|
Plagegeister aller Art und deren Bekämpfung: getwindowinfo,wie bekomme ich diesen Trojaner weg?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
11.11.2013, 10:37 | #1 |
| getwindowinfo,wie bekomme ich diesen Trojaner weg? Hallo, auch ich habe seit einigen Tagen diesen Trojaner...wäre mir bitte jemand behilflich dieses Ding wieder von meinem PC zu entfernen? LG simplyalex |
11.11.2013, 10:50 | #2 |
/// the machine /// TB-Ausbilder | getwindowinfo,wie bekomme ich diesen Trojaner weg? hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
11.11.2013, 11:12 | #3 |
| getwindowinfo,wie bekomme ich diesen Trojaner weg? Hallo Schrauber,
__________________erstmal vielen Dank für Deine Hilfe. Hier die beiden Scans Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-11-2013 01 Ran by user at 2013-11-11 10:59:37 Running from C:\Users\user\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8) AMD Catalyst Install Manager (Version: 3.0.851.0) Ashampoo Burning Studio 2012 v.10.0.15 (x32 Version: 10.0.15) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 2.0.15.16) Audible Download Manager (x32 Version: 6.6.0.15) avast! Free Antivirus (x32 Version: 9.0.2006) Bluetooth Stack for Windows by Toshiba (Version: v7.00.05) Business plus+ (HKCU Version: 1.1.0.126) CameraHelperMsi (x32 Version: 13.50.854.0) CCleaner (Version: 4.01) D3DX10 (x32 Version: 15.4.2368.0902) DivX-Setup (x32 Version: 2.6.1.9) EPSON-Drucker-Software EPU-4 Engine (x32 Version: 1.02.01) erLT (x32 Version: 1.20.138.34) EverestPoker.com (HKCU) Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287) Free YouTube to MP3 Converter version 3.12.1.320 (x32 Version: 3.12.1.320) Google Chrome (HKCU Version: 30.0.1599.101) Google Update Helper (x32 Version: 1.3.21.165) Inkscape 0.48.4 (x32 Version: 0.48.4) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) Junk Mail filter update (x32 Version: 15.4.3502.0922) Logitech SetPoint 6.32 (Version: 6.32.20) Logitech Webcam-Software (x32 Version: 2.30) LWS Facebook (x32 Version: 13.50.854.0) LWS Gallery (x32 Version: 13.50.854.0) LWS Help_main (x32 Version: 13.50.862.0) LWS Launcher (x32 Version: 13.50.859.0) LWS Motion Detection (x32 Version: 13.30.1395.0) LWS Pictures And Video (x32 Version: 13.31.1038.0) LWS Twitter (x32 Version: 13.30.1346.0) LWS Video Mask Maker (x32 Version: 13.30.1379.0) LWS VideoEffects (Version: 13.30.1379.0) LWS Webcam Software (x32 Version: 13.31.1038.0) LWS WLM Plugin (x32 Version: 1.30.1201.0) LWS YouTube Plugin (x32 Version: 13.31.1038.0) Mesh Runtime (x32 Version: 15.4.5722.2) Messenger Companion (x32 Version: 15.4.3502.0922) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Outlook Connector (x32 Version: 14.0.5118.5000) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft SQL Server Compact 3.5 SP2 DEU (x32 Version: 3.5.8080.0) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (Version: 3.5.8080.0) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (x32 Version: 10.0.30319) Motorola Bluetooth (Version: 4.0.14.324) MSI Afterburner 2.1.0 (x32 Version: 2.1.0) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) NVIDIA 3D Vision Controller-Treiber 296.10 (Version: 296.10) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06) NVIDIA Grafiktreiber 311.06 (Version: 311.06) NVIDIA Install Application (Version: 2.1002.108.688) NVIDIA PhysX (x32 Version: 9.12.0213) NVIDIA PhysX-Systemsoftware 9.12.0213 (Version: 9.12.0213) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106) NVIDIA Systemsteuerung 311.06 (Version: 311.06) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) Platform (x32 Version: 1.34) Skype™ 6.6 (x32 Version: 6.6.106) Spotify (HKCU Version: 0.9.4.185.g7545a404) Spybot - Search & Destroy (x32 Version: 2.2.25) TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.169) TuneUp Utilities 2014 (x32 Version: 14.0.1000.169) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2827325) 32-Bit Edition (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) VIA Plattform-Geräte-Manager (x32 Version: 1.34) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3555.0308) Windows Live Family Safety (Version: 15.4.3555.0308) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3555.0308) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Mesh (x32 Version: 15.4.3502.0922) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2) Windows Live Messenger (x32 Version: 15.4.3538.0513) Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) Windows Utils (x32) WinRAR ==================== Restore Points ========================= 06-11-2013 06:23:25 TuneUp Utilities 2014 wird installiert 06-11-2013 07:02:14 Windows Update 10-11-2013 18:00:27 Windows-Sicherung ==================== Hosts content: ========================== 2009-07-14 03:34 - 2013-10-27 20:27 - 00450639 ____R C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123fporn.info 127.0.0.1 www.123fporn.info 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123moviedownload.