![]() |
|
Plagegeister aller Art und deren Bekämpfung: Avira springt an c:ProgramData/BitGuard/2.7.1832.68.../loader.dllWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #3 |
| ![]() Avira springt an c:ProgramData/BitGuard/2.7.1832.68.../loader.dll hi hier die beiden Logfiles FRST und Addition
__________________und vielen Dank für die schnelle Antwort ![]() FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-12-2013 02 Ran by Manu und Marina (administrator) on MANU on 03-12-2013 18:49:12 Running from C:\Users\Manu und Marina\Downloads Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe () C:\Windows\PLFSetI.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-27] (Egis Technology Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated) HKLM\...\Run: [PLFSetI] - C:\Windows\PLFSetI.exe [206208 2010-06-09] () HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7468784 2013-02-28] (Logitech Inc.) HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-07-13] (Google Inc.) HKCU\...\Run: [msnmsgr] - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation) HKCU\...\Run: [NTRedirect] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Manu und Marina\AppData\Roaming\BabSolution\Shared\enhancedNT.dll",Run MountPoints2: {0c8c7ad5-ad31-11df-9132-806e6f6e6963} - D:\0data\cbs.exe HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation) HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-05-27] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.) HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated) HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-06-28] (NewTech Infosystems, Inc.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-05-27] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [968272 2010-06-22] (Dritek System Inc.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-25] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () AppInit_DLLs: C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\loader.dll [1958880 2013-11-18] () Startup: C:\Users\Manu und Marina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk ShortcutTarget: Logitech . Produktregistrierung.lnk -> C:\Program Files\Logitech Gaming Software\EReg\eReg.exe (Leader Technologies/Logitech) Startup: C:\Users\Manu und Marina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Manu und Marina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk ShortcutTarget: Product Registration.lnk -> C:\Users\Manu und Marina\AppData\Local\Temp\is-70SOK.tmp\ATR1.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=34A5560F6E108337&affID=121564&tsp=4961 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5742g&r=273601118855l0474z165v47522758 HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.searchgol.com/?babsrc=HP_ss_Btisdt7&mntrId=34A5560F6E108337&affID=121564&tsp=4961 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5742g&r=273601118855l0474z165v47522758 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5742g&r=273601118855l0474z165v47522758 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5742g&r=273601118855l0474z165v47522758 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5742g&r=273601118855l0474z165v47522758 URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=34A5560F6E108337&affID=121564&tsp=4961 BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.22.0\bh\delta.dll (Delta-search.com) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.22.0\deltaTlbr.dll (Delta-search.com) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Manu und Marina\AppData\Roaming\Mozilla\Firefox\Profiles\ppg8fpek.default FF user.js: detected! => C:\Users\Manu und Marina\AppData\Roaming\Mozilla\Firefox\Profiles\ppg8fpek.default\user.js FF NewTab: hxxp://www.golsearch.com/?babsrc=NT_ss_Btisdt6&mntrId=34A5560F6E108337&affID=121564&tsp=4961 FF DefaultSearchEngine: Sichere Suche FF SearchEngineOrder.1: Delta Search FF SelectedSearchEngine: Sichere Suche FF Homepage: https://www.google.de/ FF Keyword.URL: hxxp://de.search.yahoo.com/search?fr=mcafee&p= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\Manu und Marina\AppData\Roaming\Mozilla\Firefox\Profiles\ppg8fpek.