|
Plagegeister aller Art und deren Bekämpfung: Browser funktionieren nicht mehrWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
15.11.2013, 21:44 | #1 |
| Browser funktionieren nicht mehr Hallo an Alle! Seit ein paar Tagen funktionieren alle meine Browser nicht mehr. Ich habe im Internet recherchiert und verschiedene Sachen ausprobiert, aber nichts hat geholfen. Die WLAN Verbindung funktioniert einwandfrei, ich komme aber trotzdem nicht mehr ins Internet.(Im Moment benutze ich den Mac meines Mannes). Aufgrund anderer threads habe ich PING gemacht und das scheint zu funktionieren. Spätestens jetzt merkt ihr bestimmt, dass ich nicht besonders viel Ahnung von Computern habe, deshalb bin auch auch ziemlich verzweifelt. Ich hoffe es kann mir jemand helfen und ist geduldig mit meiner Unkenntnis von Fachbegriffen. Danke im Voraus, Ruthie |
16.11.2013, 11:20 | #2 |
/// the machine /// TB-Ausbilder | Browser funktionieren nicht mehr hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
16.11.2013, 17:56 | #3 |
| Browser funktionieren nicht mehr Hallo, vielen Dank für deine Antwort. Ich habe bereits gestern versucht den FRST durchzuführen, da das hier als vorbereitende Schritte gefordert wird. Deshalb habe ich wie gewünscht zuerst den Defogger installiert und drüber laufen lassen (ohne reenable), danach wollte ich den frst und den gmer. Beide hängen sich aber beim starten auf. Wenn ich den frst starten will, kommt zuerst eine fragebox, ob ich eine dial-Verbindung starten will, die mein Mann manchmal geschäftlich braucht, und wenn ich die wegklicke hängt sich der frst auf.
__________________Ich habe aber vor ein paar Tagen schon den OTL scannen lassen und poste dir hier den logfile. Defogger: defogger_disable by jpshortstuff (23.02.10.1) Log created at 22:10 on 15/11/2013 (zimmermann) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- OTL: OTL Logfile: Code:
ATTFilter OTL logfile created on: 11/13/2013 4:16:09 PM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = F:\ Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16721) Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1.96 Gb Total Physical Memory | 1.21 Gb Available Physical Memory | 61.47% Memory free 3.92 Gb Paging File | 2.82 Gb Available in Paging File | 71.79% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files Drive C: | 167.69 Gb Total Space | 51.64 Gb Free Space | 30.79% Space Free | Partition Type: NTFS Drive D: | 50.09 Gb Total Space | 49.97 Gb Free Space | 99.76% Space Free | Partition Type: NTFS Drive F: | 1.96 Gb Total Space | 1.94 Gb Free Space | 98.68% Space Free | Partition Type: FAT Computer Name: ZIMMERMANN-PC | User Name: zimmermann | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013/10/31 19:25:18 | 000,683,576 | ---- | M] (Avira Operations GmbH & Co. KG) -- c:\program files\avira\antivir desktop\avgnt.exe PRC - [2013/07/22 10:09:08 | 000,162,856 | ---- | M] (Geek Software GmbH) -- C:\Program Files\PDF24\pdf24.exe PRC - [2013/07/09 09:16:56 | 000,302,961 | ---- | M] () -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe PRC - [2013/07/06 09:18:17 | 000,879,456 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe PRC - [2013/05/16 09:59:00 | 003,830,224 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe PRC - [2013/05/16 09:56:34 | 001,033,688 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe PRC - [2013/05/16 09:56:30 | 001,817,560 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe PRC - [2013/05/15 12:21:32 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe PRC - [2012/12/05 13:22:40 | 000,092,632 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe PRC - [2012/12/05 13:22:38 | 000,247,768 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe PRC - [2012/11/23 03:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2012/10/05 21:57:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- F:\OTL.exe PRC - [2011/08/26 20:44:34 | 002,717,696 | ---- | M] (Eastman Kodak Company) -- C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe PRC - [2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010/01/19 10:34:48 | 002,201,192 | ---- | M] (SEC) -- C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe PRC - [2009/11/04 05:11:48 | 000,835,072 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe PRC - [2009/10/26 12:53:14 | 000,091,136 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe PRC - [2009/10/20 10:12:58 | 000,013,312 | ---- | M] (DoctorSoft) -- C:\Program Files\AnyPC Client\APLangApp.exe PRC - [2009/10/13 11:03:04 | 000,716,800 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe PRC - [2009/08/13 20:58:10 | 000,044,312 | ---- | M] () -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe PRC - [2009/03/30 11:34:36 | 000,241,664 | ---- | M] () -- C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe PRC - [2008/10/24 14:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe PRC - [2008/08/10 18:15:22 | 000,221,253 | ---- | M] (Aventail Corporation) -- C:\Windows\System32\ngvpnmgr.exe ========== Modules (No Company Name) ========== MOD - [2013/07/09 09:16:56 | 000,302,961 | ---- | M] () -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe MOD - [2013/05/16 09:55:28 | 000,161,112 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl MOD - [2013/05/16 09:55:26 | 000,113,496 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl MOD - [2013/05/16 09:55:24 | 000,416,600 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl MOD - [2012/02/17 19:55:35 | 000,166,912 | ---- | M] () -- C:\Program Files\WinRAR\rarext.dll MOD - [2006/08/12 04:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll ========== Services (SafeList) ========== SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDWSCService) SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDUpdateService) SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDScannerService) SRV - [2013/11/07 10:48:35 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013/10/31 19:25:40 | 000,440,376 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013/10/31 19:25:19 | 001,164,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe -- (AntiVirWebService) SRV - [2013/10/31 19:25:19 | 000,440,376 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2013/10/10 08:32:39 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/07/09 09:16:56 | 000,285,795 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe -- (HOSTS Anti-PUPs) SRV - [2013/05/27 05:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2012/12/05 13:22:40 | 000,092,632 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService) SRV - [2010/07/28 21:41:11 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2009/08/13 20:58:10 | 000,044,312 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe -- (OberonGameConsoleService) SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009/03/30 11:34:36 | 000,241,664 | ---- | M] () [Auto | Running] -- C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe -- (UI Assistant Service) SRV - [2008/10/24 14:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService) SRV - [2008/08/10 18:15:22 | 000,221,253 | ---- | M] (Aventail Corporation) [Auto | Running] -- C:\Windows\System32\ngvpnmgr.exe -- (NgVpnMgr) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\dsNcAdpt.sys -- (dsNcAdpt) DRV - [2013/10/31 19:25:19 | 000,137,208 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2013/10/31 19:25:19 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2013/10/31 19:25:19 | 000,067,680 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\avnetflt.sys -- (avnetflt) DRV - [2013/10/31 19:25:19 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012/08/27 14:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2011/03/18 12:46:26 | 000,061,704 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS) DRV - [2011/03/18 12:46:10 | 000,073,096 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K) DRV - [2010/11/23 16:10:44 | 001,249,792 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2010/11/20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010/11/20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2009/09/28 10:22:00 | 000,315,392 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7) DRV - [2009/07/14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp) DRV - [2009/07/10 14:44:52 | 000,122,880 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) DRV - [2009/01/12 09:12:56 | 000,105,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea) DRV - [2009/01/04 17:29:50 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k) DRV - [2009/01/04 17:29:50 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k) DRV - [2008/12/11 22:11:04 | 000,022,528 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Unknown] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad) DRV - [2008/12/11 22:11:04 | 000,018,816 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Stopped] -- C:\windows\System32\drivers\tcpipBM.sys -- (tcpipBM) DRV - [2008/10/29 16:35:32 | 000,007,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter.sys -- (massfilter) DRV - [2008/08/10 18:14:42 | 000,023,192 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ngwfp.sys -- (NgWfp) DRV - [2008/08/10 18:14:34 | 000,020,632 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ngfilter.sys -- (NgFilter) DRV - [2008/08/10 18:14:28 | 000,077,464 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ngvpn.sys -- (NgVpn) DRV - [2008/08/10 18:13:04 | 000,025,240 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nglog.sys -- (NgLog) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gmx.net/ IE - HKCU\..\SearchScopes,DefaultScope = IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{4A2875B3-526E-4CDD-A4CD-55633DC6E280}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=287D2BE5-0407-4EDB-B631-443CCF0E0833&apn_sauid=9B86531E-9EA2-4DE0-A7E5-DF97FB5CD124 IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" FF - prefs.js..extensions.enabledAddons: %7B195A3098-0BD5-4e90-AE22-BA1C540AFD1E%7D:4.0.4 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:25.0 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF - HKLM\Software\MozillaPlugins\@innoplus.de/ino3DViewer: C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\T-Mobile Internet Manager 03\addon [2011/11/03 10:09:07 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/11/07 10:48:31 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/11/07 10:48:31 | 000,000,000 | ---D | M] [2013/01/30 20:28:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Extensions [2013/01/30 20:28:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Extensions\home2@tomtom.com [2013/09/27 09:03:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Firefox\Profiles\ue9nijo9.default\extensions [2013/05/25 22:14:15 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Firefox\Profiles\ue9nijo9.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2013/11/07 10:48:31 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2013/11/07 10:48:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\browser\extensions [2013/11/07 10:48:36 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ========== Chrome ========== O1 HOSTS File: ([2013/11/12 10:13:17 | 001,587,203 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 212link.com O1 - Hosts: 127.0.0.1 www.ping2it.com O1 - Hosts: 127.0.0.1 dl.ividi.org O1 - Hosts: 127.0.0.1 08sr.combineads.info O1 - Hosts: 127.0.0.1 08srvr.combineads.info O1 - Hosts: 127.0.0.1 12srvr.combineads.info O1 - Hosts: 127.0.0.1 2010-fr.com O1 - Hosts: 127.0.0.1 2012-new.biz O1 - Hosts: 127.0.0.1 2319825.ourtoolbar.com O1 - Hosts: 127.0.0.1 24h00business.com O1 - Hosts: 127.0.0.1 a.daasafterdusk.com O1 - Hosts: 127.0.0.1 ad.adn360.com O1 - Hosts: 127.0.0.1 adeartss.eu O1 - Hosts: 127.0.0.1 adesoeasy.eu O1 - Hosts: 127.0.0.1 adf.girldatesforfree.net O1 - Hosts: 127.0.0.1 adm.soft365.com O1 - Hosts: 127.0.0.1 adomicileavail.googlepages.com O1 - Hosts: 127.0.0.1 ads7.complexadveising.com O1 - Hosts: 127.0.0.1 ads.aff.co O1 - Hosts: 127.0.0.1 ads.alpha00001.com O1 - Hosts: 127.0.0.1 ads.cloud4ads.com O1 - Hosts: 127.0.0.1 ads.eorezo.com O1 - Hosts: 127.0.0.1 ads.hooqy.com O1 - Hosts: 127.0.0.1 ads.icksor.com O1 - Hosts: 127.0.0.1 ads.regiedepub.com O1 - Hosts: 51303 more lines... O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [APLangApp] C:\Program Files\AnyPC Client\APLangApp.exe (DoctorSoft) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [EKAIO2StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe (Eastman Kodak Company) O4 - HKLM..