![]() |
|
Log-Analyse und Auswertung: Virusbefall als Links mit blau hinterlegten Worten mit kleinem grünen Pfeil in Browser-TextenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Virusbefall als Links mit blau hinterlegten Worten mit kleinem grünen Pfeil in Browser-Texten Hallo liebe Tronjaner-Board Gemeinschaft, seit einigen Wochen habe ich bei der Benutzung meines Google Chrome Browsers und vorherig auch im Firefox einfliegende Werbung mit kleinen Bildern zu den verschiedensten Produkten, im Fließtext sind Worte in blau verlinkt und direkt dahinter hochgesetzt ein kleiner Pfeil. Auch findet sich an den Rändern und manchmal zwischen den Zeilen Werbefenster mit den kleinen Bemerkungen "Ads by PlusHD.6Ad Options". Die Werbefenster sind teilweise so gesetzt, dass sie sich automatisch öffnen und mein Avast-Virenprogramm "meckert" und eine Bedrohung gefunden hat. Vor kurzer Zeit habe ich des Öfteren Malmarebytes laufen lassen und darüber meine Schadsoftware (vordergründig) entfernen können (damals waren es doppelt grün unterstrichene Worte, die ebenfalls Verlinkungen enthielten wie z.B. monstermarketplace), leider traten diese neuen Verlinkungen dann aber plötzlich wieder auf ohne dass ich wissentlich etwas aus dem Netz herunter geladen hätte etc. Könnt ihr mir helfen diese störenden Links/Werbung und Bedrohungen zu entfernen? Vielen Dank schon einmal im Voraus, angehängt sind die logfiles. Viele Grüße, Jasmin Das Logfile "Addition.txt": Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-12-2013 Ran by Jasmin at 2013-12-09 18:51:51 Running from C:\Users\Jasmin\Desktop\virus entfernung Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (x32) Acer Backup Manager (x32 Version: 2.0.0.68) Acer Crystal Eye webcam (x32 Version: 1.0.5.2) Acer ePower Management (x32 Version: 5.00.3005) Acer eRecovery Management (x32 Version: 4.05.3013) Acer GameZone Console (x32 Version: 6.1.0.9) Acer Registration (x32 Version: 1.03.3003) Acer ScreenSaver (x32 Version: 1.1.0707.2010) Acer Updater (x32 Version: 1.02.3001) Acrobat.com (x32 Version: 1.6.65) Add or Remove Adobe Creative Suite 3 Design Premium (x32 Version: 1.0) Adobe Acrobat 8 Professional (x32 Version: 8.0.0) Adobe AIR (x32 Version: 3.8.0.1280) Adobe Anchor Service CS3 (x32 Version: 1.0) Adobe Asset Services CS3 (x32 Version: 3) Adobe Bridge CS3 (x32 Version: 2) Adobe Bridge Start Meeting (x32 Version: 1.0) Adobe BridgeTalk Plugin CS3 (x32 Version: 1.0) Adobe Camera Raw 4.0 (x32 Version: 4.0) Adobe CMaps (x32 Version: 1.0) Adobe Color - Photoshop Specific (x32 Version: 1.0) Adobe Color Common Settings (x32 Version: 1.0) Adobe Color EU Extra Settings (x32 Version: 1.0) Adobe Color JA Extra Settings (x32 Version: 1.0) Adobe Color NA Recommended Settings (x32 Version: 1.0) Adobe Default Language CS3 (x32 Version: 1.0) Adobe Device Central CS3 (x32 Version: 1.0) Adobe Dreamweaver CS3 (x32 Version: 9) Adobe ExtendScript Toolkit 2 (x32 Version: 2.0) Adobe Extension Manager CS3 (x32 Version: 1.8) Adobe Flash CS3 (x32 Version: 9.0) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.152) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Flash Video Encoder (x32 Version: 2.0) Adobe Fonts All (x32 Version: 1.0) Adobe Help Viewer CS3 (x32 Version: 1) Adobe Illustrator CS3 (x32 Version: 13.0) Adobe InDesign CS3 (x32 Version: 5.0) Adobe InDesign CS3 Icon Handler (x32 Version: 5.0) Adobe Linguistics CS3 (x32 Version: 3.0.0) Adobe MotionPicture Color Files (x32 Version: 1.0) Adobe PDF Library Files (x32 Version: 8.0) Adobe Photoshop CS3 (x32 Version: 10) Adobe Presenter 7 (x32 Version: 7.0) Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8) Adobe Setup (x32 Version: 1.0) Adobe SING CS3 (x32 Version: 0.1) Adobe Stock Photos CS3 (x32 Version: 1.5) Adobe Type Support (x32 Version: 1.0) Adobe Update Manager CS3 (x32 Version: 5.1.0) Adobe Version Cue CS3 Client (x32 Version: 3) Adobe Version Cue CS3 Server (x32 Version: 3.0) Adobe WAS CS3 (x32 Version: 1.0) Adobe WinSoft Linguistics Plugin (x32 Version: 1.0) Adobe XMP Panels CS3 (x32 Version: 1.0) AHV content for Acrobat and Flash (x32 Version: 1) AudibleManager (x32 Version: 2011315454.48.56.33819882) avast! Free Antivirus (x32 Version: 9.0.2006) Backup Manager Basic (x32 Version: 2.0.0.68) Broadcom Gigabit NetLink Controller (Version: 14.0.2.3) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.04063) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.04063) Cisco Systems VPN Client 5.0.07.0440 (Version: 5.0.7) Corel Graphics - Windows Shell