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {067E5E75-B4A7-4F88-A88E-1C7A5DEA8758} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {195C6440-323A-4CF0-819B-57592ADF9629} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-10-20] (AVAST Software) Task: {3E142EF0-4785-4FD2-A049-80554A994C53} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe Task: {410562C0-6855-4363-9586-B023634E183F} - System32\Tasks\Google Updater and Installer => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe [2002-01-01] (Google Inc.) Task: {426920D6-C742-41CB-B902-FDB34E3864AA} - System32\Tasks\LaunchApp => C:\Program Files (x86)\JustCloud\JustCloud.exe Task: {4404C10E-DCC4-4DE6-895D-A21FAB2CCD38} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-23] (Google Inc.) Task: {4568D463-DCA2-49D4-9BE5-D3BEC7B286CE} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {472C1430-321A-45A8-8697-220FF2886880} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-23] (Google Inc.) Task: {4B279E1A-49AC-4950-B81C-A6C96F384466} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {4E8CE218-2228-4A86-AF93-85F2E399C0FE} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2013-10-30] (TuneUp Software) Task: {56BC8DEE-7E72-4F90-885A-50DCC0EB422C} - System32\Tasks\{E437A565-1254-47BD-A6A9-D22A627943FF} => Chrome.exe hxxp://ui.skype.com/ui/0/6.3.0.105/de/abandoninstall?page=tsProgressBar Task: {6B6BF3F3-4A20-4AE5-8EBB-6CABDFFDC373} - System32\Tasks\ASUS\ASUS SIX Engine => C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe [2010-02-03] (ASUSTeK Computer Inc.) Task: {7626DDE7-A56D-46E7-858A-303884D6BB51} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1623024692-3690383605-882341156-1000Core => C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-21] (Facebook Inc.) Task: {86B62057-4A0C-4421-A6D3-B0339DA68BA1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {970A0E29-A9F2-479C-9AE6-08A37A198C98} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-04-23] (Piriform Ltd) Task: {AD514FC9-860F-40A3-BE79-F30D82958CB3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1623024692-3690383605-882341156-1000UA => C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-21] (Facebook Inc.) Task: {C7516317-1601-4207-8E4E-219B5808FED4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1623024692-3690383605-882341156-1000Core => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe [2002-01-01] (Google Inc.) Task: {CDD8B18C-1DA0-4A95-9C13-64087AD0B134} - System32\Tasks\DSite => C:\Users\user\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE Task: {CE2C5FFC-F610-47F8-AF56-BE7DF6E19F69} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {D8D424AC-D05A-4902-A0F2-8AF682D4A643} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1623024692-3690383605-882341156-1000UA => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe [2002-01-01] (Google Inc.) Task: {DDCD920D-7594-4AB9-8356-E3D62E2C4C8F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1623024692-3690383605-882341156-1000Core.job => C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1623024692-3690383605-882341156-1000UA.job => C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1623024692-3690383605-882341156-1000Core.job => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1623024692-3690383605-882341156-1000UA.job => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2012-07-04 15:34 - 2010-03-15 10:28 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll 2011-10-07 10:39 - 2011-10-07 10:39 - 01304856 _____ () C:\Program Files\Logitech\SetPointP\Macros\MacroCore.dll 2002-01-01 02:04 - 2012-05-11 14:46 - 00078448 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll 2002-01-01 02:04 - 2012-05-11 14:46 - 00386160 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll 2013-11-11 09:06 - 2013-11-10 23:41 - 02140672 _____ () C:\Program Files\AVAST Software\Avast\defs\13111002\algo.dll 2013-10-20 05:59 - 2013-10-20 06:00 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-10-27 20:20 