|
Plagegeister aller Art und deren Bekämpfung: 10-Sekunden-Haushaltsbuch startet nicht mehrWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
06.11.2013, 17:03 | #1 |
| 10-Sekunden-Haushaltsbuch startet nicht mehr Hallo, ich nutze das Programm 10-Sekunden-Haushaltsbuch und habe in letzter Zeit das Problem, dass es auf einmal nicht mehr startet. Als dies zum ersten Mal passierte, ließ ich Avira AntiVir laufen, es hat nichts gefunden. Dann ließ ich Malwarebytes Anti Malware laufen, was auch einen Schädling gefunden hat (Pup.optional.irgendwas glaube ich). Nachdem ich den Schädling entfernt hatte, startete das Haushaltsbuch auch wieder. Ich vermute da also einen Zusammenhang, weshalb ich auch hier Hilfe suche. Das Programm startet jetzt wieder nicht, Malwarebytes hat diesmal aber nichts gefunden. Wenn ich versuche das Programm zu starten, bestätige ich erst das "Darf das Programm Veränderungen am PC vornehmen"-Fenster mit ja. Dann tut sich nichts, das Icon vom geöffneten Windows-Explorer unten links wird einmal kurz heller (als ob man mit dem Mauszeiger darüber fahren würde) und das war's. Mehr passiert nicht. Das Programm wird als Admin ausgeführt, eine Neuinstallation hat nichts gebracht. Ich habe Windows 7 Pro, früher unter Windows XP gab es das geschilderte Problem nie. Veränderungen der letzten Zeit am PC, die evtl. etwas mit dem blocken eines Programmstarts zu tun haben könnten, war eigentlich nur, dass ich mal Microsoft Security Essentials installiert hatte, dies aber auch schnell wieder gelöscht habe. Kann mir jemand helfen? Grüße, Steve. |
06.11.2013, 18:14 | #2 |
/// the machine /// TB-Ausbilder | 10-Sekunden-Haushaltsbuch startet nicht mehr Hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
07.11.2013, 12:14 | #3 |
| 10-Sekunden-Haushaltsbuch startet nicht mehr Hallo,
__________________vielen Dank für die schnelle Reaktion! Ich habe FRST (32-bit) laufen lassen, dies sind die Log-Dateien: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013 Ran by PC (administrator) on PC-PC on 07-11-2013 12:00:45 Running from C:\Users\PC\Desktop Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\system32\PnkBstrA.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (AppWork GmbH) C:\Program Files\JDownloader 2 beta\JDownloader v2.0\JDownloader2.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [hpqSRMon] - C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuschd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM\...\Run: [] - [x] HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1012000 2013-05-16] (NVIDIA Corporation) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-06] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2DE61392E27FCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de SearchScopes: HKLM - DefaultScope value is missing. BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 27 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\h515h78n.default FF DefaultSearchEngine: Bing FF SelectedSearchEngine: Bing FF Homepage: www.gmx.net FF NetworkProxy: "autoconfig_url", "https://secure.premiumize.me/6b601bac0bd4ad3ecc107067370969a6/proxy.pac" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @esn.me/esnsonar,version=0.70.4 - C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin: @esn/esnlaunch,version=2.1.7 - C:\Program Files\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: noscript - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\h515h78n.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: Adblock Plus - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\h515h78n.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: tabmix - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\h515h78n.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-06] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-06] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-06] (Avira Operations GmbH & Co. KG) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-08-17] () ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-06] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-06] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-10-03] (DT Soft Ltd) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 GDPkIcpt; \??\C:\Windows\system32\drivers\PktIcpt.