|
Plagegeister aller Art und deren Bekämpfung: BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
04.08.2013, 13:49 | #1 |
| BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Hallo Leute, als ich eben am surfen war, kam plötzlich von Kaspersky eine Meldung, dass eine Maleware gefunden wurde und 5s darauf wurde mein PC gesperrt. Jetzt kommt immer ein Fake-Bild vom ''Bundesamt für Sicherheit in der Informationstechnik'', worin mir vorgeworfen wird, dass ich Urheberrechtlich geschütztes Material verbreitet und Kinderpornographisches Material besitze, was natürlich nicht stimmt und ich Geld bezahlen soll, damit mein PC wieder entsperrt wird. Das ist natürlich alles murks. Noch paar Detais,wie es um den PC steht : Ein Benutzterkonto mit Adminrechten,ich, wo dieses Bild erscheint. Hierbei kann ich mit STRG ALT und ENTF das Menü mit dem Taskmanager und alles aufrufen,mehr aber auch nicht. Wenn ich i-etwas mache, lande ich wieder auf dem Bild. Abgesicherter Modus geht auch nicht, egal in welchen ich gehe, immer komme ich bis zum Anmeldefenster ,ich logge mich ein und der PC fährt direkt wieder herunter. Es handelt sich um Win7 64Bit. Ich hoffe ihr könnt mir dabei helfen und erklären, wie ich jetzt am Besten vorgehe um die Maleware zu entfernen/den PC zu bereinigen. Danke im vorraus lg TroGo Geändert von TroGo (04.08.2013 um 13:58 Uhr) |
04.08.2013, 14:37 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Hallo,
__________________Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8) Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
__________________ |
04.08.2013, 17:52 | #3 |
| BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? FRST Logfile:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-08-2013 Ran by SYSTEM on 04-08-2013 18:27:58 Running from E:\ Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [CmPCIaudio] - C:\Windows\syswow64\RunDll32.exe [44544 2009-07-14] (Microsoft Corporation) HKLM\...\Run: [Cmaudio8788] - C:\Windows\syswow64\RunDll32.exe [44544 2009-07-14] (Microsoft Corporation) HKLM\...\Run: [Cmaudio8788GX] - C:\Windows\syswow64\HsMgr.exe [200704 2008-07-11] () HKLM\...\Run: [Cmaudio8788GX64] - C:\Windows\system\HsMgr64.exe [282112 2008-07-11] () HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395928 2012-05-10] (Acronis) Winlogon\Notify\klogon: %SystemRoot%\System32\klogon.dll (Kaspersky Lab) HKLM-x32\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [36864 2007-03-20] () HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-10-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe [348760 2010-10-01] (Kaspersky Lab) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310128 2013-02-13] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [LGODDFU] - C:\Program Files (x86)\lg_fwupdate\lgfw.exe [27760 2013-03-08] (Bitleader) HKLM-x32\...\Run: [PowerDVD12DMREngine] - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe [506480 2012-12-28] (CyberLink) HKLM-x32\...\Run: [PowerDVD12Agent] - C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe [375168 2012-12-28] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated) HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2673640 2012-05-10] () HKU\GögiPC\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [163328 2009-07-14] (Microsoft Corporation) HKU\GögiPC\...\Run: [AdobeBridge] - [x] HKU\GögiPC\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1509232 2013-02-13] (Samsung) HKU\GögiPC\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup [x] HKU\GögiPC\...\Run: [Spotify Web Helper] - C:\Users\GögiPC\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-08] (Spotify Ltd) HKU\GögiPC\...\Run: [Spotify] - C:\Users\GögiPC\AppData\Roaming\Spotify\spotify.exe [4640768 2013-07-08] (Spotify Ltd) HKU\GögiPC\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844144 2013-02-13] (Samsung) HKU\GögiPC\...\Run: [PC Remote Server] - C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe [1070744 2013-07-26] (PC Remote) HKU\GögiPC\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\Users\GGIPC~1\AppData\Local\Temp\liuffsmmfodrcvajm.exe [65024 2013-08-04] () <===== ATTENTION HKU\GögiPC\...\Winlogon: [Shell] cmd.exe [344576 2009-07-14] (Microsoft Corporation) <==== ATTENTION HKU\GögiPC\...\Command Processor: "C:\Users\GGIPC~1\AppData\Local\Temp\liuffsmmfodrcvajm.exe" <===== ATTENTION! AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~2\x64\kloehk.dll,C:\PROGRA~2\KASPER~1\KASPER~2\x64\sbhook64.dll [69720 2010-10-01] (Kaspersky Lab) AppInit_DLLs-x32: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~2\sbhook.dll [69720 2010-10-01] () ==================== Services (Whitelisted) ================= S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-10-21] (Advanced Micro Devices, Inc.) S4 AODService; C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe [136544 2009-10-22] () S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe [348760 2010-10-01] (Kaspersky Lab) S2 CLHNServiceForPowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe [91248 2012-12-28] (CyberLink Corp.) S2 CSObjectsSrv; C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [743992 2009-12-21] (Infowatch) S2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [78960 2012-12-28] (CyberLink) S2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [296048 2012-12-28] (CyberLink) S4 ES lite Service; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [68136 2009-02-05] () S4 Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [135584 2012-04-26] (Futuremark Corporation) S2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2010-09-16] () S2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-02-28] () S3 NMIndexingService; "C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe" [x] S2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [x] ==================== Drivers (Whitelisted) ==================== S3 AODDriver; C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver.sys [21048 2009-10-22] (Advanced Micro Devices) S3 AODDriver; C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver.sys [21048 2009-10-22] (Advanced Micro Devices) S2 AODDriver4.01; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) S2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) S3 ATITool; C:\Windows\System32\DRIVERS\ATITool64.sys [30720 2006-11-10] () S3 cmuda3; C:\Windows\System32\drivers\cmudax3.sys [1155072 2009-12-01] (C-Media Inc) S3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2726400 2011-07-04] (C-Media Inc) S0 CSCrySec; C:\Windows\System32\DRIVERS\CSCrySec.sys [85048 2009-12-14] (Infowatch) S1 CSVirtualDiskDrv; C:\Windows\System32\DRIVERS\CSVirtualDiskDrv.sys [66104 2009-12-14] (Infowatch) S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [270912 2011-09-30] (DT Soft Ltd) S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-09-17] (EnTech Taiwan) S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-09-17] (EnTech Taiwan) S3 gdrv; C:\Windows\gdrv.sys [23080 2011-10-13] (Windows (R) Server 2003 DDK provider) S3 gdrv; C:\Windows\gdrv.sys [23080 2011-10-13] (Windows (R) Server 2003 DDK provider) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2009-11-23] () S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2009-11-23] () S3 hcw88rc5; C:\Windows\System32\Drivers\hcw88rc5.sys [15872 2009-08-06] (Hauppauge Computer Works, Inc.) S1 kl1; C:\Windows\System32\DRIVERS\kl1.sys [157712 2009-09-01] (Kaspersky Lab) S0 KLBG; C:\Windows\System32\DRIVERS\klbg.sys [40464 2009-10-14] (Kaspersky Lab) S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [353296 2013-02-11] (Kaspersky Lab) S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [27152 2009-09-14] (Kaspersky Lab) S3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [21008 2009-10-02] (Kaspersky Lab) S3 KovaPlusFltr; C:\Windows\System32\drivers\KovaPlusFltr.sys [15104 2010-01-25] (ROCCAT Development, Inc.) S3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-04-30] () S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-04-30] () S3 MRV6X64U; C:\Windows\System32\DRIVERS\MRVW23C.sys [255232 2007-01-04] (Marvell Semiconductor, Inc) S2 ntk_PowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [83704 2012-09-10] (Cyberlink Corp.) S2 ntk_PowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [83704 2012-09-10] (Cyberlink Corp.) S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [10568 2012-05-14] () S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [10568 2012-05-14] () S0 sptd; C:\Windows\System32\Drivers\sptd.sys [526392 2011-09-30] (Duplex Secure Ltd.) S0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [141920 2013-07-26] (Acronis) S2 {73526619-C24F-470B-9BED-53D455FBB5C6}; C:\Program Files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl [130320 2012-12-28] (CyberLink Corp.) S2 {73526619-C24F-470B-9BED-53D455FBB5C6}; C:\Program Files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl [130320 2012-12-28] (CyberLink Corp.) S3 ALSysIO; \??\C:\Users\GGIPC~1\AppData\Local\Temp\ALSysIO64.sys [x] S3 cpuz130; \??\C:\Users\GGIPC~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x] S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [x] S3 GPU-Z; \??\C:\Users\GGIPC~1\AppData\Local\Temp\GPU-Z.sys [x] S3 RivaTuner64; \??