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-10-27 20:20 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-10-27 20:20 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-10-27 20:20 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-10-27 20:20 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2013-09-26 10:45 - 2013-10-01 10:24 - 00265728 _____ () C:\ProgramData\Rabatt-Finder\IEToolbar.dll 2013-10-16 09:34 - 2013-10-09 01:02 - 04055504 _____ () C:\Users\user\AppData\Local\Google\Chrome\Application\30.0.1599.101\pdf.dll 2013-10-16 09:34 - 2013-10-09 01:02 - 00415184 _____ () C:\Users\user\AppData\Local\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll 2013-10-16 09:34 - 2013-10-09 01:01 - 01604560 _____ () C:\Users\user\AppData\Local\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dll 2013-10-16 09:34 - 2013-10-09 01:02 - 13584336 _____ () C:\Users\user\AppData\Local\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll 2013-10-22 08:24 - 2013-10-22 08:24 - 04591616 _____ () C:\Users\user\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\libglesv2.dll 2013-10-22 08:24 - 2013-10-22 08:24 - 00112128 _____ () C:\Users\user\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\libegl.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\user\Desktop\ausweis1.jpeg:3or4kl4x13tuuug3Byamue2s4b AlternateDataStreams: C:\Users\user\Desktop\ausweis1.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\user\Desktop\ausweis2.jpeg:3or4kl4x13tuuug3Byamue2s4b AlternateDataStreams: C:\Users\user\Desktop\ausweis2.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: avast! Firewall NDIS Filter Miniport Description: avast! Firewall NDIS Filter Miniport Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: ALWIL Software Service: aswNdis Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19) Resolution: A registry problem was detected. This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options: On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver. ==================== Event log errors: ========================= Application errors: ================== Error: (11/11/2013 08:58:02 AM) (Source: Application Hang) (User: ) Description: Programm IEXPLORE.EXE, Version 10.0.9200.16720 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1264 Startzeit: 01cedeb37ca3d6b3 Endzeit: 8 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: Error: (11/10/2013 06:34:40 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (11/10/2013 06:34:28 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Error: (11/08/2013 09:07:13 AM) (Source: Application Hang) (User: ) Description: Programm WINWORD.EXE, Version 12.0.6683.5002 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: f24 Startzeit: 01cedb9bc6bdada6 Endzeit: 2013 Anwendungspfad: C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE Berichts-ID: Error: (11/08/2013 09:06:41 AM) (Source: Application Hang) (User: ) Description: Programm OneClick.exe, Version 14.0.1000.169 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1bbc Startzeit: 01cedbb2043d5e26 Endzeit: 17471 Anwendungspfad: C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe Berichts-ID: Error: (11/07/2013 09:44:17 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (11/07/2013 09:44:08 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Error: (11/06/2013 01:13:25 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (11/06/2013 01:13:12 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Error: (11/06/2013 07:20:38 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: rstrui.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7990c Name des fehlerhaften Moduls: rstrui.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7990c Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000001d4f9 ID des fehlerhaften Prozesses: 0x1170 Startzeit der fehlerhaften Anwendung: 0xrstrui.exe0 Pfad der fehlerhaften Anwendung: rstrui.exe1 Pfad des fehlerhaften Moduls: rstrui.exe2 Berichtskennung: rstrui.exe3 System errors: ============= Error: (11/11/2013 06:48:24 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst UMVPFSrv erreicht. Error: (11/10/2013 06:08:06 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst IPBusEnum erreicht. Error: (11/10/2013 09:05:07 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (11/10/2013 09:05:07 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (11/10/2013 09:02:19 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (11/10/2013 09:02:19 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Error: (11/09/2013 06:22:40 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (11/09/2013 06:22:40 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (11/08/2013 05:00:12 PM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (11/08/2013 09:12:41 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2012-07-04 17:20:10.800 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\VIASysFx.