\Run: [HOSTS Anti-Adware_PUPs] C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe () O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH) O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.) O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupControlXP Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.68.161.141 217.68.161.171 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{235AE447-BE14-4A06-914F-D1A7B9BFA633}: DhcpNameServer = 217.68.161.141 217.68.161.171 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{95DE52F9-5E06-47C9-BE22-4B7FE2603F77}: DhcpNameServer = 192.168.168.1 O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (c:\progra~2\browse~1\25911~1.18\{c16c1~1\mngr.dll) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{b130e3cc-05f9-11e1-8855-0024545e3669}\Shell - "" = AutoRun O33 - MountPoints2\{b130e3cc-05f9-11e1-8855-0024545e3669}\Shell\AutoRun\command - "" = F:\Install.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013/11/13 12:56:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2013/11/13 12:56:42 | 000,067,680 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avnetflt.sys [2013/11/08 10:50:48 | 000,000,000 | ---D | C] -- C:\Users\zimmermann\Desktop\Babyschwimmen [2013/11/08 10:49:41 | 000,000,000 | ---D | C] -- C:\Users\zimmermann\Desktop\ofen [2013/11/07 12:19:05 | 000,000,000 | ---D | C] -- C:\Users\zimmermann\Desktop\Maitte [2013/11/07 10:48:30 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [1 C:\Users\zimmermann\Desktop\*.tmp files -> C:\Users\zimmermann\Desktop\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013/11/13 15:42:42 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job [2013/11/13 15:42:37 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat [2013/11/13 12:46:58 | 000,014,736 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/11/13 12:46:58 | 000,014,736 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/11/13 11:45:38 | 1579,630,592 | -HS- | M] () -- C:\hiberfil.sys [2013/11/12 10:57:31 | 000,917,742 | ---- | M] () -- C:\Users\zimmermann\Desktop\avira_fusebundlegen-win32-en.zip [2013/11/12 10:21:53 | 001,085,542 | ---- | M] () -- C:\Users\zimmermann\Desktop\adwcleaner_3012.exe [2013/11/12 10:13:17 | 001,587,203 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts [2013/11/10 18:40:25 | 000,654,400 | ---- | M] () -- C:\windows\System32\perfh007.dat [2013/11/10 18:40:25 | 000,616,242 | ---- | M] () -- C:\windows\System32\perfh009.dat [2013/11/10 18:40:25 | 000,130,240 | ---- | M] () -- C:\windows\System32\perfc007.dat [2013/11/10 18:40:25 | 000,106,622 | ---- | M] () -- C:\windows\System32\perfc009.dat [2013/11/06 20:16:09 | 000,002,004 | -H-- | M] () -- C:\Users\zimmermann\Documents\Default.rdp [2013/11/06 19:55:56 | 002,092,618 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts.20131112-101317.backup [2013/11/01 20:36:39 | 000,184,251 | ---- | M] () -- C:\Users\zimmermann\Desktop\Terasse_ lippoldt.PDF [2013/10/31 21:28:53 | 000,072,707 | ---- | M] () -- C:\Users\zimmermann\Documents\brandes küchenfliesen.PDF [2013/10/31 19:25:19 | 000,137,208 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avipbb.sys [2013/10/31 19:25:19 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avgntflt.sys [2013/10/31 19:25:19 | 000,067,680 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avnetflt.sys [2013/10/31 19:25:19 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avkmgr.sys [2013/10/30 11:38:35 | 000,044,908 | ---- | M] () -- C:\Users\zimmermann\Documents\Rechnung Lidl 202531487 29.10.2013.PDF [2013/10/29 10:33:18 | 000,084,693 | ---- | M] () -- C:\Users\zimmermann\Desktop\Vertrag Maitte.pdf [2013/10/23 19:13:10 | 001,448,168 | ---- | M] () -- C:\Users\zimmermann\Documents\Stiftung Warentest Kaminöfen.pdf [1 C:\Users\zimmermann\Desktop\*.tmp files -> C:\Users\zimmermann\Desktop\*.tmp -> ] ========== Files Created - No Company Name ========== [2013/11/12 10:55:13 | 000,917,742 | ---- | C] () -- C:\Users\zimmermann\Desktop\avira_fusebundlegen-win32-en.zip [2013/11/12 10:21:44 | 001,085,542 | ---- | C] () -- C:\Users\zimmermann\Desktop\adwcleaner_3012.exe [2013/11/01 20:42:34 | 000,184,251 | ---- | C] () -- C:\Users\zimmermann\Desktop\Terasse_ lippoldt.PDF [2013/10/31 21:32:00 | 000,072,707 | ---- | C] () -- C:\Users\zimmermann\Documents\brandes küchenfliesen.PDF [2013/10/30 11:39:19 | 000,044,908 | ---- | C] () -- C:\Users\zimmermann\Documents\Rechnung Lidl 202531487 29.10.2013.PDF [2013/10/29 10:33:13 | 000,084,693 | ---- | C] () -- C:\Users\zimmermann\Desktop\Vertrag Maitte.pdf [2013/10/23 19:13:10 | 001,448,168 | ---- | C] () -- C:\Users\zimmermann\Documents\Stiftung Warentest Kaminöfen.pdf [2010/09/06 11:03:51 | 000,011,383 | ---- | C] () -- C:\Users\zimmermann\gsview32.ini [2010/05/06 16:50:12 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe ========== ZeroAccess Check ========== [2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2010/05/08 11:57:15 | 000,000,000 | -HSD | M] -- C:\Users\zimmermann\AppData\Roaming\.# [2011/11/03 11:14:25 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Aventail [2010/12/19 12:11:19 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\elsterformular [2013/01/10 11:28:55 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Fighters [2011/04/09 17:39:53 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Foxit Software [2010/05/08 11:55:33 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\GameConsole [2011/07/21 15:12:51 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\GARMIN [2011/11/02 19:22:45 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Go Go Gourmet [2012/05/28 13:20:19 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\innoplus [2010/09/01 17:45:20 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Juniper Networks [2012/08/15 16:27:22 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\LaunchPad [2012/02/08 10:10:33 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Opera [2011/11/03 10:09:18 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Program Files [2011/08/16 17:16:02 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Simfy [2010/08/22 19:03:59 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Softland [2013/01/30 20:28:34 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\TomTom ========== Purity Check ========== ========== Files - Unicode (All) ========== [2013/01/14 12:14:30 | 002,176,484 | ---- | C] ()(C:\Users\zimmermann\Desktop\_?ALLROUNDER?_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf) -- C:\Users\zimmermann\Desktop\_♥ALLROUNDER♥_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf [2013/01/14 12:12:28 | 002,176,484 | ---- | M] ()(C:\Users\zimmermann\Desktop\_?ALLROUNDER?_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf) -- C:\Users\zimmermann\Desktop\_♥ALLROUNDER♥_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf ========== Alternate Data Streams ========== @Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:A42A9F39 < End of report > Vielen Dank, ruthie Hallo, vielen Dank für deine Antwort. Ich habe bereits gestern versucht den FRST durchzuführen, da das hier als vorbereitende Schritte gefordert wird. Deshalb habe ich wie gewünscht zuerst den Defogger installiert und drüber laufen lassen (ohne reenable), danach wollte ich den frst und den gmer. Beide hängen sich aber beim starten auf. Wenn ich den frst starten will, kommt zuerst eine fragebox, ob ich eine dial-Verbindung starten will, die mein Mann manchmal geschäftlich braucht, und wenn ich die wegklicke hängt sich der frst auf. Ich habe aber vor ein paar Tagen schon den OTL scannen lassen und poste dir hier den logfile. Defogger: defogger_disable by jpshortstuff (23.02.10.1) Log created at 22:10 on 15/11/2013 (zimmermann) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- OTL: OTL Logfile: Code:
ATTFilter OTL logfile created on: 11/13/2013 4:16:09 PM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = F:\ Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16721) Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1.96 Gb Total Physical Memory | 1.21 Gb Available Physical Memory | 61.47% Memory free 3.92 Gb Paging File | 2.82 Gb Available in Paging File | 71.79% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files Drive C: | 167.69 Gb Total Space | 51.64 Gb Free Space | 30.79% Space Free | Partition Type: NTFS Drive D: | 50.09 Gb Total Space | 49.97 Gb Free Space | 99.76% Space Free | Partition Type: NTFS Drive F: | 1.96 Gb Total Space | 1.94 Gb Free Space | 98.68% Space Free | Partition Type: FAT Computer Name: ZIMMERMANN-PC | User Name: zimmermann | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013/10/31 19:25:18 | 000,683,576 | ---- | M] (Avira Operations GmbH & Co. KG) -- c:\program files\avira\antivir desktop\avgnt.exe PRC - [2013/07/22 10:09:08 | 000,162,856 | ---- | M] (Geek Software GmbH) -- C:\Program Files\PDF24\pdf24.exe PRC - [2013/07/09 09:16:56 | 000,302,961 | ---- | M] () -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe PRC - [2013/07/06 09:18:17 | 000,879,456 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe PRC - [2013/05/16 09:59:00 | 003,830,224 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe PRC - [2013/05/16 09:56:34 | 001,033,688 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe PRC - [2013/05/16 09:56:30 | 001,817,560 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe PRC - [2013/05/15 12:21:32 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe PRC - [2012/12/05 13:22:40 | 000,092,632 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe PRC - [2012/12/05 13:22:38 | 000,247,768 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe PRC - [2012/11/23 03:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2012/10/05 21:57:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- F:\OTL.exe PRC - [2011/08/26 20:44:34 | 002,717,696 | ---- | M] (Eastman Kodak Company) -- C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe PRC - [2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010/01/19 10:34:48 | 002,201,192 | ---- | M] (SEC) -- C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe PRC - [2009/11/04 05:11:48 | 000,835,072 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe PRC - [2009/10/26 12:53:14 | 000,091,136 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe PRC - [2009/10/20 10:12:58 | 000,013,312 | ---- | M] (DoctorSoft) -- C:\Program Files\AnyPC Client\APLangApp.exe PRC - [2009/10/13 11:03:04 | 000,716,800 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe PRC - [2009/08/13 20:58:10 | 000,044,312 | ---- | M] () -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe PRC - [2009/03/30 11:34:36 | 000,241,664 | ---- | M] () -- C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe PRC - [2008/10/24 14:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe PRC - [2008/08/10 18:15:22 | 000,221,253 | ---- | M] (Aventail Corporation) -- C:\Windows\System32\ngvpnmgr.exe ========== Modules (No Company Name) ========== MOD - [2013/07/09 09:16:56 | 000,302,961 | ---- | M] () -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe MOD - [2013/05/16 09:55:28 | 000,161,112 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl MOD - [2013/05/16 09:55:26 | 000,113,496 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl MOD - [2013/05/16 09:55:24 | 000,416,600 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl MOD - [2012/02/17 19:55:35 | 000,166,912 | ---- | M] () -- C:\Program Files\WinRAR\rarext.dll MOD - [2006/08/12 04:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll ========== Services (SafeList) ========== SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDWSCService) SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDUpdateService) SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDScannerService) SRV - [2013/11/07 10:48:35 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013/10/31 19:25:40 | 000,440,376 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013/10/31 19:25:19 | 001,164,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe -- (AntiVirWebService) SRV - [2013/10/31 19:25:19 | 000,440,376 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2013/10/10 08:32:39 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/07/09 09:16:56 | 000,285,795 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe -- (HOSTS Anti-PUPs) SRV - [2013/05/27 05:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2012/12/05 13:22:40 | 000,092,632 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService) SRV - [2010/07/28 21:41:11 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2009/08/13 20:58:10 | 000,044,312 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe -- (OberonGameConsoleService) SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009/03/30 11:34:36 | 000,241,664 | ---- | M] () [Auto | Running] -- C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe -- (UI Assistant Service) SRV - [2008/10/24 14:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService) SRV - [2008/08/10 18:15:22 | 000,221,253 | ---- | M] (Aventail Corporation) [Auto | Running] -- C:\Windows\System32\ngvpnmgr.exe -- (NgVpnMgr) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\dsNcAdpt.sys -- (dsNcAdpt) DRV - [2013/10/31 19:25:19 | 000,137,208 