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-07 12:00 - 2013-11-07 12:00 - 01089445 _____ (Farbar) C:\Users\PC\Desktop\FRST.exe 2013-11-07 12:00 - 2013-11-07 12:00 - 00000000 ____D C:\FRST 2013-11-06 17:08 - 2013-11-06 17:10 - 00000000 ____D C:\Users\PC\Desktop\Aloe Blacc - Lift Your Spirit 2013-11-06 16:24 - 2013-11-06 16:24 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-26 13:35 - 2013-10-26 13:37 - 00000000 ____D C:\!KillBox 2013-10-26 12:38 - 2013-10-26 12:38 - 00000910 _____ C:\Users\UpdatusUser\Desktop\tento.XT.lnk 2013-10-26 12:38 - 2013-10-26 12:38 - 00000910 _____ C:\Users\PC\Desktop\tento.XT.lnk 2013-10-26 12:38 - 2013-10-26 12:38 - 00000000 ____D C:\Program Files\tento.XT 2013-10-26 11:16 - 2013-09-04 02:15 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-26 11:16 - 2013-09-04 02:14 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-26 11:16 - 2013-09-04 02:14 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-26 11:16 - 2013-09-04 02:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-26 11:16 - 2013-09-04 02:14 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-26 11:16 - 2013-09-04 02:14 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-26 11:16 - 2013-09-04 02:14 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-25 08:04 - 2013-10-25 08:07 - 00000000 ____D C:\Users\PC\Desktop\HKM Winter 2013-10-25 07:58 - 2013-10-25 07:58 - 06112281 _____ C:\Users\PC\Desktop\Kerstin.zip 2013-10-21 17:54 - 2013-10-21 17:54 - 00000000 ____D C:\ProgramData\Oracle 2013-10-21 17:53 - 2013-10-21 17:53 - 00004266 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log 2013-10-21 17:53 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-20 13:05 - 2013-10-20 13:14 - 00000000 ____D C:\Users\PC\Desktop\Women - les plus Belles Voix Féminines de L année (2012) 2013-10-20 12:56 - 2013-10-20 13:05 - 00000000 ____D C:\Users\PC\Desktop\John Newman - Tribute (Deluxe Edition) - 2013 2013-10-20 12:55 - 2013-10-20 12:55 - 00000000 ____D C:\Users\PC\Desktop\Birdy - Fire Within (Limited Deluxe Edition) - 2013 2013-10-11 11:52 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-11 11:52 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-11 11:52 - 2013-09-23 00:28 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-11 11:52 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-11 11:52 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-11 11:52 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-11 11:42 - 2013-09-14 01:48 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-11 11:42 - 2013-09-08 03:07 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-11 11:42 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-11 11:42 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-10-11 11:42 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-11 11:42 - 2013-08-29 02:50 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-11 11:42 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-11 11:42 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-11 11:42 - 2013-08-28 02:04 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-11 11:42 - 2013-08-28 01:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-11 11:42 - 2013-08-01 12:03 - 00729024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-11 11:42 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-11 11:42 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-11 11:42 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-11 11:42 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-11 11:42 - 2013-07-04 10:48 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-11 11:42 - 2013-07-03 05:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-11 11:42 - 2013-07-03 04:36 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-11 11:42 - 2013-07-03 04:36 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-11 11:42 - 2013-06-06 05:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-11 11:42 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-11 11:42 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-11 11:42 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-11 11:42 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-11 11:41 - 2013-07-12 11:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-11 11:41 - 2013-06-25 23:56 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys ==================== One Month Modified Files and Folders ======= 2013-11-07 12:00 - 2013-11-07 12:00 - 01089445 _____ (Farbar) C:\Users\PC\Desktop\FRST.exe 2013-11-07 12:00 - 2013-11-07 12:00 - 00000000 ____D C:\FRST 2013-11-07 11:56 - 2013-07-13 16:53 - 01115926 _____ C:\Windows\WindowsUpdate.log 2013-11-06 17:42 - 2013-07-14 11:41 - 00138992 _____ C:\Windows\system32\Drivers\PnkBstrK.sys 2013-11-06 17:41 - 2013-07-14 11:47 - 00281152 _____ C:\Windows\system32\PnkBstrB.xtr 2013-11-06 17:41 - 2013-07-14 11:40 - 00281152 _____ C:\Windows\system32\PnkBstrB.exe 2013-11-06 17:39 - 2013-07-14 10:15 - 00000000 ____D C:\Users\PC\AppData\Roaming\Mp3tag 2013-11-06 17:17 - 2013-07-13 17:26 - 00000000 ____D C:\Users\PC\AppData\Roaming\vlc 2013-11-06 17:10 - 2013-11-06 17:08 - 00000000 ____D C:\Users\PC\Desktop\Aloe Blacc - Lift Your Spirit 2013-11-06 16:25 - 2013-07-13 17:06 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-11-06 16:24 - 2013-11-06 16:24 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-11-03 16:06 - 2013-07-14 11:40 - 00281152 _____ C:\Windows\system32\PnkBstrB.ex0 2013-11-01 09:05 - 2010-11-20 22:01 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-27 19:10 - 2009-07-14 05:34 - 00032352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-27 19:10 - 2009-07-14 05:34 - 00032352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-27 