Extension (x32 Version: 15.0.0.487) Corel Graphics - Windows Shell Extension (x32 Version: 15.0.487) CorelDRAW Graphics Suite X5 - Capture (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - Common (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - Connect (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - Custom Data (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - DE (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - Draw (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - Filters (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - FontNav (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - IPM (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - PHOTO-PAINT (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - Photozoom Plugin (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - Redist (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - Setup Files (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - VBA (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - VideoBrowser (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - VSTA (x32 Version: 15.0) CorelDRAW Graphics Suite X5 - Windows Shell Extension 64 Bit (Version: 15.0.487) CorelDRAW Graphics Suite X5 - WT (x32 Version: 15.0) CorelDRAW Graphics Suite X5 (x32 Version: 15.0) CorelDRAW(R) Graphics Suite X5 (x32 Version: 15.0.0.486) CyberLink PowerDVD 9 (x32 Version: 9.0.3216.50) D3DX10 (x32 Version: 15.4.2368.0902) DivX-Setup (x32 Version: 2.5.0.8) Dropbox (HKCU Version: 2.0.22) eBay Worldwide (x32 Version: 2.1.0901) eSobi v2 (x32 Version: 2.0.4.000274) FastStone Image Viewer 4.5 (x32 Version: 4.5) FileZilla Client 3.5.3 (HKCU Version: 3.5.3) Free Audio CD Burner version 1.4.8 (x32) Free Studio version 5.0.9 (x32) Free YouTube to MP3 Converter version 3.12.0.128 (x32 Version: 3.12.0.128) Futuremark SystemInfo (x32 Version: 4.0.0.0) Garmin BaseCamp (x32 Version: 3.3.1) Garmin USB Drivers (x32 Version: 2.3.0.0) GMT5 (x32 Version: 5.1.0) Google Chrome (HKCU Version: 31.0.1650.63) GPL Ghostscript (Version: 9.04) GPL Ghostscript (Version: 9.06) GSview 5.0 (Version: 5.0) Hotfix für Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789) (x32 Version: 1) HP Deskjet 3520 series - Grundlegende Software für das Gerät (Version: 27.0.847.0) HP Deskjet 3520 series Hilfe (x32 Version: 27.0.0) HP Deskjet 3520 series Setup Guide (x32 Version: 27.0.0) HP Photo Creations (x32 Version: 1.0.0.3341) HP Update (x32 Version: 5.003.003.001) ICQ 8.0 (build 5977, für aktuellen Benutzer) (HKCU Version: 8.0.5977.0) Identity Card (x32 Version: 1.00.3003) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Graphics Media Accelerator Driver (x32 Version: 8.15.10.2182) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) Rapid Storage Technology (x32 Version: 9.6.2.1001) IrfanView (remove only) (x32 Version: 4.32) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) JavaFX 2.1.1 (x32 Version: 2.1.1) Junk Mail filter update (x32 Version: 15.4.3502.0922) L&H TTS3000 British English (x32) L&H TTS3000 Deutsch (x32) Lame ACM MP3 Codec (x32) Launch Manager (x32 Version: 4.0.14) Lernout & Hauspie TruVoice American English TTS Engine (x32) LesefixPRO (x32 Version: 8.00) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) McAfee Security Scan Plus (x32 Version: 3.0.207.4) Mesh Runtime (x32 Version: 15.4.5722.2) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Professional Plus 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (x32 Version: 10.0.30319) Microsoft Visual Studio Tools for Applications 2.0 - ENU (x32 Version: 9.0.30729) Microsoft Visual Studio Tools for Applications 2.0 Language Pack - DEU (x32 Version: 9.0.30729) Microsoft Visual Studio Tools for Applications 2.0 Runtime (x32 Version: 9.0.30729) Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - DEU (x32 Version: 9.0.30729) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) MyWinLocker (x32 Version: 3.1.212.0) MyWinLocker Suite (x32 Version: 3.1.212.0) Norton Online Backup (x32 Version: 2.1.17869) NTI Media Maker 9 (x32 Version: 9.0.2.8939) NVIDIA Display Control Panel (Version: 6.14.12.5997) NVIDIA Grafiktreiber 306.97 (Version: 306.97) NVIDIA Install Application (Version: 2.1002.85.551) NVIDIA Optimus 1.10.8 (Version: 1.10.8) NVIDIA PhysX (x32 Version: 9.10.0513) NVIDIA Systemsteuerung 306.97 (Version: 306.97) NVIDIA Update 1.10.8 (Version: 1.10.8) NVIDIA Update Components (Version: 1.10.8) NVIDIA Updatus (x32 Version: 1.0.3) PDF Settings (x32 Version: 1.0) PDF24 Creator 3.5.2 (x32) PDFCreator (x32 Version: 1.2.0) Processing Modflow 5.3 (x32) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6141) Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30124) ScanSoft PaperPort 11 (x32 Version: 11.1.0000) SecureW2 EAP Suite 1.1.3 for Windows (x32) Shredder (Version: 2.0.8.3) Shredder (x32 Version: 2.0.8.3) Skype Click to Call (x32 Version: 5.6.8442) Skype™ 6.0 (x32 Version: 6.0.126) Synaptics Pointing Device Driver (Version: 14.0.19.0) Überwachungstool für die Intel® Turbo-Boost-Technik (Version: 1.0.186.6) Uninstall 1.0.0.1 (x32) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825642) 32-Bit Edition (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) VirtualCloneDrive (x32) Visual Basic for Applications (R) Core - English (x32 Version: 6.4.99.69) Visual Basic for Applications (R) Core - German (x32 Version: 6.4.99.69) Visual Basic for Applications (R) Core (x32 Version: 6.4.99.69) VLC media player 1.1.9 (x32 Version: 1.1.9) Wecker für Windows 6.5 (x32 Version: 6.5) Welcome Center (x32 Version: 1.02.3007) Winamp (x32 Version: 5.61 ) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) (Version: 06/03/2009 2.3.0.0) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3502.0922) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Mesh (x32 Version: 15.4.3502.0922) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3502.0922) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3502.0922) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) WinRAR 4.00 (64-Bit) (Version: 4.00.0) ==================== Restore Points ========================= 26-11-2013 12:04:29 Windows Update 29-11-2013 20:11:55 Windows Update 04-12-2013 06:42:02 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {4A78F034-C487-4BB6-8872-814DB4AF61C8} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {4EA9DDB3-F189-46E4-A950-222E414DC9EB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4204532526-229451462-250584438-1002UA => C:\Users\Jasmin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-14] (Google Inc.) Task: {5B894E7D-455A-49BF-9CEE-6F6927737F08} - \Plus-HD-1.6-enabler No Task File Task: {60370890-E5B2-4827-B11C-DD644BEF1CDE} - System32\Tasks\DivX-Online-Aktualisierungsprogramm => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2011-07-29] () Task: {62D82259-2577-49C9-8746-6F5C7C4CB909} - \Plus-HD-1.6-codedownloader No Task File Task: {78B0C886-4496-44D5-ACE8-3091AA02D58A} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-10-21] (AVAST Software) Task: {A044BEF9-207F-43FE-A9E9-4426431038F0} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12] (Oracle Corporation) Task: {B6EBB12B-3842-4A18-8354-E3E827443A32} - \Plus-HD-1.6-firefoxinstaller No Task File Task: {B9ED1191-5388-4821-B176-4ACCE063D463} - System32\Tasks\ScanSoft Background Update => C:\Program Files (x86)\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe [2006-10-25] (Nuance Communications, Inc.) Task: {C5987BC6-7376-43F4-9F19-7AC369F78CE5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-25] (Adobe Systems Incorporated) Task: {EF799C21-8041-45E0-A41F-2333C3B09FA7} - System32\Tasks\Google Updater and Installer => C:\Users\Jasmin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-14] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4204532526-229451462-250584438-1002Core1cec7ae5cec685c.job => C:\Users\Jasmin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4204532526-229451462-250584438-1002UA.job => C:\Users\Jasmin\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2012-01-10 20:12 - 2012-01-10 20:12 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-07-19 22:29 - 2013-07-19 22:29 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2013-12-09 10:42 - 2013-12-09 09:31 - 02152448 _____ () C:\Program Files\AVAST Software\Avast\defs\13120900\algo.dll 2011-03-04 09:49 - 2011-03-04 09:49 - 00202752 _____ () C:\Program Files (x86)\Cisco Systems\VPN Client\vpnapi.dll 2010-06-29 00:20 - 2010-06-29 00:20 - 00465576 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll 2010-06-29 00:12 - 2010-06-29 00:12 - 01081600 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll 2010-11-17 13:47 - 2009-05-20 07:02 - 00072200 _____ () C:\Program Files (x86)\Launch Manager\CdDirIo.dll 2013-10-21 12:19 - 2013-10-21 12:19 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\Jasmin\AppData\Roaming\Dropbox\bin\libcef.dll 2012-05-09 15:31 - 2003-05-14 21:07 - 00389120 _____ () C:\Windows\SysWow64\actskn43.ocx 2013-08-16 13:09 - 2013-08-16 13:09 