\C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-04 18:27 - 2013-08-04 18:27 - 00000000 ____D C:\FRST 2013-08-04 13:20 - 2013-08-04 13:20 - 00393552 _____ C:\ProgramData\2433f433 2013-08-04 13:20 - 2013-08-04 13:20 - 00393528 _____ C:\Users\GögiPC\AppData\Local\2433f433 2013-08-04 13:20 - 2013-08-04 13:20 - 00393488 _____ C:\Users\GögiPC\AppData\Roaming\2433f433 2013-07-29 15:50 - 2013-07-29 15:50 - 00001082 _____ C:\Users\GögiPC\Desktop\PC Remote Server.lnk 2013-07-29 15:50 - 2013-07-29 15:50 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\PC Remote 2013-07-29 15:50 - 2013-07-29 15:50 - 00000000 ____D C:\Program Files (x86)\PC Remote 2013-07-29 15:49 - 2013-07-29 15:49 - 01163264 _____ C:\Users\GögiPC\Downloads\PCRemoteSetup.msi 2013-07-27 12:41 - 2013-07-27 12:41 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-07-26 20:32 - 2013-07-26 20:32 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Acronis 2013-07-26 20:31 - 2013-07-26 20:31 - 00000000 ____D C:\ProgramData\Acronis 2013-07-26 20:30 - 2013-07-26 20:30 - 00971360 _____ (Acronis) C:\Windows\System32\Drivers\timntr.sys 2013-07-26 20:30 - 2013-07-26 20:30 - 00001173 _____ C:\Users\Public\Desktop\Acronis True Image WD*Edition.lnk 2013-07-26 20:29 - 2013-07-26 20:29 - 00210016 _____ (Acronis) C:\Windows\System32\Drivers\vididr.sys 2013-07-26 20:28 - 2013-07-26 20:28 - 00275552 _____ (Acronis) C:\Windows\System32\Drivers\snapman.sys 2013-07-26 20:28 - 2013-07-26 20:28 - 00141920 _____ (Acronis) C:\Windows\System32\Drivers\vsflt53.sys 2013-07-26 20:28 - 2013-07-26 20:28 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-07-26 18:21 - 2013-07-26 18:28 - 156004120 _____ C:\Users\GögiPC\Downloads\tih_s_g_14192.exe 2013-07-26 16:13 - 2013-07-26 16:14 - 11232297 _____ C:\Users\GögiPC\Downloads\Stir_i_g2012.(2012).rar.part 2013-07-26 13:37 - 2013-07-26 13:37 - 01273067 _____ C:\Users\GögiPC\Downloads\4002051620318.zip 2013-07-22 18:00 - 2013-07-22 18:00 - 00000000 ____D C:\Windows\System32\MRT 2013-07-11 17:12 - 2013-07-11 17:12 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-07-11 16:38 - 2013-07-11 17:23 - 00000000 ____D C:\Users\GögiPC\Documents\SelfMV 2013-07-11 16:19 - 2013-07-11 16:19 - 00000000 ____H C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-07-11 16:17 - 2013-07-11 16:17 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-07-11 16:17 - 2013-07-11 16:17 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Samsung 2013-07-11 16:17 - 2013-07-11 16:17 - 00000000 ____D C:\Users\GögiPC\AppData\Local\Samsung 2013-07-11 16:16 - 2013-07-11 16:16 - 00000000 ____D C:\Users\GögiPC\Documents\samsung ==================== One Month Modified Files and Folders ======= 2013-08-04 18:27 - 2013-08-04 18:27 - 00000000 ____D C:\FRST 2013-08-04 13:25 - 2013-06-19 18:48 - 00003016 _____ C:\Windows\System32\Tasks\MSIAfterburner 2013-08-04 13:25 - 2013-06-04 13:13 - 00260307 _____ C:\Windows\setupact.log 2013-08-04 13:25 - 2009-11-08 19:07 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-04 13:25 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-04 13:24 - 2010-02-12 20:52 - 00000000 _____ C:\Windows\System32\Drivers\lvuvc.hs 2013-08-04 13:21 - 2010-10-10 11:16 - 02064973 _____ C:\Windows\WindowsUpdate.log 2013-08-04 13:20 - 2013-08-04 13:20 - 00393552 _____ C:\ProgramData\2433f433 2013-08-04 13:20 - 2013-08-04 13:20 - 00393528 _____ C:\Users\GögiPC\AppData\Local\2433f433 2013-08-04 13:20 - 2013-08-04 13:20 - 00393488 _____ C:\Users\GögiPC\AppData\Roaming\2433f433 2013-08-04 13:03 - 2009-11-08 19:07 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-04 13:02 - 2013-05-28 17:23 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-04 12:02 - 2009-09-21 17:27 - 00000000 ____D C:\Users\GögiPC\AppData\Local\Adobe 2013-08-03 15:18 - 2011-10-23 14:41 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\vlc 2013-08-02 18:38 - 2009-11-10 21:33 - 00010912 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-02 18:38 - 2009-11-10 21:33 - 00010912 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-02 18:31 - 2013-05-20 17:54 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Spotify 2013-08-02 18:29 - 2010-02-12 21:11 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-07-29 15:50 - 2013-07-29 15:50 - 00001082 _____ C:\Users\GögiPC\Desktop\PC Remote Server.lnk 2013-07-29 15:50 - 2013-07-29 15:50 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\PC Remote 2013-07-29 15:50 - 2013-07-29 15:50 - 00000000 ____D C:\Program Files (x86)\PC Remote 2013-07-29 15:49 - 2013-07-29 15:49 - 01163264 _____ C:\Users\GögiPC\Downloads\PCRemoteSetup.msi 2013-07-27 12:41 - 2013-07-27 12:41 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-07-27 12:40 - 2009-11-08 19:07 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-26 20:32 - 2013-07-26 20:32 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Acronis 2013-07-26 20:31 - 2013-07-26 20:31 - 00000000 ____D C:\ProgramData\Acronis 2013-07-26 20:30 - 2013-07-26 20:30 - 00971360 _____ (Acronis) C:\Windows\System32\Drivers\timntr.sys 2013-07-26 20:30 - 2013-07-26 20:30 - 00001173 _____ C:\Users\Public\Desktop\Acronis True Image WD*Edition.lnk 2013-07-26 20:29 - 2013-07-26 20:29 - 00210016 _____ (Acronis) C:\Windows\System32\Drivers\vididr.sys 2013-07-26 20:28 - 2013-07-26 20:28 - 00275552 _____ (Acronis) C:\Windows\System32\Drivers\snapman.sys 2013-07-26 20:28 - 2013-07-26 20:28 - 00141920 _____ (Acronis) C:\Windows\System32\Drivers\vsflt53.sys 2013-07-26 20:28 - 2013-07-26 20:28 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-07-26 18:28 - 2013-07-26 18:21 - 156004120 _____ C:\Users\GögiPC\Downloads\tih_s_g_14192.exe 2013-07-26 16:14 - 2013-07-26 16:13 - 11232297 _____ C:\Users\GögiPC\Downloads\Stir_i_g2012.(2012).rar.part 2013-07-26 13:37 - 2013-07-26 13:37 - 01273067 _____ C:\Users\GögiPC\Downloads\4002051620318.zip 2013-07-24 20:14 - 2011-01-09 19:34 - 00000000 ____D C:\Users\GögiPC\Desktop\Neuer Ordner 2013-07-22 18:06 - 2013-07-22 18:00 - 00000000 ____D C:\Windows\System32\MRT 2013-07-17 18:17 - 2013-05-20 17:55 - 00000000 ____D C:\Users\GögiPC\AppData\Local\Spotify 2013-07-15 18:58 - 2009-11-08 19:07 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-15 18:58 - 2009-11-08 19:07 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-14 10:07 - 2012-06-26 00:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-07-14 10:07 - 2012-05-14 02:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-14 10:07 - 2012-05-14 02:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-11 17:23 - 2013-07-11 16:38 - 00000000 ____D C:\Users\GögiPC\Documents\SelfMV 2013-07-11 17:12 - 2013-07-11 17:12 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-07-11 16:19 - 2013-07-11 16:19 - 00000000 ____H C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-07-11 16:17 - 2013-07-11 16:17 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-07-11 16:17 - 2013-07-11 16:17 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Samsung 2013-07-11 16:17 - 2013-07-11 16:17 - 00000000 ____D C:\Users\GögiPC\AppData\Local\Samsung 2013-07-11 16:16 - 2013-07-11 16:16 - 00000000 ____D C:\Users\GögiPC\Documents\samsung 2013-07-10 18:05 - 2009-09-20 13:36 - 00000000 ____D C:\ProgramData\Microsoft Help Files to move or delete: ==================== C:\Users\GGIPC~1\AppData\Local\Temp\liuffsmmfodrcvajm.exe ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-02-27 19:00:25 Restore point made on: 2013-03-08 14:48:36 Restore point made on: 2013-03-08 15:53:11 Restore point made on: 2013-03-08 16:07:08 Restore point made on: 2013-03-08 16:09:27 Restore point made on: 2013-03-08 16:13:13 Restore point made on: 2013-03-08 16:20:13 Restore point made on: 2013-03-08 17:08:48 Restore point made on: 2013-03-14 19:00:34 Restore point made on: 2013-03-23 16:52:24 Restore point made on: 2013-03-23 19:00:26 Restore point made on: 2013-03-31 23:09:56 Restore point made on: 2013-04-08 20:09:37 Restore point made on: 2013-04-10 18:00:30 Restore point made on: 2013-04-21 05:02:04 Restore point made on: 2013-04-25 18:00:37 Restore point made on: 2013-05-05 15:02:35 Restore point made on: 2013-05-13 20:20:44 Restore point made on: 2013-05-13 22:44:09 Restore point made on: 2013-05-15 18:00:41 Restore point made on: 2013-05-24 14:36:40 Restore point made on: 2013-05-31 14:47:33 Restore point made on: 2013-06-09 15:09:50 Restore point made on: 2013-06-12 18:00:56 Restore point made on: 2013-06-21 12:07:20 Restore point made on: 2013-06-28 13:52:18 Restore point made on: 2013-07-06 16:52:40 Restore point made on: 2013-07-10 18:00:37 Restore point made on: 2013-07-17 21:41:44 Restore point made on: 2013-07-22 18:00:40 Restore point made on: 2013-07-26 20:27:39 Restore point made on: 2013-07-29 15:50:29 ==================== Memory info =========================== Percentage of memory in use: 9% Total physical RAM: 8190.49 MB Available physical RAM: 7376.14 MB Total Pagefile: 8188.64 MB Available Pagefile: 7362.95 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:596.17 GB) (Free:5.01 GB) NTFS (Disk=0 Partition=1) ==>[Drive with boot components (obtained from BCD)] Drive e: () (Removable) (Total:0.96 GB) (Free:0.96 GB) FAT (Disk=1 Partition=1) Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: F7A89292) Partition 1: (Active) - (Size=596 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 983 MB) (Disk ID: 00000000) Partition 1: (Active) - (Size=983 MB) - (Type=0E) LastRegBack: 2013-08-03 11:51 ==================== End Of Log ============================ --- --- --- |
04.08.2013, 17:54 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\GögiPC\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\Users\GGIPC~1\AppData\Local\Temp\liuffsmmfodrcvajm.exe [65024 2013-08-04] () <===== ATTENTION HKU\GögiPC\...\Winlogon: [Shell] cmd.exe [344576 2009-07-14] (Microsoft Corporation) <==== ATTENTION HKU\GögiPC\...\Command Processor: "C:\Users\GGIPC~1\AppData\Local\Temp\liuffsmmfodrcvajm.exe" <===== ATTENTION! C:\Users\GGIPC~1\AppData\Local\Temp\liuffsmmfodrcvajm.exe C:\ProgramData\2433f433 C:\Users\GögiPC\AppData\Local\2433f433 C:\Users\GögiPC\AppData\Roaming\2433f433
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.