19:01 - 2013-07-13 16:59 - 00000000 ____D C:\ProgramData\NVIDIA 2013-10-27 19:01 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-27 19:01 - 2009-07-14 05:39 - 00031326 _____ C:\Windows\setupact.log 2013-10-27 18:54 - 2013-07-14 10:27 - 00000000 ____D C:\Program Files\Opera 2013-10-27 10:51 - 2010-11-20 22:48 - 00187788 _____ C:\Windows\PFRO.log 2013-10-27 10:51 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\tracing 2013-10-26 15:20 - 2013-07-14 10:05 - 00001089 _____ C:\Users\Public\Desktop\FreeFileSync.lnk 2013-10-26 13:37 - 2013-10-26 13:35 - 00000000 ____D C:\!KillBox 2013-10-26 13:29 - 2013-10-05 11:44 - 00000000 ____D C:\Users\PC\AppData\Roaming\MiniLyrics 2013-10-26 12:38 - 2013-10-26 12:38 - 00000910 _____ C:\Users\UpdatusUser\Desktop\tento.XT.lnk 2013-10-26 12:38 - 2013-10-26 12:38 - 00000910 _____ C:\Users\PC\Desktop\tento.XT.lnk 2013-10-26 12:38 - 2013-10-26 12:38 - 00000000 ____D C:\Program Files\tento.XT 2013-10-26 11:25 - 2013-07-14 11:35 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-10-26 11:25 - 2013-07-14 11:35 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-10-25 08:07 - 2013-10-25 08:04 - 00000000 ____D C:\Users\PC\Desktop\HKM Winter 2013-10-25 07:58 - 2013-10-25 07:58 - 06112281 _____ C:\Users\PC\Desktop\Kerstin.zip 2013-10-21 17:54 - 2013-10-21 17:54 - 00000000 ____D C:\ProgramData\Oracle 2013-10-21 17:53 - 2013-10-21 17:53 - 00004266 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log 2013-10-21 17:53 - 2013-10-05 08:02 - 00000000 ____D C:\Program Files\Java 2013-10-20 13:14 - 2013-10-20 13:05 - 00000000 ____D C:\Users\PC\Desktop\Women - les plus Belles Voix Féminines de L année (2012) 2013-10-20 13:05 - 2013-10-20 12:56 - 00000000 ____D C:\Users\PC\Desktop\John Newman - Tribute (Deluxe Edition) - 2013 2013-10-20 12:55 - 2013-10-20 12:55 - 00000000 ____D C:\Users\PC\Desktop\Birdy - Fire Within (Limited Deluxe Edition) - 2013 2013-10-14 10:39 - 2013-10-06 11:00 - 00000000 ____D C:\Users\PC\Desktop\Paul Smith Pullover 2013-10-12 17:59 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2013-10-12 17:16 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-10-12 16:30 - 2009-07-14 05:33 - 00410816 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-12 16:28 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-10-12 11:34 - 2013-07-14 09:42 - 00000000 ____D C:\Program Files\Everything 2013-10-12 11:16 - 2013-08-27 17:27 - 00000000 ____D C:\Users\PC\Documents\Eigene Scans 2013-10-12 11:15 - 2013-07-14 07:29 - 00000000 ____D C:\ProgramData\HP 2013-10-11 11:55 - 2013-07-14 13:47 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-10-11 11:54 - 2013-09-13 20:40 - 00000000 ____D C:\Windows\system32\MRT 2013-10-11 11:53 - 2013-07-13 17:38 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-11 11:47 - 2013-10-06 16:13 - 00001912 _____ C:\Windows\epplauncher.mif 2013-10-08 06:50 - 2013-10-05 08:02 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-10-08 06:46 - 2013-10-21 17:53 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-08 06:46 - 2013-10-05 08:02 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-08 06:46 - 2013-10-05 08:02 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe Some content of TEMP: ==================== C:\Users\PC\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe C:\Users\PC\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\PC\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\PC\AppData\Local\Temp\nvSCPAPI.dll C:\Users\PC\AppData\Local\Temp\nvStereoApiI.dll C:\Users\PC\AppData\Local\Temp\nvStInst.exe C:\Users\PC\AppData\Local\Temp\ose00000.exe C:\Users\PC\AppData\Local\Temp\proxy_vole4006523412661831548.dll C:\Users\PC\AppData\Local\Temp\SETUP.EXE C:\Users\PC\AppData\Local\Temp\sonarinst.exe C:\Users\PC\AppData\Local\Temp\unrar.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-01 08:52 ==================== End Of Log ============================ und... Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 31-10-2013 Ran by PC at 2013-11-07 12:02:16 Running from C:\Users\PC\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 10-Sekunden-Haushaltsbuch 5 5.05 (Version: 5.05) 1310 (Version: 130.0.365.000) 1310_Help (Version: 82.0.58.000) 1310Trb (Version: 82.0.242.000) 32 Bit HP CIO Components Installer (Version: 7.1.8) Adobe Flash Player 10 ActiveX (Version: 10.0.32.18) Adobe Flash Player 11 Plugin (Version: 11.9.900.117) Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05) AIO_CDB_ProductContext (Version: 130.0.365.000) AIO_CDB_Software (Version: 130.0.365.000) AIO_Scan (Version: 130.0.421.000) Alt.Binz 0.39.4 (Version: 0.39.4) Apple Application Support (Version: 2.3.4) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (Version: 2.1.3.127) Avira Free Antivirus (Version: 13.0.0.4052) Battlefield 2(TM) Battlefield 3™ (Version: 1.6.0.0) Battlelog Web Plugins (Version: 2.1.7) Bonjour (Version: 3.0.0.10) BufferChm (Version: 130.0.331.000) CDBurnerXP (Version: 4.5.1.4003) Copy (Version: 130.0.428.000) DAEMON Tools Lite (Version: 4.47.1.0333) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Destinations (Version: 130.0.0.0) DeviceDiscovery (Version: 130.0.465.000) DocProc (Version: 13.0.0.0) ESN Sonar (Version: 0.70.4) Everything 1.2.1.371 Fax (Version: 130.0.418.000) FormatFactory 3.1.1 (Version: 3.1.1) FreeFileSync 5.22 (Version: 5.22) GPBaseService2 (Version: 130.0.371.000) HP Imaging Device Functions 13.0 (Version: 13.0) HP Photosmart Essential 3.5 (Version: 3.5) HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B (Version: 13.0) HP Smart Web Printing 4.51 (Version: 4.51) HP Solution Center 13.0 (Version: 13.0) HP Update (Version: 5.005.000.001) HPDiagnosticAlert (Version: 1.00.0000) HPPhotoGadget (Version: 130.0.282.000) HPPhotoSmartDiscLabelContent1 (Version: 2.04.0000) HPPhotosmartEssential (Version: 2.04.0000) HPProductAssistant (Version: 130.0.371.000) IsoBuster 2.5 (Version: 2.5) iTunes (Version: 11.0.5.5) Java 7 Update 45 (Version: 7.0.450) Java Auto Updater (Version: 2.1.9.8) JDownloader 0.9 (Version: 0.9) JDownloader 2 (Version: 2.0) KC Softwares VideoInspector Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) MiniLyrics Mozilla Firefox 25.0 (x86 de) (Version: 25.0) Mozilla Maintenance Service (Version: 25.0) Mp3tag v2.57 (Version: v2.57) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Network (Version: 130.0.572.000) NVIDIA 3D Vision Controller-Treiber 320.49 (Version: 320.49) NVIDIA 3D Vision Treiber 320.49 (Version: 320.49) NVIDIA GeForce Experience 1.5 (Version: 1.5) NVIDIA Grafiktreiber 320.49 (Version: 320.49) NVIDIA Install Application (Version: 2.1002.124.810) NVIDIA PhysX (Version: 9.13.0604) NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604) NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.2049) NVIDIA Systemsteuerung 320.49 (Version: 320.49) NVIDIA Update 4.11.9 (Version: 4.11.9) NVIDIA Update Components (Version: 4.11.9) OCR Software by I.R.I.S. 13.0 (Version: 13.0) Opera Stable 17.0.1241.53 (Version: 17.0.1241.53) Origin (Version: 9.3.1.4482) PDF Split And Merge Basic (Version: 2.2.2) PunkBuster Services (Version: 0.991) Scan (Version: 13.0.0.0) SmartWebPrinting (Version: 130.0.457.000) SolutionCenter (Version: 130.0.373.000) Status (Version: 130.0.469.000) tento.XT v1.1 Toolbox (Version: 130.0.648.000) TrayApp (Version: 130.0.422.000) UnloadSupport (Version: 11.0.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3) Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (Version: 3) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition VLC media player 2.0.7 (Version: 2.0.7) WebReg (Version: 130.0.132.017) Winamp (Version: 5.64 ) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1) WinRAR 4.20 (32-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 15-10-2013 14:28:21 Windows Update 20-10-2013 09:42:44 Windows Update 21-10-2013 16:53:20 Installed Java 7 Update 45 25-10-2013 06:29:24 Windows Update 27-10-2013 07:19:09 Windows Update 01-11-2013 07:15:40 Windows Update 06-11-2013 15:29:45 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:04 - 2013-09-21 10:39 - 00000853 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {174A5CEA-7153-4AD0-89C9-6BD6E7260540} - System32\Tasks\{46DA68CE-E87E-4259-BB7E-1EF83403C016} => C:\Program Files\10-Sekunden-Haushaltsbuch\10hh.exe [2010-01-07] () Task: {5E68E73D-9B65-457A-A887-E9CB348BD344} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {8012CC19-729A-4752-B831-C0D2AE60F7B5} - System32\Tasks\{90C0C26C-89DE-4780-8160-0C14FB18060C} => C:\Program Files\10-Sekunden-Haushaltsbuch\10hh.exe [2010-01-07] () ==================== Loaded Modules (whitelisted) ============= 2011-03-16 23:11 - 2011-03-16 23:11 - 04297568 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-10-27 18:54 - 2013-10-21 07:41 - 00868704 _____ () C:\Program Files\Opera\17.0.1241.53\ffmpegsumo.dll 2013-10-27 18:54 - 2013-10-21 07:42 - 00881504 _____ () C:\Program Files\Opera\17.0.1241.53\libglesv2.dll 2013-10-27 18:54 - 2013-10-21 07:42 - 00109408 _____ () C:\Program Files\Opera\17.0.1241.53\libegl.dll 2013-10-26 11:25 - 2013-10-26 11:25 - 16233864 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll 2013-11-06 16:24 - 2013-11-06 16:24 - 03368048 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-11-06 17:05 - 2013-11-06 17:05 - 02593168 _____ () C:\Program Files\JDownloader 2 beta\JDownloader v2.0\tmp\7zip\SevenZipJBinding-N8q7X\lib7-Zip-JBinding.