|
Plagegeister aller Art und deren Bekämpfung: hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoomWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
31.12.2013, 14:46 | #1 |
| hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom hallo leider werde ich dieses nation zoom auch net los , habe hier ein bissche gelesen und schonmal das 64 bit ding zum scannen runter geladen hier jetzt die ergebnisse.. Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-12-2013 Ran by gundi (administrator) on GUNDI-PC on 31-12-2013 14:34:04 Running from C:\Users\gundi\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe () C:\Windows\System32\PSIService.exe (Tlapia) C:\Program Files\sysTPL\sysTPLMonitor.exe (Tlapia) C:\Program Files\sysTPL\sysTPLService.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (cyberlink) C:\Program Files\Cyberlink\Shared files\brs.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe () C:\Windows\vsnpstd3.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avcenter.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [178712 2007-10-08] (Intel Corporation) HKLM\...\Run: [BDRegion] - C:\Program Files\Cyberlink\Shared files\brs.exe [75048 2010-03-13] (cyberlink) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6724128 2009-02-03] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-02-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [snpstd3] - C:\Windows\vsnpstd3.exe [827392 2006-09-19] () HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [NeroFilterCheck] - C:\Windows\System32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-12] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll",DllRegisterServer HKCU\...\Run: [EPSON SX100 Series] - C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\Windows\TEMP\E_S88DD.tmp" /EF "HKCU" HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [NextLive] - C:\Windows\system32\rundll32.exe "C:\Users\gundi\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKCU\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess? HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Gast\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter AppInit_DLLs: c:\progra~1\search~1\datamngr\mgrldr.dll c:\docume~1\ settings\all users\application data\browserprotect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8} [ ] () dditional scan result of Farbar Recovery Scan Tool (x86) Version: 31-12-2013 Ran by gundi at 2013-12-31 14:35:23 Running from C:\Users\gundi\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== ABBYY FineReader 6.0 Sprint (Version: 6.00.1395.4512 - ABBYY Software House) Adobe Flash Player 11 ActiveX (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (Version: 12.0.2.122 - Adobe Systems, Inc.) Apple Application Support (Version: 2.1.5 - Apple Inc.) Apple Software Update (Version: 2.1.3.127 - Apple Inc.) Ashampoo Burning Studio 6 FREE (Version: 6.7.6 - ashampoo GmbH & Co. KG) Avira Free Antivirus (Version: 14.0.2.286 - Avira) CCleaner (Version: 4.00 - Piriform) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000 - Microsoft Corporation) CorelDRAW Essential Edition 3 (Version: - Corel Corporation) CorelDRAW Essential Edition 3 (Version: 3.0 - Corel Corporation) CyberLink PowerDVD 10 (Version: 10.0.1516 - CyberLink Corp.) D3DX10 (Version: 15.4.2368.0902 - Microsoft) DE (Version: 3.0 - Corel Corporation) Druckerdeinstallation für EPSON SX100 Series (Version: - SEIKO EPSON Corporation) Epson Easy Photo Print 2 (Version: 2.0.0.0 - SEIKO EPSON CORPORATION) EPSON Scan (Version: - ) Google Chrome (Version: 31.0.1650.63 - Google Inc.) Google Update Helper (Version: 1.3.22.3 - Google Inc.) HyperCam 2 (Version: - ) ImagXpress (Version: 7.0.74.0 - Nero AG) Intel(R) Matrix Storage Manager (Version: - ) Java 7 Update 45 (Version: 7.0.450 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) LightScribe System Software (Version: 1.18.8.1 - LightScribe) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Primary Interoperability Assemblies 2005 (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [DEU] (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (Version: 9.7.0621 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0 - Microsoft Corp.) MSVCRT (Version: 15.4.2862.0708 - Microsoft) MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) Nero (Version: 5.5.9.8 - ahead software gmbh) Nero Suite (Version: - ) neroxml (Version: 1.0.0 - Nero AG) NVIDIA Drivers (Version: 1.3 - NVIDIA Corporation) NVIDIA PhysX (Version: 9.09.0203 - NVIDIA Corporation) Octoshape add-in for Adobe Flash Player (Version: - ) OpenOffice.org 3.3 (Version: 3.3.9567 - OpenOffice.org) PC Camer@ (Version: 1.0.4.3 - Ihr Firmenname) PCSpeedUp (Version: - www.pcspeedup.com) PokerStars (Version: - PokerStars) QuickEngine (Version: 1.0.1 - Tlapia) Realtek High Definition Audio Driver (Version: 6.0.1.5783 - Realtek Semiconductor Corp.) Segoe UI (Version: 15.4.2271.0615 - Microsoft Corp) Skype™ 6.6 (Version: 6.6.106 - Skype Technologies S.A.) Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0 - Adobe Systems Incorporated) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) System Requirements Lab (Version: - ) sysTPL (Version: 1.0.0 - Tlapia) Ulead Photo Express 3.0 SE (Version: - ) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3 - Microsoft Corporation) Update Manager (Version: 4.60 - Corel Corporation) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Fotogalerie (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Mail (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Movie Maker (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Photo Gallery (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live PIMT Platform (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Writer (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Writer Resources (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Media Player Firefox Plugin (Version: 1.0.0.8 - Microsoft Corp) WinRAR (Version: - ) ==================== Restore Points ========================= 25-10-2013 16:25:47 Geplanter Prüfpunkt 26-10-2013 13:59:43 Geplanter Prüfpunkt 28-10-2013 14:18:05 Geplanter Prüfpunkt 30-10-2013 10:57:26 Geplanter Prüfpunkt 31-10-2013 10:41:42 Geplanter Prüfpunkt 01-11-2013 12:53:50 Geplanter Prüfpunkt 02-11-2013 15:01:41 Geplanter Prüfpunkt 03-11-2013 11:23:31 Geplanter Prüfpunkt 05-11-2013 17:10:04 Geplanter Prüfpunkt 08-11-2013 20:29:18 Geplanter Prüfpunkt 10-11-2013 15:28:45 Geplanter Prüfpunkt 11-11-2013 15:38:42 Removed Google Earth. 11-11-2013 16:43:04 Removed Google Earth. 11-11-2013 17:20:49 Installed QuickEngine 11-11-2013 17:45:49 Removed Java(TM) 6 Update 22 11-11-2013 17:47:07 Removed Java(TM) 6 Update 37 11-11-2013 17:50:45 Removed Facebook Video Calling 1.2.0.287 11-11-2013 18:02:08 Removed QuickTime 12-11-2013 16:13:53 Konfiguriert PowerDVD 13-11-2013 14:10:30 Geplanter Prüfpunkt 13-11-2013 15:14:22 Windows Update 17-11-2013 10:15:45 Geplanter Prüfpunkt 18-11-2013 19:40:58 Geplanter Prüfpunkt 19-11-2013 10:24:53 Geplanter Prüfpunkt 21-11-2013 17:36:55 Geplanter Prüfpunkt 22-11-2013 12:19:14 Geplanter Prüfpunkt 24-11-2013 19:00:12 Geplanter Prüfpunkt 25-11-2013 14:16:43 Geplanter Prüfpunkt 26-11-2013 09:36:32 Geplanter Prüfpunkt 27-11-2013 18:26:51 Geplanter Prüfpunkt 28-11-2013 09:59:25 Geplanter Prüfpunkt 29-11-2013 14:57:55 Geplanter Prüfpunkt 01-12-2013 14:47:38 Geplanter Prüfpunkt 02-12-2013 09:51:43 Geplanter Prüfpunkt 09-12-2013 16:37:10 Geplanter Prüfpunkt 11-12-2013 11:37:10 Windows Update 14-12-2013 12:45:26 Geplanter Prüfpunkt 16-12-2013 13:24:12 Geplanter Prüfpunkt 18-12-2013 12:16:20 Geplanter Prüfpunkt 22-12-2013 12:47:10 Geplanter Prüfpunkt 23-12-2013 13:22:41 Geplanter Prüfpunkt 28-12-2013 16:15:46 Geplanter Prüfpunkt 29-12-2013 15:15:14 Geplanter Prüfpunkt 31-12-2013 12:54:39 Uniblue SpeedUpMyPC installation ==================== Hosts content: ========================== 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {2251D488-4EBE-413B-9170-82FD97C65510} - System32\Tasks\Plus-HD-1.2-chromeinstaller => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-chromeinstaller.exe <==== ATTENTION Task: {2A6D5DCD-BE66-4DFE-9AF7-5A51F0D196F0} - System32\Tasks\Re-markit Update => C:\Program Files\Re-markit\ReMarkit_up.exe <==== ATTENTION Task: {2E1FA6B1-DE11-4B99-A160-3406FC66C8AA} - System32\Tasks\Plus-HD-1.2-updater => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-updater.exe <==== ATTENTION Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {35655400-4B7E-41DC-B5EF-4738BC56B3F3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-03-25] (Piriform Ltd) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {424D1112-4183-4C48-92FF-4FF9F8DCC871} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {45FA3731-31DD-488B-A3C5-F8A6760453DD} - System32\Tasks\temp_Plus-HD-1.2-enabler => C:\Users\gundi\AppData\Local\Temp\nsw673E.tmp\Plus-HD-1.2-enabler.exe <==== ATTENTION Task: {48EF12C9-25E7-4774-8027-846B638E7740} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3813596177-1276424280-2619024677-1000UA => C:\Users\gundi\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {4C1C7DC7-3DDC-43FC-AB43-2256C24ADB89} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated) Task: {51D3A3CA-95A5-43CF-B8DB-BC32023BD86E} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\TuneUp Utilities 2013\OneClick.exe Task: {55E4AC30-B974-4C21-BD4F-E7A40712C31F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3813596177-1276424280-2619024677-1000Core => C:\Users\gundi\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {638764FF-409C-41C9-88B6-8D72E6A31983} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-21] (Google Inc.) Task: {63F6E6A7-4290-4845-BBBB-F0ED798FB6A2} - System32\Tasks\{20B5A60C-7771-4AB2-A801-66932EF41167} => C:\Program Files\Skype\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {72504F05-9EE4-4D80-B59C-94694196A304} - System32\Tasks\Plus-HD-1.2-firefoxinstaller => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-firefoxinstaller.exe <==== ATTENTION Task: {762D8C1B-FCB1-42F6-BFBC-C67867CD872F} - System32\Tasks\Plus-HD-1.2-enabler => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-enabler.exe <==== ATTENTION Task: {898885D5-D91A-4A4D-9267-7E8F9C59DCA5} - System32\Tasks\Plus-HD-1.2-codedownloader => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-codedownloader.exe <==== ATTENTION Task: {983BF916-345A-4B5C-9351-64B56A82F8F4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-21] (Google Inc.) Task: {9A07FDFF-02BB-44BB-B547-BE47A8623094} - System32\Tasks\EPUpdater => C:\Users\gundi\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe <==== ATTENTION Task: {9DC09BC8-90F4-450E-A7E6-EC8ED992A202} - System32\Tasks\SpeedUpMyPC Startup => C:\Program Files\Uniblue\SpeedUpMyPC\speedupmypc.exe Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries Task: {D973E425-2C1B-40C9-9B48-B9C4F41806B7} - System32\Tasks\SpeedUpMyPC Maintenance => C:\Program Files\Uniblue\SpeedUpMyPC\speedupmypc.exe Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] () Task: {EE138026-69C2-45ED-8A8C-99F9ED448BBA} - System32\Tasks\BrowserProtect => Sc.exe start BrowserProtect <==== ATTENTION Task: {F3EDA4C2-91C9-4BB3-9314-3777B27627F8} - System32\Tasks\PC SpeedUp Service Deactivator => C:\Program Files\PC Beschleunigen\PCSUSD.exe <==== ATTENTION Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-12-04 19:23 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-04 19:23 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-04 19:23 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll 2013-12-04 19:23 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-04 19:23 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libegl.dll 2013-12-04 19:23 - 2013-12-04 03:48 - 13586896 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\gundi\Documents\clip0001.