Log-Analyse und Auswertung: mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen?
Hallo liebe Helfer,

ich versuche grade den Laptop meiner Schwester "aufzuräumen", dabei sind mir die MapsGalaxy Toolbar und MindSpark Toolbar Platform Plugin Stub aufgefallen. Habe versucht mit Avast- MapsGalaxy zu entfernen. Es wird zwar deaktiviert, aber ist trotzdem noch auf dem System und lässt sich nicht entfernen.

Ausserdem kommt mir die Toolbar MindSpark komisch vor? Laut Google ist diese Datei eine Dynamic Link Library. Aber da stand für Windows XP und hier läuft und lief immer nur Windows Vista? Ist diese Datei verdächtig? ich konnte hierzu keine klare Antwort finden.

Bitte könnt Ihr mir helfen da reinezumachen? Was kann ich machen um die loszuwerden?

Ich hab nach Anweisung die Logs erstellt. Ich hoffe ich habe alles richtig gemacht...

mfg zazfan
Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.05.03 17:31:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\strasseb\Downloads\trojaner board software\OTL.exe PRC - [2013.05.02 01:33:29 | 004,858,456 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe PRC - [2013.05.02 01:33:29 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe PRC - [2013.04.23 09:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe PRC - [2013.04.09 11:57:52 | 002,853,320 | ---- | M] (Mister Group) -- C:\Programme\System Explorer\SystemExplorer.exe PRC - [2013.03.14 04:40:22 | 001,103,768 | ---- | M] (Spotify Ltd) -- C:\Users\strasseb\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe PRC - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.11.25 06:13:10 | 000,567,256 | ---- | M] (Mister Group) -- C:\Programme\System Explorer\service\SystemExplorerService.exe PRC - [2012.09.07 17:30:34 | 000,002,560 | ---- | M] () -- C:\Programme\Secure Banking\sbservice.exe PRC - [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2008.05.02 03:44:08 | 000,805,392 | ---- | M] (Logitech, Inc.) -- C:\Programme\Logitech\SetPoint\SetPoint.exe PRC - [2008.05.02 03:40:56 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Programme\Common Files\Logishrd\KHAL2\KHALMNPR.exe PRC - [2008.01.19 09:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe PRC - [2007.09.15 10:29:10 | 000,102,400 | ---- | M] (Synaptics, Inc.) -- C:\Programme\Synaptics\SynTP\SynTPStart.exe PRC - [2007.09.05 13:09:54 | 001,620,520 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTStackServer.exe PRC - [2007.09.05 13:09:54 | 000,727,592 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe ========== Modules (No Company Name) ========== MOD - [2012.09.07 17:30:34 | 000,002,560 | ---- | M] () -- C:\Programme\Secure Banking\sbservice.exe MOD - [2012.09.07 17:30:22 | 000,016,384 | ---- | M] () -- C:\Programme\Secure Banking\SecureBanking.dll MOD - [2012.09.05 20:49:54 | 000,008,704 | ---- | M] () -- C:\Programme\Secure Banking\funcs.dll MOD - [2010.02.12 10:37:50 | 000,633,696 | ---- | M] () -- C:\Programme\Ashampoo\Ashampoo WinOptimizer 6\ContextHandler.dll MOD - [2007.09.30 19:34:52 | 000,345,384 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLTinyDB.dll MOD - [2007.09.30 19:34:42 | 000,255,384 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLCapEngine.dll MOD - [2007.09.30 19:34:42 | 000,120,208 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLSchMgr.dll MOD - [2007.09.30 19:34:42 | 000,038,184 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLCapSvcps.dll MOD - [2007.09.30 19:33:32 | 000,066,856 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\common\MCEMediaStatus.dll MOD - [2007.09.05 12:52:04 | 000,389,120 | ---- | M] () -- C:\Windows\System32\btwhidcs.dll MOD - [2007.08.14 15:43:46 | 006,365,184 | ---- | M] () -- C:\Programme\Common Files\LightScribe\QtGui4.dll MOD - [2007.07.12 13:55:52 | 000,131,072 | ---- | M] () -- C:\Programme\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll MOD - [2007.07.12 13:55:28 | 001,581,056 | ---- | M] () -- C:\Programme\Common Files\LightScribe\QtCore4.dll ========== Services (SafeList) ========== SRV - [2013.05.02 01:33:29 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2013.04.23 09:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8) SRV - [2013.04.20 15:10:36 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.04.12 18:45:36 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.11.25 06:13:10 | 000,567,256 | ---- | M] (Mister Group) [On_Demand | Running] -- C:\Programme\System Explorer\service\SystemExplorerService.exe -- (SystemExplorerHelpService) SRV - [2009.08.24 22:16:36 | 000,406,016 | ---- | M] (mst software GmbH, Germany) [On_Demand | Stopped] -- C:\Programme\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe -- (DfSdkS) SRV - [2008.05.02 03:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2008.01.19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2008.01.19 09:33:39 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2007.03.05 10:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIMMP) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIM) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\D91F.tmp -- (MEMSWEEP2) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2013.05.02 16:52:41 | 000,174,664 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm) DRV - [2013.05.02 01:34:09 | 000,765,736 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2013.05.02 01:34:09 | 000,368,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP) DRV - [2013.05.02 01:34:09 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2013.05.02 01:34:09 | 000,049,376 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt) DRV - [2013.05.02 01:34:08 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2013.05.02 01:34:08 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2013.05.02 01:34:07 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2013.03.07 01:33:22 | 000,021,576 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswKbd.sys -- (aswKbd) DRV - [2012.11.28 19:49:00 | 000,025,088 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\teamviewervpn.sys -- (teamviewervpn) DRV - [2009.10.03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009.09.05 16:55:36 | 001,183,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2008.03.04 02:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService) DRV - [2008.02.29 04:13:46 | 000,028,944 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt) DRV - [2008.02.29 04:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt) DRV - [2008.02.29 04:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt) DRV - [2007.10.18 06:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio) DRV - [2007.09.10 00:12:28 | 000,176,640 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CHDART.sys -- (HdAudAddService) DRV - [2007.07.11 10:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid) DRV - [2007.06.18 17:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr) DRV - [2007.03.21 22:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp) DRV - [2007.03.07 04:15:58 | 001,059,112 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD) DRV - [2007.02.24 14:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk) DRV - [2007.02.16 23:50:32 | 000,012,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu) DRV - [2007.01.23 16:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=Pavilion&pf=laptop IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=Pavilion&pf=laptop IE - HKLM\..