|
Plagegeister aller Art und deren Bekämpfung: BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
05.08.2013, 10:39 | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ | BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Im Anschluss: adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen Downloade Dir bitte AdwCleaner auf deinen Desktop.
Danach eine Kontrolle mit Farbars Tool bitte: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
05.08.2013, 11:21 | #17 |
| BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? JRT Logfile
__________________Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.3.3 (08.04.2013:1) OS: Windows 7 Home Premium x64 Ran by G”giPC on 05.08.2013 at 12:13:58,16 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 05.08.2013 at 12:17:26,74 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ adwCleaner Code:
ATTFilter # AdwCleaner v2.306 - Datei am 05/08/2013 um 11:58:23 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows 7 Home Premium (64 bits) # Benutzer : GögiPC - GOGI # Bootmodus : Normal # Ausgeführt unter : C:\Users\GögiPC\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\Plugins\npvsharetvplg.dll Datei Gelöscht : C:\Users\GögiPC\AppData\Roaming\Microsoft\Windows\Start Menu\eBay.lnk Datei Gelöscht : C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\foxydeal.sqlite Datei Gelöscht : C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\searchplugins\daemon-search.xml Ordner Gelöscht : C:\Users\GögiPC\AppData\Local\PackageAware ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\facemoods.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1B48071-416D-474E-A13B-BE5456E7FC31} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Schlüssel Gelöscht : HKLM\Software\facemoods.com Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoods_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoods_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31} Schlüssel Gelöscht : HKLM\Software\SimplyGen Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3D782BB2-F2A5-11D3-BF4C-000000000000} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16421 Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 --> hxxp://www.google.com -\\ Mozilla Firefox v22.0 (de) Datei : C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v24.0.1312.57 Datei : C:\Users\GögiPC\AppData\Local\Google\Chrome\User Data\Default\Preferences Gelöscht [l.9] : homepage = "hxxp://startsear.ch/?aff=1&cf=7f4d4669-179d-11e1-93e5-00241d7f2969", Gelöscht [l.13] : urls_to_restore_on_startup = [ "hxxp://startsear.ch/?aff=1&cf=7f4d4669-179d-11e1-93e5-0024[...] Gelöscht [l.2015] : homepage = "hxxp://startsear.ch/?aff=1&cf=7f4d4669-179d-11e1-93e5-00241d7f2969", Gelöscht [l.2418] : urls_to_restore_on_startup = [ "hxxp://startsear.ch/?aff=1&cf=7f4d4669-179d-11e1-93e5-00241d7[...] -\\ Opera v11.0.1156.0 Datei : C:\Users\GögiPC\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [8658 octets] - [05/08/2013 11:58:23] ########## EOF - C:\AdwCleaner[S1].txt - [8718 octets] ########## FRST FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-08-2013 Ran by GögiPC (administrator) on 05-08-2013 12:11:38 Running from C:\Users\GögiPC\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe (Infowatch) C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Microsoft Corporation) C:\Windows\System32\alg.exe () C:\Windows\SysWOW64\HsMgr.exe (CMedia) C:\Program Files\UNi Xonar Audio\Customapp\ASUSAUDIOCENTER.EXE () C:\Windows\system\HsMgr64.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Spotify Ltd) C:\Users\GögiPC\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (PC Remote) C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe (Hauppauge Computer Works) C:\Program Files (x86)\WinTV\Ir.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [CmPCIaudio] - C:\Windows\syswow64\RunDll32.exe [44544 2009-07-14] (Microsoft Corporation) HKLM\...\Run: [Cmaudio8788] - C:\Windows\syswow64\RunDll32.exe [44544 2009-07-14] (Microsoft Corporation) HKLM\...\Run: [Cmaudio8788GX] - C:\Windows\syswow64\HsMgr.exe [200704 2008-07-11] () HKLM\...\Run: [Cmaudio8788GX64] - C:\Windows\system\HsMgr64.exe [282112 2008-07-11] () HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395928 2012-05-10] (Acronis) Winlogon\Notify\klogon: %SystemRoot%\System32\klogon.dll (Kaspersky Lab) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [163328 2009-07-14] (Microsoft Corporation) HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1509232 2013-02-13] (Samsung) HKCU\...\Run: [Spotify Web Helper] - C:\Users\GögiPC\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-08] (Spotify Ltd) HKCU\...\Run: [Spotify] - C:\Users\GögiPC\AppData\Roaming\Spotify\spotify.exe [4640768 2013-07-08] (Spotify Ltd) HKCU\...\Run: [PC Remote Server] - C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe [1070744 2013-07-26] (PC Remote) HKLM-x32\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [36864 2007-03-20] () HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-10-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe [348760 2010-10-01] (Kaspersky Lab) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310128 2013-02-13] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [LGODDFU] - C:\Program Files (x86)\lg_fwupdate\lgfw.exe [27760 2013-03-08] (Bitleader) HKLM-x32\...