015-05-16 11:20 - 2009-03-06 18:45 - 00000000 ____D () C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\Adobe
2015-05-16 11:20 - 2009-03-06 18:14 - 00000000 ____D () C:\Programme\Gemeinsame Dateien\Adobe
2015-05-16 11:19 - 2009-03-06 18:14 - 00000000 ____D () C:\Programme\Adobe
2015-05-16 11:09 - 2013-07-09 19:00 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Avira
2015-05-16 11:07 - 2013-07-09 19:00 - 00000000 ____D () C:\Programme\Avira
2015-05-16 11:07 - 2012-03-11 18:17 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira
2015-05-16 10:58 - 2013-07-09 18:39 - 00002553 _____ () C:\DelFix.txt
2015-05-15 08:47 - 2008-04-14 14:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2015-05-13 14:23 - 2013-07-09 19:25 - 00000000 ____D () C:\Programme\Opera
2015-05-13 09:09 - 2013-07-11 11:56 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-05-13 09:09 - 2009-03-04 14:23 - 137310008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-05-13 08:57 - 2009-03-07 09:46 - 00000000 ____D () C:\Programme\Java
2015-05-13 08:55 - 2013-07-09 19:00 - 00146432 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2015-05-13 08:55 - 2013-07-09 19:00 - 00096352 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2015-05-10 14:43 - 2014-05-03 10:28 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Soft-Now bundle
2015-05-10 14:18 - 2011-03-28 11:46 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2524375$
2015-05-10 09:29 - 2014-06-28 15:24 - 00000000 ____D () C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\com
2015-05-10 08:35 - 2013-07-04 21:03 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
2015-05-09 09:59 - 2013-11-27 11:31 - 00001043 _____ () C:\Dokumente und Einstellungen\Dust\Desktop\Dropbox.lnk
2015-05-09 09:59 - 2013-11-27 11:29 - 00000000 ____D () C:\Dokumente und Einstellungen\Dust\Startmenü\Programme\Dropbox
2015-05-09 09:59 - 2009-03-04 13:37 - 00000000 ___RD () C:\Dokumente und Einstellungen\Dust\Startmenü\Programme\Autostart
2015-05-08 16:04 - 2014-02-04 19:38 - 00000276 _____ () C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2015-05-08 10:20 - 2013-07-04 21:41 - 00529855 _____ () C:\WINDOWS\setupapi.log
2015-05-08 10:15 - 2013-07-08 10:45 - 00000000 ____D () C:\WINDOWS\erdnt
2015-05-07 15:31 - 2011-01-11 21:09 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2015-05-07 11:32 - 2009-03-04 13:29 - 00000000 ____D () C:\WINDOWS\Registration
2015-05-07 11:04 - 2009-10-02 15:33 - 00000000 ____D () C:\WINDOWS\Minidump
==================== Files in the root of some directories =======
2009-04-14 17:30 - 2009-04-14 17:30 - 2063321 _____ (GraphicRegion.com ) C:\Programme\ablerawer14_setup.exe
2009-10-17 13:31 - 2009-10-17 13:31 - 28565216 _____ ( ) C:\Programme\AdbeRdr920_de_DE.exe
2010-02-11 11:33 - 2010-07-07 11:27 - 28534656 _____ ( ) C:\Programme\AdbeRdr930_de_DE.exe
2015-05-07 12:33 - 2015-05-07 12:36 - 0084189 _____ () C:\Programme\Addition.txt
2015-05-10 14:40 - 2015-05-10 14:40 - 2204160 _____ () C:\Programme\AdwCleaner_4.203.exe
2009-03-06 19:10 - 2009-03-06 19:10 - 2708156 _____ () C:\Programme\Apo202.exe
2009-03-11 18:10 - 2009-03-11 18:10 - 2708156 _____ () C:\Programme\Apo202b.exe
2009-03-06 19:11 - 2009-03-06 19:11 - 0441748 _____ () C:\Programme\apo202src.zip
2009-03-06 19:11 - 2009-03-06 19:11 - 0393042 _____ () C:\Programme\Apomap1.exe
2009-03-11 18:09 - 2009-03-11 18:09 - 0393042 _____ () C:\Programme\Apomap1b.exe
2009-03-06 19:11 - 2009-03-06 19:11 - 0596860 _____ () C:\Programme\Apoph101.exe
2009-03-11 18:09 - 2009-03-11 18:09 - 0596860 _____ () C:\Programme\Apoph101b.exe
