|
Plagegeister aller Art und deren Bekämpfung: Maillaccount gehackt /verschiedene Funde mit MalewarebytesWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
27.03.2014, 12:34 | #106 |
/// the machine /// TB-Ausbilder | Maillaccount gehackt /verschiedene Funde mit Malewarebytes hehe, irritiert ich bin wegen dem Wort chrome in der Fehlermeldung Folgendes bitte nochma, aber eine alte Version von Firefox installieren!! Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.03.2014, 18:53 | #107 |
| Maillaccount gehackt /verschiedene Funde mit Malewarebytes Hallo Schrauber,
__________________ich habe alles erledigt wie aufgetragen. jetzt kommt die meldung das der Mozilla veraltet ist. Es geht alles ziemlich lahm. manche Spiele gehen überhaupt nicht mit der alten mozilla-Version. Das mit dem Shockwave-Flash ist behoben. Mir ist aufgefallen das ich den Quicktimeplayer nie aktualisiert habe. Soll ich denn den alten Mozilla weiter nehmen?? Vielen Dank und lg Lotto |
30.03.2014, 12:36 | #108 |
/// the machine /// TB-Ausbilder | Maillaccount gehackt /verschiedene Funde mit Malewarebytes Update Firefox auf die neue Version.
__________________
__________________ |
26.01.2015, 22:34 | #109 |
| Maillaccount gehackt /verschiedene Funde mit Malewarebytes Hallo Schrauber, lange hatte ich meinen PC im Griff. Jetzt scheinen wieder Virusse den PC zu verlangsamen. Laut Avira habe ich ADware/Synatix.isks Laut Norton Security Scan hätte ich einen total verseuchten PC und sollte sofort dieses Programm Norton ..... kaufen bevor mein PC Fremdgesteuert würde . Die wollen bestimmt nur das Programm verkaufen. Ja ich weis es nicht . Kannst du mal nachsehen? Vielen Dank Lotto |
27.01.2015, 07:44 | #110 |
/// the machine /// TB-Ausbilder | Maillaccount gehackt /verschiedene Funde mit Malewarebytes Poste mal bitte frische FRST Logs
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.01.2015, 09:14 | #111 |
| Maillaccount gehackt /verschiedene Funde mit MalewarebytesFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-01-2015 01 Ran by Antje (administrator) on ANTJE-PC on 27-01-2015 09:05:05 Running from C:\Users\Antje\Downloads Loaded Profiles: Antje (Available profiles: Antje) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AMD) C:\Windows\System32\atiesrxx.exe (Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Creative Technology Ltd) C:\Program Files\Creative\Shared Files\CTAudSvc.exe (AMD) C:\Windows\System32\atieclxx.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (ABBYY) C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (AOL LLC) C:\Program Files\Common Files\aol\acs\AOLacsd.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (VIA) C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (FNet Co., Ltd.) C:\Program Files\XFastUsb\XFastUsb.exe (MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (Teruten) C:\Windows\System32\FsUsbExService.Exe (Creative Technology Ltd) C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe (Hewlett-Packard Company) C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe (Creative Technology Ltd) C:\Program Files\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Macrovision Europe Ltd.) C:\Users\Antje\AppData\Local\temp\Sound_Blaster_X-Fi_MB_Cleanup.0001 (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe () C:\Program Files\NETGEAR\WG111v3\WG111v3.exe (America Online, Inc.) C:\Program Files\Common Files\aol\1324678810\ee\aolsoftware.exe (Realtek) C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtlService.exe (Realtek Semiconductor Corp.) C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Creative Labs) C:\Program Files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (AOL, LLC.) C:\Program Files\AOL 9.0 VRa\waol.exe (AOL, LLC.) C:\Program Files\AOL 9.0 VRa\shellmon.exe (Microsoft Corporation) C:\Windows\System32\CompatTel\wicainventory.exe (Farbar) C:\Users\Antje\Downloads\FRST(1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [2145904 2011-02-22] (VIA) HKLM\...\Run: [XFastUsb] => C:\Program Files\XFastUsb\XFastUsb.exe [4942336 2011-12-23] (FNet Co., Ltd.) HKLM\...\Run: [CTSyncService] => C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe [1233195 2009-07-08] (Creative Technology Ltd) HKLM\...\Run: [VolPanel] => C:\Program Files\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe [241789 2009-05-04] (Creative Technology Ltd) HKLM\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM\...\Run: [RunDLLEntry] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [161584 2014-08-04] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\Run: [KiesPDLR] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-07-25] (Samsung) HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [958352 2011-07-26] (Samsung) HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\Run: [AOL Fast Start] => C:\Program Files\AOL 9.0 VRa\AOL.EXE [50480 2007-06-21] (AOL, LLC.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk ShortcutTarget: NETGEAR WG111v3 Smart Wizard.lnk -> C:\Program Files\NETGEAR\WG111v3\WG111v3.exe () BootExecute: autocheck autochk * sdnclean.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:8897;https=127.0.0.1:8897 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://de.search.yahoo.com/?fr=w3i&type=W3i_SP,204,0_0,StartPage,20120101,16988,0,8,0 SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {5D422421-30DD-42B3-826E-9224F52BFC47} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {6D0FF7A0-C6C5-4a24-8F09-C074ED2B20A0} URL = hxxp://de.search.yahoo.com/search?p={searchterms}&ei=UTF-8&fr=w3i&type=W3i_DS,105,0_0,Search,20140622,20250,0,FF29,6923 SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {6DA59B2F-C380-26BF-75EF-54850C7D29F4} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {7D09D9D4-CEDB-47B3-8779-584CFD2BABB0} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {9DDD17F4-2BF7-4662-B5A0-92270A4C54F7} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag= interactivemesuche21&index=blended&linkCode=ur2&camp=1638&creative=6742 SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {B442213A-49FA-404C-8A15-326E8709045B} URL = hxxp://suche.t-online.de/fastcgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&d ia=suche&context=wiki-tab&tpc=internet&ptl=std&classification=wikitab_internet_std&q={searchTerms}&br=ie7-toi SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {BC51C75D-1339-43dd-921D-49F5D0A2F625} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A6976579318&ie=UTF-8&q=&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A6976579318&q={searchTerms} SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {CA25764C-9109-4C88-9615-DCF100F14585} URL = hxxp://suche.t-online.de/fast-cgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&dia=suche&context=internet-tab&tpc=internet&ptl=std&classification=internet-tab_internet_std&q={searchTerms}&br=ie7-toi SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {E8B82BA8-923F-4120-B179-4144137AB04D} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie BHO: No Name -> {0025320D-4D37-4C73-9A5C-0C28F04068A3} -> C:\Users\Antje\AppData\LocalLow\IE-BHO\bho.dll No File BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Adblock IE -> {667BEE43-20BD-4CE3-94AC-E63E04D4B191} -> C:\Program Files\MGTEK\Adblock IE\adblockie.dll (MGTEK) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO: AOL Toolbar Launcher -> {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} -> C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC) DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Antje\AppData\Roaming\Mozilla\Firefox\Profiles\me88ggay.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1216156.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Extension: Avira Browser Safety - C:\Users\Antje\AppData\Roaming\Mozilla\Firefox\Profiles\me88ggay.default\Extensions\abs@avira.com [2014-12-11] FF Extension: Amazon-Icon - C:\Users\Antje\AppData\Roaming\Mozilla\Firefox\Profiles\me88ggay.default\Extensions\amazon-icon@giga.de [2014-11-11] FF Extension: Foxi Security - C:\Users\Antje\AppData\Roaming\Mozilla\Firefox\Profiles\me88ggay.default\Extensions\foxi@securitii-dhfjs.com [2014-11-11] FF Extension: Ask Toolbar - C:\Users\Antje\AppData\Roaming\Mozilla\Firefox\Profiles\me88ggay.default\Extensions\toolbar_MP3R-RG@apn.ask.com.xpi [2014-01-13] FF Extension: NoScript - C:\Users\Antje\AppData\Roaming\Mozilla\Firefox\Profiles\me88ggay.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-24] FF Extension: Adblock Plus - C:\Users\Antje\AppData\Roaming\Mozilla\Firefox\Profiles\me88ggay.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-30] FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-08-03] FF HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR Profile: C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Docs) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-18] CHR Extension: (Google Drive) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-18] CHR Extension: (YouTube) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-18] CHR Extension: (Google Search) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-18] CHR Extension: (Google Wallet) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-18] CHR Extension: (Gmail) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-18] CHR HKLM\...\Chrome\Extension: [aaaahhbocodnflflgmabphbhoppekghh] - C:\ProgramData\AskPartnerNetwork\Toolbar\MP3R-RG\CRX\ToolbarCR.crx [Not Found] CHR HKLM\...\Chrome\Extension: [aaaaojdbdbhbbkpenbmlejjngphokgnp] - C:\Users\Antje\AppData\Local\APN\GoogleCRXs\aaaaojdbdbhbbkpenbmlejjngphokgnp_7.17.2.0.crx [Not Found] CHR HKLM\...\Chrome\Extension: [caeaobpemokdfnidgaebncaooofnbfha] - C:\Users\Antje\ChromeExtensions\caeaobpemokdfnidgaebncaooofnbfha\amazon-icon-fwde.crx [2014-11-11] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ABBYY.Licensing.FineReader.Professional.11.0; C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe [819976 2011-08-18] (ABBYY) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AOL ACS; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [46640 2006-10-23] (AOL LLC) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [149296 2014-08-04] (Avira Operations GmbH & Co. KG) S3 Creative ALchemy AL6 Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2011-12-23] (Creative Labs) [File not signed] S3 Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2011-12-23] (Creative Labs) [File not signed] R2 CTAudSvcService; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [307200 2009-02-23] (Creative Technology Ltd) [File not signed] S2 Dnscache; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [File not signed] R2 FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [233472 2013-12-30] (Teruten) [File not signed] R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [660992 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [72992 2014-07-07] (Hewlett-Packard Company) R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [769432 2012-07-13] (Nero AG) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed] R2 Realtek11nSU; C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed] R3 Sound Blaster X-Fi MB Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [79360 2011-12-23] (Creative Labs) [File not signed] R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-02-17] (VIA Technologies, Inc.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) S2 SmartViewService; C:\Program Files\DeviceVM\SmartView\SmartViewService.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 AsrAppCharger; C:\Windows\System32\DRIVERS\AsrAppCharger.sys [13832 2010-06-11] (Windows (R) Win 7 DDK provider) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-14] (Avira Operations GmbH & Co. KG) R3 CompFilter; C:\Windows\System32\DRIVERS\lvbusflt.sys [22176 2012-01-18] (Logitech Inc.) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [378672 2015-01-26] (Symantec Corporation) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [29248 2012-04-19] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [14656 2011-12-23] (FNet Co., Ltd.) R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [37344 2013-12-30] () [File not signed] R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [41088 2010-10-19] (Intel Corporation) R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [67456 2011-04-13] (Renesas Electronics Corporation) R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [161024 2011-04-13] (Renesas Electronics Corporation) R3 RTL8187B; C:\Windows\System32\DRIVERS\wg111v3.sys [376832 2009-11-18] (NETGEAR Inc. ) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1801328 2011-02-17] (VIA Technologies, Inc.) R3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-29] (America Online, Inc.) S3 catchme; \??\C:\Users\Antje\AppData\Local\Temp\catchme.sys [X] S3 MSICDSetup; \??\D:\CDriver.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 09:04 - 2015-01-27 09:04 - 01120768 _____ (Farbar) C:\Users\Antje\Downloads\FRST(1).exe 2015-01-27 09:03 - 2015-01-27 09:04 - 01120768 _____ (Farbar) C:\Users\Antje\Downloads\FRST(2).exe 2015-01-26 21:23 - 2015-01-26 21:23 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared 2015-01-26 21:16 - 2015-01-27 08:56 - 00000440 ____H () C:\Windows\Tasks\Norton Security Scan for Antje.job 2015-01-26 21:16 - 2015-01-26 21:16 - 00001415 _____ () C:\Users\Public\Desktop\Norton Security Scan.LNK 2015-01-26 21:16 - 2015-01-26 21:16 - 00000000 ____D () C:\Windows\system32\Drivers\NSS 2015-01-26 21:16 - 2015-01-26 21:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan 2015-01-26 21:16 - 2015-01-26 21:16 - 00000000 ____D () C:\Program Files\Norton Security Scan 2015-01-26 10:30 - 2015-01-26 10:30 - 00000000 ____D () C:\Windows\system32\Adobe 2015-01-26 10:29 - 2015-01-26 10:30 - 13827960 _____ (Adobe Systems Inc.) C:\Users\Antje\Downloads\Shockwave_Installer_Full.exe 2015-01-14 08:43 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-01-14 08:43 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-14 08:42 - 2014-12-19 03:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 08:42 - 2014-12-19 02:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 08:42 - 2014-12-11 18:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-14 08:42 - 2014-12-06 04:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-05 18:46 - 2015-01-05 18:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 09:05 - 2014-03-21 21:30 - 00023286 _____ () C:\Users\Antje\Downloads\FRST.txt 2015-01-27 09:05 - 2014-03-21 21:29 - 00000000 ____D () C:\FRST 2015-01-27 09:03 - 2011-12-23 21:41 - 01723369 _____ () C:\Windows\WindowsUpdate.log 2015-01-27 09:02 - 2009-07-14 05:34 - 00020480 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-27 09:02 - 2009-07-14 05:34 - 00020480 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-27 08:58 - 2011-12-29 15:18 - 00000000 ____D () C:\Users\Antje\AppData\Local\CrashDumps 2015-01-27 08:56 - 2014-04-18 12:26 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-27 08:56 - 2013-06-25 14:14 - 00061456 _____ () C:\Windows\setupact.log 2015-01-27 08:56 - 2012-04-03 06:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-27 08:56 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-26 23:26 - 2013-12-11 18:20 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-01-26 23:26 - 2011-12-23 23:54 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-01-26 22:55 - 2014-04-18 12:26 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-26 21:16 - 2011-12-23 22:21 - 00000000 ____D () C:\ProgramData\Norton 2015-01-26 11:02 - 2014-09-16 18:23 - 00000000 ____D () C:\Users\Antje\Downloads\FRST-OlderVersion 2015-01-26 11:02 - 2014-03-21 21:29 - 01120768 _____ (Farbar) C:\Users\Antje\Downloads\FRST.exe 2015-01-26 09:34 - 2014-03-30 17:33 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-01-25 22:49 - 2014-03-28 10:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-01-20 10:01 - 2013-08-15 10:02 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-20 09:58 - 2009-10-14 03:21 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-01-11 23:35 - 2009-07-14 05:52 - 00000000 ____D () C:\Windows\system32\FxsTmp 2015-01-08 09:55 - 2009-10-14 03:21 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-01-05 18:51 - 2014-07-04 16:16 - 00000000 ____D () C:\Users\Antje\AppData\Local\Adobe ==================== Files in the root of some directories ======= 2013-06-27 17:14 - 2013-06-27 16:36 - 0186752 _____ () C:\Program Files\49res.dll 2013-06-27 17:14 - 2013-06-27 16:36 - 0708168 _____ (MindSpark) C:\Program Files\49Uninstall Utility Chest.dll 2013-01-10 11:53 - 2013-01-10 12:07 - 0015360 _____ () C:\Users\Antje\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-11-11 17:13 - 2012-11-11 17:13 - 0000048 ___SH () C:\ProgramData\.zreglib 2012-01-21 12:04 - 2014-08-03 10:48 - 0017073 _____ () C:\ProgramData\hpzinstall.log Some content of TEMP: ==================== C:\Users\Antje\AppData\Local\temp\avgnt.exe C:\Users\Antje\AppData\Local\temp\Quarantine.exe C:\Users\Antje\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-25 11:07 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-01-2015 01 Ran by Antje at 2015-01-27 09:11:20 Running from C:\Users\Antje\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden 4500_G510nz_Help (Version: 000.0.439.000 - Hewlett-Packard) Hidden 4500G510nz (Version: 000.0.439.000 - Hewlett-Packard) Hidden 4500G510nz_Software_Min (Version: 000.0.423.000 - Hewlett-Packard) Hidden ABBYY FineReader 11 (HKLM\...\{F1100000-0008-0000-0001-074957833700}) (Version: 11.0.289 - ABBYY) Acrobat.com (Version: 0.0.0 - Adobe Systems Incorporated) Hidden Adblock IE 2.2 (HKLM\...\{56D01524-CD68-4576-B1AE-D572E8EAFF3D}) (Version: 2.2.1524 - MGTEK) Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.6.156 - Adobe Systems, Inc.) AOL Deinstallation (HKLM\...