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\eff228aa396c1d45248a54b44d7ce5a0\IsdiInterop.ni.dll 2010-11-17 14:18 - 2010-04-13 18:52 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2012-01-08 14:41 - 2012-01-08 14:41 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2013-12-05 10:54 - 2013-12-04 03:47 - 00702416 _____ () C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-05 10:54 - 2013-12-04 03:47 - 00099792 _____ () C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\31.0.1650.63\libegl.dll 2013-12-05 10:54 - 2013-12-04 03:48 - 04055504 _____ () C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-05 10:54 - 2013-12-04 03:48 - 00399312 _____ () C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-05 10:54 - 2013-12-04 03:47 - 01619408 _____ () C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll 2013-12-05 10:54 - 2013-12-04 03:48 - 13586896 _____ () C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:93EB7685 AlternateDataStreams: C:\ProgramData\Temp:E3C56885 ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Cisco Systems VPN Adapter for 64-bit Windows Description: Cisco Systems VPN Adapter for 64-bit Windows Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: CVirtA Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (12/08/2013 10:19:35 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3. Mehrere requestedPrivileges-Elemente sind nicht im Manifest zulässig. Error: (12/01/2013 07:23:29 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3. Mehrere requestedPrivileges-Elemente sind nicht im Manifest zulässig. Error: (11/29/2013 05:22:03 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3. Mehrere requestedPrivileges-Elemente sind nicht im Manifest zulässig. Error: (11/22/2013 00:50:21 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: CORELDRW.EXE, Version: 15.0.0.486, Zeitstempel: 0x4b5e6f59 Name des fehlerhaften Moduls: CrlCUI.dll, Version: 15.0.0.486, Zeitstempel: 0x4b5ea046 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000079b4 ID des fehlerhaften Prozesses: 0x13f0 Startzeit der fehlerhaften Anwendung: 0xCORELDRW.EXE0 Pfad der fehlerhaften Anwendung: CORELDRW.EXE1 Pfad des fehlerhaften Moduls: CORELDRW.EXE2 Berichtskennung: CORELDRW.EXE3 Error: (11/18/2013 08:22:18 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3. Mehrere requestedPrivileges-Elemente sind nicht im Manifest zulässig. Error: (11/12/2013 07:17:13 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3. Mehrere requestedPrivileges-Elemente sind nicht im Manifest zulässig. Error: (11/11/2013 09:08:52 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: PmmUpdate.exe, Version: 1.1.34.0, Zeitstempel: 0x4b97a6a2 Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b96f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00039342 ID des fehlerhaften Prozesses: 0x13bc Startzeit der fehlerhaften Anwendung: 0xPmmUpdate.exe0 Pfad der fehlerhaften Anwendung: PmmUpdate.exe1 Pfad des fehlerhaften Moduls: PmmUpdate.exe2 Berichtskennung: PmmUpdate.exe3 Error: (11/10/2013 08:05:11 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: PmmUpdate.exe, Version: 1.1.34.0, Zeitstempel: 0x4b97a6a2 Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b96f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00039342 ID des fehlerhaften Prozesses: 0xe10 Startzeit der fehlerhaften Anwendung: 0xPmmUpdate.exe0 Pfad der fehlerhaften Anwendung: PmmUpdate.exe1 Pfad des fehlerhaften Moduls: PmmUpdate.exe2 Berichtskennung: PmmUpdate.exe3 Error: (11/10/2013 04:16:28 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3. Mehrere requestedPrivileges-Elemente sind nicht im Manifest zulässig. Error: (11/05/2013 03:04:56 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: CORELDRW.EXE, Version: 15.0.0.486, Zeitstempel: 0x4b5e6f59 Name des fehlerhaften Moduls: CrlCUI.dll, Version: 15.0.0.486, Zeitstempel: 0x4b5ea046 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000079b4 ID des fehlerhaften Prozesses: 0x1fb0 Startzeit der fehlerhaften Anwendung: 0xCORELDRW.EXE0 Pfad der fehlerhaften Anwendung: CORELDRW.EXE1 Pfad des fehlerhaften Moduls: CORELDRW.EXE2 Berichtskennung: CORELDRW.EXE3 System errors: ============= Error: (12/09/2013 05:45:02 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (12/09/2013 05:45:02 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (12/09/2013 11:30:05 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/09/2013 11:29:58 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/09/2013 11:29:49 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/09/2013 11:29:42 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/09/2013 11:29:34 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/09/2013 11:29:25 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/09/2013 11:29:16 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (12/09/2013 11:29:06 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Microsoft Office Sessions: ========================= Error: (03/29/2012 05:24:55 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6612.