\SearchScopes,DefaultScope = {ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803} IE - HKLM\..\SearchScopes\{ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de IE - HKLM\..\SearchScopes\{F91A88AB-7B29-4D0B-A874-A26BC37F3536}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = {ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803} IE - HKCU\..\SearchScopes\{29E9DFA0-F97D-4A9F-A8CE-E6F3784FBCCE}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=E90B559C-A755-4EC7-AF6F-B80BF6701273&apn_sauid=2E1EB563-DCD3-4CA3-925E-73B9F7DA0BDF IE - HKCU\..\SearchScopes\{ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de IE - HKCU\..\SearchScopes\{F91A88AB-7B29-4D0B-A874-A26BC37F3536}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Google" FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.order.1: "Google" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/firefox" FF - prefs.js..extensions.enabledAddons: %7B0538E3E3-7E9B-4d49-8831-A227C80A7AD3%7D:2.2.2 FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0 FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.68 FF - prefs.js..extensions.enabledAddons: %7B6bdc61ae-7b80-44a3-9476-e1d121ec2238%7D:0.85 FF - prefs.js..extensions.enabledAddons: %7B1A2D0EC4-75F5-4c91-89C4-3656F6E44B68%7D:0.5.4 FF - prefs.js..extensions.enabledAddons: %7B19503e42-ca3c-4c27-b1e2-9cdb2170ee34%7D: FF - prefs.js..extensions.enabledAddons: %7B1018e4d6-728f-4b20-ad56-37578a4de76b%7D:4.2.8 FF - prefs.js..extensions.enabledAddons: %7B0b457cAA-602d-484a-8fe7-c1d894a011ba%7D:0.98.31 FF - prefs.js..extensions.enabledAddons: isreaditlater%40ideashower.com:3.0.1 FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1488 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1 FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}: FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}: FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=" FF - prefs.js..network.proxy.autoconfig_url: "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20((url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1%20%26%26%20url.indexOf('s3.amazonaws.com')%20%3D%3D%20-1%20%26%26%20url.indexOf('ping.chartbeat.net')%20%3D%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000%3B%20PROXY%20ab-us06.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF - prefs.js..network.proxy.type: 2 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@MapsGalaxy_39.com/Plugin: C:\Program Files\MapsGalaxy_39\bar\1.bin\NP39Stub.dll (MindSpark) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\39ffxtbr@MapsGalaxy_39.com: C:\Program Files\MapsGalaxy_39\bar\1.bin [2013.05.01 23:18:23 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.05.03 15:47:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 18:45:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.05.03 11:13:32 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.04.04 21:08:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.04.29 09:12:45 | 000,000,000 | ---D | M] [2010.09.02 21:06:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Extensions [2010.09.02 21:06:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2013.05.03 15:34:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions [2012.10.09 08:16:54 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2013.04.28 18:23:12 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2013.04.28 18:23:06 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} [2013.05.01 01:39:19 | 000,000,000 | ---D | M] (HTTPS-Everywhere) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\https-everywhere@eff(86).org [2008.09.07 17:25:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Sunbird\Profiles\1mckrlaz.default\extensions [2013.04.28 18:23:14 | 000,223,719 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\isreaditlater@ideashower.com.xpi [2013.04.28 16:40:49 | 000,262,896 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\jid0-9XfBwUWnvPx4wWsfBWMCm4Jj69E@jetpack.xpi [2013.04.28 16:52:25 | 000,370,423 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013.04.28 16:50:56 | 000,581,999 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\uriloader@pdf.js.xpi [2013.04.28 18:23:04 | 000,350,097 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2013.04.28 18:23:03 | 000,087,920 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2013.04.28 18:23:03 | 000,073,384 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{6bdc61ae-7b80-44a3-9476-e1d121ec2238}.xpi [2013.04.28 18:23:03 | 000,532,430 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013.04.28 16:43:14 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013.04.28 18:23:02 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2012.05.04 15:40:46 | 000,002,333 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\askcom.xml [2013.04.29 13:09:11 | 000,002,402 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\bingp.xml [2012.12.02 14:41:43 | 000,009,650 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\my-web-search.xml [2013.04.29 10:08:37 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.04.12 18:45:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2013.05.03 15:47:41 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2009.09.05 11:29:12 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2013.04.12 18:45:37 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.03.18 17:18:29 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.08 08:33:12 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.03.18 17:18:29 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.03.18 17:18:29 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.03.18 17:18:29 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.03.18 17:18:29 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR - homepage: hxxp://mega.co.nz/ CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\pdf.