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0002.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0003.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0004.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0005.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0006.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0007.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0008.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0009.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0010.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0014.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0015.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0018.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0019.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0020.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0021.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0022.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0023.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0024.avi:TOC.WMV ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: 802.11b/g/n USB Wireless Network Adapter Description: 802.11b/g/n USB Wireless Network Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Service: netr28u Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (12/31/2013 02:20:59 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 02:14:55 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 01:55:06 PM) (Source: Windows Installer 3.1) (User: ) Description: WindowsFür diesen Befehl ist nicht genügend Speicher verfügbar. Error: (12/31/2013 01:54:01 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {511fbf08-20ae-46ed-8c2b-4415c0752b80} Error: (12/31/2013 11:58:55 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 10:44:40 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 05:05:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 11:50:48 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 09:13:43 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2013 11:28:43 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (12/31/2013 02:20:59 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/31/2013 02:14:55 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/31/2013 11:58:59 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/31/2013 10:44:40 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/30/2013 05:05:51 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/30/2013 11:50:48 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/30/2013 09:13:44 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/29/2013 11:28:44 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/29/2013 01:56:52 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/29/2013 10:18:49 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Microsoft Office Sessions: ========================= Error: (12/31/2013 02:20:59 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 02:14:55 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 01:55:06 PM) (Source: Windows Installer 3.1)(User: ) Description: WindowsFür diesen Befehl ist nicht genügend Speicher verfügbar. Error: (12/31/2013 01:54:01 PM) (Source: VSS)(User: ) Description: 0x80070005 Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {511fbf08-20ae-46ed-8c2b-4415c0752b80} Error: (12/31/2013 11:58:55 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 10:44:40 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 05:05:51 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 11:50:48 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 09:13:43 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2013 11:28:43 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 3325.27 MB Available physical RAM: 1846.54 MB Total Pagefile: 6870.36 MB Available Pagefile: 5072.93 MB Total Virtual: 2047.88 MB Available Virtual: 1901.96 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:911.51 GB) (Free:731.74 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:19.99 GB) (Free:8.92 GB) FAT32 Drive i: () (Removable) (Total:3.69 GB) (Free:0.43 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: F98D6E74) Partition 1: (Active) - (Size=912 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended) ======================================================== Disk: 4 (Size: 4 GB) (Disk ID: 00000000) Partition 1: (Not Active) - (Size=4 GB) - (Type=0B) ==================== End Of Log ============================ Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-12-2013 Ran by gundi (administrator) on GUNDI-PC on 31-12-2013 14:39:12 Running from C:\Users\gundi\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe () C:\Windows\System32\PSIService.exe (Tlapia) C:\Program Files\sysTPL\sysTPLMonitor.exe (Tlapia) C:\Program Files\sysTPL\sysTPLService.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (cyberlink) C:\Program Files\Cyberlink\Shared files\brs.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe () C:\Windows\vsnpstd3.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [178712 2007-10-08] (Intel Corporation) HKLM\...\Run: [BDRegion] - C:\Program Files\Cyberlink\Shared files\brs.exe [75048 2010-03-13] (cyberlink) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6724128 2009-02-03] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-02-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [snpstd3] - C:\Windows\vsnpstd3.exe [827392 2006-09-19] () HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [NeroFilterCheck] - C:\Windows\System32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-12] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll",DllRegisterServer HKCU\...\Run: [EPSON SX100 Series] - C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\Windows\TEMP\E_S88DD.tmp" /EF "HKCU" HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [NextLive] - C:\Windows\system32\rundll32.exe "C:\Users\gundi\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKCU\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess? HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Gast\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter AppInit_DLLs: c:\progra~1\search~1\datamngr\mgrldr.dll c:\docume~1\ settings\all users\application data\browserprotect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8} [ ] () ==================== Internet (Whitelisted) ==================== ProxyServer: http=127.0.0.1:8877;https=127.0.0.1:8877 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=a4353f1e-ff9e-4eb2-9a56-babf7f482139&searchtype=ds&q={searchTerms}&installDate=23/05/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.facebook.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=a4353f1e-ff9e-4eb2-9a56-babf7f482139&searchtype=ds&q={searchTerms}&installDate=23/05/2013 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX&q={searchTerms} SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=a4353f1e-ff9e-4eb2-9a56-babf7f482139&searchtype=ds&q={searchTerms}&installDate=23/05/2013 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_uid=2863021520344074&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_uid=2863021520344074&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=a4353f1e-ff9e-4eb2-9a56-babf7f482139&searchtype=ds&q={searchTerms}&installDate=23/05/2013 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&affID=119781&tt=gc_&babsrc=SP_ss&mntrId=CEDA02242178B865 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX&q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_uid=2863021520344074&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKLM - No Name - !{EEE6C35B-6118-11DC-9C72-001320C79847} - No File Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKCU - No Name - {40C3CC16-7269-4B32-9531-17F2950FB06F} - No File DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default FF user.js: detected! => C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\user.js FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Windows\system32\npdeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\MyStart Search.xml FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\Search_Results.xml FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\sweetim.xml FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml FF Extension: Conduit Engine - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\engine@conduit.com FF Extension: HDvid Codec - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\hdvc@hdvc.com FF Extension: Microsoft .NET Framework Assistant - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF Extension: GoPhotoIt - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\gophoto@gophoto.it.xpi FF Extension: HDvid Codec - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\hdvc@hdvc.com.xpi FF Extension: M2k Downloader - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\m2k@m2kdownloader.com.xpi FF Extension: SweetPacks Toolbar for Firefox - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ Chrome: ======= CHR HomePage: hxxp://www.nationzoom.com/?type=hp&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX CHR RestoreOnStartup: "https://www.facebook.com/logout.php" CHR Plugin: (Shockwave Flash) - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll No File CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll No File CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll No File CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll No File CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Unity Player) - C:\Users\gundi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\gundi\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Extended Protection) - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0 CHR Extension: (Lightning Newtab) - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.1.7.9_0 CHR Extension: (Google Wallet) - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR HKLM\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx CHR HKLM\...\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\gundi\AppData\Local\Wajam\Chrome\wajam.crx CHR HKLM\...\Chrome\Extension: [kpkbnefaikfaeadgidhpoanckoiaheli] - C:\Program Files\HDvidCodec.com\HDvidCodec10.crx CHR HKLM\...\Chrome\Extension: [lbbbdmbjkgojacipgefbifkiebpcdjhn] - C:\Program Files\Movie2KDownloader.com\m2kDownloader10.crx CHR HKLM\...\Chrome\Extension: [pfmopbbadnfoelckkcmjjeaaegjpjjbk] - C:\Program Files\Gophoto.it\gophotoit14.crx CHR StartMenuInternet: Google Chrome - C:\Program Files\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-12] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG) R2 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-17] (SEIKO EPSON CORPORATION) R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION) R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 sysTPLMonitor.exe; C:\Program Files\sysTPL\sysTPLMonitor.exe [395888 2013-11-27] (Tlapia) R2 sysTPLService.exe; C:\Program Files\sysTPL\sysTPLService.exe [394352 2013-11-27] (Tlapia) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-12] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-12] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG) R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [554496 2007-09-21] (Ralink Technology Corp.) S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [506112 2006-11-20] (PixArt Imaging Inc.) S3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10252544 2007-03-27] (Sonix Co. Ltd.