|
Plagegeister aller Art und deren Bekämpfung: Schäden nach qvo6.Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
18.09.2013, 14:08 | #1 |
| Schäden nach qvo6. Halo! es tut mir Leid ,dass ich meine Problem nicht so genau definieren kann. Zur Zeit lauft alles gut. Aber vor kurzem hatte ich Probleme verschieden Seiten zu öffnen (meistens youtube Vdeos). alles fing mit runterladen von RevoUninstaler an. Damit kam Delta Search und qvo6 Searchengines in Spiel. ich habe diesen mit Adwcleaner entfernt. Habe auch Einträge in Regedit entfernt. habe sogar Chrome neu installiert. Wie gesagt, einige Zeit lauft alles super. Bis es in eine Moment Störungen wie "die seite kann nicht gefunden werden" oder "keine DSL verbindung" auftauchen. Obwohl die Verbindung OK ist und die seiten doch existieren : z.B. wollte youtube startsite öffnen und kam Meldung, dass solche Seite gar nix existiert! Ich habe mit Avast die System überprüft und es wurden keine Viren gefunden. Kann mir jemand helfen zu überprüfen ob ich doch ein Virus in meine Browser habe? Bitte um Verzeihung wegen meine schlechtes Deutsch. Es ist nämlich nicht meine Muttersprache da ist es schon wieder! das erscheint nach versuch eine Siete zu öffnen: "[B]Das Sicherheitszertifikat der Website ist nicht vertrauenswürdig! Sie haben versucht, auf chrome.google.com zuzugreifen, der Server hat sich jedoch mit einem Zertifikat ausgewiesen, das von einem Aussteller herausgegeben wurde, dem das Betriebssystem des Computers nicht vertraut. Dies bedeutet möglicherweise, dass der Server seine eigenen Sicherheitsinformationen erzeugt hat, auf die Chrome als Identitätsangabe nicht vertrauen kann, oder dass ein Hacker versucht, Ihre Kommunikation abzufangen. Sie können nicht fortfahren, da der Betreiber der Website die Sicherheitsvorkehrungen für diese Domain erhöht hat. Zurück zu sicherer Website Mehr Infos dazu[/B]" |
18.09.2013, 14:14 | #2 |
/// TB-Ausbilder | Schäden nach qvo6.Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Ich habe dein Thema in Arbeit und melde mich so schnell wie möglich mit weiteren Anweisungen. |
18.09.2013, 14:14 | #3 |
/// TB-Ausbilder | Schäden nach qvo6. Servus,
__________________wir beginnen so: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
18.09.2013, 14:42 | #4 |
| The farbar- RESULTS ! Hi ! danke für deine Rückmeldung! Hier sind die Resultaten: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-09-2013 03 Ran by user (administrator) on USER-PC on 18-09-2013 15:24:39 Running from C:\Users\user\Downloads Windows 7 Ultimate (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe () C:\Program Files (x86)\Verbindungsassistent\WTGService.exe (Spotify Ltd) C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Dropbox, Inc.) C:\Users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe () C:\Windows\system32\LFXGDIPO.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [Spotify Web Helper] - C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1105408 2013-05-25] (Spotify Ltd) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20686704 2013-07-25] (Skype Technologies S.A.) MountPoints2: {a893806c-c54e-11e2-94e4-0024816156d4} - G:\AutoRun.exe MountPoints2: {a8938070-c54e-11e2-94e4-0024816156d4} - G:\AutoRun.exe HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software) Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xEFC804AE6E59CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Extension: (Google Docs) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Learn Portuguese - Tudo Bem) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\iaichpenkdlohcjgagagapnegbjmfnfh\1.46_0 CHR Extension: (German Flashcards) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijecamokjmiajijbajfnlbkfknpplkdf\1.0.1_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\WTGService.exe [296400 2009-03-03] () ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software) S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] () S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-18 15:24 - 2013-09-18 15:24 - 00000000 ____D C:\FRST 2013-09-18 15:22 - 2013-09-18 15:23 - 01950524 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe 2013-09-18 14:22 - 2013-09-18 14:22 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-09-18 14:22 - 2013-09-18 14:22 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-09-18 14:22 - 2013-09-18 14:22 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-09-18 14:22 - 2013-08-30 09:48 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-09-18 14:22 - 2013-08-30 09:47 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-09-18 14:22 - 2013-08-30 09:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-09-18 14:21 - 2013-09-18 14:21 - 00000000 ____D C:\Program Files\AVAST Software 2013-09-18 14:20 - 2013-09-18 14:21 - 00000000 ____D C:\ProgramData\AVAST Software 2013-09-18 13:48 - 2013-09-18 14:19 - 131918888 _____ C:\Users\user\Downloads\avast_free_antivirus_setup_8.0.1497.376.exe 2013-09-18 13:03 - 2013-09-18 13:03 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-18 13:02 - 2013-09-18 15:07 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-18 13:02 - 2013-09-18 13:07 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-18 13:02 - 2013-09-18 13:02 - 00004102 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-09-18 13:02 - 2013-09-18 13:02 - 00003850 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-09-18 13:01 - 2013-09-18 13:02 - 00000000 ____D C:\Users\user\AppData\Local\Deployment 2013-09-18 13:01 - 2013-09-18 13:01 - 00000000 ____D C:\Users\user\AppData\Local\Apps\2.0 2013-09-18 12:12 - 2013-09-18 12:27 - 00000000 ____D C:\AdwCleaner 2013-09-18 12:11 - 2013-09-18 12:12 - 01039554 _____ C:\Users\user\Downloads\adwcleaner004.exe 2013-09-18 10:30 - 2013-09-18 10:30 - 00262144 ____N C:\Windows\Minidump\091813-30061-01.dmp 2013-09-17 10:46 - 2013-09-17 10:46 - 00001264 _____ C:\Users\user\Desktop\Revo Uninstaller.lnk 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Users\user\AppData\Local\avgchrome 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-09-17 10:45 - 2013-09-17 10:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\user\Desktop\revosetup.exe 2013-09-17 10:44 - 2013-09-17 10:44 - 00392336 _____ (Softonic ) C:\Users\user\Downloads\SoftonicDownloader_for_revo-uninstaller.exe 2013-09-14 15:12 - 2013-09-18 10:18 - 00000087 _____ C:\Users\user\AppData\Roaming\WB.CFG 2013-09-14 15:12 - 2013-09-18 10:18 - 00000005 _____ C:\Users\user\AppData\Roaming\WBPU-TTL.DAT 2013-09-14 14:41 - 2013-09-14 14:41 - 00870600 _____ C:\Users\user\Downloads\FLVPlayerSetup.exe 2013-09-14 14:41 - 2013-09-14 14:41 - 00001021 _____ C:\Users\user\Desktop\FLV Player.lnk 2013-09-14 14:41 - 2013-09-14 14:41 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player 2013-09-14 14:41 - 2013-09-14 14:41 - 00000000 ____D C:\Program Files (x86)\FLVPlayer 2013-09-14 14:20 - 2013-09-14 14:20 - 00003174 _____ C:\Windows\System32\Tasks\{3D5AA52C-E5B5-4354-9FF7-E6FCBD1E1B38} 2013-09-14 14:12 - 2013-09-18 14:12 - 00001908 _____ C:\Windows\Tasks\LyriXeeker-1-chromeinstaller.job 2013-09-14 14:12 - 2013-09-18 14:12 - 00001294 _____ C:\Windows\Tasks\LyriXeeker-1-updater.job 2013-09-14 14:12 - 2013-09-18 14:12 - 00001198 _____ C:\Windows\Tasks\LyriXeeker-1-codedownloader.job 2013-09-14 14:12 - 2013-09-18 14:12 - 00001098 _____ C:\Windows\Tasks\LyriXeeker-1-enabler.job 2013-09-14 14:12 - 2013-09-14 14:12 - 00004324 _____ C:\Windows\System32\Tasks\LyriXeeker-1-updater 2013-09-14 14:12 - 2013-09-14 14:12 - 00004228 _____ C:\Windows\System32\Tasks\LyriXeeker-1-codedownloader 2013-09-14 14:12 - 2013-09-14 14:12 - 00004128 _____ C:\Windows\System32\Tasks\LyriXeeker-1-enabler 2013-09-14 14:12 - 2013-09-14 14:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-14 12:19 - 2013-09-14 12:20 - 00000000 ____D C:\Users\user\Desktop\miniSDcardA 2013-09-14 12:01 - 2013-09-14 12:01 - 00273960 _____ C:\Windows\Minidump\091413-39624-01.dmp 2013-09-14 11:56 - 2013-09-14 11:56 - 00262144 ____H C:\Windows\DUMP343f.DMP 2013-09-14 11:51 - 2013-09-14 11:51 - 00262144 ____N C:\Windows\Minidump\091413-47018-01.dmp 2013-09-14 11:45 - 2013-09-14 11:45 - 00262144 ____N C:\Windows\Minidump\091413-22167-01.dmp 2013-09-14 00:41 - 2011-04-09 08:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2013-09-14 00:41 - 2011-04-09 07:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2013-09-14 00:24 - 2011-11-19 17:07 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2013-09-14 00:24 - 2011-11-19 16:06 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2013-09-13 07:16 - 2012-06-03 00:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-09-13 07:16 - 2012-06-03 00:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-09-13 07:16 - 2012-06-03 00:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-09-13 07:16 - 2012-06-03 00:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-09-13 07:16 - 2012-06-03 00:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-09-13 07:16 - 2012-06-03 00:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-09-13 07:16 - 2012-06-03 00:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-09-13 07:15 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-09-13 07:15 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-09-12 21:35 - 2013-09-12 21:35 - 00368101 _____ C:\Users\user\Documents\testdruck.xps 2013-09-12 21:34 - 2013-09-12 21:34 - 00368098 _____ C:\Users\user\Documents\drucktest.xps 2013-09-12 21:32 - 2013-09-12 21:32 - 00368106 _____ C:\Users\user\Documents\cv_druck1.xps 2013-09-12 21:30 - 2013-09-12 21:30 - 00368087 _____ C:\Users\user\Documents\cv_duck.xps 2013-09-12 15:01 - 2013-09-12 15:01 - 06074368 _____ C:\Users\user\Downloads\B2500_tcm3-41664.exe 2013-09-12 15:01 - 2013-09-12 15:01 - 00000000 ____D C:\okidriver 2013-09-11 10:19 - 2013-09-11 10:19 - 00262144 ____N C:\Windows\Minidump\091113-21824-01.dmp 2013-09-08 22:26 - 2013-09-08 22:26 - 01068336 _____ (Solid State