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Manu und Marina\AppData\Roaming\Mozilla\Firefox\Profiles\ppg8fpek.default\searchplugins\BitGuard.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Delta Toolbar - C:\Users\Manu und Marina\AppData\Roaming\Mozilla\Firefox\Profiles\ppg8fpek.default\Extensions\ffxtlbr@delta.com FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG) R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [121616 2013-10-02] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.) S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.) R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation) ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-07-12] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [106904 2013-11-25] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-25] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66800 2013-01-17] (Logitech Inc.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-07-12] () R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-03 18:49 - 2013-12-03 18:49 - 00018477 _____ C:\Users\Manu und Marina\Downloads\FRST.txt 2013-12-03 18:49 - 2013-12-03 18:49 - 00000000 ____D C:\FRST 2013-12-03 18:48 - 2013-12-03 18:48 - 01959614 _____ (Farbar) C:\Users\Manu und Marina\Downloads\FRST64.exe 2013-12-03 18:47 - 2013-12-03 18:47 - 01092545 _____ (Farbar) C:\Users\Manu und Marina\Downloads\FRST.exe 2013-12-03 17:58 - 2013-12-03 17:58 - 00055574 _____ C:\Users\Manu und Marina\Desktop\Ereignisse.txt 2013-12-03 17:54 - 2013-12-03 17:54 - 00000130 _____ C:\Windows\wininit.ini 2013-12-03 17:53 - 2013-12-03 17:53 - 01272360 _____ (iMesh Inc) C:\Users\Manu und Marina\Downloads\iMeshSetup-r1487-w-bf.exe 2013-12-03 17:31 - 2013-12-03 17:33 - 00000137 _____ C:\Users\Manu und Marina\Desktop\Neues Textdokument.txt 2013-12-03 08:27 - 2013-12-03 08:27 - 00275536 _____ C:\Windows\Minidump\120313-18564-01.dmp 2013-12-03 08:22 - 2013-12-03 08:27 - 411164471 _____ C:\Windows\MEMORY.DMP 2013-12-03 08:22 - 2013-12-03 08:27 - 00000000 ____D C:\Windows\Minidump 2013-12-03 08:22 - 2013-12-03 08:22 - 00275536 _____ C:\Windows\Minidump\120313-18595-01.dmp 2013-11-23 20:00 - 2013-11-23 20:00 - 105869762 _____ C:\Windows\SysWOW64\큖ᄉ 2013-11-21 19:27 - 2013-11-21 19:27 - 00000000 ____D C:\Users\Manu und Marina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-11-16 22:02 - 2013-11-16 22:02 - 00001935 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2013-11-15 18:11 - 2013-11-15 18:11 - 104464595 _____ C:\Windows\SysWOW64\幱ꕝ¢ 2013-11-12 19:45 - 2013-11-12 19:46 - 00000000 ____D C:\Program Files (x86)\TERA 2013-11-12 19:45 - 2013-11-12 19:45 - 00001048 _____ C:\Users\Manu und Marina\Desktop\TERA.lnk 2013-11-12 19:45 - 2013-11-12 19:45 - 00000000 ____D C:\Users\Manu und Marina\AppData\Roaming\TERA 2013-11-12 19:44 - 2013-11-12 19:45 - 15366160 _____ (Gameforge Productions GmbH ) C:\Users\Manu und Marina\Downloads\TERASetup.exe 2013-11-12 19:37 - 2013-11-14 19:39 - 104278918 _____ C:\Windows\SysWOW64\ᔾಊ“ 2013-11-09 15:10 - 2013-11-09 15:10 - 00000000 ____D C:\Users\Manu und Marina\AppData\Local\Daedalic Entertainment 2013-11-09 15:09 - 2013-11-09 15:09 - 00002238 _____ C:\Users\Public\Desktop\Harveys Neue Augen.lnk 2013-11-09 14:56 - 2013-11-09 14:56 - 00000000 ____D C:\Program Files (x86)\Daedalic Entertainment 2013-11-08 20:34 - 2013-11-08 20:34 - 103316092 _____ C:\Windows\SysWOW64\甅焨Ÿ 2013-11-06 17:33 - 2013-11-06 17:33 - 102781840 _____ C:\Windows\SysWOW64\쓱엦Š 2013-11-05 19:06 - 2013-11-05 19:06 - 00000000 ____D C:\Users\Manu und Marina\Desktop\Docs ==================== One Month Modified Files and Folders ======= 2013-12-03 18:49 - 2013-12-03 18:49 - 00018477 _____ C:\Users\Manu und Marina\Downloads\FRST.txt 2013-12-03 18:49 - 2013-12-03 18:49 - 00000000 ____D C:\FRST 2013-12-03 18:48 - 2013-12-03 18:48 - 01959614 _____ (Farbar) C:\Users\Manu und Marina\Downloads\FRST64.exe 2013-12-03 18:47 - 2013-12-03 18:47 - 01092545 _____ (Farbar) C:\Users\Manu und Marina\Downloads\FRST.exe 2013-12-03 18:46 - 2011-01-15 12:28 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-03 18:46 - 2010-08-21 15:36 - 01839707 _____ C:\Windows\WindowsUpdate.log 2013-12-03 17:58 - 2013-12-03 17:58 - 00055574 _____ C:\Users\Manu und Marina\Desktop\Ereignisse.txt 2013-12-03 17:54 - 2013-12-03 17:54 - 00000130 _____ C:\Windows\wininit.ini 2013-12-03 17:53 - 2013-12-03 17:53 - 01272360 _____ (iMesh Inc) C:\Users\Manu und Marina\Downloads\iMeshSetup-r1487-w-bf.exe 2013-12-03 17:34 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-03 17:34 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-03 17:33 - 2013-12-03 17:31 - 00000137 _____ C:\Users\Manu und Marina\Desktop\Neues Textdokument.txt 2013-12-03 17:27 - 2011-01-19 20:08 - 00000000 ____D C:\Users\Manu und Marina\Tracing 2013-12-03 17:27 - 2011-01-15 12:28 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-03 17:26 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-03 17:26 - 2009-07-14 05:51 - 00069661 _____ C:\Windows\setupact.log 2013-12-03 08:27 - 2013-12-03 08:27 - 00275536 _____ C:\Windows\Minidump\120313-18564-01.dmp 2013-12-03 08:27 - 2013-12-03 08:22 - 411164471 _____ C:\Windows\MEMORY.DMP 2013-12-03 08:27 - 2013-12-03 08:22 - 00000000 ____D C:\Windows\Minidump 2013-12-03 08:26 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-03 08:22 - 2013-12-03 08:22 - 00275536 _____ C:\Windows\Minidump\120313-18595-01.dmp 2013-12-03 08:13 - 2011-01-15 12:23 - 00000000 ___RD C:\Users\Manu und Marina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-25 18:37 - 2013-05-16 18:35 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-11-25 18:37 - 2013-05-16 18:34 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-11-25 18:37 - 2013-05-16 18:34 - 00106904 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-11-25 18:37 - 2013-05-16 18:34 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-11-23 20:00 - 2013-11-23 20:00 - 105869762 _____ C:\Windows\SysWOW64\큖ᄉ 2013-11-22 19:45 - 2010-08-21 15:33 - 00072270 _____ C:\Windows\PFRO.log 2013-11-22 19:27 - 2013-09-14 07:50 - 00000000 ____D C:\ProgramData\BitGuard 2013-11-21 19:27 - 2013-11-21 19:27 - 00000000 ____D C:\Users\Manu und Marina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-11-21 19:25 - 2013-07-26 19:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-21 19:25 - 2013-07-09 20:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-19 03:33 - 2011-02-16 20:21 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-16 22:02 - 2013-11-16 22:02 - 00001935 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2013-11-16 22:02 - 2013-10-19 21:02 - 00000000 ____D C:\Program Files\McAfee Security Scan 2013-11-15 18:11 - 2013-11-15 18:11 - 104464595 _____ C:\Windows\SysWOW64\幱ꕝ¢ 2013-11-14 19:39 - 2013-11-12 19:37 - 104278918 _____ C:\Windows\SysWOW64\ᔾಊ“ 2013-11-12 19:46 - 2013-11-12 19:45 - 00000000 ____D C:\Program Files (x86)\TERA 2013-11-12 19:45 - 2013-11-12 19:45 - 00001048 _____ C:\Users\Manu und Marina\Desktop\TERA.lnk 2013-11-12 19:45 - 2013-11-12 19:45 - 00000000 ____D C:\Users\Manu und Marina\AppData\Roaming\TERA 2013-11-12 19:45 - 2013-11-12 19:44 - 15366160 _____ (Gameforge Productions GmbH ) C:\Users\Manu und Marina\Downloads\TERASetup.exe 