|
Plagegeister aller Art und deren Bekämpfung: habe Probleme mit MonsterMarketplace.comWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.10.2013, 12:01 | #1 |
| habe Probleme mit MonsterMarketplace.com Hallo, ich bin neu hier. Vor einigen Tagen habe ich festgestellt, dass mein PC wohl infiziert ist. Ständig gehen popup's von MonsterMarketplace.com auf und stören den Arbeitsablauf nachhaltig. Ich verwende Windows 7 Ultimate 32 bit Servicepack 1, Firefox als Browser. Meine Avira Free Antivir hat nichts gefunden. Ich weiss im Moment nicht, wie ich mich verhalten soll und wäre für Hilfe sehr dankbar. |
09.10.2013, 13:01 | #2 |
/// TB-Ausbilder | habe Probleme mit MonsterMarketplace.com Hallo,
__________________mach bitte einen FRST-Scan: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
10.10.2013, 10:17 | #3 |
| habe Probleme mit MonsterMarketplace.com So, hier kommt der FRST.txt
__________________[ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013 Ran by christa (administrator) on CHRISTA-PC on 10-10-2013 10:58:43 Running from C:\Users\christa\Downloads Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe () C:\Programme\mySQL\bin\Mysqld-nt.exe (Nitro PDF Software) C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Ask) C:\Program Files\Ask.com\Updater\Updater.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (MySQL AB) C:\Programme\mySQL\bin\winmysqladmin.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (Farbar) C:\Users\christa\Downloads\FRST(1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [] - [x] HKLM\...\Run: [ApnUpdater] - C:\Program Files\Ask.com\Updater\Updater.exe [1648264 2013-04-30] (Ask) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-07] (Avira Operations GmbH & Co. KG) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) MountPoints2: {ada2a755-e216-11e2-ab3c-0026b917f939} - F:\LaunchU3.exe -a MountPoints2: {ada2a7a5-e216-11e2-ab3c-0026b917f939} - F:\AutoRun.exe Startup: C:\Users\christa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mySQL.lnk ShortcutTarget: mySQL.lnk -> C:\Programme\mySQL\bin\winmysqladmin.exe (MySQL AB) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Delta Search HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2B5ACA2C4B60CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=B6A7701A04BB4A54&affID=119556&tsp=4933 SearchScopes: HKCU - {E779A530-EFFF-4BF7-8985-7159A6D21394} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=cddcab32-fdf9-482b-8061-f99d4686b12b&apn_sauid=6B0DD5B2-15D7-464D-AB46-0F57819BC20E BHO: Plus-HD-1.6 - {11111111-1111-1111-1111-110311201102} - C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-bho.dll (Plus HD) BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKCU -Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\mvpym892.default FF user.js: detected! => C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\mvpym892.default\user.js FF NewTab: user_pref("browser.newtab.url", ""); FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF Homepage: hxxp://www.spiegel.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @nitropdf.com/NitroPDF - C:\Program Files\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\mvpym892.default\Extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com FF Extension: No Name - C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\mvpym892.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} Chrome: ======= CHR RestoreOnStartup: "hxxp://www.google.com" CHR Extension: (Avira Toolbar) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaabfjnbeinlpljodiajipidiompfl\7.15.26.0_0 CHR Extension: (Docs) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (Google Drive) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0 CHR Extension: (YouTube) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (Plus-HD-1.6) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.23.35_0 CHR Extension: (Wajam) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0 CHR Extension: (Skype Click to Call) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.12.0.13601_0 CHR HKLM\...\Chrome\Extension: [aaaaabfjnbeinlpljodiajipidiompfl] - C:\Users\christa\AppData\Local\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.26.0.crx CHR HKLM\...\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\christa\AppData\Local\Wajam\Chrome\wajam.crx CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440392 2013-10-07] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-07] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-07] (Avira Operations GmbH & Co. KG) R2 mySQL; C:\Programme\mySQL\bin\Mysqld-nt.exe [1142784 2003-09-14] () R2 NitroReaderDriverReadSpool3; C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe [196624 2013-07-26] (Nitro PDF Software) R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3273088 2013-09-16] (Skype Technologies S.A.) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1724192 2013-01-28] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-10-07] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-10-07] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-11-16] (TuneUp Software) S3 massfilter; system32\drivers\massfilter.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [x] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-10 10:13 - 2013-10-10 10:13 - 00000056 _____ C:\Windows\setupact.log 2013-10-10 10:13 - 2013-10-10 10:13 - 00000000 _____ C:\Windows\setuperr.log 2013-10-10 07:53 - 2013-10-10 09:13 - 00061582 _____ C:\Windows\WindowsUpdate.log 2013-10-08 08:23 - 2013-10-08 08:23 - 01087213 _____ (Farbar) C:\Users\christa\Downloads\FRST(1).exe 2013-10-07 19:17 - 2013-10-07 19:18 - 00013797 _____ C:\Users\christa\Downloads\Addition.txt 2013-10-07 19:17 - 2013-10-07 19:17 - 00000000 ____D C:\FRST 2013-10-07 18:53 - 2013-10-07 18:53 - 01087213 _____ (Farbar) C:\Users\christa\Downloads\FRST.exe 2013-10-07 16:57 - 2013-10-07 16:57 - 00002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-07 16:53 - 2013-10-10 10:13 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-07 16:53 - 2013-10-10 09:04 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-07 16:53 - 2013-10-07 16:57 - 00000000 ____D C:\Program Files\Google 2013-10-07 16:21 - 2013-10-07 16:21 - 06175328 _____ C:\Users\christa\Downloads\Berlin_20130821.pptx 2013-10-07 16:17 - 2013-10-07 16:17 - 00000000 ____D C:\Users\christa\AppData\Roaming\Nitro 2013-10-07 16:16 - 2013-10-07 16:16 - 00001961 _____ C:\Users\Public\Desktop\Nitro Reader.lnk 2013-10-07 16:16 - 2013-10-07 16:16 - 00000000 ____D C:\ProgramData\Nitro 2013-10-07 16:16 - 2013-10-07 16:16 - 00000000 ____D C:\Program Files\Nitro 2013-10-07 16:16 - 2013-10-07 16:16 - 00000000 ____D C:\Program Files\Common Files\Nitro 2013-10-07 16:16 - 2013-07-26 06:57 - 00027152 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalmon2.dll 2013-10-07 16:16 - 2013-07-26 06:57 - 00018448 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalui2.dll 2013-10-07 16:15 - 2013-10-07 16:15 - 01679552 _____ (Solid State Networks) C:\Users\christa\Downloads\nitro_pdf_reader3565_32_dlm.exe 2013-10-07 16:13 - 2013-10-07 16:16 - 00000000 ____D C:\Users\christa\AppData\Roaming\Downloaded Installations 2013-10-07 16:12 - 2013-10-07 16:12 - 01678960 _____ (Solid State Networks) C:\Users\christa\Downloads\nitro_pdf_reader3565_64_dlm(1).exe 2013-10-07 16:11 - 2013-10-07 16:11 - 01678960 _____ (Solid State Networks) C:\Users\christa\Downloads\nitro_pdf_reader3565_64_dlm.exe 2013-10-07 16:05 - 2013-10-07 16:24 - 00000000 ____D C:\Users\christa\Documents\Mietausfall.de 2013-10-07 16:03 - 2013-10-07 16:03 - 10285321 _____ C:\Users\christa\Downloads\mietausfall_de.zip 2013-10-06 14:05 - 2013-10-06 20:05 - 99477982 _____ C:\Windows\system32\꞊窞k 2013-10-05 16:02 - 2013-10-05 16:02 - 99359319 _____ C:\Windows\system32\㹎ﵺb 2013-10-05 09:11 - 2013-10-05 09:11 - 99319274 _____ C:\Windows\system32\ﴫj 2013-10-04 14:48 - 2013-10-04 14:48 - 99209434 _____ C:\Windows\system32\妡g 2013-10-04 08:47 - 2013-10-04 08:47 - 99176917 _____ C:\Windows\system32\�溬c 2013-10-03 20:53 - 2013-10-03 20:53 - 99160839 _____ C:\Windows\system32\藍ဃz 2013-10-03 14:53 - 2013-10-03 14:53 - 99102760 _____ C:\Windows\system32\偒�r 2013-10-03 08:36 - 2013-10-03 08:36 - 98878632 _____ C:\Windows\system32\ꥱ첰^ 2013-10-02 20:38 - 2013-10-02 20:38 - 98834313 _____ C:\Windows\system32\翷䁻[ 2013-10-02 14:38 - 2013-10-02 14:38 - 98743931 _____ C:\Windows\system32\┒뛜] 2013-10-02 14:21 - 2013-10-07 11:10 - 00000000 ____D C:\Users\christa\Documents\Q-Plain 2013-10-02 08:38 - 2013-10-02 08:38 - 98712514 _____ C:\Windows\system32\䔯[ 2013-10-01 21:20 - 2013-10-01 21:20 - 98612549 _____ C:\Windows\system32\ḿ` 2013-10-01 09:54 - 2013-10-01 09:56 - 68977688 _____ C:\Users\christa\Downloads\PS7510_1315.exe 2013-10-01 09:45 - 2013-10-01 09:46 - 25999288 _____ C:\Users\christa\Downloads\PS7510_Basicx86_1315(1).exe 2013-10-01 07:46 - 2013-10-01 07:46 - 98602865 _____ C:\Windows\system32\ᴍ粛_ 2013-09-30 13:01 - 2012-10-17 04:04 - 00580712 ____N (Hewlett-Packard Co.) C:\Windows\system32\HPDiscoPMA611.dll 2013-09-30 13:00 - 2013-09-30 13:02 - 00000000 ____D C:\Users\christa\AppData\Local\HP 2013-09-30 13:00 - 2013-09-30 13:00 - 00000057 _____ C:\ProgramData\Ament.ini 2013-09-30 13:00 - 2013-09-30 13:00 - 00000000 ____D C:\ProgramData\HP 2013-09-30 13:00 - 2013-09-30 13:00 - 00000000 ____D C:\Program Files\HP 2013-09-30 12:59 - 2013-09-30 13:00 - 25999288 _____ C:\Users\christa\Downloads\PS7510_Basicx86_1315.exe 2013-09-29 09:25 - 2013-09-29 18:26 - 98466785 _____ C:\Windows\system32\ꢮﰥa 2013-09-27 12:06 - 2013-09-27 12:06 - 98201609 _____ C:\Windows\system32\淅ᰱ` 2013-09-26 18:14 - 2013-09-26 18:14 - 97961477 _____ C:\Windows\system32\侽�] 2013-09-26 12:13 - 2013-09-26 12:13 - 97927968 _____ C:\Windows\system32\i 2013-09-25 12:31 - 2013-09-25 12:31 - 97717271 _____ C:\Windows\system32\ㅑ䍖e 2013-09-24 12:12 - 2013-09-24 18:12 - 97531747 _____ C:\Windows\system32\桝炇d 2013-09-24 01:09 - 2013-09-24 01:09 - 98798431 _____ C:\Windows\system32\色쥝i 2013-09-23 12:11 - 2013-09-23 18:16 - 98674763 _____ C:\Windows\system32\䗫㚺Y 2013-09-20 09:11 - 2013-09-20 09:11 - 98453713 _____ C:\Windows\system32\ꤌ烷i 2013-09-19 11:56 - 2013-09-19 11:56 - 98343078 _____ C:\Windows\system32\명栕b 2013-09-18 20:55 - 2013-09-18 20:55 - 98177822 _____ C:\Windows\system32\뼺ይg 2013-09-18 14:33 - 2013-09-18 14:34 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-17 10:18 - 2013-09-17 18:11 - 97949955 _____ C:\Windows\system32\樍毲f 2013-09-16 17:36 - 2013-09-17 01:11 - 97872530 _____ C:\Windows\system32\ࠈ퍱j 2013-09-16 11:36 - 2013-09-16 11:36 - 97745148 _____ C:\Windows\system32\ჱf 2013-09-15 21:01 - 2013-09-15 21:01 - 97671483 _____ C:\Windows\system32\䲊첷n 2013-09-14 16:24 - 2013-09-14 16:24 - 97581476 _____ C:\Windows\system32\왆Ꮺg 2013-09-13 11:10 - 2013-09-13 17:10 - 97492159 _____ C:\Windows\system32\€t 2013-09-12 20:25 - 2013-09-12 20:25 - 97373152 _____ C:\Windows\system32\훵垘r 2013-09-12 11:23 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 11:23 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 11:23 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-12 11:23 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-12 11:23 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 11:23 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-11 11:26 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 11:26 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-11 11:26 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-11 11:26 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-11 11:26 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 11:26 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-11 11:26 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-11 11:20 - 2013-09-11 11:20 - 97080355 _____ C:\Windows\system32\짳æb 2013-09-10 11:31 - 2013-09-10 18:40 - 96985259 _____ C:\Windows\system32\⒧嫖W ==================== One Month Modified Files and Folders ======= 2013-10-10 10:50 - 2013-06-03 13:22 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-10 10:49 - 2013-10-10 07:53 - 00061582 _____ C:\Windows\WindowsUpdate.log 2013-10-10 10:31 - 2013-06-05 13:14 - 00000000 ____D C:\Users\christa\AppData\Roaming\Skype 2013-10-10 10:17 - 2010-11-20 23:01 - 00004522 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-10 10:13 - 2013-10-10 10:13 - 00000056 _____ C:\Windows\setupact.log 2013-10-10 10:13 - 2013-10-10 10:13 - 00000000 _____ C:\Windows\setuperr.log 2013-10-10 10:13 - 2013-10-07 16:53 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-10 10:13 - 2013-07-04 13:34 - 00001280 _____ C:\Windows\Tasks\Plus-HD-1.6-updater.job 2013-10-10 10:13 - 2013-07-04 13:34 - 00001192 _____ C:\Windows\Tasks\Plus-HD-1.6-codedownloader.job 2013-10-10 10:13 - 2013-07-04 13:34 - 00001090 _____ C:\Windows\Tasks\Plus-HD-1.6-enabler.job 2013-10-10 10:13 - 2013-07-04 13:33 - 00001888 _____ C:\Windows\Tasks\Plus-HD-1.6-chromeinstaller.job 2013-10-10 10:13 - 2013-07-04 13:33 - 00001812 _____ C:\Windows\Tasks\Plus-HD-1.6-firefoxinstaller.job 2013-10-10 10:13 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-10 09:04 - 2013-10-07 16:53 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-10 08:59 - 2009-07-14 06:34 - 00016864 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-10 08:59 - 2009-07-14 06:34 - 00016864 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-10 07:53 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\LogFiles 2013-10-09 16:23 - 2013-06-03 13:22 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-10-09 16:23 - 2013-06-03 13:22 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-10-08 13:27 - 2013-06-03 13:13 - 00000000 ____D C:\Users\christa\AppData\Local\Google 2013-10-08 08:23 - 2013-10-08 08:23 - 01087213 _____ (Farbar) C:\Users\christa\Downloads\FRST(1).exe 2013-10-07 19:18 - 2013-10-07 19:17 - 00013797 _____ C:\Users\christa\Downloads\Addition.txt 2013-10-07 19:17 - 2013-10-07 19:17 - 00000000 ____D C:\FRST 2013-10-07 18:53 - 2013-10-07 18:53 - 01087213 _____ (Farbar) C:\Users\christa\Downloads\FRST.exe 2013-10-07 17:39 - 2013-08-29 13:17 - 00000000 ____D C:\Program Files\LyricsContainer 2013-10-07 16:57 - 2013-10-07 16:57 - 00002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-07 16:57 - 2013-10-07 16:53 - 00000000 ____D C:\Program Files\Google 2013-10-07 16:24 - 2013-10-07 16:05 - 00000000 ____D C:\Users\christa\Documents\Mietausfall.de 2013-10-07 16:21 - 2013-10-07 16:21 - 06175328 _____ C:\Users\christa\Downloads\Berlin_20130821.pptx 2013-10-07 16:17 - 2013-10-07 16:17 - 00000000 ____D C:\Users\christa\AppData\Roaming\Nitro 2013-10-07 16:16 - 2013-10-07 16:16 - 00001961 _____ C:\Users\Public\Desktop\Nitro Reader.lnk 2013-10-07 16:16 - 2013-10-07 16:16 - 00000000 ____D C:\ProgramData\Nitro 2013-10-07 16:16 - 2013-10-07 16:16 - 00000000 ____D C:\Program Files\Nitro 2013-10-07 16:16 - 2013-10-07 16:16 - 00000000 ____D C:\Program Files\Common Files\Nitro 2013-10-07 16:16 - 2013-10-07 16:13 - 00000000 ____D C:\Users\christa\AppData\Roaming\Downloaded Installations 2013-10-07 16:15 - 2013-10-07 16:15 - 01679552 _____ (Solid State Networks) C:\Users\christa\Downloads\nitro_pdf_reader3565_32_dlm.exe 2013-10-07 16:12 - 2013-10-07 16:12 - 01678960 _____ (Solid State Networks) C:\Users\christa\Downloads\nitro_pdf_reader3565_64_dlm(1).exe 2013-10-07 16:11 - 2013-10-07 16:11 - 01678960 _____ (Solid State Networks) C:\Users\christa\Downloads\nitro_pdf_reader3565_64_dlm.exe 2013-10-07 16:03 - 2013-10-07 16:03 - 10285321 _____ C:\Users\christa\Downloads\mietausfall_de.zip 2013-10-07 14:39 - 2013-06-17 22:11 - 00067680 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-10-07 14:39 - 2013-06-17 22:09 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-10-07 14:39 - 2013-06-17 22:09 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-10-07 14:39 - 2013-06-17 22:09 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-10-07 11:10 - 2013-10-02 14:21 - 00000000 ____D C:\Users\christa\Documents\Q-Plain 2013-10-06 20:05 - 2013-10-06 14:05 - 99477982 _____ C:\Windows\system32\꞊窞k 2013-10-05 16:02 - 2013-10-05 16:02 - 99359319 _____ C:\Windows\system32\㹎ﵺb 2013-10-05 09:11 - 2013-10-05 09:11 - 99319274 _____ C:\Windows\system32\ﴫj 2013-10-04 14:48 - 2013-10-04 14:48 - 99209434 _____ C:\Windows\system32\妡g 2013-10-04 14:47 - 2009-07-14 06:53 - 00032638 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-04 08:47 - 2013-10-04 08:47 - 99176917 _____ C:\Windows\system32\�溬c 2013-10-03 20:53 - 2013-10-03 20:53 - 99160839 _____ C:\Windows\system32\藍ဃz 2013-10-03 14:53 - 2013-10-03 14:53 - 99102760 _____ C:\Windows\system32\偒�r 2013-10-03 08:36 - 2013-10-03 08:36 - 98878632 _____ C:\Windows\system32\ꥱ첰^ 2013-10-02 20:38 - 2013-10-02 20:38 - 98834313 _____ C:\Windows\system32\翷䁻[ 2013-10-02 14:38 - 2013-10-02 14:38 - 98743931 _____ C:\Windows\system32\┒뛜] 2013-10-02 08:38 - 2013-10-02 08:38 - 98712514 _____ C:\Windows\system32\䔯[ 2013-10-01 21:20 - 2013-10-01 21:20 - 98612549 _____ C:\Windows\system32\ḿ` 2013-10-01 09:56 - 2013-10-01 09:54 - 68977688 _____ C:\Users\christa\Downloads\PS7510_1315.exe 2013-10-01 09:52 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2013-10-01 09:46 - 2013-10-01 09:45 - 25999288 _____ C:\Users\christa\Downloads\PS7510_Basicx86_1315(1).exe 2013-10-01 07:46 - 2013-10-01 07:46 - 98602865 _____ C:\Windows\system32\ᴍ粛_ 2013-09-30 13:02 - 2013-09-30 13:00 - 00000000 ____D C:\Users\christa\AppData\Local\HP 2013-09-30 13:00 - 2013-09-30 13:00 - 00000057 _____ C:\ProgramData\Ament.ini 2013-09-30 13:00 - 2013-09-30 13:00 - 00000000 ____D C:\ProgramData\HP 2013-09-30 13:00 - 2013-09-30 13:00 - 00000000 ____D C:\Program Files\HP 2013-09-30 13:00 - 2013-09-30 12:59 - 25999288 _____ C:\Users\christa\Downloads\PS7510_Basicx86_1315.exe 2013-09-30 13:00 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\twain_32 2013-09-29 18:26 - 2013-09-29 09:25 - 98466785 _____ C:\Windows\system32\ꢮﰥa 2013-09-27 12:06 - 2013-09-27 12:06 - 98201609 _____ C:\Windows\system32\淅ᰱ` 2013-09-26 18:14 - 2013-09-26 18:14 - 97961477 _____ C:\Windows\system32\侽�] 2013-09-26 12:14 - 2013-06-05 13:14 - 00000000 ___RD C:\Program Files\Skype 2013-09-26 12:13 - 2013-09-26 12:13 - 97927968 _____ C:\Windows\system32\i 2013-09-25 12:31 - 2013-09-25 12:31 - 97717271 _____ C:\Windows\system32\ㅑ䍖e 2013-09-24 18:12 - 2013-09-24 12:12 - 97531747 _____ C:\Windows\system32\桝炇d 2013-09-24 01:09 - 2013-09-24 01:09 - 98798431 _____ C:\Windows\system32\色쥝i 2013-09-23 18:16 - 2013-09-23 12:11 - 98674763 _____ C:\Windows\system32\䗫㚺Y 2013-09-20 09:11 - 2013-09-20 09:11 - 98453713 _____ C:\Windows\system32\ꤌ烷i 2013-09-19 11:56 - 2013-09-19 11:56 - 98343078 _____ C:\Windows\system32\명栕b 2013-09-19 11:55 - 2013-06-17 21:45 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-09-18 20:56 - 2013-06-17 21:45 - 00000000 ____D C:\Users\christa\AppData\Local\Mozilla 2013-09-18 20:55 - 2013-09-18 20:55 - 98177822 _____ C:\Windows\system32\뼺ይg 2013-09-18 14:34 - 2013-09-18 14:33 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-17 18:11 - 2013-09-17 10:18 - 97949955 _____ C:\Windows\system32\樍毲f 2013-09-17 01:11 - 2013-09-16 17:36 - 97872530 _____ C:\Windows\system32\ࠈ퍱j 2013-09-16 11:36 - 2013-09-16 11:36 - 97745148 _____ C:\Windows\system32\ჱf 2013-09-15 21:01 - 2013-09-15 21:01 - 97671483 _____ C:\Windows\system32\䲊첷n 2013-09-14 18:35 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-09-14 16:24 - 2013-09-14 16:24 - 97581476 _____ C:\Windows\system32\왆Ꮺg 2013-09-13 17:10 - 2013-09-13 11:10 - 97492159 _____ C:\Windows\system32\€t 2013-09-12 20:25 - 2013-09-12 20:25 - 97373152 _____ C:\Windows\system32\훵垘r 2013-09-12 14:28 - 2013-06-03 22:49 - 00000000 ____D C:\Windows\Panther 2013-09-12 14:22 - 2009-07-14 06:33 - 00265640 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-11 11:20 - 2013-09-11 11:20 - 97080355 _____ C:\Windows\system32\짳æb 2013-09-10 18:40 - 2013-09-10 11:31 - 96985259 _____ C:\Windows\system32\⒧嫖W Some content of TEMP: ==================== C:\Users\christa\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-02 09:38 ==================== End Of Log ============================ --- --- --- ] Ansicht[/CODE] und hier der Addition.txt, vielen Dank für deine UnterstützungFRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 03-10-2013 Ran by christa at 2013-10-10 11:02:49 Running from C:\Users\christa\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 11 ActiveX (Version: 11.9.900.117) Adobe Flash Player 11 Plugin (Version: 11.8.800.168) Adobe Reader XI (11.0.04) - Deutsch (Version: 11.0.04) Ask Toolbar (Version: 1.15.26.0) Avira Free Antivirus (Version: 14.0.0.383) Avira SearchFree Toolbar plus Web Protection Updater (HKCU Version: 1.2.6.45268) CCleaner (Version: 4.02) Google Chrome (Version: 30.0.1599.69) Google Update Helper (Version: 1.3.21.153) HP Photosmart 7510 series Basic Device Software (Version: 28.0.1315.0) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Mozilla