|
Plagegeister aller Art und deren Bekämpfung: Win 7: Nervige Pop-Ups bzw. "überblendete" WerbungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
23.10.2013, 09:47 | #1 |
| Win 7: Nervige Pop-Ups bzw. "überblendete" Werbung Hallo zusammen, seit geraumer Zeit kämpfe ich mit echt nervigen Werbeformen. Zum einen Pop-Ups, obwohl ich diese blockiert eingestellt habe. Zum anderen legt sich die Werbung wie ein Schleier über die Seite, die ich eigentlich sehen will. Oft wird der Mauszeiger in dieser Werbung als Instrument zum Zielen für Interaktion dargestellt (Shooting, Ausziehen von Kleidungsstücken, ...). Die Fa. Star Games ist mir jetzt wiederholt als Werbetreibender aufgefallen. Irgendwelche wiederkehrende Muster bezüglich des Auftretens sind mir leider noch nicht aufgefallen... (doch...der genervte User...:-) ) Als permanenten PC-Schutz habe ich Kaspersky, ergänzt um CC-Cleaner, Ad Aware, Malwarebytes und adwcleaner. Habe schon einmal auf eigene Faust mit diesen Programmen mein Glück versucht, konnte das Phänomen bisher mit keinem der Programme stoppen... (den Hinweis in den Regeln habe ich erst danach gelesen... :-( ) Die Logdatei von Malwarebytes habe ich unten kopiert. In der Checkliste habe ich den Hinweis bzgl. der geschäftlichen Rechner gelesen. Wir haben ein kleines Einzelhandelsgeschäft, mein Laptop ist zwar dort als Gast auf den Server (Warenwirtschaft) eingebunden, aber eigentlich mein privater Laptop. IT-Abteilung habe ich nicht, nur einen Ein-Mann-Betrieb, der mir den Server für die Warenwirtschaft und rudimentäre Aufteilungen aufgesetzt hat. Falls das ein Ausschlusskriterium ist, schreibt es mir einfach, wäre zwar schade, aber nun mal Bestandteil der Regeln. Mag mir jemand helfen??? lg André Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.10.23.03 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 8.0.7601.17514 Andre.Gunkel :: LAPTOP-ANG [Administrator] 23.10.2013 10:21:14 MBAM-log-2013-10-23 (10-40-08).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 303989 Laufzeit: 11 Minute(n), 41 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|OMESupervisor (PUP.Optional.OfferMosquito.A) -> Daten: C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe (PUP.Optional.OfferMosquito.A) -> Keine Aktion durchgeführt. (Ende) |
23.10.2013, 11:35 | #2 |
/// the machine /// TB-Ausbilder | Win 7: Nervige Pop-Ups bzw. "überblendete" Werbung hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
23.10.2013, 12:35 | #3 |
| Win 7: Nervige Pop-Ups bzw. "überblendete" Werbung FRST Additions Logfile:
__________________FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-10-2013 Ran by Andre.Gunkel at 2013-10-23 13:26:08 Running from C:\Users\Andre.Gunkel\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Anti-Virus (Enabled - Up to date) {56547CC9-C9B2-849D-8FEF-A496150D6A06} AV: Ad-Aware Antivirus (Disabled - Out of date) {D87B6541-12A1-DAEA-0033-9B8057AAB996} AS: Ad-Aware Antivirus (Disabled - Out of date) {631A84A5-349B-D564-3A83-A0F22C2DF32B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Kaspersky Anti-Virus (Enabled - Up to date) {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} FW: Ad-Aware Firewall (Disabled) {E040E464-58CE-DBB2-2B6C-32B5A979FEED} FW: Kaspersky Anti-Virus (Disabled) {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D} ==================== Installed Programs ====================== Ad-Aware Antivirus (Version: 11.0.4516.0) AdAwareInstaller (Version: 11.0.4516.0) AdAwareUpdater (Version: 11.0.4516.0) Adobe Flash Player 11 ActiveX (Version: 11.9.900.117) Adobe Flash Player 11 Plugin (Version: 11.9.900.117) Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8) Ahnenblatt 2.67 (Version: 2.67.0.0) AntimalwareEngine (Version: 2.6.0.0) Apple Application Support (Version: 2.3.6) Apple Mobile Device Support (Version: 7.0.0.117) Apple Software Update (Version: 2.1.3.127) Bonjour (Version: 3.0.0.10) CCleaner (Version: 4.06) D3DX10 (Version: 15.4.2368.0902) Definition update for Microsoft Office 2010 (KB982726) Dropbox (HKCU Version: 2.0.22) Fotogalerie (Version: 16.4.3508.0205) Freemake Video Converter Version 4.0.4 (Version: 4.0.4) Google Earth (Version: 7.1.1.1888) HiPath 3000 Manager C 69.50.12.0 iCloud (Version: 3.0.2.163) Intel(R) Graphics Media Accelerator Driver (Version: 8.15.10.1892) Intel(R) TV Wizard iTunes (Version: 11.1.0.126) Java 7 Update 45 (Version: 7.0.450) Java Auto Updater (Version: 2.1.9.8) JMicron Flash Media Controller Driver (Version: 1.00.29.02) Kaspersky Anti-Virus 6.0 für Windows Workstation (Version: 6.0.4.1424) Kaspersky Lab Administrationsagent (Version: 8.0.2134) Launch Manager (Version: 3.0.07) Lightworks (Version: 11.1.0.0) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Office Access MUI (German) 2010 (Version: 14.0.4763.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.4763.1000) Microsoft Office Home and Business 2010 (Version: 14.0.4763.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.4763.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.4763.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.4763.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.4763.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.4763.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.4763.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.4763.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.4763.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.4763.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.4763.1000) Microsoft Office Single Image 2010 (Version: 14.0.4763.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.4763.1000) Microsoft Silverlight (Version: 4.0.60129.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0) Microsoft XML Parser (Version: 8.20.8730.4) Minianwendung "Desktoplinks" für Windows Small Business Server 2008 (Version: 6.0.5601.6) MobileMe Control Panel (Version: 3.1.8.0) Movie Maker (Version: 16.4.3508.0205) Mozilla Firefox 24.0 (x86 de) (Version: 24.0) Mozilla Maintenance Service (Version: 24.0) MSVCRT (Version: 15.4.2862.0708) MSVCRT110 (Version: 16.4.1108.0727) MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (Version: 4.30.2100.0) PDFCreator (Version: 1.2.1) Photo Common (Version: 16.4.3508.0205) Photo Gallery (Version: 16.4.3508.0205) Pixum Fotobuch PL-2303 USB-to-Serial (Version: 1.3.0) PMB (Version: 5.5.02.12220) QuickTime (Version: 7.74.80.86) RAPTOR-ADJUST M3 PLAT VERS 1.0 (Version: 1.0) RAPTOR-GAMING H3 7.1 USB Readiris Pro 10 Safari (Version: 5.34.57.2) Samsung Network PC Fax (Version: 1.05.22.00) Samsung Scan Assistant (Version: 1.04.20.00) Skype Click to Call (Version: 5.9.9216) Skype™ 6.6 (Version: 6.6.106) SmarThru 4 StarMoney (Version: 3.0.0.124) StarMoney (Version: 4.0.0.203) StarMoney 8.0 S-Edition (Version: 8.0) StarMoney 9.0 S-Edition (Version: 9.0) TeamViewer 5 (Version: 5.1.10408 ) TeamViewer 6 (Version: 6.0.11656) Update for Microsoft Office 2010 (KB2202188) Update for Microsoft Office 2010 (KB2413186) Update for Microsoft Office 2010 (KB2494150) Update for Microsoft OneNote 2010 (KB2493983) Update for Microsoft Outlook Social Connector (KB2289116) Update für Microsoft Outlook Social Connector (KB2289116) Wartung Samsung CLX-3180 Series Windows Live Communications Platform (Version: 16.4.3508.0205) Windows Live Essentials (Version: 16.4.3508.0205) Windows Live ID Sign-in Assistant (Version: 7.250.4311.0) Windows Live Installer (Version: 16.4.3508.0205) Windows Live Photo Common (Version: 16.4.3508.0205) Windows Live PIMT Platform (Version: 16.4.3508.0205) Windows Live SOXE (Version: 16.4.3508.0205) Windows Live SOXE Definitions (Version: 16.4.3508.0205) Windows Live UX Platform (Version: 16.4.3508.0205) Windows Live UX Platform Language Pack (Version: 16.4.3508.0205) Windows Mobile-Gerätecenter (Version: 6.1.6965.0) Windows Small Business Server 2008 ClientAgent (Version: 6.0.5601.6) Windows Small Business Server 2008 WMI Provider (Version: 6.0.5601.6) WinZip 15.0 (Version: 15.0.9411) WinZip Command Line Support Add-On 3.2 ==================== Restore Points ========================= 11-10-2013 13:28:56 AA11 11-10-2013 14:06:36 Integrity Tool wird entfernt 11-10-2013 21:13:51 DirectX wurde installiert 11-10-2013 21:15:10 Microsoft Visual C++ 2005 Redistributable wird installiert 12-10-2013 00:05:21 Windows Update 15-10-2013 07:01:32 AusweisApp wird entfernt 20-10-2013 11:34:33 Installed Java 7 Update 45 ==================== Hosts content: ========================== 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {01480A45-8778-4DA5-AEB8-C96B45297627} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {11796752-A3EF-4D5E-AC85-9B2E57E0605B} - System32\Tasks\{2BC13689-43E7-4AB5-AB15-A9EDBC6063C2} => C:\Program Files\Skype\\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {2945E918-B5D7-4A83-8579-5B3AFE21411F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {47C0988B-B6A0-4FCD-B542-2F417ADC6A64} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-03-25] (Google Inc.) Task: {4960BF7C-53F9-4D27-80D6-C1596946CD39} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-09-19] (Piriform Ltd) Task: {5D70C335-7E31-41B6-992C-C779CEF3675D} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation) Task: {91618413-79B3-46CA-BE8D-95C20121CD42} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-08] (Adobe Systems Incorporated) Task: {EB26DC93-6500-4D43-ACF3-269EE2D599B2} - System32\Tasks\{C7360B4F-594C-41F6-984C-AA10AA07AF2B} => C:\Program Files\Skype\\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {FCC2008E-E403-4B9B-A24F-582C7B79443C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-03-25] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2012-09-19 00:04 - 2009-10-31 15:42 - 01384520 _____ () C:\Windows\twain_32\Samsung\CLX3180\ssole.dll 2012-09-19 00:04 - 2010-11-11 11:46 - 00293888 _____ () C:\Windows\twain_32\Samsung\CLX3180\NetModule2.dll 2011-06-24 22:56 - 2011-06-24 22:56 - 00087328 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2011-06-24 22:56 - 2011-06-24 22:56 - 01241888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 00131920 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\pugixml.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 02038088 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\RCF.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 00048000 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\boost_date_time-vc100-mt-1_53.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 00107392 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\boost_filesystem-vc100-mt-1_53.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 00021880 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\boost_system-vc100-mt-1_53.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 00086904 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\boost_thread-vc100-mt-1_53.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 00405368 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\boost_locale-vc100-mt-1_53.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 00227168 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\HtmlFramework.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 00232272 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\Logger.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 00055128 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\DllStorage.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 00643952 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareTrayDefaultSkin.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 00119640 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\Localization.dll 2013-10-08 17:46 - 2013-10-08 17:46 - 00541008 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\SQLite.dll 2013-10-01 09:16 - 2013-10-01 09:17 - 03279768 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-10-08 22:00 - 2013-10-08 22:00 - 16233864 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/19/2013 01:53:13 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_9_900_117.exe, Version: 11.9.900.117, Zeitstempel: 0x5244d3b6 Name des fehlerhaften Moduls: FlashPlayerPlugin_11_9_900_117.exe, Version: 11.9.900.117, Zeitstempel: 0x5244d3b6 Ausnahmecode: 0x40000015 Fehleroffset: 0x00017b60 ID des fehlerhaften Prozesses: 0xac0 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_11_9_900_117.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_11_9_900_117.