2013-11-09 15:10 - 2013-11-09 15:10 - 00000000 ____D C:\Users\Manu und Marina\AppData\Local\Daedalic Entertainment 2013-11-09 15:09 - 2013-11-09 15:09 - 00002238 _____ C:\Users\Public\Desktop\Harveys Neue Augen.lnk 2013-11-09 14:56 - 2013-11-09 14:56 - 00000000 ____D C:\Program Files (x86)\Daedalic Entertainment 2013-11-09 14:51 - 2010-08-22 01:27 - 00654610 _____ C:\Windows\system32\perfh007.dat 2013-11-09 14:51 - 2010-08-22 01:27 - 00130192 _____ C:\Windows\system32\perfc007.dat 2013-11-09 14:51 - 2009-07-14 06:13 - 01500018 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-08 20:40 - 2011-06-18 08:28 - 00000000 ____D C:\Program Files (x86)\RIFT Game 2013-11-08 20:34 - 2013-11-08 20:34 - 103316092 _____ C:\Windows\SysWOW64\甅焨Ÿ 2013-11-06 17:33 - 2013-11-06 17:33 - 102781840 _____ C:\Windows\SysWOW64\쓱엦Š 2013-11-05 19:06 - 2013-11-05 19:06 - 00000000 ____D C:\Users\Manu und Marina\Desktop\Docs 2013-11-05 19:06 - 2011-10-06 00:26 - 00000000 ____D C:\Users\Manu und Marina\Desktop\Progs Some content of TEMP: ==================== C:\Users\Manu und Marina\AppData\Local\Temp\AskSLib.dll C:\Users\Manu und Marina\AppData\Local\Temp\AutoRun.exe C:\Users\Manu und Marina\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Manu und Marina\AppData\Local\Temp\avgnt.exe C:\Users\Manu und Marina\AppData\Local\Temp\binkw32.dll C:\Users\Manu und Marina\AppData\Local\Temp\d2l_Install.exe C:\Users\Manu und Marina\AppData\Local\Temp\drm_dialogs.dll C:\Users\Manu und Marina\AppData\Local\Temp\drm_dyndata_7330014.dll C:\Users\Manu und Marina\AppData\Local\Temp\drm_dyndata_7340007.dll C:\Users\Manu und Marina\AppData\Local\Temp\drm_dyndata_7370014.dll C:\Users\Manu und Marina\AppData\Local\Temp\eauninstall.exe C:\Users\Manu und Marina\AppData\Local\Temp\jre-6u32-windows-i586-iftw.exe C:\Users\Manu und Marina\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Manu und Marina\AppData\Local\Temp\Need for Speed Underground 2_uninst.exe C:\Users\Manu und Marina\AppData\Local\Temp\setup_fsu_cid.exe C:\Users\Manu und Marina\AppData\Local\Temp\SIntf16.dll C:\Users\Manu und Marina\AppData\Local\Temp\SIntf32.dll C:\Users\Manu und Marina\AppData\Local\Temp\SIntfNT.dll C:\Users\Manu und Marina\AppData\Local\Temp\wlsetup-cvr.exe C:\Users\Manu und Marina\AppData\Local\Temp\_isB5BA.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-30 15:51 ==================== End Of Log ============================ --- --- --- und additition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-12-2013 02 Ran by Manu und Marina at 2013-12-03 18:49:50 Running from C:\Users\Manu und Marina\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Acer Backup Manager (x32 Version: 2.0.0.68) Acer Crystal Eye Webcam (x32 Version: 5.2.19.3) Acer ePower Management (x32 Version: 5.00.3005) Acer eRecovery Management (x32 Version: 4.05.3013) Acer GameZone Console (x32 Version: 6.1.0.9) Acer Registration (x32 Version: 1.03.3003) Acer ScreenSaver (x32 Version: 1.1.0707.2010) Acer Updater (x32 Version: 1.02.3001) Acrobat.com (x32 Version: 1.6.65) Adobe AIR (x32 Version: 1.5.0.7220) Adobe Flash Player 10 ActiveX (x32 Version: 10.1.102.64) Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94) Adobe Reader 9.1 MUI (x32 Version: 9.1.0) Advanced Combat Tracker (remove only) (x32) Airport Mania First Flight (x32) Apple Application Support (x32 Version: 2.3.4) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (x32 Version: 2.1.3.127) ATI Catalyst Install Manager (Version: 3.0.778.0) Avira Free Antivirus (x32 Version: 14.0.1.749) Backup Manager Basic (x32 Version: 2.0.0.68) BioShock (x32 Version: 2.62.0000) BitGuard (x32) <==== ATTENTION Bonjour (Version: 3.0.0.10) Broadcom Gigabit NetLink Controller (Version: 14.0.2.3) Cake Mania (x32) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0527.1242.20909) Catalyst