Firefox 24.0 (x86 de) (Version: 24.0) Mozilla Maintenance Service (Version: 24.0) mySQL Nitro Reader 3 (Version: 3.5.6.5) Plus-HD-1.6 (Version: 1.27.153.10) poweroffice Skype Click to Call (Version: 6.12.13601) Skype™ 6.6 (Version: 6.6.106) TuneUp Utilities 2013 (Version: 13.0.3020.2) TuneUp Utilities Language Pack (de-DE) (Version: 13.0.3020.2) VLC media player 2.0.7 (Version: 2.0.7) ==================== Restore Points ========================= 01-09-2013 21:39:41 Scheduled Checkpoint 09-09-2013 18:15:42 Scheduled Checkpoint 12-09-2013 09:21:32 Windows Update 19-09-2013 10:34:47 Scheduled Checkpoint 26-09-2013 16:34:15 Scheduled Checkpoint 03-10-2013 17:41:55 Scheduled Checkpoint 07-10-2013 14:16:24 Nitro Reader 3 wird installiert ==================== Hosts content: ========================== 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {17ECAE68-43EC-4CB4-B0B1-29F4A6F36B46} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated) Task: {1FB223CD-F522-4D7B-A7F8-6714B6E55D12} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe [2013-04-30] () Task: {37D98794-0B73-425E-9761-F8D2B6F0E24D} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-05-11] (Adobe Systems Incorporated) Task: {439449E1-6296-4384-BE2D-DF615DD02671} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-05-24] (Piriform Ltd) Task: {5360D152-957F-43AA-9775-F07013B00CA7} - System32\Tasks\Plus-HD-1.6-updater => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-updater.exe [2013-07-04] (Plus HD) Task: {60E85A5F-55CC-42DA-AD34-356F633E5D8F} - System32\Tasks\Plus-HD-1.6-enabler => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-enabler.exe [2013-07-04] (Plus HD) Task: {71FC1B79-D268-43ED-A68B-3C9E16FB207C} - System32\Tasks\Plus-HD-1.6-chromeinstaller => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-chromeinstaller.exe [2013-07-04] (Plus HD) Task: {9844A5F2-7142-4CDD-B35E-8F4AD4A7A80A} - System32\Tasks\Plus-HD-1.6-codedownloader => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-codedownloader.exe [2013-07-04] (Plus HD) Task: {9C8BE657-C20D-4A55-BA7A-25E9A05D0721} - System32\Tasks\Plus-HD-1.6-firefoxinstaller => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-firefoxinstaller.exe [2013-07-04] (Plus HD) Task: {B3D6D9C7-0559-4455-878E-A51FEF5E3F25} - System32\Tasks\Google Updater and Installer => C:\Users\christa\AppData\Local\Google\Update\GoogleUpdate.exe Task: {B4789B48-4CDD-4B0D-A546-53E75F360FB2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-07] (Google Inc.) Task: {CE3C842B-C75B-4FD4-8D81-A9985D080004} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\TuneUp Utilities 2013\OneClick.exe [2013-01-28] (TuneUp Software) Task: {F979C97B-CE3D-485E-A1F5-98C418AB7F49} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-07] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Plus-HD-1.6-chromeinstaller.job => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-chromeinstaller.exe Task: C:\Windows\Tasks\Plus-HD-1.6-codedownloader.job => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-codedownloader.exe Task: C:\Windows\Tasks\Plus-HD-1.6-enabler.job => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-enabler.exe Task: C:\Windows\Tasks\Plus-HD-1.6-firefoxinstaller.job => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-firefoxinstaller.exe Task: C:\Windows\Tasks\Plus-HD-1.6-updater.job => C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-updater.exe ==================== Loaded Modules (whitelisted) ============= 2013-06-17 22:09 - 2013-01-25 10:25 - 00397704 _____ () C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll 2013-06-19 14:15 - 2003-09-14 21:08 - 00409667 _____ () C:\Programme\mySQL\bin\LIBMYSQL.dll 2013-09-18 14:33 - 2013-09-18 14:34 - 03279768 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-09-12 20:50 - 2013-09-12 20:50 - 16177544 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: PCI Simple Communications Controller Description: PCI Simple Communications Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (10/10/2013 10:17:14 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (10/10/2013 10:17:14 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (10/10/2013 10:15:21 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/10/2013 07:52:56 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/10/2013 07:52:32 AM) (Source: Windows Search Service) (User: ) Description: The index cannot be initialized. Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (10/10/2013 07:52:32 AM) (Source: Windows Search Service) (User: ) Description: The application cannot be initialized. Context: Windows Application Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (10/10/2013 07:52:32 AM) (Source: Windows Search Service) (User: ) Description: The gatherer object cannot be initialized. Context: Windows Application, SystemIndex Catalog Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (10/10/2013 07:52:32 AM) (Source: Windows Search Service) (User: ) Description: The plug-in in <Search.TripoliIndexer> cannot be initialized. Context: Windows Application, SystemIndex Catalog Details: Element not found. (HRESULT : 0x80070490) (0x80070490) Error: (10/10/2013 07:52:31 AM) (Source: Windows Search Service) (User: ) Description: The plug-in in <Search.JetPropStore> cannot be initialized. Context: Windows Application, SystemIndex Catalog Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (10/10/2013 07:52:31 AM) (Source: Windows Search Service) (User: ) Description: The Windows Search Service cannot load the property store information. Context: Windows Application, SystemIndex Catalog Details: The content index database is corrupt. (HRESULT : 0xc0041800) (0xc0041800) System errors: ============= Error: (10/10/2013 10:13:38 AM) (Source: atikmdag) (User: ) Description: Display is not active Error: (10/10/2013 10:13:38 AM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (10/10/2013 10:13:38 AM) (Source: EventLog) (User: ) Description: The previous system shutdown at 09:13:05 on 10.10.2013 was unexpected. Error: (10/10/2013 08:50:47 AM) (Source: atikmdag) (User: ) Description: Display is not active Error: (10/10/2013 07:52:32 AM) (Source: Service Control Manager) (User: ) Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (10/10/2013 07:52:32 AM) (Source: Service Control Manager) (User: ) Description: The Windows Search service terminated with service-specific error %%-1073473535. Error: (10/10/2013 07:51:13 AM) (Source: atikmdag) (User: ) Description: Display is not active Error: (10/10/2013 07:51:13 AM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (10/10/2013 07:51:14 AM) (Source: EventLog) (User: ) Description: The previous system shutdown at 19:39:43 on 09.10.2013 was unexpected. Error: (10/09/2013 04:22:31 PM) (Source: atikmdag) (User: ) Description: Display is not active Microsoft Office Sessions: ========================= Error: (10/10/2013 10:17:14 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT AUTHORITY) Description: WmiApRplWmiApRpl8F20300004D070000 Error: (10/10/2013 10:17:14 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT AUTHORITY) Description: Performance1637070000000000000000000009030000 Error: (10/10/2013 10:15:21 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/10/2013 07:52:56 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/10/2013 07:52:32 AM) (Source: Windows Search Service)(User: ) Description: Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (10/10/2013 07:52:32 AM) (Source: Windows Search Service)(User: ) Description: Context: Windows Application Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (10/10/2013 07:52:32 AM) (Source: Windows Search Service)(User: ) Description: Context: Windows Application, SystemIndex Catalog Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (10/10/2013 07:52:32 AM) (Source: Windows Search Service)(User: ) Description: Context: Windows Application, SystemIndex Catalog Details: Element not found. (HRESULT : 0x80070490) (0x80070490) Search.TripoliIndexer Error: (10/10/2013 07:52:31 AM) (Source: Windows Search Service)(User: ) Description: Context: Windows Application, SystemIndex Catalog Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Search.JetPropStore Error: (10/10/2013 07:52:31 AM) (Source: Windows Search Service)(User: ) Description: Context: Windows Application, SystemIndex Catalog Details: The content index database is corrupt. (HRESULT : 0xc0041800) (0xc0041800) ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 2996.52 MB Available physical RAM: 1665.84 MB Total Pagefile: 5991.34 MB Available Pagefile: 4343.55 MB Total Virtual: 2047.88 MB Available Virtual: 1917 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:288.23 GB) (Free:240.82 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: E6356DA8) Partition 1: (Not Active) - (Size=100 MB) - (Type=DE) Partition 2: (Active) - (Size=10 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=288 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
10.10.2013, 10:27 | #4 |
/// TB-Ausbilder | habe Probleme mit MonsterMarketplace.com ok. Schritt 1
Schritt 2 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 3 Starte noch einmal FRST.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
10.10.2013, 11:53 | #5 |
| habe Probleme mit MonsterMarketplace.com AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.007 - Report created 10/10/2013 at 12:46:38 # Updated 09/10/2013 by Xplode # Operating System : Windows 7 Ultimate Service Pack 1 (32 bits) # Username : christa - CHRISTA-PC # Running from : C:\Users\christa\Downloads\adwcleaner(1).exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp ***** [ Shortcuts ] ***** ***** [ Registry ] ***** ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16686 -\\ Mozilla Firefox v24.0 (de) [ File : C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\mvpym892.default\prefs.js ] -\\ Google Chrome v30.0.1599.69 [ File : C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [14832 octets] - [10/10/2013 12:37:14] AdwCleaner[R1].txt - [1149 octets] - [10/10/2013 12:46:08] AdwCleaner[S0].txt - [14948 octets] - [10/10/2013 12:39:18] AdwCleaner[S1].txt - [1073 octets] - [10/10/2013 12:46:38] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1133 octets] ########## FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013 Ran by christa (administrator) on CHRISTA-PC on 10-10-2013 12:51:40 Running from C:\Users\christa\Downloads Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe () C:\Programme\mySQL\bin\Mysqld-nt.exe (Nitro PDF Software) C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (MySQL AB) C:\Programme\mySQL\bin\winmysqladmin.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (Farbar) C:\Users\christa\Downloads\FRST(1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [] - [x] HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-07] (Avira Operations GmbH & Co. KG) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) MountPoints2: {ada2a755-e216-11e2-ab3c-0026b917f939} - F:\LaunchU3.exe -a MountPoints2: {ada2a7a5-e216-11e2-ab3c-0026b917f939} - F:\AutoRun.exe Startup: C:\Users\christa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mySQL.lnk ShortcutTarget: mySQL.lnk -> C:\Programme\mySQL\bin\winmysqladmin.exe (MySQL AB) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2B5ACA2C4B60CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {E779A530-EFFF-4BF7-8985-7159A6D21394} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=cddcab32-fdf9-482b-8061-f99d4686b12b&apn_sauid=6B0DD5B2-15D7-464D-AB46-0F57819BC20E DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\mvpym892.default FF NewTab: user_pref("browser.newtab.url", ""); FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF Homepage: hxxp://www.spiegel.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @nitropdf.com/NitroPDF - C:\Program Files\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\mvpym892.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} Chrome: ======= CHR Extension: (Avira Toolbar) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaabfjnbeinlpljodiajipidiompfl\7.15.26.0_0 CHR Extension: (Docs) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (Google Drive) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0 CHR Extension: (YouTube) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (Skype Click to Call) - C:\Users\christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.12.0.13601_0 CHR HKLM\...\Chrome\Extension: [aaaaabfjnbeinlpljodiajipidiompfl] - C:\Users\christa\AppData\Local\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.26.0.crx CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440392 2013-10-07] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-07] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-07] (Avira Operations GmbH & Co. KG) R2 mySQL; C:\Programme\mySQL\bin\Mysqld-nt.exe [1142784 2003-09-14] () R2 NitroReaderDriverReadSpool3; C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe [196624 2013-07-26] (Nitro PDF Software) R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3273088 2013-09-16] (Skype Technologies S.A.) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1724192 2013-01-28] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-10-07] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-10-07] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-11-16] (TuneUp Software) S3 massfilter; system32\drivers\massfilter.