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/06/2013 06:24:50 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 8081 Error: (11/06/2013 06:24:50 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 8081 Error: (11/06/2013 06:24:50 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (11/06/2013 06:24:49 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7082 Error: (11/06/2013 06:24:49 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 7082 Error: (11/06/2013 06:24:49 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (11/06/2013 06:24:48 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6084 Error: (11/06/2013 06:24:48 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6084 Error: (11/06/2013 06:24:48 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (11/06/2013 06:24:47 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5085 System errors: ============= Error: (11/07/2013 11:55:31 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Netman erreicht. Error: (11/06/2013 05:38:47 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "FreeAgent Drive" den Befehl "chkdsk" aus. Error: (11/06/2013 05:36:11 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "FreeAgent Drive" den Befehl "chkdsk" aus. Error: (11/06/2013 05:36:02 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "FreeAgent Drive" den Befehl "chkdsk" aus. Error: (10/27/2013 10:49:58 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst Gruppenrichtlinienclient konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (10/25/2013 06:33:53 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst lmhosts erreicht. Error: (10/12/2013 07:27:48 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "FreeAgent Drive" den Befehl "chkdsk" aus. Error: (10/12/2013 07:27:23 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk3\DR3 gefunden. Error: (10/12/2013 07:27:22 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk3\DR3 gefunden. Error: (10/12/2013 07:27:22 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk3\DR3 gefunden. Microsoft Office Sessions: ========================= Error: (11/06/2013 06:24:50 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 8081 Error: (11/06/2013 06:24:50 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 8081 Error: (11/06/2013 06:24:50 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (11/06/2013 06:24:49 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7082 Error: (11/06/2013 06:24:49 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 7082 Error: (11/06/2013 06:24:49 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (11/06/2013 06:24:48 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6084 Error: (11/06/2013 06:24:48 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6084 Error: (11/06/2013 06:24:48 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (11/06/2013 06:24:47 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5085 ==================== Memory info =========================== Percentage of memory in use: 40% Total physical RAM: 3325.49 MB Available physical RAM: 1966.98 MB Total Pagefile: 6649.27 MB Available Pagefile: 3984.91 MB Total Virtual: 2047.88 MB Available Virtual: 1888.21 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:238.37 GB) (Free:137.33 GB) NTFS Drive e: (WD1500GB) (Fixed) (Total:1397.26 GB) (Free:11.6 GB) NTFS Drive f: () (Fixed) (Total:69.23 GB) (Free:11.73 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 1397 GB) (Disk ID: 270FF3F3) Partition 1: (Not Active) - (Size=-698723990528) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: A23EF086) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=238 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 69 GB) (Disk ID: 2E2C2E2B) Partition 1: (Active) - (Size=69 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Viele Grüße, Steve. |
07.11.2013, 14:57 | #4 |
/// the machine /// TB-Ausbilder | 10-Sekunden-Haushaltsbuch startet nicht mehr Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.11.2013, 17:18 | #5 |
| 10-Sekunden-Haushaltsbuch startet nicht mehr Hallo, hier kommen die Logs: Code:
ATTFilter # AdwCleaner v3.011 - Bericht erstellt am 07/11/2013 um 17:05:19 # Updated 03/11/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits) # Benutzername : PC - PC-PC # Gestartet von : C:\Users\PC\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16720 -\\ Mozilla Firefox v25.0 (de) [ Datei : C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\h515h78n.default\prefs.js ] [ Datei : C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\wvx3gk6y.default\prefs.js ] ************************* AdwCleaner[R0].txt - [3943 octets] - [25/08/2013 11:35:10] AdwCleaner[R1].txt - [4003 octets] - [25/08/2013 11:36:10] AdwCleaner[R2].txt - [1156 octets] - [07/11/2013 17:04:09] AdwCleaner[S0].txt - [4102 octets] - [25/08/2013 11:37:17] AdwCleaner[S1].txt - [1078 octets] - [07/11/2013 17:05:19] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1138 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Professional x86 Ran by PC on 07.11.2013 at 17:12:26,55 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\PC\AppData\Roaming\mozilla\firefox\profiles\h515h78n.default\minidumps [7 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 07.11.2013 at 17:14:08,10 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013 Ran by PC (administrator) on PC-PC on 07-11-2013 17:16:14 Running from C:\Users\PC\Desktop Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\system32\PnkBstrA.