__________________ Logfiles bitte immer in CODE-Tags posten |
04.08.2013, 18:14 | #5 |
| BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ?Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-08-2013 Ran by SYSTEM at 2013-08-04 19:13:07 Run:1 Running from E:\ Boot Mode: Recovery ============================================== HKU\GögiPC\Software\Microsoft\Windows\CurrentVersion\Run\\qcgce2mrvjq91kk1e7pnbb19m52fx => Value deleted successfully. HKU\GögiPC\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully. HKU\GögiPC\Software\Microsoft\Command Processor\\AutoRun => Value deleted successfully. C:\Users\GGIPC~1\AppData\Local\Temp\liuffsmmfodrcvajm.exe => Moved successfully. C:\ProgramData\2433f433 => Moved successfully. C:\Users\GögiPC\AppData\Local\2433f433 => Moved successfully. C:\Users\GögiPC\AppData\Roaming\2433f433 => Moved successfully. ==== End of Fixlog ==== |
04.08.2013, 18:15 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Startet Windows wieder normal? Wenn ja: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ --> BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? |
04.08.2013, 18:47 | #7 |
| BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Habe den Scan durchgeführt, aber mein PC hat keine Internetverbindung. Die Netztwerke vom Nachbarn werden gefunden,doch meins nicht. Über mein Handy und Notebook,kann ich problemlos ins Internet. Hat das jetzt was mit dem ganzen hier zutun ? FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-08-2013 Ran by GögiPC (administrator) on 04-08-2013 19:40:52 Running from C:\Users\GögiPC\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe (Infowatch) C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe () C:\Windows\SysWOW64\HsMgr.exe () C:\Windows\system\HsMgr64.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (CMedia) C:\Program Files\UNi Xonar Audio\Customapp\ASUSAUDIOCENTER.EXE (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Spotify Ltd) C:\Users\GögiPC\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (PC Remote) C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe (Hauppauge Computer Works) C:\Program Files (x86)\WinTV\Ir.exe (Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [CmPCIaudio] - C:\Windows\syswow64\RunDll32.exe [44544 2009-07-14] (Microsoft Corporation) HKLM\...\Run: [Cmaudio8788] - C:\Windows\syswow64\RunDll32.exe [44544 2009-07-14] (Microsoft Corporation) HKLM\...\Run: [Cmaudio8788GX] - C:\Windows\syswow64\HsMgr.exe [200704 2008-07-11] () HKLM\...\Run: [Cmaudio8788GX64] - C:\Windows\system\HsMgr64.exe [282112 2008-07-11] () HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395928 2012-05-10] (Acronis) Winlogon\Notify\klogon: %SystemRoot%\System32\klogon.dll (Kaspersky Lab) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [163328 2009-07-14] (Microsoft Corporation) HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1509232 2013-02-13] (Samsung) HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup [x] HKCU\...\Run: [Spotify Web Helper] - C:\Users\GögiPC\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-08] (Spotify Ltd) HKCU\...\Run: [Spotify] - C:\Users\GögiPC\AppData\Roaming\Spotify\spotify.exe [4640768 2013-07-08] (Spotify Ltd) HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844144 2013-02-13] (Samsung) HKCU\...\Run: [PC Remote Server] - C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe [1070744 2013-07-26] (PC Remote) HKCU\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2011-10-06] (AMD) MountPoints2: G - G:\LaunchU3.exe -a MountPoints2: {37496364-6810-11e0-9c4f-00241d7f2969} - E:\Autorun.exe MountPoints2: {374963a2-6810-11e0-9c4f-00241d7f2969} - F:\Autorun.exe MountPoints2: {55426455-e0e0-11de-ac5d-00241d7f2969} - H:\Autorun.exe MountPoints2: {58c527e6-a24e-11e2-a575-00241d7f2969} - G:\HTC_Sync_Manager_PC.exe MountPoints2: {6abb1f57-8eac-11e0-b639-00241d7f2969} - H:\NokiaPCIA_Autorun.exe MountPoints2: {d0c35962-6825-11e0-917f-00241d7f2969} - G:\Autorun.exe MountPoints2: {f55c02be-44cc-11e2-8f1d-00241d7f2969} - G:\LaunchU3.exe -a HKLM-x32\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [36864 2007-03-20] () HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-10-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe [348760 2010-10-01] (Kaspersky Lab) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310128 2013-02-13] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [LGODDFU] - C:\Program Files (x86)\lg_fwupdate\lgfw.exe [27760 2013-03-08] (Bitleader) HKLM-x32\...\Run: [PowerDVD12DMREngine] - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe [506480 2012-12-28] (CyberLink) HKLM-x32\...\Run: [PowerDVD12Agent] - C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe [375168 2012-12-28] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated) HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2673640 2012-05-10] () AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~2\x64\kloehk.dll,C:\PROGRA~2\KASPER~1\KASPER~2\x64\sbhook64.dll [69720 2010-10-01] (Kaspersky Lab) AppInit_DLLs-x32: C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~2\sbhook.dll [69720 2010-10-01] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoStart IR.lnk ShortcutTarget: AutoStart IR.lnk -> C:\Program Files (x86)\WinTV\Ir.exe (Hauppauge Computer Works) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {7C64CE0F-5B11-4A36-95F6-635B7AA1BBC7} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://startsear.ch/?aff=1&src=sp&cf=7f4d4669-179d-11e1-93e5-00241d7f2969&q={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://startsear.ch/?aff=1&src=sp&cf=7f4d4669-179d-11e1-93e5-00241d7f2969&q={searchTerms} SearchScopes: HKCU - {0D7562AE-8EF6-416d-A838-AB665251703A} URL = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ATU3&o=15380&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=UJ&apn_dtid=YYYYYYYYDE&apn_uid=7522A3FD-2BD7-4E1A-929D-E0137200CCB7&apn_sauid=837BD6FF-CB3F-4574-9572-D7FFE97B28DD SearchScopes: HKCU - {7C64CE0F-5B11-4A36-95F6-635B7AA1BBC7} URL = hxxp://www.bing.com/search?FORM=IEFM1&q={searchTerms}&src={referrer:source?} SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = hxxp://www.daemon-search.com/search?q={searchTerms} BHO: VshareComplete - {08337871-0e50-4031-9110-3bd21ca3c065} - C:\Users\GögiPC\AppData\Roaming\VshareComplete\64\VshareComplete64.dll (SimplyGen) BHO: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\ievkbd.dll (Kaspersky Lab) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\klwtbbho.dll (Kaspersky Lab) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) BHO-x32: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\ievkbd.dll (Kaspersky Lab) BHO-x32: DivX HiQ - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: CescrtHlpr Object - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab) Toolbar: HKLM - No Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - No File Toolbar: HKLM-x32 - facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - No Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - No File DPF: HKLM-x32 {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Hosts: Hosts file not detected in the default directory FireFox: ======== FF ProfilePath: C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default FF SelectedSearchEngine: Google FF Homepage: www.google.de FF Keyword.URL: hxxp://startsear.ch/?aff=1&src=sp&cf=7f4d4669-179d-11e1-93e5-00241d7f2969&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.0 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll No File FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.118.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.132.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @pages.tvunetworks.com/WebPlayer - C:\Windows\system32\TVUAx\npTVUAx.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\GögiPC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\GögiPC\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\GögiPC\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\searchplugins\daemon-search.xml FF SearchPlugin: C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\searchplugins\startsear.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml FF Extension: No Name - C:\Users\GögiPC\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: TVU Web Player - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\firefox@tvunetworks.com FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\ich@maltegoetz.de FF Extension: Gradient iCool - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\{de5809e0-2b07-11dd-bd0b-0800200c9a66} FF Extension: nasanightlaunch - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\nasanightlaunch@example.com.xpi FF Extension: No Name - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi FF Extension: No Name - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video FF HKLM-x32\...\Firefox\Extensions: [{6904342A-8307-11DF-A508-4AE2DFD72085}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa FF Extension: DivX HiQ - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa FF HKLM-x32\...\Thunderbird\Extensions: [{eea12ec4-729d-4703-bc37-106ce9879ce2}] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\THBExt FF Extension: Kaspersky Anti-Spam Extension - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\THBExt Chrome: ======= CHR HomePage: hxxp://startsear.ch/?aff=1&cf=7f4d4669-179d-11e1-93e5-00241d7f2969 CHR RestoreOnStartup: "hxxp://startsear.ch/?aff=1&cf=7f4d4669-179d-11e1-93e5-00241d7f2969" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\G\u00F6giPC\AppData\Local\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\G\u00F6giPC\AppData\Local\Google\Chrome\Application\24.0.1312.57\pdf.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\G\u00F6giPC\AppData\Local\Google\Chrome\Application\24.0.1312.57\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\G\u00F6giPC\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll No File CHR Plugin: (vShare.tv plug-in) - C:\Users\G\u00F6giPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll No File CHR Plugin: (vShare.tv plug-in) - C:\Program Files (x86)\Mozilla Firefox\plugins\npvsharetvplg.dll (vShare.tv ) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U22) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Microsoft SharedView Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\npsharedview.dll ( ) CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll No File CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc) CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc) CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\G\u00F6giPC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File CHR Plugin: (TVU Web Player for FireFox) - C:\Windows\system32\TVUAx\npTVUAx.