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-02-09] (Avira GmbH) R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl [87536 2010-03-13] (CyberLink Corp.) S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-31 14:35 - 2013-12-31 14:39 - 00025130 _____ C:\Users\gundi\Downloads\Addition.txt 2013-12-31 14:34 - 2013-12-31 14:39 - 00022680 _____ C:\Users\gundi\Downloads\FRST.txt 2013-12-31 14:33 - 2013-12-31 14:33 - 01064333 _____ (Farbar) C:\Users\gundi\Downloads\FRST.exe 2013-12-31 14:33 - 2013-12-31 14:33 - 00000000 ____D C:\FRST 2013-12-31 14:32 - 2013-12-31 14:32 - 01272360 _____ (iMesh Inc) C:\Users\gundi\Downloads\iMeshSetup-r1487-w-bc.exe 2013-12-31 14:32 - 2013-12-31 14:32 - 00000615 _____ C:\Users\Public\Desktop\iMesh-Installation fortsetzen.lnk 2013-12-31 14:32 - 2013-12-31 14:32 - 00000000 ____D C:\Program Files\iMesh Applications 2013-12-31 14:13 - 2013-12-31 14:13 - 00002420 _____ C:\Windows\PFRO.log 2013-12-31 13:55 - 2013-12-31 13:55 - 00000554 _____ C:\Windows\KB893803v2.log 2013-12-31 13:54 - 2013-12-31 14:20 - 00000000 ____D C:\Users\gundi\AppData\Roaming\newnext.me 2013-12-31 13:54 - 2013-12-31 14:03 - 00000000 ____D C:\Users\gundi\AppData\Local\Mobogenie 2013-12-31 13:54 - 2013-12-31 14:00 - 00000000 ____D C:\Program Files\MyPC Backup 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\Documents\Mobogenie 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\genienext 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\cache 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\.android 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 _____ C:\Users\gundi\daemonprocess.txt 2013-12-31 13:53 - 2013-12-31 14:01 - 00000000 ____D C:\Users\gundi\AppData\Local\Lollipop 2013-12-31 13:53 - 2013-12-31 13:53 - 00000000 ____D C:\ProgramData\WPM 2013-12-31 13:48 - 2013-12-31 13:48 - 00479792 _____ C:\Users\gundi\Downloads\Player Setup (1).exe 2013-12-31 13:47 - 2013-12-31 13:47 - 00479792 _____ C:\Users\gundi\Downloads\Player Setup.exe 2013-12-27 14:34 - 2013-12-27 14:38 - 186446085 _____ C:\Users\gundi\Desktop\2127343972001_2854723499001_EV108893-KleineHaendeGrossePfoten-source-ST.mp4 2013-12-27 14:16 - 2013-12-27 14:28 - 901182774 _____ C:\Users\gundi\Desktop\2127343972001_2854993219001_EV114583-SophieUndShiba-source-ST.mp4 2013-12-15 17:30 - 2013-12-15 17:30 - 00000000 ____D C:\Users\gundi\AppData\Local\{DE5AA92A-FFD5-4755-AB87-389C7C1A6D06} 2013-12-11 12:37 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-11 12:37 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-11 12:37 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-11 12:37 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-11 12:37 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-11 12:37 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-11 12:37 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 12:37 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-11 12:37 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 12:37 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 12:37 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-11 12:37 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 12:37 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-11 12:37 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 12:37 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-11 12:37 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-11 10:48 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-12-11 10:48 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 10:48 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-11 10:48 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 10:48 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 10:48 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 10:48 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 10:48 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-11 10:48 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 10:48 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-01 16:00 - 2013-12-01 16:00 - 01050264 _____ (Unity Technologies ApS) C:\Users\gundi\Downloads\UnityWebPlayer (2).exe 2013-12-01 15:59 - 2013-12-01 15:59 - 01050264 _____ (Unity Technologies ApS) C:\Users\gundi\Downloads\UnityWebPlayer (1).exe ==================== One Month Modified Files and Folders ======= 2013-12-31 14:39 - 2013-12-31 14:35 - 00025130 _____ C:\Users\gundi\Downloads\Addition.txt 2013-12-31 14:39 - 2013-12-31 14:34 - 00022680 _____ C:\Users\gundi\Downloads\FRST.txt 2013-12-31 14:33 - 2013-12-31 14:33 - 01064333 _____ (Farbar) C:\Users\gundi\Downloads\FRST.exe 2013-12-31 14:33 - 2013-12-31 14:33 - 00000000 ____D C:\FRST 2013-12-31 14:32 - 2013-12-31 14:32 - 01272360 _____ (iMesh Inc) C:\Users\gundi\Downloads\iMeshSetup-r1487-w-bc.exe 2013-12-31 14:32 - 2013-12-31 14:32 - 00000615 _____ C:\Users\Public\Desktop\iMesh-Installation fortsetzen.lnk 2013-12-31 14:32 - 2013-12-31 14:32 - 00000000 ____D C:\Program Files\iMesh Applications 2013-12-31 14:27 - 2010-05-21 14:53 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-31 14:24 - 2011-10-13 13:50 - 01216690 _____ C:\Windows\WindowsUpdate.log 2013-12-31 14:20 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Roaming\newnext.me 2013-12-31 14:19 - 2010-05-21 14:53 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-31 14:19 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-31 14:19 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-31 14:19 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-31 14:18 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-31 14:13 - 2013-12-31 14:13 - 00002420 _____ C:\Windows\PFRO.log 2013-12-31 14:03 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\Mobogenie 2013-12-31 14:01 - 2013-12-31 13:53 - 00000000 ____D C:\Users\gundi\AppData\Local\Lollipop 2013-12-31 14:00 - 2013-12-31 13:54 - 00000000 ____D C:\Program Files\MyPC Backup 2013-12-31 13:57 - 2006-11-02 11:33 - 01539286 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-31 13:55 - 2013-12-31 13:55 - 00000554 _____ C:\Windows\KB893803v2.log 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\Documents\Mobogenie 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\genienext 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\cache 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\.android 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 _____ C:\Users\gundi\daemonprocess.txt 2013-12-31 13:54 - 2009-06-06 12:46 - 00000000 ____D C:\Users\gundi 2013-12-31 13:53 - 2013-12-31 13:53 - 00000000 ____D C:\ProgramData\WPM 2013-12-31 13:53 - 2013-06-28 13:42 - 00001171 _____ C:\Users\gundi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-31 13:53 - 2012-10-03 13:05 - 00002193 _____ C:\Users\gundi\Desktop\Google Chrome.lnk 2013-12-31 13:48 - 2013-12-31 13:48 - 00479792 _____ C:\Users\gundi\Downloads\Player Setup (1).exe 2013-12-31 13:47 - 2013-12-31 13:47 - 00479792 _____ C:\Users\gundi\Downloads\Player Setup.exe 2013-12-31 13:41 - 2012-06-25 11:43 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-29 13:09 - 2010-10-20 20:12 - 00000000 ____D C:\Windows\Minidump 2013-12-27 14:38 - 2013-12-27 14:34 - 186446085 _____ C:\Users\gundi\Desktop\2127343972001_2854723499001_EV108893-KleineHaendeGrossePfoten-source-ST.mp4 2013-12-27 14:28 - 2013-12-27 14:16 - 901182774 _____ C:\Users\gundi\Desktop\2127343972001_2854993219001_EV114583-SophieUndShiba-source-ST.mp4 2013-12-21 15:10 - 2009-06-08 14:06 - 00007408 _____ C:\Users\gundi\AppData\Roaming\wklnhst.dat 2013-12-15 17:30 - 2013-12-15 17:30 - 00000000 ____D C:\Users\gundi\AppData\Local\{DE5AA92A-FFD5-4755-AB87-389C7C1A6D06} 2013-12-12 13:12 - 2013-02-09 23:04 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-12 13:12 - 2013-02-09 23:04 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-11 19:41 - 2012-06-25 11:43 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-11 19:41 - 2011-08-12 21:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-11 15:43 - 2006-11-02 13:47 - 00398720 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-11 15:40 - 2009-04-02 14:28 - 00000000 ____D C:\Windows\system32\RTCOM 2013-12-11 12:40 - 2013-08-14 10:55 - 00000000 ____D C:\Windows\system32\MRT 2013-12-11 12:38 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-12-01 16:00 - 2013-12-01 16:00 - 01050264 _____ (Unity Technologies ApS) C:\Users\gundi\Downloads\UnityWebPlayer (2).exe 2013-12-01 15:59 - 2013-12-01 15:59 - 01050264 _____ (Unity Technologies ApS) C:\Users\gundi\Downloads\UnityWebPlayer (1).exe Some content of TEMP: ==================== C:\Users\gundi\AppData\Local\Temp\avgnt.exe C:\Users\gundi\AppData\Local\Temp\BackupSetup.exe C:\Users\gundi\AppData\Local\Temp\kwfoalaflmgnptk.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-31 14:25 ==================== End Of Log ============================ Additional scan result of Farbar Recovery Scan Tool (x86) Version: 31-12-2013 Ran by gundi at 2013-12-31 14:39:40 Running from C:\Users\gundi\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== ABBYY FineReader 6.0 Sprint (Version: 6.00.1395.4512 - ABBYY Software House) Adobe Flash Player 11 ActiveX (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (Version: 12.0.2.122 - Adobe Systems, Inc.) Apple Application Support (Version: 2.1.5 - Apple Inc.) Apple Software Update (Version: 2.1.3.127 - Apple Inc.) Ashampoo Burning Studio 6 FREE (Version: 6.7.6 - ashampoo GmbH & Co. KG) Avira Free Antivirus (Version: 14.0.2.286 - Avira) CCleaner (Version: 4.00 - Piriform) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000 - Microsoft Corporation) CorelDRAW Essential Edition 3 (Version: - Corel Corporation) CorelDRAW Essential Edition 3 (Version: 3.0 - Corel Corporation) CyberLink PowerDVD 10 (Version: 10.0.1516 - CyberLink Corp.) D3DX10 (Version: 15.4.2368.0902 - Microsoft) DE (Version: 3.0 - Corel Corporation) Druckerdeinstallation für EPSON SX100 Series (Version: - SEIKO EPSON Corporation) Epson Easy Photo Print 2 (Version: 2.0.0.0 - SEIKO EPSON CORPORATION) EPSON Scan (Version: - ) Google Chrome (Version: 31.0.1650.63 - Google Inc.) Google Update Helper (Version: 1.3.22.3 - Google Inc.) HyperCam 2 (Version: - ) ImagXpress (Version: 7.0.74.0 - Nero AG) Intel(R) Matrix Storage Manager (Version: - ) Java 7 Update 45 (Version: 7.0.450 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) LightScribe System Software (Version: 1.18.8.1 - LightScribe) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Primary Interoperability Assemblies 2005 (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [DEU] (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (Version: 9.7.0621 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0 - Microsoft Corp.) MSVCRT (Version: 15.4.2862.0708 - Microsoft) MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) Nero (Version: 5.5.9.8 - ahead software gmbh) Nero Suite (Version: - ) neroxml (Version: 1.0.0 - Nero AG) NVIDIA Drivers (Version: 1.3 - NVIDIA Corporation) NVIDIA PhysX (Version: 9.09.0203 - NVIDIA Corporation) Octoshape add-in for Adobe Flash Player (Version: - ) OpenOffice.org 3.3 (Version: 3.3.9567 - OpenOffice.org) PC Camer@ (Version: 1.0.4.3 - Ihr Firmenname) PCSpeedUp (Version: - www.pcspeedup.com) PokerStars (Version: - PokerStars) QuickEngine (Version: 1.0.1 - Tlapia) Realtek High Definition Audio Driver (Version: 6.0.1.5783 - Realtek Semiconductor Corp.) Segoe UI (Version: 15.4.2271.0615 - Microsoft Corp) Skype™ 6.6 (Version: 6.6.106 - Skype Technologies S.A.) Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0 - Adobe Systems Incorporated) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) System Requirements Lab (Version: - ) sysTPL (Version: 1.0.0 - Tlapia) Ulead Photo Express 3.0 SE (Version: - ) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3 - Microsoft Corporation) Update Manager (Version: 4.60 - Corel Corporation) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Fotogalerie (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Mail (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Movie Maker (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Photo Gallery (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live PIMT Platform (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Writer (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Writer Resources (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Media Player Firefox Plugin (Version: 1.0.0.8 - Microsoft Corp) WinRAR (Version: - ) ==================== Restore Points ========================= 25-10-2013 16:25:47 Geplanter Prüfpunkt 26-10-2013 13:59:43 Geplanter Prüfpunkt 28-10-2013 14:18:05 Geplanter Prüfpunkt 30-10-2013 10:57:26 Geplanter Prüfpunkt 31-10-2013 10:41:42 Geplanter Prüfpunkt 01-11-2013 12:53:50 Geplanter Prüfpunkt 02-11-2013 15:01:41 Geplanter Prüfpunkt 03-11-2013 11:23:31 Geplanter Prüfpunkt 05-11-2013 17:10:04 Geplanter Prüfpunkt 08-11-2013 20:29:18 Geplanter Prüfpunkt 10-11-2013 15:28:45 Geplanter Prüfpunkt 11-11-2013 15:38:42 Removed Google Earth. 11-11-2013 16:43:04 Removed Google Earth. 11-11-2013 17:20:49 Installed QuickEngine 11-11-2013 17:45:49 Removed Java(TM) 6 Update 22 11-11-2013 17:47:07 Removed Java(TM) 6 Update 37 11-11-2013 17:50:45 Removed Facebook Video Calling 1.2.0.287 11-11-2013 18:02:08 Removed QuickTime 12-11-2013 16:13:53 Konfiguriert PowerDVD 13-11-2013 14:10:30 Geplanter Prüfpunkt 13-11-2013 15:14:22 Windows Update 17-11-2013 10:15:45 Geplanter Prüfpunkt 18-11-2013 19:40:58 Geplanter Prüfpunkt 19-11-2013 10:24:53 Geplanter Prüfpunkt 21-11-2013 17:36:55 Geplanter Prüfpunkt 22-11-2013 12:19:14 Geplanter Prüfpunkt 24-11-2013 19:00:12 Geplanter Prüfpunkt 25-11-2013 14:16:43 Geplanter Prüfpunkt 26-11-2013 09:36:32 Geplanter Prüfpunkt 27-11-2013 18:26:51 Geplanter Prüfpunkt 28-11-2013 09:59:25 Geplanter Prüfpunkt 29-11-2013 14:57:55 Geplanter Prüfpunkt 01-12-2013 14:47:38 Geplanter Prüfpunkt 02-12-2013 09:51:43 Geplanter Prüfpunkt 09-12-2013 16:37:10 Geplanter Prüfpunkt 11-12-2013 11:37:10 Windows Update 14-12-2013 12:45:26 Geplanter Prüfpunkt 16-12-2013 13:24:12 Geplanter Prüfpunkt 18-12-2013 12:16:20 Geplanter Prüfpunkt 22-12-2013 12:47:10 Geplanter Prüfpunkt 23-12-2013 13:22:41 Geplanter Prüfpunkt 28-12-2013 16:15:46 Geplanter Prüfpunkt 29-12-2013 15:15:14 Geplanter Prüfpunkt 31-12-2013 12:54:39 Uniblue SpeedUpMyPC installation ==================== Hosts content: ========================== 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {2251D488-4EBE-413B-9170-82FD97C65510} - System32\Tasks\Plus-HD-1.2-chromeinstaller => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-chromeinstaller.exe <==== ATTENTION Task: {2A6D5DCD-BE66-4DFE-9AF7-5A51F0D196F0} - System32\Tasks\Re-markit Update => C:\Program Files\Re-markit\ReMarkit_up.exe <==== ATTENTION Task: {2E1FA6B1-DE11-4B99-A160-3406FC66C8AA} - System32\Tasks\Plus-HD-1.2-updater => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-updater.exe <==== ATTENTION Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {35655400-4B7E-41DC-B5EF-4738BC56B3F3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-03-25] (Piriform Ltd) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {424D1112-4183-4C48-92FF-4FF9F8DCC871} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {45FA3731-31DD-488B-A3C5-F8A6760453DD} - System32\Tasks\temp_Plus-HD-1.2-enabler => C:\Users\gundi\AppData\Local\Temp\nsw673E.tmp\Plus-HD-1.2-enabler.exe <==== ATTENTION Task: {48EF12C9-25E7-4774-8027-846B638E7740} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3813596177-1276424280-2619024677-1000UA => C:\Users\gundi\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {4C1C7DC7-3DDC-43FC-AB43-2256C24ADB89} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated) Task: {51D3A3CA-95A5-43CF-B8DB-BC32023BD86E} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\TuneUp Utilities 2013\OneClick.exe Task: {55E4AC30-B974-4C21-BD4F-E7A40712C31F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3813596177-1276424280-2619024677-1000Core => C:\Users\gundi\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {638764FF-409C-41C9-88B6-8D72E6A31983} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-21] (Google Inc.) Task: {63F6E6A7-4290-4845-BBBB-F0ED798FB6A2} - System32\Tasks\{20B5A60C-7771-4AB2-A801-66932EF41167} => C:\Program Files\Skype\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {72504F05-9EE4-4D80-B59C-94694196A304} - System32\Tasks\Plus-HD-1.2-firefoxinstaller => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-firefoxinstaller.exe <==== ATTENTION Task: {762D8C1B-FCB1-42F6-BFBC-C67867CD872F} - System32\Tasks\Plus-HD-1.2-enabler => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-enabler.exe <==== ATTENTION Task: {898885D5-D91A-4A4D-9267-7E8F9C59DCA5} - System32\Tasks\Plus-HD-1.2-codedownloader => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-codedownloader.exe <==== ATTENTION Task: {983BF916-345A-4B5C-9351-64B56A82F8F4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-21] (Google Inc.) Task: {9A07FDFF-02BB-44BB-B547-BE47A8623094} - System32\Tasks\EPUpdater => C:\Users\gundi\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe <==== ATTENTION Task: {9DC09BC8-90F4-450E-A7E6-EC8ED992A202} - System32\Tasks\SpeedUpMyPC Startup => C:\Program Files\Uniblue\SpeedUpMyPC\speedupmypc.exe Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries Task: {D973E425-2C1B-40C9-9B48-B9C4F41806B7} - System32\Tasks\SpeedUpMyPC Maintenance => C:\Program Files\Uniblue\SpeedUpMyPC\speedupmypc.exe Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] () Task: {EE138026-69C2-45ED-8A8C-99F9ED448BBA} - System32\Tasks\BrowserProtect => Sc.exe start BrowserProtect <==== ATTENTION Task: {F3EDA4C2-91C9-4BB3-9314-3777B27627F8} - System32\Tasks\PC SpeedUp Service Deactivator => C:\Program Files\PC Beschleunigen\PCSUSD.exe <==== ATTENTION Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-02-09 23:04 - 2013-03-09 17:56 - 00397704 _____ () C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll 2013-12-04 19:23 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-04 19:23 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-04 19:23 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll 2013-12-04 19:23 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-04 19:23 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libegl.dll 2009-07-27 13:17 - 2008-09-16 19:18 - 00132608 _____ () C:\Program Files\WinRAR\rarext.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\gundi\Documents\clip0001.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0002.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0003.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0004.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0005.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0006.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0007.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0008.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0009.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0010.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0014.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0015.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0018.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0019.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0020.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0021.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0022.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0023.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0024.avi:TOC.WMV ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: 802.11b/g/n USB Wireless Network Adapter Description: 802.11b/g/n USB Wireless Network Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Service: netr28u Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (12/31/2013 02:20:59 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 02:14:55 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 01:55:06 PM) (Source: Windows Installer 3.1) (User: ) Description: WindowsFür diesen Befehl ist nicht genügend Speicher verfügbar. Error: (12/31/2013 01:54:01 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {511fbf08-20ae-46ed-8c2b-4415c0752b80} Error: (12/31/2013 11:58:55 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 10:44:40 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 05:05:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 11:50:48 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 09:13:43 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2013 11:28:43 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (12/31/2013 02:20:59 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/31/2013 02:14:55 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/31/2013 11:58:59 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/31/2013 10:44:40 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/30/2013 05:05:51 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/30/2013 11:50:48 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/30/2013 09:13:44 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/29/2013 11:28:44 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/29/2013 01:56:52 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/29/2013 10:18:49 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Microsoft Office Sessions: ========================= Error: (12/31/2013 02:20:59 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 02:14:55 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 01:55:06 PM) (Source: Windows Installer 3.1)(User: ) Description: WindowsFür diesen Befehl ist nicht genügend Speicher verfügbar. Error: (12/31/2013 01:54:01 PM) (Source: VSS)(User: ) Description: 0x80070005 Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {511fbf08-20ae-46ed-8c2b-4415c0752b80} Error: (12/31/2013 11:58:55 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 10:44:40 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 05:05:51 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 11:50:48 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 09:13:43 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2013 11:28:43 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 3325.27 MB Available physical RAM: 1771.3 MB Total Pagefile: 6870.36 MB Available Pagefile: 4922.81 MB Total Virtual: 2047.88 MB Available Virtual: 1897.96 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:911.51 GB) (Free:731.74 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:19.99 GB) (Free:8.92 GB) FAT32 Drive i: () (Removable) (Total:3.69 GB) (Free:0.43 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: F98D6E74) Partition 1: (Active) - (Size=912 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended) ======================================================== Disk: 4 (Size: 4 GB) (Disk ID: 00000000) Partition 1: (Not Active) - (Size=4 GB) - (Type=0B) ==================== End Of Log ============================ uch hoffe sie können was damit anfangen und mir helfen............. |
31.12.2013, 15:18 | #2 |
/// the machine /// TB-Ausbilder | hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom hi,
__________________So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Downloade dir bitte Shortcut Cleaner (by Grinler) auf deinen Desktop.
und ein frisches FRST log bitte.
__________________ |
31.12.2013, 16:17 | #3 |
| hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom soo hier schonmal das logfile ....