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_11_9_900_117.exe2 Berichtskennung: FlashPlayerPlugin_11_9_900_117.exe3 Error: (10/19/2013 08:54:32 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 23226910 Error: (10/19/2013 08:54:32 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 23226910 Error: (10/19/2013 08:54:32 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (10/19/2013 08:54:16 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 23211279 Error: (10/19/2013 08:54:16 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 23211279 Error: (10/19/2013 08:54:16 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (10/19/2013 08:54:01 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 23195695 Error: (10/19/2013 08:54:01 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 23195695 Error: (10/19/2013 08:54:01 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (10/23/2013 08:04:59 AM) (Source: Microsoft-Windows-GroupPolicy) (User: WEIS) Description: Bei der Verarbeitung der Gruppenrichtlinie ist aufgrund fehlender Netzwerkkonnektivität mit einem Domänencontroller ein Fehler aufgetreten. Dies kann eine vorübergehende Bedingung sein. Es wird eine Erfolgsmeldung generiert, wenn die Verbindung des Computers mit dem Domänencontroller wiederhergestellt wurde und wenn die Gruppenrichtlinie erfolgreich verarbeitet wurde. Falls für mehrere Stunden keine Erfolgsmeldung angezeigt wird, wenden Sie sich an den Administrator. Error: (10/23/2013 08:03:37 AM) (Source: Microsoft-Windows-GroupPolicy) (User: NT-AUTORITÄT) Description: Bei der Verarbeitung der Gruppenrichtlinie ist aufgrund fehlender Netzwerkkonnektivität mit einem Domänencontroller ein Fehler aufgetreten. Dies kann eine vorübergehende Bedingung sein. Es wird eine Erfolgsmeldung generiert, wenn die Verbindung des Computers mit dem Domänencontroller wiederhergestellt wurde und wenn die Gruppenrichtlinie erfolgreich verarbeitet wurde. Falls für mehrere Stunden keine Erfolgsmeldung angezeigt wird, wenden Sie sich an den Administrator. Error: (10/23/2013 08:03:22 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%20 Error: (10/23/2013 08:03:16 AM) (Source: NETLOGON) (User: ) Description: Der Computer konnte eine sichere Sitzung mit einem Domänencontroller in der Domäne WEIS aufgrund der folgenden Ursache nicht einrichten: %%1311 Dies kann zu Authentifizierungsproblemen führen. Stellen Sie sicher, dass der Computer mit dem Netzwerk verbunden ist. Wenden Sie sich an den Domänenadministrator, wenn das Problem weiterhin besteht. ZUSÄTZLICHE INFORMATIONEN Wenn dieser Computer ein Domänencontroller der bestimmten Domäne ist, wird eine sichere Sitzung zum primären Domänencontrolleremulator in der bestimmten Domäne eingerichtet. Andernfalls richtet dieser Computer eine sichere Sitzung zu einem beliebigen Domänencontroller in der bestimmten Domäne ein. Error: (10/22/2013 08:05:57 PM) (Source: Microsoft-Windows-GroupPolicy) (User: WEIS) Description: Bei der Verarbeitung der Gruppenrichtlinie ist aufgrund fehlender Netzwerkkonnektivität mit einem Domänencontroller ein Fehler aufgetreten. Dies kann eine vorübergehende Bedingung sein. Es wird eine Erfolgsmeldung generiert, wenn die Verbindung des Computers mit dem Domänencontroller wiederhergestellt wurde und wenn die Gruppenrichtlinie erfolgreich verarbeitet wurde. Falls für mehrere Stunden keine Erfolgsmeldung angezeigt wird, wenden Sie sich an den Administrator. Error: (10/22/2013 08:05:23 PM) (Source: TermService) (User: ) Description: Der Terminalserver kann den Dienstprinzipalnamen "TERMSRV", der für die Serverauthentifizierung verwendet werden soll, nicht registrieren. Der folgende Fehler ist aufgetreten: Die angegebene Domäne ist nicht vorhanden, oder es konnte keine Verbindung hergestellt werden. . Error: (10/22/2013 08:01:14 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Freemake Improver" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (10/22/2013 08:01:14 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Freemake Improver erreicht. Error: (10/22/2013 08:00:59 PM) (Source: Microsoft-Windows-GroupPolicy) (User: NT-AUTORITÄT) Description: Fehler bei der Verarbeitung der Gruppenrichtlinie. Der Computername konnte nicht aufgelöst werden. Dies kann mindestens eine der folgenden Ursachen haben: a) Fehler bei der Namensauflösung mit dem aktuellen Domänencontroller. b) Active Directory-Replikationswartezeit (ein auf einem anderen Domänencontroller erstelltes Konto hat nicht auf dem aktuellen Domänencontroller repliziert). Error: (10/22/2013 08:00:44 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%20 Microsoft Office Sessions: ========================= Error: (10/19/2013 01:53:13 PM) (Source: Application Error)(User: ) Description: FlashPlayerPlugin_11_9_900_117.exe11.9.900.1175244d3b6FlashPlayerPlugin_11_9_900_117.exe11.9.900.1175244d3b64000001500017b60ac001ceccc143f3b417C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exeC:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe07aee18c-38b5-11e3-bfaf-00238ba36c10 Error: (10/19/2013 08:54:32 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 23226910 Error: (10/19/2013 08:54:32 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 23226910 Error: (10/19/2013 08:54:32 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (10/19/2013 08:54:16 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 23211279 Error: (10/19/2013 08:54:16 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 23211279 Error: (10/19/2013 08:54:16 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (10/19/2013 08:54:01 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 23195695 Error: (10/19/2013 08:54:01 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 23195695 Error: (10/19/2013 08:54:01 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second CodeIntegrity Errors: =================================== Date: 2012-12-18 13:42:30.421 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 62% Total physical RAM: 3000.86 MB Available physical RAM: 1115.65 MB Total Pagefile: 6000.01 MB Available Pagefile: 4088.34 MB Total Virtual: 2047.88 MB Available Virtual: 1880.55 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:232.79 GB) (Free:50.26 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: D4433E6F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS) ==================== End Of Log ============================ can result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-10-2013 Ran by Andre.Gunkel (administrator) on LAPTOP-ANG on 23-10-2013 13:25:14 Running from C:\Users\Andre.Gunkel\Desktop Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareService.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\NetworkAgent 8\klnagent.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Samsung Electronics Co., Ltd.) C:\Windows\system32\spool\drivers\w32x86\3\NetFaxServer.exe (Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files\StarMoney 9.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\NetworkAgent 8\klnagent.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Google Inc.) C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe (Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe () C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareTray.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Microsoft Corporation) C:\Windows\system32\UI0Detect.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [AVP] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [311680 2010-03-12] (Kaspersky Lab) HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [1136648 2009-09-04] (Dritek System Inc.) HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-10-06] (Apple Inc.) HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [PMBVolumeWatcher] - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation) HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [688128 2011-07-06] () HKLM\...\Run: [CLX3180_Scan2Pc] - C:\Windows\Twain_32\Samsung\CLX3180\Scan2pc.exe [1990144 2011-04-29] () HKLM\...\Run: [3180 Scan2PC] - C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe [1990144 2011-04-29] () HKLM\...\Run: [Cm108Sound] - RunDll32 cm108.cpl,CMICtrlWnd HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-09-17] (Apple Inc.) HKLM\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2013-09-27] (Lavasoft) HKLM\...\Run: [] - [x] HKLM\...\Run: [AdAwareTray] - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareTray.exe [2176856 2013-10-08] () HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Policies\Explorer: [NoDriveTypeAutoRun_KL_notset] 1 HKCU\...\Run: [MobileDocuments] - C:\Program Files\Common Files\Apple\Internet Services\ubd.exe HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-09-15] (Apple Inc.) HKCU\...\Run: [Snoozer] - C:\Users\Andre.Gunkel\AppData\Roaming\Snz\Snz.exe [1226843 2013-10-10] () HKCU\...\Run: [OMESupervisor] - C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe [2220366 2013-10-10] () AppInit_DLLs: c:\progra~1\kasper~1\kasper~1.0fo\adialhk.dll c:\progra~1\kasper~1\kasper~1.0fo\kloehk.dll [ 2011-03-17] (Kaspersky Lab ZAO) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Bing HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://companyweb HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://companyweb URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {4844E65C-D8A7-4FB4-B02A-435280E846B1} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {5504FFE2-37B5-4C89-907F-238B50B79008} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=FA93766D-5B92-4310-B9E9-E8099E190F8F&apn_sauid=593BB89A-F072-41D2-996C-4F756EDC1106 SearchScopes: HKCU - {C967B79E-297A-41C2-938D-FABDB4BC8E4C} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.70.200 FireFox: ======== FF ProfilePath: C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default FF DefaultSearchEngine: Search FF SelectedSearchEngine: Search FF Homepage: hxxp://www.lederweis.de/ FF Keyword.URL: hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_5&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Ad-Aware Security Add-on - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} FF Extension: lazarus - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\lazarus@interclue.com.xpi FF Extension: om - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\om@offermosquito.com.xpi FF Extension: No Name - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi FF Extension: No Name - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ ========================== Services (Whitelisted) ================= R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [311680 2010-03-12] (Kaspersky Lab) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-09-07] (Freemake) R2 klnagent; C:\Program Files\Kaspersky Lab\NetworkAgent 8\klnagent.exe [141688 2010-10-20] (Kaspersky Lab ZAO) R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareService.exe [497744 2013-10-08] () R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\w32x86\3\NetFaxServer.exe [175104 2011-04-28] (Samsung Electronics Co., Ltd.) R2 StarMoney 8.0 OnlineUpdate; C:\Program Files\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files\StarMoney 9.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH) ==================== Drivers (Whitelisted) ==================== R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [38400 2009-07-13] (Samsung Electronics Co., Ltd.) R1 kl1; C:\Windows\System32\DRIVERS\kl1.sys [126480 2009-11-12] (Kaspersky Lab) R3 KLFLTDEV; C:\Windows\System32\DRIVERS\klfltdev.sys [24848 2009-09-03] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [233560 2011-03-17] (Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [22104 2011-03-17] (Kaspersky Lab ZAO) S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2010-07-01] (Screaming Bee LLC) R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2009-07-12] (Samsung Electronics) S3 TridVid; C:\Windows\System32\DRIVERS\tridvid6010.sys [339712 2011-01-21] (10Moons Technologies Co.,Ltd) R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [340624 2013-07-17] (BitDefender S.R.L.) S3 USBPNPA; C:\Windows\System32\drivers\CM108.sys [1515520 2009-11-18] (C-Media Electronics Inc) R3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [17792 2008-12-26] (Avnex) S1 DritekPortIO; \??