Networks) C:\Users\user\Downloads\install_reader11_de_mssd_aaa_aih.exe 2013-09-08 22:25 - 2013-09-08 22:25 - 00099792 _____ C:\Users\user\Downloads\downloaden-kostenlos_fur_adobeacrobat.exe 2013-09-08 22:19 - 2013-09-13 00:13 - 00000000 ____D C:\Users\user\Desktop\document 2013-09-03 10:46 - 2013-09-03 10:46 - 00262144 ____N C:\Windows\Minidump\090313-26457-01.dmp 2013-09-01 18:20 - 2013-09-01 18:20 - 00001007 _____ C:\Users\user\Desktop\Audacity.lnk 2013-09-01 18:20 - 2013-09-01 18:20 - 00000000 ____D C:\Program Files (x86)\Audacity 2013-09-01 18:05 - 2013-09-01 18:05 - 21281052 _____ (Audacity Team ) C:\Users\user\Downloads\audacity-win-2.0.3.exe 2013-09-01 17:52 - 2013-09-01 17:52 - 00254256 _____ C:\Users\user\Downloads\flashaudioplayer (1).zip 2013-09-01 17:39 - 2013-09-01 17:46 - 00000000 ____D C:\Users\user\AppData\Roaming\hdbADS 2013-09-01 13:35 - 2013-09-01 13:35 - 00254256 _____ C:\Users\user\Downloads\flashaudioplayer.zip 2013-09-01 13:10 - 2013-09-14 00:18 - 00000000 ____D C:\Program Files (x86)\phase5 2013-09-01 13:10 - 2013-09-01 13:10 - 00000921 _____ C:\Users\user\Desktop\HTML Editor.lnk 2013-09-01 13:10 - 2013-09-01 13:10 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Phase 5 HTML-Editor 2013-09-01 13:07 - 2013-09-01 13:07 - 03746496 _____ (Systemberatung Schommer) C:\Users\user\Downloads\phase5623install.exe 2013-08-29 21:24 - 2013-08-29 21:24 - 00001901 _____ C:\Users\user\Desktop\FileZilla.lnk 2013-08-29 21:24 - 2013-08-29 21:24 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla 2013-08-29 21:24 - 2013-08-29 21:24 - 00000000 ____D C:\Program Files (x86)\FileZilla 2013-08-29 21:23 - 2013-08-29 21:24 - 03458079 _____ C:\Users\user\Downloads\FileZilla_2_2_32_setup.exe 2013-08-28 14:16 - 2013-08-28 14:16 - 01209168 _____ C:\Windows\Minidump\082813-19297-01.dmp 2013-08-22 23:36 - 2013-09-17 13:14 - 00000000 ____D C:\Users\user\Desktop\root 2013-08-22 23:26 - 2013-08-22 23:26 - 32966136 _____ (Dropbox, Inc.) C:\Users\user\Downloads\Dropbox 2.0.26 (1).exe 2013-08-22 11:11 - 2013-09-18 13:00 - 00000000 ___RD C:\Users\user\Dropbox 2013-08-22 11:11 - 2013-08-22 23:27 - 00001013 _____ C:\Users\user\Desktop\Dropbox.lnk 2013-08-22 11:08 - 2013-08-22 23:27 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-22 09:52 - 2013-09-18 15:17 - 00000000 ____D C:\Users\user\AppData\Roaming\Dropbox 2013-08-22 09:50 - 2013-08-22 09:50 - 32966136 _____ (Dropbox, Inc.) C:\Users\user\Downloads\Dropbox 2.0.26.exe 2013-08-20 11:04 - 2013-08-20 11:04 - 00000000 ____D C:\Users\user\AppData\Roaming\OpenOffice 2013-08-20 11:03 - 2013-08-20 11:03 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk 2013-08-20 11:03 - 2013-08-20 11:03 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-08-20 10:58 - 2013-08-20 10:58 - 00000000 ____D C:\Users\user\Desktop\OpenOffice 4.0.0 (de) Installation Files 2013-08-20 10:55 - 2013-08-20 10:57 - 162401424 _____ C:\Users\user\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de.exe ==================== One Month Modified Files and Folders ======= 2013-09-18 15:24 - 2013-09-18 15:24 - 00000000 ____D C:\FRST 2013-09-18 15:23 - 2013-09-18 15:22 - 01950524 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe 2013-09-18 15:23 - 2011-10-09 19:34 - 01303426 _____ C:\Windows\WindowsUpdate.log 2013-09-18 15:17 - 2013-08-22 09:52 - 00000000 ____D C:\Users\user\AppData\Roaming\Dropbox 2013-09-18 15:17 - 2013-05-25 21:05 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-18 15:07 - 2013-09-18 13:02 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-18 15:00 - 2009-07-14 06:45 - 00009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-18 15:00 - 2009-07-14 06:45 - 00009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-18 14:22 - 2013-09-18 14:22 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-09-18 14:22 - 2013-09-18 14:22 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-09-18 14:22 - 2013-09-18 14:22 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-09-18 14:21 - 2013-09-18 14:21 - 00000000 ____D C:\Program Files\AVAST Software 2013-09-18 14:21 - 2013-09-18 14:20 - 00000000 ____D C:\ProgramData\AVAST Software 2013-09-18 14:19 - 2013-09-18 13:48 - 131918888 _____ C:\Users\user\Downloads\avast_free_antivirus_setup_8.0.1497.376.exe 2013-09-18 14:12 - 2013-09-14 14:12 - 00001908 _____ C:\Windows\Tasks\LyriXeeker-1-chromeinstaller.job 2013-09-18 14:12 - 2013-09-14 14:12 - 00001294 _____ C:\Windows\Tasks\LyriXeeker-1-updater.job 2013-09-18 14:12 - 2013-09-14 14:12 - 00001198 _____ C:\Windows\Tasks\LyriXeeker-1-codedownloader.job 2013-09-18 14:12 - 2013-09-14 14:12 - 00001098 _____ C:\Windows\Tasks\LyriXeeker-1-enabler.job 2013-09-18 13:07 - 2013-09-18 13:02 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-18 13:03 - 2013-09-18 13:03 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-18 13:03 - 2013-05-25 21:05 - 00000000 ____D C:\Users\user\AppData\Local\Google 2013-09-18 13:03 - 2013-05-25 21:05 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-18 13:02 - 2013-09-18 13:02 - 00004102 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-09-18 13:02 - 2013-09-18 13:02 - 00003850 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-09-18 13:02 - 2013-09-18 13:01 - 00000000 ____D C:\Users\user\AppData\Local\Deployment 2013-09-18 13:01 - 2013-09-18 13:01 - 00000000 ____D C:\Users\user\AppData\Local\Apps\2.0 2013-09-18 13:00 - 2013-08-22 11:11 - 00000000 ___RD C:\Users\user\Dropbox 2013-09-18 13:00 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-18 13:00 - 2009-07-14 06:51 - 00031068 _____ C:\Windows\setupact.log 2013-09-18 12:54 - 2011-10-10 14:15 - 00001439 _____ C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-18 12:27 - 2013-09-18 12:12 - 00000000 ____D C:\AdwCleaner 2013-09-18 12:20 - 2013-08-03 16:13 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype 2013-09-18 12:19 - 2013-05-26 11:10 - 00005512 _____ C:\Windows\PFRO.log 2013-09-18 12:18 - 2011-10-10 14:16 - 00000847 _____ C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-09-18 12:12 - 2013-09-18 12:11 - 01039554 _____ C:\Users\user\Downloads\adwcleaner004.exe 2013-09-18 10:30 - 2013-09-18 10:30 - 00262144 ____N C:\Windows\Minidump\091813-30061-01.dmp 2013-09-18 10:30 - 2013-05-26 21:12 - 00000000 ____D C:\Windows\Minidump 2013-09-18 10:18 - 2013-09-14 15:12 - 00000087 _____ C:\Users\user\AppData\Roaming\WB.CFG 2013-09-18 10:18 - 2013-09-14 15:12 - 00000005 _____ C:\Users\user\AppData\Roaming\WBPU-TTL.DAT 2013-09-17 13:30 - 2013-07-31 08:36 - 00000000 ____D C:\Users\user\AppData\Roaming\Audacity 2013-09-17 13:14 - 2013-08-22 23:36 - 00000000 ____D C:\Users\user\Desktop\root 2013-09-17 13:08 - 2013-06-20 21:47 - 00000000 ____D C:\Users\user\Desktop\mirFOTOS 2013-09-17 11:13 - 2009-06-21 14:44 - 00000000 ____D C:\programme 2013-09-17 11:06 - 2013-05-25 17:58 - 00000000 ____D C:\Users\user\AppData\Roaming\Adobe 2013-09-17 11:05 - 2013-05-25 17:58 - 00000000 ____D C:\ProgramData\Adobe 2013-09-17 11:05 - 2013-05-25 17:57 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-09-17 11:04 - 2013-05-25 17:59 - 00000000 ____D C:\Users\user\AppData\Local\Adobe 2013-09-17 11:04 - 2013-05-25 17:57 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-09-17 10:46 - 2013-09-17 10:46 - 00001264 _____ C:\Users\user\Desktop\Revo Uninstaller.lnk 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Users\user\AppData\Local\avgchrome 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-09-17 10:45 - 2013-09-17 10:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\user\Desktop\revosetup.exe 2013-09-17 10:44 - 2013-09-17 10:44 - 00392336 _____ (Softonic ) C:\Users\user\Downloads\SoftonicDownloader_for_revo-uninstaller.exe 2013-09-14 14:41 - 2013-09-14 14:41 - 00870600 _____ C:\Users\user\Downloads\FLVPlayerSetup.exe 2013-09-14 14:41 - 2013-09-14 14:41 - 00001021 _____ C:\Users\user\Desktop\FLV Player.lnk 2013-09-14 14:41 - 2013-09-14 14:41 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player 2013-09-14 14:41 - 2013-09-14 14:41 - 00000000 ____D C:\Program Files (x86)\FLVPlayer 2013-09-14 14:20 - 2013-09-14 14:20 - 00003174 _____ C:\Windows\System32\Tasks\{3D5AA52C-E5B5-4354-9FF7-E6FCBD1E1B38} 2013-09-14 14:12 - 2013-09-14 14:12 - 00004324 _____ C:\Windows\System32\Tasks\LyriXeeker-1-updater 2013-09-14 14:12 - 2013-09-14 14:12 - 00004228 _____ C:\Windows\System32\Tasks\LyriXeeker-1-codedownloader 2013-09-14 14:12 - 2013-09-14 14:12 - 00004128 _____ C:\Windows\System32\Tasks\LyriXeeker-1-enabler 2013-09-14 14:12 - 2013-09-14 14:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-14 12:20 - 2013-09-14 12:19 - 00000000 ____D C:\Users\user\Desktop\miniSDcardA 2013-09-14 12:01 - 2013-09-14 12:01 - 00273960 _____ C:\Windows\Minidump\091413-39624-01.dmp 2013-09-14 11:56 - 2013-09-14 11:56 - 00262144 ____H C:\Windows\DUMP343f.DMP 2013-09-14 11:51 - 2013-09-14 11:51 - 00262144 ____N C:\Windows\Minidump\091413-47018-01.dmp 2013-09-14 11:45 - 2013-09-14 11:45 - 00262144 ____N C:\Windows\Minidump\091413-22167-01.dmp 2013-09-14 00:18 - 2013-09-01 13:10 - 00000000 ____D C:\Program Files (x86)\phase5 2013-09-14 00:17 - 2013-05-25 21:05 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-14 00:17 - 2013-05-25 21:05 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-14 00:17 - 2013-05-25 21:05 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-13 00:13 - 2013-09-08 22:19 - 00000000 ____D C:\Users\user\Desktop\document 2013-09-12 21:35 - 2013-09-12 21:35 - 00368101 _____ C:\Users\user\Documents\testdruck.xps 2013-09-12 21:34 - 2013-09-12 21:34 - 00368098 _____ C:\Users\user\Documents\drucktest.xps 2013-09-12 21:32 - 2013-09-12 21:32 - 00368106 _____ C:\Users\user\Documents\cv_druck1.xps 2013-09-12 21:30 - 2013-09-12 21:30 - 00368087 _____ C:\Users\user\Documents\cv_duck.xps 2013-09-12 15:01 - 2013-09-12 15:01 - 06074368 _____ C:\Users\user\Downloads\B2500_tcm3-41664.exe 2013-09-12 15:01 - 2013-09-12 15:01 - 00000000 ____D C:\okidriver 2013-09-11 22:28 - 