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2013/10/31 19:25:19 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2013/10/31 19:25:19 | 000,067,680 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\avnetflt.sys -- (avnetflt) DRV - [2013/10/31 19:25:19 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012/08/27 14:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2011/03/18 12:46:26 | 000,061,704 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS) DRV - [2011/03/18 12:46:10 | 000,073,096 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K) DRV - [2010/11/23 16:10:44 | 001,249,792 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2010/11/20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010/11/20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2009/09/28 10:22:00 | 000,315,392 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7) DRV - [2009/07/14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp) DRV - [2009/07/10 14:44:52 | 000,122,880 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) DRV - [2009/01/12 09:12:56 | 000,105,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea) DRV - [2009/01/04 17:29:50 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k) DRV - [2009/01/04 17:29:50 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k) DRV - [2008/12/11 22:11:04 | 000,022,528 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Unknown] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad) DRV - [2008/12/11 22:11:04 | 000,018,816 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Stopped] -- C:\windows\System32\drivers\tcpipBM.sys -- (tcpipBM) DRV - [2008/10/29 16:35:32 | 000,007,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter.sys -- (massfilter) DRV - [2008/08/10 18:14:42 | 000,023,192 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ngwfp.sys -- (NgWfp) DRV - [2008/08/10 18:14:34 | 000,020,632 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ngfilter.sys -- (NgFilter) DRV - [2008/08/10 18:14:28 | 000,077,464 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ngvpn.sys -- (NgVpn) DRV - [2008/08/10 18:13:04 | 000,025,240 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nglog.sys -- (NgLog) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gmx.net/ IE - HKCU\..\SearchScopes,DefaultScope = IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{4A2875B3-526E-4CDD-A4CD-55633DC6E280}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=287D2BE5-0407-4EDB-B631-443CCF0E0833&apn_sauid=9B86531E-9EA2-4DE0-A7E5-DF97FB5CD124 IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" FF - prefs.js..extensions.enabledAddons: %7B195A3098-0BD5-4e90-AE22-BA1C540AFD1E%7D:4.0.4 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:25.0 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF - HKLM\Software\MozillaPlugins\@innoplus.de/ino3DViewer: C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\T-Mobile Internet Manager 03\addon [2011/11/03 10:09:07 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/11/07 10:48:31 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/11/07 10:48:31 | 000,000,000 | ---D | M] [2013/01/30 20:28:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Extensions [2013/01/30 20:28:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Extensions\home2@tomtom.com [2013/09/27 09:03:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Firefox\Profiles\ue9nijo9.default\extensions [2013/05/25 22:14:15 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Firefox\Profiles\ue9nijo9.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2013/11/07 10:48:31 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2013/11/07 10:48:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\browser\extensions [2013/11/07 10:48:36 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ========== Chrome ========== O1 HOSTS File: ([2013/11/12 10:13:17 | 001,587,203 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 212link.com O1 - Hosts: 127.0.0.1 www.ping2it.com O1 - Hosts: 127.0.0.1 dl.ividi.org O1 - Hosts: 127.0.0.1 08sr.combineads.info O1 - Hosts: 127.0.0.1 08srvr.combineads.info O1 - Hosts: 127.0.0.1 12srvr.combineads.info O1 - Hosts: 127.0.0.1 2010-fr.com O1 - Hosts: 127.0.0.1 2012-new.biz O1 - Hosts: 127.0.0.1 2319825.ourtoolbar.com O1 - Hosts: 127.0.0.1 24h00business.com O1 - Hosts: 127.0.0.1 a.daasafterdusk.com O1 - Hosts: 127.0.0.1 ad.adn360.com O1 - Hosts: 127.0.0.1 adeartss.eu O1 - Hosts: 127.0.0.1 adesoeasy.eu O1 - Hosts: 127.0.0.1 adf.girldatesforfree.net O1 - Hosts: 127.0.0.1 adm.soft365.com O1 - Hosts: 127.0.0.1 adomicileavail.googlepages.com O1 - Hosts: 127.0.0.1 ads7.complexadveising.com O1 - Hosts: 127.0.0.1 ads.aff.co O1 - Hosts: 127.0.0.1 ads.alpha00001.com O1 - Hosts: 127.0.0.1 ads.cloud4ads.com O1 - Hosts: 127.0.0.1 ads.eorezo.com O1 - Hosts: 127.0.0.1 ads.hooqy.com O1 - Hosts: 127.0.0.1 ads.icksor.com O1 - Hosts: 127.0.0.1 ads.regiedepub.com O1 - Hosts: 51303 more lines... O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [APLangApp] C:\Program Files\AnyPC Client\APLangApp.exe (DoctorSoft) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [EKAIO2StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe (Eastman Kodak Company) O4 - HKLM..\Run: [HOSTS Anti-Adware_PUPs] C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe () O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH) O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.) O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupControlXP Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.68.161.141 217.68.161.171 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{235AE447-BE14-4A06-914F-D1A7B9BFA633}: DhcpNameServer = 217.68.161.141 217.68.161.171 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{95DE52F9-5E06-47C9-BE22-4B7FE2603F77}: DhcpNameServer = 192.168.168.1 O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (c:\progra~2\browse~1\25911~1.18\{c16c1~1\mngr.dll) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{b130e3cc-05f9-11e1-8855-0024545e3669}\Shell - "" = AutoRun O33 - MountPoints2\{b130e3cc-05f9-11e1-8855-0024545e3669}\Shell\AutoRun\command - "" = F:\Install.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013/11/13 12:56:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2013/11/13 12:56:42 | 000,067,680 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avnetflt.sys [2013/11/08 10:50:48 | 000,000,000 | ---D | C] -- C:\Users\zimmermann\Desktop\Babyschwimmen [2013/11/08 10:49:41 | 000,000,000 | ---D | C] -- C:\Users\zimmermann\Desktop\ofen [2013/11/07 12:19:05 | 000,000,000 | ---D | C] -- C:\Users\zimmermann\Desktop\Maitte [2013/11/07 10:48:30 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [1 C:\Users\zimmermann\Desktop\*.tmp files -> C:\Users\zimmermann\Desktop\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013/11/13 15:42:42 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job [2013/11/13 15:42:37 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat [2013/11/13 12:46:58 | 000,014,736 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/11/13 12:46:58 | 000,014,736 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/11/13 11:45:38 | 1579,630,592 | -HS- | M] () -- C:\hiberfil.sys [2013/11/12 10:57:31 | 000,917,742 | ---- | M] () -- C:\Users\zimmermann\Desktop\avira_fusebundlegen-win32-en.zip [2013/11/12 10:21:53 | 001,085,542 | ---- | M] () -- C:\Users\zimmermann\Desktop\adwcleaner_3012.exe [2013/11/12 10:13:17 | 001,587,203 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts [2013/11/10 18:40:25 | 000,654,400 | ---- | M] () -- C:\windows\System32\perfh007.dat [2013/11/10 18:40:25 | 000,616,242 | ---- | M] () -- C:\windows\System32\perfh009.dat [2013/11/10 18:40:25 | 000,130,240 | ---- | M] () -- C:\windows\System32\perfc007.dat [2013/11/10 18:40:25 | 000,106,622 | ---- | M] () -- C:\windows\System32\perfc009.dat [2013/11/06 20:16:09 | 000,002,004 | -H-- | M] () -- C:\Users\zimmermann\Documents\Default.rdp [2013/11/06 19:55:56 | 002,092,618 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts.20131112-101317.backup [2013/11/01 20:36:39 | 000,184,251 | ---- | M] () -- C:\Users\zimmermann\Desktop\Terasse_ lippoldt.PDF [2013/10/31 21:28:53 | 000,072,707 | ---- | M] () -- C:\Users\zimmermann\Documents\brandes küchenfliesen.PDF [2013/10/31 19:25:19 | 000,137,208 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avipbb.sys [2013/10/31 19:25:19 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avgntflt.sys [2013/10/31 19:25:19 | 000,067,680 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avnetflt.sys [2013/10/31 19:25:19 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avkmgr.sys [2013/10/30 11:38:35 | 000,044,908 | ---- | M] () -- C:\Users\zimmermann\Documents\Rechnung Lidl 202531487 29.10.2013.PDF [2013/10/29 10:33:18 | 000,084,693 | ---- | M] () -- C:\Users\zimmermann\Desktop\Vertrag Maitte.pdf [2013/10/23 19:13:10 | 001,448,168 | ---- | M] () -- C:\Users\zimmermann\Documents\Stiftung Warentest Kaminöfen.pdf [1 C:\Users\zimmermann\Desktop\*.tmp files -> C:\Users\zimmermann\Desktop\*.tmp -> ] ========== Files Created - No Company Name ========== [2013/11/12 10:55:13 | 000,917,742 | ---- | C] () -- C:\Users\zimmermann\Desktop\avira_fusebundlegen-win32-en.zip [2013/11/12 10:21:44 | 001,085,542 | ---- | C] () -- C:\Users\zimmermann\Desktop\adwcleaner_3012.exe [2013/11/01 20:42:34 | 000,184,251 | ---- | C] () -- C:\Users\zimmermann\Desktop\Terasse_ lippoldt.PDF [2013/10/31 21:32:00 | 000,072,707 | ---- | C] () -- C:\Users\zimmermann\Documents\brandes küchenfliesen.PDF [2013/10/30 11:39:19 | 000,044,908 | ---- | C] () -- C:\Users\zimmermann\Documents\Rechnung Lidl 202531487 29.10.2013.PDF [2013/10/29 10:33:13 | 000,084,693 | ---- | C] () -- C:\Users\zimmermann\Desktop\Vertrag Maitte.pdf [2013/10/23 19:13:10 | 001,448,168 | ---- | C] () -- C:\Users\zimmermann\Documents\Stiftung Warentest Kaminöfen.pdf [2010/09/06 11:03:51 | 000,011,383 | ---- | C] () -- C:\Users\zimmermann\gsview32.ini [2010/05/06 16:50:12 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe ========== ZeroAccess Check ========== [2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2010/05/08 11:57:15 | 000,000,000 | -HSD | M] -- C:\Users\zimmermann\AppData\Roaming\.# [2011/11/03 11:14:25 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Aventail [2010/12/19 12:11:19 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\elsterformular [2013/01/10 11:28:55 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Fighters [2011/04/09 17:39:53 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Foxit Software [2010/05/08 11:55:33 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\GameConsole [2011/07/21 15:12:51 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\GARMIN [2011/11/02 19:22:45 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Go Go Gourmet [2012/05/28 13:20:19 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\innoplus [2010/09/01 17:45:20 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Juniper Networks [2012/08/15 16:27:22 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\LaunchPad [2012/02/08 10:10:33 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Opera [2011/11/03 10:09:18 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Program Files [2011/08/16 17:16:02 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Simfy [2010/08/22 19:03:59 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Softland [2013/01/30 20:28:34 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\TomTom ========== Purity Check ========== ========== Files - Unicode (All) ========== [2013/01/14 12:14:30 | 002,176,484 | ---- | C] ()(C:\Users\zimmermann\Desktop\_?ALLROUNDER?_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf) -- C:\Users\zimmermann\Desktop\_♥ALLROUNDER♥_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf [2013/01/14 12:12:28 | 002,176,484 | ---- | M] ()(C:\Users\zimmermann\Desktop\_?ALLROUNDER?_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf) -- C:\Users\zimmermann\Desktop\_♥ALLROUNDER♥_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf ========== Alternate Data Streams ========== @Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:A42A9F39 < End of report > Vielen Dank, ruthie Hallo Schrauber, jetzt hat es doch noch funktioniert, keine Ahnung warum. Hier die beiden Files: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-11-2013 Ran by zimmermann (administrator) on ZIMMERMANN-PC on 16-11-2013 17:50:03 Running from C:\Users\zimmermann\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Aventail Corporation) C:\windows\system32\ngvpnmgr.exe () C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe () C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe () C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (SEC) C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (DoctorSoft) C:\Program Files\AnyPC Client\APLangApp.