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\\npGoogleUpdate3.dll CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\MapsGalaxy_39\bar\1.bin\NP39Stub.dll CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll O1 HOSTS File: ([2012.05.04 18:52:50 | 000,442,787 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: localhost O1 - Hosts: ::1 localhost O1 - Hosts: www.007guard.com O1 - Hosts: 007guard.com O1 - Hosts: 008i.com O1 - Hosts: www.008k.com O1 - Hosts: 008k.com O1 - Hosts: www.00hq.com O1 - Hosts: 00hq.com O1 - Hosts: 010402.com O1 - Hosts: www.032439.com O1 - Hosts: 032439.com O1 - Hosts: www.0scan.com O1 - Hosts: 0scan.com O1 - Hosts: 1000gratisproben.com O1 - Hosts: www.1000gratisproben.com O1 - Hosts: 1001namen.com O1 - Hosts: www.1001namen.com O1 - Hosts: www.100888290cs.com O1 - Hosts: 100888290cs.com O1 - Hosts: 100sexlinks.com O1 - Hosts: www.100sexlinks.com O1 - Hosts: www.10sek.com O1 - Hosts: 10sek.com O1 - Hosts: 1-2005-search.com O1 - Hosts: 15216 more lines... O2 - BHO: (no name) - {1e91a655-bb4b-4693-a05e-2edebc4c9d89} - No CLSID value found. O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (no name) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [SynTPStart] C:\Programme\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [SecureBanking] C:\Programme\Secure Banking\SecureBanking.exe (Secure Banking) O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\strasseb\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = FF 00 00 00 [binary data] O8 - Extra context menu item: Alles mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlall.htm File not found O8 - Extra context menu item: Auswahl mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlselected.htm File not found O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Datei mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dllink.htm File not found O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O8 - Extra context menu item: Videos mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlfvideo.htm File not found O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O13 - gopher Prefix: missing O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0CC7C804-C27F-46A2-861A-AAF879867857}: DhcpNameServer = O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2005.09.11 17:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.05.03 17:21:40 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Template [2013.05.03 16:12:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2013.05.03 16:11:40 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA% [2013.05.03 16:11:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013.05.03 15:48:13 | 000,029,816 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2013.05.03 15:48:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2013.05.03 15:48:12 | 000,368,944 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013.05.03 15:48:09 | 000,049,760 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2013.05.03 15:48:07 | 000,056,080 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013.05.03 15:48:06 | 000,765,736 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013.05.03 15:48:03 | 000,066,336 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013.05.03 15:46:59 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2013.05.03 14:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software(0) [2013.05.01 01:32:52 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Documents\wichtige thunderbird passphrase [2013.04.29 14:00:10 | 000,000,000 | ---D | C] -- C:\Program Files\Backup Manager [2013.04.29 13:59:42 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\FNET [2013.04.29 13:58:19 | 000,000,000 | ---D | C] -- C:\Program Files\Password Protection Manager [2013.04.29 13:57:31 | 000,000,000 | ---D | C] -- C:\Program Files\FAT32 Formatter [2013.04.29 03:44:31 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Free Download Manager [2013.04.29 03:20:04 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\ImgBurn [2013.04.29 03:18:29 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\vlc [2013.04.29 03:15:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2013.04.29 03:14:05 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN [2013.04.29 03:12:03 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\IrfanView [2013.04.29 03:12:02 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView [2013.04.29 03:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe [2013.04.29 03:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2013.04.29 02:51:52 | 000,000,000 | ---D | C] -- C:\Users\strasseb\.DVDslideshowGUI [2013.04.29 02:51:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter [2013.04.29 02:51:30 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter [2013.04.29 02:51:30 | 000,000,000 | ---D | C] -- C:\Program Files\Haali [2013.04.29 02:50:56 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GUI for dvdauthor [2013.04.29 02:50:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GUI for dvdauthor [2013.04.29 02:50:50 | 000,000,000 | ---D | C] -- C:\Program Files\GUI for dvdauthor [2013.04.29 02:50:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AvsP [2013.04.29 02:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\AvsP [2013.04.29 02:49:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn [2013.04.29 02:49:49 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn [2013.04.29 02:49:04 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 [2013.04.29 02:49:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 [2013.04.29 02:49:00 | 000,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5 [2013.04.29 02:47:45 | 000,000,000 | ---D | C] -- C:\Program Files\DVD slideshow GUI [2013.04.29 02:47:33 | 007,760,687 | ---- | C] (Boraxsoft) -- C:\Users\strasseb\AppData\Roaming\SetupGFD.exe [2013.04.29 02:47:11 | 005,514,668 | ---- | C] (LIGHTNING UK!) -- C:\Users\strasseb\AppData\Roaming\Imgburn.exe [2013.04.29 02:46:51 | 005,082,084 | ---- | C] (The Public) -- C:\Users\strasseb\AppData\Roaming\Avisynth.exe [2013.04.29 00:48:35 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Desktop\Tools für überprüfungen [2013.04.29 00:15:22 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\gnupg [2013.04.29 00:07:42 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GNU Privacy Guard [2013.04.29 00:07:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GNU Privacy Guard [2013.04.29 00:07:39 | 000,000,000 | ---D | C] -- C:\Program Files\GNU [2013.04.28 23:42:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2013.04.28 18:50:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SystemExplorerDisabled [2013.04.28 18:09:02 | 000,025,088 | ---- | C] (TeamViewer GmbH) -- C:\Windows\System32\drivers\teamviewervpn.sys [2013.04.28 18:08:56 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer [2013.04.28 17:52:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos [2013.04.28 17:52:29 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos [2013.04.28 17:33:06 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Desktop\HP Drucker [2013.04.28 16:17:00 | 000,000,000 | ---D | C] -- C:\Stinger_Quarantine [2013.04.28 16:14:15 | 000,000,000 | ---D | C] -- C:\Program Files\stinger [2013.04.28 16:13:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure Banking [2013.04.28 16:12:59 | 000,000,000 | ---D | C] -- C:\Program Files\Secure