\AOL Deinstallation) (Version: - ) AP Tuner 3.08 (HKLM\...\AP Tuner 3.08) (Version: - ) Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Ask Toolbar (HKLM\...\{4D503352-2D52-4700-76A7-A758B70C0A00}) (Version: 12.10.0.3802 - APN, LLC) <==== ATTENTION ASRock App Charger v1.0.4 (HKLM\...\ASRock App Charger_is1) (Version: - ASRock Inc.) ASRock eXtreme Tuner v0.1.53 (HKLM\...\ASRock eXtreme Tuner_is1) (Version: - ) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.35 - Atheros Communications Inc.) Avira (HKLM\...\{e67154a7-9cc5-4167-b782-f3982bc6c70d}) (Version: 1.1.19.30000 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.19.30000 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) BestPractice (remove only) (HKLM\...\BestPractice) (Version: - ) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) BufferChm (Version: 130.0.331.000 - Hewlett-Packard) Hidden CameraHelperMsi (Version: 13.31.1038.0 - Logitech) Hidden Cisco EAP-FAST Module (HKLM\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) CK Gruß- und Einladungskarten Designer (HKLM\...\{579C4753-8A98-403C-8A04-C576BA8CE26A}) (Version: 1.80.0000 - CK Software) Destinations (Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (Version: 130.0.372.000 - Hewlett-Packard) Hidden DocMgr (Version: 130.0.000.000 - Ihr Firmenname) Hidden DocProc (Version: 13.0.0.0 - Hewlett-Packard) Hidden erLT (Version: 1.20.138.34 - Logitech, Inc.) Hidden Fax (Version: 130.0.418.000 - Hewlett-Packard) Hidden FileHippo.com Update Checker (HKLM\...\FileHippo.com) (Version: - ) Firebird SQL Server - MAGIX Edition (HKLM\...\{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}) (Version: 2.1.27.0 - MAGIX AG) Google Chrome (HKLM\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.) Google Update Helper (Version: 1.3.25.5 - Google Inc.) Hidden GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP) HP Document Manager 2.0 (HKLM\...\HP Document Manager) (Version: 2.0 - HP) HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP) HP Officejet 4500 G510n-z (HKLM\...\{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}) (Version: 13.0 - HP) HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Support Solutions Framework (HKLM\...\{C43602FE-988C-47BA-9F9F-B95FDDAFB624}) (Version: 11.50.0031 - Hewlett-Packard Company) HP Update (HKLM\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard) HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden HPSSupply (Version: 130.0.371.000 - Hewlett-Packard) Hidden iCloud (HKLM\...\{760BB327-3973-4608-85C8-88162E2FF3B6}) (Version: 4.0.6.28 - Apple Inc.) Iminent (Version: 4.10.0.0 - Iminent) Hidden <==== ATTENTION Intel(R) Management Engine Components (HKLM\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Internet Explorer (Version: 9 - Microsoft Corporation) Hidden iTuner (HKLM\...\{C49CBF9A-4AD7-4045-92BD-2C6E45680070}) (Version: 1.0.3 - iAppsPoint) iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.) Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle) Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) Logitech Webcam-Software (HKLM\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.30 - Logitech Inc.) MAGIX Screenshare (HKLM\...\{BB565180-FA52-40DA-A65E-651537008C34}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Speed burnR (MSI) (HKLM\...\{B0975D89-8D51-445C-BB71-95826A96780C}) (Version: 7.0.2.6 - MAGIX AG) MAGIX Video deluxe 17 Premium Download-Version (HKLM\...\MAGIX_MSI_Videodeluxe17_premium) (Version: 10.0.1.14 - MAGIX AG) MAGIX Video deluxe 17 Premium Download-Version (Version: 10.0.1.14 - MAGIX AG) Hidden MarketResearch (Version: 130.0.374.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft SkyDrive (HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\SkyDriveSetup.exe) (Version: 16.4.6010.0727 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 35.0 (x86 de) (HKLM\...\Mozilla Firefox 35.0 (x86 de)) (Version: 35.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) MP3 Rocket (HKLM\...\MP3 Rocket) (Version: - ) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyFreeCodec (HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\MyFreeCodec) (Version: - ) Nero BurningROM 12 (HKLM\...\{3DAFE920-1B88-4C66-A39B-D743F28AF10D}) (Version: 12.5.01300 - Nero AG) NETGEAR WG111v3 wireless USB 2.0 adapter (HKLM\...\InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}) (Version: 1.00.0000 - NETGEAR) NETGEAR WG111v3 wireless USB 2.0 adapter (Version: 1.00.0000 - NETGEAR) Hidden Network (Version: 130.0.374.000 - Hewlett-Packard) Hidden Norton Internet Security (Version: 18.1.0.37 - Symantec Corporation) Hidden Norton Security Scan (HKLM\...\NSS) (Version: 4.1.0.28 - Symantec Corporation) NVIDIA Grafiktreiber 267.42 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 267.42 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.10.0514 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.10.0514 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (HKLM\...\NVIDIAStereo) (Version: 7.17.12.6742 - NVIDIA Corporation) OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP) Platform (Version: 1.36 - VIA Technologies, Inc.) Hidden Prerequisite installer (Version: 12.0.0003 - Nero AG) Hidden QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) REALTEK Wireless LAN Driver and Utility (HKLM\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0165 - REALTEK Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.16.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.1.16.0 - Renesas Electronics Corporation) Hidden Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Samplitude Music Studio 17 Content Pack (HKLM\...\{B6FE6F0D-688B-458B-9E12-0F55E4009561}) (Version: 1.0.0.0 - MAGIX AG) Samplitude Music Studio 17 Download-Version (Version: 17.0.0.0 - MAGIX AG) Hidden Samplitude Music Studio 17 Vita Pack 1 (HKLM\...\{EE3264C1-2501-4D58-9B57-4D3F2F502599}) (Version: 1.0.0.0 - MAGIX AG) Samplitude Music Studio 17 Vita Pack 2 (HKLM\...\{63D7FB4F-01A1-4A8B-9180-FF2FEF369AC8}) (Version: 1.0.0.0 - MAGIX AG) Samplitude Music Studio 17 Vita Pack 3 (HKLM\...\{33F9A189-4F02-4784-8A57-F3983F9F9217}) (Version: 1.0.0.0 - MAGIX AG) Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.0.2.11071_128 - Samsung Electronics Co., Ltd.) Samsung Kies (Version: 2.0.2.11071_128 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.) Scan (Version: 13.0.0.0 - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP) Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.8.8855 - Skype Technologies S.A.) Skype™ 5.5 (HKLM\...\{AA59DDE4-B672-4621-A016-4C248204957A}) (Version: 5.5.124 - Skype Technologies S.A.) Smart OCR 3.2.1.417 (HKLM\...\Smart OCR_is1) (Version: 3.2.1.417 - SmartSoft, LLC.) SmartWebPrinting (Version: 130.0.373.000 - Hewlett-Packard) Hidden SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden Sound Blaster X-Fi MB (HKLM\...\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}) (Version: 1.0 - Creative Technology Limited) Sound Effects (HKLM\...\{A044C900-5DE1-4986-B0B8-D6A40271A929}) (Version: 2.0 - Music Oasis) Splashtop Connect IE (HKLM\...\{F9F5EF72-18CF-4DCF-A721-EC86B94DAC46}) (Version: 1.1.12.1 - Splashtop Inc.) SpywareBlaster 5.0 (HKLM\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC) Status (Version: 130.0.373.000 - Hewlett-Packard) Hidden SumatraPDF (HKLM\...\SumatraPDF) (Version: 2.2.1 - Krzysztof Kowalczyk) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Text-To-Speech-Runtime (HKLM\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH) TomTom HOME (HKLM\...\{99072AB4-D795-44D5-9D65-E3C9F8322C97}) (Version: 2.9.7 - Ihr Firmenname) TomTom HOME Visual Studio Merge Modules (HKLM\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) Toolbox (Version: 130.0.648.000 - Hewlett-Packard) Hidden TrayApp (Version: 130.0.376.000 - Hewlett-Packard) Hidden VIA Plattform-Geräte-Manager (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.36 - VIA Technologies, Inc.) VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN) WebReg (Version: 130.0.132.017 - Hewlett-Packard) Hidden Windows 7 Upgrade Advisor (HKLM\...\{9A4D182C-35C7-4791-8484-4304EBC9101A}) (Version: 2.0.5000.0 - Microsoft Corporation) WinPatrol (HKLM\...\{84481A87-2316-4923-8FAB-3BA8CA29323D}) (Version: 30.0.2014.0 - BillP Studios) WinRAR 5.01 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) XFastUsb (HKLM\...\XFastUsb) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{1853e19a-4e54-4190-8deb-2e1cc947cd60}\InprocServer32 -> C:\Program Files\AOL 9.0 VRa\axtrack.dll (AOL, LLC.) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{248FDB00-ABE4-DA9A-AEAA-45651873E13C}\InprocServer32 -> C:\Windows\system32\ole32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{7629C9DE-2E38-4963-A01C-02FFAC203D87}\InprocServer32 -> C:\Program Files\AOL 9.0 VRa\axtrack.dll (AOL, LLC.) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}\localserver32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}\localserver32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{B9F3009B-976B-41C4-A992-229DCCF3367C}\InprocServer32 -> C:\Program Files\AOL 9.0 VRa\axtrack.dll (AOL, LLC.) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\FileSyncApi.dll (Microsoft Corporation) ==================== Restore Points ========================= 30-12-2014 09:42:17 Windows Update 02-01-2015 13:12:07 Windows Update 06-01-2015 16:44:17 Windows Update 09-01-2015 17:10:05 Windows Update 14-01-2015 08:42:35 Windows Update 20-01-2015 09:55:40 Windows Update 23-01-2015 10:35:22 Windows Update 27-01-2015 09:01:46 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2013-08-19 14:47 - 00000027 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {03AF9F3C-D4C3-4C66-B3FF-94385E5067CD} - System32\Tasks\{B884BA27-1BA3-408A-81E3-F2C080791443} => pcalua.exe -a C:\Users\Antje\AppData\Local\Temp\Temp1_BEHRINGER_2902_WIN32_2.8.40.zip\BEHRINGER_2902_WIN32_2.8.40\BEHRINGER_2902_WIN32_2.8.40\Setup.exe Task: {045F01F1-6A51-4ECF-B1DD-8CCF826C5DFB} - System32\Tasks\{FFB24C49-EC37-46CD-A216-976544BB8314} => pcalua.exe -a C:\Users\Antje\Desktop\JRT.exe -d C:\Users\Antje\Desktop Task: {22297514-A4E0-4D1E-9455-F8E19C59CD27} - System32\Tasks\{7D903461-66BC-4061-85C9-3F8FA32A51B9} => C:\Program Files\AOL 9.0 VRa\aol.exe [2007-06-21] (AOL, LLC.) Task: {34A7E8FD-E08C-40C8-B837-2E80BE0A306C} - System32\Tasks\{8F4BC908-16EF-4848-947E-84237ECB4017} => pcalua.exe -a "C:\Users\Antje\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\39AZ0FF2\JavaSetup6u30[1].exe" -d "C:\Program Files\AOL 9.0 VR\download" Task: {3E3A8E37-D463-4D55-AB37-945CB206B155} - System32\Tasks\{C6D23163-BC45-4502-81AE-7D050066D03F} => C:\Program Files\AOL 9.0 VRa\aol.exe [2007-06-21] (AOL, LLC.) Task: {40EFC56F-9252-4B38-B5DD-057EF1F79324} - System32\Tasks\{CB4134A4-24E6-4801-AD5D-F14F348B4F3F} => pcalua.exe -a C:\Users\Antje\Desktop\bpsetup_1_03_1.exe -d C:\Users\Antje\Desktop Task: {41E884C9-AD6D-4197-8528-7D37E6577D28} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {52868A61-6D7B-4124-B8B9-513939B660F8} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-26] (Adobe Systems Incorporated) Task: {5A682855-60A2-47AA-930F-F7825730797E} - System32\Tasks\Norton Security Scan for Antje => C:\Program Files\Norton Security Scan\Engine\4.1.0.28\Nss.exe [2014-01-27] (Symantec Corporation) Task: {5DEFCCC0-E74F-468D-A8F6-4F22F81036C4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-18] (Google Inc.) Task: {64D1831E-C822-4FCA-947A-B5016AD58892} - System32\Tasks\{3675A0DE-B202-46D2-A003-B992F464AB20} => C:\Program Files\AOL 9.0 VRa\aol.exe [2007-06-21] (AOL, LLC.) Task: {8C20516A-0854-4055-9DDA-07F5D365959F} - System32\Tasks\{A56D0839-9B1E-4606-AE99-6CAD37FD905C} => C:\Program Files\Lexmark X1100 Series\LXBKaiox.exe Task: {8F558DF4-0619-444D-9F4F-4EF9E314EDFC} - System32\Tasks\{2924322F-7F67-4D89-8E43-BB513C3355D9} => pcalua.exe -a "C:\Program Files\PDFReader\Uninstall\Uninstall.exe" -c /Uninstall Task: {94904DBE-DBE1-4386-9DE3-1C4E1D91C064} - System32\Tasks\{9DA0F427-D915-4923-B20B-1FA49027F5E0} => C:\Program Files\Lexmark X1100 Series\LXBKaiox.exe Task: {97F8691A-B0E3-4043-8305-1F364FA2C414} - System32\Tasks\{16F0FB3C-EDC9-4C3C-8E77-E44A47D38837} => pcalua.exe -a C:\Users\Antje\Downloads\OJ4500vG510n-z_Full_13.exe -d C:\Users\Antje\Downloads Task: {9B27E834-691C-45FF-829F-B0A49E17AE7F} - System32\Tasks\{D85521BE-0739-42B1-A58D-22BB371F9D3F} => pcalua.exe -a C:\Users\Antje\AppData\Local\temp\Temp1_hm5-de-demo.zip\setup.exe Task: {A10ECCC0-1B66-4A86-9C89-4C1818EBA884} - System32\Tasks\{B10FAAC6-490F-473F-82EE-FAC8F3944A72} => pcalua.exe -a "C:\Program Files\Common Files\aolshare\aolunins_de.exe" -d "C:\Program Files\Common Files\aolshare" Task: {A772F5F9-4A3A-4937-BFB2-CD9F2B84E04E} - System32\Tasks\{AAEC8B2B-ED52-49A0-BD09-2F6923957A60} => pcalua.exe -a C:\Users\Antje\AppData\Local\Temp\jre-8u20-windows-au.exe -d C:\Windows\system32 -c /installmethod=jau FAMILYUPGRADE=1 Task: {C3FBC991-3D6D-44E0-A406-6BDDC4AC416C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {C85A48C0-2367-4172-9824-7B85B5DC8CE3} - System32\Tasks\{93CF804C-D379-4814-A73F-889901F831EE} => C:\Program Files\AOL 9.0 VRa\aol.exe [2007-06-21] (AOL, LLC.) Task: {CAEE6CC7-AD53-4CC1-A7C7-9724173B870C} - System32\Tasks\{9FF61FC0-5E04-43DB-A5E4-669321A28ECB} => pcalua.exe -a C:\Users\Antje\Documents\APTunerInstall308.exe -d C:\Users\Antje\Documents Task: {DA7A9810-A0B0-4FF4-82D3-BF57EE4B1784} - System32\Tasks\{FC053655-A6D1-46F9-809B-FA9D8B478771} => pcalua.exe -a C:\Users\Antje\AppData\Local\Temp\jre-8u25-windows-au.exe -d C:\Windows\system32 -c /installmethod=jau FAMILYUPGRADE=1 Task: {FECA1FA1-49AA-4917-877A-F2454176197A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-18] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Norton Security Scan for Antje.job => C:\PROGRA~1\NORTON~2\Engine\410~1.28\Nss.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2011-12-23 22:11 - 2011-02-22 07:02 - 00080496 ____R () C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll 2011-12-23 22:11 - 2011-02-22 07:02 - 00113264 ____R () C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll 2011-12-23 22:11 - 2011-02-22 07:02 - 00623216 ____R () C:\Program Files\VIA\VIAudioi\VDeck\Skin.dll 2015-01-27 08:56 - 2015-01-27 08:56 - 00697884 _____ () C:\Users\Antje\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0087\~df394b.tmp 2015-01-27 08:56 - 2015-01-27 08:56 - 00592896 _____ () C:\Users\Antje\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0087\~de6248.tmp 2011-12-23 22:18 - 2009-02-06 18:52 - 00073728 _____ () C:\Windows\SYSTEM32\CmdRtr.DLL 2011-12-23 22:18 - 2009-04-20 11:55 - 00148480 _____ () C:\Windows\SYSTEM32\APOMngr.DLL 2014-11-12 09:46 - 2014-08-04 13:20 - 00052472 _____ () C:\Users\Antje\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2014-08-04 13:20 - 2014-08-04 13:20 - 00139056 _____ () C:\Program Files\Avira\My Avira\Avira.OE.NativeCore.dll 2007-09-14 09:26 - 2007-09-14 09:26 - 01695744 _____ () C:\Program Files\NETGEAR\WG111v3\WG111v3.exe 2011-12-23 22:28 - 2009-12-09 21:20 - 00126976 _____ () C:\Program Files\REALTEK\11n USB Wireless LAN Utility\EnumDevLib.dll 2014-08-04 13:20 - 2014-08-04 13:20 - 00067832 _____ () C:\Program Files\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2014-03-30 17:32 - 2015-01-25 22:49 - 03925104 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2004-01-09 21:02 - 2004-01-09 21:02 - 00045056 _____ () C:\Program Files\AOL 9.0 VRa\zlib.dll 2002-04-22 22:08 - 2002-04-22 22:08 - 00053248 _____ () C:\Program Files\AOL 9.0 VRa\xmlparse.dll 2002-04-22 22:08 - 2002-04-22 22:08 - 00081920 _____ () C:\Program Files\AOL 9.0 VRa\xmltok.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:373E1720 AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Antje^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupfolder: C:^Users^Antje^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk => C:\Windows\pss\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: Bonus.SSR.FR11 => "C:\Program Files\ABBYY FineReader 11\Bonus.ScreenshotReader.exe" /autorun MSCONFIG\startupreg: FileHippo.com => "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background MSCONFIG\startupreg: HostManager => C:\Program Files\Common Files\AOL\1324678810\ee\AOLSoftware.exe MSCONFIG\startupreg: HP Software Update => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: KiesHelper => C:\Program Files\Samsung\Kies\KiesHelper.exe /s MSCONFIG\startupreg: KiesPDLR => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: LWS => C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide MSCONFIG\startupreg: NUSB3MON => "C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SkyDrive => "C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background MSCONFIG\startupreg: TomTomHOME.exe => "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s MSCONFIG\startupreg: TrayServer => C:\PROGRA~1\MAGIX\VIDEO_~2\TrayServer.exe MSCONFIG\startupreg: WinPatrol => C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot ========================= Accounts: ========================== Administrator (S-1-5-21-1184766340-1357020511-1184547663-500 - Administrator - Disabled) Antje (S-1-5-21-1184766340-1357020511-1184547663-1000 - Administrator - Enabled) => C:\Users\Antje Gast (S-1-5-21-1184766340-1357020511-1184547663-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1184766340-1357020511-1184547663-1002 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= Name: Officejet 4500 G510n-z Description: Officejet 4500 G510n-z Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} Manufacturer: HP Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Officejet 4500 G510n-z Description: Officejet 4500 G510n-z Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: HP Service: StillCam Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/27/2015 08:57:35 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Kies.exe, Version: 2.0.0.11044, Zeitstempel: 0x4e2ea381 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x531599f6 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000812f ID des fehlerhaften Prozesses: 0xa34 Startzeit der fehlerhaften Anwendung: 0xKies.exe0 Pfad der fehlerhaften Anwendung: Kies.exe1 Pfad des fehlerhaften Moduls: Kies.exe2 Berichtskennung: Kies.exe3 Error: (01/27/2015 08:57:14 AM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Kies.