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Eastman Kodak Company) C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe (Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\windows\system32\igfxext.exe (Intel Corporation) C:\windows\system32\igfxsrvc.exe (Opera Software) C:\Program Files\Opera\opera.exe (Farbar) C:\Users\zimmermann\Desktop\FRST-1.exe (Microsoft Corporation) C:\windows\system32\wuauclt.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8120864 2009-12-14] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated) HKLM\...\Run: [APLangApp] - C:\Program Files\AnyPC Client\APLangApp.exe [13312 2009-10-20] (DoctorSoft) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [] - [x] HKLM\...\Run: [EKAIO2StatusMonitor] - C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe [2717696 2011-08-26] (Eastman Kodak Company) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-03-27] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Run: [HOSTS Anti-Adware_PUPs] - C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe [302961 2013-07-09] () HKLM\...\Run: [PDFPrint] - C:\Program Files\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) MountPoints2: {b130e3cc-05f9-11e1-8855-0024545e3669} - F:\Install.exe AppInit_DLLs: c:\progra~2\browse~1\25911~1.18\{c16c1~1\mngr.dll [ ] () Startup: C:\Users\zimmermann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gmx.net/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {4A2875B3-526E-4CDD-A4CD-55633DC6E280} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=287D2BE5-0407-4EDB-B631-443CCF0E0833&apn_sauid=9B86531E-9EA2-4DE0-A7E5-DF97FB5CD124 BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 217.68.161.141 217.68.161.171 FireFox: ======== FF ProfilePath: C:\Users\zimmermann\AppData\Roaming\Mozilla\Firefox\Profiles\ue9nijo9.default FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @garmin.com/GpsControl - C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin: @innoplus.de/ino3DViewer - C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: Garmin Communicator - C:\Users\zimmermann\AppData\Roaming\Mozilla\Firefox\Profiles\ue9nijo9.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} FF HKLM\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile Internet Manager 03\addon FF Extension: Bytemobile Optimization Client - C:\Program Files\T-Mobile Internet Manager 03\addon Chrome: ======= ========================== Services (Whitelisted) ================= R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S2 HOSTS Anti-PUPs; C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe [285795 2013-07-09] () R2 NgVpnMgr; C:\windows\system32\ngvpnmgr.exe [221253 2008-08-10] (Aventail Corporation) R2 OberonGameConsoleService; C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe [44312 2009-08-13] () R2 UI Assistant Service; C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe [241664 2009-03-30] () ==================== Drivers (Whitelisted) ==================== S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [61704 2011-03-18] (FTDI Ltd.) S3 grmnusb; C:\Windows\System32\drivers\grmnusb.sys [9344 2009-04-17] (GARMIN Corp.) S3 MBAMSwissArmy; C:\windows\system32\drivers\mbamswissarmy.sys [40776 2013-11-14] (Malwarebytes Corporation) S3 NgFilter; C:\Windows\System32\DRIVERS\ngfilter.sys [20632 2008-08-10] (Aventail Corporation) R3 NgLog; C:\Windows\System32\DRIVERS\nglog.sys [25240 2008-08-10] (Aventail Corporation) R3 NgVpn; C:\Windows\System32\DRIVERS\ngvpn.sys [77464 2008-08-10] (Aventail Corporation) R3 NgWfp; C:\Windows\System32\DRIVERS\ngwfp.sys [23192 2008-08-10] (Aventail Corporation) R1 SABI; C:\windows\system32\Drivers\SABI.sys [10752 2009-05-28] (SAMSUNG ELECTRONICS) R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] () S3 dsNcAdpt; system32\DRIVERS\dsNcAdpt.sys [x] U3 kfryrpod; \??\C:\Users\ZIMMER~1\AppData\Local\Temp\kfryrpod.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-16 17:50 - 2013-11-16 17:50 - 00011304 _____ C:\Users\zimmermann\Desktop\FRST.txt 2013-11-16 17:50 - 2013-11-16 17:50 - 00000000 ____D C:\FRST 2013-11-15 22:53 - 2013-04-04 13:45 - 00377856 _____ C:\Users\zimmermann\Desktop\gmer_2.1.19163.exe 2013-11-15 22:28 - 2013-11-14 00:02 - 01090529 _____ (Farbar) C:\Users\zimmermann\Desktop\FRST-1.exe 2013-11-15 22:10 - 2013-11-15 22:16 - 00000482 _____ C:\Users\zimmermann\Desktop\defogger_disable.log 2013-11-15 22:10 - 2013-11-15 22:10 - 00000000 _____ C:\Users\zimmermann\defogger_reenable 2013-11-15 22:04 - 2013-11-15 21:52 - 00050477 _____ C:\Users\zimmermann\Desktop\Defogger.exe 2013-11-15 00:15 - 2013-11-15 00:15 - 00000079 _____ C:\windows\wininit.ini 2013-11-15 00:09 - 2013-11-15 00:09 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2013-11-14 18:52 - 2013-11-14 18:52 - 00040776 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamswissarmy.sys 2013-11-14 18:33 - 2013-11-12 10:13 - 01587203 _____ C:\windows\system32\Drivers\etc\hosts.20131114-183350.backup 2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\Malwarebytes 2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-14 18:16 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll 2013-11-14 18:16 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL 2013-11-14 18:16 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL 2013-11-14 18:16 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll 2013-11-14 18:16 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll 2013-11-14 18:16 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\windows\system32\authui.dll 2013-11-14 18:16 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\credui.dll 2013-11-14 18:16 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll 2013-11-14 18:16 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys 2013-11-14 18:16 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys 2013-11-14 18:16 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2013-11-14 18:16 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll 2013-11-14 18:16 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll 2013-11-14 18:16 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2013-11-14 18:16 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll 2013-11-14 18:16 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe 2013-11-14 18:16 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll 2013-11-14 18:16 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys 2013-11-14 10:47 - 2013-10-12 08:04 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-11-14 10:47 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-11-14 10:47 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-11-14 10:47 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-11-14 10:47 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-11-13 18:52 - 2013-11-12 10:13 - 01587203 ____R C:\windows\system32\Drivers\etc\hosts.20131113-185208.backup 2013-11-13 12:54 - 2013-11-13 12:55 - 126764512 _____ C:\Users\zimmermann\Downloads\avira_free_antivirus_de.exe 2013-11-12 10:55 - 2013-11-12 10:57 - 00917742 _____ C:\Users\zimmermann\Desktop\avira_fusebundlegen-win32-en.zip 2013-11-12 10:21 - 2013-11-12 10:21 - 01085542 _____ C:\Users\zimmermann\Desktop\adwcleaner_3012.exe 2013-11-12 10:13 - 2013-11-06 19:55 - 02092618 _____ C:\windows\system32\Drivers\etc\hosts.20131112-101317.backup 2013-11-07 12:19 - 2013-11-07 12:19 - 00000000 ____D C:\Users\zimmermann\Desktop\Maitte 2013-11-07 10:48 - 2013-11-13 18:12 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-11-16 17:50 - 2013-11-16 17:50 - 00011304 _____ C:\Users\zimmermann\Desktop\FRST.txt 2013-11-16 17:50 - 2013-11-16 17:50 - 00000000 ____D C:\FRST 2013-11-16 17:49 - 2012-06-24 11:23 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2013-11-16 17:49 - 2009-12-05 03:40 - 01866928 _____ C:\windows\WindowsUpdate.log 2013-11-15 22:29 - 2009-07-14 05:34 - 00014736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-15 22:29 - 2009-07-14 05:34 - 00014736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-15 22:16 - 2013-11-15 22:10 - 00000482 _____ C:\Users\zimmermann\Desktop\defogger_disable.log 2013-11-15 22:10 - 2013-11-15 22:10 - 00000000 _____ C:\Users\zimmermann\defogger_reenable 2013-11-15 22:10 - 2010-05-06 16:48 - 00000000 ____D C:\Users\zimmermann 2013-11-15 22:05 - 2009-07-26 21:06 - 01498742 _____ C:\windows\system32\PerfStringBackup.INI 2013-11-15 21:52 - 2013-11-15 22:04 - 00050477 _____ C:\Users\zimmermann\Desktop\Defogger.exe 2013-11-15 00:15 - 2013-11-15 00:15 - 00000079 _____ C:\windows\wininit.ini 2013-11-15 00:15 - 2013-07-09 09:21 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2 2013-11-15 00:09 - 2013-11-15 00:09 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2013-11-14 23:53 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\NDF 2013-11-14 23:28 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT 2013-11-14 23:27 - 2009-07-14 05:39 - 00138020 _____ C:\windows\setupact.log 2013-11-14 23:27 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\de-DE 2013-11-14 20:22 - 2010-05-06 16:57 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-14 19:25 - 2009-12-05 04:19 - 00968620 _____ C:\windows\PFRO.log 2013-11-14 18:52 - 2013-11-14 18:52 - 00040776 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamswissarmy.sys 2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\Malwarebytes 2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-14 10:47 - 2013-07-26 09:49 - 00000000 ____D C:\windows\system32\MRT 2013-11-14 10:45 - 2010-06-22 07:34 - 80340640 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-11-14 00:02 - 2013-11-15 22:28 - 01090529 _____ (Farbar) C:\Users\zimmermann\Desktop\FRST-1.exe 2013-11-13 18:12 - 2013-11-07 10:48 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-11-13 17:32 - 2010-11-24 11:13 - 00927232 ___SH C:\Users\zimmermann\Desktop\Thumbs.db 2013-11-13 12:55 - 2013-11-13 12:54 - 126764512 _____ C:\Users\zimmermann\Downloads\avira_free_antivirus_de.exe 2013-11-13 11:30 - 2013-08-29 16:12 - 00009284 _____ C:\Users\zimmermann\Desktop\Hochzeit.xlsx 2013-11-12 10:57 - 2013-11-12 10:55 - 00917742 _____ C:\Users\zimmermann\Desktop\avira_fusebundlegen-win32-en.zip 2013-11-12 10:28 - 2013-08-27 20:11 - 00000000 ____D C:\AdwCleaner 2013-11-12 10:21 - 2013-11-12 10:21 - 01085542 _____ C:\Users\zimmermann\Desktop\adwcleaner_3012.exe 2013-11-12 10:13 - 2013-11-14 18:33 - 01587203 _____ C:\windows\system32\Drivers\etc\hosts.20131114-183350.backup 2013-11-12 10:13 - 2013-11-13 18:52 - 01587203 ____R C:\windows\system32\Drivers\etc\hosts.20131113-185208.backup 2013-11-08 20:33 - 2012-03-11 17:41 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\vlc 2013-11-08 20:26 - 2012-07-07 18:29 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\dvdcss 2013-11-07 12:19 - 2013-11-07 12:19 - 00000000 ____D C:\Users\zimmermann\Desktop\Maitte 2013-11-06 20:16 - 2011-11-03 11:16 - 00002004 ____H C:\Users\zimmermann\Documents\Default.rdp 2013-11-06 19:55 - 2013-11-12 10:13 - 02092618 _____ C:\windows\system32\Drivers\etc\hosts.20131112-101317.backup 2013-10-22 18:00 - 2009-07-14 03:37 - 00000000 ____D C:\windows\rescache Some content of TEMP: ==================== C:\Users\zimmermann\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-10 19:21 ==================== End Of Log ============================ --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 14-11-2013 Ran by zimmermann at 2013-11-16 17:50:44 Running from C:\Users\zimmermann\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Disabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) 3D-Viewer-innoplus (Version: 14.00.70) AAVUpdateManager (Version: 16.00.0000) Adobe AIR (Version: 2.7.1.19610) Adobe Flash Player 11 ActiveX (Version: 11.9.900.117) Adobe Flash Player 11 Plugin (Version: 11.9.900.117) Adobe Reader 9.5.1 - Deutsch (Version: 9.5.1) AnyPC Client (Version: 1.0.0.23) Atheros Client Installation Program (Version: 1.0.1.0805) Aventail Connect (Version: 9.1.33) BatteryLifeExtender (Version: 1.0.1) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000) doPDF 7.1 printer Easy Display Manager (Version: 3.0) Easy Network Manager (Version: 4.2.6) Easy SpeedUp Manager (Version: 3.0.0.5) EasyBatteryManager (Version: 4.0.0.3) Edna Bricht Aus - Sammler Edition (Version: 1.0) Foxit Reader (Version: 4.3.1.323) Game Pack (Version: 5.3.0.10) Garmin BaseCamp (Version: 3.2.1) Garmin TransAlpin v2 (Version: 2.0.0.0) Garmin USB Drivers (Version: 2.3.0.0) Google Toolbar for Internet Explorer (Version: 1.0.0) Intel(R) Graphics Media Accelerator Driver (Version: 8.15.10.2202) Intel® Matrix Storage Manager Java 7 Update 25 (Version: 7.0.250) Java Auto Updater (Version: 2.1.9.5) Junk Mail filter update (Version: 14.0.8089.726) Marvell Miniport Driver (Version: 11.22.3.3) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Choice Guard (Version: 2.0.48.0) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Suite Activation Assistant (Version: 2.9) Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual Basic 