2013-05-29 21:38 - 00000000 ____D C:\Users\user\Desktop\moi text 2013-09-11 10:19 - 2013-09-11 10:19 - 00262144 ____N C:\Windows\Minidump\091113-21824-01.dmp 2013-09-09 20:30 - 2011-09-09 06:58 - 00643866 _____ C:\Windows\system32\perfh007.dat 2013-09-09 20:30 - 2011-09-09 06:58 - 00126394 _____ C:\Windows\system32\perfc007.dat 2013-09-09 20:30 - 2009-07-14 07:13 - 01472002 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-09 07:11 - 2009-07-14 06:45 - 02900304 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-08 22:44 - 2011-10-10 14:26 - 00063568 _____ C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-08 22:26 - 2013-09-08 22:26 - 01068336 _____ (Solid State Networks) C:\Users\user\Downloads\install_reader11_de_mssd_aaa_aih.exe 2013-09-08 22:25 - 2013-09-08 22:25 - 00099792 _____ C:\Users\user\Downloads\downloaden-kostenlos_fur_adobeacrobat.exe 2013-09-03 10:46 - 2013-09-03 10:46 - 00262144 ____N C:\Windows\Minidump\090313-26457-01.dmp 2013-09-01 18:20 - 2013-09-01 18:20 - 00001007 _____ C:\Users\user\Desktop\Audacity.lnk 2013-09-01 18:20 - 2013-09-01 18:20 - 00000000 ____D C:\Program Files (x86)\Audacity 2013-09-01 18:05 - 2013-09-01 18:05 - 21281052 _____ (Audacity Team ) C:\Users\user\Downloads\audacity-win-2.0.3.exe 2013-09-01 17:52 - 2013-09-01 17:52 - 00254256 _____ C:\Users\user\Downloads\flashaudioplayer (1).zip 2013-09-01 17:46 - 2013-09-01 17:39 - 00000000 ____D C:\Users\user\AppData\Roaming\hdbADS 2013-09-01 13:35 - 2013-09-01 13:35 - 00254256 _____ C:\Users\user\Downloads\flashaudioplayer.zip 2013-09-01 13:10 - 2013-09-01 13:10 - 00000921 _____ C:\Users\user\Desktop\HTML Editor.lnk 2013-09-01 13:10 - 2013-09-01 13:10 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Phase 5 HTML-Editor 2013-09-01 13:07 - 2013-09-01 13:07 - 03746496 _____ (Systemberatung Schommer) C:\Users\user\Downloads\phase5623install.exe 2013-08-30 09:48 - 2013-09-18 14:22 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-08-30 09:47 - 2013-09-18 14:22 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-08-30 09:47 - 2013-09-18 14:22 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-08-29 22:07 - 2011-10-10 14:15 - 00000000 ____D C:\Users\user\AppData\Local\VirtualStore 2013-08-29 21:24 - 2013-08-29 21:24 - 00001901 _____ C:\Users\user\Desktop\FileZilla.lnk 2013-08-29 21:24 - 2013-08-29 21:24 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla 2013-08-29 21:24 - 2013-08-29 21:24 - 00000000 ____D C:\Program Files (x86)\FileZilla 2013-08-29 21:24 - 2013-08-29 21:23 - 03458079 _____ C:\Users\user\Downloads\FileZilla_2_2_32_setup.exe 2013-08-28 14:16 - 2013-08-28 14:16 - 01209168 _____ C:\Windows\Minidump\082813-19297-01.dmp 2013-08-28 07:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-08-27 13:52 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-08-22 23:27 - 2013-08-22 11:11 - 00001013 _____ C:\Users\user\Desktop\Dropbox.lnk 2013-08-22 23:27 - 2013-08-22 11:08 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-22 23:27 - 2011-10-10 14:15 - 00000000 ___RD C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-08-22 23:26 - 2013-08-22 23:26 - 32966136 _____ (Dropbox, Inc.) C:\Users\user\Downloads\Dropbox 2.0.26 (1).exe 2013-08-22 09:50 - 2013-08-22 09:50 - 32966136 _____ (Dropbox, Inc.) C:\Users\user\Downloads\Dropbox 2.0.26.exe 2013-08-20 11:04 - 2013-08-20 11:04 - 00000000 ____D C:\Users\user\AppData\Roaming\OpenOffice 2013-08-20 11:03 - 2013-08-20 11:03 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk 2013-08-20 11:03 - 2013-08-20 11:03 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-08-20 10:59 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-08-20 10:58 - 2013-08-20 10:58 - 00000000 ____D C:\Users\user\Desktop\OpenOffice 4.0.0 (de) Installation Files 2013-08-20 10:57 - 2013-08-20 10:55 - 162401424 _____ C:\Users\user\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de.exe Some content of TEMP: ==================== C:\Users\user\AppData\Local\Temp\DataCard_Setup64.exe C:\Users\user\AppData\Local\Temp\MyDelta_sftnc.exe C:\Users\user\AppData\Local\Temp\Quarantine.exe C:\Users\user\AppData\Local\Temp\ResetDevice.exe C:\Users\user\AppData\Local\Temp\uninst1.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-11 11:09 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- als zweites kam das: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-09-2013 03 Ran by user at 2013-09-18 15:27:04 Running from C:\Users\user\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe AIR (x32 Version: 1.1.0.5790) Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.174) Adobe Media Player (x32 Version: 0.0.0) Adobe Media Player (x32 Version: 1.1) Audacity 2.0.3 (x32 Version: 2.0.3) avast! Free Antivirus (x32 Version: 8.0.1497.0) Dropbox (HKCU Version: 2.0.26) FileZilla (remove only) (x32) FLV Player (HKCU) Google Chrome (x32 Version: 29.0.1547.66) Google Update Helper (x32 Version: 1.3.21.153) Lock On: Modern Air Combat (x32 Version: 1.00.000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) OpenOffice 4.0.0 (x32 Version: 4.00.9702) Phase 5 HTML-Editor (x32 Version: 5.6.2.3) Revo Uninstaller 1.95 (x32 Version: 1.95) Skype™ 6.7 (x32 Version: 6.7.102) Spotify (HKCU Version: 0.9.0.133.gd18ed589) Update for Zip Opener (HKCU) Verbindungsassistent (x32 Version: 2.1) ==================== Restore Points ========================= 18-09-2013 12:21:27 avast! Free Antivirus Setup ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started Task: {2F02D5F6-E04C-4A84-90DD-F014C488F3CE} - \DSite No Task File Task: {37BC52F0-53B3-4C56-9667-8E01A9891AD3} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {63D01A4D-34FC-45C4-845E-09E4A72484C6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-18] (Google Inc.) Task: {653FD421-BFEC-41B7-A342-9D0C767012D3} - System32\Tasks\LyriXeeker-1-enabler => C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-enabler.exe Task: {6AC7AF7A-F9DA-4A76-B106-50FDB2B34511} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2009-07-14] (Microsoft Corporation) Task: {A80D4D5B-3651-4F82-966A-DC5C6822D9DE} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software) Task: {C8F76A3C-7AE9-4EC0-98BA-90E44C603844} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {CA70101D-0DC4-4A6C-BEBC-7D0EEC26A9C3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-14] (Adobe Systems Incorporated) Task: {CFC4D041-7569-46FC-B044-DA3D5225E11E} - System32\Tasks\LyriXeeker-1-updater => C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-updater.exe Task: {E2498BAC-FAAD-4507-89EF-B5904A57CBA2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-18] (Google Inc.) Task: {E71FF651-F99D-49DF-8E6A-E6DDBB1B537E} - System32\Tasks\LyriXeeker-1-chromeinstaller => C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-chromeinstaller.exe Task: {F045BC1D-0EC7-4B0E-B7C7-6C265A6A8638} - System32\Tasks\LyriXeeker-1-codedownloader => C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-codedownloader.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\LyriXeeker-1-chromeinstaller.job => C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-chromeinstaller.exe Task: C:\Windows\Tasks\LyriXeeker-1-codedownloader.job => C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-codedownloader.exe Task: C:\Windows\Tasks\LyriXeeker-1-enabler.job => C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-enabler.exe Task: C:\Windows\Tasks\LyriXeeker-1-updater.job => C:\Program Files (x86)\LyriXeeker-1\LyriXeeker-1-updater.exe ==================== Loaded Modules (whitelisted) ============= 2013-06-05 19:17 - 2013-06-05 19:17 - 00164016 _____ (Dropbox, Inc.) C:\Users\user\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll 2013-07-25 09:40 - 2013-07-25 09:40 - 00088944 ____R (Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.dll 2013-06-05 19:17 - 2013-06-05 19:17 - 00130736 _____ (Dropbox, Inc.) C:\Users\user\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll 2012-11-14 01:32 - 2012-11-14 01:32 - 03558400 _____ (wxWidgets development team) C:\Users\user\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll 2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\user\AppData\Roaming\Dropbox\bin\libcef.dll 2013-03-13 22:48 - 2013-03-13 22:48 - 09956864 _____ (The ICU Project) C:\Users\user\AppData\Roaming\Dropbox\bin\icudt.dll 2009-07-14 02:18 - 2009-07-14 03:38 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\imaadp32.acm 2009-07-14 02:18 - 2009-07-14 03:38 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\msg711.acm 2009-07-14 02:18 - 2009-07-14 03:38 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\msgsm32.acm 2009-07-14 02:18 - 2009-07-14 03:38 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\msadp32.acm 2009-07-14 02:07 - 2009-07-14 03:14 - 00064000 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\SysWOW64\l3codeca.acm 2013-09-18 13:03 - 2013-09-02 22:35 - 00709584 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\libglesv2.dll 2013-09-18 13:03 - 2013-09-02 22:35 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\libegl.dll 2013-09-18 13:03 - 2013-09-02 22:35 - 04053456 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\pdf.dll 2013-09-18 13:03 - 2013-09-02 22:35 - 00410576 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll 2013-09-18 13:03 - 2013-09-02 22:35 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========== AlternateDataStreams: C:\Users\user\Downloads\Calle 13 [La Bala] del Album Entren los que Quieran.lite.mp3:TOC.WMV ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (09/18/2013 03:23:44 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest. Error: (09/17/2013 01:29:24 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FLVPlayer.exe, Version: 1.0.0.1, Zeitstempel: 0x2a425e19 Name des fehlerhaften Moduls: FLVPlayer.exe, Version: 1.0.0.1, Zeitstempel: 0x2a425e19 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00003f26 ID des fehlerhaften Prozesses: 0xe00 Startzeit der fehlerhaften