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-07-04 17:20:10.769 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\VIASysFx.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-07-04 17:14:41.820 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\VIASysFx.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-07-04 17:14:41.695 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\VIASysFx.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 69% Total physical RAM: 2046.18 MB Available physical RAM: 627.82 MB Total Pagefile: 4092.35 MB Available Pagefile: 1712.64 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:151.2 GB) (Free:107.28 GB) NTFS Drive e: (Volume) (Fixed) (Total:128.18 GB) (Free:66.45 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 279 GB) (Disk ID: E832186D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=151 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=128 GB) - (Type=07 NTFS) ==================== End Of Log ============================ und..... FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2013 01 Ran by user (administrator) on USER-PC on 11-11-2013 10:55:30 Running from C:\Users\user\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (Windows Net) C:\Users\user\AppData\Roaming\Windows Net Data\net.exe (Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\audiosrv.exe (Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\LEsrv.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Macrovision Europe Ltd.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosHdpProc.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech, Inc.) HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp Winlogon\Notify\LBTWlgn: C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.) MountPoints2: F - F:\AutoRun.exe MountPoints2: {d67dfc50-0e1d-11e3-9a11-bcaec50a6b81} - F:\AutoRun.exe MountPoints2: {f3ad3047-0e0d-11e3-8dc0-bcaec50a6b81} - F:\AutoRun.exe MountPoints2: {f3ad3053-0e0d-11e3-8dc0-bcaec50a6b81} - F:\AutoRun.exe MountPoints2: {f3ad3078-0e0d-11e3-8dc0-bcaec50a6b81} - F:\AutoRun.exe MountPoints2: {f3ad3091-0e0d-11e3-8dc0-bcaec50a6b81} - F:\AutoRun.exe HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5119600 2012-05-11] (VIA) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\avastui.exe [3567800 2013-10-21] (AVAST Software) AppInit_DLLs: [97280 2009-07-14] () AppInit_DLLs-x32: [ ] () Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk ShortcutTarget: net.lnk -> C:\Users\user\AppData\Roaming\Windows Net Data\net.exe (Windows Net) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=&tguid=&q= HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.de.dawanda.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=MaxtorX6V300F0_V607P63G&ts=1376500902 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=&tguid=&q= HKCU\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=&tguid= HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=&tguid=&q= HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=MaxtorX6V300F0_V607P63G&ts=1376500902 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=MaxtorX6V300F0_V607P63G&ts=1376500902 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=&tguid=&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=MaxtorX6V300F0_V607P63G&ts=1376500902 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=&tguid= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=&tguid=&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=&tguid= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=&tguid=&q= StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=MaxtorX6V300F0_V607P63G&ts=1376500902 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=MaxtorX6V300F0_V607P63G&ts=1376500903 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=MaxtorX6V300F0_V607P63G&ts=1376500903 SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=&tguid=&q={searchTerms} SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=&tguid=&q={searchTerms} SearchScopes: HKCU - DefaultScope {BF121248-3B30-4d35-90A5-E8BEE7DF9C74} URL = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=&tguid=&q={searchTerms} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=a5cd9a13-374c-4a7e-645f-878817e6fbf0&searchtype=ds&q={searchTerms}&installDate=06/09/2013 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {BF121248-3B30-4d35-90A5-E8BEE7DF9C74} URL = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=&tguid=&q={searchTerms} BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Savings Sidekick - {11111111-1111-1111-1111-110011501160} - No File BHO-x32: IEToolbar.BHO - {1d970ed5-3eda-438d-bffd-715931e2775b} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - MoneyMillionaire Toolbar - {d28c7e56-2cc6-415c-8727-d71334085926} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) DPF: HKLM-x32 {4FF78044-96B4-4312-A5B7-FDA3CB328095} Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2 Chrome: ======= CHR HomePage: hxxp://www.de.dawanda.com/ CHR RestoreOnStartup: "hxxp://www.de.dawanda.com/", "about:newtab?source=home", "hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=&tguid=" CHR Plugin: (Shockwave Flash) - C:\Users\user\AppData\Local\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\user\AppData\Local\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\user\AppData\Local\Google\Chrome\Application\30.0.1599.101\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Java(TM) Platform SE 7 U45) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (MoneyMillionaire plugin) - C:\ProgramData\Rabatt-Finder\FFExtension20131014051325\plugins\npdf.dll ( ) CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CHR Plugin: (Google Update) - C:\Users\user\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Classic) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkacjpbfdknhflllbcmjibkdeoafencn\1.1_0 CHR Extension: (Speed Dial [FVD] - New Tab Page, 3D, Sync...) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\llaficoajjainaijghjlofdfmbjpebpa\4.3.9_0 CHR Extension: (Google Wallet) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM-x32\...\Chrome\Extension: [dhdepfaagokllfmhfbcfmocaeigmoebo] - C:\Users\user\AppData\Local\Savings Sidekick\Chrome\Savings Sidekick.crx CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx CHR StartMenuInternet: Google Chrome - C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=MaxtorX6V300F0_V607P63G&ts=1376500902 ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-10-20] (AVAST Software) R2 Bluetooth Low Energy Service; C:\Program Files\Motorola\Bluetooth\LEsrv.exe [591920 2011-07-20] (Motorola Solutions, Inc.) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2099512 2013-10-30] (TuneUp Software) S4 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-04] () R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-10-20] (AVAST Software) R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-03-07] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-10-20] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-20] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-20] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-10-20] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-11-09] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-10-20] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-10-20] () R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-17] () S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [14648 2010-05-27] () R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R3 toshidpt; C:\Windows\System32\drivers\Toshidpt.sys [9608 2009-06-19] (TOSHIBA Corporation.) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-09-18] (TuneUp Software) S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S3 MSICDSetup; \??\D:\CDriver64.sys [x] S3 NPF; system32\drivers\NPF.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-11 10:54 - 2013-11-11 10:54 - 00001151 _____ C:\Users\user\Desktop\Continue Zip Extractor Installation.lnk 2013-11-11 10:54 - 2013-11-11 10:54 - 00000000 ____D C:\FRST 2013-11-11 10:53 - 2013-11-11 10:53 - 00702696 _____ C:\Users\user\Desktop\ZipExtractorSetup (1).exe 2013-11-11 10:53 - 2013-11-11 10:53 - 00652000 _____ C:\Users\user\Desktop\ZipExtractorSetup (1).rar 2013-11-11 10:53 - 2013-11-11 10:53 - 00334600 _____ C:\Users\user\Desktop\ZipExtractorSetup.exe 2013-11-11 10:53 - 2013-11-11 10:53 - 00000000 ____D C:\Users\user\Desktop\ZipExtractorSetup (1) 2013-11-11 10:50 - 2013-11-11 10:52 - 01957590 