6.0 Enterprise Edition (Deutsch) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (Version: 10.0.40303) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (Version: 10.0.40308) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU (Version: 10.0.40303) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (Version: 10.0.40303) Microsoft Web Publishing Wizard 1.53 Microsoft Works (Version: 9.7.0621) MSVCRT (Version: 14.0.1468.721) Opera 12.16 (Version: 12.16.1860) PDF24 Creator 5.7.0 Realtek High Definition Audio Driver (Version: 6.0.1.6003) Samsung Recovery Solution 4 (Version: 4.0.0.6) Samsung Support Center (Version: 1.0.21) Samsung Update Plus (Version: 2.0) Steuer-Spar-Erklärung 2011 (Version: 16.06) Synaptics Pointing Device Driver (Version: 15.0.10.0) T-Mobile Internet Manager 03 (Version: 1.0.0.1) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825642) 32-Bit Edition Update für Microsoft Office Excel 2007 Help (KB963678) Update für Microsoft Office Outlook 2007 Help (KB963677) Update für Microsoft Office Powerpoint 2007 Help (KB963669) Update für Microsoft Office Word 2007 Help (KB963665) User Guide (Version: 1.0) VLC media player 2.0.1 (Version: 2.0.1) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) (Version: 06/03/2009 2.3.0.0) Windows Live Call (Version: 14.0.8064.0206) Windows Live Communications Platform (Version: 14.0.8064.206) Windows Live Essentials (Version: 14.0.8089.0726) Windows Live Essentials (Version: 14.0.8089.726) Windows Live Family Safety (Version: 14.0.8093.805) Windows Live Fotogalerie (Version: 14.0.8081.709) Windows Live ID-Anmelde-Assistent (Version: 6.500.3165.0) Windows Live Mail (Version: 14.0.8089.0726) Windows Live Messenger (Version: 14.0.8089.0726) Windows Live Movie Maker (Version: 14.0.8091.0730) Windows Live Sync (Version: 14.0.8089.726) Windows Live Writer (Version: 14.0.8089.0726) Windows Live-Uploadtool (Version: 14.0.8014.1029) WinRAR 4.11 (32-Bit) (Version: 4.11.0) ==================== Restore Points ========================= 22-08-2013 18:26:12 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2009-07-14 03:04 - 2013-11-12 10:13 - 01587203 ____N C:\windows\system32\Drivers\etc\hosts 127.0.0.1 212link.com 127.0.0.1 www.ping2it.com 127.0.0.1 dl.ividi.org 127.0.0.1 08sr.combineads.info 127.0.0.1 08srvr.combineads.info 127.0.0.1 12srvr.combineads.info 127.0.0.1 2010-fr.com 127.0.0.1 2012-new.biz 127.0.0.1 2319825.ourtoolbar.com 127.0.0.1 24h00business.com 127.0.0.1 a.daasafterdusk.com 127.0.0.1 ad.adn360.com 127.0.0.1 adeartss.eu 127.0.0.1 adesoeasy.eu 127.0.0.1 adf.girldatesforfree.net 127.0.0.1 adm.soft365.com 127.0.0.1 adomicileavail.googlepages.com 127.0.0.1 ads7.complexadveising.com 127.0.0.1 ads.aff.co 127.0.0.1 ads.alpha00001.com 127.0.0.1 ads.cloud4ads.com 127.0.0.1 ads.eorezo.com 127.0.0.1 ads.hooqy.com 127.0.0.1 ads.icksor.com 127.0.0.1 ads.regiedepub.com 127.0.0.1 ads.sucomspot.com 127.0.0.1 ads.tersecta.com 127.0.0.1 a.dungtank.com 127.0.0.1 adwcleaner.programmesetjeux.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {210FA61D-92F6-4FEE-B312-06AF7D4D93D5} - System32\Tasks\APSchedulerC => C:\Program Files\AnyPC Client\APLanMgrC.exe [2009-10-20] (DoctorSoft) Task: {2D577A20-059C-43FE-B6C0-1FB82EC956F8} - System32\Tasks\BatteryLifeExtender => C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2009-11-19] (Samsung Electronics. Co. Ltd.) Task: {48A6287D-9267-44E7-99FD-21FCA0982FF8} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe [2010-04-20] () Task: {56D2FA95-1D75-45C8-90A0-CB573A6E4439} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-10] (Adobe Systems Incorporated) Task: {5F228EBA-627F-4F7A-99DA-16995E5B9D76} - System32\Tasks\advSRS4 => C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2010-01-19] (SEC) Task: {88A49655-48B3-4C5D-8CD2-9B43A4A79D2F} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2009-11-04] (Samsung Electronics Co., Ltd.) Task: {8D4D5684-8FAB-4077-95EB-C9C0BBB68E80} - System32\Tasks\EasySpeedUpManager => C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe [2009-10-13] (Samsung Electronics Co., Ltd.) Task: {9A171F4D-432A-42AF-A3CC-EBCB4A1C5430} - System32\Tasks\SamsungSupportCenter => C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [2009-10-26] (SAMSUNG Electronics) Task: {A27BCA4D-2345-41B2-B23F-C1C1C656C2F4} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation) Task: {B0B9B8F6-0C8D-4755-997C-110671056F18} - System32\Tasks\VisualBeeRecovery => C:\Users\zimmermann\AppData\Local\VisualBeeExe\VisualBeeRecovery.exe Task: {CC0D875C-93E1-46F8-B7B7-80E0B3BCFA41} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2009-10-16] (SAMSUNG Electronics co., LTD.) Task: {E4D704BA-DD15-44B2-A951-16E1AAAB8843} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2012-04-21 17:40 - 2012-02-17 19:55 - 00166912 _____ () C:\Program Files\WinRAR\rarext.dll 2009-12-05 03:54 - 2006-08-12 04:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:A42A9F39 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/16/2013 11:55:54 AM) (Source: System Restore) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x80042308). Error: (11/16/2013 11:55:54 AM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Volume bzw. Datenträger ist nicht richtig angeschlossen oder wurde nicht gefunden. Fehlerkontext: GetComputerNameEx(3, NULL, [0]) [0]. Vorgang: BeginPrepareSnapshot wird verarbeitet Snapshotkontext Kontext: Ausführungskontext: System Provider Volumename: \\?\Volume{edcff9ed-e1d4-11de-abe6-806e6f6e6963}\ Snapshot-ID: {74dbca27-4965-44e4-b10e-a448e13bfb79} Error: (11/15/2013 10:54:38 PM) (Source: Application Hang) (User: ) Description: Programm gmer_2.1.19163.exe, Version 2.1.19163.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 14f0 Startzeit: 01cee24d34810fc8 Endzeit: 16 Anwendungspfad: C:\Users\zimmermann\Desktop\gmer_2.1.19163.exe Berichts-ID: 8182d7cd-4e40-11e3-89dc-415645000030 Error: (11/15/2013 10:48:31 PM) (Source: Application Hang) (User: ) Description: Programm FRST-1.exe, Version 3.3.8.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1348 Startzeit: 01cee24c03335286 Endzeit: 32 Anwendungspfad: C:\Users\zimmermann\Desktop\FRST-1.exe Berichts-ID: a5178cb1-4e3f-11e3-89dc-415645000030 Error: (11/15/2013 10:30:07 PM) (Source: Application Hang) (User: ) Description: Programm FRST-1.exe, Version 3.3.8.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 162c Startzeit: 01cee2499dc77558 Endzeit: 16 Anwendungspfad: C:\Users\zimmermann\Desktop\FRST-1.exe Berichts-ID: f8d139da-4e3c-11e3-89dc-415645000030 Error: (11/15/2013 10:25:10 PM) (Source: Application Hang) (User: ) Description: Programm FRST.exe, Version 3.3.8.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: e84 Startzeit: 01cee2491d9a3cc7 Endzeit: 31 Anwendungspfad: C:\Users\zimmermann\Desktop\FRST.exe Berichts-ID: 6548104f-4e3c-11e3-89dc-415645000030 Error: (11/15/2013 10:24:20 PM) (Source: Application Hang) (User: ) Description: Programm FRST.exe, Version 3.3.8.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: fbc Startzeit: 01cee248e32f50de Endzeit: 31 Anwendungspfad: C:\Users\zimmermann\Desktop\FRST.exe Berichts-ID: 452ffc0d-4e3c-11e3-89dc-415645000030 Error: (11/15/2013 00:01:05 AM) (Source: Application Hang) (User: ) Description: Programm iexplore.exe, Version 10.0.9200.16736 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1638 Startzeit: 01cee18c6fd5a75d Endzeit: 32 Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe Berichts-ID: Error: (11/14/2013 11:50:48 PM) (Source: Application Hang) (User: ) Description: Programm DllHost.exe, Version 6.1.7600.16385 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 414 Startzeit: 01cee18bc6cccfc8 Endzeit: 16 Anwendungspfad: C:\windows\system32\DllHost.exe Berichts-ID: 2ce27710-4d7f-11e3-89dc-415645000030 Error: (11/14/2013 11:41:03 PM) (Source: Application Hang) (User: ) Description: Programm DllHost.exe, Version 6.1.7600.16385 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 139c Startzeit: 01cee18a26fe7c20 Endzeit: 0 Anwendungspfad: C:\windows\system32\DllHost.exe Berichts-ID: 9cae6874-4d7d-11e3-89dc-415645000030 System errors: ============= Error: (11/16/2013 05:50:44 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst LanmanWorkstation erreicht. Error: (11/16/2013 05:50:14 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht. Error: (11/16/2013 05:49:44 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht. Error: (11/16/2013 11:48:51 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht. Error: (11/16/2013 11:43:32 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht. Error: (11/16/2013 11:43:02 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht. Error: (11/16/2013 11:42:32 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst LanmanWorkstation erreicht. Error: (11/16/2013 11:42:02 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht. Error: (11/16/2013 11:41:32 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht. Error: (11/15/2013 10:42:31 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht. Microsoft Office Sessions: ========================= Error: (12/31/2011 00:21:41 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3 seconds with 0 seconds of active time. This session ended with a crash. Error: (12/31/2011 00:15:32 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4 seconds with 0 seconds of active time. This session ended with a crash. Error: (12/31/2011 00:13:00 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8 seconds with 0 seconds of active time. This session ended with a crash. Error: (12/31/2011 00:05:12 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2 seconds with 0 seconds of active time. This session ended with a crash. Error: (07/19/2011 03:26:55 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6557.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 17601 seconds with 540 seconds of active time. This session ended with a crash. Error: (04/28/2011 03:36:25 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6 seconds with 0 seconds of active time. This session ended with a crash. Error: (03/08/2011 04:19:42 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 19069 seconds with 480 seconds of active time. This session ended with a crash. Error: (03/02/2011 09:21:14 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 11 seconds with 0 seconds of active time. This session ended with a crash. Error: (09/05/2010 11:12:31 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6535.5002, Microsoft Office Version: 12.0.6425.1000. This session lasted 260 seconds with 0 seconds of active time. This session ended with a crash. Error: (09/03/2010 00:04:32 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 11832 seconds with 1920 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Percentage of memory in use: 41% Total physical RAM: 2008.61 MB Available physical RAM: 1179.36 MB Total Pagefile: 4017.21 MB Available Pagefile: 2966.48 MB Total Virtual: 2047.88 MB Available Virtual: 1909.88 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:167.69 GB) (Free:52.33 GB) NTFS Drive d: () (Fixed) (Total:50.09 GB) (Free:49.97 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 233 GB) (Disk ID: 0E0EF5DF) Partition 1: (Not Active) - (Size=15 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=168 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=50 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
17.11.2013, 07:24 | #4 | |
/// the machine /// TB-Ausbilder | Browser funktionieren nicht mehrCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.11.2013, 11:38 | #5 |
| Browser funktionieren nicht mehr Hier das file, ich hoffe ich hatte alles deaktiviert. Gruß, ruthie Combofix Logfile: Code:
ATTFilter ComboFix 13-11-16.01 - zimmermann 17.11.2013 9:08.1.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.2009.1213 [GMT 1:00] ausgef¸hrt von:: c:\users\zimmermann\Desktop\ComboFix.exe SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Lˆschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\zimmermann\AppData\Roaming\.# . . ((((((((((((((((((((((( Dateien erstellt von 2013-10-17 bis 2013-11-17 )))))))))))))))))))))))))))))) . . 2013-11-17 08:29 . 2013-11-17 08:29 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-11-17 08:11 . 2013-11-17 08:11 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1257CDD1-F497-4498-AD3E-BFBC75C38A91}\offreg.dll 2013-11-16 16:50 . 2013-11-16 16:50 -------- d-----w- C:\FRST 2013-11-16 10:55 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1257CDD1-F497-4498-AD3E-BFBC75C38A91}\mpengine.dll 2013-11-14 23:09 . 2013-11-14 23:09 -------- d-----w- c:\program files\Common Files\Bitdefender 2013-11-14 17:52 . 2013-11-14 17:52 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2013-11-14 17:24 . 2013-11-14 17:24 -------- d-----w- c:\users\zimmermann\AppData\Roaming\Malwarebytes 2013-11-14 17:24 . 2013-11-14 17:24 -------- d-----w- c:\programdata\Malwarebytes . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-10-10 07:32 . 2012-06-24 10:23 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-10-10 07:32 . 2011-06-26 08:52 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-09-14 00:48 . 2013-10-08 19:55 338944 ----a-w- c:\windows\system32\drivers\afd.sys 2013-09-08 02:07 . 2013-10-08 19:55 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-09-08 02:03 . 2013-10-08 19:55 231424 ----a-w- c:\windows\system32\mswsock.dll 2013-09-04 01:15 . 2013-10-08 19:55 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys 2013-09-04 01:14 . 2013-10-08 19:55 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2013-09-04 01:14 . 2013-10-08 19:55 284672 ----a-w- c:\windows\system32\drivers\usbport.sys 2013-09-04 01:14 . 2013-10-08 19:55 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys 2013-09-04 01:14 . 2013-10-08 19:55 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys 2013-09-04 01:14 . 2013-10-08 19:55 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2013-09-04 01:14 . 2013-10-08 19:55 6016 ----a-w- c:\windows\system32\drivers\usbd.sys 2013-09-03 12:35 . 2010-07-02 17:22 238872 ------w- c:\windows\system32\MpSigStub.exe 2013-08-29 01:51 . 2013-10-08 19:55 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-08-29 01:51 . 2013-10-08 19:55 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-08-29 01:50 . 2013-10-08 19:55 1289096 ----a-w- c:\windows\system32\ntdll.dll 2013-08-29 01:50 . 2013-10-08 19:55 619520 ----a-w- c:\windows\system32\tdh.dll 2013-08-29 01:48 . 2013-10-08 19:55 640512 ----a-w- c:\windows\system32\advapi32.dll 2013-08-28 01:04 . 2013-10-08 19:55 2348544 ----a-w- c:\windows\system32\win32k.sys 2013-08-28 00:57 . 2013-10-08 19:55 434688 ----a-w- c:\windows\system32\scavengeui.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Eintr‰ge & legitime Standardeintr‰ge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-12-14 8120864] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-02-26 1713448] "APLangApp"="c:\program files\AnyPC Client\APLangApp.exe" [2009-10-20 13312] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520] "EKAIO2StatusMonitor"="c:\windows\system32\spool\DRIVERS\W32X86\3\EKAiO2MUI.exe" [2011-08-26 2717696] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "PDFPrint"="c:\program files\PDF24\pdf24.exe" [2013-07-22 162856] . c:\users\zimmermann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe . R2 UI Assistant Service;UI Assistant Service;c:\program files\T-Mobile Internet Manager 03\AssistantServices.exe [2009-03-30 241664] R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2008-10-29 7680] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2013-11-14 40776] R3 NgFilter;Aventail VPN Filter;c:\windows\system32\DRIVERS\ngfilter.sys [2008-08-10 20632] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-28 1343400] S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2009-05-28 10752] S2 AAV UpdateService;AAV UpdateService;c:\program files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [2008-10-24 128296] S2 NgVpnMgr;Aventail VPN Client;c:\windows\system32\ngvpnmgr.exe [2008-08-10 221253] S2 OberonGameConsoleService;Oberon Media Game Console service;c:\program files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe [2009-08-13 44312] S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-07-10 122880] S3 NgLog;Aventail VPN Logging;c:\windows\system32\DRIVERS\nglog.sys [2008-08-10 25240] S3 NgVpn;Aventail VPN Adapter;c:\windows\system32\DRIVERS\ngvpn.sys [2008-08-10 77464] S3 NgWfp;Aventail VPN Callout;c:\windows\system32\DRIVERS\ngwfp.sys [2008-08-10 23192] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - KFRYRPOD *Deregistered* - BMLoad *Deregistered* - kfryrpod . Inhalt des "geplante Tasks" Ordners . 2013-11-17 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-24 07:32] . . ------- Zus‰tzlicher Suchlauf ------- . uStart Page = hxxp://www.gmx.net/ IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 217.68.161.141 217.68.161.171 . - - - - Entfernte verwaiste Registrierungseintr‰ge - - - - . Toolbar-Locked - (no file) SafeBoot-mcmscsvc SafeBoot-MCODS AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\bm_installer.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-11-17 09:34:28 ComboFix-quarantined-files.txt 2013-11-17 08:32 . Vor Suchlauf: 9 Verzeichnis(se), 57.067.335.680 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 57.464.975.360 Bytes frei . - - End Of File - - D3C2557DEE0DD586023198D8F29E0C7F 2E5DEBB2116B3417023E0D6562D7ED07 Hallo Schrauber, ich habe noch eine Frage. Vor ein paar Tagen hatte auch mein Mann mal am Laptop rumgedoktort (nachdem es schon nicht mehr ging), da er dachte er könne das Problem besser lösen als ich. Jemand auf Arbeit hatte ihm gesagt er solle ausprobieren, ob das laptop noch funktioniert, wenn er es ans LAN direkt dran hängt und nicht über WLAN geht. Das hat er auch ausprobiert und es ging nicht. Seit dem funktioniert aber auch sein PC nicht mehr, den er ausschließlich für die Arbeit braucht und mit dem er eine Verbindung zum Firmennetzwerk aufbauen muss. Kann es sein, dass er unseren Router infiziert hat, durch das dranhängen meines Laptops und somit auch seinen PC? Es funktionieren nur noch apple Geräte. Danke für deine Antwort, Ruthie |
17.11.2013, 18:19 | #6 |
/// the machine /// TB-Ausbilder | Browser funktionieren nicht mehr Möglich. Router auf Werkseinstellungen zurücksetzen, Ihr müsst die Verbindungsdaten neu eingeben. Dann: Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Browser funktionieren nicht mehr |
17.11.2013, 21:28 | #7 |
| Browser funktionieren nicht mehr Erst mal wieder Danke! Hatte AdwCleaner schon auf meinem laptop. Beim Malware-Entferner konnte ich kein Update durchführen, hoffe es war die aktuelle Version. AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.012 - Bericht erstellt am 17/11/2013 um 19:23:04 # Updated 11/11/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : zimmermann - ZIMMERMANN-PC # Gestartet von : C:\Users\zimmermann\Desktop\adwcleaner_3012.exe # Option : Lˆschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verkn¸pfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16736 -\\ Mozilla Firefox v [ Datei : C:\Users\zimmermann\AppData\Roaming\Mozilla\Firefox\Profiles\ue9nijo9.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\zimmermann\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [2801 octets] - [27/08/2013 20:12:38] AdwCleaner[R1].txt - [2247 octets] - [12/11/2013 10:24:44] AdwCleaner[R2].txt - [2307 octets] - [12/11/2013 10:27:41] AdwCleaner[R3].txt - [1233 octets] - [17/11/2013 19:21:35] AdwCleaner[S0].txt - [2648 octets] - [27/08/2013 20:20:06] AdwCleaner[S1].txt - [2368 octets] - [12/11/2013 10:28:39] AdwCleaner[S2].txt - [1155 octets] - [17/11/2013 19:23:04] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1215 octets] ########## Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.17.03 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16736 zimmermann :: ZIMMERMANN-PC [Administrator] Schutz: Aktiviert 17.11.2013 19:43:52 mbam-log-2013-11-17 (19-43-52).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 339202 Laufzeit: 57 Minute(n), 49 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\AdwCleaner\Quarantine\C\Users\ZIMMER~1\AppData\Local\Temp\OCS\ocs_v7d.exe.vir (PUP.Optional.DownloadSponsor.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Home Premium x86 Ran by zimmermann on 17.11.2013 at 21:04:12,41 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1871111397-3539990770-1974983793-1001\Software\ib updater Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1871111397-3539990770-1974983793-1001\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\dmwu_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\dmwu_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\etype_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\etype_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\etypesetup_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\etypesetup_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\etypeuninstall_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\etypeuninstall_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\etypeupdate_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\etypeupdate_rasmancs Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{4A2875B3-526E-4CDD-A4CD-55633DC6E280} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\fighters" Successfully deleted: [Folder] "C:\Users\zimmermann\AppData\Roaming\fighters" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 17.11.2013 at 21:07:49,05 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-11-2013 02 Ran by zimmermann (administrator) on ZIMMERMANN-PC on 17-11-2013 21:16:18 Running from C:\Users\zimmermann\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Aventail Corporation) C:\windows\system32\ngvpnmgr.exe () C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe () C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (SEC) C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Intel Corporation) C:\windows\system32\igfxext.exe (Intel Corporation) C:\windows\system32\igfxsrvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Eastman Kodak Company) C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\windows\system32\wuauclt.exe (Farbar) C:\Users\zimmermann\Desktop\FRST-5.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8120864 2009-12-14] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated) HKLM\...\Run: [APLangApp] - C:\Program Files\AnyPC Client\APLangApp.exe [13312 2009-10-20] (DoctorSoft) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [EKAIO2StatusMonitor] - C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe [2717696 2011-08-26] (Eastman Kodak Company) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-03-27] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Run: [PDFPrint] - C:\Program Files\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) Startup: C:\Users\zimmermann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gmx.net/ SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 217.68.161.141 217.68.161.171 FireFox: ======== FF ProfilePath: C:\Users\zimmermann\AppData\Roaming\Mozilla\Firefox\Profiles\ue9nijo9.default FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @garmin.com/GpsControl - C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin: @innoplus.de/ino3DViewer - C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: Garmin Communicator - C:\Users\zimmermann\AppData\Roaming\Mozilla\Firefox\Profiles\ue9nijo9.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} FF HKLM\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile Internet Manager 03\addon FF Extension: Bytemobile Optimization Client - C:\Program Files\T-Mobile Internet Manager 03\addon Chrome: ======= ========================== Services (Whitelisted) ================= R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NgVpnMgr; C:\windows\system32\ngvpnmgr.exe [221253 2008-08-10] (Aventail Corporation) R2 OberonGameConsoleService; C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe [44312 2009-08-13] () R2 UI Assistant Service; C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe [241664 2009-03-30] () ==================== Drivers (Whitelisted) ==================== S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [61704 2011-03-18] (FTDI Ltd.) S3 grmnusb; C:\Windows\System32\drivers\grmnusb.sys [9344 2009-04-17] (GARMIN Corp.) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 NgFilter; C:\Windows\System32\DRIVERS\ngfilter.sys [20632 2008-08-10] (Aventail Corporation) R3 NgLog; C:\Windows\System32\DRIVERS\nglog.sys [25240 2008-08-10] (Aventail Corporation) R3 NgVpn; C:\Windows\System32\DRIVERS\ngvpn.sys [77464 2008-08-10] (Aventail Corporation) R3 NgWfp; C:\Windows\System32\DRIVERS\ngwfp.sys [23192 2008-08-10] (Aventail Corporation) R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] () U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\ZIMMER~1\AppData\Local\Temp\catchme.sys [x] S3 dsNcAdpt; system32\DRIVERS\dsNcAdpt.