\Run: [PowerDVD12DMREngine] - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe [506480 2012-12-28] (CyberLink) HKLM-x32\...\Run: [PowerDVD12Agent] - C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe [375168 2012-12-28] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated) HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2673640 2012-05-10] () AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\PROGRA~2\KASPER~1\KASPER~2\sbhook.dll C:\PROGRA~2\KASPER~1\KASPER~2\x64\kloehk.dll C:\PROGRA~2\KASPER~1\KASPER~2\x64\sbhook64.dll [15448 2010-10-01] (Kaspersky Lab) AppInit_DLLs-x32: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll C:\PROGRA~2\KASPER~1\KASPER~2\sbhook.dll [109144 2010-10-01] (Kaspersky Lab) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoStart IR.lnk ShortcutTarget: AutoStart IR.lnk -> C:\Program Files (x86)\WinTV\Ir.exe (Hauppauge Computer Works) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {7C64CE0F-5B11-4A36-95F6-635B7AA1BBC7} URL = hxxp://www.bing.com/search?FORM=IEFM1&q={searchTerms}&src={referrer:source?} BHO: VshareComplete - {08337871-0e50-4031-9110-3bd21ca3c065} - C:\Users\GögiPC\AppData\Roaming\VshareComplete\64\VshareComplete64.dll No File BHO: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\ievkbd.dll (Kaspersky Lab) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\klwtbbho.dll (Kaspersky Lab) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) BHO-x32: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\ievkbd.dll (Kaspersky Lab) BHO-x32: DivX HiQ - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab) DPF: HKLM-x32 {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default FF SelectedSearchEngine: Google FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.0 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll No File FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.118.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.132.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @pages.tvunetworks.com/WebPlayer - C:\Windows\system32\TVUAx\npTVUAx.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\GögiPC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\GögiPC\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\GögiPC\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF Extension: No Name - C:\Users\GögiPC\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: TVU Web Player - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\firefox@tvunetworks.com FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\ich@maltegoetz.de FF Extension: Gradient iCool - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\{de5809e0-2b07-11dd-bd0b-0800200c9a66} FF Extension: nasanightlaunch - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\nasanightlaunch@example.com.xpi FF Extension: No Name - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi FF Extension: No Name - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video FF HKLM-x32\...\Firefox\Extensions: [{6904342A-8307-11DF-A508-4AE2DFD72085}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa FF Extension: DivX HiQ - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa FF HKLM-x32\...\Thunderbird\Extensions: [{eea12ec4-729d-4703-bc37-106ce9879ce2}] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\THBExt FF Extension: Kaspersky Anti-Spam Extension - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\THBExt Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\G\u00F6giPC\AppData\Local\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\G\u00F6giPC\AppData\Local\Google\Chrome\Application\24.0.1312.57\pdf.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\G\u00F6giPC\AppData\Local\Google\Chrome\Application\24.0.1312.57\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\G\u00F6giPC\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll No File CHR Plugin: (vShare.tv plug-in) - C:\Users\G\u00F6giPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll No File CHR Plugin: (vShare.tv plug-in) - C:\Program Files (x86)\Mozilla Firefox\plugins\npvsharetvplg.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U22) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Microsoft SharedView Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\npsharedview.dll ( ) CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll No File CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc) CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc) CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\G\u00F6giPC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File CHR Plugin: (TVU Web Player for FireFox) - C:\Windows\system32\TVUAx\npTVUAx.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (AT_JamesWhite) - C:\Users\GGIPC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm\3_0 CHR Extension: (DivX HiQ) - C:\Users\GGIPC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.1.94_0 CHR Extension: (vshare plugin) - C:\Users\GGIPC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\GGIPC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0 CHR HKLM-x32\...\Chrome\Extension: [fnjbmmemklcjgepojigaapkoodmkgbae] - C:\Program Files (x86)\DivX\DivX Plus Web Player\google_chrome\wpa\wpa.crx CHR HKLM-x32\...\Chrome\Extension: [kpionmjnkbpcdpcflammlgllecmejgjj] - C:\Program Files (x86)\StartSearch plugin\vshareplg.