Control Center InstallProxy (x32 Version: 2010.0527.1242.20909) Catalyst Control Center Localization All (x32 Version: 2010.0527.1242.20909) CCC Help Chinese Standard (x32 Version: 2010.0527.1241.20909) CCC Help Chinese Traditional (x32 Version: 2010.0527.1241.20909) CCC Help Czech (x32 Version: 2010.0527.1241.20909) CCC Help Danish (x32 Version: 2010.0527.1241.20909) CCC Help Dutch (x32 Version: 2010.0527.1241.20909) CCC Help English (x32 Version: 2010.0527.1241.20909) CCC Help Finnish (x32 Version: 2010.0527.1241.20909) CCC Help French (x32 Version: 2010.0527.1241.20909) CCC Help German (x32 Version: 2010.0527.1241.20909) CCC Help Greek (x32 Version: 2010.0527.1241.20909) CCC Help Hungarian (x32 Version: 2010.0527.1241.20909) CCC Help Italian (x32 Version: 2010.0527.1241.20909) CCC Help Japanese (x32 Version: 2010.0527.1241.20909) CCC Help Korean (x32 Version: 2010.0527.1241.20909) CCC Help Norwegian (x32 Version: 2010.0527.1241.20909) CCC Help Polish (x32 Version: 2010.0527.1241.20909) CCC Help Portuguese (x32 Version: 2010.0527.1241.20909) CCC Help Russian (x32 Version: 2010.0527.1241.20909) CCC Help Spanish (x32 Version: 2010.0527.1241.20909) CCC Help Swedish (x32 Version: 2010.0527.1241.20909) CCC Help Thai (x32 Version: 2010.0527.1241.20909) CCC Help Turkish (x32 Version: 2010.0527.1241.20909) ccc-core-static (x32 Version: 2010.0527.1242.20909) ccc-utility64 (Version: 2010.0527.1242.20909) CyberLink PowerDVD 9 (x32 Version: 9.0.2829.50) Delta Chrome Toolbar (x32) Delta toolbar (x32 Version: 1.8.22.0) <==== ATTENTION Diablo II (x32) Diablo III (x32 Version: 1.0.8.16603) Dream Day First Home (x32) eBay Worldwide (x32 Version: 2.1.0901) eSobi v2 (x32 Version: 2.0.4.000274) FarmFrenzy (x32) Free YouTube to MP3 Converter version 3.12.9.725 (x32 Version: 3.12.9.725) Galapago (x32) Google Toolbar for Internet Explorer (x32 Version: 1.0.0) Google Toolbar for Internet Explorer (x32 Version: 7.5.4601.54) Google Update Helper (x32 Version: 1.3.21.165) Harveys Neue Augen (x32 Version: 1.1) Heroes of Hellas (x32) Identity Card (x32 Version: 1.00.3003) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) Rapid Storage Technology (x32 Version: 9.6.2.1001) Intel(R) Turbo Boost Technology Driver (x32 Version: 01.02.00.1002) iTunes (Version: 11.0.4.4) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Junk Mail filter update (x32 Version: 14.0.8117.416) Launch Manager (x32 Version: 4.0.12) Logitech Gaming Software (Version: 8.45.88) Logitech Gaming Software 8.45 (Version: 8.45.88) McAfee Security Scan Plus (Version: 3.8.130.10) McAfee SiteAdvisor (Version: 3.1.1.119) McAfee SiteAdvisor (x32 Version: 3.6.549) Merriam Websters Spell Jam (x32) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Choice Guard (x32 Version: 2.0.48.0) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000) Microsoft Silverlight (x32 Version: 4.1.10111.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 25.0.1 (x86 de) (x32 Version: 25.0.1) Mozilla Maintenance Service (x32 Version: 25.0.1) MSVCRT (x32 Version: 14.0.1468.721) MyWinLocker (x32 Version: 3.1.212.0) MyWinLocker Suite (x32 Version: 3.1.212.0) Norton Online Backup (x32 Version: 2.1.17869) NTI Media Maker 9 (x32 Version: 9.0.2.8928) NVIDIA PhysX v8.04.25 (x32 Version: 8.04.25) Oblivion (x32 Version: 1.00.0000) OpenOffice.org 3.3 (x32 Version: 3.3.9567) Poker Pop (x32) PX Profile Update (x32 Version: 1.00.1.) Realtek HDMI Audio Driver for ATI (x32 Version: 6.0.1.6034) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6141) Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30122) RIFT (x32 Version: 1.0.0) Shredder (Version: 2.0.8.3) Shredder (x32 Version: 2.0.8.3) Star Wars: The Old Republic (x32 Version: 1.00) Synaptics Pointing Device Driver (Version: 