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-17 21:15 - 2013-11-17 16:00 - 01090935 _____ (Farbar) C:\Users\zimmermann\Desktop\FRST-5.exe 2013-11-17 21:07 - 2013-11-17 21:07 - 00002453 _____ C:\Users\zimmermann\Desktop\JRT.txt 2013-11-17 21:04 - 2013-11-17 21:04 - 00000000 ____D C:\windows\ERUNT 2013-11-17 19:36 - 2013-11-05 23:36 - 01034531 _____ (Thisisu) C:\Users\zimmermann\Desktop\JRT-1.exe 2013-11-17 19:04 - 2013-11-17 19:04 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-17 19:04 - 2013-11-17 19:04 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-11-17 19:04 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2013-11-17 19:03 - 2013-11-17 19:00 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\zimmermann\Desktop\mbam-setup-1-1.75.0.1300.exe 2013-11-17 10:48 - 2013-11-17 10:48 - 00008736 _____ C:\Users\zimmermann\Desktop\ComboFix.txt 2013-11-17 10:39 - 2013-11-17 10:39 - 00000000 ____D C:\32788R22FWJFW 2013-11-17 09:34 - 2013-11-17 09:34 - 00008736 _____ C:\ComboFix.txt 2013-11-17 09:06 - 2013-11-17 09:34 - 00000000 ____D C:\Qoobox 2013-11-17 09:06 - 2011-06-26 07:45 - 00256000 _____ C:\windows\PEV.exe 2013-11-17 09:06 - 2010-11-07 18:20 - 00208896 _____ C:\windows\MBR.exe 2013-11-17 09:06 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe 2013-11-17 09:06 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe 2013-11-17 09:06 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe 2013-11-17 09:06 - 2000-08-31 01:00 - 00098816 _____ C:\windows\sed.exe 2013-11-17 09:06 - 2000-08-31 01:00 - 00080412 _____ C:\windows\grep.exe 2013-11-17 09:06 - 2000-08-31 01:00 - 00068096 _____ C:\windows\zip.exe 2013-11-17 09:05 - 2013-11-17 09:30 - 00000000 ____D C:\windows\erdnt 2013-11-17 09:01 - 2013-11-16 08:29 - 05146587 ____R (Swearware) C:\Users\zimmermann\Desktop\ComboFix.exe 2013-11-16 17:50 - 2013-11-17 21:16 - 00010842 _____ C:\Users\zimmermann\Desktop\FRST.txt 2013-11-16 17:50 - 2013-11-16 17:51 - 00022360 _____ C:\Users\zimmermann\Desktop\Addition.txt 2013-11-16 17:50 - 2013-11-16 17:50 - 00000000 ____D C:\FRST 2013-11-15 22:53 - 2013-04-04 13:45 - 00377856 _____ C:\Users\zimmermann\Desktop\gmer_2.1.19163.exe 2013-11-15 22:10 - 2013-11-15 22:16 - 00000482 _____ C:\Users\zimmermann\Desktop\defogger_disable.log 2013-11-15 22:10 - 2013-11-15 22:10 - 00000000 _____ C:\Users\zimmermann\defogger_reenable 2013-11-15 22:04 - 2013-11-15 21:52 - 00050477 _____ C:\Users\zimmermann\Desktop\Defogger.exe 2013-11-15 00:15 - 2013-11-15 00:15 - 00000079 _____ C:\windows\wininit.ini 2013-11-15 00:09 - 2013-11-15 00:09 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2013-11-14 18:33 - 2013-11-12 10:13 - 01587203 _____ C:\windows\system32\Drivers\etc\hosts.20131114-183350.backup 2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\Malwarebytes 2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-14 18:16 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll 2013-11-14 18:16 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL 2013-11-14 18:16 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL 2013-11-14 18:16 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll 2013-11-14 18:16 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll 2013-11-14 18:16 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\windows\system32\authui.dll 2013-11-14 18:16 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\credui.dll 2013-11-14 18:16 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll 2013-11-14 18:16 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys 2013-11-14 18:16 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys 2013-11-14 18:16 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2013-11-14 18:16 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll 2013-11-14 18:16 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll 2013-11-14 18:16 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2013-11-14 18:16 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll 2013-11-14 18:16 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe 2013-11-14 18:16 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll 2013-11-14 18:16 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys 2013-11-14 10:47 - 2013-10-12 08:04 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-11-14 10:47 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-11-14 10:47 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-11-14 10:47 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-11-14 10:47 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-11-13 18:52 - 2013-11-12 10:13 - 01587203 ____R C:\windows\system32\Drivers\etc\hosts.20131113-185208.backup 2013-11-13 12:54 - 2013-11-13 12:55 - 126764512 _____ C:\Users\zimmermann\Downloads\avira_free_antivirus_de.exe 2013-11-12 10:21 - 2013-11-12 10:21 - 01085542 _____ C:\Users\zimmermann\Desktop\adwcleaner_3012.exe 2013-11-12 10:13 - 2013-11-06 19:55 - 02092618 _____ C:\windows\system32\Drivers\etc\hosts.20131112-101317.backup 2013-11-07 12:19 - 2013-11-07 12:19 - 00000000 ____D C:\Users\zimmermann\Desktop\Maitte 2013-11-07 10:48 - 2013-11-13 18:12 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-11-17 21:16 - 2013-11-16 17:50 - 00010842 _____ C:\Users\zimmermann\Desktop\FRST.txt 2013-11-17 21:15 - 2013-01-03 18:28 - 00000000 ____D C:\Users\zimmermann\Desktop\Mama Texte 2013-11-17 21:07 - 2013-11-17 21:07 - 00002453 _____ C:\Users\zimmermann\Desktop\JRT.txt 2013-11-17 21:04 - 2013-11-17 21:04 - 00000000 ____D C:\windows\ERUNT 2013-11-17 21:00 - 2009-07-14 05:34 - 00014736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-17 21:00 - 2009-07-14 05:34 - 00014736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-17 20:51 - 2009-12-05 21:21 - 00000000 ____D C:\windows\de-DE 2013-11-17 20:51 - 2009-12-05 04:19 - 00974278 _____ C:\windows\PFRO.log 2013-11-17 20:51 - 2009-12-05 03:40 - 01934013 _____ C:\windows\WindowsUpdate.log 2013-11-17 20:51 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT 2013-11-17 20:51 - 2009-07-14 05:39 - 00138244 _____ C:\windows\setupact.log 2013-11-17 20:35 - 2012-06-24 11:23 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2013-11-17 19:23 - 2013-08-27 20:11 - 00000000 ____D C:\AdwCleaner 2013-11-17 19:04 - 2013-11-17 19:04 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-17 19:04 - 2013-11-17 19:04 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-11-17 19:00 - 2013-11-17 19:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\zimmermann\Desktop\mbam-setup-1-1.75.0.1300.exe 2013-11-17 16:00 - 2013-11-17 21:15 - 01090935 _____ (Farbar) C:\Users\zimmermann\Desktop\FRST-5.exe 2013-11-17 10:48 - 2013-11-17 10:48 - 00008736 _____ C:\Users\zimmermann\Desktop\ComboFix.txt 2013-11-17 10:39 - 2013-11-17 10:39 - 00000000 ____D C:\32788R22FWJFW 2013-11-17 10:07 - 2009-07-14 03:37 - 00000000 ____D C:\windows\rescache 2013-11-17 09:34 - 2013-11-17 09:34 - 00008736 _____ C:\ComboFix.txt 2013-11-17 09:34 - 2013-11-17 09:06 - 00000000 ____D C:\Qoobox 2013-11-17 09:34 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Default 2013-11-17 09:34 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public 2013-11-17 09:30 - 2013-11-17 09:05 - 00000000 ____D C:\windows\erdnt 2013-11-17 09:29 - 2009-07-14 03:04 - 00000215 _____ C:\windows\system.ini 2013-11-16 17:51 - 2013-11-16 17:50 - 00022360 _____ C:\Users\zimmermann\Desktop\Addition.txt 2013-11-16 17:50 - 2013-11-16 17:50 - 00000000 ____D C:\FRST 2013-11-16 08:29 - 2013-11-17 09:01 - 05146587 ____R (Swearware) C:\Users\zimmermann\Desktop\ComboFix.exe 2013-11-15 22:16 - 2013-11-15 22:10 - 00000482 _____ C:\Users\zimmermann\Desktop\defogger_disable.log 2013-11-15 22:10 - 2013-11-15 22:10 - 00000000 _____ C:\Users\zimmermann\defogger_reenable 2013-11-15 22:10 - 2010-05-06 16:48 - 00000000 ____D C:\Users\zimmermann 2013-11-15 22:05 - 2009-07-26 21:06 - 01498742 _____ C:\windows\system32\PerfStringBackup.INI 2013-11-15 21:52 - 2013-11-15 22:04 - 00050477 _____ C:\Users\zimmermann\Desktop\Defogger.exe 2013-11-15 00:15 - 2013-11-15 00:15 - 00000079 _____ C:\windows\wininit.ini 2013-11-15 00:09 - 2013-11-15 00:09 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2013-11-14 23:53 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\NDF 2013-11-14 23:27 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\de-DE 2013-11-14 20:22 - 2010-05-06 16:57 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\Malwarebytes 2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-14 10:47 - 2013-07-26 09:49 - 00000000 ____D C:\windows\system32\MRT 2013-11-14 10:45 - 2010-06-22 07:34 - 80340640 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-11-13 18:12 - 2013-11-07 10:48 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-11-13 17:32 - 2010-11-24 11:13 - 00927232 ___SH C:\Users\zimmermann\Desktop\Thumbs.db 2013-11-13 12:55 - 2013-11-13 12:54 - 126764512 _____ C:\Users\zimmermann\Downloads\avira_free_antivirus_de.exe 2013-11-13 11:30 - 2013-08-29 16:12 - 00009284 _____ C:\Users\zimmermann\Desktop\Hochzeit.xlsx 2013-11-12 10:21 - 2013-11-12 10:21 - 01085542 _____ C:\Users\zimmermann\Desktop\adwcleaner_3012.exe 2013-11-12 10:13 - 2013-11-14 18:33 - 01587203 _____ C:\windows\system32\Drivers\etc\hosts.20131114-183350.backup 2013-11-12 10:13 - 2013-11-13 18:52 - 01587203 ____R C:\windows\system32\Drivers\etc\hosts.20131113-185208.backup 2013-11-08 20:33 - 2012-03-11 17:41 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\vlc 2013-11-08 20:26 - 2012-07-07 18:29 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\dvdcss 2013-11-07 12:19 - 2013-11-07 12:19 - 00000000 ____D C:\Users\zimmermann\Desktop\Maitte 2013-11-06 20:16 - 2011-11-03 11:16 - 00002004 ____H C:\Users\zimmermann\Documents\Default.rdp 2013-11-06 19:55 - 2013-11-12 10:13 - 02092618 _____ C:\windows\system32\Drivers\etc\hosts.20131112-101317.backup 2013-11-05 23:36 - 2013-11-17 19:36 - 01034531 _____ (Thisisu) C:\Users\zimmermann\Desktop\JRT-1.exe Some content of TEMP: ==================== C:\Users\zimmermann\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-10 19:21 ==================== End Of Log ============================ |
18.11.2013, 12:31 | #8 |
/// the machine /// TB-Ausbilder | Browser funktionieren nicht mehrESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.11.2013, 17:50 | #9 |
| Browser funktionieren nicht mehr Vielen vielen Dank! Internet geht wieder. War ein bißchen ein Kmpf mit dem Eset, hoffe das stimmt trotzdem so. Wars das dann? Was mache ich mit den ganzen runtergeladenen Programme? Vor allem mit dem Defogger, den ich "disabled" habe. Muss ich da jetzt reenable durchführen? Tausend Dank, Schrauber! Werde mich erkenntlich zeigen. Das ist echt super, was ihr da macht! Gruß, Ruthie ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internet# version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=1584040d3a906143bbb6004dcd737c8e # engine=15925 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-18 04:24:26 # local_time=2013-11-18 05:24:26 (+0100, Mitteleurop‰ische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 76935 136423057 0 0 # scanned=152970 # found=0 # cleaned=0 # scan_time=4368 Results of screen317's Security Check version 0.99.76 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` MVPS Hosts File Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 25 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader 9 Adobe Reader out of Date! ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-11-2013 02 Ran by zimmermann (administrator) on ZIMMERMANN-PC on 18-11-2013 17:39:53 Running from C:\Users\zimmermann\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Aventail Corporation) C:\windows\system32\ngvpnmgr.exe () C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe () C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe () C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Eastman Kodak Company) C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (SEC) C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (Intel Corporation) C:\windows\system32\igfxext.exe (Intel Corporation) C:\windows\system32\igfxsrvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Opera Software) C:\Program Files\Opera\opera.exe (Farbar) C:\Users\zimmermann\Desktop\FRST-5.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8120864 2009-12-14] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated) HKLM\...\Run: [APLangApp] - C:\Program Files\AnyPC Client\APLangApp.exe [13312 2009-10-20] (DoctorSoft) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [EKAIO2StatusMonitor] - C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe [2717696 2011-08-26] (Eastman Kodak Company) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-03-27] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Run: [PDFPrint] - C:\Program Files\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) Startup: C:\Users\zimmermann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gmx.net/ SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 217.68.161.141 217.68.161.171 FireFox: ======== FF ProfilePath: C:\Users\zimmermann\AppData\Roaming\Mozilla\Firefox\Profiles\ue9nijo9.default FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @garmin.com/GpsControl - C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin: @innoplus.de/ino3DViewer - C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: Garmin Communicator - C:\Users\zimmermann\AppData\Roaming\Mozilla\Firefox\Profiles\ue9nijo9.