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.Windows.Markup.XamlParseException Stapel: bei System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) bei System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) bei System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) bei System.Windows.Application.LoadComponent(System.Object, System.Uri) bei Kies.App.InitializeComponent() bei Kies.App.Main() Error: (01/26/2015 09:12:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Kies.exe, Version: 2.0.0.11044, Zeitstempel: 0x4e2ea381 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x531599f6 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000812f ID des fehlerhaften Prozesses: 0xe48 Startzeit der fehlerhaften Anwendung: 0xKies.exe0 Pfad der fehlerhaften Anwendung: Kies.exe1 Pfad des fehlerhaften Moduls: Kies.exe2 Berichtskennung: Kies.exe3 Error: (01/26/2015 09:11:55 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Kies.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.Windows.Markup.XamlParseException Stapel: bei System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) bei System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) bei System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) bei System.Windows.Application.LoadComponent(System.Object, System.Uri) bei Kies.App.InitializeComponent() bei Kies.App.Main() Error: (01/26/2015 10:58:57 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 35.0.0.5486, Zeitstempel: 0x54af7153 Name des fehlerhaften Moduls: mozalloc.dll, Version: 35.0.0.5486, Zeitstempel: 0x54af69d4 Ausnahmecode: 0x80000003 Fehleroffset: 0x00001425 ID des fehlerhaften Prozesses: 0x1ab0 Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Error: (01/26/2015 10:58:57 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm firefox.exe, Version 35.0.0.5486 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 2f3c Startzeit: 01d0394ce7918059 Endzeit: 14 Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe Berichts-ID: Error: (01/26/2015 10:44:45 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm waol.exe, Version 9.5.0.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 9c4 Startzeit: 01d03942eb017ce9 Endzeit: 16 Anwendungspfad: C:\Program Files\AOL 9.0 VRa\waol.exe Berichts-ID: f0b5de88-a53f-11e4-a146-00038a000015 Error: (01/26/2015 09:35:31 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Kies.exe, Version: 2.0.0.11044, Zeitstempel: 0x4e2ea381 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x531599f6 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000812f ID des fehlerhaften Prozesses: 0x904 Startzeit der fehlerhaften Anwendung: 0xKies.exe0 Pfad der fehlerhaften Anwendung: Kies.exe1 Pfad des fehlerhaften Moduls: Kies.exe2 Berichtskennung: Kies.exe3 Error: (01/26/2015 09:35:27 AM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Kies.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.Windows.Markup.XamlParseException Stapel: bei System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) bei System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) bei System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) bei System.Windows.Application.LoadComponent(System.Object, System.Uri) bei Kies.App.InitializeComponent() bei Kies.App.Main() Error: (01/25/2015 09:00:14 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Kies.exe, Version: 2.0.0.11044, Zeitstempel: 0x4e2ea381 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x531599f6 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000812f ID des fehlerhaften Prozesses: 0x96c Startzeit der fehlerhaften Anwendung: 0xKies.exe0 Pfad der fehlerhaften Anwendung: Kies.exe1 Pfad des fehlerhaften Moduls: Kies.exe2 Berichtskennung: Kies.exe3 System errors: ============= Error: (01/27/2015 08:58:25 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/27/2015 08:57:32 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/27/2015 08:57:32 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/27/2015 08:57:32 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/27/2015 08:57:32 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/27/2015 08:57:32 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/27/2015 08:57:32 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/27/2015 08:57:32 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/27/2015 08:57:32 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/27/2015 08:57:32 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Microsoft Office Sessions: ========================= Error: (02/03/2013 04:56:00 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 524 seconds with 480 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Processor: Intel(R) Pentium(R) CPU G620 @ 2.60GHz Percentage of memory in use: 42% Total physical RAM: 3054.7 MB Available physical RAM: 1761.32 MB Total Pagefile: 6105.64 MB Available Pagefile: 4434.64 MB Total Virtual: 2047.88 MB Available Virtual: 1912.96 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:836.92 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A27B1D46) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Danke lieber Schrauber du bist Spitze. |
27.01.2015, 13:33 | #112 |
/// the machine /// TB-Ausbilder | Maillaccount gehackt /verschiedene Funde mit Malewarebytes Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.01.2015, 14:33 | #113 |
| Maillaccount gehackt /verschiedene Funde mit Malewarebytes Hallo Schrauber das ASK Toolbar hab ich gelöscht , aber das Iminent finde ich nicht. Hast du noch einen Tip wo ich das finde??? Dankeeeeeeeeeeeee Code:
ATTFilter ComboFix 15-01-27.01 - Antje 27.01.2015 14:17:32.5.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.3055.1839 [GMT 1:00] ausgeführt von:: c:\users\Antje\Downloads\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Antje\AppData\Local\temp\avgnt.exe\Avira.OE.ExtApi.dll . . ((((((((((((((((((((((( Dateien erstellt von 2014-12-27 bis 2015-01-27 )))))))))))))))))))))))))))))) . . 2015-01-27 13:22 . 2015-01-27 13:25 -------- d-----w- c:\users\Antje\AppData\Local\temp 2015-01-27 13:22 . 2015-01-27 13:22 -------- d-----w- c:\users\Public\AppData\Local\temp 2015-01-27 13:22 . 2015-01-27 13:22 -------- d-----w- c:\users\Petzold\AppData\Local\temp 2015-01-27 13:22 . 2015-01-27 13:22 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-01-27 13:22 . 2015-01-27 13:22 -------- d-----w- c:\users\Antje.Antje-PC\AppData\Local\temp 2015-01-27 13:22 . 2015-01-27 13:22 -------- d-----w- c:\users\Administrator\AppData\Local\temp 2015-01-27 13:21 . 2015-01-27 13:21 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FAFB9C13-877F-4E54-B4AB-D2277F5D7794}\offreg.dll 2015-01-27 08:02 . 2014-12-02 11:01 9054624 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FAFB9C13-877F-4E54-B4AB-D2277F5D7794}\mpengine.dll 2015-01-26 20:23 . 2015-01-26 20:23 -------- d-----w- c:\program files\Common Files\Symantec Shared 2015-01-26 20:16 . 2015-01-26 20:16 -------- d-----w- c:\windows\system32\drivers\NSS 2015-01-26 20:16 . 2015-01-26 20:16 -------- d-----w- c:\program files\Norton Security Scan 2015-01-26 20:16 . 2015-01-26 20:16 -------- d-----w- c:\program files\NortonInstaller 2015-01-26 09:30 . 2015-01-26 09:30 -------- d-----w- c:\windows\system32\Adobe 2015-01-25 21:49 . 2015-01-25 21:49 73840 ----a-w- c:\program files\Mozilla Firefox\wow_helper.exe 2015-01-14 07:43 . 2014-12-12 05:11 3971512 ----a-w- c:\windows\system32\ntkrnlpa.exe 2015-01-14 07:43 . 2014-12-12 05:11 3916728 ----a-w- c:\windows\system32\ntoskrnl.exe 2015-01-14 07:42 . 2014-12-19 02:43 164864 ----a-w- c:\windows\system32\profsvc.dll 2015-01-14 07:42 . 2014-12-11 17:47 46592 ----a-w- c:\windows\system32\TSWbPrxy.exe 2015-01-14 07:42 . 2014-12-06 03:50 242688 ----a-w- c:\windows\system32\nlasvc.dll 2015-01-14 07:42 . 2014-12-19 01:34 116224 ----a-w- c:\windows\system32\drivers\mrxdav.sys . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-01-26 22:26 . 2013-12-11 17:20 701616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2015-01-26 22:26 . 2011-12-23 22:54 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2015-01-08 08:55 . 2009-10-14 02:21 249488 ------w- c:\windows\system32\MpSigStub.exe 2014-12-13 03:33 . 2014-12-18 17:28 115712 ----a-w- c:\windows\system32\ieUnatt.exe 2014-12-04 04:38 . 2014-12-10 10:45 337920 ----a-w- c:\windows\system32\generaltel.dll 2014-12-04 04:38 . 2014-12-10 10:45 610304 ----a-w- c:\windows\system32\invagent.dll 2014-12-04 04:38 . 2014-12-10 10:45 315392 ----a-w- c:\windows\system32\devinv.dll 2014-12-04 04:38 . 2014-12-10 10:45 728576 ----a-w- c:\windows\system32\appraiser.dll 2014-12-04 04:38 . 2014-12-10 10:45 159744 ----a-w- c:\windows\system32\aepic.dll 2014-12-04 04:38 . 2014-12-10 10:45 202752 ----a-w- c:\windows\system32\aepdu.dll 2014-12-04 04:34 . 2014-12-10 10:45 873984 ----a-w- c:\windows\system32\aeinv.dll 2014-12-01 23:28 . 2014-12-10 10:45 1160872 ----a-w- c:\windows\system32\aitstatic.exe 2014-11-22 02:20 . 2014-12-10 10:44 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-11-22 02:20 . 2014-12-10 10:45 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-11-22 02:07 . 2014-12-10 10:45 501248 ----a-w- c:\windows\system32\vbscript.dll 2014-11-22 02:07 . 2014-12-10 10:44 62464 ----a-w- c:\windows\system32\iesetup.dll 2014-11-22 02:06 . 2014-12-10 10:45 47616 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-11-22 02:05 . 2014-12-10 10:45 64000 ----a-w- c:\windows\system32\MshtmlDac.dll 2014-11-22 01:55 . 2014-12-10 10:45 102912 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-11-22 01:54 . 2014-12-10 10:45 620032 ----a-w- c:\windows\system32\jscript9diag.dll 2014-11-22 01:48 . 2014-12-10 10:45 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-11-22 01:40 . 2014-12-10 10:45 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2014-11-22 01:29 . 2014-12-10 10:45 4299264 ----a-w- c:\windows\system32\jscript9.dll 2014-11-22 01:22 . 2014-12-10 10:44 2052096 ----a-w- c:\windows\system32\inetcpl.cpl 2014-11-22 01:21 . 2014-12-10 10:45 1155072 ----a-w- c:\windows\system32\mshtmlmedia.dll 2014-11-22 01:00 . 2014-12-10 10:45 1888256 ----a-w- c:\windows\system32\wininet.dll 2014-11-11 02:44 . 2014-12-10 10:45 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll 2014-11-11 02:44 . 2014-11-19 08:21 186880 ----a-w- c:\windows\system32\pku2u.dll 2014-11-11 02:44 . 2014-11-19 08:21 550912 ----a-w- c:\windows\system32\kerberos.dll 2014-11-11 01:32 . 2014-12-10 10:45 74752 ----a-w- c:\windows\system32\drivers\tdx.sys 2014-11-08 02:45 . 2014-12-10 10:44 2048 ----a-w- c:\windows\system32\tzres.dll 2014-11-04 13:56 . 2014-06-28 10:48 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2014-10-30 01:45 . 2014-12-10 10:44 155136 ----a-w- c:\windows\system32\charmap.exe 2013-06-27 15:36 . 2013-06-27 16:14 186752 ----a-w- c:\program files\49res.dll 2013-06-27 15:36 . 2013-06-27 16:14 708168 ----a-w- c:\program files\49Uninstall Utility Chest.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2012-08-17 07:27 220608 ----a-w- c:\users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2012-08-17 07:27 220608 ----a-w- c:\users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2012-08-17 07:27 220608 ----a-w- c:\users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2014-07-25 845120] "KiesPreload"="c:\program files\Samsung\Kies\Kies.exe" [2011-07-26 958352] "AOL Fast Start"="c:\program files\AOL 9.0 VRa\AOL.EXE" [2007-06-21 50480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2011-02-22 2145904] "XFastUsb"="c:\program files\XFastUsb\XFastUsb.exe" [2011-12-23 4942336] "CTSyncService"="c:\program files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" [2009-07-08 1233195] "VolPanel"="c:\program files\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" [2009-05-04 241789] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "RunDLLEntry"="c:\windows\system32\AmbRunE.dll" [2009-02-26 14848] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2014-12-16 702768] "Avira Systray"="c:\program files\Avira\My Avira\Avira.OE.Systray.exe" [2014-08-04 161584] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2014-10-15 157480] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2014-10-02 421888] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768] NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2007-9-14 1695744] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableSecureUIAPath"= 1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^Users^Antje^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk] path=c:\users\Antje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk backup=c:\windows\pss\Dropbox.lnk.Startup backupExtension=.Startup . [HKLM\~\startupfolder\C:^Users^Antje^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk] path=c:\users\Antje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk backup=c:\windows\pss\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2014-12-19 07:48 1022152 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2014-10-11 12:05 60712 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bonus.SSR.FR11] 2011-08-19 00:04 925960 ----a-w- c:\program files\ABBYY FineReader 11\Bonus.ScreenshotReader.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileHippo.com] 2012-11-23 08:22 307712 ----a-w- c:\program files\FileHippo.com\UpdateChecker.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager] 2006-09-26 00:52 50736 ----a-w- c:\program files\Common Files\aol\1324678810\ee\aolsoftware.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2011-05-10 01:41 49208 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2014-10-15 04:42 157480 ----a-w- c:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR] 2014-07-25 08:42 845120 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent] 2014-07-25 08:42 311616 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS] 2011-11-11 13:08 205336 ----a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NUSB3MON] 2011-04-14 17:17 113288 ----a-w- c:\program files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2014-10-02 13:23 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyDrive] 2012-08-17 07:27 238528 ----a-w- c:\users\Antje\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe] 2007-03-14 14:52 3770024 ----a-w- c:\program files\TomTom HOME\TomTomHOME.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrayServer] 2008-08-07 16:18 90112 ----a-w- c:\progra~1\MAGIX\VIDEO_~2\Trayserver.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPatrol] 2014-01-24 02:20 429120 ----a-w- c:\program files\BillP Studios\WinPatrol\WinPatrol.exe . R2 SmartViewService;SmartView service;c:\program files\DeviceVM\SmartView\SmartViewService.exe [x] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-12-23 79360] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-12-23 79360] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2014-06-16 89856] R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800] R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [2012-04-19 29248] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-11-22 102912] R3 MSICDSetup;MSICDSetup;D:\CDriver.sys [x] R3 netr73;RT73 USB-Drahtlos-LAN-Kartentreiber für Vista;c:\windows\system32\DRIVERS\netr73.sys [2009-07-13 545792] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-08-18 600608] R3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [2011-12-23 79360] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2014-06-16 184192] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys [2010-06-11 13832] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-11-14 37352] S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [2011-12-23 14656] S2 ABBYY.Licensing.FineReader.Professional.11.0;ABBYY FineReader 11 PE Licensing Service;c:\program files\ABBYY FineReader 11\NetworkLicenseServer.exe [2011-08-18 819976] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128] S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2014-12-16 431920] S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files\Avira\My Avira\Avira.OE.ServiceHost.exe [2014-08-04 149296] S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376] S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2013-12-30 233472] S2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;c:\program files\Hp\Common\HPSupportSolutionsFrameworkService.exe [2014-07-07 72992] S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2012-07-13 769432] S2 Realtek11nSU;Realtek11nSU;c:\program files\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [2010-04-16 36864] S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2013-08-27 93072] S2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280] S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [2011-02-17 27760] S3 CompFilter;UVCCompositeFilter;c:\windows\system32\DRIVERS\lvbusflt.sys [2012-01-18 22176] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2013-12-30 37344] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2010-08-24 68208] S3 MEI;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECI.sys [2010-10-19 41088] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-04-13 67456] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-04-13 161024] S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Win7 Driver;c:\windows\system32\DRIVERS\wg111v3.sys [2009-11-18 376832] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2011-02-17 1801328] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-10-30 15:56 1089352 ----a-w- c:\program files\Google\Chrome\Application\38.0.2125.111\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2015-01-27 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 22:26] . 2015-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2014-04-18 11:26] . 2015-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2014-04-18 11:26] . 2015-01-27 c:\windows\Tasks\Norton Security Scan for Antje.job - c:\progra~1\NORTON~2\Engine\410~1.28\Nss.exe [2015-01-26 06:04] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.com mStart Page = hxxp://www.google.com uInternet Settings,ProxyOverride = <-loopback>;www.joosoft.com IE: &AOL Toolbar-Suche - c:\program files\aol\aol toolbar 4.0\resources\de-DE\local\search.html IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: {{c0e8ae32-0758-4c8d-ab71-23b361fe8964} - c:\users\Antje\AppData\Local\Temp\ie_script_fwde.htm TCP: DhcpNameServer = 192.168.1.1 DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab FF - ProfilePath - c:\users\Antje\AppData\Roaming\Mozilla\Firefox\Profiles\me88ggay.default\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . MSConfigStartUp-KiesHelper - c:\program files\Samsung\Kies\KiesHelper.exe AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- . - - - - - - - > 'Explorer.exe'(5180) c:\windows\system32\LINKINFO.dll . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\system32\nvvsvc.exe c:\program files\Creative\Shared Files\CTAudSvc.exe c:\windows\system32\atieclxx.exe c:\program files\NVIDIA Corporation\Display\NvXDSync.exe c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Common Files\AOL\ACS\AOLAcsd.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\system32\taskhost.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\sppsvc.exe c:\program files\REALTEK\11n USB Wireless LAN Utility\RtWlan.exe c:\program files\Avira\AntiVir Desktop\avshadow.exe c:\windows\system32\conhost.exe c:\program files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Zeit der Fertigstellung: 2015-01-27 14:28:42 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2015-01-27 13:28 ComboFix2.txt 2014-11-11 13:25 ComboFix3.txt 2014-11-06 12:26 ComboFix4.txt 2014-09-15 19:41 ComboFix5.txt 2015-01-27 13:16 . Vor Suchlauf: 22 Verzeichnis(se), 898.422.071.296 Bytes frei Nach Suchlauf: 23 Verzeichnis(se), 898.220.806.144 Bytes frei . - - End Of File - - 275981886104F9BD3C39588C1F088890 A36C5E4F47E84449FF07ED3517B43A31 Danke Schrauber |