14.0.19.0) TeamSpeak 3 Client (x32) TERA (x32 Version: 7) Überwachungstool für die Intel® Turbo-Boost-Technik (Version: 1.0.186.6) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) VLC media player 1.1.7 (x32 Version: 1.1.7) Welcome Center (x32 Version: 1.02.3002) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.5) Windows Live Call (x32 Version: 14.0.8117.0416) Windows Live Communications Platform (x32 Version: 14.0.8117.416) Windows Live Essentials (x32 Version: 14.0.8117.0416) Windows Live Essentials (x32 Version: 14.0.8117.416) Windows Live Fotogalerie (x32 Version: 14.0.8117.416) Windows Live Mail (x32 Version: 14.0.8117.0416) Windows Live Messenger (x32 Version: 14.0.8117.0416) Windows Live Movie Maker (x32 Version: 14.0.8117.0416) Windows Live Sync (x32 Version: 14.0.8117.416) Windows Live Writer (x32 Version: 14.0.8117.0416) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029) ==================== Restore Points ========================= 13-11-2013 05:10:33 Windows Update 26-11-2013 19:57:04 Geplanter Prüfpunkt 01-12-2013 07:53:02 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {38369992-021D-4903-812F-FD9E8C14005C} - System32\Tasks\EPUpdater => C:\Users\Manu und Marina\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () Task: {5AC5DE2D-4FF2-4EA0-B5EE-AAAFFE78C86C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-15] (Google Inc.) Task: {671E95B9-A282-4E53-8AEE-09617342B714} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-15] (Google Inc.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-11-21 19:27 - 2013-11-18 15:32 - 01958880 _____ () C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\loader.dll 2013-05-16 18:34 - 2013-05-16 18:28 - 00397704 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2010-06-28 14:20 - 2010-06-28 14:20 - 00465576 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll 2010-06-28 14:12 - 2010-06-28 14:12 - 01081600 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll 2013-08-22 19:18 - 2013-08-22 11:02 - 00187888 _____ () C:\Users\Manu und Marina\AppData\Roaming\BabSolution\Shared\enhancedNT.dll 2011-01-17 15:19 - 2011-10-05 22:57 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 2010-07-25 07:10 - 2009-05-20 07:02 - 00072200 _____ () C:\Program Files (x86)\Launch Manager\CdDirIo.dll 2012-03-23 11:29 - 2012-03-23 11:29 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\468559891333f68f1c9acfe15c02f7a5\IsdiInterop.ni.dll 2010-07-13 12:32 - 2010-04-13 17:52 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2013-07-26 19:20 - 2013-11-20 19:39 - 03363952 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:0B9176C0 AlternateDataStreams: C:\ProgramData\Temp:4D066AD2 AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/02/2013 06:15:03 PM) (Source: CVHSVC) (User: ) Description: Nur zur Information. Error: Der Server lieferte eine ungültige oder unbekannte Rückmeldung. ErrorCode: 14007(0x36b7). Error: (12/01/2013 09:43:09 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (12/01/2013 09:42:46 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (12/01/2013 08:57:42 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (12/01/2013 08:56:13 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (11/30/2013 03:55:02 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (11/30/2013 03:53:19 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (11/30/2013 00:41:02 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9470 Error: (11/30/2013 00:41:02 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9470 Error: (11/30/2013 00:41:02 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (12/03/2013 08:27:21 AM) (Source: BugCheck) (User: ) Description: 0x000000f4 (0x0000000000000003, 0xfffffa80074cb040, 0xfffffa80074cb320, 