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\google_chrome\html5video\html5video.crx CHR StartMenuInternet: Google Chrome - C:\Users\GögiPC\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-10-21] (Advanced Micro Devices, Inc.) S4 AODService; C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe [136544 2009-10-22] () R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe [348760 2010-10-01] (Kaspersky Lab) R2 CLHNServiceForPowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe [91248 2012-12-28] (CyberLink Corp.) R2 CSObjectsSrv; C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [743992 2009-12-21] (Infowatch) R2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [78960 2012-12-28] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [296048 2012-12-28] (CyberLink) S4 ES lite Service; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [68136 2009-02-05] () S4 Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [135584 2012-04-26] (Futuremark Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2010-09-16] () R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-02-28] () S3 NMIndexingService; "C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe" [x] S2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [x] ==================== Drivers (Whitelisted) ==================== S3 AODDriver; C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver.sys [21048 2009-10-22] (Advanced Micro Devices) S3 AODDriver; C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver.sys [21048 2009-10-22] (Advanced Micro Devices) R2 AODDriver4.01; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) S2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) S3 ATITool; C:\Windows\System32\DRIVERS\ATITool64.sys [30720 2006-11-10] () S3 cmuda3; C:\Windows\System32\drivers\cmudax3.sys [1155072 2009-12-01] (C-Media Inc) R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2726400 2011-07-04] (C-Media Inc) R0 CSCrySec; C:\Windows\System32\DRIVERS\CSCrySec.sys [85048 2009-12-14] (Infowatch) R1 CSVirtualDiskDrv; C:\Windows\System32\DRIVERS\CSVirtualDiskDrv.sys [66104 2009-12-14] (Infowatch) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [270912 2011-09-30] (DT Soft Ltd) S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-09-17] (EnTech Taiwan) S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-09-17] (EnTech Taiwan) S3 gdrv; C:\Windows\gdrv.sys [23080 2011-10-13] (Windows (R) Server 2003 DDK provider) S3 gdrv; C:\Windows\gdrv.sys [23080 2011-10-13] (Windows (R) Server 2003 DDK provider) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2009-11-23] () S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2009-11-23] () R3 hcw88rc5; C:\Windows\System32\Drivers\hcw88rc5.sys [15872 2009-08-06] (Hauppauge Computer Works, Inc.) R1 kl1; C:\Windows\System32\DRIVERS\kl1.sys [157712 2009-09-01] (Kaspersky Lab) R0 KLBG; C:\Windows\System32\DRIVERS\klbg.sys [40464 2009-10-14] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [353296 2013-02-11] (Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [27152 2009-09-14] (Kaspersky Lab) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [21008 2009-10-02] (Kaspersky Lab) R3 KovaPlusFltr; C:\Windows\System32\drivers\KovaPlusFltr.sys [15104 2010-01-25] (ROCCAT Development, Inc.) S3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-04-30] () S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-04-30] () R3 MRV6X64U; C:\Windows\System32\DRIVERS\MRVW23C.sys [255232 2007-01-04] (Marvell Semiconductor, Inc) R2 ntk_PowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [83704 2012-09-10] (Cyberlink Corp.) R2 ntk_PowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [83704 2012-09-10] (Cyberlink Corp.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [526392 2011-09-30] () R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [141920 2013-07-26] (Acronis) R2 {73526619-C24F-470B-9BED-53D455FBB5C6}; C:\Program Files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl [130320 2012-12-28] (CyberLink Corp.) R2 {73526619-C24F-470B-9BED-53D455FBB5C6}; C:\Program Files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl [130320 2012-12-28] (CyberLink Corp.) S3 ALSysIO; \??\C:\Users\GGIPC~1\AppData\Local\Temp\ALSysIO64.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 cpuz130; \??\C:\Users\GGIPC~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x] S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [x] S3 GPU-Z; \??\C:\Users\GGIPC~1\AppData\Local\Temp\GPU-Z.sys [x] S3 RivaTuner64; \??