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [x] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-10 12:36 - 2013-10-10 12:46 - 00000000 ____D C:\AdwCleaner 2013-10-10 12:36 - 2013-10-10 12:36 - 01048960 _____ C:\Users\christa\Downloads\adwcleaner.exe 2013-10-10 12:36 - 2013-10-10 12:36 - 01048960 _____ C:\Users\christa\Downloads\adwcleaner(1).exe 2013-10-10 10:13 - 2013-10-10 12:47 - 00000224 _____ C:\Windows\setupact.log 2013-10-10 10:13 - 2013-10-10 10:13 - 00000000 _____ C:\Windows\setuperr.log 2013-10-10 07:53 - 2013-10-10 12:46 - 00126950 _____ C:\Windows\WindowsUpdate.log 2013-10-08 08:23 - 2013-10-08 08:23 - 01087213 _____ (Farbar) C:\Users\christa\Downloads\FRST(1).exe 2013-10-07 19:17 - 2013-10-10 11:03 - 00013641 _____ C:\Users\christa\Downloads\Addition.txt 2013-10-07 19:17 - 2013-10-07 19:17 - 00000000 ____D C:\FRST 2013-10-07 18:53 - 2013-10-07 18:53 - 01087213 _____ (Farbar) C:\Users\christa\Downloads\FRST.exe 2013-10-07 16:57 - 2013-10-07 16:57 - 00002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-07 16:53 - 2013-10-10 12:47 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-07 16:53 - 2013-10-10 12:16 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-07 16:53 - 2013-10-07 16:57 - 00000000 ____D C:\Program Files\Google 2013-10-07 16:21 - 2013-10-07 16:21 - 06175328 _____ C:\Users\christa\Downloads\Berlin_20130821.pptx 2013-10-07 16:17 - 2013-10-07 16:17 - 00000000 ____D C:\Users\christa\AppData\Roaming\Nitro 2013-10-07 16:16 - 2013-10-07 16:16 - 00001961 _____ C:\Users\Public\Desktop\Nitro Reader.lnk 2013-10-07 16:16 - 2013-10-07 16:16 - 00000000 ____D C:\ProgramData\Nitro 2013-10-07 16:16 - 2013-10-07 16:16 - 00000000 ____D C:\Program Files\Nitro 2013-10-07 16:16 - 2013-10-07 16:16 - 00000000 ____D C:\Program Files\Common Files\Nitro 2013-10-07 16:16 - 2013-07-26 06:57 - 00027152 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalmon2.dll 2013-10-07 16:16 - 2013-07-26 06:57 - 00018448 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalui2.dll 2013-10-07 16:15 - 2013-10-07 16:15 - 01679552 _____ (Solid State Networks) C:\Users\christa\Downloads\nitro_pdf_reader3565_32_dlm.exe 2013-10-07 16:13 - 2013-10-07 16:16 - 00000000 ____D C:\Users\christa\AppData\Roaming\Downloaded Installations 2013-10-07 16:12 - 2013-10-07 16:12 - 01678960 _____ (Solid State Networks) C:\Users\christa\Downloads\nitro_pdf_reader3565_64_dlm(1).exe 2013-10-07 16:11 - 2013-10-07 16:11 - 01678960 _____ (Solid State Networks) C:\Users\christa\Downloads\nitro_pdf_reader3565_64_dlm.exe 2013-10-07 16:05 - 2013-10-07 16:24 - 00000000 ____D C:\Users\christa\Documents\Mietausfall.de 2013-10-07 16:03 - 2013-10-07 16:03 - 10285321 _____ C:\Users\christa\Downloads\mietausfall_de.zip 2013-10-06 14:05 - 2013-10-06 20:05 - 99477982 _____ C:\Windows\system32\꞊窞k 2013-10-05 16:02 - 2013-10-05 16:02 - 99359319 _____ C:\Windows\system32\㹎ﵺb 2013-10-05 09:11 - 2013-10-05 09:11 - 99319274 _____ C:\Windows\system32\ﴫj 2013-10-04 14:48 - 2013-10-04 14:48 - 99209434 _____ C:\Windows\system32\妡g 2013-10-04 08:47 - 2013-10-04 08:47 - 99176917 _____ C:\Windows\system32\�溬c 2013-10-03 20:53 - 2013-10-03 20:53 - 99160839 _____ C:\Windows\system32\藍ဃz 2013-10-03 14:53 - 2013-10-03 14:53 - 99102760 _____ C:\Windows\system32\偒�r 2013-10-03 08:36 - 2013-10-03 08:36 - 98878632 _____ C:\Windows\system32\ꥱ첰^ 2013-10-02 20:38 - 2013-10-02 20:38 - 98834313 _____ C:\Windows\system32\翷䁻[ 2013-10-02 14:38 - 2013-10-02 14:38 - 98743931 _____ C:\Windows\system32\┒뛜] 2013-10-02 14:21 - 2013-10-07 11:10 - 00000000 ____D C:\Users\christa\Documents\Q-Plain 2013-10-02 08:38 - 2013-10-02 08:38 - 98712514 _____ C:\Windows\system32\䔯[ 2013-10-01 21:20 - 2013-10-01 21:20 - 98612549 _____ C:\Windows\system32\ḿ` 2013-10-01 09:54 - 2013-10-01 09:56 - 68977688 _____ C:\Users\christa\Downloads\PS7510_1315.exe 2013-10-01 09:45 - 2013-10-01 09:46 - 25999288 _____ C:\Users\christa\Downloads\PS7510_Basicx86_1315(1).exe 2013-10-01 07:46 - 2013-10-01 07:46 - 98602865 _____ C:\Windows\system32\ᴍ粛_ 2013-09-30 13:01 - 2012-10-17 04:04 - 00580712 ____N (Hewlett-Packard Co.) C:\Windows\system32\HPDiscoPMA611.dll 2013-09-30 13:00 - 2013-09-30 13:02 - 00000000 ____D C:\Users\christa\AppData\Local\HP 2013-09-30 13:00 - 2013-09-30 13:00 - 00000057 _____ C:\ProgramData\Ament.ini 2013-09-30 13:00 - 2013-09-30 13:00 - 00000000 ____D C:\ProgramData\HP 2013-09-30 13:00 - 2013-09-30 13:00 - 00000000 ____D C:\Program Files\HP 2013-09-30 12:59 - 2013-09-30 13:00 - 25999288 _____ C:\Users\christa\Downloads\PS7510_Basicx86_1315.exe 2013-09-29 09:25 - 2013-09-29 18:26 - 98466785 _____ C:\Windows\system32\ꢮﰥa 2013-09-27 12:06 - 2013-09-27 12:06 - 98201609 _____ C:\Windows\system32\淅ᰱ` 2013-09-26 18:14 - 2013-09-26 18:14 - 97961477 _____ C:\Windows\system32\侽�] 2013-09-26 12:13 - 2013-09-26 12:13 - 97927968 _____ C:\Windows\system32\i 2013-09-25 12:31 - 2013-09-25 12:31 - 97717271 _____ C:\Windows\system32\ㅑ䍖e 2013-09-24 12:12 - 2013-09-24 18:12 - 97531747 _____ C:\Windows\system32\桝炇d 2013-09-24 01:09 - 2013-09-24 01:09 - 98798431 _____ C:\Windows\system32\色쥝i 2013-09-23 12:11 - 2013-09-23 18:16 - 98674763 _____ C:\Windows\system32\䗫㚺Y 2013-09-20 09:11 - 2013-09-20 09:11 - 98453713 _____ C:\Windows\system32\ꤌ烷i 2013-09-19 11:56 - 2013-09-19 11:56 - 98343078 _____ C:\Windows\system32\명栕b 2013-09-18 20:55 - 2013-09-18 20:55 - 98177822 _____ C:\Windows\system32\뼺ይg 2013-09-18 14:33 - 2013-09-18 14:34 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-17 10:18 - 2013-09-17 18:11 - 97949955 _____ C:\Windows\system32\樍毲f 2013-09-16 17:36 - 2013-09-17 01:11 - 97872530 _____ C:\Windows\system32\ࠈ퍱j 2013-09-16 11:36 - 2013-09-16 11:36 - 97745148 _____ C:\Windows\system32\ჱf 2013-09-15 21:01 - 2013-09-15 21:01 - 97671483 _____ C:\Windows\system32\䲊첷n 2013-09-14 16:24 - 2013-09-14 16:24 - 97581476 _____ C:\Windows\system32\왆Ꮺg 2013-09-13 11:10 - 2013-09-13 17:10 - 97492159 _____ C:\Windows\system32\€t 2013-09-12 20:25 - 2013-09-12 20:25 - 97373152 _____ C:\Windows\system32\훵垘r 2013-09-12 11:23 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 11:23 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 11:23 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-12 11:23 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 11:23 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-12 11:23 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 11:23 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-11 11:26 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 11:26 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-11 11:26 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-11 11:26 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-11 11:26 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 11:26 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 11:26 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-11 11:26 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-11 11:20 - 2013-09-11 11:20 - 97080355 _____ C:\Windows\system32\짳æb 2013-09-10 11:31 - 2013-09-10 18:40 - 96985259 _____ C:\Windows\system32\⒧嫖W ==================== One Month Modified Files and Folders ======= 2013-10-10 12:51 - 2013-10-10 07:53 - 00126950 _____ C:\Windows\WindowsUpdate.log 2013-10-10 12:50 - 2013-06-03 13:22 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-10 12:48 - 2013-06-05 13:14 - 00000000 ____D C:\Users\christa\AppData\Roaming\Skype 2013-10-10 12:47 - 2013-10-10 10:13 - 00000224 _____ C:\Windows\setupact.log 2013-10-10 12:47 - 2013-10-07 16:53 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-10 12:47 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-10 12:46 - 2013-10-10 12:36 - 00000000 ____D C:\AdwCleaner 2013-10-10 12:46 - 2009-07-14 06:34 - 00016864 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-10 12:46 - 2009-07-14 06:34 - 00016864 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-10 12:36 - 2013-10-10 12:36 - 01048960 _____ C:\Users\christa\Downloads\adwcleaner.exe 2013-10-10 12:36 - 2013-10-10 12:36 - 01048960 _____ C:\Users\christa\Downloads\adwcleaner(1).exe 2013-10-10 12:16 - 2013-10-07 16:53 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-10 11:03 - 2013-10-07 19:17 - 00013641 _____ C:\Users\christa\Downloads\Addition.txt 2013-10-10 10:17 - 2010-11-20 23:01 - 00004522 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-10 10:13 - 2013-10-10 10:13 - 00000000 _____ C:\Windows\setuperr.log 2013-10-10 07:53 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\LogFiles 2013-10-09 16:23 - 2013-06-03 13:22 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-10-09 16:23 - 2013-06-03 13:22 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-10-08 13:27 - 2013-06-03 13:13 - 00000000 ____D C:\Users\christa\AppData\Local\Google 2013-10-08 08:23 - 2013-10-08 08:23 - 01087213 _____ (Farbar) C:\Users\christa\Downloads\FRST(1).exe 2013-10-07 19:17 - 2013-10-07 19:17 - 00000000 ____D C:\FRST 2013-10-07 18:53 - 2013-10-07 18:53 - 01087213 _____ (Farbar) C:\Users\christa\Downloads\FRST.exe 2013-10-07 16:57 - 2013-10-07 16:57 - 00002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-07 16:57 - 2013-10-07 16:53 - 00000000 ____D C:\Program Files\Google 2013-10-07 16:24 - 2013-10-07 16:05 - 00000000 ____D C:\Users\christa\Documents\Mietausfall.de 2013-10-07 16:21 - 2013-10-07 16:21 - 06175328 _____ C:\Users\christa\Downloads\Berlin_20130821.pptx 2013-10-07 16:17 - 2013-10-07 16:17 - 00000000 ____D C:\Users\christa\AppData\Roaming\Nitro 2013-10-07 16:16 - 2013-10-07 16:16 - 00001961 _____ C:\Users\Public\Desktop\Nitro Reader.lnk 2013-10-07 16:16 - 2013-10-07 16:16 - 00000000 ____D C:\ProgramData\Nitro 2013-10-07 16:16 - 2013-10-07 16:16 - 00000000 ____D C:\Program Files\Nitro 2013-10-07 16:16 - 2013-10-07 16:16 - 00000000 ____D C:\Program Files\Common Files\Nitro 2013-10-07 16:16 - 2013-10-07 16:13 - 00000000 ____D C:\Users\christa\AppData\Roaming\Downloaded Installations 2013-10-07 16:15 - 2013-10-07 16:15 - 01679552 _____ (Solid State Networks) C:\Users\christa\Downloads\nitro_pdf_reader3565_32_dlm.exe 2013-10-07 16:12 - 2013-10-07 16:12 - 01678960 _____ (Solid State Networks) C:\Users\christa\Downloads\nitro_pdf_reader3565_64_dlm(1).exe 2013-10-07 16:11 - 2013-10-07 16:11 - 01678960 _____ (Solid State Networks) C:\Users\christa\Downloads\nitro_pdf_reader3565_64_dlm.exe 2013-10-07 16:03 - 2013-10-07 16:03 - 10285321 _____ C:\Users\christa\Downloads\mietausfall_de.zip 2013-10-07 14:39 - 2013-06-17 22:11 - 00067680 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-10-07 14:39 - 2013-06-17 22:09 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-10-07 14:39 - 2013-06-17 22:09 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-10-07 14:39 - 2013-06-17 22:09 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-10-07 11:10 - 2013-10-02 14:21 - 00000000 ____D C:\Users\christa\Documents\Q-Plain 2013-10-06 20:05 - 2013-10-06 14:05 - 99477982 _____ C:\Windows\system32\꞊窞k 2013-10-05 16:02 - 2013-10-05 16:02 - 99359319 _____ C:\Windows\system32\㹎ﵺb 2013-10-05 09:11 - 2013-10-05 09:11 - 99319274 _____ C:\Windows\system32\ﴫj 2013-10-04 14:48 - 2013-10-04 14:48 - 99209434 _____ C:\Windows\system32\妡g 2013-10-04 14:47 - 2009-07-14 06:53 - 00032638 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-04 08:47 - 2013-10-04 08:47 - 99176917 _____ C:\Windows\system32\�溬c 2013-10-03 20:53 - 2013-10-03 20:53 - 99160839 _____ C:\Windows\system32\藍ဃz 2013-10-03 14:53 - 2013-10-03 14:53 - 99102760 _____ C:\Windows\system32\偒�r 2013-10-03 08:36 - 2013-10-03 08:36 - 98878632 _____ C:\Windows\system32\ꥱ첰^ 2013-10-02 20:38 - 2013-10-02 20:38 - 98834313 _____ C:\Windows\system32\翷䁻[ 2013-10-02 14:38 - 2013-10-02 14:38 - 98743931 _____ C:\Windows\system32\┒뛜] 2013-10-02 08:38 - 2013-10-02 08:38 - 98712514 _____ C:\Windows\system32\䔯[ 2013-10-01 21:20 - 2013-10-01 21:20 - 98612549 _____ C:\Windows\system32\ḿ` 2013-10-01 09:56 - 2013-10-01 09:54 - 68977688 _____ C:\Users\christa\Downloads\PS7510_1315.exe 2013-10-01 09:52 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2013-10-01 09:46 - 2013-10-01 09:45 - 25999288 _____ C:\Users\christa\Downloads\PS7510_Basicx86_1315(1).exe 2013-10-01 07:46 - 2013-10-01 07:46 - 98602865 _____ C:\Windows\system32\ᴍ粛_ 2013-09-30 13:02 - 2013-09-30 13:00 - 00000000 ____D C:\Users\christa\AppData\Local\HP 2013-09-30 13:00 - 2013-09-30 13:00 - 00000057 _____ C:\ProgramData\Ament.ini 2013-09-30 13:00 - 2013-09-30 13:00 - 00000000 ____D C:\ProgramData\HP 2013-09-30 13:00 - 2013-09-30 13:00 - 00000000 ____D C:\Program Files\HP 2013-09-30 13:00 - 2013-09-30 12:59 - 25999288 _____ C:\Users\christa\Downloads\PS7510_Basicx86_1315.exe 2013-09-30 13:00 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\twain_32 2013-09-29 18:26 - 2013-09-29 09:25 - 98466785 _____ C:\Windows\system32\ꢮﰥa 2013-09-27 12:06 - 2013-09-27 12:06 - 98201609 _____ C:\Windows\system32\淅ᰱ` 2013-09-26 18:14 - 2013-09-26 18:14 - 97961477 _____ C:\Windows\system32\侽�] 2013-09-26 12:14 - 2013-06-05 13:14 - 00000000 ___RD C:\Program Files\Skype 2013-09-26 12:13 - 2013-09-26 12:13 - 97927968 _____ C:\Windows\system32\i 2013-09-25 12:31 - 2013-09-25 12:31 - 97717271 _____ C:\Windows\system32\ㅑ䍖e 2013-09-24 18:12 - 2013-09-24 12:12 - 97531747 _____ C:\Windows\system32\桝炇d 2013-09-24 01:09 - 2013-09-24 01:09 - 98798431 _____ C:\Windows\system32\色쥝i 2013-09-23 18:16 - 2013-09-23 12:11 - 98674763 _____ C:\Windows\system32\䗫㚺Y 2013-09-20 09:11 - 2013-09-20 09:11 - 98453713 _____ C:\Windows\system32\ꤌ烷i 2013-09-19 11:56 - 2013-09-19 11:56 - 98343078 _____ C:\Windows\system32\명栕b 2013-09-19 11:55 - 2013-06-17 21:45 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-09-18 20:56 - 2013-06-17 21:45 - 00000000 ____D C:\Users\christa\AppData\Local\Mozilla 2013-09-18 20:55 - 2013-09-18 20:55 - 98177822 _____ C:\Windows\system32\뼺ይg 2013-09-18 14:34 - 2013-09-18 14:33 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-17 18:11 - 2013-09-17 10:18 - 97949955 _____ C:\Windows\system32\樍毲f 2013-09-17 01:11 - 2013-09-16 17:36 - 97872530 _____ C:\Windows\system32\ࠈ퍱j 2013-09-16 11:36 - 2013-09-16 11:36 - 97745148 _____ C:\Windows\system32\ჱf 2013-09-15 21:01 - 2013-09-15 21:01 - 97671483 _____ C:\Windows\system32\䲊첷n 2013-09-14 18:35 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-09-14 16:24 - 2013-09-14 16:24 - 97581476 _____ C:\Windows\system32\왆Ꮺg 2013-09-13 17:10 - 2013-09-13 11:10 - 97492159 _____ C:\Windows\system32\€t 2013-09-12 20:25 - 2013-09-12 20:25 - 97373152 _____ C:\Windows\system32\훵垘r 2013-09-12 14:28 - 2013-06-03 22:49 - 00000000 ____D C:\Windows\Panther 2013-09-12 14:22 - 2009-07-14 06:33 - 00265640 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-11 11:20 - 2013-09-11 11:20 - 97080355 _____ C:\Windows\system32\짳æb 2013-09-10 18:40 - 2013-09-10 11:31 - 96985259 _____ C:\Windows\system32\⒧嫖W Some content of TEMP: ==================== C:\Users\christa\AppData\Local\Temp\avgnt.exe C:\Users\christa\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-02 09:38 ==================== End Of Log ============================ --- --- --- |