2009-03-06 21:36 - 2009-03-06 21:36 - 47828912 _____ (ashampoo GmbH & Co. KG ) C:\Programme\ashampoo_photo_commander_7_710_sm.exe
2015-05-16 11:06 - 2015-05-16 11:06 - 207437104 _____ () C:\Programme\avira_antivirus_de-de.exe
2009-11-28 21:20 - 2009-11-28 21:20 - 31066056 _____ () C:\Programme\avira_antivir_personal415_de.exe
2009-11-28 21:23 - 2010-11-18 12:02 - 44151368 _____ () C:\Programme\avira_antivir_personal_de.exe
2013-07-08 12:20 - 2013-07-08 12:21 - 2092792 _____ () C:\Programme\avira_free_antivirus.exe
2010-10-07 12:17 - 2010-10-09 09:33 - 36589669 _____ () C:\Programme\cbuilder_xe_win_esd.zip
2009-05-14 15:35 - 2009-05-14 15:36 - 2707968 _____ () C:\Programme\cooliris-win-iefull-release-1.10.0.25085.en-US.msi
2015-05-12 10:24 - 2015-05-12 10:24 - 2347384 _____ (ESET) C:\Programme\esetsmartinstaller_deu.exe
2009-04-16 18:45 - 2009-04-16 18:45 - 0627297 _____ (Freshworx ) C:\Programme\etopelister-install.exe
2010-05-04 16:28 - 2010-05-04 16:28 - 4076719 _____ () C:\Programme\FileZilla_3.2.7.1_win32-setup.exe
2009-03-06 19:11 - 2009-03-06 19:11 - 0055452 _____ () C:\Programme\flame-chm.zip
2009-03-11 18:10 - 2009-03-11 18:10 - 0055452 _____ () C:\Programme\flame-chmb.zip
2009-03-06 19:15 - 2009-03-06 19:15 - 0039140 _____ () C:\Programme\flamepack7.zip
2009-03-06 21:29 - 2009-03-06 21:29 - 10473064 _____ (IN MEDIA KG ) C:\Programme\fotoworks_setup.exe
2015-05-07 12:11 - 2015-05-07 12:11 - 1141248 _____ (Farbar) C:\Programme\FRST.exe
2015-05-07 12:29 - 2015-05-23 10:22 - 0033883 _____ () C:\Programme\FRST.txt
2015-05-19 14:14 - 2015-05-19 14:14 - 0415232 _____ (Farbar) C:\Programme\FSS.exe
2015-05-19 14:15 - 2015-05-23 10:20 - 0002303 _____ () C:\Programme\FSS.txt
2009-03-06 21:38 - 2009-03-06 21:38 - 16006800 _____ ( ) C:\Programme\gimp-2.6.5-i686-setup.exe
2009-03-19 14:02 - 2009-03-19 14:02 - 6409944 _____ (EXP Systems LLC) C:\Programme\Install_PDFR_v228.exe
2015-05-13 08:53 - 2015-05-13 08:53 - 0561760 _____ (Oracle Corporation) C:\Programme\JavaSetup8u45.exe
2011-04-16 18:22 - 2011-04-16 18:22 - 0885024 _____ (Sun Microsystems, Inc.) C:\Programme\jre-6u24-windows-i586-iftw.exe
2015-05-10 14:51 - 2015-05-10 14:51 - 2720307 _____ (Thisisu) C:\Programme\JRT.exe
2009-03-06 21:01 - 2009-03-06 21:01 - 0154846 _____ () C:\Programme\jubu-flames.rar
2009-03-07 12:09 - 2009-03-07 12:10 - 39235584 _____ () C:\Programme\k4b03dex.exe
2009-03-06 19:05 - 2009-03-06 19:05 - 5062814 _____ (InstallShield Software Corporation) C:\Programme\k620cdex.exe
2009-03-07 12:35 - 2009-03-07 12:35 - 5055560 _____ (InstallShield Software Corporation) C:\Programme\k620cenx.exe
2009-03-06 18:27 - 2009-03-06 18:27 - 32453152 _____ (InstallShield Software Corporation) C:\Programme\K690adex.exe
2009-03-07 11:59 - 2009-03-07 11:59 - 32453152 _____ (InstallShield Software Corporation) C:\Programme\K690adexb.exe
2009-03-07 12:37 - 2009-03-07 12:37 - 32440072 _____ (InstallShield Software Corporation) C:\Programme\K690aenx.exe
2009-03-06 18:32 - 2009-03-06 18:32 - 32440072 _____ (InstallShield Software Corporation) C:\Programme\K690aenxm.exe
2009-03-07 11:56 - 2009-03-07 11:56 - 78327355 _____ () C:\Programme\k8530dex.zip
2009-10-17 15:04 - 2009-10-17 15:04 - 2297244 _____ () C:\Programme\mapserver-5.6.0-beta3.tar.gz
2015-05-16 11:24 - 2015-05-16 11:24 - 3020968 _____ (Malwarebytes ) C:\Programme\mbae-setup-1.06.1.1019.exe
2015-05-10 08:34 - 2015-05-10 08:34 - 21546080 _____ (Malwarebytes Corporation ) C:\Programme\mbam-setup-2.1.6.1022.exe
2015-05-07 09:54 - 2015-05-07 09:54 - 32623176 _____ (Opera Software) C:\Programme\Opera_28.0.1750.51_Setup.exe
2010-10-27 11:01 - 2010-10-27 11:01 - 2288616 _____ (ParetoLogic Inc.) C:\Programme\ParetoLogic FileCure.exe