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 11217 seconds with 2340 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Percentage of memory in use: 40% Total physical RAM: 7862.71 MB Available physical RAM: 4673.04 MB Total Pagefile: 15723.6 MB Available Pagefile: 12148.94 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:230.23 GB) (Free:64.39 GB) NTFS Drive e: (Daten) (Fixed) (Total:454.31 GB) (Free:8.98 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 677BD8DD) Partition 1: (Not Active) - (Size=14 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=230 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=454 GB) - (Type=OF Extended) ==================== End Of Log ============================ Das Logfile "defogger_disable.log" schaut etwas komisch aus, aber ich kenne mich leider absolut nicht damit aus. Entschuldigung. Dennoch, der Vollständigkeit halber hier: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 18:49 on 09/12/2013 (Jasmin) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-12-2013 Ran by Jasmin (administrator) on JASMIN on 09-12-2013 18:55:48 Running from C:\Users\Jasmin\Desktop\virus entfernung Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Computer, Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Nuance Communications, Inc.) C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Dropbox, Inc.) C:\Users\Jasmin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Christoph Bünger Software) C:\Program Files (x86)\Wecker6\Wecker.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation) C:\Windows\splwow64.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-27] (Egis Technology Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated) HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [icq] - C:\Users\Jasmin\AppData\Roaming\ICQM\icq.exe [26596344 2012-12-19] (ICQ) HKCU\...\Run: [Google Update] - C:\Users\Jasmin\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-05-14] (Google Inc.) MountPoints2: {557e8c37-5eae-11e3-acd3-99bbe0ed6454} - F:\LaunchU3.exe -a MountPoints2: {8cbf64b4-8a0d-11e0-8ae7-1c7508ccb332} - J:\SETUP.EXE MountPoints2: {b4f38ef6-78b1-11e0-98a5-1c7508ccb332} - H:\Autoplay.exe -auto MountPoints2: {f21bb380-74ac-11e1-acff-f9bf31f3db57} - F:\unlock.exe autoplay=true HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation) HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-05-27] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.) HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-06-29] (NewTech Infosystems, Inc.) HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.) HKLM-x32\...\Run: [PaperPort PTD] - C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe [30248 2007-01-29] (Nuance Communications, Inc.) HKLM-x32\...\Run: [IndexSearch] - C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe [46632 2007-01-29] (Nuance Communications, Inc.) HKLM-x32\...\Run: [Adobe_ID0EYTHM] - C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe [1884160 2007-03-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [703888 2013-07-19] (Cisco Systems, Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\avastui.exe [3567800 2013-10-21] (AVAST Software) HKLM-x32\...\Run: [20131121] - C:\Program Files\AVAST Software\Avast\Setup\emupdate\05adcc99-f077-4b72-b93a-dfd5756577f0.exe [180184 2013-11-23] (AVAST Software) HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\UpdatusUser\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () AppInit_DLLs: C:\Windows\System32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation) Startup: C:\Users\Jasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Jasmin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Jasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - .lnk ShortcutTarget: Tintenwarnungen überwachen - .lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) Startup: C:\Users\Jasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wecker für Windows 6.lnk ShortcutTarget: Wecker