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe 2013-11-08 09:26 - 2013-11-08 09:37 - 00000000 ____D C:\Program Files (x86)\Desk 365 2013-11-08 09:26 - 2013-11-08 09:27 - 00000000 ____D C:\Users\user\AppData\Roaming\Desk 365 2013-11-08 09:25 - 2013-11-08 10:22 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-11-08 09:25 - 2013-11-08 10:21 - 00000000 ____D C:\Users\user\AppData\Local\Lollipop 2013-11-08 09:25 - 2013-11-08 09:37 - 00000000 ____D C:\ProgramData\eSafe 2013-11-08 09:24 - 2013-11-08 10:21 - 00000000 ____D C:\Program Files (x86)\Plus-HD-1.3 2013-11-08 09:24 - 2013-11-08 10:20 - 00000000 ____D C:\Program Files (x86)\Feven 1.5 2013-11-07 13:07 - 2013-11-07 13:07 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2013-11-06 07:52 - 2013-10-30 10:45 - 00043320 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2013-11-06 07:52 - 2013-10-30 10:45 - 00036152 _____ (TuneUp Software) C:\Windows\SysWOW64\uxtuneup.dll 2013-11-06 07:28 - 2013-10-30 10:45 - 00040760 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2013-11-06 07:28 - 2013-10-30 10:45 - 00029496 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2013-11-06 07:28 - 2013-10-30 10:45 - 00025400 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll 2013-11-06 07:26 - 2013-11-06 07:51 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2014 2013-11-06 07:22 - 2013-11-06 07:40 - 00000000 __SHD C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2013-11-06 07:21 - 2013-11-06 07:21 - 32522152 _____ (TuneUp Software) C:\Users\user\Desktop\TuneUpUtilities2014_de-DE.exe 2013-10-27 20:27 - 2009-06-10 22:00 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts.20131027-202736.backup 2013-10-27 20:21 - 2013-10-27 20:21 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2013-10-27 20:20 - 2013-10-27 20:26 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-27 20:20 - 2013-10-27 20:21 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-10-27 20:20 - 2013-10-27 20:20 - 00001379 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-10-27 20:20 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2013-10-26 12:45 - 2013-11-10 09:00 - 00000952 _____ C:\Windows\setupact.log 2013-10-26 12:45 - 2013-11-09 06:19 - 00003226 _____ C:\Windows\PFRO.log 2013-10-26 12:45 - 2013-10-26 12:45 - 00000000 _____ C:\Windows\setuperr.log 2013-10-26 12:18 - 2013-10-26 12:25 - 00000000 ____D C:\Users\user\AppData\Roaming\Windows Net Data 2013-10-26 12:17 - 2013-10-26 12:38 - 00000000 ____D C:\Users\user\AppData\Roaming\HomeTab 2013-10-26 12:17 - 2013-08-13 07:38 - 00032328 _____ C:\Windows\Launcher.exe 2013-10-26 12:16 - 2013-10-26 12:18 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-10-26 12:12 - 2013-10-26 12:13 - 00000000 ____D C:\Users\user\AppData\Local\DownloadGuide 2013-10-25 20:01 - 2013-10-25 20:02 - 00092286 _____ C:\Windows\system32\cc_20131025_210136.reg 2013-10-21 14:23 - 2013-10-21 14:23 - 00000000 ____D C:\Users\user\AppData\Roaming\AVAST Software 2013-10-20 07:56 - 2013-10-20 07:56 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 07:56 - 2013-10-08 06:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-20 07:56 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-20 07:56 - 2013-10-08 06:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-20 07:56 - 2013-10-08 06:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-20 07:55 - 2013-10-20 07:56 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-20 06:01 - 2013-10-20 06:01 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-10-20 00:56 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-20 00:56 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-20 00:56 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-20 00:56 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-20 00:56 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-20 00:56 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-20 00:56 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-15 10:11 - 2013-10-15 10:29 - 00000000 ____D C:\Users\user\Desktop\Renovierungskosten 2013-10-13 15:32 - 2013-10-13 15:32 - 00000000 ____D C:\Users\user\Desktop\BeexViewer ==================== One Month Modified Files and Folders ======= 2013-11-11 10:56 - 2013-03-12 05:02 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-11 10:54 - 2013-11-11 10:54 - 00001151 _____ C:\Users\user\Desktop\Continue Zip Extractor Installation.lnk 2013-11-11 10:54 - 2013-11-11 10:54 - 00000000 ____D C:\FRST 2013-11-11 10:53 - 2013-11-11 