\C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-05 12:11 - 2013-08-05 12:11 - 00038733 _____ C:\Users\GögiPC\Desktop\FRST64 2.txt 2013-08-05 12:03 - 2013-08-05 12:03 - 00008745 _____ C:\Users\GögiPC\Desktop\AdwCleaner[S1].txt 2013-08-05 12:00 - 2013-08-05 12:00 - 00028550 _____ C:\Windows\setupact.log 2013-08-05 12:00 - 2013-08-05 12:00 - 00000000 _____ C:\Windows\setuperr.log 2013-08-05 11:58 - 2013-08-05 11:58 - 00008745 _____ C:\AdwCleaner[S1].txt 2013-08-05 11:55 - 2013-08-05 11:55 - 00005647 _____ C:\Users\GögiPC\Desktop\JRT.txt 2013-08-05 11:51 - 2013-08-05 11:51 - 00000000 ____D C:\Windows\ERUNT 2013-08-05 11:49 - 2013-08-05 11:49 - 00666633 _____ C:\Users\GögiPC\Desktop\adwcleaner.exe 2013-08-05 11:49 - 2013-08-05 11:49 - 00562008 _____ (Oleg N. Scherbakov) C:\Users\GögiPC\Desktop\JRT.exe 2013-08-05 03:23 - 2013-08-05 03:23 - 00025283 _____ C:\ComboFix.txt 2013-08-05 02:59 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-05 02:59 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-05 02:59 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-05 02:59 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-05 02:59 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-05 02:59 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-05 02:59 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-05 02:59 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-05 02:58 - 2013-08-05 03:24 - 00000000 ____D C:\Qoobox 2013-08-05 02:58 - 2013-08-05 03:20 - 00000000 ____D C:\Windows\erdnt 2013-08-05 02:56 - 2013-08-05 02:57 - 05099708 ____R (Swearware) C:\Users\GögiPC\Desktop\ComboFix.exe 2013-08-04 20:39 - 2013-08-04 20:39 - 00003580 _____ C:\Users\GögiPC\Desktop\FSS.txt 2013-08-04 20:38 - 2013-08-04 20:38 - 00357145 _____ (Farbar) C:\Users\GögiPC\Desktop\FSS.exe 2013-08-04 19:41 - 2013-08-04 19:42 - 00028561 _____ C:\Users\GögiPC\Desktop\Addition.txt 2013-08-04 19:40 - 2013-08-05 12:09 - 01788733 _____ (Farbar) C:\Users\GögiPC\Desktop\FRST64.exe 2013-08-04 19:28 - 2013-08-05 12:05 - 00003016 _____ C:\Windows\System32\Tasks\MSIAfterburner 2013-08-04 19:27 - 2013-08-04 19:27 - 00000000 ____D C:\FRST 2013-07-29 16:50 - 2013-07-29 16:50 - 00001082 _____ C:\Users\GögiPC\Desktop\PC Remote Server.lnk 2013-07-29 16:50 - 2013-07-29 16:50 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\PC Remote 2013-07-29 16:50 - 2013-07-29 16:50 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Remote 2013-07-29 16:50 - 2013-07-29 16:50 - 00000000 ____D C:\Program Files (x86)\PC Remote 2013-07-27 13:41 - 2013-07-27 13:41 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-07-26 21:32 - 2013-07-26 21:32 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Acronis 2013-07-26 21:31 - 2013-07-26 21:31 - 00000000 ____D C:\ProgramData\Acronis 2013-07-26 21:30 - 2013-07-26 21:30 - 00971360 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2013-07-26 21:30 - 2013-07-26 21:30 - 00001173 _____ C:\Users\Public\Desktop\Acronis True Image WD*Edition.lnk 2013-07-26 21:29 - 2013-07-26 21:29 - 00210016 _____ (Acronis) C:\Windows\system32\Drivers\vididr.sys 2013-07-26 21:28 - 2013-07-26 21:28 - 00275552 _____ (Acronis) C:\Windows\system32\Drivers\snapman.sys 2013-07-26 21:28 - 2013-07-26 21:28 - 00141920 _____ (Acronis) C:\Windows\system32\Drivers\vsflt53.sys 2013-07-26 21:28 - 2013-07-26 21:28 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-07-22 19:00 - 2013-07-22 19:06 - 00000000 ____D C:\Windows\system32\MRT 2013-07-11 18:12 - 2013-07-11 18:12 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-07-11 17:38 - 2013-07-11 18:23 - 00000000 ____D C:\Users\GögiPC\Documents\SelfMV 2013-07-11 17:19 - 2013-07-11 17:19 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-07-11 17:17 - 2013-07-11 17:17 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-07-11 17:17 - 2013-07-11 17:17 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Samsung 2013-07-11 17:17 - 2013-07-11 17:17 - 00000000 ____D C:\Users\GGIPC~1\AppData\Local\Samsung 2013-07-11 17:16 - 2013-07-11 17:16 - 00000000 ____D C:\Users\GögiPC\Documents\samsung ==================== One Month Modified Files and Folders ======= 2013-08-05 12:10 - 2009-11-10 22:33 - 00010912 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-05 12:10 - 2009-11-10 22:33 - 00010912 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-05 12:09 - 2013-08-04 19:40 - 01788733 _____ (Farbar) C:\Users\GögiPC\Desktop\FRST64.exe 2013-08-05 12:07 - 2013-05-20 18:54 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Spotify 2013-08-05 12:07 - 2010-10-10 12:16 - 01048604 _____ C:\Windows\WindowsUpdate.log 2013-08-05 12:05 - 2013-08-04 19:28 - 00003016 _____ C:\Windows\System32\Tasks\MSIAfterburner 2013-08-05 12:04 - 2010-02-12 22:11 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-08-05 12:03 - 2013-08-05 12:03 - 00008745 _____ C:\Users\GögiPC\Desktop\AdwCleaner[S1].txt 2013-08-05 12:03 - 2009-11-08 20:07 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-05 12:02 - 2013-05-28 18:23 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-05 12:01 - 2009-11-08 20:07 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-05 12:00 - 2013-08-05 12:00 - 00028550 _____ C:\Windows\setupact.log 2013-08-05 12:00 - 2013-08-05 12:00 - 00000000 _____ C:\Windows\setuperr.log 2013-08-05 12:00 - 2011-06-28 03:24 - 00054658 _____ C:\Windows\PFRO.log 2013-08-05 12:00 - 2010-02-12 21:52 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs 2013-08-05 12:00 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-05 11:58 - 2013-08-05 11:58 - 00008745 _____ C:\AdwCleaner[S1].txt 2013-08-05 11:55 - 2013-08-05 11:55 - 00005647 _____ C:\Users\GögiPC\Desktop\JRT.txt 2013-08-05 11:51 - 2013-08-05 11:51 - 00000000 ____D C:\Windows\ERUNT 2013-08-05 11:49 - 2013-08-05 11:49 - 00666633 _____ C:\Users\GögiPC\Desktop\adwcleaner.exe 2013-08-05 11:49 - 2013-08-05 11:49 - 00562008 _____ (Oleg N. Scherbakov) C:\Users\GögiPC\Desktop\JRT.exe 2013-08-05 03:24 - 2013-08-05 02:58 - 00000000 ____D C:\Qoobox 2013-08-05 03:23 - 2013-08-05 03:23 - 00025283 _____ C:\ComboFix.txt 2013-08-05 03:23 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-08-05 