__________________Malwarebytes Anti-Malware (Test) 1.75.0.1300 Malwarebytes : Free Anti-Malware Datenbank Version: v2013.12.31.04 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 gundi :: GUNDI-PC [Administrator] Schutz: Aktiviert 31.12.2013 15:32:13 mbam-log-2013-12-31 (15-32-13).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 230703 Laufzeit: 8 Minute(n), 34 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 1 C:\Users\gundi\AppData\Roaming\newnext.me\nengine.dll (PUP.Optional.NextLive.A) -> Löschen bei Neustart. Infizierte Registrierungsschlüssel: 18 HKCR\AppID\{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4} (PUP.Optional.Iminent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} (PUP.Optional.Wajam.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} (PUP.Optional.Datamngr.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} (PUP.Optional.Iminent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} (PUP.Optional.Iminent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\1ClickDownload (PUP.Optional.1ClickDownload.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\BabSolution\Updater (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\DomaIQ (PUP.Optional.DomaIQ.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\nationzoomSoftware (PUP.Optional.NationZoom.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo (PUP.Optional.Elex.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Google\Chrome\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk (PUP.Optional.Gophoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Speedchecker Limited\PC Speed Up (PUP.Optional.PCSpeedUp.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\Software\Iminent (PUP.Optional.Iminent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 4 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NextLive (PUP.Optional.NextLive.A) -> Daten: C:\Windows\system32\rundll32.exe "C:\Users\gundi\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {52B8E72F-8D4F-11E1-A65D-00242178B865} -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs|bProtectTabs (PUP.Optional.BrowserProtect.A) -> Daten: Delta Search -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {52B8E72F-8D4F-11E1-A65D-00242178B865} -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 11 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Page (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=a4353f1e-ff9e-4eb2-9a56-babf7f482139&searchtype=ds&q={searchTerms}&installDate=23/05/2013) Gut: (Google) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL (PUP.Optional.NationZoom.A) -> Bösartig: (Nation Zoom) Gut: (Google) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=a4353f1e-ff9e-4eb2-9a56-babf7f482139&searchtype=ds&q={searchTerms}&installDate=23/05/2013) Gut: (Google) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=a4353f1e-ff9e-4eb2-9a56-babf7f482139&searchtype=ds&q={searchTerms}&installDate=23/05/2013) Gut: (Google) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|SearchAssistant (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=a4353f1e-ff9e-4eb2-9a56-babf7f482139&searchtype=ds&q={searchTerms}&installDate=23/05/2013) Gut: (Google) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command| (PUP.Optional.NationZoom.A) -> Bösartig: (C:\Program Files\Internet Explorer\iexplore.exe Nation Zoom) Gut: (iexplore.exe) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.NationZoom.A) -> Bösartig: (Nation Zoom) Gut: (Google) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL (PUP.Optional.NationZoom.A) -> Bösartig: (hxxp://www.nationzoom.com/web/?type=ds&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX&q={searchTerms}) Gut: (Google) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|DefaultScope (PUP.Optional.Qone8) -> Bösartig: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}) Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\Software\Microsoft\Internet Explorer\Main|Default_Page_URL (PUP.Optional.NationZoom.A) -> Bösartig: (Nation Zoom) Gut: (Google) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\Software\Microsoft\Internet Explorer\Main|Search Page (PUP.Optional.NationZoom) -> Bösartig: (hxxp://www.nationzoom.com/web/?type=ds&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX&q={searchTerms}) Gut: (Google) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 9 C:\Users\gundi\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com (PUP.Optional.HDVidCodec.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Gophoto.it (PUP.Optional.Gophoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\IminentToolbar (PUP.Optional.Iminent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\OpenCandy\FF119A510BA04D7D8B983DFA79781D34 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\hdvidcodec.com (PUP.Optional.HDVidCodec.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\newnext.me (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\newnext.me\cache (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 24 C:\ProgramData\WPM\wprotectmanager.exe (PUP.Optional.WpManager.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Local\Temp\parent.txt (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Local\Temp\6b54163d-0843-42f2-8d38-5eeb214f3b1b0\parent.txt (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Local\Temp\fullpackage_temp1388494406\Baofeng.exe (PUP.Optional.NationZoom.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Local\Temp\fullpackage_temp1388494406\tmp\NewGdp.exe (PUP.Optional.WpManager.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\Downloads\codec_pack_660967_ch.exe (PUP.BundleInstaller.DW) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\Downloads\cottageawp.exe (PUP.Optional.InstallIQ) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\Downloads\iMeshSetup-r1487-w-bc.exe (PUP.Optional.Bandoo.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\Downloads\Player Setup (1).exe (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\Downloads\Player Setup.exe (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\Downloads\Setup.exe (PUP.Optional.iBryte) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\Downloads\setup_codec_3dx.exe (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\Downloads\sweetimsetup.exe (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com\HDVidCodec.lnk (PUP.Optional.HDVidCodec.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com\Uninstall.lnk (PUP.Optional.HDVidCodec.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Gophoto.it\gophotoit14.crx (PUP.Optional.Gophoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\newnext.me\nengine.dll (PUP.Optional.NextLive.A) -> Löschen bei Neustart. C:\Users\gundi\AppData\Roaming\OpenCandy\FF119A510BA04D7D8B983DFA79781D34\2787.ico (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\OpenCandy\FF119A510BA04D7D8B983DFA79781D34\EBB77268-338F-4C6A-8590-AD88FED26F4A (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\OpenCandy\FF119A510BA04D7D8B983DFA79781D34\Installer.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\OpenCandy\FF119A510BA04D7D8B983DFA79781D34\OCBrowserHelper_1.0.3.85.dll (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\newnext.me\nengine.cookie (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\gundi\AppData\Roaming\newnext.me\cache\spark.bin (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) hi es tut mir wrklich leid aber das in son kleines fenster amchen kapier ich nicht sorry hier der bericht vom adwcleanerAdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 31/12/2013 um 15:51:27 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : gundi - GUNDI-PC # Gestartet von : C:\Users\gundi\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Ask Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\boost_interprocess Ordner Gelöscht : C:\ProgramData\Browser Manager Ordner Gelöscht : C:\ProgramData\Tarma Installer Ordner Gelöscht : C:\ProgramData\WPM Ordner Gelöscht : C:\Program Files\iMesh Applications Ordner Gelöscht : C:\Program Files\Movie2KDownloader.com Ordner Gelöscht : C:\Program Files\MyPC Backup Ordner Gelöscht : C:\Users\gundi\AppData\Local\Ilivid Player Ordner Gelöscht : C:\Users\gundi\AppData\Local\Kiwee Toolbar Ordner Gelöscht : C:\Users\gundi\AppData\Local\lollipop Ordner Gelöscht : C:\Users\gundi\AppData\Local\Mobogenie Ordner Gelöscht : C:\Users\gundi\AppData\Local\PutLockerDownloader Ordner Gelöscht : C:\Users\gundi\AppData\Local\Wajam Ordner Gelöscht : C:\Users\gundi\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\gundi\AppData\LocalLow\IncrediMail_MediaBar_2 Ordner Gelöscht : C:\Users\gundi\AppData\LocalLow\Kiwee Toolbar Ordner Gelöscht : C:\Users\gundi\AppData\Roaming\Tlapia Ordner Gelöscht : C:\Users\gundi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movie2KDownloader.com Ordner Gelöscht : C:\Users\gundi\Documents\Mobogenie Ordner Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Conduit Ordner Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\ConduitEngine Ordner Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\engine@conduit.com Ordner Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\hdvc@hdvc.com Ordner Gelöscht : C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml Ordner Gelöscht : C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\gophoto@gophoto.it.xpi Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\hdvc@hdvc.com.xpi Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\m2k@m2kdownloader.com.xpi Datei Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\lollipop.lnk Datei Gelöscht : C:\Users\gundi\Desktop\HDVidCodec.lnk Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\bProtector_extensions.rdf Datei Gelöscht : C:\Program Files\Mozilla Firefox\Components\AskSearch.js Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\invalidprefs.js Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\Askcom.xml Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\Babylon.xml Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\delta.xml Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\MyStart Search.xml Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\Search_Results.xml Datei Gelöscht : C:\Program Files\Mozilla Firefox\searchplugins\Search_Results.xml Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\SweetIm.xml Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\Web Search.xml Datei Gelöscht : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\user.js Datei Gelöscht : C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx Datei Gelöscht : C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage Datei Gelöscht : C:\Windows\System32\Tasks\BrowserProtect Datei Gelöscht : C:\Windows\System32\Tasks\EPUpdater Datei Gelöscht : C:\Windows\System32\Tasks\PC SpeedUp Service Deactivator Datei Gelöscht : C:\Windows\System32\Tasks\Re-markit Update Datei Gelöscht : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\gundi\Desktop\Google Chrome.lnk Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\gundi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Verknüpfung Desinfiziert : C:\Users\gundi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Verknüpfung Desinfiziert : C:\Users\gundi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\gundi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\kpkbnefaikfaeadgidhpoanckoiaheli [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EE138026-69C2-45ED-8A8C-99F9ED448BBA} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9A07FDFF-02BB-44BB-B547-BE47A8623094} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3EDA4C2-91C9-4BB3-9314-3777B27627F8} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A6D5DCD-BE66-4DFE-9AF7-5A51F0D196F0} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{424D1112-4183-4C48-92FF-4FF9F8DCC871} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9DC09BC8-90F4-450E-A7E6-EC8ED992A202} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D973E425-2C1B-40C9-9B48-B9C4F41806B7} Schlüssel Gelöscht : HKCU\Software\Classes\Applications\lollipop.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\InstallerControl.InstallerObject Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\InstallerControl.InstallerObject.