Anwendung: 0xFLVPlayer.exe0 Pfad der fehlerhaften Anwendung: FLVPlayer.exe1 Pfad des fehlerhaften Moduls: FLVPlayer.exe2 Berichtskennung: FLVPlayer.exe3 Error: (09/17/2013 10:44:38 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest. Error: (09/17/2013 10:44:35 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest. Error: (09/12/2013 11:21:22 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (09/09/2013 09:02:33 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (09/01/2013 08:26:08 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (09/01/2013 05:45:39 PM) (Source: EventSystem) (User: ) Description: 80070005EventSystem.EventSubscription{EE0259CE-07A7-4B0D-889C-4402CDA80751}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}SLSVC_LOGON Error: (08/27/2013 02:14:53 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (08/25/2013 11:34:54 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 8.0.7600.16385, Zeitstempel: 0x4a5bc69e Name des fehlerhaften Moduls: mshtml.dll, Version: 8.0.7600.16385, Zeitstempel: 0x4a5bda8a Ausnahmecode: 0xc0000005 Fehleroffset: 0x0022ad5a ID des fehlerhaften Prozesses: 0xafc Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0 Pfad der fehlerhaften Anwendung: iexplore.exe1 Pfad des fehlerhaften Moduls: iexplore.exe2 Berichtskennung: iexplore.exe3 System errors: ============= Error: (09/18/2013 02:18:19 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (09/18/2013 01:00:05 PM) (Source: Microsoft-Windows-WHEA-Logger) (User: NT-AUTORITÄT) Description: Schwerwiegender Hardwarefehler. Gemeldet von Komponente: Prozessorkern Fehlerquelle: 3 Fehlertyp: 256 Prozessor-ID: 1 Die Detailansicht dieses Eintrags beinhaltet weitere Informationen. Error: (09/18/2013 00:59:47 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (09/18/2013 00:59:47 PM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (09/18/2013 00:28:49 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (09/18/2013 00:28:49 PM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (09/18/2013 00:20:43 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{A93958B0-968A-4992-9689-E6D9E4D2500A}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (09/18/2013 00:19:36 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (09/18/2013 00:19:36 PM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (09/18/2013 10:33:13 AM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Microsoft Office Sessions: ========================= Error: (09/18/2013 03:23:44 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifestC:\Users\user\Downloads\SoftonicDownloader_for_revo-uninstaller.exe Error: (09/17/2013 01:29:24 PM) (Source: Application Error)(User: ) Description: FLVPlayer.exe1.0.0.12a425e19FLVPlayer.exe1.0.0.12a425e19c000000500003f26e0001ceb39928081f0bC:\Program Files (x86)\FLVPlayer\FLVPlayer.exeC:\Program Files (x86)\FLVPlayer\FLVPlayer.exe66d5e33c-1f8c-11e3-918f-00247e51b583 Error: (09/17/2013 10:44:38 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifestC:\Users\user\Downloads\SoftonicDownloader_for_revo-uninstaller.exe Error: (09/17/2013 10:44:35 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifestC:\Users\user\Downloads\SoftonicDownloader_for_revo-uninstaller.exe Error: (09/12/2013 11:21:22 PM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (09/09/2013 09:02:33 PM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (09/01/2013 08:26:08 PM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (09/01/2013 05:45:39 PM) (Source: EventSystem)(User: ) Description: 80070005EventSystem.EventSubscription{EE0259CE-07A7-4B0D-889C-4402CDA80751}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}SLSVC_LOGON Error: (08/27/2013 02:14:53 PM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (08/25/2013 11:34:54 PM) (Source: Application Error)(User: ) Description: iexplore.exe8.0.7600.163854a5bc69emshtml.dll8.0.7600.163854a5bda8ac00000050022ad5aafc01cea1d9d75cdca6C:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Windows\SysWOW64\mshtml.dll2e08a482-0dce-11e3-a8bb-00247e51b583 ==================== Memory info =========================== Percentage of memory in use: 42% Total physical RAM: 3836.87 MB Available physical RAM: 2216.65 MB Total Pagefile: 7671.88 MB Available Pagefile: 5952.2 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:48.83 GB) (Free:1.97 GB) NTFS Drive d: () (Fixed) (Total:48.83 GB) (Free:1.57 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: () (Fixed) (Total:37.56 GB) (Free:0.54 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 71723968) Partition 1: (Active) - (Size=49 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=49 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=38 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=98 GB) - (Type=05) ==================== End Of Log ============================ nochmal DANKE !!!! gracias P.S. Noch was über die VIRUS BEHAVIOR: ...wenn ich eine seite zu öffnen versuche wird ein "S" nach der "http" hinzugefügt!!!! siecht so aus: "https://" und dann kommt redirect zum: hxxp://192.168.2.1/redir.stm?u=jwP0 |
18.09.2013, 15:21 | #5 |
/// TB-Ausbilder | Schäden nach qvo6. Servus, so geht es los: Scan mit Combofix
|
18.09.2013, 18:22 | #6 |
| Combo Fix Log so. Log wurde ohne Probleme erstellt :-) ComboFix Log: Code:
ATTFilter ComboFix 13-09-17.01 - user 18.09.2013 16:39:57.1.2 - x64 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.49.1031.18.3837.2048 [GMT 2:00] ausgeführt von:: c:\users\user\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Setup.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-08-18 bis 2013-09-18 )))))))))))))))))))))))))))))) . . 2013-09-18 14:52 . 2013-09-18 14:52 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-09-18 13:24 . 2013-09-18 13:24 -------- d-----w- C:\FRST 2013-09-18 12:22 . 2013-08-30 07:48 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-09-18 12:22 . 2013-08-30 07:48 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys 2013-09-18 12:22 . 2013-08-30 07:48 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-09-18 12:22 . 2013-08-30 07:48 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2013-09-18 12:22 . 2013-08-30 07:48 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2013-09-18 12:22 . 2013-08-30 07:48 204880 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-09-18 12:22 . 2013-08-30 07:48 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-09-18 12:22 . 2013-08-30 07:48 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-09-18 12:22 . 2013-08-30 07:47 287840 ----a-w- c:\windows\system32\aswBoot.exe 2013-09-18 12:22 . 2013-08-30 07:47 41664 ----a-w- c:\windows\avastSS.scr 2013-09-18 12:21 . 2013-09-18 12:21 -------- d-----w- c:\program files\AVAST Software 2013-09-18 12:20 . 2013-09-18 12:21 -------- d-----w- c:\programdata\AVAST Software 2013-09-18 11:01 . 2013-09-18 11:01 -------- d-----w- c:\users\user\AppData\Local\Apps 2013-09-18 11:01 . 2013-09-18 11:02 -------- d-----w- c:\users\user\AppData\Local\Deployment 2013-09-18 10:12 . 2013-09-18 10:27 -------- d-----w- C:\AdwCleaner 2013-09-17 08:46 . 2013-09-17 08:46 -------- d-----w- c:\users\user\AppData\Local\avgchrome 2013-09-17 08:46 . 2013-09-17 08:46 -------- d-----w- c:\windows\SysWow64\searchplugins 2013-09-17 08:46 . 2013-09-17 08:46 -------- d-----w- c:\windows\SysWow64\Extensions 2013-09-17 08:46 . 2013-09-17 08:46 -------- d-----w- c:\program files (x86)\VS Revo Group 2013-09-14 12:41 . 2013-09-14 12:41 -------- d-----w- c:\program files (x86)\FLVPlayer 2013-09-13 22:41 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe 2013-09-13 22:41 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe 2013-09-13 22:24 . 2011-11-19 15:07 77312 ----a-w- c:\windows\system32\packager.dll 2013-09-13 22:24 . 2011-11-19 14:06 67072 ----a-w- c:\windows\SysWow64\packager.dll 2013-09-13 05:16 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll 2013-09-13 05:16 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe 2013-09-13 05:16 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll 2013-09-13 05:16 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll 2013-09-13 05:16 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll 2013-09-13 05:16 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll 2013-09-13 05:16 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll 2013-09-13 05:15 . 2012-06-02 13:19 186752 ----a-w- c:\windows\system32\wuwebv.dll 2013-09-13 05:15 . 2012-06-02 13:15 36864 ----a-w- c:\windows\system32\wuapp.exe 2013-09-12 13:01 . 2013-09-12 13:01 -------- d-----w- C:\okidriver 2013-09-01 16:20 . 2013-09-01 16:20 -------- d-----w- c:\program files (x86)\Audacity 2013-09-01 16:20 . 2013-09-01 16:20 -------- d-----w- c:\users\user\AppData\Local\Programs 2013-09-01 15:39 . 2013-09-01 15:46 -------- d-----w- c:\users\user\AppData\Roaming\hdbADS 2013-09-01 11:10 . 2013-09-13 22:18 -------- d-----w- c:\program files (x86)\phase5 2013-08-29 19:24 . 2013-08-29 19:24 -------- d-----w- c:\program files (x86)\FileZilla 2013-08-28 05:12 . 2013-08-28 05:12 -------- d-----w- c:\users\user\AppData\Local\Diagnostics 2013-08-22 09:11 . 2013-09-18 11:00 -------- d-----r- c:\users\user\Dropbox 2013-08-22 07:52 . 2013-09-18 14:32 -------- d-----w- c:\users\user\AppData\Roaming\Dropbox 2013-08-20 09:04 . 2013-08-20 09:04 -------- d-----w- c:\users\user\AppData\Roaming\OpenOffice 2013-08-20 09:03 . 2013-08-20 09:03 -------- d-----w- c:\program files (x86)\OpenOffice 4 . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-09-13 22:17 . 2013-05-25 19:05 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-09-13 22:17 . 2013-05-25 19:05 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-08-03 06:06 . 2013-08-03 06:06 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2013-08-03 06:05 . 2013-08-03 06:05 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2013-08-03 06:05 . 