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe (Opera Software) C:\Program Files\Opera\17.0.1241.53\opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [hpqSRMon] - C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuschd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM\...\Run: [] - [x] HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1012000 2013-05-16] (NVIDIA Corporation) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-06] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2DE61392E27FCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de SearchScopes: HKLM - DefaultScope value is missing. BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 27 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\h515h78n.default FF DefaultSearchEngine: Bing FF SelectedSearchEngine: Bing FF Homepage: www.gmx.net FF NetworkProxy: "autoconfig_url", "https://secure.premiumize.me/6b601bac0bd4ad3ecc107067370969a6/proxy.pac" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @esn.me/esnsonar,version=0.70.4 - C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin: @esn/esnlaunch,version=2.1.7 - C:\Program Files\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: noscript - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\h515h78n.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: Adblock Plus - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\h515h78n.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: tabmix - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\h515h78n.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-06] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-06] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-06] (Avira Operations GmbH & Co. KG) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-08-17] () ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-06] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-06] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-10-03] (DT Soft Ltd) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 GDPkIcpt; \??\C:\Windows\system32\drivers\PktIcpt.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-07 17:14 - 2013-11-07 17:14 - 00000750 _____ C:\Users\PC\Desktop\JRT.txt 2013-11-07 17:11 - 2013-11-07 17:11 - 01034531 _____ (Thisisu) C:\Users\PC\Desktop\JRT.exe 2013-11-07 17:01 - 2013-11-07 17:01 - 01073262 _____ C:\Users\PC\Desktop\adwcleaner.exe 2013-11-07 16:41 - 2013-11-07 16:47 - 00000000 ____D C:\Users\PC\Desktop\Paloma Faith 2013-11-07 16:36 - 2013-11-07 16:45 - 00000000 ____D C:\Users\PC\Desktop\Tim Bendzko - Am Seidenen Faden (2013) 2013-11-07 12:02 - 2013-11-07 12:02 - 00016874 _____ C:\Users\PC\Desktop\Addition.txt 2013-11-07 12:00 - 2013-11-07 12:00 - 01089445 _____ (Farbar) C:\Users\PC\Desktop\FRST.exe 2013-11-07 12:00 - 2013-11-07 12:00 - 00000000 ____D C:\FRST 2013-11-06 17:08 - 2013-11-06 17:10 - 00000000 ____D C:\Users\PC\Desktop\Aloe Blacc - Lift Your Spirit 2013-11-06 16:24 - 2013-11-06 16:24 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-26 13:35 - 2013-10-26 13:37 - 00000000 ____D C:\!KillBox 2013-10-26 12:38 - 2013-10-26 12:38 - 00000910 _____ C:\Users\UpdatusUser\Desktop\tento.XT.lnk 2013-10-26 12:38 - 2013-10-26 12:38 - 00000910 _____ C:\Users\PC\Desktop\tento.XT.lnk 2013-10-26 12:38 - 2013-10-26 12:38 - 00000000 ____D C:\Program Files\tento.XT 2013-10-26 11:16 - 2013-09-04 02:15 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-26 11:16 - 2013-09-04 02:14 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-26 11:16 - 2013-09-04 02:14 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-26 11:16 - 2013-09-04 02:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-26 11:16 - 2013-09-04 02:14 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-26 11:16 - 2013-09-04 02:14 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-26 11:16 - 2013-09-04 02:14 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-25 08:04 - 2013-10-25 08:07 - 00000000 ____D C:\Users\PC\Desktop\HKM Winter 2013-10-25 07:58 - 2013-10-25 07:58 - 06112281 _____ C:\Users\PC\Desktop\Kerstin.zip 2013-10-21 17:54 - 2013-10-21 17:54 - 00000000 ____D C:\ProgramData\Oracle 2013-10-21 17:53 - 2013-10-21 17:53 - 00004266 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log 2013-10-21 17:53 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-20 13:05 - 2013-10-20 13:14 - 00000000 ____D C:\Users\PC\Desktop\Women - les plus Belles Voix Féminines de L année (2012) 2013-10-20 12:56 - 2013-10-20 13:05 - 00000000 ____D C:\Users\PC\Desktop\John Newman - Tribute (Deluxe Edition) - 2013 2013-10-20 12:55 - 2013-10-20 12:55 - 00000000 ____D C:\Users\PC\Desktop\Birdy - Fire Within (Limited Deluxe Edition) - 2013 2013-10-11 11:52 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-11 11:52 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-11 11:52 - 2013-09-23 00:28 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-11 11:52 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-11 11:52 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-11 