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Movie2KDownloader Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4260E0CC-0F75-462E-88A3-1E05C248BF4C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{40C3CC16-7269-4B32-9531-17F2950FB06F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4260E0CC-0F75-462E-88A3-1E05C248BF4C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{377E5D4D-77E5-476A-8716-7E70A9272DA0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{40C3CC16-7269-4B32-9531-17F2950FB06F}] Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command Schlüssel Gelöscht : HKCU\Software\BabSolution Schlüssel Gelöscht : HKCU\Software\ilivid Schlüssel Gelöscht : HKCU\Software\IM Schlüssel Gelöscht : HKCU\Software\lollipop Schlüssel Gelöscht : HKCU\Software\SmartBar Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\IncrediMail_MediaBar_2 Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\Freeze.com Schlüssel Gelöscht : HKLM\Software\iLividSRTB Schlüssel Gelöscht : HKLM\Software\Speedchecker Limited Schlüssel Gelöscht : HKLM\Software\supWPM Schlüssel Gelöscht : HKLM\Software\Tarma Installer Schlüssel Gelöscht : HKLM\Software\Uniblue Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\1ClickDownload Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\IMBoosterARP Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Iminent Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~1\search~1\datamngr\mgrldr.dll Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - data\browserprotect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8} Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F2E0D3DD9E5E4B74CA43BCE77815E287 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7 ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16526 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default] -\\ Mozilla Firefox v [ Datei : C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\prefs.js ] Zeile gelöscht : user_pref("CT2319825.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Zeile gelöscht : user_pref("CT2319825.CTID", "CT2319825"); Zeile gelöscht : user_pref("CT2319825.CurrentServerDate", "12-12-2010"); Zeile gelöscht : user_pref("CT2319825.DialogsAlignMode", "LTR"); Zeile gelöscht : user_pref("CT2319825.DownloadReferralCookieData", ""); Zeile gelöscht : user_pref("CT2319825.EMailNotifierPollDate", "Thu Sep 30 2010 16:47:58 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.EnableSearchHistory", false); Zeile gelöscht : user_pref("CT2319825.EnableSearchSuggest", false); Zeile gelöscht : user_pref("CT2319825.FeedPollDate11908299", "Thu Sep 30 2010 16:38:58 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.FirstServerDate", "30-9-2010"); Zeile gelöscht : user_pref("CT2319825.FirstTime", true); Zeile gelöscht : user_pref("CT2319825.FirstTimeFF3", true); Zeile gelöscht : user_pref("CT2319825.FirstTimeSettingsDone", true); Zeile gelöscht : user_pref("CT2319825.FixPageNotFoundErrors", true); Zeile gelöscht : user_pref("CT2319825.GroupingServerCheckInterval", 1440); Zeile gelöscht : user_pref("CT2319825.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Zeile gelöscht : user_pref("CT2319825.Initialize", true); Zeile gelöscht : user_pref("CT2319825.InitializeCommonPrefs", true); Zeile gelöscht : user_pref("CT2319825.InstallationAndCookieDataSentCount", 1); Zeile gelöscht : user_pref("CT2319825.InstalledDate", "Thu Sep 30 2010 14:43:52 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.InvalidateCache", false); Zeile gelöscht : user_pref("CT2319825.IsGrouping", false); Zeile gelöscht : user_pref("CT2319825.IsMulticommunity", false); Zeile gelöscht : user_pref("CT2319825.IsOpenThankYouPage", false); Zeile gelöscht : user_pref("CT2319825.IsOpenUninstallPage", true); Zeile gelöscht : user_pref("CT2319825.LanguagePackLastCheckTime", "Sun Dec 12 2010 19:42:23 GMT+0100"); Zeile gelöscht : user_pref("CT2319825.LanguagePackReloadIntervalMM", 1440); Zeile gelöscht : user_pref("CT2319825.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx"); Zeile gelöscht : user_pref("CT2319825.LastLogin_2.5.8.6", "Thu Sep 30 2010 14:43:53 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.LastLogin_2.7.2.0", "Sun Dec 12 2010 19:42:22 GMT+0100"); Zeile gelöscht : user_pref("CT2319825.LatestVersion", "2.7.2.0"); Zeile gelöscht : user_pref("CT2319825.Locale", "de"); Zeile gelöscht : user_pref("CT2319825.LoginCache", 4); Zeile gelöscht : user_pref("CT2319825.MCDetectTooltipHeight", "83"); Zeile gelöscht : user_pref("CT2319825.MCDetectTooltipShow", false); Zeile gelöscht : user_pref("CT2319825.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Zeile gelöscht : user_pref("CT2319825.MCDetectTooltipWidth", "295"); Zeile gelöscht : user_pref("CT2319825.RadioIsPodcast", false); Zeile gelöscht : user_pref("CT2319825.RadioLastCheckTime", "Thu Sep 30 2010 14:43:53 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.RadioLastUpdateIPServer", "3"); Zeile gelöscht : user_pref("CT2319825.RadioLastUpdateServer", "129224641269630000"); Zeile gelöscht : user_pref("CT2319825.RadioMediaID", "11949532"); Zeile gelöscht : user_pref("CT2319825.RadioMediaType", "Media Player"); Zeile gelöscht : user_pref("CT2319825.RadioMenuSelectedID", "EBRadioMenu_CT231982511949532"); Zeile gelöscht : user_pref("CT2319825.RadioStationName", "1Live"); Zeile gelöscht : user_pref("CT2319825.RadioStationURL", "hxxp://gffstream.ic.llnwd.net/stream/gffstream_stream_wdr_einslive_a"); Zeile gelöscht : user_pref("CT2319825.SHRINK_TOOLBAR", 0); Zeile gelöscht : user_pref("CT2319825.SavedHomepage", "www.habbo.de"); Zeile gelöscht : user_pref("CT2319825.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2319825&octid=EB_ORIGINAL_CTID&SearchSource=1"); Zeile gelöscht : user_pref("CT2319825.SearchFromAddressBarIsInit", true); Zeile gelöscht : user_pref("CT2319825.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&q="); Zeile gelöscht : user_pref("CT2319825.SearchInNewTabEnabled", true); Zeile gelöscht : user_pref("CT2319825.SearchInNewTabIntervalMM", 1440); Zeile gelöscht : user_pref("CT2319825.SearchInNewTabLastCheckTime", "Sun Dec 12 2010 19:42:22 GMT+0100"); Zeile gelöscht : user_pref("CT2319825.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID"); Zeile gelöscht : user_pref("CT2319825.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID"); Zeile gelöscht : user_pref("CT2319825.SettingsCheckIntervalMin", 120); Zeile gelöscht : user_pref("CT2319825.SettingsLastCheckTime", "Sun Dec 12 2010 19:42:21 GMT+0100"); Zeile gelöscht : user_pref("CT2319825.SettingsLastUpdate", "1291980849"); Zeile gelöscht : user_pref("CT2319825.ThirdPartyComponentsInterval", 504); Zeile gelöscht : user_pref("CT2319825.ThirdPartyComponentsLastCheck", "Sun Dec 12 2010 19:42:21 GMT+0100"); Zeile gelöscht : user_pref("CT2319825.ThirdPartyComponentsLastUpdate", "1255348257"); Zeile gelöscht : user_pref("CT2319825.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112"); Zeile gelöscht : user_pref("CT2319825.Uninstall", true); Zeile gelöscht : user_pref("CT2319825.UserID", "UN76872180917024523"); Zeile gelöscht : user_pref("CT2319825.ValidationData_Toolbar", 2); Zeile gelöscht : user_pref("CT2319825.WeatherNetwork", ""); Zeile gelöscht : user_pref("CT2319825.WeatherPollDate", "Thu Sep 30 2010 16:38:59 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.WeatherUnit", "C"); Zeile gelöscht : user_pref("CT2319825.alertChannelId", "715912"); Zeile gelöscht : user_pref("CT2319825.backendstorage.id", "32343630303934"); Zeile gelöscht : user_pref("CT2319825.clientLogIsEnabled", false); Zeile gelöscht : user_pref("CT2319825.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent"); Zeile gelöscht : user_pref("CT2319825.components.1000034", false); Zeile gelöscht : user_pref("CT2319825.components.1000082", false); Zeile gelöscht : user_pref("CT2319825.components.1000234", false); Zeile gelöscht : user_pref("CT2319825.components.129136390572498374", false); Zeile gelöscht : user_pref("CT2319825.myStuffEnabled", true); Zeile gelöscht : user_pref("CT2319825.myStuffPublihserMinWidth", 400); Zeile gelöscht : user_pref("CT2319825.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID"); Zeile gelöscht : user_pref("CT2319825.myStuffServiceIntervalMM", 1440); Zeile gelöscht : user_pref("CT2319825.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT"); Zeile gelöscht : user_pref("CT2319825.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation"); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1235508/1231181/DE", "\"0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2843456", "\"0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=de-de", "hrY3aRo68pvVAKwJTjMFmA=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=de-de", "poKjTfHs0NrVUIalKI8jyg=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=de-de", "QmycQXJXVyFVAzIiNllWhQ=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=de-de", "ZdrYrsEQox0wVf3yXX8zTQ=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"803651ba7facb1:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"807dc126dd28cc1:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"634289840782570000\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000"); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=1/11/2011 5:25:10 PM", "634303635100000000"); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/2011 11:17:11 AM", "634356118310000000"); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2843456/CT2843456", "\"1295273672\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"634310612473900000\""); Zeile gelöscht : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine"); Zeile gelöscht : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com"); Zeile gelöscht : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine"); Zeile gelöscht : user_pref("CommunityToolbar.IsEngineShown", true); Zeile gelöscht : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Zeile gelöscht : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine"); Zeile gelöscht : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com"); Zeile gelöscht : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine"); Zeile gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q="); Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT2319825,ConduitEngine"); Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT2319825"); Zeile gelöscht : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon May 16 2011 23:04:40 GMT+0200"); Zeile gelöscht : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440); Zeile gelöscht : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Jun 29 2011 13:57:08 GMT+0200"); Zeile gelöscht : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Zeile gelöscht : user_pref("CommunityToolbar.alert.locale", "en"); Zeile gelöscht : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Zeile gelöscht : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Tue Jun 28 2011 18:40:54 GMT+0200"); Zeile gelöscht : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559"); Zeile gelöscht : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Zeile gelöscht : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Zeile gelöscht : user_pref("CommunityToolbar.alert.showTrayIcon", false); Zeile gelöscht : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Zeile gelöscht : user_pref("CommunityToolbar.alert.userId", "8e386215-d500-4b24-86f9-b3e953588452"); Zeile gelöscht : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Mon Feb 14 2011 10:17:35 GMT+0100"); Zeile gelöscht : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Zeile gelöscht : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Zeile gelöscht : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2319825"); Zeile gelöscht : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Sat Jun 18 2011 23:27:24 GMT+0200"); Zeile gelöscht : user_pref("ConduitEngine.CTID", "ConduitEngine"); Zeile gelöscht : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Tue Jun 28 2011 21:46:45 GMT+0200"); Zeile gelöscht : user_pref("ConduitEngine.FirstServerDate", "05/17/2011 00"); Zeile gelöscht : user_pref("ConduitEngine.FirstTime", true); Zeile gelöscht : user_pref("ConduitEngine.FirstTimeFF3", true); Zeile gelöscht : user_pref("ConduitEngine.HasUserGlobalKeys", true); Zeile gelöscht : user_pref("ConduitEngine.Initialize", true); Zeile gelöscht : user_pref("ConduitEngine.InitializeCommonPrefs", true); Zeile gelöscht : user_pref("ConduitEngine.InstalledDate", "Mon May 16 2011 23:04:40 GMT+0200"); Zeile