03:20 - 2013-08-05 02:58 - 00000000 ____D C:\Windows\erdnt 2013-08-05 03:14 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-08-05 02:57 - 2013-08-05 02:56 - 05099708 ____R (Swearware) C:\Users\GögiPC\Desktop\ComboFix.exe 2013-08-05 02:00 - 2009-09-21 18:27 - 00000000 ____D C:\Users\GGIPC~1\AppData\Local\Adobe 2013-08-04 20:39 - 2013-08-04 20:39 - 00003580 _____ C:\Users\GögiPC\Desktop\FSS.txt 2013-08-04 20:38 - 2013-08-04 20:38 - 00357145 _____ (Farbar) C:\Users\GögiPC\Desktop\FSS.exe 2013-08-04 19:42 - 2013-08-04 19:41 - 00028561 _____ C:\Users\GögiPC\Desktop\Addition.txt 2013-08-04 19:41 - 2009-07-14 19:58 - 19095724 _____ C:\Windows\system32\perfh007.dat 2013-08-04 19:41 - 2009-07-14 19:58 - 05955080 _____ C:\Windows\system32\perfc007.dat 2013-08-04 19:41 - 2009-07-14 07:13 - 00006284 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-04 19:27 - 2013-08-04 19:27 - 00000000 ____D C:\FRST 2013-08-03 16:18 - 2011-10-23 15:41 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\vlc 2013-07-29 16:50 - 2013-07-29 16:50 - 00001082 _____ C:\Users\GögiPC\Desktop\PC Remote Server.lnk 2013-07-29 16:50 - 2013-07-29 16:50 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\PC Remote 2013-07-29 16:50 - 2013-07-29 16:50 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Remote 2013-07-29 16:50 - 2013-07-29 16:50 - 00000000 ____D C:\Program Files (x86)\PC Remote 2013-07-27 13:41 - 2013-07-27 13:41 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-07-27 13:40 - 2009-11-08 20:07 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-26 21:32 - 2013-07-26 21:32 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Acronis 2013-07-26 21:31 - 2013-07-26 21:31 - 00000000 ____D C:\ProgramData\Acronis 2013-07-26 21:30 - 2013-07-26 21:30 - 00971360 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2013-07-26 21:30 - 2013-07-26 21:30 - 00001173 _____ C:\Users\Public\Desktop\Acronis True Image WD*Edition.lnk 2013-07-26 21:29 - 2013-07-26 21:29 - 00210016 _____ (Acronis) C:\Windows\system32\Drivers\vididr.sys 2013-07-26 21:28 - 2013-07-26 21:28 - 00275552 _____ (Acronis) C:\Windows\system32\Drivers\snapman.sys 2013-07-26 21:28 - 2013-07-26 21:28 - 00141920 _____ (Acronis) C:\Windows\system32\Drivers\vsflt53.sys 2013-07-26 21:28 - 2013-07-26 21:28 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-07-24 21:14 - 2011-01-09 20:34 - 00000000 ____D C:\Users\GögiPC\Desktop\Neuer Ordner 2013-07-22 19:06 - 2013-07-22 19:00 - 00000000 ____D C:\Windows\system32\MRT 2013-07-17 19:17 - 2013-05-20 18:55 - 00000000 ____D C:\Users\GGIPC~1\AppData\Local\Spotify 2013-07-15 19:58 - 2009-11-08 20:07 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-15 19:58 - 2009-11-08 20:07 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-14 11:07 - 2012-06-26 01:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-07-14 11:07 - 2012-05-14 03:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-14 11:07 - 2012-05-14 03:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-11 18:23 - 2013-07-11 17:38 - 00000000 ____D C:\Users\GögiPC\Documents\SelfMV 2013-07-11 18:12 - 2013-07-11 18:12 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-07-11 17:19 - 2013-07-11 17:19 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-07-11 17:17 - 2013-07-11 17:17 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-07-11 17:17 - 2013-07-11 17:17 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Samsung 2013-07-11 17:17 - 2013-07-11 17:17 - 00000000 ____D C:\Users\GGIPC~1\AppData\Local\Samsung 2013-07-11 17:16 - 2013-07-11 17:16 - 00000000 ____D C:\Users\GögiPC\Documents\samsung 2013-07-10 19:05 - 2009-09-20 14:36 - 00000000 ____D C:\ProgramData\Microsoft Help ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-03 12:51 ==================== End Of Log ============================ --- --- --- FRST Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-08-2013 Ran by GögiPC at 2013-08-05 12:12:00 Running from C:\Users\GögiPC\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Update for Microsoft Office 2007 (KB2508958) (x32) Xonar Audio Driver 7-Zip 9.20 (x32) Acronis True Image WD*Edition (x32 Version: 13.0.14189) Adobe AIR (x32 Version: 2.5.1.17730) Adobe Download Assistant (x32 Version: 1.2.5) Adobe Flash Player 10 ActiveX (x32 Version: 10.0.32.18) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Media Player (x32 Version: 1.8) Adobe Photoshop CS6 (x32 Version: 13.0) Adobe Reader XI (11.0.02) - Deutsch (x32 Version: 11.0.02) AMD Accelerated Video Transcoding (Version: 12.5.100.21021) AMD APP SDK Runtime (Version: 10.0.1084.2) AMD AVIVO64 Codecs (Version: 11.7.0.11006) AMD Catalyst Install Manager (Version: 8.0.903.