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (AT_JamesWhite) - C:\Users\GGIPC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm\3_0 CHR Extension: (VshareComplete plugin for chrome) - C:\Users\GGIPC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlfienamagdnkekbbbocojppncdambda\1.1_0 CHR Extension: (DivX HiQ) - C:\Users\GGIPC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.1.94_0 CHR Extension: (vshare plugin) - C:\Users\GGIPC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\GGIPC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0 CHR HKLM-x32\...\Chrome\Extension: [dlfienamagdnkekbbbocojppncdambda] - C:\Program Files (x86)\VshareComplete\chrome\VshareCompleteChrome.crx CHR HKLM-x32\...\Chrome\Extension: [fnjbmmemklcjgepojigaapkoodmkgbae] - C:\Program Files (x86)\DivX\DivX Plus Web Player\google_chrome\wpa\wpa.crx CHR HKLM-x32\...\Chrome\Extension: [ihflimipbcaljfnojhhknppphnnciiif] - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoods.crx CHR HKLM-x32\...\Chrome\Extension: [kpionmjnkbpcdpcflammlgllecmejgjj] - C:\Program Files (x86)\StartSearch plugin\vshareplg.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\google_chrome\html5video\html5video.crx CHR StartMenuInternet: Google Chrome - C:\Users\GögiPC\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-10-21] (Advanced Micro Devices, Inc.) S4 AODService; C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe [136544 2009-10-22] () R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe [348760 2010-10-01] (Kaspersky Lab) R2 CLHNServiceForPowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe [91248 2012-12-28] (CyberLink Corp.) R2 CSObjectsSrv; C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [743992 2009-12-21] (Infowatch) R2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [78960 2012-12-28] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [296048 2012-12-28] (CyberLink) S4 ES lite Service; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [68136 2009-02-05] () S4 Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [135584 2012-04-26] (Futuremark Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2010-09-16] () R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-02-28] () S3 NMIndexingService; "C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe" [x] S2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [x] ==================== Drivers (Whitelisted) ==================== S3 AODDriver; C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver.sys [21048 2009-10-22] (Advanced Micro Devices) S3 AODDriver; C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver.sys [21048 2009-10-22] (Advanced Micro Devices) R2 AODDriver4.01; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) S2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) S3 ATITool; C:\Windows\System32\DRIVERS\ATITool64.sys [30720 2006-11-10] () S3 cmuda3; C:\Windows\System32\drivers\cmudax3.sys [1155072 2009-12-01] (C-Media Inc) R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2726400 2011-07-04] (C-Media Inc) R0 CSCrySec; C:\Windows\System32\DRIVERS\CSCrySec.sys [85048 2009-12-14] (Infowatch) R1 CSVirtualDiskDrv; C:\Windows\System32\DRIVERS\CSVirtualDiskDrv.sys [66104 2009-12-14] (Infowatch) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [270912 2011-09-30] (DT Soft Ltd) S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-09-17] (EnTech Taiwan) S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-09-17] (EnTech Taiwan) S3 gdrv; C:\Windows\gdrv.sys [23080 2011-10-13] (Windows (R) Server 2003 DDK provider) S3 gdrv; C:\Windows\gdrv.sys [23080 2011-10-13] (Windows (R) Server 2003 DDK provider) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2009-11-23] () S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2009-11-23] () R3 hcw88rc5; C:\Windows\System32\Drivers\hcw88rc5.sys [15872 2009-08-06] (Hauppauge Computer Works, Inc.) R1 kl1; C:\Windows\System32\DRIVERS\kl1.sys [157712 2009-09-01] (Kaspersky Lab) R0 KLBG; C:\Windows\System32\DRIVERS\klbg.sys [40464 2009-10-14] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [353296 2013-02-11] (Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [27152 2009-09-14] (Kaspersky Lab) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [21008 2009-10-02] (Kaspersky Lab) R3 KovaPlusFltr; C:\Windows\System32\drivers\KovaPlusFltr.sys [15104 2010-01-25] (ROCCAT Development, Inc.) S3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-04-30] () S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-04-30] () R3 MRV6X64U; C:\Windows\System32\DRIVERS\MRVW23C.sys [255232 2007-01-04] (Marvell Semiconductor, Inc) R2 ntk_PowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [83704 2012-09-10] (Cyberlink Corp.) R2 ntk_PowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [83704 2012-09-10] (Cyberlink Corp.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [526392 2011-09-30] () R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [141920 2013-07-26] (Acronis) R2 {73526619-C24F-470B-9BED-53D455FBB5C6}; C:\Program Files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl [130320 2012-12-28] (CyberLink Corp.) R2 {73526619-C24F-470B-9BED-53D455FBB5C6}; C:\Program Files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl [130320 2012-12-28] (CyberLink Corp.) S3 ALSysIO; \??\C:\Users\GGIPC~1\AppData\Local\Temp\ALSysIO64.sys [x] S3 cpuz130; \??\C:\Users\GGIPC~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x] S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [x] S3 GPU-Z; \??\C:\Users\GGIPC~1\AppData\Local\Temp\GPU-Z.sys [x] S3 RivaTuner64; \??\C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-04 19:40 - 2013-08-04 17:53 - 01781485 _____ (Farbar) C:\Users\GögiPC\Desktop\FRST64.exe 2013-08-04 19:28 - 2013-08-04 19:28 - 00003016 _____ C:\Windows\System32\Tasks\MSIAfterburner 2013-08-04 19:27 - 2013-08-04 19:27 - 00000000 ____D C:\FRST 2013-07-29 16:50 - 2013-07-29 16:50 - 00001082 _____ C:\Users\GögiPC\Desktop\PC Remote Server.lnk 2013-07-29 16:50 - 2013-07-29 16:50 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\PC Remote 2013-07-29 16:50 - 2013-07-29 16:50 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Remote 2013-07-29 16:50 - 2013-07-29 16:50 - 00000000 ____D C:\Program Files (x86)\PC Remote 2013-07-29 16:49 - 2013-07-29 16:49 - 01163264 _____ C:\Users\GögiPC\Downloads\PCRemoteSetup.msi 2013-07-27 13:41 - 2013-07-27 13:41 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-07-26 21:32 - 2013-07-26 21:32 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Acronis 2013-07-26 21:31 - 2013-07-26 21:31 - 00000000 ____D C:\ProgramData\Acronis 2013-07-26 21:30 - 2013-07-26 21:30 - 00971360 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2013-07-26 21:30 - 2013-07-26 21:30 - 00001173 _____ C:\Users\Public\Desktop\Acronis True Image WD*Edition.lnk 2013-07-26 21:29 - 2013-07-26 21:29 - 00210016 _____ (Acronis) C:\Windows\system32\Drivers\vididr.sys 2013-07-26 21:28 - 2013-07-26 21:28 - 00275552 _____ (Acronis) C:\Windows\system32\Drivers\snapman.sys 2013-07-26 21:28 - 2013-07-26 21:28 - 00141920 _____ (Acronis) C:\Windows\system32\Drivers\vsflt53.sys 2013-07-26 21:28 - 2013-07-26 21:28 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-07-26 19:21 - 2013-07-26 19:28 - 156004120 _____ C:\Users\GögiPC\Downloads\tih_s_g_14192.exe 2013-07-26 17:13 - 2013-07-26 17:14 - 11232297 _____ C:\Users\GögiPC\Downloads\Stir_i_g2012.(2012).rar.part 2013-07-26 14:37 - 2013-07-26 14:37 - 01273067 _____ C:\Users\GögiPC\Downloads\4002051620318.zip 2013-07-22 19:00 - 2013-07-22 19:06 - 00000000 ____D C:\Windows\system32\MRT 2013-07-11 18:12 - 2013-07-11 18:12 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-07-11 17:38 - 2013-07-11 18:23 - 00000000 ____D C:\Users\GögiPC\Documents\SelfMV 2013-07-11 17:19 - 2013-07-11 17:19 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-07-11 17:17 - 2013-07-11 17:17 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-07-11 17:17 - 2013-07-11 17:17 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Samsung 2013-07-11 17:17 - 2013-07-11 17:17 - 00000000 ____D C:\Users\GGIPC~1\AppData\Local\Samsung 2013-07-11 17:16 - 2013-07-11 17:16 - 00000000 ____D C:\Users\GögiPC\Documents\samsung ==================== One Month Modified Files and Folders ======= 2013-08-04 19:34 - 2009-11-10 22:33 - 00010912 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-04 19:34 - 2009-11-10 22:33 - 00010912 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-04 19:31 - 2010-02-12 21:52 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs 2013-08-04 19:30 - 2013-05-20 18:54 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Spotify 2013-08-04 19:30 - 2010-10-10 12:16 - 02069133 _____ C:\Windows\WindowsUpdate.log 2013-08-04 19:28 - 2013-08-04 19:28 - 00003016 _____ C:\Windows\System32\Tasks\MSIAfterburner 2013-08-04 19:27 - 2013-08-04 19:27 - 00000000 ____D C:\FRST 2013-08-04 19:27 - 2010-02-12 22:11 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-08-04 19:25 - 2013-06-04 14:13 - 00288857 _____ C:\Windows\setupact.log 2013-08-04 19:25 - 2009-11-08 20:07 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-04 19:25 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-04 17:53 - 2013-08-04 19:40 - 01781485 _____ (Farbar) C:\Users\GögiPC\Desktop\FRST64.exe 2013-08-04 14:03 - 2009-11-08 20:07 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-04 14:02 - 2013-05-28 18:23 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-04 13:02 - 2009-09-21 18:27 - 00000000 ____D C:\Users\GGIPC~1\AppData\Local\Adobe 2013-08-03 16:18 - 2011-10-23 15:41 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\vlc 2013-07-29 16:50 - 2013-07-29 16:50 - 00001082 _____ C:\Users\GögiPC\Desktop\PC Remote Server.lnk 2013-07-29 16:50 - 2013-07-29 16:50 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\PC Remote 2013-07-29 16:50 - 2013-07-29 16:50 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Remote 2013-07-29 16:50 - 2013-07-29 16:50 - 00000000 ____D C:\Program Files (x86)\PC Remote 2013-07-29 16:49 - 2013-07-29 16:49 - 01163264 _____ C:\Users\GögiPC\Downloads\PCRemoteSetup.msi 2013-07-27 13:41 - 2013-07-27 13:41 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-07-27 13:40 - 2009-11-08 20:07 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-26 21:32 - 2013-07-26 21:32 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Acronis 2013-07-26 21:31 - 2013-07-26 21:31 - 00000000 ____D C:\ProgramData\Acronis 2013-07-26 21:30 - 2013-07-26 21:30 - 00971360 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2013-07-26 21:30 - 2013-07-26 21:30 - 00001173 _____ C:\Users\Public\Desktop\Acronis True Image WD*Edition.lnk 2013-07-26 21:29 - 2013-07-26 21:29 - 00210016 _____ (Acronis) C:\Windows\system32\Drivers\vididr.sys 2013-07-26 21:28 - 2013-07-26 21:28 - 00275552 _____ (Acronis) C:\Windows\system32\Drivers\snapman.sys 2013-07-26 21:28 - 2013-07-26 21:28 - 00141920 _____ (Acronis) C:\Windows\system32\Drivers\vsflt53.sys 2013-07-26 21:28 - 2013-07-26 21:28 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-07-26 19:28 - 2013-07-26 19:21 - 156004120 _____ C:\Users\GögiPC\Downloads\tih_s_g_14192.exe 2013-07-26 17:14 - 2013-07-26 17:13 - 11232297 _____ C:\Users\GögiPC\Downloads\Stir_i_g2012.