gelöscht : user_pref("ConduitEngine.IsMulticommunity", false); Zeile gelöscht : user_pref("ConduitEngine.IsOpenThankYouPage", false); Zeile gelöscht : user_pref("ConduitEngine.IsOpenUninstallPage", true); Zeile gelöscht : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Wed Jun 29 2011 13:57:01 GMT+0200"); Zeile gelöscht : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Wed Jun 29 2011 13:57:01 GMT+0200"); Zeile gelöscht : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true); Zeile gelöscht : user_pref("ConduitEngine.SettingsLastCheckTime", "Wed Jun 29 2011 13:57:01 GMT+0200"); Zeile gelöscht : user_pref("ConduitEngine.UserID", "UN66899231735818546"); Zeile gelöscht : user_pref("ConduitEngine.componentAlertEnabled", false); Zeile gelöscht : user_pref("ConduitEngine.engineLocale", "de"); Zeile gelöscht : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Wed Jun 29 2011 13:57:02 GMT+0200"); Zeile gelöscht : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Wed Jun 29 2011 13:57:01 GMT+0200"); Zeile gelöscht : user_pref("ConduitEngine.initDone", true); Zeile gelöscht : user_pref("ConduitEngine.isAppTrackingManagerOn", true); Zeile gelöscht : user_pref("browser.search.defaultthis.engineName", "Winload Customized Web Search"); Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=3&q={searchTerms}"); Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=eb46a027-df3e-41af-ad1e-c9ae5d3a9549&affid=111585&searchtype=ds&babsrc=lnkry&q="); Zeile gelöscht : user_pref("extensions.delta.admin", false); Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst"); Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.delta.dfltLng", "en"); Zeile gelöscht : user_pref("extensions.delta.excTlbr", false); Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true); Zeile gelöscht : user_pref("extensions.delta.id", "cedae39000000000000002242178b865"); Zeile gelöscht : user_pref("extensions.delta.instlDay", "15848"); Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst"); Zeile gelöscht : user_pref("extensions.delta.newTab", false); Zeile gelöscht : user_pref("extensions.delta.prdct", "delta"); Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta"); Zeile gelöscht : user_pref("extensions.delta.rvrt", "false"); Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base"); Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", ""); Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.21.5"); Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.21.518:36:33"); Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.21.5"); Zeile gelöscht : user_pref("extensions.delta_i.babExt", ""); Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=119781&tt=gc_"); Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss"); Zeile gelöscht : user_pref("extensions.enabledItems", "helperbar@helperbar.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.2.1,{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.[...] Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false); Zeile gelöscht : user_pref("extensions.snipit.askTbInstalled", true); [ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\g3rmhp88.default\prefs.js ] -\\ Google Chrome v31.0.1650.63 [ Datei : C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht : homepage ************************* AdwCleaner[R0].txt - [35492 octets] - [31/12/2013 15:49:51] AdwCleaner[S0].txt - [34362 octets] - [31/12/2013 15:51:27] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [34423 octets] ########## jetzt das junkwareJRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows Vista (TM) Home Premium x86 Ran by gundi on 31.12.2013 at 16:01:14,59 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3813596177-1276424280-2619024677-1000\Software\sweetim ~~~ Files Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-1.2-chromeinstaller Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-1.2-codedownloader Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-1.2-enabler Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-1.2-firefoxinstaller Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-1.2-updater ~~~ Folders Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin" Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{02079B94-8881-4ECA-966B-30BCFEEA0678} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{0419939B-A565-44AA-8EB3-5A029CD69A96} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{0D7E27E3-CA46-429E-A982-85BEB4FAC509} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{0DCEDCFF-4B8F-4793-AA73-43C5220BD9E4} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{109A494E-DEC3-499C-9044-EFBC326D9A07} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{15E60ED4-0729-4921-989B-3A795ABBE834} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{1ADC8128-56EC-4F3D-A63D-0CE63104CE87} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{26596F3C-AA01-47D2-B04F-F26D4AD614C0} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{2B277EF5-A1CF-4E2F-BD20-01CA0734B3EF} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{2C2509E1-73BA-4DF9-BD97-5C734181B0B6} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{33EF0547-F160-4E07-AD21-4FDD01C53BD9} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{37A19C65-49A8-47D7-8F7A-B40942CAB22C} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{3C74D3E8-0D5F-45C3-9FE2-597535840763} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{4E23A270-BA72-4C56-9A8C-0867C7976FAF} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{51C5813C-441C-4415-996A-2BA267C19BEA} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{6D0A07E1-DBA2-416B-9EF9-0B7688C699B0} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{72EB327F-C8EE-4644-8A50-CFEF14E15089} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{75225580-8A62-4BEE-B6D7-9D9253A6543C} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{90A28FC0-3FE3-4514-BA7C-733C8B0879F4} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{93C89D5C-2859-499D-8E3E-2B29DB41221C} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{99154F9B-EE50-493E-B851-AF8256CDBF43} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{A34E03E0-6C7B-4862-99B6-ECFA5C0AEE16} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{A573BF09-A8C6-478A-BFF9-47DD6F918FE5} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{A9B05920-6041-4C55-9888-03D7C4ED2592} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{A9E27430-5F5E-4828-A6F0-A3F1279F9751} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{AADB7031-4379-41AD-BB44-707CDEEF279E} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{ACD8A2F7-0D9E-4706-BBE4-E3F4D10978F1} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{AEEF21E2-FFF4-413B-9A41-C80236AC6F67} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{B1EF8E20-6FD8-4C44-953B-723EF371E757} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{B73B2C62-6513-44E0-BAEA-0A16F4046710} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{B89974E8-DFD3-4A86-BDE8-37F8DFC9DF65} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{C002402A-5715-423D-A8C9-18D38B21616B} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{C7B85D4F-2E7E-410C-AF1C-B039DCF2F6DC} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{D8424A00-2DC5-45CF-9DD6-CEAF8374F9FB} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{DDE7030A-7EC5-462B-B212-E712AAA2F951} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{DE5AA92A-FFD5-4755-AB87-389C7C1A6D06} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{E183A136-AC48-467D-8B46-DAC187F9E2F1} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{ED31B46B-DD8D-401D-A81A-A13F0CB8B1B6} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{F5928C3C-59B9-481A-B876-234D3F1906A0} Successfully deleted: [Empty Folder] C:\Users\gundi\appdata\local\{FB6D8AEF-D04F-4ADF-8EBD-BCA17D19B09F} ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 31.12.2013 at 16:04:55,30 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ zbd zu letzt shortcut Shortcut Cleaner 1.2.6 by Lawrence Abrams (Grinler) Bleeping Computer - Technical Support and Computer Help Copyright 2008-2013 BleepingComputer.com More Information about Shortcut Cleaner can be found at this link: Shortcut Cleaner Download Windows Version: Windows Vista (TM) Home Premium Service Pack 2 Program started at: 12/31/2013 04:07:33 PM. Scanning for registry hijacks: * No issues found in the Registry. Searching for Hijacked Shortcuts: Searching C:\Users\gundi\AppData\Roaming\Microsoft\Windows\Start Menu\ Searching C:\ProgramData\Microsoft\Windows\Start Menu\ Searching C:\Users\gundi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ Searching C:\Users\Public\Desktop\ Searching C:\Users\gundi\Desktop 0 bad shortcuts found. Program finished at: 12/31/2013 04:07:36 PM Execution time: 0 hours(s), 0 minute(s), and 2 seconds(s) sooo es ist alles beim alten..vielen dank was sagen sie zu den berichten alles in ordnung?...kann ich die gedownloadeten sachen wieder entfernen oder sollen die drauf bleiben??? ich wünsche einen guten rutsch |
01.01.2014, 13:24 | #4 |
/// the machine /// TB-Ausbilder | hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom Gleich, erst noch Kontrollscans ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.01.2014, 13:07 | #5 |
| hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=9e18d407626ba14ea5a8bdb49fb12425 # engine=16484 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-02 12:02:08 # local_time=2014-01-02 01:02:08 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=1799 16775165 100 97 14412 159335433 7179 0 # compatibility_mode=5892 16776574 100 100 28363102 226196856 0 0 # scanned=161893 # found=0 # cleaned=0 # scan_time=10604 so dann der rest ^^ Results of screen317's Security Check version 0.99.77 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java 7 Update 45 Adobe Flash Player 11.9.900.170 Adobe Reader 9 Adobe Reader out of Date! Adobe Reader 10.1.8 Adobe Reader out of Date! Google Chrome 31.0.1650.57 Google Chrome 31.0.1650.63 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |
03.01.2014, 09:58 | #6 |
/// the machine /// TB-Ausbilder | hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom Frisches FRST log fehlt
__________________ --> hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom |
04.01.2014, 19:06 | #7 |
| hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom was isn das?? hihi aaaaaaaaaah ok das meinst du hier ...... FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-01-2014 Ran by gundi (administrator) on GUNDI-PC on 04-01-2014 19:03:44 Running from C:\Users\gundi\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Windows\System32\PSIService.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Tlapia) C:\Program Files\sysTPL\sysTPLMonitor.exe (Tlapia) C:\Program Files\sysTPL\sysTPLService.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (cyberlink) C:\Program Files\Cyberlink\Shared files\brs.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe () C:\Windows\vsnpstd3.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Piriform Ltd) C:\Program Files\Defraggler\Defraggler.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\gundi\Downloads\FRST (1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [178712 2007-10-08] (Intel Corporation) HKLM\...\Run: [BDRegion] - C:\Program Files\Cyberlink\Shared files\brs.exe [75048 2010-03-13] (cyberlink) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6724128 2009-02-03] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-02-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [snpstd3] - C:\Windows\vsnpstd3.exe [827392 2006-09-19] () HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [NeroFilterCheck] - C:\Windows\System32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-12] (Avira Operations GmbH & Co. KG) HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll",DllRegisterServer HKCU\...\Run: [EPSON SX100 Series] - C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\Windows\TEMP\E_S88DD.tmp" /EF "HKCU" HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation) HKCU\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess? HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Gast\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) AppInit_DLLs: c:\docume~1\ settings\all users\application [ ] () ==================== Internet (Whitelisted) ==================== ProxyServer: http=127.0.0.1:8877;https=127.0.0.1:8877 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.facebook.de/ StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKLM - No Name - !