27.01.2015, 20:14 | #114 |
/// the machine /// TB-Ausbilder | Maillaccount gehackt /verschiedene Funde mit Malewarebytes Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.01.2015, 14:13 | #115 |
| Maillaccount gehackt /verschiedene Funde mit MalewarebytesCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Protection, 28.01.2015 08:37:16, SYSTEM, ANTJE-PC, Protection, Malware Protection, Starting, Protection, 28.01.2015 08:37:16, SYSTEM, ANTJE-PC, Protection, Malware Protection, Started, Protection, 28.01.2015 08:37:16, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Starting, Protection, 28.01.2015 08:39:32, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Started, Update, 28.01.2015 08:51:53, SYSTEM, ANTJE-PC, Manual, Malware Database, 2015.1.27.10, 2015.1.28.3, Protection, 28.01.2015 08:51:53, SYSTEM, ANTJE-PC, Protection, Refresh, Starting, Protection, 28.01.2015 08:51:53, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Stopping, Protection, 28.01.2015 08:51:53, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Stopped, Protection, 28.01.2015 08:52:18, SYSTEM, ANTJE-PC, Protection, Refresh, Success, Protection, 28.01.2015 08:52:18, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Starting, Protection, 28.01.2015 08:52:19, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Started, Update, 28.01.2015 10:38:26, SYSTEM, ANTJE-PC, Scheduler, Malware Database, 2015.1.28.3, 2015.1.28.4, Protection, 28.01.2015 10:38:26, SYSTEM, ANTJE-PC, Protection, Refresh, Starting, Protection, 28.01.2015 10:38:26, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Stopping, Protection, 28.01.2015 10:38:26, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Stopped, Protection, 28.01.2015 10:38:31, SYSTEM, ANTJE-PC, Protection, Refresh, Success, Protection, 28.01.2015 10:38:31, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Starting, Protection, 28.01.2015 10:38:32, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Started, Protection, 28.01.2015 10:40:40, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Stopping, Protection, 28.01.2015 10:40:40, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Stopped, Protection, 28.01.2015 10:40:40, SYSTEM, ANTJE-PC, Protection, Malware Protection, Stopping, Protection, 28.01.2015 10:40:40, SYSTEM, ANTJE-PC, Protection, Malware Protection, Stopped, Protection, 28.01.2015 10:40:59, SYSTEM, ANTJE-PC, Protection, Malware Protection, Starting, Protection, 28.01.2015 10:40:59, SYSTEM, ANTJE-PC, Protection, Malware Protection, Started, Protection, 28.01.2015 10:40:59, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Starting, Protection, 28.01.2015 10:40:59, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Started, Update, 28.01.2015 10:41:01, SYSTEM, ANTJE-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1, Update, 28.01.2015 10:41:01, SYSTEM, ANTJE-PC, Manual, Rootkit Database, 2014.11.18.1, 2015.1.14.1, Update, 28.01.2015 10:41:07, SYSTEM, ANTJE-PC, Manual, Malware Database, 2014.11.20.6, 2015.1.28.4, Protection, 28.01.2015 10:41:07, SYSTEM, ANTJE-PC, Protection, Refresh, Starting, Protection, 28.01.2015 10:41:07, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Stopping, Protection, 28.01.2015 10:41:07, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Stopped, Protection, 28.01.2015 10:41:12, SYSTEM, ANTJE-PC, Protection, Refresh, Success, Protection, 28.01.2015 10:41:12, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Starting, Protection, 28.01.2015 10:41:12, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Started, Scan, 28.01.2015 10:52:59, SYSTEM, ANTJE-PC, Manual, Start:28.01.2015 10:42:36, Duration:9 min 38 sec, Threat Scan, Completed, 0 Malware Detections, 3 Non-Malware Detections, Protection, 28.01.2015 10:55:37, SYSTEM, ANTJE-PC, Protection, Malware Protection, Starting, Protection, 28.01.2015 10:55:37, SYSTEM, ANTJE-PC, Protection, Malware Protection, Started, Protection, 28.01.2015 10:55:37, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Starting, Protection, 28.01.2015 10:57:54, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Started, Update, 28.01.2015 11:20:59, SYSTEM, ANTJE-PC, Scheduler, Malware Database, 2015.1.28.4, 2015.1.28.5, Protection, 28.01.2015 11:20:59, SYSTEM, ANTJE-PC, Protection, Refresh, Starting, Protection, 28.01.2015 11:20:59, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Stopping, Protection, 28.01.2015 11:20:59, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Stopped, Protection, 28.01.2015 11:21:22, SYSTEM, ANTJE-PC, Protection, Refresh, Success, Protection, 28.01.2015 11:21:22, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Starting, Protection, 28.01.2015 11:21:22, SYSTEM, ANTJE-PC, Protection, Malicious Website Protection, Started, (end) Lg Und Danke Lotto Code:
ATTFilter # AdwCleaner v4.109 - Bericht erstellt am 28/01/2015 um 13:54:59 # Aktualisiert 24/01/2015 von Xplode # Database : 2015-01-26.1 [Live] # Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits) # Benutzername : Antje - ANTJE-PC # Gestartet von : C:\Users\Antje\Downloads\AdwCleaner_4.109.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Windows\system32\config\systemprofile\AppData\Roaming\Fighters ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Schlüssel Gelöscht : HKCU\Software\Fighters Schlüssel Gelöscht : HKLM\SOFTWARE\Fighters Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>;www.joosoft.com ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17496 -\\ Mozilla Firefox v35.0 (x86 de) -\\ Google Chrome v38.0.2125.111 ************************* AdwCleaner[R0].txt - [13756 octets] - [27/01/2014 19:43:15] AdwCleaner[R1].txt - [3411 octets] - [27/01/2014 19:52:54] AdwCleaner[R2].txt - [1691 octets] - [16/09/2014 15:25:44] AdwCleaner[R3].txt - [1448 octets] - [06/11/2014 14:07:02] AdwCleaner[R4].txt - [1508 octets] - [06/11/2014 14:08:38] AdwCleaner[R5].txt - [9374 octets] - [11/11/2014 13:55:25] AdwCleaner[R6].txt - [1477 octets] - [11/11/2014 14:28:41] AdwCleaner[R7].txt - [1753 octets] - [01/12/2014 19:10:10] AdwCleaner[R8].txt - [2132 octets] - [14/12/2014 10:22:44] AdwCleaner[R9].txt - [2139 octets] - [28/01/2015 13:51:57] AdwCleaner[S0].txt - [13676 octets] - [27/01/2014 19:43:55] AdwCleaner[S1].txt - [2553 octets] - [29/08/2014 09:03:36] AdwCleaner[S2].txt - [1752 octets] - [16/09/2014 15:27:02] AdwCleaner[S3].txt - [1569 octets] - [06/11/2014 14:10:08] AdwCleaner[S4].txt - [9250 octets] - [11/11/2014 13:57:41] AdwCleaner[S5].txt - [2193 octets] - [14/12/2014 10:52:45] AdwCleaner[S6].txt - [2060 octets] - [28/01/2015 13:54:59] ########## EOF - C:\AdwCleaner\AdwCleaner[S6].txt - [2120 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.1 (12.28.2014:1) OS: Windows 7 Ultimate x86 Ran by Antje on 28.01.2015 at 14:02:08,41 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] C:\Program Files\49res.dll Successfully deleted: [File] C:\Program Files\49Uninstall Utility Chest.dll ~~~ Folders Successfully deleted: [Folder] "C:\Program Files\myfree codec" ~~~ FireFox Emptied folder: C:\Users\Antje\AppData\Roaming\mozilla\firefox\profiles\me88ggay.default\minidumps [3 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 28.01.2015 at 14:04:16,30 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ So das war glaub ich alles. Bis später......Dankeeeeeeeeee FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-01-2015 Ran by Antje (administrator) on ANTJE-PC on 28-01-2015 14:08:45 Running from C:\Users\Antje\Downloads Loaded Profiles: Antje (Available profiles: Antje) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AMD) C:\Windows\System32\atiesrxx.exe (Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Creative Technology Ltd) C:\Program Files\Creative\Shared Files\CTAudSvc.exe (AMD) C:\Windows\System32\atieclxx.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (ABBYY) C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (AOL LLC) C:\Program Files\Common Files\aol\acs\AOLacsd.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (Teruten) C:\Windows\System32\FsUsbExService.Exe (VIA) C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (FNet Co., Ltd.) C:\Program Files\XFastUsb\XFastUsb.exe (Creative Technology Ltd) C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe (Creative Technology Ltd) C:\Program Files\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Hewlett-Packard Company) C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Macrovision Europe Ltd.) C:\Users\Antje\AppData\Local\temp\Sound_Blaster_X-Fi_MB_Cleanup.0001 (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (Realtek) C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtlService.exe (Realtek Semiconductor Corp.) C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe () C:\Program Files\NETGEAR\WG111v3\WG111v3.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Creative Labs) C:\Program Files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Farbar) C:\Users\Antje\Downloads\FRST(3).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [2145904 2011-02-22] (VIA) HKLM\...\Run: [XFastUsb] => C:\Program Files\XFastUsb\XFastUsb.exe [4942336 2011-12-23] (FNet Co., Ltd.) HKLM\...\Run: [CTSyncService] => C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe [1233195 2009-07-08] (Creative Technology Ltd) HKLM\...\Run: [VolPanel] => C:\Program Files\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe [241789 2009-05-04] (Creative Technology Ltd) HKLM\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM\...\Run: [RunDLLEntry] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [161584 2014-08-04] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\Run: [KiesPDLR] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-07-25] (Samsung) HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [958352 2011-07-26] (Samsung) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk ShortcutTarget: NETGEAR WG111v3 Smart Wizard.lnk -> C:\Program Files\NETGEAR\WG111v3\WG111v3.exe () BootExecute: autocheck autochk * sdnclean.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:8897;https=127.0.0.1:8897 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://de.search.yahoo.com/?fr=w3i&type=W3i_SP,204,0_0,StartPage,20120101,16988,0,8,0 SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {5D422421-30DD-42B3-826E-9224F52BFC47} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {6D0FF7A0-C6C5-4a24-8F09-C074ED2B20A0} URL = hxxp://de.search.yahoo.com/search?p={searchterms}&ei=UTF-8&fr=w3i&type=W3i_DS,105,0_0,Search,20140622,20250,0,FF29,6923 SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {6DA59B2F-C380-26BF-75EF-54850C7D29F4} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {7D09D9D4-CEDB-47B3-8779-584CFD2BABB0} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {9DDD17F4-2BF7-4662-B5A0-92270A4C54F7} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag= interactivemesuche21&index=blended&linkCode=ur2&camp=1638&creative=6742 SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {B442213A-49FA-404C-8A15-326E8709045B} URL = hxxp://suche.t-online.de/fastcgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&d ia=suche&context=wiki-tab&tpc=internet&ptl=std&classification=wikitab_internet_std&q={searchTerms}&br=ie7-toi SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {BC51C75D-1339-43dd-921D-49F5D0A2F625} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A6976579318&ie=UTF-8&q=&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A6976579318&q={searchTerms} SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {CA25764C-9109-4C88-9615-DCF100F14585} URL = hxxp://suche.t-online.de/fast-cgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&dia=suche&context=internet-tab&tpc=internet&ptl=std&classification=internet-tab_internet_std&q={searchTerms}&br=ie7-toi SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {E8B82BA8-923F-4120-B179-4144137AB04D} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Adblock IE -> {667BEE43-20BD-4CE3-94AC-E63E04D4B191} -> C:\Program Files\MGTEK\Adblock IE\adblockie.dll (MGTEK) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO: AOL Toolbar Launcher -> {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} -> C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC) DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Antje\AppData\Roaming\Mozilla\Firefox\Profiles\me88ggay.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1216156.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-08-03] FF HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR Profile: C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Docs) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-18] CHR Extension: (Google Drive) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-18] CHR Extension: (YouTube) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-18] CHR Extension: (Google Search) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-18] CHR Extension: (Google Wallet) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-18] CHR Extension: (Gmail) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-18] CHR HKLM\...\Chrome\Extension: [aaaaojdbdbhbbkpenbmlejjngphokgnp] - C:\Users\Antje\AppData\Local\APN\GoogleCRXs\aaaaojdbdbhbbkpenbmlejjngphokgnp_7.17.2.0.crx [Not Found] CHR HKLM\...\Chrome\Extension: [caeaobpemokdfnidgaebncaooofnbfha] - C:\Users\Antje\ChromeExtensions\caeaobpemokdfnidgaebncaooofnbfha\amazon-icon-fwde.crx [2014-11-11] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ABBYY.Licensing.FineReader.Professional.11.0; C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe [819976 2011-08-18] (ABBYY) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AOL ACS; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [46640 2006-10-23] (AOL LLC) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [149296 2014-08-04] (Avira Operations GmbH & Co. KG) S3 Creative ALchemy AL6 Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2011-12-23] (Creative Labs) [File not signed] S3 Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2011-12-23] (Creative Labs) [File not signed] R2 CTAudSvcService; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [307200 2009-02-23] (Creative Technology Ltd) [File not signed] S2 Dnscache; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [File not signed] R2 FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [233472 2013-12-30] (Teruten) [File not signed] R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [660992 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [72992 2014-07-07] (Hewlett-Packard Company) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [769432 2012-07-13] (Nero AG) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed] R2 Realtek11nSU; C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed] R3 Sound Blaster X-Fi MB Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [79360 2011-12-23] (Creative Labs) [File not signed] R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-02-17] (VIA Technologies, Inc.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) S2 SmartViewService; C:\Program Files\DeviceVM\SmartView\SmartViewService.