11:52 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-11 11:52 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-11 11:42 - 2013-09-14 01:48 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-11 11:42 - 2013-09-08 03:07 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-11 11:42 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-11 11:42 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-10-11 11:42 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-11 11:42 - 2013-08-29 02:50 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-11 11:42 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-11 11:42 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-11 11:42 - 2013-08-28 02:04 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-11 11:42 - 2013-08-28 01:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-11 11:42 - 2013-08-01 12:03 - 00729024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-11 11:42 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-11 11:42 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-11 11:42 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-11 11:42 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-11 11:42 - 2013-07-04 10:48 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-11 11:42 - 2013-07-03 05:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-11 11:42 - 2013-07-03 04:36 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-11 11:42 - 2013-07-03 04:36 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-11 11:42 - 2013-06-06 05:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-11 11:42 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-11 11:42 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-11 11:42 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-11 11:42 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-11 11:41 - 2013-07-12 11:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-11 11:41 - 2013-06-25 23:56 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys ==================== One Month Modified Files and Folders ======= 2013-11-07 17:14 - 2013-11-07 17:14 - 00000750 _____ C:\Users\PC\Desktop\JRT.txt 2013-11-07 17:14 - 2009-07-14 05:34 - 00032352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-07 17:14 - 2009-07-14 05:34 - 00032352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-07 17:11 - 2013-11-07 17:11 - 01034531 _____ (Thisisu) C:\Users\PC\Desktop\JRT.exe 2013-11-07 17:11 - 2010-11-20 22:01 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-07 17:06 - 2013-07-13 17:06 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-11-07 17:06 - 2013-07-13 16:59 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-07 17:06 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-07 17:06 - 2009-07-14 05:39 - 00031494 _____ C:\Windows\setupact.log 2013-11-07 17:05 - 2013-08-25 11:35 - 00000000 ____D C:\AdwCleaner 2013-11-07 17:05 - 2013-07-13 16:53 - 01175309 _____ C:\Windows\WindowsUpdate.log 2013-11-07 17:02 - 2013-10-05 11:44 - 00000000 ____D C:\Users\PC\AppData\Roaming\MiniLyrics 2013-11-07 17:01 - 2013-11-07 17:01 - 01073262 _____ C:\Users\PC\Desktop\adwcleaner.exe 2013-11-07 16:51 - 2013-07-14 10:15 - 00000000 ____D C:\Users\PC\AppData\Roaming\Mp3tag 2013-11-07 16:47 - 2013-11-07 16:41 - 00000000 ____D C:\Users\PC\Desktop\Paloma Faith 2013-11-07 16:45 - 2013-11-07 16:36 - 00000000 ____D C:\Users\PC\Desktop\Tim Bendzko - Am Seidenen Faden (2013) 2013-11-07 12:02 - 2013-11-07 12:02 - 00016874 _____ C:\Users\PC\Desktop\Addition.txt 2013-11-07 12:00 - 2013-11-07 12:00 - 01089445 _____ (Farbar) C:\Users\PC\Desktop\FRST.exe 2013-11-07 12:00 - 2013-11-07 12:00 - 00000000 ____D C:\FRST 2013-11-06 17:42 - 2013-07-14 11:41 - 00138992 _____ C:\Windows\system32\Drivers\PnkBstrK.sys 2013-11-06 17:41 - 2013-07-14 11:47 - 00281152 _____ C:\Windows\system32\PnkBstrB.xtr 2013-11-06 17:41 - 2013-07-14 11:40 - 00281152 _____ C:\Windows\system32\PnkBstrB.exe 2013-11-06 17:17 - 2013-07-13 17:26 - 00000000 ____D C:\Users\PC\AppData\Roaming\vlc 2013-11-06 17:10 - 2013-11-06 17:08 - 00000000 ____D C:\Users\PC\Desktop\Aloe Blacc - Lift Your Spirit 2013-11-06 16:24 - 2013-11-06 16:24 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-11-03 16:06 - 2013-07-14 11:40 - 00281152 _____ C:\Windows\system32\PnkBstrB.ex0 2013-10-27 18:54 - 2013-07-14 10:27 - 00000000 ____D C:\Program Files\Opera 2013-10-27 10:51 - 2010-11-20 22:48 - 00187788 _____ C:\Windows\PFRO.log 2013-10-27 10:51 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\tracing 2013-10-26 15:20 - 2013-07-14 10:05 - 00001089 _____ C:\Users\Public\Desktop\FreeFileSync.lnk 2013-10-26 13:37 - 2013-10-26 13:35 - 00000000 ____D C:\!KillBox 2013-10-26 12:38 - 2013-10-26 12:38 - 00000910 _____ C:\Users\UpdatusUser\Desktop\tento.XT.lnk 2013-10-26 12:38 - 2013-10-26 12:38 - 00000910 _____ C:\Users\PC\Desktop\tento.XT.lnk 2013-10-26 12:38 - 2013-10-26 12:38 - 00000000 ____D C:\Program Files\tento.XT 2013-10-26 11:25 - 2013-07-14 11:35 