10.10.2013, 11:55 | #6 |
/// TB-Ausbilder | habe Probleme mit MonsterMarketplace.com Sind die Probleme jetzt verschwunden? Schritt 1 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 2 ESET Online Scanner
__________________ --> habe Probleme mit MonsterMarketplace.com |
10.10.2013, 13:09 | #7 |
| habe Probleme mit MonsterMarketplace.com Ja, die Probleme sind weg, SUPER!!! hier die Datei Malwarebytes Anti-Malware (Test) 1.75.0.1300 Malwarebytes : Free Anti-Malware download Datenbank Version: v2013.10.10.03 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16686 christa :: CHRISTA-PC [Administrator] Schutz: Aktiviert 10.10.2013 13:12:04 mbam-log-2013-10-10 (13-12-04).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 182711 Laufzeit: 4 Minute(n), 55 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 7 C:\Users\christa\Downloads\CodecPerformerSetup.exe (PUP.Optional.Performersoft) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\christa\Downloads\CodecPerformerSetup (1).exe (PUP.Optional.Performersoft) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\christa\Downloads\CodecPerformerSetup (2).exe (PUP.Optional.Performersoft) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\christa\Downloads\CodecPerformerSetup (3).exe (PUP.Optional.Performersoft) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\christa\Downloads\TVSetup(1).exe (PUP.Optional.Inbox) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\christa\Downloads\TVSetup.exe (PUP.Optional.Inbox) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\christa\Downloads\Virtual Piano.exe (PUP.Optional.Solimba) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=5d5a24a32cb76e4cb88a563502734bea # engine=15431 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-10-10 11:30:51 # local_time=2013-10-10 01:30:51 (+0100, W. Europe Daylight Time) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 97 20339 246827941 13117 0 # compatibility_mode=5893 16776574 100 94 7785773 133035842 0 0 # scanned=3775 # found=1 # cleaned=0 # scan_time=77 sh=D728152D9314430ABD6B1F662E5395DCDE0C5FD4 ft=0 fh=0000000000000000 vn="Win32/AdWare.AddLyrics.T application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\LyricsContainer\133.crx.vir" ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=5d5a24a32cb76e4cb88a563502734bea # engine=15431 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-10-10 11:57:53 # local_time=2013-10-10 01:57:53 (+0100, W. Europe Daylight Time) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 97 21961 246829563 14739 0 # compatibility_mode=5893 16776574 100 94 7787395 133037464 0 0 # scanned=76577 # found=1 # cleaned=0 # scan_time=1549 sh=D728152D9314430ABD6B1F662E5395DCDE0C5FD4 ft=0 fh=0000000000000000 vn="Win32/AdWare.AddLyrics.T application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\LyricsContainer\133.crx.vir" |
10.10.2013, 13:31 | #8 |
/// TB-Ausbilder | habe Probleme mit MonsterMarketplace.com Prima. Räumen wir auf. Schritt 1 Die Version deines Adobe PDF Readers ist veraltet, wir müssen ihn updaten:
Überprüfe dann mit diesem Plugin-Check (mit dem Firefox hier), ob nun alle deine verwendeten Versionen aktuell sind und update sie anderenfalls. Cleanup Zum Schluss werden wir jetzt noch unsere Tools (inklusive der Quarantäne-Ordner) wegräumen, die verseuchten Systemwiederherstellungspunkte löschen und alle Einstellungen wieder herrichten. Auch diese Schritte sind noch wichtig und sollten in der angegebenen Reihenfolge ausgeführt werden.
>> OK << Wir sind durch, deine Logs sehen für mich im Moment sauber aus. Ich habe dir nachfolgend ein paar Hinweise und Tipps zusammengestellt, die dazu beitragen sollen, dass du in Zukunft unsere Hilfe nicht mehr brauchen wirst. Bitte gib mir danach noch eine kurze Rückmeldung, wenn auch von deiner Seite keine Probleme oder Fragen mehr offen sind, damit ich dieses Thema als erledigt betrachten kann. Epilog: Tipps, Dos & Don'ts Aktualität von System und Software Das Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die automatischen Updates aktiviert sind:
Auch die installierte Software sollte immer in der aktuellsten Version vorliegen. Speziell gilt das für den Browser, Java, Flash-Player und PDF-Reader, denn bekannte Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim blossen Besuch einer präparierten Website per Drive-by Download Malware zu installieren. Das kann sogar auf normalerweise legitimen Websites geschehen, wenn es einem Angreifer gelungen ist, seinen Code in die Seite einzuschleusen, und ist deshalb relativ unberechenbar.
Sicherheits-Software Eine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine verseuchte Datei nicht erkennt). Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt. Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons zur Empfehlung gibt:
(Un-)Sicheres Verhalten im Internet Nebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert. Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
Allgemeine Hinweise Abschliessend noch ein paar grundsätzliche Bemerkungen:
Wenn du möchtest, kannst du das Forum mit einer kleinen Spende unterstützen. Es bleibt mir nur noch, dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen.
__________________ cheers, Leo |
11.10.2013, 07:47 | #9 |
| habe Probleme mit MonsterMarketplace.com Hallo Leo, es läuft nun alles super. Vielen Dank für deine Hilfe. Ich werde euch auf jeden Fall weiter empfehlen. Spende ist unterwegs. Schöne Grüsse Uwe |
11.10.2013, 08:54 | #10 |
/// TB-Ausbilder | habe Probleme mit MonsterMarketplace.com Danke für die Rückmeldung, Uwe. Und im Namen des Teams vielen Dank für die Spende! Freut mich, dass wir helfen konnten. Falls du dem Forum noch Verbesserungsvorschläge, Kritik oder ein Lob mitgeben möchtest, kannst du das hier tun. Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten. Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter. Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.
__________________ cheers, Leo |
Themen zu habe Probleme mit MonsterMarketplace.com |
32 bit, avira, dankbar, festgestellt, firefox, free, gestellt, hilfe, monstermarketplace.com, neu, popup, probleme, pup.optional.inbox, pup.optional.performersoft, pup.optional.solimba, servicepack, stören, tagen, ultima, ultimate, verhalten, win32/adware.addlyrics.t, windows, windows 7, windows 7 ultimate |