Banking [2013.04.28 16:08:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2013.04.28 16:08:16 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2013.04.28 15:25:27 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\TeamViewer [2013.04.28 15:10:16 | 000,000,000 | ---D | C] -- C:\ProgramData\SystemExplorer [2013.04.28 15:10:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Explorer [2013.04.28 15:10:02 | 000,000,000 | ---D | C] -- C:\Program Files\System Explorer [2013.04.12 18:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox ========== Files - Modified Within 30 Days ========== [2013.05.06 12:51:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.05.06 12:45:48 | 000,632,530 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.05.06 12:45:48 | 000,599,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.05.06 12:45:48 | 000,127,566 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.05.06 12:45:48 | 000,105,202 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.05.06 12:42:13 | 000,000,163 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini [2013.05.06 12:41:29 | 000,032,156 | ---- | M] () -- C:\ProgramData\nvModes.001 [2013.05.06 12:41:14 | 000,032,156 | ---- | M] () -- C:\ProgramData\nvModes.dat [2013.05.06 12:40:44 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013.05.06 12:40:44 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013.05.06 12:40:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.05.06 12:40:26 | 3220,144,128 | -HS- | M] () -- C:\hiberfil.sys [2013.05.06 12:39:35 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2013.05.03 17:39:43 | 000,000,000 | ---- | M] () -- C:\Users\strasseb\defogger_reenable [2013.05.03 17:39:06 | 000,000,795 | ---- | M] () -- C:\Users\strasseb\Desktop\Defogger.exe - Verknüpfung.lnk [2013.05.03 17:38:05 | 000,000,811 | ---- | M] () -- C:\Users\strasseb\Desktop\gmer_2.1.19163.exe - Verknüpfung.lnk [2013.05.03 17:37:35 | 000,000,750 | ---- | M] () -- C:\Users\strasseb\Desktop\OTL.exe - Verknüpfung.lnk [2013.05.03 17:21:56 | 000,002,653 | ---- | M] () -- C:\Users\strasseb\Desktop\Microsoft Works-Tabellenkalkulation.lnk [2013.05.03 17:21:37 | 000,000,000 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\wklnhst.dat [2013.05.03 17:21:26 | 000,002,032 | ---- | M] () -- C:\Users\strasseb\Desktop\Microsoft Works-Textverarbeitung.lnk [2013.05.03 17:10:02 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.05.03 16:50:49 | 000,000,373 | ---- | M] () -- C:\Users\strasseb\Desktop\Bilder - Verknüpfung.lnk [2013.05.03 16:10:52 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf [2013.05.03 15:58:34 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2013.05.03 15:48:13 | 000,001,829 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.05.03 15:31:24 | 000,000,762 | ---- | M] () -- C:\Users\strasseb\Documents\Meine freigegebenen Ordner.lnk [2013.05.03 15:16:16 | 000,350,944 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.05.03 13:49:11 | 000,008,268 | ---- | M] () -- C:\Users\strasseb\AppData\Local\d3d9caps.dat [2013.05.02 16:52:41 | 000,174,664 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys [2013.05.02 01:34:09 | 000,765,736 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013.05.02 01:34:09 | 000,368,944 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013.05.02 01:34:09 | 000,056,080 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013.05.02 01:34:09 | 000,049,376 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013.05.02 01:34:08 | 000,066,336 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013.05.02 01:34:08 | 000,049,760 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2013.05.02 01:34:07 | 000,029,816 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2013.05.02 01:33:35 | 000,041,664 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2013.05.02 01:33:27 | 000,229,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2013.04.29 03:15:02 | 000,000,859 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk [2013.04.29 03:12:08 | 000,000,807 | ---- | M] () -- C:\Users\Public\Desktop\IrfanView.lnk [2013.04.29 03:03:07 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2013.04.29 02:51:41 | 000,034,936 | ---- | M] () -- C:\Windows\System32\uninstHelixYUV.exe [2013.04.29 02:48:31 | 000,000,902 | ---- | M] () -- C:\Users\strasseb\Desktop\DVD slideshow GUI.lnk [2013.04.29 02:47:45 | 007,760,687 | ---- | M] (Boraxsoft) -- C:\Users\strasseb\AppData\Roaming\SetupGFD.exe [2013.04.29 02:47:33 | 005,243,208 | ---- | M] ( ) -- C:\Users\strasseb\AppData\Roaming\AvsP.exe [2013.04.29 02:47:23 | 001,357,348 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\MatroskaSplitter.exe [2013.04.29 02:47:20 | 000,117,723 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\yuvcodecs-1.3.exe [2013.04.29 02:47:19 | 005,514,668 | ---- | M] (LIGHTNING UK!) -- C:\Users\strasseb\AppData\Roaming\Imgburn.exe [2013.04.29 02:47:11 | 005,082,084 | ---- | M] (The Public) -- C:\Users\strasseb\AppData\Roaming\Avisynth.exe [2013.04.29 02:45:06 | 000,000,671 | ---- | M] () -- C:\Users\strasseb\Desktop\Download - Verknüpfung.lnk [2013.04.28 22:16:16 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2013.04.28 21:10:55 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.04.28 21:10:55 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.04.28 18:09:08 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.04.28 16:34:11 | 002,335,270 | ---- | M] () -- C:\Windows\System32\85636D9.mht [2013.04.28 16:33:26 | 002,335,270 | ---- | M] () -- C:\Windows\System32\a0687E5.mht [2013.04.28 14:27:35 | 000,027,620 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\nvModes.001 [2013.04.10 20:19:30 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk ========== Files Created - No Company Name ========== [2013.05.03 17:39:43 | 000,000,000 | ---- | C] () -- C:\Users\strasseb\defogger_reenable [2013.05.03 17:38:05 | 000,000,811 | ---- | C] () -- C:\Users\strasseb\Desktop\gmer_2.1.19163.exe - Verknüpfung.lnk [2013.05.03 17:37:35 | 000,000,750 | ---- | C] () -- C:\Users\strasseb\Desktop\OTL.exe - Verknüpfung.lnk [2013.05.03 17:36:42 | 000,000,795 | ---- | C] () -- C:\Users\strasseb\Desktop\Defogger.exe - Verknüpfung.lnk [2013.05.03 17:21:56 | 000,002,653 | ---- | C] () -- C:\Users\strasseb\Desktop\Microsoft Works-Tabellenkalkulation.lnk [2013.05.03 17:21:37 | 000,000,000 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\wklnhst.dat [2013.05.03 17:21:26 | 000,002,032 | ---- | C] () -- C:\Users\strasseb\Desktop\Microsoft Works-Textverarbeitung.lnk [2013.05.03 17:10:02 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.05.03 16:50:49 | 000,000,373 | ---- | C] () -- C:\Users\strasseb\Desktop\Bilder - Verknüpfung.lnk [2013.05.03 16:10:52 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf [2013.05.03 15:48:13 | 000,001,829 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.05.03 15:48:05 | 000,174,664 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys [2013.05.03 15:48:04 | 000,049,376 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013.05.03 15:31:24 | 000,000,762 | ---- | C] () -- C:\Users\strasseb\Documents\Meine freigegebenen Ordner.lnk [2013.05.03 13:59:46 | 3220,144,128 | -HS- | C] () -- C:\hiberfil.sys [2013.04.29 04:10:41 | 000,350,944 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2013.04.29 03:15:02 | 000,000,859 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2013.04.29 03:12:08 | 000,000,807 | ---- | C] () -- C:\Users\Public\Desktop\IrfanView.lnk [2013.04.29 03:03:07 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2013.04.29 03:03:07 | 000,001,892 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2013.04.29 02:51:40 | 000,034,936 | ---- | C] () -- C:\Windows\System32\uninstHelixYUV.exe [2013.04.29 02:49:52 | 000,001,662 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk [2013.04.29 02:48:31 | 000,000,902 | ---- | C] () -- C:\Users\strasseb\Desktop\DVD slideshow GUI.lnk [2013.04.29 02:47:23 | 005,243,208 | ---- | C] ( ) -- C:\Users\strasseb\AppData\Roaming\AvsP.exe [2013.04.29 02:47:20 | 001,357,348 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\MatroskaSplitter.exe [2013.04.29 02:47:19 | 000,117,723 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\yuvcodecs-1.3.exe [2013.04.29 02:45:06 | 000,000,671 | ---- | C] () -- C:\Users\strasseb\Desktop\Download - Verknüpfung.lnk [2013.04.28 22:16:16 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2013.04.28 18:09:08 | 000,000,967 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk [2013.04.28 18:09:08 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.04.28 16:34:11 | 002,335,270 | ---- | C] () -- C:\Windows\System32\85636D9.mht [2013.04.28 16:33:26 | 002,335,270 | ---- | C] () -- C:\Windows\System32\a0687E5.mht [2013.04.28 14:50:53 | 000,032,156 | ---- | C] () -- C:\ProgramData\nvModes.dat [2013.04.28 14:50:53 | 000,032,156 | ---- | C] () -- C:\ProgramData\nvModes.001 [2013.01.11 22:13:51 | 000,000,104 | ---- | C] () -- C:\Users\strasseb\Internet - Verknüpfung.lnk [2011.09.15 02:11:16 | 001,048,576 | ---- | C] () -- C:\Windows\System32\syndata.bin [2008.10.27 18:56:57 | 000,008,268 | ---- | C] () -- C:\Users\strasseb\AppData\Local\d3d9caps.dat [2008.10.27 14:01:05 | 000,004,096 | -H-- | C] () -- C:\Users\strasseb\AppData\Local\keyfile3.drm [2008.08.17 09:41:40 | 000,027,620 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\nvModes.001 [2008.08.16 15:10:56 | 000,027,620 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\nvModes.dat [2008.08.15 20:00:51 | 000,008,192 | ---- | C] () -- C:\Users\strasseb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2012.07.25 18:15:42 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Ashampoo [2012.07.25 17:16:31 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Ashampoo Slideshow Studio Elements [2012.06.02 16:17:20 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\EAC [2013.04.29 13:59:42 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\FNET [2013.05.03 12:25:59 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Free Download Manager [2013.04.29 00:58:54 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\gnupg [2010.08.20 11:37:13 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Image Zone Express [2013.04.29 03:20:04 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\ImgBurn [2013.04.29 03:12:03 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\IrfanView [2008.09.07 19:00:01 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Printer Info Cache [2013.04.28 15:38:51 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Spotify [2013.04.29 01:46:19 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\TeamViewer [2013.05.03 17:21:40 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Template [2010.09.02 21:06:21 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Thunderbird [2008.09.07 16:09:44 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\WildTangent ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2 < End of report > Geändert von zazfan (06.05.2013 um 14:05 Uhr) Grund: logs einfügen |
![]() | #2 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Hallo,
__________________Kannst du die Logfiles bitte nicht anhängen (das erschwert mir das Auswerten massiv), sondern deren Inhalt direkt innerhalb von Codetags einfügen: [code]Inhalt Logfile[/code]. Falls die Logs zu gross sind, dann (und nur dann) in ein zip-Archiv (nicht *.7z) packen und anhängen. Danke.
__________________ |
![]() | #3 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Ok, dann versuch mal das:
__________________Schritt 1 Downloade Dir bitte ![]()
Schritt 2 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ |
![]() | #4 |
Hallo Leo,

danke für die schnelle Hilfe.

Anbei die angeforderten Logs:
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000..\Run: [SecureBanking] C:\Programme\Secure Banking\SecureBanking.exe (Secure Banking) O4 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000..\Run: [Spotify Web Helper] C:\Users\strasseb\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) O4 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O7 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O7 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = FF 00 00 00 [binary data] O8 - Extra context menu item: Alles mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlall.htm File not found O8 - Extra context menu item: Auswahl mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlselected.htm File not found O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Datei mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dllink.htm File not found O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O8 - Extra context menu item: Videos mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlfvideo.htm File not found O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O13 - gopher Prefix: missing O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet) O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet) O15 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\..Trusted Ranges: Range1 ([http] in Local intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0CC7C804-C27F-46A2-861A-AAF879867857}: DhcpNameServer = O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2005.09.11 17:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.05.03 17:21:40 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Template [2013.05.03 16:12:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2013.05.03 16:11:40 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA% [2013.05.03 16:11:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013.05.03 15:48:13 | 000,029,816 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2013.05.03 15:48:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2013.05.03 