2010-01-03 16:44 - 2010-01-03 16:44 - 2470416 _____ (ParetoLogic Inc.) C:\Programme\ParetoLogic FileCure_bup_.exe
2010-01-03 16:45 - 2010-01-03 16:45 - 2470416 _____ (ParetoLogic Inc.) C:\Programme\ParetoLogic FileCure_ifo_.exe
2009-05-15 19:51 - 2009-05-15 19:51 - 3485376 _____ (HDRsoft Sarl ) C:\Programme\PhotomatixPro313de.exe
2009-03-06 21:35 - 2009-03-06 21:35 - 9934392 _____ (Google Inc.) C:\Programme\picasa3-setup.exe
2009-04-14 18:05 - 2009-04-14 18:05 - 8862548 _____ () C:\Programme\rawtherapee23.exe
2009-04-08 12:57 - 2009-04-08 12:57 - 11969419 _____ () C:\Programme\rawtherapee24rc2.exe
2015-05-16 11:16 - 2015-05-16 11:16 - 1126608 _____ (Adobe Systems Incorporated) C:\Programme\reader11xp_de_ra_install.exe
2015-05-08 09:54 - 2015-05-08 09:54 - 2623656 _____ (VS Revo Group Ltd.) C:\Programme\revosetup95.exe
2015-05-12 12:52 - 2015-05-12 12:52 - 0852630 _____ () C:\Programme\SecurityCheck.exe
2009-04-16 17:14 - 2009-07-21 20:39 - 18699392 _____ () C:\Programme\setupDE.exe
2011-04-14 12:48 - 2011-04-14 12:48 - 1029000 _____ (Skype Technologies S.A.) C:\Programme\SkypeSetup.exe
2009-04-17 16:43 - 2009-04-17 16:43 - 18458240 _____ () C:\Programme\turbolister.exe
2009-03-07 12:17 - 2009-03-07 12:17 - 32453152 _____ (InstallShield Software Corporation) C:\Programme\zoom browser ex.exe
2009-03-07 20:26 - 2009-03-07 20:26 - 32453152 _____ (InstallShield Software Corporation) C:\Programme\zoombrowser2.exe
2009-03-07 12:36 - 2009-03-07 12:36 - 5055560 _____ (InstallShield Software Corporation) C:\Programme\zoombrw.exe
2009-03-05 17:32 - 2009-03-05 21:01 - 0000070 _____ () C:\Dokumente und Einstellungen\Dust\Anwendungsdaten\wklnhst.dat
2009-10-17 14:28 - 2009-10-22 17:38 - 2183680 _____ () C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\cooliris-win-ie-release-1.10.1.25877.de-DE.msi
2009-07-29 15:09 - 2009-07-29 15:10 - 2119680 _____ () C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\cooliris-win-ie-release-1.11.2.27471.en-US.msi
2009-10-14 11:43 - 2009-10-14 11:43 - 2124288 _____ () C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\cooliris-win-ie-release-1.11.5.29501.en-US.msi
2014-01-05 18:26 - 2014-01-05 18:26 - 0000664 _____ () C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\d3d9caps.dat
2009-03-07 10:11 - 2013-12-31 11:49 - 0014336 _____ () C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2009-05-15 19:54 - 2009-05-15 19:54 - 0000137 _____ () C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
2014-07-19 19:58 - 2014-07-19 19:58 - 0003298 _____ () C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\Anwendungsdaten\recently-used.xbel
Some content of TEMP:
====================
C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp\5kgxuba4.dll
C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp\AcDeltree.exe
C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp\APNSetup.exe
C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp\avgnt.exe
C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp\cf7sq8fl.dll
C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpzc4lib.dll
C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp\e-ovtz0c.dll
C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp\lkjha6i9.dll
C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp\MSETUP4.EXE
C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp\Quarantine.exe
C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp\sqlite3.dll
C:\Dokumente und Einstellungen\Dust\Lokale Einstellungen\temp\x2zacksf.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
--- --- ---
--- --- ---