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} FF HKLM\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile Internet Manager 03\addon FF Extension: Bytemobile Optimization Client - C:\Program Files\T-Mobile Internet Manager 03\addon Chrome: ======= ========================== Services (Whitelisted) ================= R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NgVpnMgr; C:\windows\system32\ngvpnmgr.exe [221253 2008-08-10] (Aventail Corporation) R2 OberonGameConsoleService; C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe [44312 2009-08-13] () R2 UI Assistant Service; C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe [241664 2009-03-30] () ==================== Drivers (Whitelisted) ==================== S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [61704 2011-03-18] (FTDI Ltd.) S3 grmnusb; C:\Windows\System32\drivers\grmnusb.sys [9344 2009-04-17] (GARMIN Corp.) S3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 NgFilter; C:\Windows\System32\DRIVERS\ngfilter.sys [20632 2008-08-10] (Aventail Corporation) R3 NgLog; C:\Windows\System32\DRIVERS\nglog.sys [25240 2008-08-10] (Aventail Corporation) R3 NgVpn; C:\Windows\System32\DRIVERS\ngvpn.sys [77464 2008-08-10] (Aventail Corporation) R3 NgWfp; C:\Windows\System32\DRIVERS\ngwfp.sys [23192 2008-08-10] (Aventail Corporation) R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] () U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\ZIMMER~1\AppData\Local\Temp\catchme.sys [x] S3 dsNcAdpt; system32\DRIVERS\dsNcAdpt.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-18 13:47 - 2013-11-17 16:00 - 01090935 _____ (Farbar) C:\Users\zimmermann\Desktop\FRST.exe 2013-11-18 13:46 - 2013-11-18 13:38 - 00891184 _____ C:\Users\zimmermann\Desktop\SecurityCheck.exe 2013-11-18 13:46 - 2013-04-04 13:07 - 02347384 _____ (ESET) C:\Users\zimmermann\Desktop\esetsmartinstaller_enu.exe 2013-11-17 21:33 - 2013-11-17 21:34 - 00004767 _____ C:\windows\IE11_main.log 2013-11-17 21:15 - 2013-11-17 16:00 - 01090935 _____ (Farbar) C:\Users\zimmermann\Desktop\FRST-5.exe 2013-11-17 21:07 - 2013-11-17 21:07 - 00002453 _____ C:\Users\zimmermann\Desktop\JRT.txt 2013-11-17 21:04 - 2013-11-17 21:04 - 00000000 ____D C:\windows\ERUNT 2013-11-17 19:36 - 2013-11-05 23:36 - 01034531 _____ (Thisisu) C:\Users\zimmermann\Desktop\JRT-1.exe 2013-11-17 19:04 - 2013-11-17 19:04 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-17 19:04 - 2013-11-17 19:04 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-11-17 19:04 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2013-11-17 19:03 - 2013-11-17 19:00 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\zimmermann\Desktop\mbam-setup-1-1.75.0.1300.exe 2013-11-17 10:48 - 2013-11-17 10:48 - 00008736 _____ C:\Users\zimmermann\Desktop\ComboFix.txt 2013-11-17 10:39 - 2013-11-17 10:39 - 00000000 ____D C:\32788R22FWJFW 2013-11-17 09:34 - 2013-11-17 09:34 - 00008736 _____ C:\ComboFix.txt 2013-11-17 09:06 - 2013-11-17 09:34 - 00000000 ____D C:\Qoobox 2013-11-17 09:06 - 2011-06-26 07:45 - 00256000 _____ C:\windows\PEV.exe 2013-11-17 09:06 - 2010-11-07 18:20 - 00208896 _____ C:\windows\MBR.exe 2013-11-17 09:06 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe 2013-11-17 09:06 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe 2013-11-17 09:06 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe 2013-11-17 09:06 - 2000-08-31 01:00 - 00098816 _____ C:\windows\sed.exe 2013-11-17 09:06 - 2000-08-31 01:00 - 00080412 _____ C:\windows\grep.exe 2013-11-17 09:06 - 2000-08-31 01:00 - 00068096 _____ C:\windows\zip.exe 2013-11-17 09:05 - 2013-11-17 09:30 - 00000000 ____D C:\windows\erdnt 2013-11-17 09:01 - 2013-11-16 08:29 - 05146587 ____R (Swearware) C:\Users\zimmermann\Desktop\ComboFix.exe 2013-11-16 17:50 - 2013-11-18 17:39 - 00010758 _____ C:\Users\zimmermann\Desktop\FRST.txt 2013-11-16 17:50 - 2013-11-16 17:51 - 00022360 _____ C:\Users\zimmermann\Desktop\Addition.txt 2013-11-16 17:50 - 2013-11-16 17:50 - 00000000 ____D C:\FRST 2013-11-15 22:53 - 2013-04-04 13:45 - 00377856 _____ C:\Users\zimmermann\Desktop\gmer_2.1.19163.exe 2013-11-15 22:10 - 2013-11-15 22:16 - 00000482 _____ C:\Users\zimmermann\Desktop\defogger_disable.log 2013-11-15 22:10 - 2013-11-15 22:10 - 00000000 _____ C:\Users\zimmermann\defogger_reenable 2013-11-15 22:04 - 2013-11-15 21:52 - 00050477 _____ C:\Users\zimmermann\Desktop\Defogger.exe 2013-11-15 00:15 - 2013-11-15 00:15 - 00000079 _____ C:\windows\wininit.ini 2013-11-15 00:09 - 2013-11-15 00:09 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2013-11-14 18:33 - 2013-11-12 10:13 - 01587203 _____ C:\windows\system32\Drivers\etc\hosts.20131114-183350.backup 2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\Malwarebytes 2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-14 18:16 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll 2013-11-14 18:16 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL 2013-11-14 18:16 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL 2013-11-14 18:16 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll 2013-11-14 18:16 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll 2013-11-14 18:16 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\windows\system32\authui.dll 2013-11-14 18:16 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\credui.dll 2013-11-14 18:16 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll 2013-11-14 18:16 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys 2013-11-14 18:16 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys 2013-11-14 18:16 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2013-11-14 18:16 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll 2013-11-14 18:16 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll 2013-11-14 18:16 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2013-11-14 18:16 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll 2013-11-14 18:16 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe 2013-11-14 18:16 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll 2013-11-14 18:16 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys 2013-11-14 10:47 - 2013-10-12 08:04 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-11-14 10:47 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-11-14 10:47 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-11-14 10:47 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-11-14 10:47 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-11-14 10:47 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-11-13 18:52 - 2013-11-12 10:13 - 01587203 ____R C:\windows\system32\Drivers\etc\hosts.20131113-185208.backup 2013-11-13 12:54 - 2013-11-13 12:55 - 126764512 _____ C:\Users\zimmermann\Downloads\avira_free_antivirus_de.exe 2013-11-12 10:21 - 2013-11-12 10:21 - 01085542 _____ C:\Users\zimmermann\Desktop\adwcleaner_3012.exe 2013-11-12 10:13 - 2013-11-06 19:55 - 02092618 _____ C:\windows\system32\Drivers\etc\hosts.20131112-101317.backup 2013-11-07 12:19 - 2013-11-07 12:19 - 00000000 ____D C:\Users\zimmermann\Desktop\Maitte 2013-11-07 10:48 - 2013-11-13 18:12 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-11-18 17:40 - 2013-11-16 17:50 - 00010758 _____ C:\Users\zimmermann\Desktop\FRST.txt 2013-11-18 17:35 - 2012-06-24 11:23 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2013-11-18 16:49 - 2009-12-05 03:40 - 01993475 _____ C:\windows\WindowsUpdate.log 2013-11-18 14:45 - 2009-07-26 21:06 - 01498742 _____ C:\windows\system32\PerfStringBackup.INI 2013-11-18 13:38 - 2013-11-18 13:46 - 00891184 _____ C:\Users\zimmermann\Desktop\SecurityCheck.exe 2013-11-18 10:05 - 2009-07-14 05:34 - 00014736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-18 10:05 - 2009-07-14 05:34 - 00014736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-18 09:55 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT 2013-11-18 09:55 - 2009-07-14 05:39 - 00138300 _____ C:\windows\setupact.log 2013-11-17 21:34 - 2013-11-17 21:33 - 00004767 _____ C:\windows\IE11_main.log 2013-11-17 21:15 - 2013-01-03 18:28 - 00000000 ____D C:\Users\zimmermann\Desktop\Mama Texte 2013-11-17 21:07 - 2013-11-17 21:07 - 00002453 _____ C:\Users\zimmermann\Desktop\JRT.txt 2013-11-17 21:04 - 2013-11-17 21:04 - 00000000 ____D C:\windows\ERUNT 2013-11-17 20:51 - 2009-12-05 21:21 - 00000000 ____D C:\windows\de-DE 2013-11-17 20:51 - 2009-12-05 04:19 - 00974278 _____ C:\windows\PFRO.log 2013-11-17 19:23 - 2013-08-27 20:11 - 00000000 ____D C:\AdwCleaner 2013-11-17 19:04 - 2013-11-17 19:04 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-17 19:04 - 2013-11-17 19:04 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-11-17 19:00 - 2013-11-17 19:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\zimmermann\Desktop\mbam-setup-1-1.75.0.1300.exe 2013-11-17 16:00 - 2013-11-18 13:47 - 01090935 _____ (Farbar) C:\Users\zimmermann\Desktop\FRST.exe 2013-11-17 16:00 - 2013-11-17 21:15 - 01090935 _____ (Farbar) C:\Users\zimmermann\Desktop\FRST-5.exe 2013-11-17 10:48 - 2013-11-17 10:48 - 00008736 _____ C:\Users\zimmermann\Desktop\ComboFix.txt 2013-11-17 10:39 - 2013-11-17 10:39 - 00000000 ____D C:\32788R22FWJFW 2013-11-17 10:07 - 2009-07-14 03:37 - 00000000 ____D C:\windows\rescache 2013-11-17 09:34 - 2013-11-17 09:34 - 00008736 _____ C:\ComboFix.txt 2013-11-17 09:34 - 2013-11-17 09:06 - 00000000 ____D C:\Qoobox 2013-11-17 09:34 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Default 2013-11-17 09:34 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public 2013-11-17 09:30 - 2013-11-17 09:05 - 00000000 ____D C:\windows\erdnt 2013-11-17 09:29 - 2009-07-14 03:04 - 00000215 _____ C:\windows\system.ini 2013-11-16 17:51 - 2013-11-16 17:50 - 00022360 _____ C:\Users\zimmermann\Desktop\Addition.txt 2013-11-16 17:50 - 2013-11-16 17:50 - 00000000 ____D C:\FRST 2013-11-16 08:29 - 2013-11-17 09:01 - 05146587 ____R (Swearware) C:\Users\zimmermann\Desktop\ComboFix.exe 2013-11-15 22:16 - 2013-11-15 22:10 - 00000482 _____ C:\Users\zimmermann\Desktop\defogger_disable.log 2013-11-15 22:10 - 2013-11-15 22:10 - 00000000 _____ C:\Users\zimmermann\defogger_reenable 2013-11-15 22:10 - 2010-05-06 16:48 - 00000000 ____D C:\Users\zimmermann 2013-11-15 21:52 - 2013-11-15 22:04 - 00050477 _____ C:\Users\zimmermann\Desktop\Defogger.exe 2013-11-15 00:15 - 2013-11-15 00:15 - 00000079 _____ C:\windows\wininit.ini 2013-11-15 00:09 - 2013-11-15 00:09 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2013-11-14 23:53 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\NDF 2013-11-14 23:27 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\de-DE 2013-11-14 20:22 - 2010-05-06 16:57 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\Malwarebytes 2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-14 10:47 - 2013-07-26 09:49 - 00000000 ____D C:\windows\system32\MRT 2013-11-14 10:45 - 2010-06-22 07:34 - 80340640 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-11-13 18:12 - 2013-11-07 10:48 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-11-13 17:32 - 2010-11-24 11:13 - 00927232 ___SH C:\Users\zimmermann\Desktop\Thumbs.db 2013-11-13 12:55 - 2013-11-13 12:54 - 126764512 _____ C:\Users\zimmermann\Downloads\avira_free_antivirus_de.exe 2013-11-13 11:30 - 2013-08-29 16:12 - 00009284 _____ C:\Users\zimmermann\Desktop\Hochzeit.xlsx 2013-11-12 10:21 - 2013-11-12 10:21 - 01085542 _____ C:\Users\zimmermann\Desktop\adwcleaner_3012.exe 2013-11-12 10:13 - 2013-11-14 18:33 - 01587203 _____ C:\windows\system32\Drivers\etc\hosts.20131114-183350.backup 2013-11-12 10:13 - 2013-11-13 18:52 - 01587203 ____R C:\windows\system32\Drivers\etc\hosts.20131113-185208.backup 2013-11-08 20:33 - 2012-03-11 17:41 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\vlc 2013-11-08 20:26 - 2012-07-07 18:29 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\dvdcss 2013-11-07 12:19 - 2013-11-07 12:19 - 00000000 ____D C:\Users\zimmermann\Desktop\Maitte 2013-11-06 20:16 - 2011-11-03 11:16 - 00002004 ____H C:\Users\zimmermann\Documents\Default.rdp 2013-11-06 19:55 - 2013-11-12 10:13 - 02092618 _____ C:\windows\system32\Drivers\etc\hosts.20131112-101317.backup 2013-11-05 23:36 - 2013-11-17 19:36 - 01034531 _____ (Thisisu) C:\Users\zimmermann\Desktop\JRT-1.exe Some content of TEMP: ==================== C:\Users\zimmermann\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-10 19:21 ==================== End Of Log ============================ |
19.11.2013, 10:42 | #10 |
/// the machine /// TB-Ausbilder | Browser funktionieren nicht mehr Java und Adobe updaten. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.11.2013, 19:39 | #11 |
| Browser funktionieren nicht mehr Hallo Schrauber, habe alles erledigt. Werde mir deine Tipps zu Herzen nehmen. Vielen vielen Dank nochmals, alles Gute für dich! Abschiedsgrüße von ruthie. |
20.11.2013, 12:31 | #12 |
/// the machine /// TB-Ausbilder | Browser funktionieren nicht mehr Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Browser funktionieren nicht mehr |
ahnung, anderer, ausprobiert, besonders, browser, browser geht nicht mehr, computer, fachbegriffe, funktionieren, funktioniert, hoffe, interne, internet, mac, merkt, nicht mehr, nichts, sache, sachen, schei, tagen, threads, verbindung, verschiedene, wlan, wlan verbindung, ziemlich |