15:48:12 | 000,368,944 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013.05.03 15:48:09 | 000,049,760 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2013.05.03 15:48:07 | 000,056,080 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013.05.03 15:48:06 | 000,765,736 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013.05.03 15:48:03 | 000,066,336 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013.05.03 15:46:59 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2013.05.03 14:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software(0) [2013.05.01 01:32:52 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Documents\wichtige thunderbird passphrase [2013.04.29 14:00:10 | 000,000,000 | ---D | C] -- C:\Program Files\Backup Manager [2013.04.29 13:59:42 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\FNET [2013.04.29 13:58:19 | 000,000,000 | ---D | C] -- C:\Program Files\Password Protection Manager [2013.04.29 13:57:31 | 000,000,000 | ---D | C] -- C:\Program Files\FAT32 Formatter [2013.04.29 03:44:31 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Free Download Manager [2013.04.29 03:20:04 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\ImgBurn [2013.04.29 03:18:29 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\vlc [2013.04.29 03:15:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2013.04.29 03:14:05 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN [2013.04.29 03:12:03 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\IrfanView [2013.04.29 03:12:02 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView [2013.04.29 03:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe [2013.04.29 03:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2013.04.29 02:51:52 | 000,000,000 | ---D | C] -- C:\Users\strasseb\.DVDslideshowGUI [2013.04.29 02:51:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter [2013.04.29 02:51:30 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter [2013.04.29 02:51:30 | 000,000,000 | ---D | C] -- C:\Program Files\Haali [2013.04.29 02:50:56 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GUI for dvdauthor [2013.04.29 02:50:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GUI for dvdauthor [2013.04.29 02:50:50 | 000,000,000 | ---D | C] -- C:\Program Files\GUI for dvdauthor [2013.04.29 02:50:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AvsP [2013.04.29 02:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\AvsP [2013.04.29 02:49:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn [2013.04.29 02:49:49 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn [2013.04.29 02:49:04 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 [2013.04.29 02:49:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 [2013.04.29 02:49:00 | 000,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5 [2013.04.29 02:47:45 | 000,000,000 | ---D | C] -- C:\Program Files\DVD slideshow GUI [2013.04.29 02:47:33 | 007,760,687 | ---- | C] (Boraxsoft) -- C:\Users\strasseb\AppData\Roaming\SetupGFD.exe [2013.04.29 02:47:11 | 005,514,668 | ---- | C] (LIGHTNING UK!) -- C:\Users\strasseb\AppData\Roaming\Imgburn.exe [2013.04.29 02:46:51 | 005,082,084 | ---- | C] (The Public) -- C:\Users\strasseb\AppData\Roaming\Avisynth.exe [2013.04.29 00:48:35 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Desktop\Tools für überprüfungen [2013.04.29 00:15:22 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\gnupg [2013.04.29 00:07:42 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GNU Privacy Guard [2013.04.29 00:07:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GNU Privacy Guard [2013.04.29 00:07:39 | 000,000,000 | ---D | C] -- C:\Program Files\GNU [2013.04.28 23:42:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2013.04.28 18:50:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SystemExplorerDisabled [2013.04.28 18:09:02 | 000,025,088 | ---- | C] (TeamViewer GmbH) -- C:\Windows\System32\drivers\teamviewervpn.sys [2013.04.28 18:08:56 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer [2013.04.28 17:52:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos [2013.04.28 17:52:29 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos [2013.04.28 17:33:06 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Desktop\HP Drucker [2013.04.28 16:17:00 | 000,000,000 | ---D | C] -- C:\Stinger_Quarantine [2013.04.28 16:14:15 | 000,000,000 | ---D | C] -- C:\Program Files\stinger [2013.04.28 16:13:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure Banking [2013.04.28 16:12:59 | 000,000,000 | ---D | C] -- C:\Program Files\Secure Banking [2013.04.28 16:08:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2013.04.28 16:08:16 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2013.04.28 15:25:27 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\TeamViewer [2013.04.28 15:10:16 | 000,000,000 | ---D | C] -- C:\ProgramData\SystemExplorer [2013.04.28 15:10:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Explorer [2013.04.28 15:10:02 | 000,000,000 | ---D | C] -- C:\Program Files\System Explorer [2013.04.12 18:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox ========== Files - Modified Within 30 Days ========== [2013.05.07 11:51:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.05.07 11:19:20 | 000,632,530 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.05.07 11:19:20 | 000,599,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.05.07 11:19:20 | 000,127,566 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.05.07 11:19:20 | 000,105,202 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.05.07 11:14:04 | 000,032,156 | ---- | M] () -- C:\ProgramData\nvModes.dat [2013.05.07 11:14:03 | 000,032,156 | ---- | M] () -- C:\ProgramData\nvModes.001 [2013.05.07 11:13:39 | 000,000,163 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini [2013.05.07 11:12:21 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013.05.07 11:12:21 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013.05.07 11:12:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.05.07 11:12:08 | 3220,103,168 | -HS- | M] () -- C:\hiberfil.sys [2013.05.07 11:11:13 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2013.05.07 11:00:56 | 000,000,791 | ---- | M] () -- C:\Users\strasseb\Desktop\adwcleaner.exe - Verknüpfung.lnk [2013.05.06 14:59:56 | 000,014,624 | ---- | M] () -- C:\Users\strasseb\Desktop\OTL.zip [2013.05.06 14:59:43 | 000,009,932 | ---- | M] () -- C:\Users\strasseb\Desktop\gmer.zip [2013.05.03 17:39:43 | 000,000,000 | ---- | M] () -- C:\Users\strasseb\defogger_reenable [2013.05.03 17:39:06 | 000,000,795 | ---- | M] () -- C:\Users\strasseb\Desktop\Defogger.exe - Verknüpfung.lnk [2013.05.03 17:38:05 | 000,000,811 | ---- | M] () -- C:\Users\strasseb\Desktop\gmer_2.1.19163.exe - Verknüpfung.lnk [2013.05.03 17:37:35 | 000,000,750 | ---- | M] () -- C:\Users\strasseb\Desktop\OTL.exe - Verknüpfung.lnk [2013.05.03 17:21:56 | 000,002,653 | ---- | M] () -- C:\Users\strasseb\Desktop\Microsoft Works-Tabellenkalkulation.lnk [2013.05.03 17:21:37 | 000,000,000 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\wklnhst.dat [2013.05.03 17:21:26 | 000,002,032 | ---- | M] () -- C:\Users\strasseb\Desktop\Microsoft Works-Textverarbeitung.lnk [2013.05.03 17:10:02 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.05.03 16:50:49 | 000,000,373 | ---- | M] () -- C:\Users\strasseb\Desktop\Bilder - Verknüpfung.lnk [2013.05.03 16:10:52 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf [2013.05.03 15:58:34 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2013.05.03 15:48:13 | 000,001,829 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.05.03 15:31:24 | 000,000,762 | ---- | M] () -- C:\Users\strasseb\Documents\Meine freigegebenen Ordner.lnk [2013.05.03 15:16:16 | 000,350,944 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.05.03 13:49:11 | 000,008,268 | ---- | M] () -- C:\Users\strasseb\AppData\Local\d3d9caps.dat [2013.05.02 16:52:41 | 000,174,664 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys [2013.05.02 01:34:09 | 000,765,736 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013.05.02 01:34:09 | 000,368,944 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013.05.02 01:34:09 | 000,056,080 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013.05.02 01:34:09 | 000,049,376 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013.05.02 01:34:08 | 000,066,336 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013.05.02 01:34:08 | 000,049,760 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2013.05.02 01:34:07 | 000,029,816 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2013.05.02 01:33:35 | 000,041,664 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2013.05.02 01:33:27 | 000,229,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2013.04.29 03:15:02 | 000,000,859 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk [2013.04.29 03:12:08 | 000,000,807 | ---- | M] () -- C:\Users\Public\Desktop\IrfanView.lnk [2013.04.29 03:03:07 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2013.04.29 02:51:41 | 000,034,936 | ---- | M] () -- C:\Windows\System32\uninstHelixYUV.exe [2013.04.29 02:48:31 | 000,000,902 | ---- | M] () -- C:\Users\strasseb\Desktop\DVD slideshow GUI.lnk [2013.04.29 02:47:45 | 007,760,687 | ---- | M] (Boraxsoft) -- C:\Users\strasseb\AppData\Roaming\SetupGFD.exe [2013.04.29 02:47:33 | 005,243,208 | ---- | M] ( ) -- C:\Users\strasseb\AppData\Roaming\AvsP.exe [2013.04.29 02:47:23 | 001,357,348 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\MatroskaSplitter.exe [2013.04.29 02:47:20 | 000,117,723 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\yuvcodecs-1.3.exe [2013.04.29 02:47:19 | 005,514,668 | ---- | M] (LIGHTNING UK!) -- C:\Users\strasseb\AppData\Roaming\Imgburn.exe [2013.04.29 02:47:11 | 005,082,084 | ---- | M] (The Public) -- C:\Users\strasseb\AppData\Roaming\Avisynth.exe [2013.04.29 02:45:06 | 000,000,671 | ---- | M] () -- C:\Users\strasseb\Desktop\Download - Verknüpfung.lnk [2013.04.28 22:16:16 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2013.04.28 21:10:55 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.04.28 21:10:55 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.04.28 18:09:08 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.04.28 16:34:11 | 002,335,270 | ---- | M] () -- C:\Windows\System32\85636D9.mht [2013.04.28 16:33:26 | 002,335,270 | ---- | M] () -- C:\Windows\System32\a0687E5.mht [2013.04.28 14:27:35 | 000,027,620 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\nvModes.001 [2013.04.10 20:19:30 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk ========== Files Created - No Company Name ========== [2013.05.07 11:00:56 | 000,000,791 | ---- | C] () -- C:\Users\strasseb\Desktop\adwcleaner.exe - Verknüpfung.lnk [2013.05.06 14:59:55 | 000,014,624 | ---- | C] () -- C:\Users\strasseb\Desktop\OTL.zip [2013.05.06 14:59:42 | 000,009,932 | ---- | C] () -- C:\Users\strasseb\Desktop\gmer.zip [2013.05.03 17:39:43 | 000,000,000 | ---- | C] () -- C:\Users\strasseb\defogger_reenable [2013.05.03 17:38:05 | 000,000,811 | ---- | C] () -- C:\Users\strasseb\Desktop\gmer_2.1.19163.exe - Verknüpfung.lnk [2013.05.03 17:37:35 | 000,000,750 | ---- | C] () -- C:\Users\strasseb\Desktop\OTL.exe - Verknüpfung.lnk [2013.05.03 17:36:42 | 000,000,795 | ---- | C] () -- C:\Users\strasseb\Desktop\Defogger.exe - Verknüpfung.lnk [2013.05.03 17:21:56 | 000,002,653 | ---- | C] () -- C:\Users\strasseb\Desktop\Microsoft Works-Tabellenkalkulation.lnk [2013.05.03 17:21:37 | 000,000,000 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\wklnhst.dat [2013.05.03 17:21:26 | 000,002,032 | ---- | C] () -- C:\Users\strasseb\Desktop\Microsoft Works-Textverarbeitung.lnk [2013.05.03 17:10:02 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.05.03 16:50:49 | 000,000,373 | ---- | C] () -- C:\Users\strasseb\Desktop\Bilder - Verknüpfung.lnk [2013.05.03 16:10:52 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf [2013.05.03 15:48:13 | 000,001,829 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.05.03 15:48:05 | 000,174,664 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys [2013.05.03 15:48:04 | 000,049,376 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013.05.03 15:31:24 | 000,000,762 | ---- | C] () -- C:\Users\strasseb\Documents\Meine freigegebenen Ordner.lnk [2013.05.03 13:59:46 | 3220,103,168 | -HS- | C] () -- C:\hiberfil.sys [2013.04.29 04:10:41 | 000,350,944 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2013.04.29 03:15:02 | 000,000,859 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2013.04.29 03:12:08 | 000,000,807 | ---- | C] () -- C:\Users\Public\Desktop\IrfanView.lnk [2013.04.29 03:03:07 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2013.04.29 03:03:07 | 000,001,892 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2013.04.29 02:51:40 | 000,034,936 | ---- | C] () -- C:\Windows\System32\uninstHelixYUV.exe [2013.04.29 02:49:52 | 000,001,662 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk [2013.04.29 02:48:31 | 000,000,902 | ---- | C] () -- C:\Users\strasseb\Desktop\DVD slideshow GUI.lnk [2013.04.29 02:47:23 | 005,243,208 | ---- | C] ( ) -- C:\Users\strasseb\AppData\Roaming\AvsP.exe [2013.04.29 02:47:20 | 001,357,348 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\MatroskaSplitter.exe [2013.04.29 02:47:19 | 000,117,723 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\yuvcodecs-1.3.exe [2013.04.29 02:45:06 | 000,000,671 | ---- | C] () -- C:\Users\strasseb\Desktop\Download - Verknüpfung.lnk [2013.04.28 22:16:16 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2013.04.28 18:09:08 | 000,000,967 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk [2013.04.28 18:09:08 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.04.28 16:34:11 | 002,335,270 | ---- | C] () -- C:\Windows\System32\85636D9.mht [2013.04.28 16:33:26 | 002,335,270 | ---- | C] () -- C:\Windows\System32\a0687E5.mht [2013.04.28 14:50:53 | 000,032,156 | ---- | C] () -- C:\ProgramData\nvModes.dat [2013.04.28 14:50:53 | 000,032,156 | ---- | C] () -- C:\ProgramData\nvModes.001 [2013.01.11 22:13:51 | 000,000,104 | ---- | C] () -- C:\Users\strasseb\Internet - Verknüpfung.lnk [2011.09.15 02:11:16 | 001,048,576 | ---- | C] () -- C:\Windows\System32\syndata.bin [2008.10.27 18:56:57 | 000,008,268 | ---- | C] () -- C:\Users\strasseb\AppData\Local\d3d9caps.dat [2008.10.27 14:01:05 | 000,004,096 | -H-- | C] () -- C:\Users\strasseb\AppData\Local\keyfile3.drm [2008.08.17 09:41:40 | 000,027,620 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\nvModes.001 [2008.08.16 15:10:56 | 000,027,620 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\nvModes.dat [2008.08.15 20:00:51 | 000,008,192 | ---- | C] () -- C:\Users\strasseb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2012.07.25 18:15:42 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Ashampoo [2012.07.25 17:16:31 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Ashampoo Slideshow Studio Elements [2012.06.02 16:17:20 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\EAC [2013.04.29 13:59:42 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\FNET [2013.05.03 12:25:59 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Free Download Manager [2013.04.29 00:58:54 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\gnupg [2010.08.20 11:37:13 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Image Zone Express [2013.04.29 03:20:04 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\ImgBurn [2013.04.29 03:12:03 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\IrfanView [2008.09.07 19:00:01 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Printer Info Cache [2013.04.28 15:38:51 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Spotify [2013.04.29 01:46:19 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\TeamViewer [2013.05.03 17:21:40 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Template [2010.09.02 21:06:21 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Thunderbird [2008.09.07 16:09:44 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\WildTangent ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2 < End of report > |
![]() | #5 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Hey, wie läuft der Rechner denn jetzt? Schritt 1 Fixen mit OTL
ATTFilter :OTL @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2 FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\39ffxtbr@MapsGalaxy_39.com: C:\Program Files\MapsGalaxy_39\bar\1.bin FF - HKLM\Software\MozillaPlugins\@MapsGalaxy_39.com/Plugin: C:\Program Files\MapsGalaxy_39\bar\1.bin\NP39Stub.dll File not found IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\..\SearchScopes\{29E9DFA0-F97D-4A9F-A8CE-E6F3784FBCCE}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=E90B559C-A755-4EC7-AF6F-B80BF6701273&apn_sauid=2E1EB563-DCD3-4CA3-925E-73B9F7DA0BDF :commands [emptytemp]
Schritt 2 Downloade Dir bitte ![]()
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte ![]()
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
![]() | #6 |
Hallo Leo,

der Rechner läuft wunderbar, nur bis er hochgefahren ist und alles geladen hat dauert noch ziemlich lange...

Hier meine logs:
![]() | #7 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Hallo, sieht gut aus. Und auch die Software ist schon alle aktuell. ![]() Wegen des langsamen Aufstartens: Vielleicht findest du hier eine Möglichkeit, das ein wenig zu beschleunigen: http://www.trojaner-board.de/71631-p...samer-tun.html Hier müssen wir nur noch aufräumen: Cleanup Zum Schluss werden wir jetzt noch unsere Tools (inklusive der Quarantäne-Ordner) wegräumen, die verseuchten Systemwiederherstellungspunkte löschen und alle Einstellungen wieder herrichten. Auch diese Schritte sind noch wichtig und sollten in der angegebenen Reihenfolge ausgeführt werden.
>> OK << Wir sind durch, deine Logs sehen für mich im Moment sauber aus. ![]() Ich habe dir nachfolgend ein paar Hinweise und Tipps zusammengestellt, die dazu beitragen sollen, dass du in Zukunft unsere Hilfe nicht mehr brauchen wirst. Bitte gib mir danach noch eine kurze Rückmeldung, wenn auch von deiner Seite keine Probleme oder Fragen mehr offen sind, damit ich dieses Thema als erledigt betrachten kann. Epilog: Tipps, Dos & Don'ts ![]() Das Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die automatischen Updates aktiviert sind:
Auch die installierte Software sollte immer in der aktuellsten Version vorliegen. Speziell gilt das für den Browser, Java, Flash-Player und PDF-Reader, denn bekannte Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim blossen Besuch einer präparierten Website per Drive-by Download Malware zu installieren. Das kann sogar auf normalerweise legitimen Websites geschehen, wenn es einem Angreifer gelungen ist, seinen Code in die Seite einzuschleusen, und ist deshalb relativ unberechenbar.
![]() Eine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine verseuchte Datei nicht erkennt). Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt. Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons zur Empfehlung gibt:
![]() Nebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert. Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
![]() Abschliessend noch ein paar grundsätzliche Bemerkungen:
Wenn du möchtest, kannst du das Forum mit einer kleinen Spende unterstützen. Es bleibt mir nur noch, dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen. ![]()
__________________ cheers, Leo |
![]() | #8 |
| ![]() mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Hallo Leo/Aharonov, vielen Dank für die schnelle und kompetente Hilfe ![]() Läuft alles wunderbar und habe auch noch richtig viel gelernt dabei ![]() lG zazfan |
![]() | #9 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Danke für die Rückmeldung. Freut mich, dass wir helfen konnten. ![]() Falls du dem Forum noch Verbesserungsvorschläge, Kritik oder ein Lob mitgeben möchtest, kannst du das hier tun. Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten. Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter. Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.
__________________ cheers, Leo |
![]() |
Themen zu mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? |
32 bit, 7-zip, antwort, anweisung, aswrvrt.sys, datei, deaktiviert, dynamic, entferne, entfernen, erstell, free download, google, hoffe, install.exe, intranet, komisch, konnte, laptop, launch, lightning, link, microsoft office 2003, mindspark, mindspark toolbar, officejet, plug-in, plugin, richtig, s3.amazonaws.com, spotify web helper, system, toolbar, verdächtig, versuche, versucht, vista, wie entfernen, wie entfernen?, windows, windows vista, windows xp |