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Fuel (Version: 2012.1021.1547.26491) AMD Media Foundation Decoders (Version: 1.0.71021.1557) AMD OverDrive (x32 Version: 3.1.0.0342) AMD VISION Engine Control Center (x32 Version: 2012.1021.1547.26491) Apple Application Support (x32 Version: 2.3.2) Apple Mobile Device Support (Version: 6.0.1.3) Apple Software Update (x32 Version: 2.1.3.127) aquasuite (x32) Assassin's Creed II (x32 Version: 1.01) Battlefield 3™ (x32 Version: 1.4.0.0) Battlelog Web Plugins (x32 Version: 2.1.4) BD_3D Advisor (x32 Version: 2.0.5913) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1021.1547.26491) Catalyst Control Center InstallProxy (x32 Version: 2012.1021.1547.26491) Catalyst Control Center Localization All (x32 Version: 2012.1021.1547.26491) CCC Help Chinese Standard (x32 Version: 2012.1021.1546.26491) CCC Help Chinese Traditional (x32 Version: 2012.1021.1546.26491) CCC Help Czech (x32 Version: 2012.1021.1546.26491) CCC Help Danish (x32 Version: 2012.1021.1546.26491) CCC Help Dutch (x32 Version: 2012.1021.1546.26491) CCC Help English (x32 Version: 2012.1021.1546.26491) CCC Help Finnish (x32 Version: 2012.1021.1546.26491) CCC Help French (x32 Version: 2012.1021.1546.26491) CCC Help German (x32 Version: 2012.1021.1546.26491) CCC Help Greek (x32 Version: 2012.1021.1546.26491) CCC Help Hungarian (x32 Version: 2012.1021.1546.26491) CCC Help Italian (x32 Version: 2012.1021.1546.26491) CCC Help Japanese (x32 Version: 2012.1021.1546.26491) CCC Help Korean (x32 Version: 2012.1021.1546.26491) CCC Help Norwegian (x32 Version: 2012.1021.1546.26491) CCC Help Polish (x32 Version: 2012.1021.1546.26491) CCC Help Portuguese (x32 Version: 2012.1021.1546.26491) CCC Help Russian (x32 Version: 2012.1021.1546.26491) CCC Help Spanish (x32 Version: 2012.1021.1546.26491) CCC Help Swedish (x32 Version: 2012.1021.1546.26491) CCC Help Thai (x32 Version: 2012.1021.1546.26491) CCC Help Turkish (x32 Version: 2012.1021.1546.26491) ccc-utility64 (Version: 2012.1021.1547.26491) C-Media PCI Audio Device Corel WinDVD 2010 (x32 Version: 10.0.5.713) Crysis® 2 (x32 Version: 1.0.0.0) CyberLink PowerDVD 12 (x32 Version: 12.0.2428.57) DAEMON Tools Lite (x32 Version: 4.41.3.0173) DB Fahrplaninformation 2011 (x32) DivX-Setup (x32 Version: 2.5.0.8) EasySaver B9.0205.1 (x32 Version: 1.00.0000) ESN Sonar (x32 Version: 0.70.0) ESN Sonar (x32 Version: 0.70.4) Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287) FM Screen Capture Codec (Remove Only) (x32) Fraps (remove only) (x32) Futuremark SystemInfo (x32 Version: 4.9.0) GeoGebra (x32 Version: 3.2.0.0) Gigabyte Raid Configurer (x32 Version: 1.00.0000) Google Chrome (HKCU Version: 24.0.1312.57) Google Earth (x32 Version: 7.1.1.1888) Google Update Helper (x32 Version: 1.3.21.153) Grand Theft Auto IV (x32 Version: 1.00.0000) GTA San Andreas (x32 Version: 1.00.00001) Hauppauge WinTV Infrared Remote (x32 Version: 2.65.27300) Hauppauge WinTV Scheduler (x32) Hauppauge WinTV Soft PVR (x32) HD Tune 2.55 (x32) Heaven DX11 Benchmark version 3.0 (Version: 3.0) HTC BMP USB Driver (x32 Version: 1.0.5375) HTC Driver Installer (x32 Version: 3.0.0.005) HTC Sync (x32 Version: 3.0.5511) HydraVision (x32 Version: 4.2.216.0) Internet-TV für Windows Media Center (x32 Version: 4.2.2.0) InterVideo FilterSDK for Hauppauge (x32) IrfanView (remove only) (x32 Version: 4.27) iTunes (Version: 11.0.1.12) Java 7 Update 7 (64-bit) (Version: 7.0.70) Java Auto Updater (x32 Version: 2.0.2.4) Java(TM) 6 Update 22 (x32 Version: 6.0.220) Job Scheduler 1.3.10.1132 (x32 Version: 1.3.10.1132) Kaspersky PURE (x32 Version: 9.1.0.124) LG Tool Kit (x32 Version: 10.01.0712.01) Logitech Webcam Software (Version: 12.00.1280) Logitech Webcam Software-Treiberpaket (Version: 12.0.1278) LuPO 1.0.2.43 (x32) Mafia II (x32 Version: 1.0) Mass Effect 2 (x32 Version: 1.00) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320) Microsoft .NET Framework 4 Extended (Version: 4.0.30320) Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Choice Guard (x32 Version: 2.0.48.0) Microsoft Flight Simulator X (x32 Version: 10.0.61355.0) Microsoft Flight Simulator X Service Pack 1 (x32 Version: 10.0.61355.0) Microsoft Flight Simulator X Service Pack 2 (x32 Version: 10.0.61472.0) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.88.0) Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0) Microsoft SharedView (x32 Version: 8.0.5725.0) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (x32 Version: 9.0.30411) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053) Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000) Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000) Microsoft-Maus- und Tastatur-Center (Version: 1.1.500.0) MKVToolNix 6.2.0 (x32 Version: 6.2.0) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) MSI Afterburner 2.2.1 (x32 Version: 2.2.1) MSI Kombustor 2.3.0 (x32) MSVCRT (x32 Version: 14.0.1468.721) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) MSXML 4.0 SP2 Parser und SDK (x32 Version: 4.20.9818.0) MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0) NAVIGON Fresh 3.3.1 (x32 Version: 3.3.1) Need for Speed™ ProStreet (x32 Version: 1.0.1.0) Need for Speed™ SHIFT (x32 Version: 1.0.0.0) NVIDIA PhysX (x32 Version: 9.10.0513) OpenAL (x32) Opera 11.00 (x32 Version: 11.00.1156) Opera Stable 15.0.1147.130 (x32 Version: 15.0.1147.130) Origin (x32 Version: 8.5.0.4554) oZone3D.Net FurMark v1.7.0 (x32) PC Remote (x32 Version: 3.44) PDF Settings CS6 (x32 Version: 11.0) PlayReady PC Runtime amd64 (Version: 1.3.0) Pro Evolution Soccer 2010 (x32 Version: 1.00.0000) PunkBuster Services (x32 Version: 0.991) QuickTime (x32 Version: 7.69.80.9) Ralink RT2870 Wireless LAN Card (x32 Version: 1.5.5.0) Realtek 8169 8168 8101E 8102E Ethernet Driver (x32 Version: 1.00.0000) Realtek High Definition Audio Driver (x32 Version: 6.0.1.5780) ROCCAT Kova[+] Mouse Driver (x32 Version: 1.10) Rockstar Games Social Club (x32 Version: 1.00.0000) Room EQ Wizard V5 (x32) Samsung