(2012).rar.part 2013-07-26 14:37 - 2013-07-26 14:37 - 01273067 _____ C:\Users\GögiPC\Downloads\4002051620318.zip 2013-07-24 21:14 - 2011-01-09 20:34 - 00000000 ____D C:\Users\GögiPC\Desktop\Neuer Ordner 2013-07-22 19:06 - 2013-07-22 19:00 - 00000000 ____D C:\Windows\system32\MRT 2013-07-17 19:17 - 2013-05-20 18:55 - 00000000 ____D C:\Users\GGIPC~1\AppData\Local\Spotify 2013-07-15 19:58 - 2009-11-08 20:07 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-15 19:58 - 2009-11-08 20:07 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-14 11:07 - 2012-06-26 01:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-07-14 11:07 - 2012-05-14 03:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-14 11:07 - 2012-05-14 03:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-11 18:23 - 2013-07-11 17:38 - 00000000 ____D C:\Users\GögiPC\Documents\SelfMV 2013-07-11 18:12 - 2013-07-11 18:12 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-07-11 17:19 - 2013-07-11 17:19 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-07-11 17:17 - 2013-07-11 17:17 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-07-11 17:17 - 2013-07-11 17:17 - 00000000 ____D C:\Users\GögiPC\AppData\Roaming\Samsung 2013-07-11 17:17 - 2013-07-11 17:17 - 00000000 ____D C:\Users\GGIPC~1\AppData\Local\Samsung 2013-07-11 17:16 - 2013-07-11 17:16 - 00000000 ____D C:\Users\GögiPC\Documents\samsung 2013-07-10 19:05 - 2009-09-20 14:36 - 00000000 ____D C:\ProgramData\Microsoft Help ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-03 12:51 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-08-2013 Ran by GögiPC at 2013-08-04 19:41:21 Running from C:\Users\GögiPC\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Update for Microsoft Office 2007 (KB2508958) (x32) Xonar Audio Driver 7-Zip 9.20 (x32) Acronis True Image WD*Edition (x32 Version: 13.0.14189) Adobe AIR (x32 Version: 2.5.1.17730) Adobe Download Assistant (x32 Version: 1.2.5) Adobe Flash Player 10 ActiveX (x32 Version: 10.0.32.18) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Media Player (x32 Version: 1.8) Adobe Photoshop CS6 (x32 Version: 13.0) Adobe Reader XI (11.0.02) - Deutsch (x32 Version: 11.0.02) AMD Accelerated Video Transcoding (Version: 12.5.100.21021) AMD APP SDK Runtime (Version: 10.0.1084.2) AMD AVIVO64 Codecs (Version: 11.7.0.11006) AMD Catalyst Install Manager (Version: 8.0.903.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Fuel (Version: 2012.1021.1547.26491) AMD Media Foundation Decoders (Version: 1.0.71021.1557) AMD OverDrive (x32 Version: 3.1.0.0342) AMD VISION Engine Control Center (x32 Version: 2012.1021.1547.26491) Apple Application Support (x32 Version: 2.3.2) Apple Mobile Device Support (Version: 6.0.1.3) Apple Software Update (x32 Version: 2.1.3.127) aquasuite (x32) Assassin's Creed II (x32 Version: 1.01) Battlefield 3™ (x32 Version: 1.4.0.0) Battlelog Web Plugins (x32 Version: 2.1.4) BD_3D Advisor (x32 Version: 2.0.5913) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1021.1547.26491) Catalyst Control Center InstallProxy (x32 Version: 2012.1021.1547.26491) Catalyst Control Center Localization All (x32 Version: 2012.1021.1547.26491) CCC Help Chinese Standard (x32 Version: 2012.1021.1546.26491) CCC Help Chinese Traditional (x32 Version: 2012.1021.1546.26491) CCC Help Czech (x32 Version: 2012.1021.1546.26491) CCC Help Danish (x32 Version: 2012.1021.1546.26491) CCC Help Dutch (x32 Version: 2012.1021.1546.26491) CCC Help English (x32 Version: 2012.1021.1546.26491) CCC Help Finnish (x32 Version: 2012.1021.1546.26491) CCC Help French (x32 Version: 2012.1021.1546.26491) CCC Help German (x32 Version: 2012.1021.1546.26491) CCC Help Greek (x32 Version: 2012.1021.1546.26491) CCC Help Hungarian (x32 Version: 2012.1021.1546.26491) CCC Help Italian (x32 Version: 2012.1021.1546.26491) CCC Help Japanese (x32 Version: 2012.1021.1546.26491) CCC Help Korean (x32 Version: 2012.1021.1546.26491) CCC Help Norwegian (x32 Version: 2012.1021.1546.26491) CCC Help Polish (x32 Version: 2012.1021.1546.26491) CCC Help Portuguese (x32 Version: 2012.1021.1546.26491) CCC Help Russian (x32 Version: 2012.1021.1546.26491) CCC Help Spanish (x32 Version: 2012.1021.1546.26491) CCC Help Swedish (x32 Version: 2012.1021.1546.26491) CCC Help Thai (x32 Version: 2012.1021.1546.26491) CCC Help Turkish (x32 Version: 2012.1021.1546.26491) ccc-utility64 (Version: 2012.1021.1547.26491) C-Media PCI Audio Device Corel WinDVD 2010 (x32 Version: 10.0.5.713) Crysis® 2 (x32 Version: 1.0.0.0) CyberLink PowerDVD 12 (x32 Version: 12.0.2428.57) DAEMON Tools Lite (x32 Version: 4.41.3.0173) DB Fahrplaninformation 2011 (x32) DivX-Setup (x32 Version: 2.5.0.8) EasySaver B9.0205.1 (x32 Version: 1.00.0000) ESN Sonar (x32 Version: 0.70.0) ESN Sonar (x32 Version: 0.70.4) Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287) FM Screen Capture Codec (Remove Only) (x32) Fraps (remove only) (x32) Futuremark SystemInfo (x32 Version: 4.9.0) GeoGebra (x32 Version: 3.2.0.0) Gigabyte Raid Configurer (x32 Version: 1.00.0000) Google Chrome (HKCU Version: 24.0.1312.57) Google Earth (x32 Version: 7.1.1.1888) Google Update Helper (x32 Version: 1.3.21.153) Grand Theft Auto IV (x32 Version: 1.00.0000) GTA San Andreas (x32 Version: 1.00.00001) Hauppauge WinTV Infrared Remote (x32 Version: 2.65.27300) Hauppauge WinTV Scheduler (x32) Hauppauge WinTV Soft PVR (x32) HD Tune 2.55 (x32) Heaven DX11 Benchmark version 3.0 (Version: 3.0) HTC BMP USB Driver (x32 Version: 1.0.5375) HTC Driver Installer (x32 Version: 3.0.0.005) HTC Sync (x32 Version: 3.0.5511) HydraVision (x32 Version: 4.2.216.0) Internet-TV für Windows Media Center (x32 Version: 4.2.2.0) InterVideo FilterSDK for Hauppauge (x32) IrfanView (remove only) (x32 Version: 4.27) iTunes (Version: 11.0.1.12) Java 7 Update 7 (64-bit) (Version: 7.0.70) Java Auto Updater (x32 Version: 2.0.2.4) Java(TM) 6 Update 22 (x32 Version: 6.0.220) Job Scheduler 1.3.10.1132 (x32 Version: 1.3.10.1132) Kaspersky PURE (x32 Version: 9.1.0.124) LG Tool Kit (x32 Version: 10.01.0712.01) Logitech Webcam Software (Version: 12.00.1280) Logitech Webcam Software-Treiberpaket (Version: 12.0.1278) LuPO 1.0.2.43 (x32) Mafia II (x32 Version: 1.0) Mass Effect 2 (x32 Version: 1.00) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320) Microsoft .NET Framework 4 Extended (Version: 4.0.30320) Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Choice Guard (x32 Version: 2.0.48.0) Microsoft Flight Simulator X (x32 Version: 10.0.61355.0) Microsoft Flight Simulator X Service Pack 1 (x32 Version: 10.0.61355.0) Microsoft Flight Simulator X Service Pack 2 (x32 Version: 10.0.61472.0) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.88.0) Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0) Microsoft SharedView (x32 Version: 8.0.5725.0) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (x32 Version: 9.0.30411) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053) Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000) Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000) Microsoft-Maus- und Tastatur-Center (Version: 1.1.500.0) MKVToolNix 6.2.0 (x32 Version: 6.2.0) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) MSI Afterburner 2.2.1 (x32 Version: 2.2.1) MSI Kombustor 2.3.0 (x32) MSVCRT (x32 Version: 14.0.1468.721) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) MSXML 4.0 SP2 Parser und SDK (x32 Version: 4.20.9818.0) MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0) NAVIGON Fresh 3.3.1 (x32 Version: 3.3.1) Need for Speed™ ProStreet (x32 Version: 1.0.1.0) Need for Speed™ SHIFT (x32 Version: 1.0.0.0) NVIDIA PhysX (x32 Version: 9.10.0513) OpenAL (x32) Opera 11.00 (x32 Version: 11.00.1156) Opera Stable 15.0.1147.130 (x32 Version: 15.0.1147.130) Origin (x32 Version: 8.5.0.4554) oZone3D.Net FurMark v1.7.0 (x32) PC Remote (x32 Version: 3.44) PDF Settings CS6 (x32 Version: 11.0) PlayReady PC Runtime amd64 (Version: 1.3.0) Pro Evolution Soccer 2010 (x32 Version: 1.00.0000) PunkBuster Services (x32 Version: 0.991) QuickTime (x32 Version: 7.69.80.9) Ralink RT2870 Wireless LAN Card (x32 Version: 1.5.5.0) Realtek 8169 8168 8101E 8102E Ethernet Driver (x32 Version: 1.00.0000) Realtek High Definition Audio Driver (x32 Version: 6.0.1.5780) ROCCAT Kova[+] Mouse Driver (x32 Version: 1.10) Rockstar Games Social Club (x32 Version: 1.00.0000) Room EQ Wizard V5 (x32) Samsung Kies (x32 Version: 2.5.2.13021_10) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.18.0) SimCity 4 (x32) SketchUp 8 (x32 Version: 3.0.16846) Skype™ 5.10 (x32 Version: 5.10.116) SopCast 3.3.2 (x32 Version: 3.3.2) Spotify (HKCU Version: 0.9.1.57.ge7405149) The Lord of the Rings FREE Trial (x32 Version: 1.00.0000) TIPP10 Version 2.1.0 (x32) Ubisoft Game Launcher (x32 Version: 1.0.0.0) Uninstall 1.0.0.1 (x32) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) VC80CRTRedist - 8.0.50727.4053 (x32 Version: 1.1.0) Veetle TV 0.9.18 (x32 Version: 0.9.18) VLC media player 2.0.4 (Version: 2.0.4) vShare plugin 1.3 (x32 Version: 1.3) vShare.tv plugin 1.3 (x32 Version: 1.3) VshareComplete (x32) VTPlus32 für WinTV (German) (x32) Win7codecs (x32 Version: 3.1.7) Windows Live Call (x32 Version: 14.0.8117.0416) Windows Live Communications Platform (x32 Version: 14.0.8117.416) Windows Live Essentials (x32 Version: 14.0.8117.0416) Windows Live Essentials (x32 Version: 14.0.8117.416) Windows Live Fotogalerie (x32 Version: 14.0.8117.416) Windows Live ID Sign-in Assistant (Version: 6.500.3165.0) Windows Live Messenger (x32 Version: 14.0.8117.0416) Windows Live Movie Maker (x32 Version: 14.0.8117.0416) Windows Live Sync (x32 Version: 14.0.8117.416) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029) Windows Media Center Add-in for Silverlight (x32 Version: 4.7.3.0) Windows Media Encoder 9 Series (x32 Version: 9.00.2980) Windows Media Encoder 9 Series (x32) Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8) WinRAR ==================== Restore Points ========================= 27-02-2013 18:00:11 Windows Update 08-03-2013 13:48:07 Installiert Suite 08-03-2013 14:53:04 Installiert PowerDVD 08-03-2013 15:07:01 Konfiguriert PowerDVD 08-03-2013 15:09:15 Konfiguriert PowerDVD 08-03-2013 15:13:06 Konfiguriert PowerStarter 08-03-2013 15:20:07 Installed Corel WinDVD 2010. 