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-10-26 11:25 - 2013-07-14 11:35 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-10-25 08:07 - 2013-10-25 08:04 - 00000000 ____D C:\Users\PC\Desktop\HKM Winter 2013-10-25 07:58 - 2013-10-25 07:58 - 06112281 _____ C:\Users\PC\Desktop\Kerstin.zip 2013-10-21 17:54 - 2013-10-21 17:54 - 00000000 ____D C:\ProgramData\Oracle 2013-10-21 17:53 - 2013-10-21 17:53 - 00004266 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log 2013-10-21 17:53 - 2013-10-05 08:02 - 00000000 ____D C:\Program Files\Java 2013-10-20 13:14 - 2013-10-20 13:05 - 00000000 ____D C:\Users\PC\Desktop\Women - les plus Belles Voix Féminines de L année (2012) 2013-10-20 13:05 - 2013-10-20 12:56 - 00000000 ____D C:\Users\PC\Desktop\John Newman - Tribute (Deluxe Edition) - 2013 2013-10-20 12:55 - 2013-10-20 12:55 - 00000000 ____D C:\Users\PC\Desktop\Birdy - Fire Within (Limited Deluxe Edition) - 2013 2013-10-14 10:39 - 2013-10-06 11:00 - 00000000 ____D C:\Users\PC\Desktop\Paul Smith Pullover 2013-10-12 17:59 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2013-10-12 17:16 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-10-12 16:30 - 2009-07-14 05:33 - 00410816 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-12 16:28 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-10-12 11:34 - 2013-07-14 09:42 - 00000000 ____D C:\Program Files\Everything 2013-10-12 11:16 - 2013-08-27 17:27 - 00000000 ____D C:\Users\PC\Documents\Eigene Scans 2013-10-12 11:15 - 2013-07-14 07:29 - 00000000 ____D C:\ProgramData\HP 2013-10-11 11:55 - 2013-07-14 13:47 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-10-11 11:54 - 2013-09-13 20:40 - 00000000 ____D C:\Windows\system32\MRT 2013-10-11 11:53 - 2013-07-13 17:38 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-11 11:47 - 2013-10-06 16:13 - 00001912 _____ C:\Windows\epplauncher.mif 2013-10-08 06:50 - 2013-10-05 08:02 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-10-08 06:46 - 2013-10-21 17:53 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-08 06:46 - 2013-10-05 08:02 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-08 06:46 - 2013-10-05 08:02 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe Some content of TEMP: ==================== C:\Users\PC\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe C:\Users\PC\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\PC\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\PC\AppData\Local\Temp\nvSCPAPI.dll C:\Users\PC\AppData\Local\Temp\nvStereoApiI.dll C:\Users\PC\AppData\Local\Temp\nvStInst.exe C:\Users\PC\AppData\Local\Temp\ose00000.exe C:\Users\PC\AppData\Local\Temp\proxy_vole4006523412661831548.dll C:\Users\PC\AppData\Local\Temp\Quarantine.exe C:\Users\PC\AppData\Local\Temp\SETUP.EXE C:\Users\PC\AppData\Local\Temp\sonarinst.exe C:\Users\PC\AppData\Local\Temp\unrar.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-01 08:52 ==================== End Of Log ============================ Kannst Du schon ein Problem erkennen? Grüße, Steve. |
08.11.2013, 10:16 | #6 |
/// the machine /// TB-Ausbilder | 10-Sekunden-Haushaltsbuch startet nicht mehr Nicht wirklich. Revo Uninstaller - Download - Filepony damit mal das Programm deinstallieren, Reste entfernen, neu installieren. Und bitte mal Link zu dem programm, wo du das lädst.
__________________ --> 10-Sekunden-Haushaltsbuch startet nicht mehr |
08.11.2013, 16:00 | #7 |
| 10-Sekunden-Haushaltsbuch startet nicht mehr Hallo, ich habe grad versucht, das Programm zu starten, es hat geklappt! Revo habe ich noch nicht genutzt, war ja jetzt erstmal nicht mehr notwendig. Dass mit dem Entfernen von Programmresten ist hier auch so eine Sache, da darin auch die gespeicherten Ein- und Ausgaben (der letzten Jahre) liegen. Das Programm habe ich direkt von der Seite des Programmierers geladen (www.guckmal.de). Wenn ich das richtig sehe, wurden bei den vorherigen Schritten nur ein Reg.Schlüssel und irgendwelche Bestandteile des FF-Profils bearbeitet. Irgendwie muss es also hieran gelegen haben. Ich schaue mal, ob es auch in den nächsten Tagen problemlos läuft und melde mich dann nochmal. Grüße, Steve. |
09.11.2013, 13:21 | #8 |
/// the machine /// TB-Ausbilder | 10-Sekunden-Haushaltsbuch startet nicht mehr ok
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.11.2013, 14:15 | #9 |
| 10-Sekunden-Haushaltsbuch startet nicht mehr Hallo nochmal, das Programm lässt sich immer noch problemlos starten, die Maßnahmen haben's also gebracht. Vielen Dank nochmal, Steve. |
24.11.2013, 08:35 | #10 |
/// the machine /// TB-Ausbilder | 10-Sekunden-Haushaltsbuch startet nicht mehr Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu 10-Sekunden-Haushaltsbuch startet nicht mehr |
antivir, avira, avira antivir, blocken, entfernt, essen, gelöscht, icon, installiert, links, malwarebytes, microsoft, neuinstallation, nicht mehr, nichts, problem, programm, schnell, schädling, security, starten, startet, startet nicht, windows 7, windows xp |