2013-08-03 06:05 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 130736 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 130736 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 130736 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Spotify Web Helper"="c:\users\user\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-05-25 1105408] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-07-25 20686704] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968] . c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-6-5 27370808] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R0 aswRvrt;aswRvrt; [x] R1 aswSnx;aswSnx; [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] S0 aswVmm;aswVmm; [x] S1 aswSP;aswSP; [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x] S2 WTGService;WTGService;c:\program files (x86)\Verbindungsassistent\WTGService.exe;c:\program files (x86)\Verbindungsassistent\WTGService.exe [x] S3 yukonw7;NDIS6.2-Miniporttreiber für Marvell Yukon-Ethernet-Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - ASWFSBLK *NewlyCreated* - ASWMONFLT *NewlyCreated* - ASWRDR *NewlyCreated* - ASWSP *NewlyCreated* - ASWTDI *NewlyCreated* - ASWVMM . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-09-18 11:03 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.66\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-09-18 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-25 22:17] . 2013-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-18 11:02] . 2013-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-18 11:02] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-08-30 07:47 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 164016 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 164016 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 164016 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 164016 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mDefault_Page_URL = hxxp://www.google.com mStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.2.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-AdobeBridge - (no file) AddRemove-DSite - c:\users\user\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_174_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_174_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_174_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_174_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_174.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_174.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_174.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_174.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-09-18 16:57:19 ComboFix-quarantined-files.txt 2013-09-18 14:57 . Vor Suchlauf: 2.145.558.528 Bytes frei Nach Suchlauf: 2.597.396.480 Bytes frei . - - End Of File - - 604DFFBAD006F38C171342021DE25A88 A36C5E4F47E84449FF07ED3517B43A31 |
18.09.2013, 18:43 | #7 |
/// TB-Ausbilder | Schäden nach qvo6. Servus, ok, gut. So geht es weiter: Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Downloade Dir bitte Malwarebytes Anti-Malware
Bitte poste mit deiner nächsten Antwort
|
18.09.2013, 20:09 | #8 |
| Adware,JRT,Malwarebytes hier die ADWcleaner ergebnisse: Code:
ATTFilter # AdwCleaner v3.004 - Bericht erstellt am 18/09/2013 um 19:59:59 # Updated 15/09/2013 von Xplode # Betriebssystem : Windows 7 Ultimate (64 bits) # Benutzername : user - USER-PC # Gestartet von : C:\Users\user\Downloads\adwcleaner004.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} ***** [ Browser ] ***** -\\ Internet Explorer v8.0.7600.16385 -\\ Google Chrome v29.0.1547.66 [ Datei : C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [10068 octets] - [18/09/2013 12:12:41] AdwCleaner[R1].txt - [893 octets] - [18/09/2013 12:26:12] AdwCleaner[R2].txt - [1130 octets] - [18/09/2013 19:59:02] AdwCleaner[S0].txt - [6836 octets] - [18/09/2013 12:18:11] AdwCleaner[S1].txt - [953 octets] - [18/09/2013 12:27:12] AdwCleaner[S2].txt - [1052 octets] - [18/09/2013 19:59:59] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1112 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.1 (09.15.2013:1) OS: Windows 7 Ultimate x64 Ran by user on 18.09.2013 at 20:10:26,69 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\bProtectTabs ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1988867521-2379809488-694433238-1000\Software\SweetIM Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220422182256} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550455185556} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660466186656} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440444184456} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220422182256} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550455185556} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660466186656} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440444184456} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550455185556} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660466186656} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440444184456} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550455185556} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660466186656} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440444184456} ~~~ Files ~~~ Folders I- Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.09.18.10 Windows 7 x64 NTFS Internet Explorer 8.0.7600.16385 user :: USER-PC [Administrator] Schutz: Aktiviert 18.09.2013 20:51:58 mbam-log-2013-09-18 (20-51-58).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 195170 Laufzeit: 3 Minute(n), 3 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 3 C:\Users\user\Downloads\downloaden-kostenlos_fur_adobeacrobat.exe (Hoax.SMS) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\user\Downloads\FLVPlayerSetup.exe (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\user\Downloads\SoftonicDownloader_for_revo-uninstaller.exe (PUP.Optional.Softonic) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) II- Code:
ATTFilter 2013/09/18 20:05:25 +0200 USER-PC user MESSAGE Starting protection 2013/09/18 20:05:25 +0200 USER-PC user MESSAGE Protection started successfully 2013/09/18 20:05:25 +0200 USER-PC user MESSAGE Starting IP protection 2013/09/18 20:06:18 +0200 USER-PC user MESSAGE IP Protection started successfully 2013/09/18 20:07:44 +0200 USER-PC user MESSAGE Starting database refresh 2013/09/18 20:07:44 +0200 USER-PC user MESSAGE Stopping IP protection 2013/09/18 20:07:51 +0200 USER-PC user MESSAGE Executing scheduled update: Daily 2013/09/18 20:07:54 +0200 USER-PC user MESSAGE IP Protection stopped successfully 2013/09/18 20:07:56 +0200 USER-PC user MESSAGE Database already up-to-date 2013/09/18 20:08:00 +0200 USER-PC user MESSAGE Database refreshed successfully 2013/09/18 20:08:00 +0200 USER-PC user MESSAGE Starting IP protection 2013/09/18 20:08:11 +0200 USER-PC user MESSAGE IP Protection started successfully 2013/09/18 20:57:23 +0200 USER-PC user MESSAGE Starting protection 2013/09/18 20:57:23 +0200 USER-PC user MESSAGE Protection started successfully 2013/09/18 20:57:24 +0200 USER-PC user MESSAGE Starting IP protection 2013/09/18 20:57:42 +0200 USER-PC user MESSAGE IP Protection started successfully |
19.09.2013, 13:49 | #9 |
/// TB-Ausbilder | Schäden nach qvo6. Servus, wie läuft dein Rechner momentan? Gibt es noch Probleme mit qvo6? Wenn ja, in welchem Browser treten die Probleme auf? Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. |
19.09.2013, 14:14 | #10 |
| immernoch probleme! Also Qvo6 ist nicht mehr da als Search engine! das erstmal gut! Aber! Chrome und iExplorer funktionieren eine weile gut bis es auf einmal nicht mehr geht. Wenn man eine Seite Öffnen will erscheint in der URL bar das: hxxp://192.168.2.1/redir.stm?u=jwP0 oder wenn man z.B. Google öffnen möchte erscheint das: https (durchgestrichen!):// google.com und leere seite: "die seite konnte nicht gefunden werden" hier ist die letzte FRST log: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-09-2013 03 Ran by user (administrator) on USER-PC on 19-09-2013 15:00:44 Running from C:\Users\user\Desktop\antiMalwareScans& Logs Windows 7 Ultimate (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Program Files (x86)\Verbindungsassistent\WTGService.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Spotify Ltd) C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Dropbox, Inc.) C:\Users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe () C:\Windows\system32\LFXGDIPO.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [Spotify Web Helper] - C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1105408 2013-05-25] (Spotify Ltd) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20686704 2013-07-25] (Skype Technologies S.A.