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 AsrAppCharger; C:\Windows\System32\DRIVERS\AsrAppCharger.sys [13832 2010-06-11] (Windows (R) Win 7 DDK provider) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-14] (Avira Operations GmbH & Co. KG) R3 CompFilter; C:\Windows\System32\DRIVERS\lvbusflt.sys [22176 2012-01-18] (Logitech Inc.) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [378672 2015-01-26] (Symantec Corporation) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [29248 2012-04-19] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [14656 2011-12-23] (FNet Co., Ltd.) R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [37344 2013-12-30] () [File not signed] R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-01-28] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation) R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [41088 2010-10-19] (Intel Corporation) R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [67456 2011-04-13] (Renesas Electronics Corporation) R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [161024 2011-04-13] (Renesas Electronics Corporation) R3 RTL8187B; C:\Windows\System32\DRIVERS\wg111v3.sys [376832 2009-11-18] (NETGEAR Inc. ) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1801328 2011-02-17] (VIA Technologies, Inc.) R3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-29] (America Online, Inc.) S3 catchme; \??\C:\Users\Antje\AppData\Local\Temp\catchme.sys [X] S3 MSICDSetup; \??\D:\CDriver.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-28 14:07 - 2015-01-28 14:07 - 01121280 _____ (Farbar) C:\Users\Antje\Downloads\FRST(3).exe 2015-01-28 14:04 - 2015-01-28 14:04 - 00000954 _____ () C:\Users\Antje\Desktop\JRT.txt 2015-01-28 14:00 - 2015-01-28 14:00 - 01707939 _____ (Thisisu) C:\Users\Antje\Downloads\JRT(3).exe 2015-01-28 13:51 - 2015-01-28 13:51 - 02194432 _____ () C:\Users\Antje\Downloads\AdwCleaner_4.109.exe 2015-01-28 13:47 - 2015-01-28 13:47 - 00004789 _____ () C:\Users\Antje\Desktop\mbam.txt 2015-01-28 10:53 - 2015-01-28 10:54 - 00001524 _____ () C:\Mwbm.txt 2015-01-28 10:39 - 2015-01-28 10:39 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Antje\Downloads\mbam-setup-2.0.4.1028(1).exe 2015-01-27 22:16 - 2015-01-28 13:59 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-27 22:16 - 2015-01-28 10:40 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-27 22:16 - 2015-01-28 10:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-27 22:16 - 2015-01-28 10:40 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2015-01-27 22:16 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-27 22:16 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-27 22:16 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-27 21:45 - 2015-01-27 21:45 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Antje\Downloads\mbam-setup-2.0.4.1028.exe 2015-01-27 14:28 - 2015-01-27 14:28 - 00022122 _____ () C:\ComboFix.txt 2015-01-27 14:10 - 2015-01-27 14:10 - 05610622 ____R (Swearware) C:\Users\Antje\Downloads\ComboFix.exe 2015-01-27 13:44 - 2015-01-27 13:44 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Antje\Downloads\revosetup95(1).exe 2015-01-27 09:04 - 2015-01-27 09:04 - 01120768 _____ (Farbar) C:\Users\Antje\Downloads\FRST(1).exe 2015-01-27 09:03 - 2015-01-27 09:04 - 01120768 _____ (Farbar) C:\Users\Antje\Downloads\FRST(2).exe 2015-01-26 21:23 - 2015-01-26 21:23 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared 2015-01-26 21:16 - 2015-01-27 08:56 - 00000440 ____H () C:\Windows\Tasks\Norton Security Scan for Antje.job 2015-01-26 21:16 - 2015-01-26 21:16 - 00001415 _____ () C:\Users\Public\Desktop\Norton Security Scan.LNK 2015-01-26 21:16 - 2015-01-26 21:16 - 00000000 ____D () C:\Windows\system32\Drivers\NSS 2015-01-26 21:16 - 2015-01-26 21:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan 2015-01-26 21:16 - 2015-01-26 21:16 - 00000000 ____D () C:\Program Files\Norton Security Scan 2015-01-26 10:30 - 2015-01-26 10:30 - 00000000 ____D () C:\Windows\system32\Adobe 2015-01-26 10:29 - 2015-01-26 10:30 - 13827960 _____ (Adobe Systems Inc.) C:\Users\Antje\Downloads\Shockwave_Installer_Full.exe 2015-01-14 08:43 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-01-14 08:43 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-14 08:42 - 2014-12-19 03:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 08:42 - 2014-12-19 02:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 08:42 - 2014-12-11 18:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-14 08:42 - 2014-12-06 04:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-05 18:46 - 2015-01-05 18:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-28 14:09 - 2014-03-21 21:30 - 00022286 _____ () C:\Users\Antje\Downloads\FRST.txt 2015-01-28 14:08 - 2014-03-21 21:29 - 00000000 ____D () C:\FRST 2015-01-28 14:02 - 2013-04-11 15:27 - 00000000 ____D () C:\ProgramData\TEMP 2015-01-28 14:01 - 2011-12-23 21:41 - 01819505 _____ () C:\Windows\WindowsUpdate.log 2015-01-28 14:01 - 2009-07-14 05:34 - 00020480 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-28 14:01 - 2009-07-14 05:34 - 00020480 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-28 13:58 - 2011-12-29 15:18 - 00000000 ____D () C:\Users\Antje\AppData\Local\CrashDumps 2015-01-28 13:56 - 2014-04-18 12:26 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-28 13:56 - 2013-06-25 14:14 - 00061736 _____ () C:\Windows\setupact.log 2015-01-28 13:56 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-28 13:55 - 2014-04-18 12:26 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-28 13:55 - 2014-01-27 19:43 - 00000000 ____D () C:\AdwCleaner 2015-01-28 13:55 - 2011-12-23 22:19 - 00695362 _____ () C:\Windows\PFRO.log 2015-01-28 13:20 - 2012-04-03 06:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-27 22:16 - 2013-06-13 08:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-27 14:28 - 2014-08-29 08:38 - 00000000 ____D () C:\Qoobox 2015-01-27 14:25 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini 2015-01-27 14:04 - 2012-01-26 12:04 - 00000000 ____D () C:\Users\Antje\AppData\Roaming\Skype 2015-01-27 13:45 - 2014-03-28 10:12 - 00001226 _____ () C:\Users\Antje\Desktop\Revo Uninstaller.lnk 2015-01-27 13:45 - 2014-03-13 16:38 - 00000000 ____D () C:\Program Files\VS Revo Group 2015-01-27 09:12 - 2014-03-21 21:30 - 00038127 _____ () C:\Users\Antje\Downloads\Addition.txt 2015-01-26 23:26 - 2013-12-11 18:20 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-01-26 23:26 - 2011-12-23 23:54 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-01-26 21:16 - 2011-12-23 22:21 - 00000000 ____D () C:\ProgramData\Norton 2015-01-26 11:02 - 2014-09-16 18:23 - 00000000 ____D () C:\Users\Antje\Downloads\FRST-OlderVersion 2015-01-26 11:02 - 2014-03-21 21:29 - 01120768 _____ (Farbar) C:\Users\Antje\Downloads\FRST.exe 2015-01-26 09:34 - 2014-03-30 17:33 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-01-25 22:49 - 2014-03-28 10:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-01-20 10:01 - 2013-08-15 10:02 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-20 09:58 - 2009-10-14 03:21 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-01-11 23:35 - 2009-07-14 05:52 - 00000000 ____D () C:\Windows\system32\FxsTmp 2015-01-08 09:55 - 2009-10-14 03:21 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-01-05 18:51 - 2014-07-04 16:16 - 00000000 ____D () C:\Users\Antje\AppData\Local\Adobe ==================== Files in the root of some directories ======= 2013-06-27 17:14 - 2013-06-27 16:36 - 0186752 _____ () C:\Program Files\49res.dll 2013-06-27 17:14 - 2013-06-27 16:36 - 0708168 _____ (MindSpark) C:\Program Files\49Uninstall Utility Chest.dll 2013-01-10 11:53 - 2013-01-10 12:07 - 0015360 _____ () C:\Users\Antje\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-11-11 17:13 - 2012-11-11 17:13 - 0000048 ___SH () C:\ProgramData\.zreglib 2012-01-21 12:04 - 2014-08-03 10:48 - 0017073 _____ () C:\ProgramData\hpzinstall.log Some content of TEMP: ==================== C:\Users\Antje\AppData\Local\temp\avgnt.exe C:\Users\Antje\AppData\Local\temp\Quarantine.exe C:\Users\Antje\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-25 11:07 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 28-01-2015 Ran by Antje at 2015-01-28 14:09:19 Running from C:\Users\Antje\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden 4500_G510nz_Help (Version: 000.0.439.000 - Hewlett-Packard) Hidden 4500G510nz (Version: 000.0.439.000 - Hewlett-Packard) Hidden 4500G510nz_Software_Min (Version: 000.0.423.000 - Hewlett-Packard) Hidden ABBYY FineReader 11 (HKLM\...\{F1100000-0008-0000-0001-074957833700}) (Version: 11.0.289 - ABBYY) Acrobat.com (Version: 0.0.0 - Adobe Systems Incorporated) Hidden Adblock IE 2.2 (HKLM\...\{56D01524-CD68-4576-B1AE-D572E8EAFF3D}) (Version: 2.2.1524 - MGTEK) Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.6.156 - Adobe Systems, Inc.) AOL Deinstallation (HKLM\...\AOL Deinstallation) (Version: - ) AP Tuner 3.08 (HKLM\...\AP Tuner 3.08) (Version: - ) Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASRock App Charger v1.0.4 (HKLM\...\ASRock App Charger_is1) (Version: - ASRock Inc.) ASRock eXtreme Tuner v0.1.53 (HKLM\...\ASRock eXtreme Tuner_is1) (Version: - ) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.35 - Atheros Communications Inc.) Avira (HKLM\...\{e67154a7-9cc5-4167-b782-f3982bc6c70d}) (Version: 1.1.19.30000 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.19.30000 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) BestPractice (remove only) (HKLM\...\BestPractice) (Version: - ) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) BufferChm (Version: 130.0.331.000 - Hewlett-Packard) Hidden CameraHelperMsi (Version: 13.31.1038.0 - Logitech) Hidden Cisco EAP-FAST Module (HKLM\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) CK Gruß- und Einladungskarten Designer (HKLM\...\{579C4753-8A98-403C-8A04-C576BA8CE26A}) (Version: 1.80.0000 - CK Software) Destinations (Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (Version: 130.0.372.000 - Hewlett-Packard) Hidden DocMgr (Version: 130.0.000.000 - Ihr Firmenname) Hidden DocProc (Version: 13.0.0.0 - Hewlett-Packard) Hidden erLT (Version: 1.20.138.34 - Logitech, Inc.) Hidden Fax (Version: 130.0.418.000 - Hewlett-Packard) Hidden FileHippo.com Update Checker (HKLM\...\FileHippo.com) (Version: - ) Firebird SQL Server - MAGIX Edition (HKLM\...\{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}) (Version: 2.1.27.0 - MAGIX AG) Google Chrome (HKLM\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.) Google Update Helper (Version: 1.3.25.5 - Google Inc.) Hidden GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP) HP Document Manager 2.0 (HKLM\...\HP Document Manager) (Version: 2.0 - HP) HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP) HP Officejet 4500 G510n-z (HKLM\...\{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}) (Version: 13.0 - HP) HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Support Solutions Framework (HKLM\...\{C43602FE-988C-47BA-9F9F-B95FDDAFB624}) (Version: 11.50.0031 - Hewlett-Packard Company) HP Update (HKLM\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard) HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden HPSSupply (Version: 130.0.371.000 - Hewlett-Packard) Hidden iCloud (HKLM\...\{760BB327-3973-4608-85C8-88162E2FF3B6}) (Version: 4.0.6.28 - Apple Inc.) Iminent (Version: 4.10.0.0 - Iminent) Hidden <==== ATTENTION Intel(R) Management Engine Components (HKLM\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Internet Explorer (Version: 9 - Microsoft Corporation) Hidden iTuner (HKLM\...\{C49CBF9A-4AD7-4045-92BD-2C6E45680070}) (Version: 1.0.3 - iAppsPoint) iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.) Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle) Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) Logitech Webcam-Software (HKLM\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.30 - Logitech Inc.) MAGIX Screenshare (HKLM\...\{BB565180-FA52-40DA-A65E-651537008C34}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Speed burnR (MSI) (HKLM\...\{B0975D89-8D51-445C-BB71-95826A96780C}) (Version: 7.0.2.6 - MAGIX AG) MAGIX Video deluxe 17 Premium Download-Version (HKLM\...\MAGIX_MSI_Videodeluxe17_premium) (Version: 10.0.1.14 - MAGIX AG) MAGIX Video deluxe 17 Premium Download-Version (Version: 10.0.1.14 - MAGIX AG) Hidden Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) MarketResearch (Version: 130.0.374.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft SkyDrive (HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\SkyDriveSetup.exe) (Version: 16.4.6010.0727 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 35.0 (x86 de) (HKLM\...\Mozilla Firefox 35.0 (x86 de)) (Version: 35.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) MP3 Rocket (HKLM\...\MP3 Rocket) (Version: - ) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyFreeCodec (HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\MyFreeCodec) (Version: - ) Nero BurningROM 12 (HKLM\...\{3DAFE920-1B88-4C66-A39B-D743F28AF10D}) (Version: 12.5.01300 - Nero AG) NETGEAR WG111v3 wireless USB 2.0 adapter (HKLM\...\InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}) (Version: 1.00.0000 - NETGEAR) NETGEAR WG111v3 wireless USB 2.0 adapter (Version: 1.00.0000 - NETGEAR) Hidden Network (Version: 130.0.374.000 - Hewlett-Packard) Hidden Norton Internet Security (Version: 18.1.0.37 - Symantec Corporation) Hidden Norton Security Scan (HKLM\...\NSS) (Version: 4.1.0.28 - Symantec Corporation) NVIDIA Grafiktreiber 267.42 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 267.42 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.10.0514 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.10.0514 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (HKLM\...\NVIDIAStereo) (Version: 7.17.12.6742 - NVIDIA Corporation) OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP) Platform (Version: 1.36 - VIA Technologies, Inc.) Hidden Prerequisite installer (Version: 12.0.0003 - Nero AG) Hidden QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) REALTEK Wireless LAN Driver and Utility (HKLM\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0165 - REALTEK Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.16.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.1.16.0 - Renesas Electronics Corporation) Hidden Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Samplitude Music Studio 17 Content Pack (HKLM\...\{B6FE6F0D-688B-458B-9E12-0F55E4009561}) (Version: 1.0.0.0 - MAGIX AG) Samplitude Music Studio 17 Download-Version (Version: 17.0.0.0 - MAGIX AG) Hidden Samplitude Music Studio 17 Vita Pack 1 (HKLM\...\{EE3264C1-2501-4D58-9B57-4D3F2F502599}) (Version: 1.0.0.0 - MAGIX AG) Samplitude Music Studio 17 Vita Pack 2 (HKLM\...\{63D7FB4F-01A1-4A8B-9180-FF2FEF369AC8}) (Version: 1.0.0.0 - MAGIX AG) Samplitude Music Studio 17 Vita Pack 3 (HKLM\...\{33F9A189-4F02-4784-8A57-F3983F9F9217}) (Version: 1.0.0.0 - MAGIX AG) Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.0.2.11071_128 - Samsung Electronics Co., Ltd.) Samsung Kies (Version: 2.0.2.11071_128 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.) Scan (Version: 13.0.0.0 - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP) Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.8.8855 - Skype Technologies S.A.) Skype™ 5.5 (HKLM\...\{AA59DDE4-B672-4621-A016-4C248204957A}) (Version: 5.5.124 - Skype Technologies S.A.) Smart OCR 3.2.1.417 (HKLM\...\Smart OCR_is1) (Version: 3.2.1.417 - SmartSoft, LLC.) SmartWebPrinting (Version: 130.0.373.000 - Hewlett-Packard) Hidden SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden Sound Blaster X-Fi MB (HKLM\...\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}) (Version: 1.0 - Creative Technology Limited) Sound Effects (HKLM\...\{A044C900-5DE1-4986-B0B8-D6A40271A929}) (Version: 2.0 - Music Oasis) Splashtop Connect IE (HKLM\...\{F9F5EF72-18CF-4DCF-A721-EC86B94DAC46}) (Version: 1.1.12.1 - Splashtop Inc.) SpywareBlaster 5.0 (HKLM\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC) Status (Version: 130.0.373.000 - Hewlett-Packard) Hidden SumatraPDF (HKLM\...\SumatraPDF) (Version: 2.2.1 - Krzysztof Kowalczyk) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Text-To-Speech-Runtime (HKLM\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH) TomTom HOME (HKLM\...\{99072AB4-D795-44D5-9D65-E3C9F8322C97}) (Version: 2.9.7 - Ihr Firmenname) TomTom HOME Visual Studio Merge Modules (HKLM\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) Toolbox (Version: 130.0.648.000 - Hewlett-Packard) Hidden TrayApp (Version: 130.0.376.000 - Hewlett-Packard) Hidden VIA Plattform-Geräte-Manager (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.36 - VIA Technologies, Inc.) VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN) WebReg (Version: 130.0.132.017 - Hewlett-Packard) Hidden Windows 7 Upgrade Advisor (HKLM\...\{9A4D182C-35C7-4791-8484-4304EBC9101A}) (Version: 2.0.5000.0 - Microsoft Corporation) WinPatrol (HKLM\...\{84481A87-2316-4923-8FAB-3BA8CA29323D}) (Version: 30.0.2014.0 - BillP Studios) WinRAR 5.01 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) XFastUsb (HKLM\...\XFastUsb) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{1853e19a-4e54-4190-8deb-2e1cc947cd60}\InprocServer32 -> C:\Program Files\AOL 9.0 VRa\axtrack.dll (AOL, LLC.) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{248FDB00-ABE4-DA9A-AEAA-45651873E13C}\InprocServer32 -> C:\Windows\system32\ole32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{7629C9DE-2E38-4963-A01C-02FFAC203D87}\InprocServer32 -> C:\Program Files\AOL 9.0 VRa\axtrack.dll (AOL, LLC.) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}\localserver32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}\localserver32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{B9F3009B-976B-41C4-A992-229DCCF3367C}\InprocServer32 -> C:\Program Files\AOL 9.0 VRa\axtrack.dll (AOL, LLC.) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\FileSyncApi.dll (Microsoft Corporation) ==================== Restore Points ========================= 30-12-2014 09:42:17 Windows Update 02-01-2015 13:12:07 Windows Update 06-01-2015 16:44:17 Windows Update 09-01-2015 17:10:05 Windows Update 14-01-2015 08:42:35 Windows Update 20-01-2015 09:55:40 Windows Update 23-01-2015 10:35:22 Windows Update 27-01-2015 09:01:46 Windows Update 27-01-2015 13:50:14 Revo Uninstaller's restore point - Ask Toolbar ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2015-01-27 14:22 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {03AF9F3C-D4C3-4C66-B3FF-94385E5067CD} - System32\Tasks\{B884BA27-1BA3-408A-81E3-F2C080791443} => pcalua.exe -a C:\Users\Antje\AppData\Local\Temp\Temp1_BEHRINGER_2902_WIN32_2.8.40.zip\BEHRINGER_2902_WIN32_2.8.40\BEHRINGER_2902_WIN32_2.8.40\Setup.exe Task: {045F01F1-6A51-4ECF-B1DD-8CCF826C5DFB} - System32\Tasks\{FFB24C49-EC37-46CD-A216-976544BB8314} => pcalua.exe -a C:\Users\Antje\Desktop\JRT.exe -d C:\Users\Antje\Desktop Task: {22297514-A4E0-4D1E-9455-F8E19C59CD27} - System32\Tasks\{7D903461-66BC-4061-85C9-3F8FA32A51B9} => C:\Program Files\AOL 9.0 VRa\aol.exe [2007-06-21] (AOL, LLC.) Task: {34A7E8FD-E08C-40C8-B837-2E80BE0A306C} - System32\Tasks\{8F4BC908-16EF-4848-947E-84237ECB4017} => pcalua.exe -a "C:\Users\Antje\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\39AZ0FF2\JavaSetup6u30[1].exe" -d "C:\Program Files\AOL 9.0 VR\download" Task: {3E3A8E37-D463-4D55-AB37-945CB206B155} - System32\Tasks\{C6D23163-BC45-4502-81AE-7D050066D03F} => C:\Program Files\AOL 9.0 VRa\aol.exe [2007-06-21] (AOL, LLC.) Task: {40EFC56F-9252-4B38-B5DD-057EF1F79324} - System32\Tasks\{CB4134A4-24E6-4801-AD5D-F14F348B4F3F} => pcalua.exe -a C:\Users\Antje\Desktop\bpsetup_1_03_1.exe -d C:\Users\Antje\Desktop Task: {41E884C9-AD6D-4197-8528-7D37E6577D28} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {41FC715C-F2C7-4235-9B69-75187C62DB23} - System32\Tasks\{4587AF3A-277F-45C9-B12C-16027686B52D} => pcalua.exe -a "C:\Program Files\VS Revo Group\Revo Uninstaller\Revouninstaller.exe" -d "C:\Program Files\VS Revo Group\Revo Uninstaller" Task: {52868A61-6D7B-4124-B8B9-513939B660F8} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-26] (Adobe Systems Incorporated) Task: {5A682855-60A2-47AA-930F-F7825730797E} - System32\Tasks\Norton Security Scan for Antje => C:\Program Files\Norton Security Scan\Engine\4.1.0.28\Nss.exe [2014-01-27] (Symantec Corporation) Task: {5DEFCCC0-E74F-468D-A8F6-4F22F81036C4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-18] (Google Inc.) Task: {64D1831E-C822-4FCA-947A-B5016AD58892} - System32\Tasks\{3675A0DE-B202-46D2-A003-B992F464AB20} => C:\Program Files\AOL 9.0 VRa\aol.exe [2007-06-21] (AOL, LLC.) Task: {8C20516A-0854-4055-9DDA-07F5D365959F} - System32\Tasks\{A56D0839-9B1E-4606-AE99-6CAD37FD905C} => C:\Program Files\Lexmark X1100 Series\LXBKaiox.exe Task: {8F558DF4-0619-444D-9F4F-4EF9E314EDFC} - System32\Tasks\{2924322F-7F67-4D89-8E43-BB513C3355D9} => pcalua.exe -a "C:\Program Files\PDFReader\Uninstall\Uninstall.exe" -c /Uninstall Task: {94904DBE-DBE1-4386-9DE3-1C4E1D91C064} - System32\Tasks\{9DA0F427-D915-4923-B20B-1FA49027F5E0} => C:\Program Files\Lexmark X1100 Series\LXBKaiox.exe Task: {97F8691A-B0E3-4043-8305-1F364FA2C414} - System32\Tasks\{16F0FB3C-EDC9-4C3C-8E77-E44A47D38837} => pcalua.exe -a C:\Users\Antje\Downloads\OJ4500vG510n-z_Full_13.exe -d C:\Users\Antje\Downloads Task: {9B27E834-691C-45FF-829F-B0A49E17AE7F} - System32\Tasks\{D85521BE-0739-42B1-A58D-22BB371F9D3F} => pcalua.exe -a C:\Users\Antje\AppData\Local\temp\Temp1_hm5-de-demo.zip\setup.exe Task: {A10ECCC0-1B66-4A86-9C89-4C1818EBA884} - System32\Tasks\{B10FAAC6-490F-473F-82EE-FAC8F3944A72} => pcalua.exe -a "C:\Program Files\Common Files\aolshare\aolunins_de.exe" -d "C:\Program Files\Common Files\aolshare" Task: {A772F5F9-4A3A-4937-BFB2-CD9F2B84E04E} - System32\Tasks\{AAEC8B2B-ED52-49A0-BD09-2F6923957A60} => pcalua.exe -a C:\Users\Antje\AppData\Local\Temp\jre-8u20-windows-au.exe -d C:\Windows\system32 -c /installmethod=jau FAMILYUPGRADE=1 Task: {C3FBC991-3D6D-44E0-A406-6BDDC4AC416C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {C85A48C0-2367-4172-9824-7B85B5DC8CE3} - System32\Tasks\{93CF804C-D379-4814-A73F-889901F831EE} => C:\Program Files\AOL 9.0 VRa\aol.exe [2007-06-21] (AOL, LLC.) Task: {CAEE6CC7-AD53-4CC1-A7C7-9724173B870C} - System32\Tasks\{9FF61FC0-5E04-43DB-A5E4-669321A28ECB} => pcalua.exe -a C:\Users\Antje\Documents\APTunerInstall308.exe -d C:\Users\Antje\Documents Task: {DA7A9810-A0B0-4FF4-82D3-BF57EE4B1784} - System32\Tasks\{FC053655-A6D1-46F9-809B-FA9D8B478771} => pcalua.exe -a C:\Users\Antje\AppData\Local\Temp\jre-8u25-windows-au.exe -d C:\Windows\system32 -c /installmethod=jau FAMILYUPGRADE=1 Task: {FECA1FA1-49AA-4917-877A-F2454176197A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-18] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Norton Security Scan for Antje.job => C:\PROGRA~1\NORTON~2\Engine\410~1.28\Nss.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2011-12-23 22:11 - 2011-02-22 07:02 - 00080496 ____R () C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll 2011-12-23 22:11 - 2011-02-22 07:02 - 00113264 ____R () C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll 2011-12-23 22:11 - 2011-02-22 07:02 - 00623216 ____R () C:\Program Files\VIA\VIAudioi\VDeck\Skin.dll 2015-01-28 13:56 - 2015-01-28 13:56 - 00697884 _____ () C:\Users\Antje\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0000\~df394b.tmp 2015-01-28 13:56 - 2015-01-28 13:56 - 00592896 _____ () C:\Users\Antje\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0000\~de6248.tmp 2011-12-23 22:18 - 2009-02-06 18:52 - 00073728 _____ () C:\Windows\SYSTEM32\CmdRtr.DLL 2011-12-23 22:18 - 2009-04-20 11:55 - 00148480 _____ () C:\Windows\SYSTEM32\APOMngr.DLL 2015-01-28 08:36 - 2014-08-04 13:20 - 00052472 _____ () C:\Users\Antje\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2014-08-04 13:20 - 2014-08-04 13:20 - 00139056 _____ () C:\Program Files\Avira\My Avira\Avira.OE.NativeCore.dll 2011-12-23 22:28 - 2009-12-09 21:20 - 00126976 _____ () C:\Program Files\REALTEK\11n USB Wireless LAN Utility\EnumDevLib.dll 2014-08-04 13:20 - 2014-08-04 13:20 - 00067832 _____ () C:\Program Files\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2007-09-14 09:26 - 2007-09-14 09:26 - 01695744 _____ () C:\Program Files\NETGEAR\WG111v3\WG111v3.exe 2014-03-30 17:32 - 2015-01-25 22:49 - 03925104 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:373E1720 AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Antje^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupfolder: C:^Users^Antje^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk => C:\Windows\pss\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: Bonus.SSR.FR11 => "C:\Program Files\ABBYY FineReader 11\Bonus.ScreenshotReader.exe" /autorun MSCONFIG\startupreg: FileHippo.com => "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background MSCONFIG\startupreg: HostManager => C:\Program Files\Common Files\AOL\1324678810\ee\AOLSoftware.exe MSCONFIG\startupreg: HP Software Update => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: KiesPDLR => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: LWS => C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide MSCONFIG\startupreg: NUSB3MON => "C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SkyDrive => "C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background MSCONFIG\startupreg: TomTomHOME.exe => "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s MSCONFIG\startupreg: TrayServer => C:\PROGRA~1\MAGIX\VIDEO_~2\TrayServer.exe MSCONFIG\startupreg: WinPatrol => C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot ========================= Accounts: ========================== Administrator (S-1-5-21-1184766340-1357020511-1184547663-500 - Administrator - Disabled) Antje (S-1-5-21-1184766340-1357020511-1184547663-1000 - Administrator - Enabled) => C:\Users\Antje Gast (S-1-5-21-1184766340-1357020511-1184547663-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1184766340-1357020511-1184547663-1002 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= Name: Officejet 4500 G510n-z Description: Officejet 4500 G510n-z Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} Manufacturer: HP Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Officejet 4500 G510n-z Description: Officejet 4500 G510n-z Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: HP Service: StillCam Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= Error: (02/03/2013 04:56:00 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 524 seconds with 480 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Processor: Intel(R) Pentium(R) CPU G620 @ 2.60GHz Percentage of memory in use: 41% Total physical RAM: 3054.7 MB Available physical RAM: 1799.68 MB Total Pagefile: 6105.64 MB Available Pagefile: 4375.46 MB Total Virtual: 2047.88 MB Available Virtual: 1912.3 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:834.52 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A27B1D46) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
28.01.2015, 18:06 | #116 |
/// the machine /// TB-Ausbilder | Maillaccount gehackt /verschiedene Funde mit MalewarebytesESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.01.2015, 20:38 | #117 |
| Maillaccount gehackt /verschiedene Funde mit MalewarebytesCode:
ATTFilter C:\AdwCleaner\Quarantine\C\Program Files\MyPC Backup\MyPC Backup.exe.vir Variante von MSIL/MyPCBackup.A evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\Optimizer Pro\OptimizerPro.exe.vir Variante von Win32/SpeedingUpMyPC Anwendung Gesäubert durch Löschen - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\Optimizer Pro\OptProCrash.dll.vir Variante von Win32/SProtector.L evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\Optimizer Pro\OptProSmartScan.exe.vir Variante von Win32/Adware.SpeedingUpMyPC.C Anwendung Gesäubert durch Löschen - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\DpInterface32.dll.vir Win32/Thinknice.E evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\DpInterface64.dll.vir Win64/Thinknice.F evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\HpUI.exe.vir Variante von Win32/Thinknice.F evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\Loader32.exe.vir Win32/Thinknice.E evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\Loader64.exe.vir Win64/Thinknice.E evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\RSHP.exe.vir Win32/Thinknice.G evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\SearchProtect32.dll.vir Variante von Win32/Thinknice.E evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\SearchProtect64.dll.vir Win64/Thinknice.F evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\SupIePluginServiceUpdate.exe.vir Variante von Win32/ELEX.AV evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\SupTab.dll.vir Win32/Thinknice.B evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\uninstall.exe.vir Win32/Thinknice.E evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\WindowsSupportDll32.dll.vir Variante von Win32/Thinknice.F evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Program Files\SupTab\WindowsSupportDll64.dll.vir Variante von Win32/Thinknice.F evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\ProgramData\CoupScanner\NdhmOa53Fxh5ZB.dll.vir Variante von Win32/Adware.MultiPlug.EG Anwendung Gesäubert durch Löschen - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\ProgramData\CoupScanner\NdhmOa53Fxh5ZB.exe.vir Variante von Win32/AdWare.MultiPlug.BN Anwendung Gesäubert durch Löschen - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir Variante von Win32/ELEX.AV evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Users\Antje\AppData\Local\Temp\OptimizerPro.exe.vir Variante von Win32/OptimizerEliteMax.C evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Users\Antje\AppData\Roaming\Mozilla\Firefox\Profiles\me88ggay.default\Extensions\I1D@1yVz.org\content\bg.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Users\Antje\AppData\Roaming\Security Systems\uninstall.exe.vir Variante von Win32/Adware.Synatix.A Anwendung Gesäubert durch Löschen - in Quarantäne kopiert C:\AdwCleaner\Quarantine\C\Users\Antje\AppData\Roaming\Systweak\ssd\SSDPTstub.exe.vir Win32/Systweak.G evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Program Files\49Uninstall Utility Chest.dll Win32/Toolbar.MyWebSearch.W evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Qoobox\Quarantine\C\Users\Antje\AppData\Local\nsa84B1.tmp.vir Win32/AnyProtect.F evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Qoobox\Quarantine\C\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\flbijmemdbkngmpkbgodpjhoiicaciol\4.4\QMc.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert C:\Qoobox\Quarantine\C\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmaalfaappddkggilhahaebfhdmmmngf\122\BJ2hAK.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert C:\Users\Antje\Desktop\Musikstudio17\audacity-win-unicode-1.3.12.exe Variante von Win32/Downloader.JooSoft.A evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Users\Antje\Desktop\Neuer Ordner (2)\iLividSetupV1.exe Variante von Win32/Toolbar.SearchSuite.Z evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Users\Antje\Documents\Documents\IE9-WindowsVista-x86-deu.exe Variante von Win32/Downloader.JooSoft.A evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Users\Antje\Documents\Documents\iLividSetupV1.exe Variante von Win32/Toolbar.SearchSuite.Z evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Users\Antje\Downloads\Beauty-Studio---Hair-Master-lnstall.exe Win32/WinloadSDA.I evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Users\Antje\Downloads\cbsidlm-cbsi188-AOL-ORG_DE-75553800.exe Variante von Win32/CNETInstaller.B evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Users\Antje\Downloads\cbsidlm-tr1_13-Adblock_IE-ORG-75650179.exe Win32/DownloadAdmin.G evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Users\Antje\Downloads\cbsidlm-tr1_13-Super_Ad_Blocker-ORG-10295147.exe Win32/DownloadAdmin.G evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Users\Antje\Downloads\cbsidlm-tr1_13-WOT_Web_of_Trust_for_Internet_Explorer-ORG-10777505.exe Win32/DownloadAdmin.G evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Users\Antje\Downloads\install_flash_player_32bit.exe Variante von Win32/Downloader.JooSoft.A evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Users\Antje\Downloads\mp3rocket.exe Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert C:\Windows\Installer\ce4d4d.msi Variante von Win32/Toolbar.Iminent.E evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert Code:
ATTFilter UNSUPPORTED OPERATING SYSTEM! ABORTED! LG Lotto |
29.01.2015, 07:13 | #118 |
/// the machine /// TB-Ausbilder | Maillaccount gehackt /verschiedene Funde mit Malewarebytes Passt schon, das frische FRST log und die Antwort auf meine Frage fehlt aber noch
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.01.2015, 10:57 | #119 |