08-03-2013 16:08:29 Installiert PowerDVD 14-03-2013 18:00:14 Windows Update 23-03-2013 15:52:01 Geplanter Prüfpunkt 23-03-2013 18:00:11 Windows Update 31-03-2013 22:09:36 Entfernt 3DMark 11 08-04-2013 19:09:03 Geplanter Prüfpunkt 10-04-2013 17:00:13 Windows Update 21-04-2013 04:01:32 Geplanter Prüfpunkt 25-04-2013 17:00:11 Windows Update 05-05-2013 14:01:53 Geplanter Prüfpunkt 13-05-2013 19:20:06 Geplanter Prüfpunkt 13-05-2013 21:43:35 Installed SketchUp 8 15-05-2013 17:00:14 Windows Update 24-05-2013 13:35:54 Geplanter Prüfpunkt 31-05-2013 13:46:53 Geplanter Prüfpunkt 09-06-2013 14:09:24 Geplanter Prüfpunkt 12-06-2013 17:00:24 Windows Update 21-06-2013 11:07:01 Geplanter Prüfpunkt 28-06-2013 12:51:58 Geplanter Prüfpunkt 06-07-2013 15:52:17 Geplanter Prüfpunkt 10-07-2013 17:00:13 Windows Update 17-07-2013 20:41:19 Geplanter Prüfpunkt 22-07-2013 17:00:22 Windows Update 26-07-2013 19:27:13 Acronis True Image wird installiert 29-07-2013 14:50:06 Installed PC Remote ==================== Scheduled Tasks (whitelisted) ============= Task: {04FD5BE0-5C2A-4BDB-89E0-5C83F6A868FF} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-08-04] (Microsoft Corporation) Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {137C9A19-C927-4E1C-A60D-18E67A2A9830} - System32\Tasks\WPD\SqmUpload_S-1-5-21-129091277-1404308245-1713919007-1002 => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {18C46911-AE17-4CD5-BDFD-799166206041} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Device Center\itype.exe [2012-06-26] (Microsoft Corporation) Task: {196991BF-68C6-4D10-8DCB-683D03EF9FD8} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-129091277-1404308245-1713919007-1000UA => C:\Users\GögiPC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: {2343AB93-BA06-4B5F-8022-68597A7DF11F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-129091277-1404308245-1713919007-1000Core => C:\Users\GögiPC\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-14] (Google Inc.) Task: {26873A48-77AC-4A85-B1E2-4DE15E67C815} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-11-08] (Google Inc.) Task: {36E4A8B4-19D2-4F28-BC68-7DD7671AE7F6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-11-08] (Google Inc.) Task: {4405F356-6BD5-4F0A-9D2C-3CE2041B76F3} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2012-05-14] () Task: {5A026CB4-5EF6-496D-9094-0260017EAB5E} - System32\Tasks\Microsoft\Windows\Defrag\ManualDefrag => C:\Windows\system32\defrag.exe [2009-07-14] (Microsoft Corp.) Task: {643002D8-9E3B-4161-8809-396C082B8336} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-129091277-1404308245-1713919007-1000Core => C:\Users\GögiPC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: {65E3B4AE-08B0-4A60-ADEE-C15DA46B738C} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Device Center\ipoint.exe [2012-06-26] (Microsoft Corporation) Task: {71216718-E80C-4A94-B812-BB5CB63AEF66} - System32\Tasks\User_Feed_Synchronization-{B6B34A72-81EF-4613-A0DD-4907EF734045} => C:\Windows\system32\msfeedssync.exe [2012-03-16] (Microsoft Corporation) Task: {712C6861-2B14-4E72-92BA-22B6921FE2B7} - System32\Tasks\Microsoft\Windows\Wired\GatherWiredInfo => C:\Windows\system32\gatherWiredInfo.vbs No File Task: {815C2AEA-3DDF-40E2-BD53-5FD68378DDCA} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-129091277-1404308245-1713919007-1000UA => C:\Users\GögiPC\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-14] (Google Inc.) Task: {903E4620-BCF0-4728-9BD1-CBAEC83B78E0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated) Task: {956709D3-4DA4-4295-B982-C8FF2A8ED1C8} - System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe => c:\Program Files\Microsoft Device Center\devicecenter.exe [2012-06-26] (Microsoft) Task: {ADF2C455-C587-4A23-8959-72A28993F302} - System32\Tasks\AdobeAAMUpdater-1.0-GOGI-GögiPC => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated) Task: {C523EF49-92D8-4ECD-8D70-72636363A4C3} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2011-01-07] () Task: {CB7BDB21-C0B6-469A-9FFD-F08062FF907D} - System32\Tasks\{DA8A8CB8-8E38-4434-895A-763FE01A3186} => C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe No File Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs No File Task: {FB79E791-B75F-4236-84C7-572B4E4EBC39} - System32\Tasks\{9CACB411-662F-4BA4-A3D7-79AC25A7FDCE} => C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe No File Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-129091277-1404308245-1713919007-1000Core.job => C:\Users\GögiPC\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-129091277-1404308245-1713919007-1000UA.job => C:\Users\GögiPC\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-129091277-1404308245-1713919007-1000Core.job => C:\Users\GögiPC\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-129091277-1404308245-1713919007-1000UA.job => C:\Users\GögiPC\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= Name: AILT2RX2 IDE Controller Description: AILT2RX2 IDE Controller Class Guid: {4D36E97B-E325-11CE-BFC1-08002BE10318} Manufacturer: (Standard mass storage controllers) Service: afy6405l Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/04/2013 07:41:39 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (08/04/2013 07:41:39 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/04/2013 07:41:39 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/04/2013 07:26:29 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/04/2013 02:20:32 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: wmpnetwk.exe, Version: 12.0.7600.16385, Zeitstempel: 0x4a5bd03d Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7600.17206, Zeitstempel: 0x50e669a2 Ausnahmecode: 0x0000046b Fehleroffset: 0x000000000000ac3d ID des fehlerhaften Prozesses: 0x82c Startzeit der fehlerhaften Anwendung: 0xwmpnetwk.exe0 Pfad der fehlerhaften Anwendung: wmpnetwk.exe1 Pfad des fehlerhaften Moduls: wmpnetwk.exe2 Berichtskennung: wmpnetwk.exe3 Error: (08/02/2013 07:27:29 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/29/2013 04:50:54 PM) (Source: .NET Runtime) (User: ) Description: Application: PCRemote.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.NullReferenceException Stack: at PCRemote.HotspotHandler.OnNotification(WLAN_NOTIFICATION_DATA ByRef, IntPtr) Error: (07/14/2013 11:08:47 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/13/2013 04:55:12 PM) (Source: Application Hang) (User: ) Description: Programm Explorer.EXE, Version 6.1.7600.16768 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: ce8 Startzeit: 01ce74aed01c4b3a Endzeit: 708 Anwendungspfad: C:\Windows\Explorer.EXE Berichts-ID: 35b77e0a-ebcc-11e2-b5c1-00241d7f2969 Error: (06/29/2013 11:53:43 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (08/04/2013 07:36:54 PM) (Source: Microsoft-Windows-DNS-Client) (User: NT-AUTORITÄT) Description: Fehler beim Lesen der Datei für lokale Hosts. Error: (08/04/2013 07:34:22 PM) (Source: Microsoft-Windows-DNS-Client) (User: NT-AUTORITÄT) Description: Fehler beim Lesen der Datei für lokale Hosts. Error: (08/04/2013 07:30:43 PM) (Source: Microsoft-Windows-DNS-Client) (User: NT-AUTORITÄT) Description: Fehler beim Lesen der Datei für lokale Hosts. Error: (08/04/2013 07:25:23 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "StarWind AE Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (08/04/2013 07:25:18 PM) (Source: Microsoft-Windows-DNS-Client) (User: NT-AUTORITÄT) Description: Fehler beim Lesen der Datei für lokale Hosts. Error: (08/04/2013 07:25:15 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (08/04/2013 02:33:10 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: AFD CSVirtualDiskDrv DfsC discache kl1 KLIF KLIM6 NetBIOS NetBT nsiproxy Psched rdbss spldr sptd tdx Wanarpv6 WfpLwf Error: (08/04/2013 02:33:10 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NLA (Network Location Awareness)" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/04/2013 02:33:10 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerkverbindungen" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/04/2013 02:33:10 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SMB 2.0-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 29% Total physical RAM: 8190.49 MB Available physical RAM: 5753.98 MB Total Pagefile: 12299.82 MB Available Pagefile: 10003.62 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:596.17 GB) (Free:8.99 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)] Drive f: () (Removable) (Total:0.96 GB) (Free:0.96 GB) FAT (Disk=1 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: F7A89292) Partition 1: (Active) - (Size=596 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 983 MB) (Disk ID: 00000000) Partition 1: (Active) - (Size=983 MB) - (Type=0E) ==================== End Of Log ============================ |
04.08.2013, 19:19 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Netzwerk geht bei dir nicht? Bitte ein Log mit FSS machen: Downloade dir bitte Farbar Service Scanner
Poste bitte den Inhalt hier.