10:53 - 00702696 _____ C:\Users\user\Desktop\ZipExtractorSetup (1).exe 2013-11-11 10:53 - 2013-11-11 10:53 - 00652000 _____ C:\Users\user\Desktop\ZipExtractorSetup (1).rar 2013-11-11 10:53 - 2013-11-11 10:53 - 00334600 _____ C:\Users\user\Desktop\ZipExtractorSetup.exe 2013-11-11 10:53 - 2013-11-11 10:53 - 00000000 ____D C:\Users\user\Desktop\ZipExtractorSetup (1) 2013-11-11 10:52 - 2013-11-11 10:50 - 01957590 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe 2013-11-11 10:31 - 2009-07-14 05:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-11 10:31 - 2009-07-14 05:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-11 10:25 - 2013-01-23 06:42 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-11 10:23 - 2002-01-01 05:01 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1623024692-3690383605-882341156-1000UA.job 2013-11-11 09:06 - 2002-01-01 01:09 - 01148080 _____ C:\Windows\WindowsUpdate.log 2013-11-11 08:28 - 2013-03-21 15:21 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1623024692-3690383605-882341156-1000UA.job 2013-11-11 07:02 - 2013-01-23 06:42 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-11 06:48 - 2012-07-05 14:07 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs 2013-11-10 19:23 - 2002-01-01 05:01 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1623024692-3690383605-882341156-1000Core.job 2013-11-10 18:08 - 2013-03-21 15:21 - 00000902 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1623024692-3690383605-882341156-1000Core.job 2013-11-10 09:03 - 2012-08-10 05:34 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-10 09:01 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-10 09:01 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Registration 2013-11-10 09:00 - 2013-10-26 12:45 - 00000952 _____ C:\Windows\setupact.log 2013-11-10 09:00 - 2002-01-01 02:49 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-09 06:26 - 2012-08-10 05:34 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2013-11-09 06:19 - 2013-10-26 12:45 - 00003226 _____ C:\Windows\PFRO.log 2013-11-08 10:22 - 2013-11-08 09:25 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-11-08 10:22 - 2002-01-01 01:30 - 00000000 ___RD C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-08 10:21 - 2013-11-08 09:25 - 00000000 ____D C:\Users\user\AppData\Local\Lollipop 2013-11-08 10:21 - 2013-11-08 09:24 - 00000000 ____D C:\Program Files (x86)\Plus-HD-1.3 2013-11-08 10:20 - 2013-11-08 09:24 - 00000000 ____D C:\Program Files (x86)\Feven 1.5 2013-11-08 09:37 - 2013-11-08 09:26 - 00000000 ____D C:\Program Files (x86)\Desk 365 2013-11-08 09:37 - 2013-11-08 09:25 - 00000000 ____D C:\ProgramData\eSafe 2013-11-08 09:27 - 2013-11-08 09:26 - 00000000 ____D C:\Users\user\AppData\Roaming\Desk 365 2013-11-08 09:26 - 2011-02-19 22:03 - 00420944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll 2013-11-08 09:26 - 2011-02-18 23:40 - 00773712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll 2013-11-07 13:07 - 2013-11-07 13:07 - 00002770 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2013-11-06 08:09 - 2013-03-25 12:23 - 00003704 _____ C:\Windows\System32\Tasks\Java Update Scheduler 2013-11-06 07:53 - 2012-07-10 04:25 - 00000000 ____D C:\ProgramData\TuneUp Software 2013-11-06 07:51 - 2013-11-06 07:26 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2014 2013-11-06 07:40 - 2013-11-06 07:22 - 00000000 __SHD C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2013-11-06 07:35 - 2012-11-24 16:14 - 00000783 _____ C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EverestPoker.com.lnk 2013-11-06 07:27 - 2012-07-10 04:27 - 00000000 ____D C:\Users\user\AppData\Roaming\TuneUp Software 2013-11-06 07:21 - 2013-11-06 07:21 - 32522152 _____ (TuneUp Software) C:\Users\user\Desktop\TuneUpUtilities2014_de-DE.exe 2013-11-06 07:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Recovery 2013-11-06 07:17 - 2002-01-01 01:29 - 00000000 __SHD C:\Recovery 2013-11-06 07:15 - 2009-07-14 19:18 - 00000000 ____D C:\Windows\CSC 2013-11-06 07:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Msdtc 2013-10-30 11:47 - 2009-07-14 18:58 - 00696832 _____ C:\Windows\system32\perfh007.dat 2013-10-30 11:47 - 2009-07-14 18:58 - 00148128 _____ C:\Windows\system32\perfc007.dat 2013-10-30 11:47 - 2009-07-14 06:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-30 10:45 - 2013-11-06 07:52 - 00043320 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2013-10-30 10:45 - 2013-11-06 07:52 - 00036152 _____ (TuneUp Software) C:\Windows\SysWOW64\uxtuneup.dll 2013-10-30 10:45 - 2013-11-06 07:28 - 00040760 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2013-10-30 10:45 - 2013-11-06 07:28 - 00029496 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2013-10-30 10:45 - 2013-11-06 07:28 - 00025400 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll 2013-10-27 20:40 - 2013-10-08 18:50 - 00000000 ____D C:\Users\user\SyncFolder 2013-10-27 20:26 - 2013-10-27 20:20 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-27 20:21 - 2013-10-27 20:21 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2013-10-27 20:21 - 2013-10-27 20:20 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-10-27 20:20 - 2013-10-27 20:20 - 00001379 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-10-26 12:54 - 2002-01-01 02:04 - 00000000 ____D C:\Users\user\AppData\Roaming\DeviceVm 2013-10-26 12:45 - 2013-10-26 12:45 - 00000000 _____ C:\Windows\setuperr.log 2013-10-26 12:38 - 2013-10-26 12:17 - 00000000 ____D C:\Users\user\AppData\Roaming\HomeTab 2013-10-26 12:25 - 2013-10-26 12:18 - 00000000 ____D C:\Users\user\AppData\Roaming\Windows Net Data 2013-10-26 12:18 - 2013-10-26 12:16 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-10-26 12:17 - 2002-01-01 01:30 - 00001421 _____ C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-10-26 12:13 - 2013-10-26 12:12 - 00000000 ____D C:\Users\user\AppData\Local\DownloadGuide 2013-10-25 20:02 - 2013-10-25 20:01 - 00092286 _____ C:\Windows\system32\cc_20131025_210136.reg 2013-10-25 19:47 - 2002-01-01 01:05 - 00000000 ____D C:\Windows\Panther 2013-10-25 09:58 - 2012-07-05 11:10 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype 2013-10-25 08:59 - 2012-10-24 10:34 - 00000000 ____D C:\Users\user\AppData\Roaming\Spotify 2013-10-25 07:39 - 2012-10-24 10:35 - 00000000 ____D C:\Users\user\AppData\Local\Spotify 2013-10-25 05:01 - 2012-07-12 16:01 - 00000000 ____D C:\Program Files (x86)\Audible 2013-10-25 04:45 - 2013-09-26 10:44 - 00000000 ____D C:\ProgramData\Rabatt-Finder 2013-10-21 14:26 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-10-21 14:23 - 2013-10-21 14:23 - 00000000 ____D C:\Users\user\AppData\Roaming\AVAST Software 2013-10-20 07:56 - 2013-10-20 07:56 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 07:56 - 2013-10-20 07:55 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-20 07:56 - 2013-07-21 07:23 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-20 06:01 - 2013-10-20 06:01 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-10-20 06:00 - 2013-03-23 06:24 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-20 06:00 - 2013-03-23 06:24 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-20 06:00 - 2012-08-10 05:34 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-10-20 06:00 - 2012-08-10 05:34 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-10-20 06:00 - 2012-08-10 05:34 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-10-20 06:00 - 2012-08-10 05:34 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-10-20 06:00 - 2012-08-10 05:34 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-10-20 06:00 - 2012-08-10 05:33 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-10-20 06:00 - 2012-07-03 15:51 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-10-20 05:57 - 2012-07-03 15:49 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-20 05:56 - 2012-07-03 15:51 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-10-18 15:04 - 2013-03-19 13:58 - 00000000 ____D C:\Users\user\AppData\Local\Deployment 2013-10-15 10:29 - 2013-10-15 10:11 - 00000000 ____D C:\Users\user\Desktop\Renovierungskosten 2013-10-13 15:32 - 2013-10-13 15:32 - 00000000 ____D C:\Users\user\Desktop\BeexViewer Files to move or delete: ==================== C:\Users\user\avast_free_antivirus_setup701456.exe Some content of TEMP: ==================== C:\Users\user\AppData\Local\Temp\BackupSetup.exe C:\Users\user\AppData\Local\Temp\ICReinstall_ZipExtractorSetup (1).exe C:\Users\user\AppData\Local\Temp\Setup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-10 18:43 ==================== End Of Log ============================ LG simplyalex |
11.11.2013, 15:23 | #4 |
/// the machine /// TB-Ausbilder | getwindowinfo,wie bekomme ich diesen Trojaner weg? hi, So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu getwindowinfo,wie bekomme ich diesen Trojaner weg? |
entferne, entfernen, getwindowinfo, tagen, troja, trojaner, trojaner getwindow, trojaner weg? |