\C:\Program Files\Launch Manager\DPortIO.sys [x] S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-23 13:24 - 2013-10-23 13:24 - 00000000 ____D C:\FRST 2013-10-23 13:23 - 2013-10-23 13:23 - 01087503 _____ (Farbar) C:\Users\Andre.Gunkel\Desktop\FRST.exe 2013-10-23 13:20 - 2013-10-23 13:20 - 00014983 _____ C:\Users\Andre.Gunkel\Desktop\X+WWqGKT.htm 2013-10-21 11:34 - 2013-10-21 11:34 - 00342115 _____ C:\Users\Andre.Gunkel\Desktop\kunden.txt 2013-10-20 15:04 - 2013-10-20 15:04 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 13:36 - 2013-10-20 13:36 - 00000000 ____D C:\Program Files\Common Files\Java 2013-10-20 13:36 - 2013-10-08 07:50 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-10-20 13:36 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-20 13:36 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-20 13:36 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-20 13:35 - 2013-10-20 13:36 - 00004874 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log 2013-10-16 12:12 - 2013-10-16 12:12 - 00010090 _____ C:\Users\Andre.Gunkel\Desktop\AdwCleaner[S0].txt 2013-10-16 12:01 - 2013-10-16 12:07 - 00000000 ____D C:\AdwCleaner 2013-10-16 12:00 - 2013-10-16 12:00 - 01048960 _____ C:\Users\Andre.Gunkel\Desktop\adwcleaner.exe 2013-10-14 20:14 - 2013-10-14 20:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Snz 2013-10-12 17:37 - 2013-10-12 17:37 - 00000000 ____D C:\Users\Andre.Gunkel\.MCReferenceSdk 2013-10-11 23:17 - 2013-10-11 23:17 - 00001943 _____ C:\Users\Public\Desktop\Lightworks (11.1).lnk 2013-10-11 23:17 - 2013-10-11 23:17 - 00000000 ____D C:\ProgramData\Geevs 2013-10-11 23:14 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2013-10-11 23:14 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2013-10-11 23:14 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2013-10-11 23:14 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2013-10-11 18:53 - 2013-10-11 18:59 - 72720560 _____ (Lightworks) C:\Users\Andre.Gunkel\Downloads\setup_11.1_full_32bit.exe 2013-10-11 15:52 - 2013-10-11 15:52 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\LavasoftStatistics 2013-10-11 15:34 - 2013-10-11 15:34 - 00001327 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk 2013-10-11 15:33 - 2013-10-11 15:33 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\adawarebp 2013-10-11 15:33 - 2013-10-11 15:33 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 2013-10-11 15:32 - 2013-10-11 15:33 - 00000000 ____D C:\Program Files\Lavasoft 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Users\IS\andre.gunkel 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Users\IS 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Program Files\Toolbar Cleaner 2013-10-11 15:31 - 2013-10-11 15:31 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Lavasoft 2013-10-11 15:30 - 2013-10-11 15:30 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2013-10-11 15:28 - 2013-10-11 15:28 - 01724552 _____ C:\Users\Andre.Gunkel\Downloads\Adaware_Installer.exe 2013-10-11 15:28 - 2013-10-11 15:28 - 00000000 ____D C:\ProgramData\Lavasoft 2013-10-10 18:23 - 2013-10-10 18:23 - 02220366 _____ C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe 2013-10-10 13:03 - 2013-10-10 13:03 - 00000000 ____D C:\Windows\de 2013-10-10 13:02 - 2013-10-10 13:02 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-10-10 13:01 - 2013-10-10 13:02 - 00000000 ____D C:\Program Files\Windows Live 2013-10-10 13:00 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2013-10-10 13:00 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2013-10-10 13:00 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2013-10-10 13:00 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2013-10-10 12:54 - 2013-10-10 12:54 - 01245184 _____ (Microsoft Corporation) C:\Users\Andre.Gunkel\Downloads\wlsetup-webde_16.4.3505.0912.exe 2013-10-10 08:50 - 2013-10-10 08:50 - 00000961 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-10 08:50 - 2013-10-10 08:50 - 00000000 ____D C:\Program Files\CCleaner 2013-10-10 08:49 - 2013-10-10 08:49 - 03294168 _____ (Piriform Ltd) C:\Users\Andre.Gunkel\Downloads\ccsetup406_slim.exe 2013-10-10 00:32 - 2013-10-10 00:32 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{D1F696EE-4AC9-4180-8E0D-677BD145C7A1} 2013-10-09 23:58 - 2013-10-09 23:58 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Malwarebytes 2013-10-09 23:57 - 2013-10-09 23:57 - 00001063 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 23:57 - 2013-10-09 23:57 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 23:57 - 2013-10-09 23:57 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-09 23:57 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-09 23:56 - 2013-10-09 23:56 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Andre.Gunkel\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-08 11:06 - 2013-10-08 11:06 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{B57CBA9D-F1F3-4583-A41D-3E8DF3CD4622} 2013-10-07 23:06 - 2013-10-07 23:06 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{42389A2C-4AAE-47CA-92F1-D3A7275C5B96} 2013-10-07 22:07 - 2013-10-07 22:07 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{D1B65288-BDD6-4533-9305-A106904ADFC8} 2013-10-07 10:13 - 2013-10-07 10:13 - 00179984 _____ (Kaspersky Lab) C:\Users\Andre.Gunkel\Downloads\kss12.0.1.117mlg_en-de_ru-de_fr-de_de-de.exe 2013-10-06 19:23 - 2013-10-06 19:23 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{7944CC22-787E-4E2C-8787-93A3B58A6EA2} 2013-10-06 18:54 - 2013-10-06 18:54 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{E9426538-02C3-4EA7-BE7C-579ED4672789} 2013-10-06 18:24 - 2013-10-06 18:24 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{018A0A36-EDDC-4421-AB0F-00B05245D690} 2013-10-06 14:08 - 2013-10-06 14:08 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{C190DAF3-E8F7-474F-AE1A-72D1637BF9CD} 2013-10-06 13:05 - 2013-10-06 13:05 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{6A33A4EB-12CD-4EC9-BD70-8C5475A1BFF0} 2013-10-06 12:52 - 2013-10-06 12:52 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{9E3940BB-4CC4-4D45-A54C-4A538D13ABCC} 2013-10-06 12:44 - 2013-10-06 12:44 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{9379E1D0-A35A-4693-9F37-B3EF43F6180D} 2013-10-06 10:29 - 2013-10-06 10:29 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{DF129DA7-356D-497B-9C9D-FCBB52063BF5} 2013-10-05 22:28 - 2013-10-05 22:29 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{B88B4DFA-2E5C-4C50-8CC1-AA8530A7A817} 2013-10-05 10:28 - 2013-10-05 10:28 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{40EF02A3-9067-4DA6-968D-9820B66A7272} 2013-10-04 14:06 - 2013-10-04 14:06 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{0AB0F183-F11D-4881-B4A0-7A6AB26B268E} 2013-10-04 13:44 - 2013-10-04 13:44 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{6227F893-E306-4126-8CA7-F54F63A4D44A} 2013-10-04 13:07 - 2013-10-04 13:07 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{FEF9A27D-71F7-44A6-BEA1-3FA4E4DBF000} 2013-10-04 12:32 - 2013-10-04 12:32 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{6AF6AB4D-5F8D-4BDB-9B15-5119993BB247} 2013-10-04 12:04 - 2013-10-04 12:04 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{FADF4FB0-A6A2-42DC-B37A-241A47BA8E70} 2013-10-03 21:03 - 2013-10-03 21:03 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{8940AB10-9868-411A-89E8-47F67C9A6AD6} 2013-10-03 09:02 - 2013-10-03 09:03 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{1AE41AD6-7CD9-4DC1-A579-7B397950F822} 2013-10-03 06:38 - 2013-10-03 06:38 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{A44D5D36-7209-48C4-8A58-647AC69A8027} 2013-10-02 16:08 - 2013-10-02 16:08 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{217FCBD5-F54F-454C-B87B-7D9E079B00FE} 2013-10-02 03:05 - 2013-10-02 03:05 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{27A753EB-A852-4674-BFCC-31025EFD0992} 2013-10-01 09:49 - 2013-10-01 09:49 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{F9BFA550-9F80-4418-9A3F-112ABD409B6D} 2013-10-01 09:16 - 2013-10-01 09:17 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-30 21:49 - 2013-09-30 21:49 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{FA26DF71-65CA-443D-BFFB-2EEF4A7D3556} 2013-09-30 09:48 - 2013-09-30 09:49 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{699EDC2C-4558-4C12-86BF-827059FB7172} 2013-09-29 21:48 - 2013-09-29 21:48 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{85973ECA-D48D-4FE1-A0B1-10C6F96DCFC4} 2013-09-26 21:32 - 2013-09-26 21:32 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-09-26 21:31 - 2013-09-26 21:32 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-09-26 21:31 - 2013-09-26 21:32 - 00000000 ____D C:\Program Files\iTunes 2013-09-26 21:31 - 2013-09-26 21:31 - 00000000 ____D C:\Program Files\iPod 2013-09-24 22:40 - 2013-09-24 22:41 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{926AAC78-B42B-4724-9F70-DC386D54C906} ==================== One Month Modified Files and Folders ======= 2013-10-23 13:24 - 2013-10-23 13:24 - 00000000 ____D C:\FRST 2013-10-23 13:23 - 2013-10-23 13:23 - 01087503 _____ (Farbar) C:\Users\Andre.Gunkel\Desktop\FRST.exe 2013-10-23 13:20 - 2013-10-23 13:20 - 00014983 _____ C:\Users\Andre.Gunkel\Desktop\X+WWqGKT.htm 2013-10-23 13:01 - 2011-03-25 00:42 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-23 13:00 - 2012-04-19 17:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-23 12:58 - 2011-03-17 13:13 - 00000112 _____ C:\Windows\system32\config\netlogon.ftl 2013-10-23 12:37 - 2010-12-02 11:09 - 01581070 _____ C:\Windows\WindowsUpdate.log 2013-10-23 11:21 - 2011-03-17 13:23 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-10-23 08:11 - 2009-07-14 06:34 - 00014960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-23 08:11 - 2009-07-14 06:34 - 00014960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-23 08:08 - 2011-07-19 23:01 - 00000000 ____D C:\Program Files\StarMoney 8.0 S-Edition 2013-10-23 08:04 - 2011-03-25 00:42 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-23 08:03 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-23 08:03 - 2009-07-14 06:39 - 00144511 _____ C:\Windows\setupact.log 2013-10-22 20:07 - 2013-05-17 11:44 - 00000000 ____D C:\Program Files\StarMoney 9.0 S-Edition 2013-10-22 08:02 - 2011-03-31 09:28 - 00000000 ____D C:\_André Gunkel 2013-10-21 11:34 - 2013-10-21 11:34 - 00342115 _____ C:\Users\Andre.Gunkel\Desktop\kunden.txt 2013-10-21 07:52 - 2011-03-17 13:16 - 00000836 __RSH C:\Users\Andre.Gunkel\ntuser.pol 2013-10-21 07:52 - 2011-03-17 13:16 - 00000000 ____D C:\Users\Andre.Gunkel 2013-10-20 15:04 - 2013-10-20 15:04 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 13:36 - 2013-10-20 13:36 - 00000000 ____D C:\Program Files\Common Files\Java 2013-10-20 13:36 - 2013-10-20 13:35 - 00004874 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log 2013-10-20 13:36 - 2011-03-16 15:09 - 00000000 ____D C:\Program Files\Java 2013-10-20 01:37 - 2011-03-27 00:10 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Apple Computer 2013-10-19 10:18 - 2010-12-02 11:18 - 01507106 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-18 23:32 - 2011-12-30 00:53 - 00000000 ____D C:\Material 2013-10-18 07:19 - 2011-12-30 00:53 - 00000000 ____D C:\Sound 2013-10-16 12:12 - 2013-10-16 12:12 - 00010090 _____ C:\Users\Andre.Gunkel\Desktop\AdwCleaner[S0].txt 2013-10-16 12:07 - 2013-10-16 12:01 - 00000000 ____D C:\AdwCleaner 2013-10-16 12:07 - 2013-03-06 14:31 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Common 2013-10-16 12:00 - 2013-10-16 12:00 - 01048960 _____ C:\Users\Andre.Gunkel\Desktop\adwcleaner.exe 2013-10-15 09:04 - 2012-03-20 21:05 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\TeamSpeak 3 Client 2013-10-14 20:14 - 2013-10-14 20:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Snz 2013-10-14 20:07 - 2011-03-16 15:04 - 00060924 _____ C:\Windows\PFRO.log 2013-10-12 17:44 - 2011-12-30 00:41 - 00000000 ____D C:\Users\Public\Documents\Lightworks 2013-10-12 17:37 - 2013-10-12 17:37 - 00000000 ____D C:\Users\Andre.Gunkel\.MCReferenceSdk 2013-10-11 23:17 - 2013-10-11 23:17 - 00001943 _____ C:\Users\Public\Desktop\Lightworks (11.1).lnk 2013-10-11 23:17 - 2013-10-11 23:17 - 00000000 ____D C:\ProgramData\Geevs 2013-10-11 23:17 - 2011-12-30 00:40 - 00000000 ____D C:\Program Files\Lightworks 2013-10-11 18:59 - 2013-10-11 18:53 - 72720560 _____ (Lightworks) C:\Users\Andre.Gunkel\Downloads\setup_11.1_full_32bit.exe 2013-10-11 18:43 - 2011-03-17 13:16 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\VirtualStore 2013-10-11 