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software) Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xEFC804AE6E59CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Extension: (Google Docs) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Learn Arabic) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdgbpjkalbphhojlogonmdbpaeaecpjn\1_0 CHR Extension: (Learn Portuguese - Tudo Bem) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\iaichpenkdlohcjgagagapnegbjmfnfh\1.46_0 CHR Extension: (babbel.com) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmkbolconpmgdcpjcmhiiegjjopiofkn\1.1.1_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\WTGService.exe [296400 2009-03-03] () ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-18 20:10 - 2013-09-18 20:10 - 00000000 ____D C:\Windows\ERUNT 2013-09-18 20:05 - 2013-09-18 20:05 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes 2013-09-18 20:04 - 2013-09-18 20:04 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-18 20:04 - 2013-09-18 20:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-18 20:04 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-18 19:55 - 2013-09-18 19:55 - 01029675 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe 2013-09-18 19:54 - 2013-09-18 19:55 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-18 16:57 - 2013-09-18 16:57 - 00017088 _____ C:\ComboFix.txt 2013-09-18 16:36 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-09-18 16:36 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-09-18 16:36 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-09-18 16:36 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-09-18 16:36 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-09-18 16:36 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-09-18 16:36 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-09-18 16:36 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-09-18 16:35 - 2013-09-18 16:57 - 00000000 ____D C:\Qoobox 2013-09-18 16:35 - 2013-09-18 16:54 - 00000000 ____D C:\Windows\erdnt 2013-09-18 15:29 - 2013-09-18 15:29 - 00031895 _____ C:\Users\user\Downloads\FRST.txt 2013-09-18 15:27 - 2013-09-18 15:29 - 00019528 _____ C:\Users\user\Downloads\Addition.txt 2013-09-18 15:24 - 2013-09-18 15:24 - 00000000 ____D C:\FRST 2013-09-18 14:22 - 2013-09-19 14:55 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-09-18 14:22 - 2013-09-18 14:22 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-09-18 14:22 - 2013-09-18 14:22 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-09-18 14:22 - 2013-08-30 09:48 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-09-18 14:22 - 2013-08-30 09:48 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-09-18 14:22 - 2013-08-30 09:47 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-09-18 14:22 - 2013-08-30 09:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-09-18 14:21 - 2013-09-18 14:21 - 00000000 ____D C:\Program Files\AVAST Software 2013-09-18 14:20 - 2013-09-18 14:21 - 00000000 ____D C:\ProgramData\AVAST Software 2013-09-18 13:48 - 2013-09-18 14:19 - 131918888 _____ C:\Users\user\Downloads\avast_free_antivirus_setup_8.0.1497.376.exe 2013-09-18 13:03 - 2013-09-18 13:03 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-18 13:02 - 2013-09-19 14:53 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-18 13:02 - 2013-09-19 09:07 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-18 13:02 - 2013-09-18 13:02 - 00004102 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-09-18 13:02 - 2013-09-18 13:02 - 00003850 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-09-18 13:01 - 2013-09-18 13:02 - 00000000 ____D C:\Users\user\AppData\Local\Deployment 2013-09-18 13:01 - 2013-09-18 13:01 - 00000000 ____D C:\Users\user\AppData\Local\Apps\2.0 2013-09-18 12:12 - 2013-09-18 20:00 - 00000000 ____D C:\AdwCleaner 2013-09-18 12:11 - 2013-09-18 12:12 - 01039554 _____ C:\Users\user\Downloads\adwcleaner004.exe 2013-09-18 10:30 - 2013-09-18 10:30 - 00262144 ____N C:\Windows\Minidump\091813-30061-01.dmp 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Users\user\AppData\Local\avgchrome 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-09-14 15:12 - 2013-09-18 10:18 - 00000087 _____ C:\Users\user\AppData\Roaming\WB.CFG 2013-09-14 15:12 - 2013-09-18 10:18 - 00000005 _____ C:\Users\user\AppData\Roaming\WBPU-TTL.DAT 2013-09-14 14:41 - 2013-09-14 14:41 - 00001021 _____ C:\Users\user\Desktop\FLV Player.lnk 2013-09-14 14:41 - 2013-09-14 14:41 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player 2013-09-14 14:41 - 2013-09-14 14:41 - 00000000 ____D C:\Program Files (x86)\FLVPlayer 2013-09-14 14:20 - 2013-09-14 14:20 - 00003174 _____ C:\Windows\System32\Tasks\{3D5AA52C-E5B5-4354-9FF7-E6FCBD1E1B38} 2013-09-14 14:12 - 2013-09-14 14:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-14 12:19 - 2013-09-14 12:20 - 00000000 ____D C:\Users\user\Desktop\miniSDcardA 2013-09-14 12:01 - 2013-09-14 12:01 - 00273960 _____ C:\Windows\Minidump\091413-39624-01.dmp 2013-09-14 11:56 - 2013-09-14 11:56 - 00262144 ____H C:\Windows\DUMP343f.DMP 2013-09-14 11:51 - 2013-09-14 11:51 - 00262144 ____N C:\Windows\Minidump\091413-47018-01.dmp 2013-09-14 11:45 - 2013-09-14 11:45 - 00262144 ____N C:\Windows\Minidump\091413-22167-01.dmp 2013-09-14 00:41 - 2011-04-09 08:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2013-09-14 00:41 - 2011-04-09 07:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2013-09-14 00:24 - 2011-11-19 17:07 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2013-09-14 00:24 - 2011-11-19 16:06 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2013-09-13 07:16 - 2012-06-03 00:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-09-13 07:16 - 2012-06-03 00:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-09-13 07:16 - 2012-06-03 00:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-09-13 07:16 - 2012-06-03 00:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-09-13 07:16 - 2012-06-03 00:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-09-13 07:16 - 2012-06-03 00:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-09-13 07:16 - 2012-06-03 00:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-09-13 07:15 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-09-13 07:15 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-09-12 21:35 - 2013-09-12 21:35 - 00368101 _____ C:\Users\user\Documents\testdruck.xps 2013-09-12 21:34 - 2013-09-12 21:34 - 00368098 _____ C:\Users\user\Documents\drucktest.xps 2013-09-12 21:32 - 2013-09-12 21:32 - 00368106 _____ C:\Users\user\Documents\cv_druck1.xps 2013-09-12 21:30 - 2013-09-12 21:30 - 00368087 _____ C:\Users\user\Documents\cv_duck.xps 2013-09-12 15:01 - 2013-09-12 15:01 - 06074368 _____ C:\Users\user\Downloads\B2500_tcm3-41664.exe 2013-09-12 15:01 - 2013-09-12 15:01 - 00000000 ____D C:\okidriver 2013-09-11 10:19 - 2013-09-11 10:19 - 00262144 ____N C:\Windows\Minidump\091113-21824-01.dmp 2013-09-08 22:26 - 2013-09-08 22:26 - 01068336 _____ (Solid State Networks) C:\Users\user\Downloads\install_reader11_de_mssd_aaa_aih.exe 2013-09-08 22:19 - 2013-09-13 00:13 - 00000000 ____D C:\Users\user\Desktop\document 2013-09-03 10:46 - 2013-09-03 10:46 - 00262144 ____N C:\Windows\Minidump\090313-26457-01.dmp 2013-09-01 18:20 - 2013-09-01 18:20 - 00001007 _____ C:\Users\user\Desktop\Audacity.lnk 2013-09-01 18:20 - 2013-09-01 18:20 - 00000000 ____D C:\Program Files (x86)\Audacity 2013-09-01 18:05 - 2013-09-01 18:05 - 21281052 _____ (Audacity Team ) C:\Users\user\Downloads\audacity-win-2.0.3.exe 2013-09-01 17:52 - 2013-09-01 17:52 - 00254256 _____ C:\Users\user\Downloads\flashaudioplayer (1).zip 2013-09-01 17:39 - 2013-09-01 17:46 - 00000000 ____D C:\Users\user\AppData\Roaming\hdbADS 2013-09-01 13:35 - 2013-09-01 13:35 - 00254256 _____ C:\Users\user\Downloads\flashaudioplayer.zip 2013-09-01 13:10 - 2013-09-14 00:18 - 00000000 ____D C:\Program Files (x86)\phase5 2013-09-01 13:10 - 2013-09-01 13:10 - 00000921 _____ C:\Users\user\Desktop\HTML Editor.lnk 2013-09-01 13:10 - 2013-09-01 13:10 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Phase 5 HTML-Editor 2013-09-01 13:07 - 2013-09-01 13:07 - 03746496 _____ (Systemberatung Schommer) C:\Users\user\Downloads\phase5623install.exe 2013-08-29 21:24 - 2013-08-29 21:24 - 00001901 _____ C:\Users\user\Desktop\FileZilla.lnk 2013-08-29 21:24 - 2013-08-29 21:24 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla 2013-08-29 21:24 - 2013-08-29 21:24 - 00000000 ____D C:\Program Files (x86)\FileZilla 2013-08-29 21:23 - 2013-08-29 21:24 - 03458079 _____ C:\Users\user\Downloads\FileZilla_2_2_32_setup.exe 2013-08-28 14:16 - 2013-08-28 14:16 - 01209168 _____ C:\Windows\Minidump\082813-19297-01.dmp 2013-08-22 23:36 - 2013-09-17 13:14 - 00000000 ____D C:\Users\user\Desktop\root 2013-08-22 23:26 - 2013-08-22 23:26 - 32966136 _____ (Dropbox, Inc.) C:\Users\user\Downloads\Dropbox 2.0.26 (1).exe 2013-08-22 11:11 - 2013-09-19 14:55 - 00000000 ___RD C:\Users\user\Dropbox 2013-08-22 11:11 - 2013-08-22 23:27 - 00001013 _____ C:\Users\user\Desktop\Dropbox.lnk 2013-08-22 11:08 - 2013-08-22 23:27 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-22 09:52 - 2013-09-19 15:01 - 00000000 ____D C:\Users\user\AppData\Roaming\Dropbox 2013-08-22 09:50 - 2013-08-22 09:50 - 32966136 _____ (Dropbox, Inc.) C:\Users\user\Downloads\Dropbox 2.0.26.exe 2013-08-20 11:04 - 2013-08-20 11:04 - 00000000 ____D C:\Users\user\AppData\Roaming\OpenOffice 2013-08-20 11:03 - 2013-08-20 11:03 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk 2013-08-20 11:03 - 2013-08-20 11:03 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-08-20 10:58 - 2013-08-20 10:58 - 00000000 ____D C:\Users\user\Desktop\OpenOffice 4.0.0 (de) Installation Files 2013-08-20 10:55 - 2013-08-20 10:57 - 162401424 _____ C:\Users\user\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de.exe ==================== One Month Modified Files and Folders ======= 2013-09-19 15:01 - 2013-08-22 09:52 - 00000000 ____D C:\Users\user\AppData\Roaming\Dropbox 2013-09-19 14:57 - 2011-10-09 19:34 - 01319616 _____ C:\Windows\WindowsUpdate.log 2013-09-19 14:55 - 2013-09-18 14:22 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-09-19 14:55 - 2013-08-22 11:11 - 00000000 ___RD C:\Users\user\Dropbox 2013-09-19 14:55 - 2013-08-03 16:13 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype 2013-09-19 14:53 - 2013-09-18 13:02 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-19 14:53 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-19 14:53 - 2009-07-14 06:51 - 00031292 _____ C:\Windows\setupact.log 2013-09-19 09:36 - 2009-07-14 06:45 - 00009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-19 09:36 - 2009-07-14 06:45 - 00009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-19 09:17 - 2013-05-25 21:05 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-19 09:07 - 2013-09-18 13:02 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-18 20:56 - 2013-05-26 11:10 - 00007150 _____ C:\Windows\PFRO.log 2013-09-18 20:10 - 2013-09-18 20:10 - 00000000 ____D C:\Windows\ERUNT 2013-09-18 20:05 - 2013-09-18 20:05 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes 2013-09-18 20:04 - 2013-09-18 20:04 