| Maillaccount gehackt /verschiedene Funde mit MalewarebytesFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-01-2015 01 Ran by Antje (administrator) on ANTJE-PC on 29-01-2015 10:32:52 Running from C:\Users\Antje\Downloads Loaded Profiles: Antje (Available profiles: Antje) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AMD) C:\Windows\System32\atiesrxx.exe (Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Creative Technology Ltd) C:\Program Files\Creative\Shared Files\CTAudSvc.exe (AMD) C:\Windows\System32\atieclxx.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (ABBYY) C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (AOL LLC) C:\Program Files\Common Files\aol\acs\AOLacsd.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (Teruten) C:\Windows\System32\FsUsbExService.Exe (VIA) C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (FNet Co., Ltd.) C:\Program Files\XFastUsb\XFastUsb.exe (Creative Technology Ltd) C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe (Creative Technology Ltd) C:\Program Files\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Hewlett-Packard Company) C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe (Macrovision Europe Ltd.) C:\Users\Antje\AppData\Local\temp\Sound_Blaster_X-Fi_MB_Cleanup.0001 (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe () C:\Program Files\NETGEAR\WG111v3\WG111v3.exe (AOL, LLC.) C:\Program Files\AOL 9.0 VRa\waol.exe (America Online, Inc.) C:\Program Files\Common Files\aol\1324678810\ee\aolsoftware.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (Realtek) C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtlService.exe (Realtek Semiconductor Corp.) C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (AOL, LLC.) C:\Program Files\AOL 9.0 VRa\shellmon.exe (Creative Labs) C:\Program Files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [2145904 2011-02-22] (VIA) HKLM\...\Run: [XFastUsb] => C:\Program Files\XFastUsb\XFastUsb.exe [4942336 2011-12-23] (FNet Co., Ltd.) HKLM\...\Run: [CTSyncService] => C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe [1233195 2009-07-08] (Creative Technology Ltd) HKLM\...\Run: [VolPanel] => C:\Program Files\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe [241789 2009-05-04] (Creative Technology Ltd) HKLM\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM\...\Run: [RunDLLEntry] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [161584 2014-08-04] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\Run: [KiesPDLR] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-07-25] (Samsung) HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [958352 2011-07-26] (Samsung) HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\Run: [AOL Fast Start] => C:\Program Files\AOL 9.0 VRa\AOL.EXE [50480 2007-06-21] (AOL, LLC.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk ShortcutTarget: NETGEAR WG111v3 Smart Wizard.lnk -> C:\Program Files\NETGEAR\WG111v3\WG111v3.exe () BootExecute: autocheck autochk * sdnclean.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:8897;https=127.0.0.1:8897 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://de.search.yahoo.com/?fr=w3i&type=W3i_SP,204,0_0,StartPage,20120101,16988,0,8,0 SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {5D422421-30DD-42B3-826E-9224F52BFC47} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {6D0FF7A0-C6C5-4a24-8F09-C074ED2B20A0} URL = hxxp://de.search.yahoo.com/search?p={searchterms}&ei=UTF-8&fr=w3i&type=W3i_DS,105,0_0,Search,20140622,20250,0,FF29,6923 SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {6DA59B2F-C380-26BF-75EF-54850C7D29F4} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {7D09D9D4-CEDB-47B3-8779-584CFD2BABB0} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {9DDD17F4-2BF7-4662-B5A0-92270A4C54F7} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag= interactivemesuche21&index=blended&linkCode=ur2&camp=1638&creative=6742 SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {B442213A-49FA-404C-8A15-326E8709045B} URL = hxxp://suche.t-online.de/fastcgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&d ia=suche&context=wiki-tab&tpc=internet&ptl=std&classification=wikitab_internet_std&q={searchTerms}&br=ie7-toi SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {BC51C75D-1339-43dd-921D-49F5D0A2F625} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A6976579318&ie=UTF-8&q=&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A6976579318&q={searchTerms} SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {CA25764C-9109-4C88-9615-DCF100F14585} URL = hxxp://suche.t-online.de/fast-cgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&dia=suche&context=internet-tab&tpc=internet&ptl=std&classification=internet-tab_internet_std&q={searchTerms}&br=ie7-toi SearchScopes: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000 -> {E8B82BA8-923F-4120-B179-4144137AB04D} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Adblock IE -> {667BEE43-20BD-4CE3-94AC-E63E04D4B191} -> C:\Program Files\MGTEK\Adblock IE\adblockie.dll (MGTEK) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO: AOL Toolbar Launcher -> {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} -> C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC) DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Antje\AppData\Roaming\Mozilla\Firefox\Profiles\me88ggay.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1216156.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-08-03] FF HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR Profile: C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Docs) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-18] CHR Extension: (Google Drive) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-18] CHR Extension: (YouTube) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-18] CHR Extension: (Google Search) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-18] CHR Extension: (Google Wallet) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-18] CHR Extension: (Gmail) - C:\Users\Antje\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-18] CHR HKLM\...\Chrome\Extension: [aaaaojdbdbhbbkpenbmlejjngphokgnp] - C:\Users\Antje\AppData\Local\APN\GoogleCRXs\aaaaojdbdbhbbkpenbmlejjngphokgnp_7.17.2.0.crx [Not Found] CHR HKLM\...\Chrome\Extension: [caeaobpemokdfnidgaebncaooofnbfha] - C:\Users\Antje\ChromeExtensions\caeaobpemokdfnidgaebncaooofnbfha\amazon-icon-fwde.crx [2014-11-11] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ABBYY.Licensing.FineReader.Professional.11.0; C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe [819976 2011-08-18] (ABBYY) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AOL ACS; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [46640 2006-10-23] (AOL LLC) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [149296 2014-08-04] (Avira Operations GmbH & Co. KG) S3 Creative ALchemy AL6 Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2011-12-23] (Creative Labs) [File not signed] S3 Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2011-12-23] (Creative Labs) [File not signed] R2 CTAudSvcService; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [307200 2009-02-23] (Creative Technology Ltd) [File not signed] S2 Dnscache; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [File not signed] R2 FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [233472 2013-12-30] (Teruten) [File not signed] R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [660992 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [72992 2014-07-07] (Hewlett-Packard Company) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [769432 2012-07-13] (Nero AG) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed] R2 Realtek11nSU; C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed] R3 Sound Blaster X-Fi MB Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [79360 2011-12-23] (Creative Labs) [File not signed] R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-02-17] (VIA Technologies, Inc.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) S2 SmartViewService; C:\Program Files\DeviceVM\SmartView\SmartViewService.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 AsrAppCharger; C:\Windows\System32\DRIVERS\AsrAppCharger.sys [13832 2010-06-11] (Windows (R) Win 7 DDK provider) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-14] (Avira Operations GmbH & Co. KG) R3 CompFilter; C:\Windows\System32\DRIVERS\lvbusflt.sys [22176 2012-01-18] (Logitech Inc.) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [29248 2012-04-19] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [14656 2011-12-23] (FNet Co., Ltd.) R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [37344 2013-12-30] () [File not signed] R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-01-29] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation) R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [41088 2010-10-19] (Intel Corporation) R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [67456 2011-04-13] (Renesas Electronics Corporation) R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [161024 2011-04-13] (Renesas Electronics Corporation) R3 RTL8187B; C:\Windows\System32\DRIVERS\wg111v3.sys [376832 2009-11-18] (NETGEAR Inc. ) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1801328 2011-02-17] (VIA Technologies, Inc.) R3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-29] (America Online, Inc.) S3 catchme; \??\C:\Users\Antje\AppData\Local\Temp\catchme.sys [X] S3 MSICDSetup; \??\D:\CDriver.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-28 20:38 - 2015-01-28 20:38 - 00852573 _____ () C:\Users\Antje\Downloads\SecurityCheck(2).exe 2015-01-28 20:34 - 2015-01-28 20:34 - 00852573 _____ () C:\Users\Antje\Downloads\SecurityCheck(1).exe 2015-01-28 18:56 - 2015-01-28 18:56 - 02347384 _____ (ESET) C:\Users\Antje\Downloads\esetsmartinstaller_deu.exe 2015-01-28 14:04 - 2015-01-28 14:04 - 00000954 _____ () C:\Users\Antje\Desktop\JRT.txt 2015-01-28 14:00 - 2015-01-28 14:00 - 01707939 _____ (Thisisu) C:\Users\Antje\Downloads\JRT(3).exe 2015-01-28 13:51 - 2015-01-28 13:51 - 02194432 _____ () C:\Users\Antje\Downloads\AdwCleaner_4.109.exe 2015-01-28 13:47 - 2015-01-28 13:47 - 00004789 _____ () C:\Users\Antje\Desktop\mbam.txt 2015-01-28 10:53 - 2015-01-28 10:54 - 00001524 _____ () C:\Mwbm.txt 2015-01-28 10:39 - 2015-01-28 10:39 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Antje\Downloads\mbam-setup-2.0.4.1028(1).exe 2015-01-27 22:16 - 2015-01-29 10:26 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-27 22:16 - 2015-01-28 10:40 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-27 22:16 - 2015-01-28 10:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-27 22:16 - 2015-01-28 10:40 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2015-01-27 22:16 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-27 22:16 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-27 22:16 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-27 21:45 - 2015-01-27 21:45 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Antje\Downloads\mbam-setup-2.0.4.1028.exe 2015-01-27 14:28 - 2015-01-27 14:28 - 00022122 _____ () C:\ComboFix.txt 2015-01-27 14:10 - 2015-01-27 14:10 - 05610622 ____R (Swearware) C:\Users\Antje\Downloads\ComboFix.exe 2015-01-27 13:44 - 2015-01-27 13:44 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Antje\Downloads\revosetup95(1).exe 2015-01-26 21:23 - 2015-01-28 20:43 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared 2015-01-26 10:30 - 2015-01-26 10:30 - 00000000 ____D () C:\Windows\system32\Adobe 2015-01-26 10:29 - 2015-01-26 10:30 - 13827960 _____ (Adobe Systems Inc.) C:\Users\Antje\Downloads\Shockwave_Installer_Full.exe 2015-01-14 08:43 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-01-14 08:43 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-14 08:42 - 2014-12-19 03:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 08:42 - 2014-12-19 02:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 08:42 - 2014-12-11 18:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-14 08:42 - 2014-12-06 04:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-05 18:46 - 2015-01-05 18:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-29 10:33 - 2014-03-21 21:30 - 00022523 _____ () C:\Users\Antje\Downloads\FRST.txt 2015-01-29 10:32 - 2014-09-16 18:23 - 00000000 ____D () C:\Users\Antje\Downloads\FRST-OlderVersion 2015-01-29 10:32 - 2014-03-21 21:29 - 01121792 _____ (Farbar) C:\Users\Antje\Downloads\FRST.exe 2015-01-29 10:32 - 2014-03-21 21:29 - 00000000 ____D () C:\FRST 2015-01-29 10:20 - 2012-04-03 06:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-29 10:11 - 2009-07-14 05:34 - 00020480 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-29 10:11 - 2009-07-14 05:34 - 00020480 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-29 09:55 - 2014-04-18 12:26 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-29 09:55 - 2011-12-23 21:41 - 01862577 _____ () C:\Windows\WindowsUpdate.log 2015-01-29 09:54 - 2011-12-29 15:18 - 00000000 ____D () C:\Users\Antje\AppData\Local\CrashDumps 2015-01-29 09:51 - 2014-04-18 12:26 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-29 09:51 - 2013-06-25 14:14 - 00061792 _____ () C:\Windows\setupact.log 2015-01-29 09:51 - 2011-12-23 22:19 - 00704698 _____ () C:\Windows\PFRO.log 2015-01-29 09:51 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-28 20:22 - 2011-12-24 00:09 - 00000000 ____D () C:\Users\Antje\Desktop\Neuer Ordner (2) 2015-01-28 20:22 - 2011-12-24 00:04 - 00000000 ____D () C:\Users\Antje\Desktop\Musikstudio17 2015-01-28 17:09 - 2009-07-14 03:04 - 00000772 _____ () C:\Windows\win.ini 2015-01-28 14:09 - 2014-03-21 21:30 - 00029568 _____ () C:\Users\Antje\Downloads\Addition.txt 2015-01-28 14:02 - 2013-04-11 15:27 - 00000000 ____D () C:\ProgramData\TEMP 2015-01-28 13:55 - 2014-01-27 19:43 - 00000000 ____D () C:\AdwCleaner 2015-01-27 22:16 - 2013-06-13 08:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-27 14:28 - 2014-08-29 08:38 - 00000000 ____D () C:\Qoobox 2015-01-27 14:25 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini 2015-01-27 14:04 - 2012-01-26 12:04 - 00000000 ____D () C:\Users\Antje\AppData\Roaming\Skype 2015-01-27 13:45 - 2014-03-28 10:12 - 00001226 _____ () C:\Users\Antje\Desktop\Revo Uninstaller.lnk 2015-01-27 13:45 - 2014-03-13 16:38 - 00000000 ____D () C:\Program Files\VS Revo Group 2015-01-26 23:26 - 2013-12-11 18:20 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-01-26 23:26 - 2011-12-23 23:54 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-01-26 21:16 - 2011-12-23 22:21 - 00000000 ____D () C:\ProgramData\Norton 2015-01-26 09:34 - 2014-03-30 17:33 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-01-25 22:49 - 2014-03-28 10:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-01-20 10:01 - 2013-08-15 10:02 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-20 09:58 - 2009-10-14 03:21 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-01-11 23:35 - 2009-07-14 05:52 - 00000000 ____D () C:\Windows\system32\FxsTmp 2015-01-08 09:55 - 2009-10-14 03:21 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-01-05 18:51 - 2014-07-04 16:16 - 00000000 ____D () C:\Users\Antje\AppData\Local\Adobe ==================== Files in the root of some directories ======= 2013-06-27 17:14 - 2013-06-27 16:36 - 0186752 _____ () C:\Program Files\49res.dll 2013-01-10 11:53 - 2013-01-10 12:07 - 0015360 _____ () C:\Users\Antje\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-11-11 17:13 - 2012-11-11 17:13 - 0000048 ___SH () C:\ProgramData\.zreglib 2012-01-21 12:04 - 2014-08-03 10:48 - 0017073 _____ () C:\ProgramData\hpzinstall.log Some content of TEMP: ==================== C:\Users\Antje\AppData\Local\temp\avgnt.exe C:\Users\Antje\AppData\Local\temp\Quarantine.exe C:\Users\Antje\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-25 11:07 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 28-01-2015 01 Ran by Antje at 2015-01-29 10:33:23 Running from C:\Users\Antje\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden 4500_G510nz_Help (Version: 000.0.439.000 - Hewlett-Packard) Hidden 4500G510nz (Version: 000.0.439.000 - Hewlett-Packard) Hidden 4500G510nz_Software_Min (Version: 000.0.423.000 - Hewlett-Packard) Hidden ABBYY FineReader 11 (HKLM\...\{F1100000-0008-0000-0001-074957833700}) (Version: 11.0.289 - ABBYY) Acrobat.com (Version: 0.0.0 - Adobe Systems Incorporated) Hidden Adblock IE 2.2 (HKLM\...\{56D01524-CD68-4576-B1AE-D572E8EAFF3D}) (Version: 2.2.1524 - MGTEK) Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.6.156 - Adobe Systems, Inc.) AOL Deinstallation (HKLM\...\AOL Deinstallation) (Version: - ) AP Tuner 3.08 (HKLM\...\AP Tuner 3.08) (Version: - ) Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASRock App Charger v1.0.4 (HKLM\...\ASRock App Charger_is1) (Version: - ASRock Inc.) ASRock eXtreme Tuner v0.1.53 (HKLM\...\ASRock eXtreme Tuner_is1) (Version: - ) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.35 - Atheros Communications Inc.) Avira (HKLM\...\{e67154a7-9cc5-4167-b782-f3982bc6c70d}) (Version: 1.1.19.30000 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.19.30000 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) BestPractice (remove only) (HKLM\...\BestPractice) (Version: - ) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) BufferChm (Version: 130.0.331.000 - Hewlett-Packard) Hidden CameraHelperMsi (Version: 13.31.1038.0 - Logitech) Hidden Cisco EAP-FAST Module (HKLM\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) CK Gruß- und Einladungskarten Designer (HKLM\...\{579C4753-8A98-403C-8A04-C576BA8CE26A}) (Version: 1.80.0000 - CK Software) Destinations (Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (Version: 130.0.372.000 - Hewlett-Packard) Hidden DocMgr (Version: 130.0.000.000 - Ihr Firmenname) Hidden DocProc (Version: 13.0.0.0 - Hewlett-Packard) Hidden erLT (Version: 1.20.138.34 - Logitech, Inc.) Hidden Fax (Version: 130.0.418.000 - Hewlett-Packard) Hidden FileHippo.com Update Checker (HKLM\...\FileHippo.com) (Version: - ) Firebird SQL Server - MAGIX Edition (HKLM\...\{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}) (Version: 2.1.27.0 - MAGIX AG) Google Chrome (HKLM\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.) Google Update Helper (Version: 1.3.25.5 - Google Inc.) Hidden GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP) HP Document Manager 2.0 (HKLM\...\HP Document Manager) (Version: 2.0 - HP) HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP) HP Officejet 4500 G510n-z (HKLM\...\{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}) (Version: 13.0 - HP) HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Support Solutions Framework (HKLM\...\{C43602FE-988C-47BA-9F9F-B95FDDAFB624}) (Version: 11.50.0031 - Hewlett-Packard Company) HP Update (HKLM\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard) HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden HPSSupply (Version: 130.0.371.000 - Hewlett-Packard) Hidden iCloud (HKLM\...\{760BB327-3973-4608-85C8-88162E2FF3B6}) (Version: 4.0.6.28 - Apple Inc.) Iminent (Version: 4.10.0.0 - Iminent) Hidden <==== ATTENTION Intel(R) Management Engine Components (HKLM\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Internet Explorer (Version: 9 - Microsoft Corporation) Hidden iTuner (HKLM\...\{C49CBF9A-4AD7-4045-92BD-2C6E45680070}) (Version: 1.0.3 - iAppsPoint) iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.) Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle) Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) Logitech Webcam-Software (HKLM\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.30 - Logitech Inc.) MAGIX Screenshare (HKLM\...\{BB565180-FA52-40DA-A65E-651537008C34}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Speed burnR (MSI) (HKLM\...\{B0975D89-8D51-445C-BB71-95826A96780C}) (Version: 7.0.2.6 - MAGIX AG) MAGIX Video deluxe 17 Premium Download-Version (HKLM\...\MAGIX_MSI_Videodeluxe17_premium) (Version: 10.0.1.14 - MAGIX AG) MAGIX Video deluxe 17 Premium Download-Version (Version: 10.0.1.14 - MAGIX AG) Hidden Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) MarketResearch (Version: 130.0.374.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft SkyDrive (HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\SkyDriveSetup.exe) (Version: 16.4.6010.0727 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 35.0 (x86 de) (HKLM\...