16:06 - 2011-03-17 19:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla 2013-10-11 15:58 - 2011-07-19 23:01 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-10-11 15:52 - 2013-10-11 15:52 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\LavasoftStatistics 2013-10-11 15:34 - 2013-10-11 15:34 - 00001327 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk 2013-10-11 15:33 - 2013-10-11 15:33 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\adawarebp 2013-10-11 15:33 - 2013-10-11 15:33 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 2013-10-11 15:33 - 2013-10-11 15:32 - 00000000 ____D C:\Program Files\Lavasoft 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Users\IS\andre.gunkel 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Users\IS 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Program Files\Toolbar Cleaner 2013-10-11 15:31 - 2013-10-11 15:31 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Lavasoft 2013-10-11 15:30 - 2013-10-11 15:30 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2013-10-11 15:28 - 2013-10-11 15:28 - 01724552 _____ C:\Users\Andre.Gunkel\Downloads\Adaware_Installer.exe 2013-10-11 15:28 - 2013-10-11 15:28 - 00000000 ____D C:\ProgramData\Lavasoft 2013-10-10 22:54 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2013-10-10 18:23 - 2013-10-10 18:23 - 02220366 _____ C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe 2013-10-10 13:04 - 2012-01-01 14:07 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\Windows Live 2013-10-10 13:03 - 2013-10-10 13:03 - 00000000 ____D C:\Windows\de 2013-10-10 13:02 - 2013-10-10 13:02 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-10-10 13:02 - 2013-10-10 13:01 - 00000000 ____D C:\Program Files\Windows Live 2013-10-10 13:00 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-10-10 12:54 - 2013-10-10 12:54 - 01245184 _____ (Microsoft Corporation) C:\Users\Andre.Gunkel\Downloads\wlsetup-webde_16.4.3505.0912.exe 2013-10-10 09:44 - 2011-03-31 09:28 - 00000000 ____D C:\_Leder Weis 2013-10-10 09:02 - 2011-05-19 11:22 - 00000000 ____D C:\Program Files\PDFCreator 2013-10-10 09:02 - 2011-04-05 08:29 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Skype 2013-10-10 08:54 - 2011-12-03 14:45 - 00000000 ____D C:\Windows\Minidump 2013-10-10 08:50 - 2013-10-10 08:50 - 00000961 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-10 08:50 - 2013-10-10 08:50 - 00000000 ____D C:\Program Files\CCleaner 2013-10-10 08:49 - 2013-10-10 08:49 - 03294168 _____ (Piriform Ltd) C:\Users\Andre.Gunkel\Downloads\ccsetup406_slim.exe 2013-10-10 00:32 - 2013-10-10 00:32 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{D1F696EE-4AC9-4180-8E0D-677BD145C7A1} 2013-10-10 00:27 - 2011-03-16 12:23 - 00000000 ____D C:\Windows\PCHEALTH 2013-10-09 23:58 - 2013-10-09 23:58 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Malwarebytes 2013-10-09 23:57 - 2013-10-09 23:57 - 00001063 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 23:57 - 2013-10-09 23:57 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 23:57 - 2013-10-09 23:57 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-09 23:56 - 2013-10-09 23:56 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Andre.Gunkel\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-08 22:00 - 2012-04-19 17:11 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-10-08 22:00 - 2011-05-14 23:15 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-10-08 11:06 - 2013-10-08 11:06 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{B57CBA9D-F1F3-4583-A41D-3E8DF3CD4622} 2013-10-08 07:50 - 2013-10-20 13:36 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-10-08 07:46 - 2013-10-20 13:36 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-08 07:46 - 2013-10-20 13:36 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-08 07:46 - 2013-10-20 13:36 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-07 23:06 - 2013-10-07 23:06 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{42389A2C-4AAE-47CA-92F1-D3A7275C5B96} 2013-10-07 22:07 - 2013-10-07 22:07 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{D1B65288-BDD6-4533-9305-A106904ADFC8} 2013-10-07 10:13 - 2013-10-07 10:13 - 00179984 _____ (Kaspersky Lab) C:\Users\Andre.Gunkel\Downloads\kss12.0.1.117mlg_en-de_ru-de_fr-de_de-de.exe 2013-10-06 19:23 - 2013-10-06 19:23 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{7944CC22-787E-4E2C-8787-93A3B58A6EA2} 2013-10-06 18:54 - 2013-10-06 18:54 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{E9426538-02C3-4EA7-BE7C-579ED4672789} 2013-10-06 18:24 - 2013-10-06 18:24 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{018A0A36-EDDC-4421-AB0F-00B05245D690} 2013-10-06 14:08 - 2013-10-06 14:08 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{C190DAF3-E8F7-474F-AE1A-72D1637BF9CD} 2013-10-06 13:05 - 2013-10-06 13:05 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{6A33A4EB-12CD-4EC9-BD70-8C5475A1BFF0} 2013-10-06 12:52 - 2013-10-06 12:52 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{9E3940BB-4CC4-4D45-A54C-4A538D13ABCC} 2013-10-06 12:44 - 2013-10-06 12:44 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{9379E1D0-A35A-4693-9F37-B3EF43F6180D} 2013-10-06 10:29 - 2013-10-06 10:29 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{DF129DA7-356D-497B-9C9D-FCBB52063BF5} 2013-10-05 22:29 - 2013-10-05 22:28 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{B88B4DFA-2E5C-4C50-8CC1-AA8530A7A817} 2013-10-05 10:28 - 2013-10-05 10:28 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{40EF02A3-9067-4DA6-968D-9820B66A7272} 2013-10-04 14:06 - 2013-10-04 14:06 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{0AB0F183-F11D-4881-B4A0-7A6AB26B268E} 2013-10-04 13:44 - 2013-10-04 13:44 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{6227F893-E306-4126-8CA7-F54F63A4D44A} 2013-10-04 13:07 - 2013-10-04 13:07 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{FEF9A27D-71F7-44A6-BEA1-3FA4E4DBF000} 2013-10-04 12:32 - 2013-10-04 12:32 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{6AF6AB4D-5F8D-4BDB-9B15-5119993BB247} 2013-10-04 12:04 - 2013-10-04 12:04 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{FADF4FB0-A6A2-42DC-B37A-241A47BA8E70} 2013-10-03 21:03 - 2013-10-03 21:03 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{8940AB10-9868-411A-89E8-47F67C9A6AD6} 2013-10-03 09:03 - 2013-10-03 09:02 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{1AE41AD6-7CD9-4DC1-A579-7B397950F822} 2013-10-03 06:38 - 2013-10-03 06:38 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{A44D5D36-7209-48C4-8A58-647AC69A8027} 2013-10-02 16:08 - 2013-10-02 16:08 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{217FCBD5-F54F-454C-B87B-7D9E079B00FE} 2013-10-02 03:05 - 2013-10-02 03:05 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{27A753EB-A852-4674-BFCC-31025EFD0992} 2013-10-02 02:56 - 2012-04-28 05:42 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-10-01 11:10 - 2011-03-17 19:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\Mozilla 2013-10-01 09:49 - 2013-10-01 09:49 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{F9BFA550-9F80-4418-9A3F-112ABD409B6D} 2013-10-01 09:17 - 2013-10-01 09:16 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-30 21:49 - 2013-09-30 21:49 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{FA26DF71-65CA-443D-BFFB-2EEF4A7D3556} 2013-09-30 09:49 - 2013-09-30 09:48 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{699EDC2C-4558-4C12-86BF-827059FB7172} 2013-09-29 21:48 - 2013-09-29 21:48 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{85973ECA-D48D-4FE1-A0B1-10C6F96DCFC4} 2013-09-26 21:40 - 2011-03-27 00:10 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\Apple Computer 2013-09-26 21:32 - 2013-09-26 21:32 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-09-26 21:32 - 2013-09-26 21:31 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-09-26 21:32 - 2013-09-26 21:31 - 00000000 ____D C:\Program Files\iTunes 2013-09-26 21:31 - 2013-09-26 21:31 - 00000000 ____D C:\Program Files\iPod 2013-09-26 21:31 - 2011-03-27 00:08 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-09-24 22:41 - 2013-09-24 22:40 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\{926AAC78-B42B-4724-9F70-DC386D54C906} Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\ose00000.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\0d7181b6-ef47-402e-bc75-af9e3e97c026.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\18e5ab1b-2558-43bc-aab9-119b7cb6fefa.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-21 09:34 ==================== End Of Log ============================[/CODE] --- --- --- Danke für die Antwort und Bereitschaft! Hoffe richtig so...?! lg André |
23.10.2013, 15:29 | #4 |
/// the machine /// TB-Ausbilder | Win 7: Nervige Pop-Ups bzw. "überblendete" WerbungSo funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.10.2013, 17:08 | #5 |
| Win 7: Nervige Pop-Ups bzw. "überblendete" WerbungCode:
ATTFilter # AdwCleaner v3.010 - Bericht erstellt am 23/10/2013 um 17:31:03 # Updated 20/10/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits) # Benutzername : Andre.Gunkel - LAPTOP-ANG # Gestartet von : C:\Users\Andre.Gunkel\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Program Files\Toolbar Cleaner Ordner Gelöscht : C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\adawaretb Datei Gelöscht : C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\om@offermosquito.com.xpi ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gelöscht : HKLM\Software\Toolbar Cleaner Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner ***** [ Browser ] ***** -\\ Internet Explorer v8.0.7601.17514 -\\ Mozilla Firefox v24.0 (de) [ Datei : C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\prefs.js ] Zeile gelöscht : user_pref("extensions.aniweather.timeShifted", 716759); Zeile gelöscht : user_pref("om.config", "{\"active\":true,\"name\":\"twde\",\"id\":25,\"dispId\":\"CH-25\",\"aboutLink\":\"\",\"trackingGeneral\":true,\"xhrDomains\":[\"become\",\"shopzilla\",\"twenga\",\"bizrate\"],\[...] ************************* AdwCleaner[R0].txt - [9928 octets] - [16/10/2013 12:01:51] AdwCleaner[R1].txt - [1813 octets] - [23/10/2013 17:30:17] AdwCleaner[S0].txt - [10090 octets] - [16/10/2013 12:07:07] AdwCleaner[S1].txt - [1738 octets] - [23/10/2013 17:31:03] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1798 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.7 (10.15.2013:3) OS: Windows 7 Professional x86 Ran by Andre.Gunkel on 23.10.2013 at 17:52:37,42 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1630470227-941947291-60570364-1616\Software\SweetIM Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\adawarebp_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\adawarebp_rasmancs Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5504FFE2-37B5-4C89-907F-238B50B79008} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\Andre.Gunkel\appdata\local\adawarebp" Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{018A0A36-EDDC-4421-AB0F-00B05245D690} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{04C322ED-0B37-41F1-AAB9-BFAF315729ED} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{09C9A922-60AC-4ABA-898B-AF357A33BA84} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{0AB0F183-F11D-4881-B4A0-7A6AB26B268E} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{0D7FF6F5-6DCB-4575-B4C6-05A77C199C1C} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{0E25C9B2-5FB2-448A-B9BF-73D4F4568637} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{0F5886BA-77FD-4C3E-8504-DF3532C7DC07} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{1AE41AD6-7CD9-4DC1-A579-7B397950F822} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{217FCBD5-F54F-454C-B87B-7D9E079B00FE} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{27A753EB-A852-4674-BFCC-31025EFD0992} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{40EF02A3-9067-4DA6-968D-9820B66A7272} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{42389A2C-4AAE-47CA-92F1-D3A7275C5B96} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{523A05D2-706C-4D3E-9137-87EBE20C6931} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{5AC21A13-8175-4FDB-93F0-BD2B9718C84A} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{5DEA25C5-E944-47A4-A785-CBA6C936CB20} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{6227F893-E306-4126-8CA7-F54F63A4D44A} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{65454FB5-0CCE-44DA-9C1C-44885062FE0B} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{699EDC2C-4558-4C12-86BF-827059FB7172} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{6A33A4EB-12CD-4EC9-BD70-8C5475A1BFF0} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{6AF6AB4D-5F8D-4BDB-9B15-5119993BB247} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{733ED290-3AEE-4D71-923F-1E758275817B} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{7944CC22-787E-4E2C-8787-93A3B58A6EA2} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{79FD131F-CCBF-44AD-AD89-F9628D9DFA35} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{7CBDB16A-3AC7-44BE-BAD4-54531C23FE47} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{7F013D32-34B7-4765-94B0-5CB0118F1311} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{7F7B8102-8F28-4319-81FE-93F0C60EE72B} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{83AB9124-BBE8-4906-A19F-83481A086810} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{85973ECA-D48D-4FE1-A0B1-10C6F96DCFC4} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{871D3316-EB09-4561-AC7C-A5E3610B5E41} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{8940AB10-9868-411A-89E8-47F67C9A6AD6} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{89A74361-15B8-484F-B7D2-021FFCC6D193} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{8EA8C415-33CC-428F-8788-B3A0768A8D25} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{926AAC78-B42B-4724-9F70-DC386D54C906} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{9379E1D0-A35A-4693-9F37-B3EF43F6180D} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{977355F4-3942-438E-AE99-E94C8179AFA4} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{9E3940BB-4CC4-4D45-A54C-4A538D13ABCC} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{A142E1E4-2341-4D51-88F5-718135B9916A} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{A44D5D36-7209-48C4-8A58-647AC69A8027} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{B57CBA9D-F1F3-4583-A41D-3E8DF3CD4622} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{B88B4DFA-2E5C-4C50-8CC1-AA8530A7A817} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{C190DAF3-E8F7-474F-AE1A-72D1637BF9CD} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{C46B76B2-9F3E-4472-9423-F06EF4F2506C} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{CAB64DA6-800A-4B16-96AB-724B170D42B7} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{CC2BA678-90B5-4A74-A030-48B9CD627DEA} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{D1B65288-BDD6-4533-9305-A106904ADFC8} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{D1F696EE-4AC9-4180-8E0D-677BD145C7A1} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{DED520C2-4A82-48C0-A62B-3DBB46EA5FE9} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{DF129DA7-356D-497B-9C9D-FCBB52063BF5} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{E08F5B9A-2C41-475E-8F9E-BF2ED33387D7} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{E9426538-02C3-4EA7-BE7C-579ED4672789} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{EC99F483-C2D8-42ED-BC2B-81F9C2B4F4A5} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{EF57AE87-14F3-45A6-B144-B988A41577DB} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{F9BFA550-9F80-4418-9A3F-112ABD409B6D} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{FA26DF71-65CA-443D-BFFB-2EEF4A7D3556} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{FADF4FB0-A6A2-42DC-B37A-241A47BA8E70} Successfully deleted: [Empty Folder] C:\Users\Andre.Gunkel\appdata\local\{FEF9A27D-71F7-44A6-BEA1-3FA4E4DBF000} ~~~ FireFox Successfully deleted: [Folder] C:\Users\Andre.Gunkel\AppData\Roaming\mozilla\firefox\profiles\w50h8h6n.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} Successfully deleted the following from C:\Users\Andre.Gunkel\AppData\Roaming\mozilla\firefox\profiles\w50h8h6n.default\prefs.js user_pref("browser.search.defaulturl", "hxxp://wisersearch.com/search.php?channel=de&q="); user_pref("keyword.URL", "hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_5&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q="); Emptied folder: C:\Users\Andre.Gunkel\AppData\Roaming\mozilla\firefox\profiles\w50h8h6n.default\minidumps [218 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 23.10.2013 at 17:55:49,88 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-10-2013 Ran by Andre.Gunkel (administrator) on LAPTOP-ANG on 23-10-2013 18:01:34 Running from C:\Users\Andre.Gunkel\Desktop Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareService.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\NetworkAgent 8\klnagent.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Samsung Electronics Co., Ltd.) C:\Windows\system32\spool\drivers\w32x86\3\NetFaxServer.exe (Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files\StarMoney 9.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\NetworkAgent 8\klnagent.exe (Google Inc.) C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe (Microsoft Corporation) C:\Windows\system32\UI0Detect.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe () C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareTray.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [AVP] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [311680 2010-03-12] (Kaspersky Lab) HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [1136648 2009-09-04] (Dritek System Inc.) HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-10-06] (Apple Inc.) HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [PMBVolumeWatcher] - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation) HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [688128 2011-07-06] () HKLM\...\Run: [CLX3180_Scan2Pc] - C:\Windows\Twain_32\Samsung\CLX3180\Scan2pc.exe [1990144 2011-04-29] () HKLM\...\Run: [3180 Scan2PC] - C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe [1990144 2011-04-29] () HKLM\...\Run: [Cm108Sound] - RunDll32 cm108.cpl,CMICtrlWnd HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-09-17] (Apple Inc.) HKLM\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2013-09-27] (Lavasoft) HKLM\...\Run: [] - [x] HKLM\...\Run: [AdAwareTray] - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareTray.exe [2176856 2013-10-08] () HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Run: [MobileDocuments] - C:\Program Files\Common Files\Apple\Internet Services\ubd.exe HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-09-15] (Apple Inc.) HKCU\...\Run: [Snoozer] - C:\Users\Andre.Gunkel\AppData\Roaming\Snz\Snz.exe [1226843 2013-10-10] () HKCU\...\Run: [OMESupervisor] - C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe [2220366 2013-10-10] () AppInit_DLLs: c:\progra~1\kasper~1\kasper~1.0fo\adialhk.dll c:\progra~1\kasper~1\kasper~1.0fo\kloehk.dll [ 2011-03-17] (Kaspersky Lab ZAO) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://companyweb HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://companyweb URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {4844E65C-D8A7-4FB4-B02A-435280E846B1} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {C967B79E-297A-41C2-938D-FABDB4BC8E4C} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default FF DefaultSearchEngine: Search FF SelectedSearchEngine: Search FF Homepage: hxxp://www.lederweis.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: lazarus - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\lazarus@interclue.com.xpi FF Extension: No Name - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi FF Extension: No Name - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ ========================== Services (Whitelisted) ================= S2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [311680 2010-03-12] (Kaspersky Lab) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-09-07] (Freemake) R2 klnagent; C:\Program Files\Kaspersky Lab\NetworkAgent 8\klnagent.exe [141688 2010-10-20] (Kaspersky Lab ZAO) R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareService.exe [497744 2013-10-08] () R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\w32x86\3\NetFaxServer.exe [175104 2011-04-28] (Samsung Electronics Co., Ltd.) R2 StarMoney 8.0 OnlineUpdate; C:\Program Files\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files\StarMoney 9.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH) ==================== Drivers (Whitelisted) ==================== R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [38400 2009-07-13] (Samsung Electronics Co., Ltd.) R1 kl1; C:\Windows\System32\DRIVERS\kl1.sys [126480 2009-11-12] (Kaspersky Lab) R3 KLFLTDEV; C:\Windows\System32\DRIVERS\klfltdev.sys [24848 2009-09-03] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [233560 2011-03-17] (Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [22104 2011-03-17] (Kaspersky Lab ZAO) S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2010-07-01] (Screaming Bee LLC) R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2009-07-12] (Samsung Electronics) S3 TridVid; C:\Windows\System32\DRIVERS\tridvid6010.sys [339712 2011-01-21] (10Moons Technologies Co.,Ltd) R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [340624 2013-07-17] (BitDefender S.R.L.) S3 USBPNPA; C:\Windows\System32\drivers\CM108.sys [1515520 2009-11-18] (C-Media Electronics Inc) R3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [17792 2008-12-26] (Avnex) S1 DritekPortIO; \??\C:\Program Files\Launch Manager\DPortIO.sys [x] S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-23 18:01 - 2013-10-23 18:01 - 01088127 _____ (Farbar) C:\Users\Andre.Gunkel\Desktop\FRST.exe 2013-10-23 17:55 - 2013-10-23 17:55 - 00008355 _____ C:\Users\Andre.Gunkel\Desktop\JRT.txt 2013-10-23 17:52 - 2013-10-23 17:52 - 00000000 ____D C:\Windows\ERUNT 2013-10-23 17:50 - 2013-10-23 17:50 - 01033335 _____ (Thisisu) C:\Users\Andre.Gunkel\Desktop\JRT.exe 2013-10-23 17:29 - 2013-10-23 17:29 - 01060070 _____ C:\Users\Andre.Gunkel\Desktop\adwcleaner.exe 2013-10-23 13:26 - 2013-10-23 13:26 - 00020934 _____ C:\Users\Andre.Gunkel\Desktop\Addition.txt 2013-10-23 13:24 - 2013-10-23 13:24 - 00000000 ____D C:\FRST 2013-10-23 13:20 - 2013-10-23 13:20 - 00014983 _____ C:\Users\Andre.Gunkel\Desktop\X+WWqGKT.htm 2013-10-21 11:34 - 2013-10-21 11:34 - 00342115 _____ C:\Users\Andre.Gunkel\Desktop\kunden.txt 2013-10-20 15:04 - 2013-10-20 15:04 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 13:36 - 2013-10-20 13:36 - 00000000 ____D C:\Program Files\Common Files\Java 2013-10-20 13:36 - 2013-10-08 07:50 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-10-20 13:36 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-20 13:36 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-20 13:36 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-20 13:35 - 2013-10-20 13:36 - 00004874 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log 2013-10-16 12:12 - 2013-10-16 12:12 - 00010090 _____ C:\Users\Andre.Gunkel\Desktop\AdwCleaner[S0].txt 2013-10-16 12:01 - 2013-10-23 17:31 - 00000000 ____D C:\AdwCleaner 2013-10-14 20:14 - 2013-10-14 20:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Snz 2013-10-12 17:37 - 2013-10-12 17:37 - 00000000 ____D C:\Users\Andre.Gunkel\.MCReferenceSdk 2013-10-11 23:17 - 2013-10-11 23:17 - 00001943 _____ C:\Users\Public\Desktop\Lightworks (11.1).lnk 2013-10-11 23:17 - 2013-10-11 23:17 - 00000000 ____D C:\ProgramData\Geevs 2013-10-11 23:14 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2013-10-11 23:14 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2013-10-11 23:14 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2013-10-11 23:14 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2013-10-11 18:53 - 2013-10-11 18:59 - 72720560 _____ (Lightworks) C:\Users\Andre.Gunkel\Downloads\setup_11.1_full_32bit.exe 2013-10-11 15:52 - 2013-10-11 15:52 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\LavasoftStatistics 2013-10-11 15:34 - 2013-10-11 15:34 - 00001327 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk 2013-10-11 15:33 - 2013-10-11 15:33 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 2013-10-11 15:32 - 2013-10-11 15:33 - 00000000 ____D C:\Program Files\Lavasoft 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Users\IS\andre.gunkel 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Users\IS 2013-10-11 15:31 - 2013-10-11 15:31 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Lavasoft 