__________________ Logfiles bitte immer in CODE-Tags posten |
04.08.2013, 19:41 | #9 |
| BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Wie gesagt, es geht schon ,nur nicht über mein Netzwerk. Benutzte gerade die Internetfreigabe vom Handy aus und da geht das ja. Also der PC um den es hier geht ist über mein Handy ans mobile Internet angebunden. Ist mit den .txt Files aus dem vorpost von mir alles in Ordnung ? Code:
ATTFilter Farbar Service Scanner Version: 26-07-2013 Ran by GögiPC (administrator) on 04-08-2013 at 20:39:12 Running from "C:\Users\GögiPC\Desktop" Microsoft Windows 7 Home Premium (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ SDRSVC Service is not running. Checking service configuration: The start type of SDRSVC service is OK. The ImagePath of SDRSVC service is OK. The ServiceDll of SDRSVC service is OK. VSS Service is not running. Checking service configuration: The start type of VSS service is OK. The ImagePath of VSS service is OK. System Restore Disabled Policy: ======================== Action Center: ============ wscsvc Service is not running. Checking service configuration: Checking Start type: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist. Checking ImagePath: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist. Checking ServiceDll: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist. Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: Checking Start type: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist. Checking ImagePath: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist. Checking ServiceDll: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist. Windows Defender Disabled Policy: ========================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=DWORD:1 RpcSs Service is not running. Checking service configuration: The start type of RpcSs service is OK. The ImagePath of RpcSs service is OK. Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys [2013-02-13 19:58] - [2013-01-04 07:41] - 1893224 ____A (Microsoft Corporation) 5CFB7AB8F9524D1A1E14369DE63B83CC C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** |
04.08.2013, 22:02 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Bitte ein Log mit CF machen: Scan mit Combofix
__________________ Logfiles bitte immer in CODE-Tags posten |
04.08.2013, 22:24 | #11 |
| BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Also ich habe den PC und Router 1h vom Netz getrennt und wieder angemacht,ich bin wieder drin über Wlan. Soll ich trotzdem Combofix drüber laufen lassen ? |
04.08.2013, 22:33 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Ja mach bitte
__________________ Logfiles bitte immer in CODE-Tags posten |
05.08.2013, 02:27 | #13 |
| BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? So hab das dann auch hinter mir. Combofix hat gemekert,dass Kaspersky noch am laufen wäre, aber ich habe das Programm beendet und extra noch im Task Manager nach dem avp.exe Prozess gesucht, um sicher zu gehen. Da war nix. Code:
ATTFilter ComboFix 13-08-04.01 - GögiPC 05.08.2013 3:02.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.49.1031.18.8190.5402 [GMT 2:00] ausgeführt von:: c:\users\G÷giPC\Desktop\ComboFix.exe AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} AV: Kaspersky PURE *Enabled/Outdated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} FW: Kaspersky PURE *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D} SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: Kaspersky PURE *Enabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\StartSearch plugin c:\program files (x86)\StartSearch plugin\IEhelperActiveX.dll c:\program files (x86)\StartSearch plugin\uninst.exe c:\program files (x86)\StartSearch plugin\vShareBar.dll c:\program files (x86)\StartSearch plugin\vshareplg.crx c:\programdata\4195E04981.sys c:\windows\SysWow64\frapsvid.dll . . ((((((((((((((((((((((( Dateien erstellt von 2013-07-05 bis 2013-08-05 )))))))))))))))))))))))))))))) . . 2013-08-05 01:13 . 2013-08-05 01:13 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-08-04 17:27 . 2013-08-04 17:27 -------- d-----w- C:\FRST 2013-07-29 14:50 . 2013-07-29 14:50 -------- d-----w- c:\users\GögiPC\AppData\Roaming\PC Remote 2013-07-29 14:50 . 2013-07-29 14:50 -------- d-----w- c:\program files (x86)\PC Remote 2013-07-26 19:32 . 2013-07-26 19:32 -------- d-----w- c:\users\GögiPC\AppData\Roaming\Acronis 2013-07-26 19:30 . 2013-07-26 19:30 971360 ----a-w- c:\windows\system32\drivers\timntr.sys 2013-07-26 19:29 . 2013-07-26 19:29 210016 ----a-w- c:\windows\system32\drivers\vididr.sys 2013-07-26 19:28 . 2013-07-26 19:28 141920 ----a-w- c:\windows\system32\drivers\vsflt53.sys 2013-07-26 19:28 . 2013-07-26 19:28 275552 ----a-w- c:\windows\system32\drivers\snapman.sys 2013-07-26 19:28 . 2013-07-26 19:28 -------- d-----w- c:\program files (x86)\Common Files\Acronis 2013-07-26 19:28 . 2013-07-26 19:28 -------- d-----w- c:\program files (x86)\Acronis 2013-07-22 17:00 . 2013-07-22 17:06 -------- d-----w- c:\windows\system32\MRT 2013-07-11 15:17 . 2013-07-11 15:17 -------- d-----w- c:\users\GögiPC\AppData\Local\Samsung 2013-07-11 15:17 . 2013-07-11 15:17 -------- d-----w- c:\users\GögiPC\AppData\Roaming\Samsung . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-23 22:57 . 2012-03-23 19:30 78277128 ----a-w- c:\windows\system32\MRT.exe 2013-06-12 17:02 . 2012-05-17 10:21 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-06-12 17:02 . 2011-07-05 19:02 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-04 07:15 . 2013-06-04 07:15 708168 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll 2013-06-04 07:15 . 2013-06-04 07:15 103448 ----a-w- c:\windows\system32\drivers\ssudbus.sys 2013-06-04 07:15 . 2013-06-04 07:15 203672 ----a-w- c:\windows\system32\drivers\ssudmdm.sys 2013-06-04 07:15 . 2013-06-04 07:15 1490656 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll 2013-06-03 17:59 . 2011-12-30 01:22 291088 ----a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-06-03 17:59 . 2010-06-13 19:35 291088 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr 2013-06-03 17:54 . 2011-12-30 01:22 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0 2013-05-20 10:09 . 2010-07-02 12:25 8456 --sha-w- c:\programdata\KGyGaAvL.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\KAVOverlayIcon] @="{dd230880-495a-11d1-b064-008048ec2fc5}" [HKEY_CLASSES_ROOT\CLSID\{dd230880-495a-11d1-b064-008048ec2fc5}] 2010-10-01 21:05 129624 ----a-w- c:\program files (x86)\Kaspersky Lab\Kaspersky PURE\shellex.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 163328] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] "KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2013-02-13 1509232] "Spotify Web Helper"="c:\users\GögiPC\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-07-08 1104384] "Spotify"="c:\users\GögiPC\AppData\Roaming\Spotify\spotify.exe" [2013-07-08 4640768] "PC Remote Server"="c:\program files (x86)\PC Remote\PC Remote\PCRemote.exe" [2013-07-26 1070744] "HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2011-10-06 393216] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-10-21 642216] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe" [2010-10-01 348760] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2013-02-13 310128] "LGODDFU"="c:\program files (x86)\lg_fwupdate\lgfw.exe" [2013-03-08 27760] "PowerDVD12DMREngine"="c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe" [2012-12-28 506480] "PowerDVD12Agent"="c:\program files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe" [2012-12-28 375168] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352] "TrueImageMonitor.exe"="c:\program files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" [2012-05-10 2673640] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ AutoStart IR.lnk - c:\program files (x86)\WinTV\Ir.exe /QUIET [2013-2-12 117344] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~2\mzvkbd3.dll c:\progra~2\KASPER~1\KASPER~2\sbhook.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux4"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x] R3 ALSysIO;ALSysIO;c:\users\GGIPC~1\AppData\Local\Temp\ALSysIO64.sys;c:\users\GGIPC~1\AppData\Local\Temp\ALSysIO64.sys [x] R3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x] R3 AODDriver;AODDriver;c:\program files (x86)\AMD\OverDrive\amd64\AODDriver.sys;c:\program files (x86)\AMD\OverDrive\amd64\AODDriver.sys [x] R3 BrSerIb;Brother MFC Serial Interface Driver(WDM);c:\windows\system32\DRIVERS\BrSerIb.sys;c:\windows\SYSNATIVE\DRIVERS\BrSerIb.sys [x] R3 BrUsbSIb;Brother MFC Serial USB Driver(WDM);c:\windows\system32\DRIVERS\BrUsbSIb.sys;c:\windows\SYSNATIVE\DRIVERS\BrUsbSIb.sys [x] R3 cpuz130;cpuz130;c:\users\GGIPC~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys;c:\users\GGIPC~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x] R3 cpuz135;cpuz135;c:\windows\TEMP\cpuz135\cpuz135_x64.sys;c:\windows\TEMP\cpuz135\cpuz135_x64.