0xfffff800033d4e10)C:\Windows\MEMORY.DMP120313-18564-01 Error: (12/03/2013 08:27:14 AM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 03.12.2013 um 08:26:14 unerwartet heruntergefahren. Error: (12/03/2013 08:22:26 AM) (Source: BugCheck) (User: ) Description: 0x000000f4 (0x0000000000000003, 0xfffffa8007452310, 0xfffffa80074525f0, 0xfffff800033dae10)C:\Windows\MEMORY.DMP120313-18595-01 Error: (12/03/2013 08:22:19 AM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 03.12.2013 um 08:20:41 unerwartet heruntergefahren. Error: (11/26/2013 07:47:08 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Multimediaklassenplaner" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (11/26/2013 07:47:08 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Benutzerprofildienst" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (11/26/2013 07:47:08 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows-Verwaltungsinstrumentation" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (11/26/2013 07:46:08 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Server" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (11/26/2013 07:45:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (11/26/2013 07:45:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Designs" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Microsoft Office Sessions: ========================= Error: (12/02/2013 06:15:03 PM) (Source: CVHSVC)(User: ) Description: Error: Der Server lieferte eine ungültige oder unbekannte Rückmeldung. ErrorCode: 14007(0x36b7). Error: (12/01/2013 09:43:09 AM) (Source: SideBySide)(User: ) Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"c:\program files (x86)\windows live\photo gallery\MovieMaker.Exec:\program files (x86)\windows live\photo gallery\WLMFDS.DLL8 Error: (12/01/2013 09:42:46 AM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (12/01/2013 08:57:42 AM) (Source: SideBySide)(User: ) Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"c:\program files (x86)\windows live\photo gallery\MovieMaker.Exec:\program files (x86)\windows live\photo gallery\WLMFDS.DLL8 Error: (12/01/2013 08:56:13 AM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (11/30/2013 03:55:02 PM) (Source: SideBySide)(User: ) Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"c:\program files (x86)\windows live\photo gallery\MovieMaker.Exec:\program files (x86)\windows live\photo gallery\WLMFDS.DLL8 Error: (11/30/2013 03:53:19 PM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (11/30/2013 00:41:02 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9470 Error: (11/30/2013 00:41:02 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9470 Error: (11/30/2013 00:41:02 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second ==================== Memory info =========================== Percentage of memory in use: 39% Total physical RAM: 3958.71 MB Available physical RAM: 2398.08 MB Total Pagefile: 7915.56 MB Available Pagefile: 5980.1 MB Total Virtual: 8192 MB Available Virtual: 8191.79 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:284.99 GB) (Free:124.38 GB) NTFS Drive d: (HNA) (CDROM) (Total:2.55 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 4FE2FD3D) Partition 1: (Not Active) - (Size=13 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=285 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
Themen zu Avira springt an c:ProgramData/BitGuard/2.7.1832.68.../loader.dll |
abend, adware/bprotector.e, bluescreen, enthält, geklickt, heute, laptop, plötzlich, pup.bprotector, pup.optional.babsolution.a, pup.optional.babylon.a, pup.optional.bandoo.a, pup.optional.bprotector.a, pup.optional.datamngr.a, pup.optional.delta, pup.optional.delta.a, pup.optional.filescout.a, pup.optional.opencandy, pup.optional.startpage, spring, unerwünschtes programm |