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-18 20:04 - 2013-09-18 20:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-18 20:00 - 2013-09-18 12:12 - 00000000 ____D C:\AdwCleaner 2013-09-18 19:55 - 2013-09-18 19:55 - 01029675 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe 2013-09-18 19:55 - 2013-09-18 19:54 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-18 17:40 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-18 16:57 - 2013-09-18 16:57 - 00017088 _____ C:\ComboFix.txt 2013-09-18 16:57 - 2013-09-18 16:35 - 00000000 ____D C:\Qoobox 2013-09-18 16:57 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-09-18 16:54 - 2013-09-18 16:35 - 00000000 ____D C:\Windows\erdnt 2013-09-18 16:52 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-09-18 15:29 - 2013-09-18 15:29 - 00031895 _____ C:\Users\user\Downloads\FRST.txt 2013-09-18 15:29 - 2013-09-18 15:27 - 00019528 _____ C:\Users\user\Downloads\Addition.txt 2013-09-18 15:24 - 2013-09-18 15:24 - 00000000 ____D C:\FRST 2013-09-18 14:22 - 2013-09-18 14:22 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-09-18 14:22 - 2013-09-18 14:22 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-09-18 14:21 - 2013-09-18 14:21 - 00000000 ____D C:\Program Files\AVAST Software 2013-09-18 14:21 - 2013-09-18 14:20 - 00000000 ____D C:\ProgramData\AVAST Software 2013-09-18 14:19 - 2013-09-18 13:48 - 131918888 _____ C:\Users\user\Downloads\avast_free_antivirus_setup_8.0.1497.376.exe 2013-09-18 13:03 - 2013-09-18 13:03 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-18 13:03 - 2013-05-25 21:05 - 00000000 ____D C:\Users\user\AppData\Local\Google 2013-09-18 13:03 - 2013-05-25 21:05 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-18 13:02 - 2013-09-18 13:02 - 00004102 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-09-18 13:02 - 2013-09-18 13:02 - 00003850 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-09-18 13:02 - 2013-09-18 13:01 - 00000000 ____D C:\Users\user\AppData\Local\Deployment 2013-09-18 13:01 - 2013-09-18 13:01 - 00000000 ____D C:\Users\user\AppData\Local\Apps\2.0 2013-09-18 12:54 - 2011-10-10 14:15 - 00001439 _____ C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-18 12:18 - 2011-10-10 14:16 - 00000847 _____ C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-09-18 12:12 - 2013-09-18 12:11 - 01039554 _____ C:\Users\user\Downloads\adwcleaner004.exe 2013-09-18 10:30 - 2013-09-18 10:30 - 00262144 ____N C:\Windows\Minidump\091813-30061-01.dmp 2013-09-18 10:30 - 2013-05-26 21:12 - 00000000 ____D C:\Windows\Minidump 2013-09-18 10:18 - 2013-09-14 15:12 - 00000087 _____ C:\Users\user\AppData\Roaming\WB.CFG 2013-09-18 10:18 - 2013-09-14 15:12 - 00000005 _____ C:\Users\user\AppData\Roaming\WBPU-TTL.DAT 2013-09-17 13:30 - 2013-07-31 08:36 - 00000000 ____D C:\Users\user\AppData\Roaming\Audacity 2013-09-17 13:14 - 2013-08-22 23:36 - 00000000 ____D C:\Users\user\Desktop\root 2013-09-17 13:08 - 2013-06-20 21:47 - 00000000 ____D C:\Users\user\Desktop\mirFOTOS 2013-09-17 11:13 - 2009-06-21 14:44 - 00000000 ____D C:\programme 2013-09-17 11:06 - 2013-05-25 17:58 - 00000000 ____D C:\Users\user\AppData\Roaming\Adobe 2013-09-17 11:05 - 2013-05-25 17:58 - 00000000 ____D C:\ProgramData\Adobe 2013-09-17 11:05 - 2013-05-25 17:57 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-09-17 11:04 - 2013-05-25 17:59 - 00000000 ____D C:\Users\user\AppData\Local\Adobe 2013-09-17 11:04 - 2013-05-25 17:57 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Users\user\AppData\Local\avgchrome 2013-09-17 10:46 - 2013-09-17 10:46 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-09-14 14:41 - 2013-09-14 14:41 - 00001021 _____ C:\Users\user\Desktop\FLV Player.lnk 2013-09-14 14:41 - 2013-09-14 14:41 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player 2013-09-14 14:41 - 2013-09-14 14:41 - 00000000 ____D C:\Program Files (x86)\FLVPlayer 2013-09-14 14:20 - 2013-09-14 14:20 - 00003174 _____ C:\Windows\System32\Tasks\{3D5AA52C-E5B5-4354-9FF7-E6FCBD1E1B38} 2013-09-14 14:12 - 2013-09-14 14:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-14 12:20 - 2013-09-14 12:19 - 00000000 ____D C:\Users\user\Desktop\miniSDcardA 2013-09-14 12:01 - 2013-09-14 12:01 - 00273960 _____ C:\Windows\Minidump\091413-39624-01.dmp 2013-09-14 11:56 - 2013-09-14 11:56 - 00262144 ____H C:\Windows\DUMP343f.DMP 2013-09-14 11:51 - 2013-09-14 11:51 - 00262144 ____N C:\Windows\Minidump\091413-47018-01.dmp 2013-09-14 11:45 - 2013-09-14 11:45 - 00262144 ____N C:\Windows\Minidump\091413-22167-01.dmp 2013-09-14 00:18 - 2013-09-01 13:10 - 00000000 ____D C:\Program Files (x86)\phase5 2013-09-14 00:17 - 2013-05-25 21:05 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-14 00:17 - 2013-05-25 21:05 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-14 00:17 - 2013-05-25 21:05 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-13 00:13 - 2013-09-08 22:19 - 00000000 ____D C:\Users\user\Desktop\document 2013-09-12 21:35 - 2013-09-12 21:35 - 00368101 _____ C:\Users\user\Documents\testdruck.xps 2013-09-12 21:34 - 2013-09-12 21:34 - 00368098 _____ C:\Users\user\Documents\drucktest.xps 2013-09-12 21:32 - 2013-09-12 21:32 - 00368106 _____ C:\Users\user\Documents\cv_druck1.xps 2013-09-12 21:30 - 2013-09-12 21:30 - 00368087 _____ C:\Users\user\Documents\cv_duck.xps 2013-09-12 15:01 - 2013-09-12 15:01 - 06074368 _____ C:\Users\user\Downloads\B2500_tcm3-41664.exe 2013-09-12 15:01 - 2013-09-12 15:01 - 00000000 ____D C:\okidriver 2013-09-11 22:28 - 2013-05-29 21:38 - 00000000 ____D C:\Users\user\Desktop\moi text 2013-09-11 10:19 - 2013-09-11 10:19 - 00262144 ____N C:\Windows\Minidump\091113-21824-01.dmp 2013-09-09 20:30 - 2011-09-09 06:58 - 00643866 _____ C:\Windows\system32\perfh007.dat 2013-09-09 20:30 - 2011-09-09 06:58 - 00126394 _____ C:\Windows\system32\perfc007.dat 2013-09-09 20:30 - 2009-07-14 07:13 - 01472002 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-09 07:11 - 2009-07-14 06:45 - 02900304 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-08 22:44 - 2011-10-10 14:26 - 00063568 _____ C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-08 22:26 - 2013-09-08 22:26 - 01068336 _____ (Solid State Networks) C:\Users\user\Downloads\install_reader11_de_mssd_aaa_aih.exe 2013-09-03 10:46 - 2013-09-03 10:46 - 00262144 ____N C:\Windows\Minidump\090313-26457-01.dmp 2013-09-01 18:20 - 2013-09-01 18:20 - 00001007 _____ C:\Users\user\Desktop\Audacity.lnk 2013-09-01 18:20 - 2013-09-01 18:20 - 00000000 ____D C:\Program Files (x86)\Audacity 2013-09-01 18:05 - 2013-09-01 18:05 - 21281052 _____ (Audacity Team ) C:\Users\user\Downloads\audacity-win-2.0.3.exe 2013-09-01 17:52 - 2013-09-01 17:52 - 00254256 _____ C:\Users\user\Downloads\flashaudioplayer (1).zip 2013-09-01 17:46 - 2013-09-01 17:39 - 00000000 ____D C:\Users\user\AppData\Roaming\hdbADS 2013-09-01 13:35 - 2013-09-01 13:35 - 00254256 _____ C:\Users\user\Downloads\flashaudioplayer.zip 2013-09-01 13:10 - 2013-09-01 13:10 - 00000921 _____ C:\Users\user\Desktop\HTML Editor.lnk 2013-09-01 13:10 - 2013-09-01 13:10 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Phase 5 HTML-Editor 2013-09-01 13:07 - 2013-09-01 13:07 - 03746496 _____ (Systemberatung Schommer) C:\Users\user\Downloads\phase5623install.exe 2013-08-30 09:48 - 2013-09-18 14:22 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-08-30 09:48 - 2013-09-18 14:22 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-08-30 09:47 - 2013-09-18 14:22 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-08-30 09:47 - 2013-09-18 14:22 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-08-29 22:07 - 2011-10-10 14:15 - 00000000 ____D C:\Users\user\AppData\Local\VirtualStore 2013-08-29 21:24 - 2013-08-29 21:24 - 00001901 _____ C:\Users\user\Desktop\FileZilla.lnk 2013-08-29 21:24 - 2013-08-29 21:24 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla 2013-08-29 21:24 - 2013-08-29 21:24 - 00000000 ____D C:\Program Files (x86)\FileZilla 2013-08-29 21:24 - 2013-08-29 21:23 - 03458079 _____ C:\Users\user\Downloads\FileZilla_2_2_32_setup.exe 2013-08-28 14:16 - 2013-08-28 14:16 - 01209168 _____ C:\Windows\Minidump\082813-19297-01.dmp 2013-08-28 07:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-08-27 13:52 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-08-22 23:27 - 2013-08-22 11:11 - 00001013 _____ C:\Users\user\Desktop\Dropbox.lnk 2013-08-22 23:27 - 2013-08-22 11:08 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-22 23:27 - 2011-10-10 14:15 - 00000000 ___RD C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-08-22 23:26 - 2013-08-22 23:26 - 32966136 _____ (Dropbox, Inc.) C:\Users\user\Downloads\Dropbox 2.0.26 (1).exe 2013-08-22 09:50 - 2013-08-22 09:50 - 32966136 _____ (Dropbox, Inc.) C:\Users\user\Downloads\Dropbox 2.0.26.exe 2013-08-20 11:04 - 2013-08-20 11:04 - 00000000 ____D C:\Users\user\AppData\Roaming\OpenOffice 2013-08-20 11:03 - 2013-08-20 11:03 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk 2013-08-20 11:03 - 2013-08-20 11:03 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-08-20 10:59 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-08-20 10:58 - 2013-08-20 10:58 - 00000000 ____D C:\Users\user\Desktop\OpenOffice 4.0.0 (de) Installation Files 2013-08-20 10:57 - 2013-08-20 10:55 - 162401424 _____ C:\Users\user\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de.exe Some content of TEMP: ==================== C:\Users\user\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-11 11:09 ==================== End Of Log ============================ und Addition Scan: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-09-2013 03 Ran by user at 2013-09-19 15:02:11 Running from C:\Users\user\Desktop\antiMalwareScans& Logs Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe AIR (x32 Version: 1.1.0.5790) Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.174) Adobe Media Player (x32 Version: 0.0.0) Adobe Media Player (x32 Version: 1.1) Audacity 2.0.3 (x32 Version: 2.0.3) avast! Free