für Windows 6.lnk -> C:\Program Files (x86)\Wecker6\Wecker.exe (Christoph Bünger Software) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{BA455E5F-B88C-4E85-96F3-5AFAD778D69B}: [NameServer]134.102.20.20,134.102.200.14 FireFox: ======== FF ProfilePath: C:\Users\Jasmin\AppData\Roaming\Mozilla\Firefox\Profiles\h0e9p0mu.default FF DefaultSearchEngine: Google Search FF Homepage: spiegelonline.de FF Keyword.URL: hxxp://www.google.de/search?hl=de&q= FF NetworkProxy: "http", "proxy.uni-greifswald.de" FF NetworkProxy: "http_port", 8080 FF NetworkProxy: "socks_remote_dns", true FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Jasmin\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Jasmin\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\Jasmin\AppData\Roaming\Mozilla\Firefox\Profiles\h0e9p0mu.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\Jasmin\AppData\Roaming\Mozilla\Firefox\Profiles\h0e9p0mu.default\searchplugins\startpage-https.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: FoxyProxy Basic - C:\Users\Jasmin\AppData\Roaming\Mozilla\Firefox\Profiles\h0e9p0mu.default\Extensions\foxyproxy@eric.h.jung FF Extension: DVDVideoSoft Menu - C:\Users\Jasmin\AppData\Roaming\Mozilla\Firefox\Profiles\h0e9p0mu.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: Adblock Plus - C:\Users\Jasmin\AppData\Roaming\Mozilla\Firefox\Profiles\h0e9p0mu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR HomePage: CHR RestoreOnStartup: "hxxp://www.google.de/" CHR DefaultSearchKeyword: google.de CHR DefaultSearchProvider: Google CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Jasmin\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll No File CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll No File CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll No File CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll No File CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll No File CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll No File CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File CHR Plugin: (Java(TM) Platform SE 7 U5) - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Google Earth Plugin) - C:\Users\Jasmin\AppData\Local\Google\Google Earth\plugin\npgeplugin.dll No File CHR Plugin: (Google Update) - C:\Users\Jasmin\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Extension: (YouTube) - C:\Users\Jasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Jasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (AdBlock) - C:\Users\Jasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0 CHR Extension: (Plus-HD-1.6) - C:\Users\Jasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.25.121_0 CHR Extension: (Google Wallet) - C:\Users\Jasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Jasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0 CHR Extension: (Gmail) - C:\Users\Jasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-10-21] (AVAST Software) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe [237008 2011-06-17] (McAfee, Inc.) S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.) R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation) ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-10-21] (AVAST Software) R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21136 2012-10-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-10-21] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-21] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-21] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-10-21] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-11-10] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-10-21] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-10-21] () R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] () R3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52080 2013-07-19] (Cisco Systems, Inc.) S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [x] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [x] ==================== NetSvcs (Whitelisted) =================== |
Themen zu Virusbefall als Links mit blau hinterlegten Worten mit kleinem grünen Pfeil in Browser-Texten |
.com, 4d36e972-e325-11ce-bfc1-08002be10318, adblock, blau verlinkt, bonjour, computer, converter, desktop, device driver, email, entfernen, error, excel, firefox, flash player, google, help, home, homepage, mp3, pmmupdate.exe, programm, richtlinie, scan, security, server, sich automatisch, symantec, virus, werbefenster, werbung, windows |