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 ENTECH64;ENTECH64;c:\windows\system32\DRIVERS\ENTECH64.sys;c:\windows\SYSNATIVE\DRIVERS\ENTECH64.sys [x] R3 GPU-Z;GPU-Z;c:\users\GGIPC~1\AppData\Local\Temp\GPU-Z.sys;c:\users\GGIPC~1\AppData\Local\Temp\GPU-Z.sys [x] R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x] R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x] R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x] R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x] R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys;c:\windows\SYSNATIVE\DRIVERS\LVPr2M64.sys [x] R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 vcd10bus;Virtual CD v10 Bus Enumerator;c:\windows\system32\DRIVERS\vcd10bus.sys;c:\windows\SYSNATIVE\DRIVERS\vcd10bus.sys [x] R4 AODService;AODService;c:\program files (x86)\AMD\OverDrive\AODAssist.exe;c:\program files (x86)\AMD\OverDrive\AODAssist.exe [x] R4 ES lite Service;ES lite Service for program management.;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE [x] R4 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [x] R4 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [x] R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] S0 CSCrySec;InfoWatch Encrypt Sector Library driver;c:\windows\system32\DRIVERS\CSCrySec.sys;c:\windows\SYSNATIVE\DRIVERS\CSCrySec.sys [x] S0 KLBG;Kaspersky Lab Boot Guard Driver;c:\windows\system32\DRIVERS\klbg.sys;c:\windows\SYSNATIVE\DRIVERS\klbg.sys [x] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S0 vididr;Acronis Virtual Disk;c:\windows\system32\DRIVERS\vididr.sys;c:\windows\SYSNATIVE\DRIVERS\vididr.sys [x] S0 vidsflt53;Acronis Disk Storage Filter (53);c:\windows\system32\DRIVERS\vsflt53.sys;c:\windows\SYSNATIVE\DRIVERS\vsflt53.sys [x] S1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;c:\windows\system32\DRIVERS\CSVirtualDiskDrv.sys;c:\windows\SYSNATIVE\DRIVERS\CSVirtualDiskDrv.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;c:\windows\system32\drivers\hcw88aud.sys;c:\windows\SYSNATIVE\drivers\hcw88aud.sys [x] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x] S2 {73526619-C24F-470B-9BED-53D455FBB5C6};Power Control [2013/03/08 17:13];c:\program files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl;c:\program files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x] S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x] S2 CLHNServiceForPowerDVD12;CLHNServiceForPowerDVD12;c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe;c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe [x] S2 CSObjectsSrv;Verwaltungsservice vom CryproStorage-System;c:\program files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe;c:\program files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [x] S2 CyberLink PowerDVD 12 Media Server Monitor Service;CyberLink PowerDVD 12 Media Server Monitor Service;c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe;c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [x] S2 CyberLink PowerDVD 12 Media Server Service;CyberLink PowerDVD 12 Media Server Service;c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe;c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [x] S2 ntk_PowerDVD12;ntk_PowerDVD12;c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys;c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [x] S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x] S2 regi;regi;c:\windows\system32\drivers\regi.sys;c:\windows\SYSNATIVE\drivers\regi.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 cmudaxp;ASUS Xonar DX Audio Interface;c:\windows\system32\drivers\cmudaxp.sys;c:\windows\SYSNATIVE\drivers\cmudaxp.sys [x] S3 hcw88bda;Hauppauge WinTV 88x DVB Tuner/Demod;c:\windows\system32\drivers\hcw88bda.sys;c:\windows\SYSNATIVE\drivers\hcw88bda.sys [x] S3 hcw88rc5;Hauppauge WinTV 88x IR Decoder;c:\windows\system32\Drivers\hcw88rc5.sys;c:\windows\SYSNATIVE\Drivers\hcw88rc5.sys [x] S3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;c:\windows\system32\drivers\hcw88tse.sys;c:\windows\SYSNATIVE\drivers\hcw88tse.sys [x] S3 hcw88vid;Hauppauge WinTV 88x Video;c:\windows\system32\drivers\hcw88vid.sys;c:\windows\SYSNATIVE\drivers\hcw88vid.sys [x] S3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;c:\windows\system32\drivers\HCW88BAR.sys;c:\windows\SYSNATIVE\drivers\HCW88BAR.sys [x] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x] S3 KovaPlusFltr;ROCCAT Kova[+] Mouse;c:\windows\system32\drivers\KovaPlusFltr.sys;c:\windows\SYSNATIVE\drivers\KovaPlusFltr.sys [x] S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x] S3 LVUVC64;Logitech Webcam 500(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x] S3 MRV6X64U;Vista 64-bits Native WiFi Driver - USB;c:\windows\system32\DRIVERS\MRVW23C.sys;c:\windows\SYSNATIVE\DRIVERS\MRVW23C.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *Deregistered* - RTCore64 . Inhalt des "geplante Tasks" Ordners . 2013-08-05 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-17 17:02] . 2013-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-11-08 18:07] . 2013-08-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-11-08 18:07] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{08337871-0e50-4031-9110-3bd21ca3c065}] 2011-11-09 01:54 167416 ----a-w- c:\users\GögiPC\AppData\Roaming\VshareComplete\64\VshareComplete64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\KAVOverlayIcon] @="{dd230880-495a-11d1-b064-008048ec2fc5}" [HKEY_CLASSES_ROOT\CLSID\{dd230880-495a-11d1-b064-008048ec2fc5}] 2010-10-01 21:06 170584 ----a-w- c:\program files (x86)\Kaspersky Lab\Kaspersky PURE\x64\ShellEx.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CmPCIaudio"="c:\windows\Syswow64\CMICNFG3.dll" [2009-10-30 8151040] "Cmaudio8788"="c:\windows\Syswow64\cmicnfgp.dll" [2011-05-12 8790016] "Cmaudio8788GX"="c:\windows\syswow64\HsMgr.exe" [2008-07-11 200704] "Cmaudio8788GX64"="c:\windows\system\HsMgr64.exe" [2008-07-11 282112] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392] "Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2012-05-10 395928] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~2\x64\kloehk.dll c:\progra~2\KASPER~1\KASPER~2\x64\sbhook64.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mStart Page = hxxp://www.google.com mSearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 192.168.2.1 TCP: Interfaces\{C265E40D-21BB-4BD1-B14E-3583AE64DFB4}\75C414E4D2030313144364932493137333: NameServer = 4.2.2.1,4.2.2.2 FF - ProfilePath - c:\users\GögiPC\AppData\Roaming\Mozilla\Firefox\Profiles\lcpbiddt.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - www.google.de FF - prefs.js: keyword.URL - hxxp://startsear.ch/?aff=1&src=sp&cf=7f4d4669-179d-11e1-93e5-00241d7f2969&q= FF - ExtSQL: !HIDDEN! 2009-11-10 21:38; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension . - - - - Entfernte verwaiste Registrierungseinträge - - - - . BHO-{64182481-4F71-486b-A045-B233BD0DA8FC} - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll Toolbar-{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll Wow6432Node-HKCU-Run-AdobeBridge - (no file) Wow6432Node-HKCU-Run-KiesAirMessage - c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe AddRemove-Hauppauge WinTV Scheduler - c:\progra~2\WinTV\\SCHEDU~1\uniSCHED.exe AddRemove-Hauppauge WinTV Soft PVR - c:\progra~2\WinTV\UNSftPVR.EXE AddRemove-Uninstall_is1 - c:\program files (x86)\Common Files\DVDVideoSoft\unins000.exe AddRemove-vShare plugin - c:\program files (x86)\StartSearch plugin\uninst.exe AddRemove-{43B74FAB-FB58-447D-8D3A-5F638AF36FD1} - c:\programdata\{D8116CA6-DBDF-4415-AB4A-BE0CEFB71935}\Netzmanager1.050.1606_101110a.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{73526619-C24F-470B-9BED-53D455FBB5C6}] "ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-129091277-1404308245-1713919007-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:e0,ab,c7,48,46,6f,c9,bc,90,8a,db,79,67,8e,8f,d1,dc,73,38,af,32,61,22, ad,2c,ce,8b,73,26,dc,5b,1a,8a,9a,ea,90,b8,92,bd,38,4d,32,b8,a0,26,1b,d9,e5,\ "??"=hex:f0,e7,8b,b9,d1,cf,6f,75,a6,7a,35,10,4b,60,41,ed . [HKEY_USERS\S-1-5-21-129091277-1404308245-1713919007-1000\Software\SecuROM\License information*] "datasecu"=hex:8e,05,77,fd,6a,48,86,4d,b8,1a,f5,76,ce,41,7f,3d,a0,2e,e7,82,3e, c2,7b,15,07,5b,7f,e7,ec,d2,21,18,75,07,ba,ee,a2,cb,25,23,f9,98,9c,8b,7c,9c,\ "rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-08-05 03:23:30 ComboFix-quarantined-files.txt 2013-08-05 01:23 . Vor Suchlauf: 19 Verzeichnis(se), 34.387.603.456 Bytes frei Nach Suchlauf: 27 Verzeichnis(se), 35.197.243.392 Bytes frei . - - End Of File - - 58AB20B11678F46C21989A4A5738B472 A36C5E4F47E84449FF07ED3517B43A31 |
05.08.2013, 09:46 | #14 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ?Zitat:
Deinstalliere AntiVir oder Kaspersky
__________________ Logfiles bitte immer in CODE-Tags posten |
05.08.2013, 10:31 | #15 |
| BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? Antivir ist deinstalliert. Bei den Programmen in der Systemsteuerung ist das nicht mehr aufgelistet. |
Themen zu BSI Maleware mit Aufforderung zum Bezahlen - wie bereinigen ? |
anmeldefenster, aufforderung, aufrufen, beste, besten, direkt, erklären, geld, hoffe, kaspersky, leute, maleware, maleware gefunden, modus, natürlich, plötzlich, rechte, rechten, sicherheit, sperrt, strg, surfe, surfen, taskmanager, verbreitet, win, win7 |