\Mozilla Firefox 35.0 (x86 de)) (Version: 35.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) MP3 Rocket (HKLM\...\MP3 Rocket) (Version: - ) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyFreeCodec (HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\...\MyFreeCodec) (Version: - ) Nero BurningROM 12 (HKLM\...\{3DAFE920-1B88-4C66-A39B-D743F28AF10D}) (Version: 12.5.01300 - Nero AG) NETGEAR WG111v3 wireless USB 2.0 adapter (HKLM\...\InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}) (Version: 1.00.0000 - NETGEAR) NETGEAR WG111v3 wireless USB 2.0 adapter (Version: 1.00.0000 - NETGEAR) Hidden Network (Version: 130.0.374.000 - Hewlett-Packard) Hidden Norton Internet Security (Version: 18.1.0.37 - Symantec Corporation) Hidden NVIDIA Grafiktreiber 267.42 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 267.42 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.10.0514 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.10.0514 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (HKLM\...\NVIDIAStereo) (Version: 7.17.12.6742 - NVIDIA Corporation) OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP) Platform (Version: 1.36 - VIA Technologies, Inc.) Hidden Prerequisite installer (Version: 12.0.0003 - Nero AG) Hidden QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) REALTEK Wireless LAN Driver and Utility (HKLM\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0165 - REALTEK Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.16.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.1.16.0 - Renesas Electronics Corporation) Hidden Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Samplitude Music Studio 17 Content Pack (HKLM\...\{B6FE6F0D-688B-458B-9E12-0F55E4009561}) (Version: 1.0.0.0 - MAGIX AG) Samplitude Music Studio 17 Download-Version (Version: 17.0.0.0 - MAGIX AG) Hidden Samplitude Music Studio 17 Vita Pack 1 (HKLM\...\{EE3264C1-2501-4D58-9B57-4D3F2F502599}) (Version: 1.0.0.0 - MAGIX AG) Samplitude Music Studio 17 Vita Pack 2 (HKLM\...\{63D7FB4F-01A1-4A8B-9180-FF2FEF369AC8}) (Version: 1.0.0.0 - MAGIX AG) Samplitude Music Studio 17 Vita Pack 3 (HKLM\...\{33F9A189-4F02-4784-8A57-F3983F9F9217}) (Version: 1.0.0.0 - MAGIX AG) Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.0.2.11071_128 - Samsung Electronics Co., Ltd.) Samsung Kies (Version: 2.0.2.11071_128 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.) Scan (Version: 13.0.0.0 - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP) Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.8.8855 - Skype Technologies S.A.) Skype™ 5.5 (HKLM\...\{AA59DDE4-B672-4621-A016-4C248204957A}) (Version: 5.5.124 - Skype Technologies S.A.) Smart OCR 3.2.1.417 (HKLM\...\Smart OCR_is1) (Version: 3.2.1.417 - SmartSoft, LLC.) SmartWebPrinting (Version: 130.0.373.000 - Hewlett-Packard) Hidden SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden Sound Blaster X-Fi MB (HKLM\...\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}) (Version: 1.0 - Creative Technology Limited) Sound Effects (HKLM\...\{A044C900-5DE1-4986-B0B8-D6A40271A929}) (Version: 2.0 - Music Oasis) Splashtop Connect IE (HKLM\...\{F9F5EF72-18CF-4DCF-A721-EC86B94DAC46}) (Version: 1.1.12.1 - Splashtop Inc.) SpywareBlaster 5.0 (HKLM\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC) Status (Version: 130.0.373.000 - Hewlett-Packard) Hidden SumatraPDF (HKLM\...\SumatraPDF) (Version: 2.2.1 - Krzysztof Kowalczyk) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Text-To-Speech-Runtime (HKLM\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH) TomTom HOME (HKLM\...\{99072AB4-D795-44D5-9D65-E3C9F8322C97}) (Version: 2.9.7 - Ihr Firmenname) TomTom HOME Visual Studio Merge Modules (HKLM\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) Toolbox (Version: 130.0.648.000 - Hewlett-Packard) Hidden TrayApp (Version: 130.0.376.000 - Hewlett-Packard) Hidden VIA Plattform-Geräte-Manager (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.36 - VIA Technologies, Inc.) VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN) WebReg (Version: 130.0.132.017 - Hewlett-Packard) Hidden Windows 7 Upgrade Advisor (HKLM\...\{9A4D182C-35C7-4791-8484-4304EBC9101A}) (Version: 2.0.5000.0 - Microsoft Corporation) WinPatrol (HKLM\...\{84481A87-2316-4923-8FAB-3BA8CA29323D}) (Version: 30.0.2014.0 - BillP Studios) WinRAR 5.01 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) XFastUsb (HKLM\...\XFastUsb) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{1853e19a-4e54-4190-8deb-2e1cc947cd60}\InprocServer32 -> C:\Program Files\AOL 9.0 VRa\axtrack.dll (AOL, LLC.) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{248FDB00-ABE4-DA9A-AEAA-45651873E13C}\InprocServer32 -> C:\Windows\system32\ole32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{7629C9DE-2E38-4963-A01C-02FFAC203D87}\InprocServer32 -> C:\Program Files\AOL 9.0 VRa\axtrack.dll (AOL, LLC.) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}\localserver32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}\localserver32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{B9F3009B-976B-41C4-A992-229DCCF3367C}\InprocServer32 -> C:\Program Files\AOL 9.0 VRa\axtrack.dll (AOL, LLC.) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1184766340-1357020511-1184547663-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\FileSyncApi.dll (Microsoft Corporation) ==================== Restore Points ========================= 30-12-2014 09:42:17 Windows Update 02-01-2015 13:12:07 Windows Update 06-01-2015 16:44:17 Windows Update 09-01-2015 17:10:05 Windows Update 14-01-2015 08:42:35 Windows Update 20-01-2015 09:55:40 Windows Update 23-01-2015 10:35:22 Windows Update 27-01-2015 09:01:46 Windows Update 27-01-2015 13:50:14 Revo Uninstaller's restore point - Ask Toolbar ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2015-01-27 14:22 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {03AF9F3C-D4C3-4C66-B3FF-94385E5067CD} - System32\Tasks\{B884BA27-1BA3-408A-81E3-F2C080791443} => pcalua.exe -a C:\Users\Antje\AppData\Local\Temp\Temp1_BEHRINGER_2902_WIN32_2.8.40.zip\BEHRINGER_2902_WIN32_2.8.40\BEHRINGER_2902_WIN32_2.8.40\Setup.exe Task: {045F01F1-6A51-4ECF-B1DD-8CCF826C5DFB} - System32\Tasks\{FFB24C49-EC37-46CD-A216-976544BB8314} => pcalua.exe -a C:\Users\Antje\Desktop\JRT.exe -d C:\Users\Antje\Desktop Task: {22297514-A4E0-4D1E-9455-F8E19C59CD27} - System32\Tasks\{7D903461-66BC-4061-85C9-3F8FA32A51B9} => C:\Program Files\AOL 9.0 VRa\aol.exe [2007-06-21] (AOL, LLC.) Task: {34A7E8FD-E08C-40C8-B837-2E80BE0A306C} - System32\Tasks\{8F4BC908-16EF-4848-947E-84237ECB4017} => pcalua.exe -a "C:\Users\Antje\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\39AZ0FF2\JavaSetup6u30[1].exe" -d "C:\Program Files\AOL 9.0 VR\download" Task: {3E3A8E37-D463-4D55-AB37-945CB206B155} - System32\Tasks\{C6D23163-BC45-4502-81AE-7D050066D03F} => C:\Program Files\AOL 9.0 VRa\aol.exe [2007-06-21] (AOL, LLC.) Task: {40EFC56F-9252-4B38-B5DD-057EF1F79324} - System32\Tasks\{CB4134A4-24E6-4801-AD5D-F14F348B4F3F} => pcalua.exe -a C:\Users\Antje\Desktop\bpsetup_1_03_1.exe -d C:\Users\Antje\Desktop Task: {41E884C9-AD6D-4197-8528-7D37E6577D28} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {41FC715C-F2C7-4235-9B69-75187C62DB23} - System32\Tasks\{4587AF3A-277F-45C9-B12C-16027686B52D} => pcalua.exe -a "C:\Program Files\VS Revo Group\Revo Uninstaller\Revouninstaller.exe" -d "C:\Program Files\VS Revo Group\Revo Uninstaller" Task: {52868A61-6D7B-4124-B8B9-513939B660F8} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-26] (Adobe Systems Incorporated) Task: {5DEFCCC0-E74F-468D-A8F6-4F22F81036C4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-18] (Google Inc.) Task: {64D1831E-C822-4FCA-947A-B5016AD58892} - System32\Tasks\{3675A0DE-B202-46D2-A003-B992F464AB20} => C:\Program Files\AOL 9.0 VRa\aol.exe [2007-06-21] (AOL, LLC.) Task: {8C20516A-0854-4055-9DDA-07F5D365959F} - System32\Tasks\{A56D0839-9B1E-4606-AE99-6CAD37FD905C} => C:\Program Files\Lexmark X1100 Series\LXBKaiox.exe Task: {8F558DF4-0619-444D-9F4F-4EF9E314EDFC} - System32\Tasks\{2924322F-7F67-4D89-8E43-BB513C3355D9} => pcalua.exe -a "C:\Program Files\PDFReader\Uninstall\Uninstall.exe" -c /Uninstall Task: {94904DBE-DBE1-4386-9DE3-1C4E1D91C064} - System32\Tasks\{9DA0F427-D915-4923-B20B-1FA49027F5E0} => C:\Program Files\Lexmark X1100 Series\LXBKaiox.exe Task: {97F8691A-B0E3-4043-8305-1F364FA2C414} - System32\Tasks\{16F0FB3C-EDC9-4C3C-8E77-E44A47D38837} => pcalua.exe -a C:\Users\Antje\Downloads\OJ4500vG510n-z_Full_13.exe -d C:\Users\Antje\Downloads Task: {9B27E834-691C-45FF-829F-B0A49E17AE7F} - System32\Tasks\{D85521BE-0739-42B1-A58D-22BB371F9D3F} => pcalua.exe -a C:\Users\Antje\AppData\Local\temp\Temp1_hm5-de-demo.zip\setup.exe Task: {A10ECCC0-1B66-4A86-9C89-4C1818EBA884} - System32\Tasks\{B10FAAC6-490F-473F-82EE-FAC8F3944A72} => pcalua.exe -a "C:\Program Files\Common Files\aolshare\aolunins_de.exe" -d "C:\Program Files\Common Files\aolshare" Task: {A772F5F9-4A3A-4937-BFB2-CD9F2B84E04E} - System32\Tasks\{AAEC8B2B-ED52-49A0-BD09-2F6923957A60} => pcalua.exe -a C:\Users\Antje\AppData\Local\Temp\jre-8u20-windows-au.exe -d C:\Windows\system32 -c /installmethod=jau FAMILYUPGRADE=1 Task: {C3FBC991-3D6D-44E0-A406-6BDDC4AC416C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {C85A48C0-2367-4172-9824-7B85B5DC8CE3} - System32\Tasks\{93CF804C-D379-4814-A73F-889901F831EE} => C:\Program Files\AOL 9.0 VRa\aol.exe [2007-06-21] (AOL, LLC.) Task: {CAEE6CC7-AD53-4CC1-A7C7-9724173B870C} - System32\Tasks\{9FF61FC0-5E04-43DB-A5E4-669321A28ECB} => pcalua.exe -a C:\Users\Antje\Documents\APTunerInstall308.exe -d C:\Users\Antje\Documents Task: {DA7A9810-A0B0-4FF4-82D3-BF57EE4B1784} - System32\Tasks\{FC053655-A6D1-46F9-809B-FA9D8B478771} => pcalua.exe -a C:\Users\Antje\AppData\Local\Temp\jre-8u25-windows-au.exe -d C:\Windows\system32 -c /installmethod=jau FAMILYUPGRADE=1 Task: {FECA1FA1-49AA-4917-877A-F2454176197A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-18] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2011-12-23 22:11 - 2011-02-22 07:02 - 00080496 ____R () C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll 2011-12-23 22:11 - 2011-02-22 07:02 - 00113264 ____R () C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll 2011-12-23 22:11 - 2011-02-22 07:02 - 00623216 ____R () C:\Program Files\VIA\VIAudioi\VDeck\Skin.dll 2015-01-29 09:51 - 2015-01-29 09:51 - 00697884 _____ () C:\Users\Antje\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0001\~df394b.tmp 2015-01-29 09:51 - 2015-01-29 09:51 - 00592896 _____ () C:\Users\Antje\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0001\~de6248.tmp 2011-12-23 22:18 - 2009-02-06 18:52 - 00073728 _____ () C:\Windows\SYSTEM32\CmdRtr.DLL 2011-12-23 22:18 - 2009-04-20 11:55 - 00148480 _____ () C:\Windows\SYSTEM32\APOMngr.DLL 2015-01-28 08:36 - 2014-08-04 13:20 - 00052472 _____ () C:\Users\Antje\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2014-08-04 13:20 - 2014-08-04 13:20 - 00139056 _____ () C:\Program Files\Avira\My Avira\Avira.OE.NativeCore.dll 2007-09-14 09:26 - 2007-09-14 09:26 - 01695744 _____ () C:\Program Files\NETGEAR\WG111v3\WG111v3.exe 2004-01-09 21:02 - 2004-01-09 21:02 - 00045056 _____ () C:\Program Files\AOL 9.0 VRa\zlib.dll 2002-04-22 22:08 - 2002-04-22 22:08 - 00053248 _____ () C:\Program Files\AOL 9.0 VRa\xmlparse.dll 2002-04-22 22:08 - 2002-04-22 22:08 - 00081920 _____ () C:\Program Files\AOL 9.0 VRa\xmltok.dll 2011-12-23 22:28 - 2009-12-09 21:20 - 00126976 _____ () C:\Program Files\REALTEK\11n USB Wireless LAN Utility\EnumDevLib.dll 2014-08-04 13:20 - 2014-08-04 13:20 - 00067832 _____ () C:\Program Files\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2014-03-30 17:32 - 2015-01-25 22:49 - 03925104 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:373E1720 AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Antje^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupfolder: C:^Users^Antje^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk => C:\Windows\pss\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: Bonus.SSR.FR11 => "C:\Program Files\ABBYY FineReader 11\Bonus.ScreenshotReader.exe" /autorun MSCONFIG\startupreg: FileHippo.com => "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background MSCONFIG\startupreg: HostManager => C:\Program Files\Common Files\AOL\1324678810\ee\AOLSoftware.exe MSCONFIG\startupreg: HP Software Update => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: KiesPDLR => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: LWS => C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide MSCONFIG\startupreg: NUSB3MON => "C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SkyDrive => "C:\Users\Antje\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background MSCONFIG\startupreg: TomTomHOME.exe => "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s MSCONFIG\startupreg: TrayServer => C:\PROGRA~1\MAGIX\VIDEO_~2\TrayServer.exe MSCONFIG\startupreg: WinPatrol => C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot ========================= Accounts: ========================== Administrator (S-1-5-21-1184766340-1357020511-1184547663-500 - Administrator - Disabled) Antje (S-1-5-21-1184766340-1357020511-1184547663-1000 - Administrator - Enabled) => C:\Users\Antje Gast (S-1-5-21-1184766340-1357020511-1184547663-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1184766340-1357020511-1184547663-1002 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= Name: Officejet 4500 G510n-z Description: Officejet 4500 G510n-z Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} Manufacturer: HP Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Officejet 4500 G510n-z Description: Officejet 4500 G510n-z Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: HP Service: StillCam Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/29/2015 09:52:01 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Kies.exe, Version: 2.0.0.11044, Zeitstempel: 0x4e2ea381 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x531599f6 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000812f ID des fehlerhaften Prozesses: 0xacc Startzeit der fehlerhaften Anwendung: 0xKies.exe0 Pfad der fehlerhaften Anwendung: Kies.exe1 Pfad des fehlerhaften Moduls: Kies.exe2 Berichtskennung: Kies.exe3 Error: (01/29/2015 09:51:43 AM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Kies.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.Windows.Markup.XamlParseException Stapel: bei System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) bei System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) bei System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) bei System.Windows.Application.LoadComponent(System.Object, System.Uri) bei Kies.App.InitializeComponent() bei Kies.App.Main() System errors: ============= Error: (01/29/2015 10:26:37 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/29/2015 10:26:14 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/29/2015 09:53:47 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/29/2015 09:53:47 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/29/2015 09:53:47 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/29/2015 09:53:47 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/29/2015 09:53:47 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/29/2015 09:53:47 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/29/2015 09:53:47 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Error: (01/29/2015 09:53:47 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DNS-Client" wurde mit folgendem Fehler beendet: %%2 Microsoft Office Sessions: ========================= Error: (02/03/2013 04:56:00 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 524 seconds with 480 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Processor: Intel(R) Pentium(R) CPU G620 @ 2.60GHz Percentage of memory in use: 39% Total physical RAM: 3054.7 MB Available physical RAM: 1847.57 MB Total Pagefile: 6105.64 MB Available Pagefile: 4422.18 MB Total Virtual: 2047.88 MB Available Virtual: 1917.5 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:835.34 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A27B1D46) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Hallo lieber Schrauber, wegen deiner Frage noch Probleme......es ist alles viel schneller geworden und bleibt nicht hängen. Das ist schon mal gut. Ich würde noch bischen testen wollen ob es geht oder was noch komisch ist..... Ich habe noch eine Frage, welchen Player (Für Spiele) kann ich denn runterladen ? Da hatte ich einen der wollte stets beim start vom pc ein neues update. Manchmal mehrmals am Tag , das ist schon komisch?? ok. Ansonsten vielen Dank für deine schnelle und proffessionelle und nette Hilfe. LG Lotto |
29.01.2015, 17:20 | #120 | |
/// the machine /// TB-Ausbilder | Maillaccount gehackt /verschiedene Funde mit Malewarebytes Revo Uninstaller - Download - Filepony damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.google.com/chrome/answer/3296214?hl=de Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Program Files\49Uninstall Utility Chest.dll CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKU\S-1-5-21-1184766340-1357020511-1184547663-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:8897;https=127.0.0.1:8897 Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte. Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Maillaccount gehackt /verschiedene Funde mit Malewarebytes |
administrator, adware.fakeinstaller, adware.installcore, anti-malware, besser, dateien, folge, hallo zusammen, install.exe, maleware, pup.offerbundler.st, pup.software.updater, quarantäne, swvupdater, test, uninstall.exe, updater.exe, version, windows.old |