Kies (x32 Version: 2.5.2.13021_10) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.18.0) SimCity 4 (x32) SketchUp 8 (x32 Version: 3.0.16846) Skype™ 5.10 (x32 Version: 5.10.116) SopCast 3.3.2 (x32 Version: 3.3.2) Spotify (HKCU Version: 0.9.1.57.ge7405149) The Lord of the Rings FREE Trial (x32 Version: 1.00.0000) TIPP10 Version 2.1.0 (x32) Ubisoft Game Launcher (x32 Version: 1.0.0.0) Uninstall 1.0.0.1 (x32) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) VC80CRTRedist - 8.0.50727.4053 (x32 Version: 1.1.0) Veetle TV 0.9.18 (x32 Version: 0.9.18) VLC media player 2.0.4 (Version: 2.0.4) vShare plugin 1.3 (x32 Version: 1.3) vShare.tv plugin 1.3 (x32 Version: 1.3) VshareComplete (x32) VTPlus32 für WinTV (German) (x32) Win7codecs (x32 Version: 3.1.7) Windows Live Call (x32 Version: 14.0.8117.0416) Windows Live Communications Platform (x32 Version: 14.0.8117.416) Windows Live Essentials (x32 Version: 14.0.8117.0416) Windows Live Essentials (x32 Version: 14.0.8117.416) Windows Live Fotogalerie (x32 Version: 14.0.8117.416) Windows Live ID Sign-in Assistant (Version: 6.500.3165.0) Windows Live Messenger (x32 Version: 14.0.8117.0416) Windows Live Movie Maker (x32 Version: 14.0.8117.0416) Windows Live Sync (x32 Version: 14.0.8117.416) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029) Windows Media Center Add-in for Silverlight (x32 Version: 4.7.3.0) Windows Media Encoder 9 Series (x32 Version: 9.00.2980) Windows Media Encoder 9 Series (x32) Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8) WinRAR ==================== Restore Points ========================= 08-03-2013 13:48:07 Installiert Suite 08-03-2013 14:53:04 Installiert PowerDVD 08-03-2013 15:07:01 Konfiguriert PowerDVD 08-03-2013 15:09:15 Konfiguriert PowerDVD 08-03-2013 15:13:06 Konfiguriert PowerStarter 08-03-2013 15:20:07 Installed Corel WinDVD 2010. 08-03-2013 16:08:29 Installiert PowerDVD 14-03-2013 18:00:14 Windows Update 23-03-2013 15:52:01 Geplanter Prüfpunkt 23-03-2013 18:00:11 Windows Update 31-03-2013 22:09:36 Entfernt 3DMark 11 08-04-2013 19:09:03 Geplanter Prüfpunkt 10-04-2013 17:00:13 Windows Update 21-04-2013 04:01:32 Geplanter Prüfpunkt 25-04-2013 17:00:11 Windows Update 05-05-2013 14:01:53 Geplanter Prüfpunkt 13-05-2013 19:20:06 Geplanter Prüfpunkt 13-05-2013 21:43:35 Installed SketchUp 8 15-05-2013 17:00:14 Windows Update 24-05-2013 13:35:54 Geplanter Prüfpunkt 31-05-2013 13:46:53 Geplanter Prüfpunkt 09-06-2013 14:09:24 Geplanter Prüfpunkt 12-06-2013 17:00:24 Windows Update 21-06-2013 11:07:01 Geplanter Prüfpunkt 28-06-2013 12:51:58 Geplanter Prüfpunkt 06-07-2013 15:52:17 Geplanter Prüfpunkt 10-07-2013 17:00:13 Windows Update 17-07-2013 20:41:19 Geplanter Prüfpunkt 22-07-2013 17:00:22 Windows Update 26-07-2013 19:27:13 Acronis True Image wird installiert 29-07-2013 14:50:06 Installed PC Remote 05-08-2013 00:59:37 ComboFix created restore point ==================== Hosts content: ========================== 2013-08-05 03:14 - 2013-08-05 03:14 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {04FD5BE0-5C2A-4BDB-89E0-5C83F6A868FF} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-08-04] (Microsoft Corporation) Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {137C9A19-C927-4E1C-A60D-18E67A2A9830} - System32\Tasks\WPD\SqmUpload_S-1-5-21-129091277-1404308245-1713919007-1002 => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {18C46911-AE17-4CD5-BDFD-799166206041} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Device Center\itype.exe [2012-06-26] (Microsoft Corporation) Task: {26873A48-77AC-4A85-B1E2-4DE15E67C815} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-11-08] (Google Inc.) Task: {36E4A8B4-19D2-4F28-BC68-7DD7671AE7F6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-11-08] (Google Inc.) Task: {5A026CB4-5EF6-496D-9094-0260017EAB5E} - System32\Tasks\Microsoft\Windows\Defrag\ManualDefrag => C:\Windows\system32\defrag.exe [2009-07-14] (Microsoft Corp.) Task: {65E3B4AE-08B0-4A60-ADEE-C15DA46B738C} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Device Center\ipoint.exe [2012-06-26] (Microsoft Corporation) Task: {71216718-E80C-4A94-B812-BB5CB63AEF66} - System32\Tasks\User_Feed_Synchronization-{B6B34A72-81EF-4613-A0DD-4907EF734045} => C:\Windows\system32\msfeedssync.exe [2012-03-16] (Microsoft Corporation) Task: {712C6861-2B14-4E72-92BA-22B6921FE2B7} - System32\Tasks\Microsoft\Windows\Wired\GatherWiredInfo => C:\Windows\system32\gatherWiredInfo.vbs No File Task: {903E4620-BCF0-4728-9BD1-CBAEC83B78E0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated) Task: {956709D3-4DA4-4295-B982-C8FF2A8ED1C8} - System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe => c:\Program Files\Microsoft Device Center\devicecenter.exe [2012-06-26] (Microsoft) Task: {ADF2C455-C587-4A23-8959-72A28993F302} - System32\Tasks\AdobeAAMUpdater-1.0-GOGI-GögiPC => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated) Task: {C523EF49-92D8-4ECD-8D70-72636363A4C3} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2011-01-07] () Task: {CADFF5CB-5637-4F31-9802-0B7F732B1B51} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2012-05-14] () Task: {CB7BDB21-C0B6-469A-9FFD-F08062FF907D} - System32\Tasks\{DA8A8CB8-8E38-4434-895A-763FE01A3186} => C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe No File Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs No File Task: {FB79E791-B75F-4236-84C7-572B4E4EBC39} - System32\Tasks\{9CACB411-662F-4BA4-A3D7-79AC25A7FDCE} => C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe No File Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= Name: AILT2RX2 IDE Controller Description: AILT2RX2 IDE Controller Class Guid: {4D36E97B-E325-11CE-BFC1-08002BE10318} Manufacturer: (Standard mass storage controllers) Service: ak8ts88u Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/05/2013 00:01:59 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (08/05/2013 00:00:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "StarWind AE Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (08/05/2013 00:00:38 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (08/05/2013 11:59:10 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error: (08/05/2013 11:59:10 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (08/05/2013 11:59:10 AM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-08-05 03:11:04.727 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-08-05 03:11:04.551 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-08 16:25:21.337 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-08 16:25:21.168 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-08 16:25:20.960 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-08 16:25:20.630 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-08 16:25:20.394 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-08 16:25:20.265 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-08 16:25:20.114 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\gpapi.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-08 16:25:19.968 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\gpapi.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 33% Total physical RAM: 8190.49 MB Available physical RAM: 5417.71 MB Total Pagefile: 16379.12 MB Available Pagefile: 13755.83 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:596.17 GB) (Free:29.87 GB) NTFS (Disk=0 Partition=1) ==>[Drive with boot components (obtained from BCD)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: F7A89292) Partition 1: (Active) - (Size=596 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
05.08.2013, 11:23 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM)
__________________Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ |
05.08.2013, 19:06 | #19 |
| BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Also ESET hat noch was gefunden. Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a0b1b791c80d0842b1edd9f48a8cc695 # engine=14656 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-05 01:12:52 # local_time=2013-08-05 03:12:52 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=1282 16774526 100 100 15090508 134699344 2728090 0 # compatibility_mode=1797 16774142 0 89 89003546 152149212 0 0 # compatibility_mode=5893 16776574 100 94 15095181 128114043 0 0 # scanned=304685 # found=9 # cleaned=0 # scan_time=9313 sh=2CA5B3BEFCDA6F90A84B644AE0D882F7AAC8D122 ft=1 fh=00e9ab8f971a1be6 vn="Win32/Moure.C trojan" ac=I fn="C:\FRST\Quarantine\liuffsmmfodrcvajm.exe" sh=21C23C470BDABB763D2FC372D86E9D3FB9F923AE ft=1 fh=1a43b0206fc57ad6 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="C:\Program Files (x86)\Codemasters\DiRT 3\paul.dll" sh=5B31FB5741304E8486ACFD81E30B314B87A28E9F ft=1 fh=b4b60b69ec22cbd1 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="C:\Program Files (x86)\Codemasters\DiRT 3\SKIDROW.dll" sh=ACADF2B82AECDEDB4D590808EEB01D436999E91E ft=1 fh=f1e915411acfaf75 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\ubiorbitapi_r2.dll" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="C:\Spiele Installationen\Dirt 3\Dirt.3\Dirt.3-SKIDROW\sr-dirt3\sr-dirt3.iso" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAD trojan" ac=I fn="C:\Spiele Installationen\Need for Speed HotPursuit\rld-nshp\rld-nshp.iso" sh=AE295385D4F268E7FFDC7FA0845F23C512DD76EB ft=0 fh=0000000000000000 vn="a variant of Java/Agent.BR trojan" ac=I fn="C:\Users\GögiPC\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\5ee8d1e1-4b455d89" sh=5BC8FC902AC06B2E27A1D8DF625411682D31E7EF ft=0 fh=0000000000000000 vn="probably a variant of Java/Agent.BR trojan" ac=I fn="C:\Users\GögiPC\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\f33661-425f8533" sh=D03DCD16C3B146C462CFBAB99C7F4579BD29B356 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\GögiPC\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\1b9ce070-30c59de1" |
05.08.2013, 23:12 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ?Code:
ATTFilter C:\Program Files (x86)\Codemasters\DiRT 3\paul.dll" C:\Program Files (x86)\Codemasters\DiRT 3\SKIDROW.dll" C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\ubiorbitapi_r2.dll" C:\Spiele Installationen\Dirt 3\Dirt.3\Dirt.3-SKIDROW\sr-dirt3\sr-dirt3.iso" C:\Spiele Installationen\Need for Speed HotPursuit\rld-nshp\rld-nshp.iso" Bitte lesen => http://www.trojaner-board.de/95393-c...-software.html
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? |
anmeldefenster, aufforderung, aufrufen, beste, besten, direkt, erklären, geld, hoffe, kaspersky, leute, maleware, maleware gefunden, modus, natürlich, plötzlich, rechte, rechten, sicherheit, sperrt, strg, surfe, surfen, taskmanager, verbreitet, win, win7 |