2013-10-11 15:30 - 2013-10-11 15:30 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2013-10-11 15:28 - 2013-10-11 15:28 - 01724552 _____ C:\Users\Andre.Gunkel\Downloads\Adaware_Installer.exe 2013-10-11 15:28 - 2013-10-11 15:28 - 00000000 ____D C:\ProgramData\Lavasoft 2013-10-10 18:23 - 2013-10-10 18:23 - 02220366 _____ C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe 2013-10-10 13:03 - 2013-10-10 13:03 - 00000000 ____D C:\Windows\de 2013-10-10 13:02 - 2013-10-10 13:02 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-10-10 13:01 - 2013-10-10 13:02 - 00000000 ____D C:\Program Files\Windows Live 2013-10-10 13:00 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2013-10-10 13:00 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2013-10-10 13:00 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2013-10-10 13:00 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2013-10-10 12:54 - 2013-10-10 12:54 - 01245184 _____ (Microsoft Corporation) C:\Users\Andre.Gunkel\Downloads\wlsetup-webde_16.4.3505.0912.exe 2013-10-10 08:50 - 2013-10-10 08:50 - 00000961 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-10 08:50 - 2013-10-10 08:50 - 00000000 ____D C:\Program Files\CCleaner 2013-10-10 08:49 - 2013-10-10 08:49 - 03294168 _____ (Piriform Ltd) C:\Users\Andre.Gunkel\Downloads\ccsetup406_slim.exe 2013-10-09 23:58 - 2013-10-09 23:58 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Malwarebytes 2013-10-09 23:57 - 2013-10-09 23:57 - 00001063 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 23:57 - 2013-10-09 23:57 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 23:57 - 2013-10-09 23:57 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-09 23:57 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-09 23:56 - 2013-10-09 23:56 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Andre.Gunkel\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-07 10:13 - 2013-10-07 10:13 - 00179984 _____ (Kaspersky Lab) C:\Users\Andre.Gunkel\Downloads\kss12.0.1.117mlg_en-de_ru-de_fr-de_de-de.exe 2013-10-01 09:16 - 2013-10-01 09:17 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-26 21:32 - 2013-09-26 21:32 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-09-26 21:31 - 2013-09-26 21:32 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-09-26 21:31 - 2013-09-26 21:32 - 00000000 ____D C:\Program Files\iTunes 2013-09-26 21:31 - 2013-09-26 21:31 - 00000000 ____D C:\Program Files\iPod ==================== One Month Modified Files and Folders ======= 2013-10-23 18:01 - 2013-10-23 18:01 - 01088127 _____ (Farbar) C:\Users\Andre.Gunkel\Desktop\FRST.exe 2013-10-23 18:01 - 2011-03-25 00:42 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-23 18:00 - 2012-04-19 17:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-23 17:55 - 2013-10-23 17:55 - 00008355 _____ C:\Users\Andre.Gunkel\Desktop\JRT.txt 2013-10-23 17:52 - 2013-10-23 17:52 - 00000000 ____D C:\Windows\ERUNT 2013-10-23 17:50 - 2013-10-23 17:50 - 01033335 _____ (Thisisu) C:\Users\Andre.Gunkel\Desktop\JRT.exe 2013-10-23 17:44 - 2011-03-25 00:42 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-23 17:44 - 2011-03-17 13:23 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-10-23 17:40 - 2009-07-14 06:34 - 00014960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-23 17:40 - 2009-07-14 06:34 - 00014960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-23 17:32 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-23 17:32 - 2009-07-14 06:39 - 00144623 _____ C:\Windows\setupact.log 2013-10-23 17:31 - 2013-10-16 12:01 - 00000000 ____D C:\AdwCleaner 2013-10-23 17:31 - 2010-12-02 11:09 - 01638991 _____ C:\Windows\WindowsUpdate.log 2013-10-23 17:29 - 2013-10-23 17:29 - 01060070 _____ C:\Users\Andre.Gunkel\Desktop\adwcleaner.exe 2013-10-23 17:14 - 2011-03-17 13:13 - 00000112 _____ C:\Windows\system32\config\netlogon.ftl 2013-10-23 17:13 - 2011-03-31 09:28 - 00000000 ____D C:\_Leder Weis 2013-10-23 13:26 - 2013-10-23 13:26 - 00020934 _____ C:\Users\Andre.Gunkel\Desktop\Addition.txt 2013-10-23 13:24 - 2013-10-23 13:24 - 00000000 ____D C:\FRST 2013-10-23 13:20 - 2013-10-23 13:20 - 00014983 _____ C:\Users\Andre.Gunkel\Desktop\X+WWqGKT.htm 2013-10-23 08:08 - 2011-07-19 23:01 - 00000000 ____D C:\Program Files\StarMoney 8.0 S-Edition 2013-10-22 20:07 - 2013-05-17 11:44 - 00000000 ____D C:\Program Files\StarMoney 9.0 S-Edition 2013-10-22 08:02 - 2011-03-31 09:28 - 00000000 ____D C:\_André Gunkel 2013-10-21 11:34 - 2013-10-21 11:34 - 00342115 _____ C:\Users\Andre.Gunkel\Desktop\kunden.txt 2013-10-21 07:52 - 2011-03-17 13:16 - 00000836 __RSH C:\Users\Andre.Gunkel\ntuser.pol 2013-10-21 07:52 - 2011-03-17 13:16 - 00000000 ____D C:\Users\Andre.Gunkel 2013-10-20 15:04 - 2013-10-20 15:04 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 13:36 - 2013-10-20 13:36 - 00000000 ____D C:\Program Files\Common Files\Java 2013-10-20 13:36 - 2013-10-20 13:35 - 00004874 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log 2013-10-20 13:36 - 2011-03-16 15:09 - 00000000 ____D C:\Program Files\Java 2013-10-20 01:37 - 2011-03-27 00:10 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Apple Computer 2013-10-19 10:18 - 2010-12-02 11:18 - 01507106 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-18 23:32 - 2011-12-30 00:53 - 00000000 ____D C:\Material 2013-10-18 07:19 - 2011-12-30 00:53 - 00000000 ____D C:\Sound 2013-10-16 12:12 - 2013-10-16 12:12 - 00010090 _____ C:\Users\Andre.Gunkel\Desktop\AdwCleaner[S0].txt 2013-10-16 12:07 - 2013-03-06 14:31 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Common 2013-10-15 09:04 - 2012-03-20 21:05 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\TeamSpeak 3 Client 2013-10-14 20:14 - 2013-10-14 20:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Snz 2013-10-14 20:07 - 2011-03-16 15:04 - 00060924 _____ C:\Windows\PFRO.log 2013-10-12 17:44 - 2011-12-30 00:41 - 00000000 ____D C:\Users\Public\Documents\Lightworks 2013-10-12 17:37 - 2013-10-12 17:37 - 00000000 ____D C:\Users\Andre.Gunkel\.MCReferenceSdk 2013-10-11 23:17 - 2013-10-11 23:17 - 00001943 _____ C:\Users\Public\Desktop\Lightworks (11.1).lnk 2013-10-11 23:17 - 2013-10-11 23:17 - 00000000 ____D C:\ProgramData\Geevs 2013-10-11 23:17 - 2011-12-30 00:40 - 00000000 ____D C:\Program Files\Lightworks 2013-10-11 18:59 - 2013-10-11 18:53 - 72720560 _____ (Lightworks) C:\Users\Andre.Gunkel\Downloads\setup_11.1_full_32bit.exe 2013-10-11 18:43 - 2011-03-17 13:16 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\VirtualStore 2013-10-11 16:06 - 2011-03-17 19:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla 2013-10-11 15:58 - 2011-07-19 23:01 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-10-11 15:52 - 2013-10-11 15:52 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\LavasoftStatistics 2013-10-11 15:34 - 2013-10-11 15:34 - 00001327 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk 2013-10-11 15:33 - 2013-10-11 15:33 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 2013-10-11 15:33 - 2013-10-11 15:32 - 00000000 ____D C:\Program Files\Lavasoft 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Users\IS\andre.gunkel 2013-10-11 15:32 - 2013-10-11 15:32 - 00000000 ____D C:\Users\IS 2013-10-11 15:31 - 2013-10-11 15:31 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Lavasoft 2013-10-11 15:30 - 2013-10-11 15:30 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2013-10-11 15:28 - 2013-10-11 15:28 - 01724552 _____ C:\Users\Andre.Gunkel\Downloads\Adaware_Installer.exe 2013-10-11 15:28 - 2013-10-11 15:28 - 00000000 ____D C:\ProgramData\Lavasoft 2013-10-10 22:54 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2013-10-10 18:23 - 2013-10-10 18:23 - 02220366 _____ C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe 2013-10-10 13:04 - 2012-01-01 14:07 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\Windows Live 2013-10-10 13:03 - 2013-10-10 13:03 - 00000000 ____D C:\Windows\de 2013-10-10 13:02 - 2013-10-10 13:02 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-10-10 13:02 - 2013-10-10 13:01 - 00000000 ____D C:\Program Files\Windows Live 2013-10-10 13:00 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-10-10 12:54 - 2013-10-10 12:54 - 01245184 _____ (Microsoft Corporation) C:\Users\Andre.Gunkel\Downloads\wlsetup-webde_16.4.3505.0912.exe 2013-10-10 09:02 - 2011-05-19 11:22 - 00000000 ____D C:\Program Files\PDFCreator 2013-10-10 09:02 - 2011-04-05 08:29 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Skype 2013-10-10 08:54 - 2011-12-03 14:45 - 00000000 ____D C:\Windows\Minidump 2013-10-10 08:50 - 2013-10-10 08:50 - 00000961 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-10 08:50 - 2013-10-10 08:50 - 00000000 ____D C:\Program Files\CCleaner 2013-10-10 08:49 - 2013-10-10 08:49 - 03294168 _____ (Piriform Ltd) C:\Users\Andre.Gunkel\Downloads\ccsetup406_slim.exe 2013-10-10 00:27 - 2011-03-16 12:23 - 00000000 ____D C:\Windows\PCHEALTH 2013-10-09 23:58 - 2013-10-09 23:58 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Malwarebytes 2013-10-09 23:57 - 2013-10-09 23:57 - 00001063 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 23:57 - 2013-10-09 23:57 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 23:57 - 2013-10-09 23:57 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-09 23:56 - 2013-10-09 23:56 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Andre.Gunkel\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-08 22:00 - 2012-04-19 17:11 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-10-08 22:00 - 2011-05-14 23:15 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-10-08 07:50 - 2013-10-20 13:36 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-10-08 07:46 - 2013-10-20 13:36 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-08 07:46 - 2013-10-20 13:36 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-08 07:46 - 2013-10-20 13:36 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-07 10:13 - 2013-10-07 10:13 - 00179984 _____ (Kaspersky Lab) C:\Users\Andre.Gunkel\Downloads\kss12.0.1.117mlg_en-de_ru-de_fr-de_de-de.exe 2013-10-02 02:56 - 2012-04-28 05:42 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-10-01 11:10 - 2011-03-17 19:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\Mozilla 2013-10-01 09:17 - 2013-10-01 09:16 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-26 21:40 - 2011-03-27 00:10 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\Apple Computer 2013-09-26 21:32 - 2013-09-26 21:32 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-09-26 21:32 - 2013-09-26 21:31 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-09-26 21:32 - 2013-09-26 21:31 - 00000000 ____D C:\Program Files\iTunes 2013-09-26 21:31 - 2013-09-26 21:31 - 00000000 ____D C:\Program Files\iPod 2013-09-26 21:31 - 2011-03-27 00:08 - 00000000 ____D C:\Program Files\Common Files\Apple Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\ose00000.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\0d7181b6-ef47-402e-bc75-af9e3e97c026.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\18e5ab1b-2558-43bc-aab9-119b7cb6fefa.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-21 09:34 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- :-) In der Form besser so??? Schon mal ein Zwischen - Danke an Dich "Schrauber" :-) |
24.10.2013, 08:48 | #6 |
/// the machine /// TB-Ausbilder | Win 7: Nervige Pop-Ups bzw. "überblendete" WerbungESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Win 7: Nervige Pop-Ups bzw. "überblendete" Werbung |
02.11.2013, 15:08 | #7 |
| Win 7: Nervige Pop-Ups bzw. "überblendete" WerbungCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=110a49754d472f4198b964abf63cfae0 # engine=15691 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-10-30 11:51:03 # local_time=2013-10-30 12:51:03 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 533602 134765054 0 0 # scanned=309091 # found=0 # cleaned=0 # scan_time=7558 Code:
ATTFilter Results of screen317's Security Check version 0.99.74 Windows 7 Service Pack 1 x86 (UAC is enabled) ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Anti-Virus Ad-Aware Antivirus Antivirus out of date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Ad-Aware Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java 7 Update 45 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader 10.1.8 Adobe Reader out of Date! Mozilla Firefox (24.0) ````````Process Check: objlist.exe by Laurent```````` Ad-Aware AAWService.exe is disabled! Ad-Aware AAWTray.exe is disabled! Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareService.exe Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareTray.exe StarMoney 8.0 S-Edition ouservice StarMoneyOnlineUpdate.exe StarMoney 9.0 S-Edition ouservice StarMoneyOnlineUpdate.exe Kaspersky Lab NetworkAgent 8 klnagent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Windows 7 Service Pack 1 x86 (UAC is enabled) ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Anti-Virus Ad-Aware Antivirus Antivirus out of date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Ad-Aware Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java 7 Update 45 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader 10.1.8 Adobe Reader out of Date! Mozilla Firefox (24.0) ````````Process Check: objlist.exe by Laurent```````` Ad-Aware AAWService.exe is disabled! Ad-Aware AAWTray.exe is disabled! Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareService.exe Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareTray.exe StarMoney 8.0 S-Edition ouservice StarMoneyOnlineUpdate.exe StarMoney 9.0 S-Edition ouservice StarMoneyOnlineUpdate.exe Kaspersky Lab NetworkAgent 8 klnagent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Results of screen317's Security Check version 0.99.74 Windows 7 Service Pack 1 x86 (UAC is enabled) ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Anti-Virus Ad-Aware Antivirus Antivirus out of date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Ad-Aware Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java 7 Update 45 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader 10.1.8 Adobe Reader out of Date! Mozilla Firefox (24.0) ````````Process Check: objlist.exe by Laurent```````` Ad-Aware AAWService.exe is disabled! Ad-Aware AAWTray.exe is disabled! Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareService.exe Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareTray.exe StarMoney 8.0 S-Edition ouservice StarMoneyOnlineUpdate.exe StarMoney 9.0 S-Edition ouservice StarMoneyOnlineUpdate.exe Kaspersky Lab NetworkAgent 8 klnagent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Results of screen317's Security Check version 0.99.74 Windows 7 Service Pack 1 x86 (UAC is enabled) ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Anti-Virus Ad-Aware Antivirus Antivirus out of date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Ad-Aware Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java 7 Update 45 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader 10.1.8 Adobe Reader out of Date! Mozilla Firefox (24.0) ````````Process Check: objlist.exe by Laurent```````` Ad-Aware AAWService.exe is disabled! Ad-Aware AAWTray.exe is disabled! Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareService.exe Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4516.0\AdAwareTray.exe StarMoney 8.0 S-Edition ouservice StarMoneyOnlineUpdate.exe StarMoney 9.0 S-Edition ouservice StarMoneyOnlineUpdate.exe Kaspersky Lab NetworkAgent 8 klnagent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013 Ran by Andre.Gunkel (administrator) on LAPTOP-ANG on 02-11-2013 14:58:15 Running from C:\Users\Andre.Gunkel\Desktop Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareService.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\NetworkAgent 8\klnagent.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Samsung Electronics Co., Ltd.) C:\Windows\system32\spool\drivers\w32x86\3\NetFaxServer.exe (Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files\StarMoney 9.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\NetworkAgent 8\klnagent.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Google Inc.) C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe () C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareTray.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Microsoft Corporation) C:\Windows\system32\UI0Detect.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [AVP] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [311680 2010-03-12] (Kaspersky Lab) HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [1136648 2009-09-04] (Dritek System Inc.) HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-10-06] (Apple Inc.) HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [PMBVolumeWatcher] - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation) HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [688128 2011-07-06] () HKLM\...\Run: [CLX3180_Scan2Pc] - C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe [1990144 2011-04-29] () HKLM\...\Run: [3180 Scan2PC] - C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe [1990144 2011-04-29] () HKLM\...\Run: [Cm108Sound] - RunDll32 cm108.cpl,CMICtrlWnd HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-09-17] (Apple Inc.) HKLM\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2013-09-27] (Lavasoft) HKLM\...\Run: [] - [x] HKLM\...\Run: [AdAwareTray] - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareTray.exe [2176856 2013-10-08] () HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Run: [MobileDocuments] - C:\Program Files\Common Files\Apple\Internet Services\ubd.exe HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-09-15] (Apple Inc.) HKCU\...\Run: [Snoozer] - C:\Users\Andre.Gunkel\AppData\Roaming\Snz\Snz.exe [1226843 2013-10-10] () HKCU\...\Run: [OMESupervisor] - C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe [2220366 2013-10-10] () AppInit_DLLs: c:\progra~1\kasper~1\kasper~1.0fo\adialhk.dll c:\progra~1\kasper~1\kasper~1.0fo\kloehk.dll [ 2011-03-17] (Kaspersky Lab ZAO) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://companyweb HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://companyweb URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {4844E65C-D8A7-4FB4-B02A-435280E846B1} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {C967B79E-297A-41C2-938D-FABDB4BC8E4C} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.70.200 FireFox: ======== FF ProfilePath: C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default FF DefaultSearchEngine: Search FF SelectedSearchEngine: Search FF Homepage: hxxp://www.lederweis.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: lazarus - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\lazarus@interclue.com.xpi FF Extension: om - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\om@offermosquito.com.xpi FF Extension: aniweatherdefault - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi FF Extension: Adblock Plus - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: prefs - C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla\Firefox\Profiles\w50h8h6n.default\Extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ ========================== Services (Whitelisted) ================= S2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe [311680 2010-03-12] (Kaspersky Lab) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-09-07] (Freemake) R2 klnagent; C:\Program Files\Kaspersky Lab\NetworkAgent 8\klnagent.exe [141688 2010-10-20] (Kaspersky Lab ZAO) R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4516.0\AdAwareService.exe [497744 2013-10-08] () R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\w32x86\3\NetFaxServer.exe [175104 2011-04-28] (Samsung Electronics Co., Ltd.) R2 StarMoney 8.0 OnlineUpdate; C:\Program Files\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files\StarMoney 9.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH) ==================== Drivers (Whitelisted) ==================== S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [38400 2009-07-13] (Samsung Electronics Co., Ltd.) R1 kl1; C:\Windows\System32\DRIVERS\kl1.sys [126480 2009-11-12] (Kaspersky Lab) R3 KLFLTDEV; C:\Windows\System32\DRIVERS\klfltdev.sys [24848 2009-09-03] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [233560 2011-03-17] (Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [22104 2011-03-17] (Kaspersky Lab ZAO) S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2010-07-01] (Screaming Bee LLC) R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2009-07-12] (Samsung Electronics) S3 TridVid; C:\Windows\System32\DRIVERS\tridvid6010.sys [339712 2011-01-21] (10Moons Technologies Co.,Ltd) R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [340624 2013-07-17] (BitDefender S.R.L.) S3 USBPNPA; C:\Windows\System32\drivers\CM108.sys [1515520 2009-11-18] (C-Media Electronics Inc) R3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [17792 2008-12-26] (Avnex) S1 DritekPortIO; \??\C:\Program Files\Launch Manager\DPortIO.sys [x] S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-02 14:57 - 2013-11-02 14:57 - 01089445 _____ (Farbar) C:\Users\Andre.Gunkel\Desktop\FRST.exe 2013-11-02 11:00 - 2013-11-02 11:00 - 00891167 _____ C:\Users\Andre.Gunkel\Desktop\SecurityCheck.exe 2013-10-30 10:42 - 2013-10-30 10:42 - 02347384 _____ (ESET) C:\Users\Andre.Gunkel\Downloads\esetsmartinstaller_enu.exe 2013-10-28 12:40 - 2012-06-02 23:19 - 01933848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-10-28 12:40 - 2012-06-02 23:19 - 00053784 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-10-28 12:40 - 2012-06-02 23:19 - 00045080 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-10-28 12:40 - 2012-06-02 23:12 - 02422272 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-10-28 12:39 - 2012-06-02 23:19 - 00577048 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-10-28 12:39 - 2012-06-02 23:19 - 00035864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-10-28 12:39 - 2012-06-02 23:12 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-10-28 12:38 - 2012-06-02 15:19 - 00171904 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-10-28 12:38 - 2012-06-02 15:12 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-10-25 13:19 - 2013-10-28 02:55 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\adawarebp 2013-10-23 16:55 - 2013-10-23 16:55 - 00008355 _____ C:\Users\Andre.Gunkel\Desktop\JRT.txt 2013-10-23 16:52 - 2013-10-23 16:52 - 00000000 ____D C:\Windows\ERUNT 2013-10-23 16:50 - 2013-10-23 16:50 - 01033335 _____ (Thisisu) C:\Users\Andre.Gunkel\Desktop\JRT.exe 2013-10-23 16:29 - 2013-10-23 16:29 - 01060070 _____ C:\Users\Andre.Gunkel\Desktop\adwcleaner.exe 2013-10-23 12:26 - 2013-10-23 12:26 - 00020934 _____ C:\Users\Andre.Gunkel\Desktop\Addition.txt 2013-10-23 12:24 - 2013-10-23 12:24 - 00000000 ____D C:\FRST 2013-10-23 12:20 - 2013-10-23 12:20 - 00014983 _____ C:\Users\Andre.Gunkel\Desktop\X+WWqGKT.htm 2013-10-21 10:34 - 2013-10-21 10:34 - 00342115 _____ C:\Users\Andre.Gunkel\Desktop\kunden.txt 2013-10-20 14:04 - 2013-10-20 14:04 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 12:36 - 2013-10-20 12:36 - 00000000 ____D C:\Program Files\Common Files\Java 2013-10-20 12:36 - 2013-10-08 06:50 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-10-20 12:36 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-20 12:36 - 2013-10-08 06:46 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-20 12:36 - 2013-10-08 06:46 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-20 12:35 - 2013-10-20 12:36 - 00004874 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log 2013-10-16 11:12 - 2013-10-16 11:12 - 00010090 _____ C:\Users\Andre.Gunkel\Desktop\AdwCleaner[S0].txt 2013-10-16 11:01 - 2013-10-23 16:31 - 00000000 ____D C:\AdwCleaner 2013-10-14 19:14 - 2013-10-14 19:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Snz 2013-10-12 16:37 - 2013-10-12 16:37 - 00000000 ____D C:\Users\Andre.Gunkel\.MCReferenceSdk 2013-10-11 22:17 - 2013-10-11 22:17 - 00001943 _____ C:\Users\Public\Desktop\Lightworks (11.1).lnk 2013-10-11 22:17 - 2013-10-11 22:17 - 00000000 ____D C:\ProgramData\Geevs 2013-10-11 22:14 - 2010-06-02 03:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2013-10-11 22:14 - 2010-05-26 10:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2013-10-11 22:14 - 2010-05-26 10:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2013-10-11 22:14 - 2010-05-26 10:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2013-10-11 17:53 - 2013-10-11 17:59 - 72720560 _____ (Lightworks) C:\Users\Andre.Gunkel\Downloads\setup_11.1_full_32bit.exe 2013-10-11 14:52 - 2013-10-11 14:52 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\LavasoftStatistics 2013-10-11 14:34 - 2013-10-11 14:34 - 00001327 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk 2013-10-11 14:33 - 2013-10-11 14:33 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 2013-10-11 14:32 - 2013-10-11 14:33 - 00000000 ____D C:\Program Files\Lavasoft 2013-10-11 14:32 - 2013-10-11 14:32 - 00000000 ____D C:\Users\IS\andre.gunkel 2013-10-11 14:32 - 2013-10-11 14:32 - 00000000 ____D C:\Users\IS 2013-10-11 14:31 - 2013-10-11 14:31 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Lavasoft 2013-10-11 14:30 - 2013-10-11 14:30 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2013-10-11 14:28 - 2013-10-11 14:28 - 01724552 _____ C:\Users\Andre.Gunkel\Downloads\Adaware_Installer.exe 2013-10-11 14:28 - 2013-10-11 14:28 - 00000000 ____D C:\ProgramData\Lavasoft 2013-10-10 17:23 - 2013-10-10 17:23 - 02220366 _____ C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe 2013-10-10 12:03 - 2013-10-10 12:03 - 00000000 ____D C:\Windows\de 2013-10-10 12:02 - 2013-10-10 12:02 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-10-10 12:01 - 2013-10-10 12:02 - 00000000 ____D C:\Program Files\Windows Live 2013-10-10 12:00 - 2010-06-02 03:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2013-10-10 12:00 - 2010-06-02 03:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2013-10-10 12:00 - 2010-05-26 10:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2013-10-10 12:00 - 2010-05-26 10:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2013-10-10 11:54 - 2013-10-10 11:54 - 01245184 _____ (Microsoft Corporation) C:\Users\Andre.Gunkel\Downloads\wlsetup-webde_16.4.3505.0912.exe 2013-10-10 07:50 - 2013-10-10 07:50 - 00000961 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-10 07:50 - 2013-10-10 07:50 - 00000000 ____D C:\Program Files\CCleaner 2013-10-10 07:49 - 2013-10-10 07:49 - 03294168 _____ (Piriform Ltd) C:\Users\Andre.Gunkel\Downloads\ccsetup406_slim.exe 2013-10-09 22:58 - 2013-10-09 22:58 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Malwarebytes 2013-10-09 22:57 - 2013-10-09 22:57 - 00001063 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 22:57 - 2013-10-09 22:57 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 22:57 - 2013-10-09 22:57 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-09 22:57 - 2013-04-04 13:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-09 22:56 - 2013-10-09 22:56 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Andre.Gunkel\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-07 09:13 - 2013-10-07 09:13 - 00179984 _____ (Kaspersky Lab) C:\Users\Andre.Gunkel\Downloads\kss12.0.1.117mlg_en-de_ru-de_fr-de_de-de.exe ==================== One Month Modified Files and Folders ======= 2013-11-02 14:57 - 2013-11-02 14:57 - 01089445 _____ (Farbar) C:\Users\Andre.Gunkel\Desktop\FRST.exe 2013-11-02 14:45 - 2010-12-02 10:09 - 02047693 _____ C:\Windows\WindowsUpdate.log 2013-11-02 14:01 - 2011-03-24 23:42 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-02 14:00 - 2012-04-19 16:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-02 13:29 - 2011-03-17 12:13 - 00000112 _____ C:\Windows\system32\config\netlogon.ftl 2013-11-02 11:00 - 2013-11-02 11:00 - 00891167 _____ C:\Users\Andre.Gunkel\Desktop\SecurityCheck.exe 2013-11-02 10:01 - 2009-07-14 05:34 - 00014960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-02 10:01 - 2009-07-14 05:34 - 00014960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-02 09:56 - 2011-07-19 22:01 - 00000000 ____D C:\Program Files\StarMoney 8.0 S-Edition 2013-11-02 09:53 - 2011-03-24 23:42 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-02 09:53 - 2011-03-17 12:23 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-11-02 09:50 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-02 09:50 - 2009-07-14 05:39 - 00145015 _____ C:\Windows\setupact.log 2013-10-30 15:04 - 2013-05-17 10:44 - 00000000 ____D C:\Program Files\StarMoney 9.0 S-Edition 2013-10-30 10:43 - 2010-12-02 10:18 - 01507106 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-30 10:42 - 2013-10-30 10:42 - 02347384 _____ (ESET) C:\Users\Andre.Gunkel\Downloads\esetsmartinstaller_enu.exe 2013-10-29 12:44 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2013-10-29 10:53 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-10-28 02:55 - 2013-10-25 13:19 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\adawarebp 2013-10-24 08:50 - 2011-03-31 08:28 - 00000000 ____D C:\_Leder Weis 2013-10-23 16:55 - 2013-10-23 16:55 - 00008355 _____ C:\Users\Andre.Gunkel\Desktop\JRT.txt 2013-10-23 16:52 - 2013-10-23 16:52 - 00000000 ____D C:\Windows\ERUNT 2013-10-23 16:50 - 2013-10-23 16:50 - 01033335 _____ (Thisisu) C:\Users\Andre.Gunkel\Desktop\JRT.exe 2013-10-23 16:31 - 2013-10-16 11:01 - 00000000 ____D C:\AdwCleaner 2013-10-23 16:29 - 2013-10-23 16:29 - 01060070 _____ C:\Users\Andre.Gunkel\Desktop\adwcleaner.exe 2013-10-23 12:26 - 2013-10-23 12:26 - 00020934 _____ C:\Users\Andre.Gunkel\Desktop\Addition.txt 2013-10-23 12:24 - 2013-10-23 12:24 - 00000000 ____D C:\FRST 2013-10-23 12:20 - 2013-10-23 12:20 - 00014983 _____ C:\Users\Andre.Gunkel\Desktop\X+WWqGKT.htm 2013-10-22 07:02 - 2011-03-31 08:28 - 00000000 ____D C:\_André Gunkel 2013-10-21 10:34 - 2013-10-21 10:34 - 00342115 _____ C:\Users\Andre.Gunkel\Desktop\kunden.txt 2013-10-21 06:52 - 2011-03-17 12:16 - 00000836 __RSH C:\Users\Andre.Gunkel\ntuser.pol 2013-10-21 06:52 - 2011-03-17 12:16 - 00000000 ____D C:\Users\Andre.Gunkel 2013-10-20 14:04 - 2013-10-20 14:04 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 12:36 - 2013-10-20 12:36 - 00000000 ____D C:\Program Files\Common Files\Java 2013-10-20 12:36 - 2013-10-20 12:35 - 00004874 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log 2013-10-20 12:36 - 2011-03-16 14:09 - 00000000 ____D C:\Program Files\Java 2013-10-20 00:37 - 2011-03-26 23:10 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Apple Computer 2013-10-18 22:32 - 2011-12-29 23:53 - 00000000 ____D C:\Material 2013-10-18 06:19 - 2011-12-29 23:53 - 00000000 ____D C:\Sound 2013-10-16 11:12 - 2013-10-16 11:12 - 00010090 _____ C:\Users\Andre.Gunkel\Desktop\AdwCleaner[S0].txt 2013-10-16 11:07 - 2013-03-06 13:31 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Common 2013-10-15 08:04 - 2012-03-20 20:05 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\TeamSpeak 3 Client 2013-10-14 19:14 - 2013-10-14 19:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Snz 2013-10-14 19:07 - 2011-03-16 14:04 - 00060924 _____ C:\Windows\PFRO.log 2013-10-12 16:44 - 2011-12-29 23:41 - 00000000 ____D C:\Users\Public\Documents\Lightworks 2013-10-12 16:37 - 2013-10-12 16:37 - 00000000 ____D C:\Users\Andre.Gunkel\.MCReferenceSdk 2013-10-11 22:17 - 2013-10-11 22:17 - 00001943 _____ C:\Users\Public\Desktop\Lightworks (11.1).lnk 2013-10-11 22:17 - 2013-10-11 22:17 - 00000000 ____D C:\ProgramData\Geevs 2013-10-11 22:17 - 2011-12-29 23:40 - 00000000 ____D C:\Program Files\Lightworks 2013-10-11 17:59 - 2013-10-11 17:53 - 72720560 _____ (Lightworks) C:\Users\Andre.Gunkel\Downloads\setup_11.1_full_32bit.exe 2013-10-11 17:43 - 2011-03-17 12:16 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\VirtualStore 2013-10-11 15:06 - 2011-03-17 18:14 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Mozilla 2013-10-11 14:58 - 2011-07-19 22:01 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-10-11 14:52 - 2013-10-11 14:52 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\LavasoftStatistics 2013-10-11 14:34 - 2013-10-11 14:34 - 00001327 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk 2013-10-11 14:33 - 2013-10-11 14:33 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 2013-10-11 14:33 - 2013-10-11 14:32 - 00000000 ____D C:\Program Files\Lavasoft 2013-10-11 14:32 - 2013-10-11 14:32 - 00000000 ____D C:\Users\IS\andre.gunkel 2013-10-11 14:32 - 2013-10-11 14:32 - 00000000 ____D C:\Users\IS 2013-10-11 14:31 - 2013-10-11 14:31 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Lavasoft 2013-10-11 14:30 - 2013-10-11 14:30 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2013-10-11 14:28 - 2013-10-11 14:28 - 01724552 _____ C:\Users\Andre.Gunkel\Downloads\Adaware_Installer.exe 2013-10-11 14:28 - 2013-10-11 14:28 - 00000000 ____D C:\ProgramData\Lavasoft 2013-10-10 21:54 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF 2013-10-10 17:23 - 2013-10-10 17:23 - 02220366 _____ C:\Users\Andre.Gunkel\AppData\Local\omesuperv.exe 2013-10-10 12:04 - 2012-01-01 13:07 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Local\Windows Live 2013-10-10 12:03 - 2013-10-10 12:03 - 00000000 ____D C:\Windows\de 2013-10-10 12:02 - 2013-10-10 12:02 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-10-10 12:02 - 2013-10-10 12:01 - 00000000 ____D C:\Program Files\Windows Live 2013-10-10 12:00 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-10-10 11:54 - 2013-10-10 11:54 - 01245184 _____ (Microsoft Corporation) C:\Users\Andre.Gunkel\Downloads\wlsetup-webde_16.4.3505.0912.exe 2013-10-10 08:02 - 2011-05-19 10:22 - 00000000 ____D C:\Program Files\PDFCreator 2013-10-10 08:02 - 2011-04-05 07:29 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Skype 2013-10-10 07:54 - 2011-12-03 13:45 - 00000000 ____D C:\Windows\Minidump 2013-10-10 07:50 - 2013-10-10 07:50 - 00000961 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-10 07:50 - 2013-10-10 07:50 - 00000000 ____D C:\Program Files\CCleaner 2013-10-10 07:49 - 2013-10-10 07:49 - 03294168 _____ (Piriform Ltd) C:\Users\Andre.Gunkel\Downloads\ccsetup406_slim.exe 2013-10-09 23:27 - 2011-03-16 11:23 - 00000000 ____D C:\Windows\PCHEALTH 2013-10-09 22:58 - 2013-10-09 22:58 - 00000000 ____D C:\Users\Andre.Gunkel\AppData\Roaming\Malwarebytes 2013-10-09 22:57 - 2013-10-09 22:57 - 00001063 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-09 22:57 - 2013-10-09 22:57 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-09 22:57 - 2013-10-09 22:57 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-09 22:56 - 2013-10-09 22:56 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Andre.Gunkel\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-08 21:00 - 2012-04-19 16:11 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-10-08 21:00 - 2011-05-14 22:15 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-10-08 06:50 - 2013-10-20 12:36 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-10-08 06:46 - 2013-10-20 12:36 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-08 06:46 - 2013-10-20 12:36 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-08 06:46 - 2013-10-20 12:36 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-07 09:13 - 2013-10-07 09:13 - 00179984 _____ (Kaspersky Lab) C:\Users\Andre.Gunkel\Downloads\kss12.0.1.117mlg_en-de_ru-de_fr-de_de-de.exe Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\ose00000.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\0d7181b6-ef47-402e-bc75-af9e3e97c026.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\18e5ab1b-2558-43bc-aab9-119b7cb6fefa.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Andre.Gunkel\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-02 10:24 ==================== End Of Log ============================ --- --- --- |
02.11.2013, 19:16 | #8 |
/// the machine /// TB-Ausbilder | Win 7: Nervige Pop-Ups bzw. "überblendete" Werbung Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.11.2013, 08:33 | #9 |
| Win 7: Nervige Pop-Ups bzw. "überblendete" Werbung Also so weit läuft es rund, nur den Fall hier hatte ich auf meiner eigenen Homepage und da ist nicht mal Werbung geschwweige denn irgendwelche Sondersachen... ? |
07.11.2013, 14:02 | #10 |
/// the machine /// TB-Ausbilder | Win 7: Nervige Pop-Ups bzw. "überblendete" Werbung Firefox mal neu installieren
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.11.2013, 09:45 | #11 |
| Win 7: Nervige Pop-Ups bzw. "überblendete" Werbung Ok, habe Firefox neu installiert. Sieht nach 10 Tagen jetzt störungfrei aus. supi! Dir Schrauber vielen herzlichen Dank, Deine Hinweise und Tipps habe ich gespeichert, um ab und zu mal wieder drauf zu schauen. Liebe Grüße André |
19.11.2013, 12:50 | #12 |
/// the machine /// TB-Ausbilder | Win 7: Nervige Pop-Ups bzw. "überblendete" Werbung Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Win 7: Nervige Pop-Ups bzw. "überblendete" Werbung |
administrator, anti-malware, appdata, autostart, blockiert, checkliste, dateien, explorer, hallo zusammen, kaspersky, laptop, logdatei, malwarebytes, microsoft, pop-ups, programme, rechner, regeln, seite, server, software, speicher, version, werbung, wiederholt, win |