Antivirus (x32 Version: 8.0.1497.0) Dropbox (HKCU Version: 2.0.26) FileZilla (remove only) (x32) FLV Player (HKCU) Google Chrome (x32 Version: 29.0.1547.66) Lock On: Modern Air Combat (x32 Version: 1.00.000) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) OpenOffice 4.0.0 (x32 Version: 4.00.9702) Phase 5 HTML-Editor (x32 Version: 5.6.2.3) Revo Uninstaller 1.95 (x32 Version: 1.95) Skype™ 6.7 (x32 Version: 6.7.102) Spotify (HKCU Version: 0.9.0.133.gd18ed589) Verbindungsassistent (x32 Version: 2.1) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-09-18 16:52 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started Task: {2F02D5F6-E04C-4A84-90DD-F014C488F3CE} - \DSite No Task File Task: {63D01A4D-34FC-45C4-845E-09E4A72484C6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-18] (Google Inc.) Task: {6AC7AF7A-F9DA-4A76-B106-50FDB2B34511} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2009-07-14] (Microsoft Corporation) Task: {78518758-3AA2-4C43-A61A-94462968C74C} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {A80D4D5B-3651-4F82-966A-DC5C6822D9DE} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software) Task: {CA70101D-0DC4-4A6C-BEBC-7D0EEC26A9C3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-14] (Adobe Systems Incorporated) Task: {E2498BAC-FAAD-4507-89EF-B5904A57CBA2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-18] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-06-05 19:17 - 2013-06-05 19:17 - 00164016 _____ (Dropbox, Inc.) C:\Users\user\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll 2009-07-14 02:18 - 2009-07-14 03:38 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\imaadp32.acm 2009-07-14 02:18 - 2009-07-14 03:38 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\msg711.acm 2009-07-14 02:18 - 2009-07-14 03:38 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\msgsm32.acm 2009-07-14 02:18 - 2009-07-14 03:38 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\msadp32.acm 2009-07-14 02:07 - 2009-07-14 03:14 - 00064000 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\SysWOW64\l3codeca.acm 2012-11-14 01:32 - 2012-11-14 01:32 - 03558400 _____ (wxWidgets development team) C:\Users\user\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll 2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\user\AppData\Roaming\Dropbox\bin\libcef.dll 2013-03-13 22:48 - 2013-03-13 22:48 - 09956864 _____ (The ICU Project) C:\Users\user\AppData\Roaming\Dropbox\bin\icudt.dll 2013-09-18 13:03 - 2013-09-02 22:35 - 00709584 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\libglesv2.dll 2013-09-18 13:03 - 2013-09-02 22:35 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\libegl.dll 2013-09-18 13:03 - 2013-09-02 22:35 - 04053456 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\pdf.dll 2013-09-18 13:03 - 2013-09-02 22:35 - 00410576 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll 2013-09-18 13:03 - 2013-09-02 22:35 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ffmpegsumo.dll 2013-09-18 13:03 - 2013-09-02 22:35 - 13599184 _____ () C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========== AlternateDataStreams: C:\Users\user\Downloads\Calle 13 [La Bala] del Album Entren los que Quieran.lite.mp3:TOC.WMV ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (09/19/2013 08:48:05 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. System errors: ============= Error: (09/19/2013 02:53:44 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (09/19/2013 02:53:44 PM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (09/19/2013 09:29:26 AM) (Source: atikmdag) (User: ) Description: Display is not active Error: (09/19/2013 09:29:06 AM) (Source: atikmdag) (User: ) Description: Display is not active Error: (09/19/2013 08:29:50 AM) (Source: Microsoft-Windows-WHEA-Logger) (User: NT-AUTORITÄT) Description: Schwerwiegender Hardwarefehler. Gemeldet von Komponente: Prozessorkern Fehlerquelle: 3 Fehlertyp: 9 Prozessor-ID: 1 Die Detailansicht dieses Eintrags beinhaltet weitere Informationen. Error: (09/19/2013 08:29:25 AM) (Source: atikmdag) (User: ) Description: Display is not active Error: (09/19/2013 08:29:25 AM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (09/18/2013 08:57:03 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (09/18/2013 08:57:03 PM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Microsoft Office Sessions: ========================= Error: (09/19/2013 08:48:05 AM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 CodeIntegrity Errors: =================================== Date: 2013-09-18 16:51:18.427 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-09-18 16:51:18.345 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 35% Total physical RAM: 3836.87 MB Available physical RAM: 2470.46 MB Total Pagefile: 7671.88 MB Available Pagefile: 6102.33 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:48.83 GB) (Free:2.88 GB) NTFS Drive d: () (Fixed) (Total:48.83 GB) (Free:1.82 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: () (Fixed) (Total:37.56 GB) (Free:0.64 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 71723968) Partition 1: (Active) - (Size=49 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=49 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=38 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=98 GB) - (Type=05) ==================== End Of Log =========================== |
19.09.2013, 14:51 | #11 | |
/// TB-Ausbilder | Schäden nach qvo6. Servus, Zitat:
Wir versuchen jetzt noch ein Letztes... wenn das auch nicht hilft, dann müssen wir wohl den IE und CHR zurücksetzen. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Task: {2F02D5F6-E04C-4A84-90DD-F014C488F3CE} - \DSite No Task File end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
Gibt es immer noch die genannten Probleme beim IE und Google Chrome? Bitte poste mit deiner nächsten Antwort
|
20.09.2013, 22:25 | #12 |
| Schäden nach qvo6. Halo! sorry das ich mich paar Tage nicht gemeldet habe. Heute habe ich nur diese Forum geöffnet und paar seiten wegen aktualisierung von FRST und bis jetzt kein problem. Aber wie gesagt manchmal läuft lange gut und dann...wieder scheisse. so. hier the FRST log: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-09-2013 01 Ran by user at 2013-09-20 22:55:20 Run:1 Running from C:\Users\user\Desktop\antiMalwareScans& Logs Boot Mode: Normal ============================================== Content of fixlist: ***************** start SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Task: {2F02D5F6-E04C-4A84-90DD-F014C488F3CE} - \DSite No Task File end ***************** HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2F02D5F6-E04C-4A84-90DD-F014C488F3CE} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F02D5F6-E04C-4A84-90DD-F014C488F3CE} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite => Key deleted successfully. ==== End of Fixlog ==== und Zoek log Code:
ATTFilter Zoek.exe Version 4.0.0.4 Updated 19-September-2013 Tool run by user on 20.09.2013 at 22:59:14,72. Microsoft Windows 7 Ultimate 6.1.7600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\user\Desktop\antiMalwareScans& Logs\zoek\zoek.scr [Script inserted] ==== System Restore Info ====================== 20.09.2013 23:01:14 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== "C:\Windows\SysWow64\searchplugins" deleted "C:\Windows\SysWow64\Extensions" deleted ==== Chrome Look ====================== Learn Arabic - user - Default\Extensions\hdgbpjkalbphhojlogonmdbpaeaecpjn Learn Portuguese - Tudo Bem - user - Default\Extensions\iaichpenkdlohcjgagagapnegbjmfnfh Chrome In-App Payments service - user - Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="hxxp://www.google.com" "Start Page"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Page_URL"="hxxp://www.google.com" "Start Page"="hxxp://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] No DefaultScope Set For HKCU New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Reset Google Chrome ====================== C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Application Cache\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\user\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found ==== EOF on 20.09.2013 at 23:17:11,78 ====================== |
21.09.2013, 11:15 | #13 |
/// TB-Ausbilder | Schäden nach qvo6. Servus, Schritt 1 ESET Online Scanner
Schritt 2 Downloade Dir bitte SecurityCheck und:
Bitte poste mit deiner nächsten Antwort
|
23.09.2013, 10:46 | #14 |
| Schäden nach qvo6. halo! ESET läuft nicht:-( Es fangt mit Scan an und bei 1% bleibt stundenlang stecken. Habe ich zwei Tage nach einander probiert. Ich habe es deinstalliert. Ich werde es nochmal installieren und erneut versuchen. Leider habe ich gerade nicht viel Zeit dafür:-( hier sind die Security check Ergebnisse: Code:
ATTFilter Results of screen317's Security Check version 0.99.73 Windows 7 x64 (UAC is enabled) Out of date service pack!! ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Google Chrome 29.0.1547.66 Google Chrome 29.0.1547.76 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` vielen vielen dank! grosse Respekt für deine ehrenamtliche Arbeit! |
23.09.2013, 13:08 | #15 |
/// TB-Ausbilder | Schäden nach qvo6. Servus, Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Downloade und installiere als Erstes: Windows 7 Service Pack 1 (windows6.1-KB976932-X64.exe) Schritt 1 Die Reihenfolge ist hier entscheidend.
Schritt 2 Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von Registry Cleanern. Diese Schaden deinem System mehr als dass sie helfen. Hier ein englischer Link: Miekemoes Blogspot ( MVP ) Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
Themen zu Schäden nach qvo6. |
avast, browser, einträge, hoax.sms, keine viren, meldung, probleme, pup.optional.installcore.a, pup.optional.softonic, regedit, runterladen, schäden, search, seiten, störungen, system, verbindung, verschieden, überprüfe, überprüfen, youtube, öffnen |