{EEE6C35B-6118-11DC-9C72-001320C79847} - No File DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Windows\system32\npdeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: Microsoft .NET Framework Assistant - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "https://www.facebook.com/logout.php" CHR Plugin: (Shockwave Flash) - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll No File CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll No File CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll No File CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll No File CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Unity Player) - C:\Users\gundi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\gundi\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Google Wallet) - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR HKLM\...\Chrome\Extension: [lbbbdmbjkgojacipgefbifkiebpcdjhn] - C:\Program Files\Movie2KDownloader.com\m2kDownloader10.crx ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-12] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG) R2 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-17] (SEIKO EPSON CORPORATION) R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 sysTPLMonitor.exe; C:\Program Files\sysTPL\sysTPLMonitor.exe [395888 2013-11-27] (Tlapia) R2 sysTPLService.exe; C:\Program Files\sysTPL\sysTPLService.exe [394352 2013-11-27] (Tlapia) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-12] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-12] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [554496 2007-09-21] (Ralink Technology Corp.) S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [506112 2006-11-20] (PixArt Imaging Inc.) S3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10252544 2007-03-27] (Sonix Co. Ltd.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-02-09] (Avira GmbH) R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl [87536 2010-03-13] (CyberLink Corp.) S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-04 19:03 - 2014-01-04 19:03 - 01064761 _____ (Farbar) C:\Users\gundi\Downloads\FRST (1).exe 2014-01-04 15:19 - 2014-01-04 15:19 - 00001706 _____ C:\Users\Public\Desktop\Defraggler.lnk 2014-01-04 15:19 - 2014-01-04 15:19 - 00000000 ____D C:\Program Files\Defraggler 2014-01-04 15:18 - 2014-01-04 15:18 - 04208656 _____ (Piriform Ltd) C:\Users\gundi\Downloads\dfsetup216.exe 2014-01-02 13:08 - 2014-01-02 13:08 - 00891200 _____ C:\Users\gundi\Downloads\SecurityCheck.exe 2014-01-02 10:03 - 2014-01-02 10:03 - 02347384 _____ (ESET) C:\Users\gundi\Downloads\esetsmartinstaller_enu.exe 2013-12-31 16:07 - 2013-12-31 16:07 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\gundi\Downloads\sc-cleaner.exe 2013-12-31 16:07 - 2013-12-31 16:07 - 00001814 _____ C:\sc-cleaner.txt 2013-12-31 16:04 - 2013-12-31 16:04 - 00005540 _____ C:\Users\gundi\Desktop\JRT.txt 2013-12-31 16:01 - 2013-12-31 16:01 - 00000000 ____D C:\Windows\ERUNT 2013-12-31 16:00 - 2013-12-31 16:00 - 01034531 _____ (Thisisu) C:\Users\gundi\Downloads\JRT.exe 2013-12-31 15:31 - 2014-01-01 16:48 - 00000000 ____D C:\AdwCleaner 2013-12-31 15:31 - 2013-12-31 15:31 - 01233962 _____ C:\Users\gundi\Downloads\adwcleaner.exe 2013-12-31 15:31 - 2013-12-31 15:31 - 00000000 ____D C:\Users\gundi\AppData\Roaming\Malwarebytes 2013-12-31 15:30 - 2013-12-31 15:30 - 00000910 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-31 15:30 - 2013-12-31 15:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-12-31 15:30 - 2013-12-31 15:30 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-12-31 15:30 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-12-31 15:29 - 2013-12-31 15:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\gundi\Downloads\mbam-setup-1.75.0.1300.exe 2013-12-31 14:34 - 2014-01-04 19:03 - 00016673 _____ C:\Users\gundi\Downloads\FRST.txt 2013-12-31 14:33 - 2013-12-31 14:33 - 01064333 _____ (Farbar) C:\Users\gundi\Downloads\FRST.exe 2013-12-31 14:33 - 2013-12-31 14:33 - 00000000 ____D C:\FRST 2013-12-31 14:32 - 2013-12-31 14:32 - 00000615 _____ C:\Users\Public\Desktop\iMesh-Installation fortsetzen.lnk 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\genienext 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\cache 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\.android 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 _____ C:\Users\gundi\daemonprocess.txt 2013-12-27 14:34 - 2013-12-27 14:38 - 186446085 _____ C:\Users\gundi\Desktop\2127343972001_2854723499001_EV108893-KleineHaendeGrossePfoten-source-ST.mp4 2013-12-27 14:16 - 2013-12-27 14:28 - 901182774 _____ C:\Users\gundi\Desktop\2127343972001_2854993219001_EV114583-SophieUndShiba-source-ST.mp4 2013-12-11 12:37 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-11 12:37 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-11 12:37 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-11 12:37 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-11 12:37 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-11 12:37 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-11 12:37 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 12:37 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-11 12:37 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 12:37 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 12:37 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-11 12:37 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 12:37 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-11 12:37 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 12:37 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-11 12:37 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-11 10:48 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-12-11 10:48 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 10:48 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-11 10:48 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 10:48 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 10:48 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 10:48 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 10:48 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-11 10:48 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 10:48 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe ==================== One Month Modified Files and Folders ======= 2014-01-04 19:04 - 2013-12-31 14:34 - 00016673 _____ C:\Users\gundi\Downloads\FRST.txt 2014-01-04 19:03 - 2014-01-04 19:03 - 01064761 _____ (Farbar) C:\Users\gundi\Downloads\FRST (1).exe 2014-01-04 18:44 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-04 18:44 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-04 18:41 - 2012-06-25 11:43 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-04 18:27 - 2010-05-21 14:53 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-04 15:56 - 2011-10-13 13:50 - 00103115 _____ C:\Windows\WindowsUpdate.log 2014-01-04 15:19 - 2014-01-04 15:19 - 00001706 _____ C:\Users\Public\Desktop\Defraggler.lnk 2014-01-04 15:19 - 2014-01-04 15:19 - 00000000 ____D C:\Program Files\Defraggler 2014-01-04 15:18 - 2014-01-04 15:18 - 04208656 _____ (Piriform Ltd) C:\Users\gundi\Downloads\dfsetup216.exe 2014-01-04 14:44 - 2010-05-21 14:53 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-04 14:44 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-04 12:35 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-02 13:08 - 2014-01-02 13:08 - 00891200 _____ C:\Users\gundi\Downloads\SecurityCheck.exe 2014-01-02 11:45 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET 2014-01-02 10:03 - 2014-01-02 10:03 - 02347384 _____ (ESET) C:\Users\gundi\Downloads\esetsmartinstaller_enu.exe 2014-01-01 16:48 - 2013-12-31 15:31 - 00000000 ____D C:\AdwCleaner 2014-01-01 14:03 - 2006-11-02 11:33 - 01539286 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-31 16:07 - 2013-12-31 16:07 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\gundi\Downloads\sc-cleaner.exe 2013-12-31 16:07 - 2013-12-31 16:07 - 00001814 _____ C:\sc-cleaner.txt 2013-12-31 16:04 - 2013-12-31 16:04 - 00005540 _____ C:\Users\gundi\Desktop\JRT.txt 2013-12-31 16:01 - 2013-12-31 16:01 - 00000000 ____D C:\Windows\ERUNT 2013-12-31 16:00 - 2013-12-31 16:00 - 01034531 _____ (Thisisu) C:\Users\gundi\Downloads\JRT.exe 2013-12-31 15:53 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\LiveKernelReports 2013-12-31 15:51 - 2013-06-28 13:42 - 00000979 _____ C:\Users\gundi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-31 15:51 - 2012-10-03 13:05 - 00001079 _____ C:\Users\gundi\Desktop\Google Chrome.lnk 2013-12-31 15:31 - 2013-12-31 15:31 - 01233962 _____ C:\Users\gundi\Downloads\adwcleaner.exe 2013-12-31 15:31 - 2013-12-31 15:31 - 00000000 ____D C:\Users\gundi\AppData\Roaming\Malwarebytes 2013-12-31 15:30 - 2013-12-31 15:30 - 00000910 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-31 15:30 - 2013-12-31 15:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-12-31 15:30 - 2013-12-31 15:30 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-12-31 15:29 - 2013-12-31 15:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\gundi\Downloads\mbam-setup-1.75.0.1300.exe 2013-12-31 14:33 - 2013-12-31 14:33 - 01064333 _____ (Farbar) C:\Users\gundi\Downloads\FRST.exe 2013-12-31 14:33 - 2013-12-31 14:33 - 00000000 ____D C:\FRST 2013-12-31 14:32 - 2013-12-31 14:32 - 00000615 _____ C:\Users\Public\Desktop\iMesh-Installation fortsetzen.lnk 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\genienext 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\cache 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\.android 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 _____ C:\Users\gundi\daemonprocess.txt 2013-12-31 13:54 - 2009-06-06 12:46 - 00000000 ____D C:\Users\gundi 2013-12-29 13:09 - 2010-10-20 20:12 - 00000000 ____D C:\Windows\Minidump 2013-12-27 14:38 - 2013-12-27 14:34 - 186446085 _____ C:\Users\gundi\Desktop\2127343972001_2854723499001_EV108893-KleineHaendeGrossePfoten-source-ST.mp4 2013-12-27 14:28 - 2013-12-27 14:16 - 901182774 _____ C:\Users\gundi\Desktop\2127343972001_2854993219001_EV114583-SophieUndShiba-source-ST.mp4 2013-12-21 15:10 - 2009-06-08 14:06 - 00007408 _____ C:\Users\gundi\AppData\Roaming\wklnhst.dat 2013-12-12 13:12 - 2013-02-09 23:04 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-12 13:12 - 2013-02-09 23:04 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-11 19:41 - 2012-06-25 11:43 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-11 19:41 - 2011-08-12 21:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-11 15:43 - 2006-11-02 13:47 - 00398720 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-11 15:40 - 2009-04-02 14:28 - 00000000 ____D C:\Windows\system32\RTCOM 2013-12-11 12:40 - 2013-08-14 10:55 - 00000000 ____D C:\Windows\system32\MRT 2013-12-11 12:38 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe Some content of TEMP: ==================== C:\Users\gundi\AppData\Local\Temp\avgnt.exe C:\Users\gundi\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-04 14:51 ==================== End Of Log ============================ --- --- --- |
05.01.2014, 16:19 | #8 |
/// the machine /// TB-Ausbilder | hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom Adobe updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter AppInit_DLLs: c:\docume~1\ settings\all users\application [ ] () Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Falls Du Lob oder Kritik loswerden möchtest kannst Du das hier tun Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.01.2014, 15:18 | #9 |
| hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom sorry das tool hat irgentwie kein texr erstellt ich hab jetzt das ergebnis in das fast leere fenster reingetan... AppInit_DLLs: c:\docume~1\ settings\all users\application [ ] () FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-01-2014 Ran by gundi (administrator) on GUNDI-PC on 06-01-2014 15:13:21 Running from C:\Users\gundi\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Windows\System32\PSIService.exe (Tlapia) C:\Program Files\sysTPL\sysTPLMonitor.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Tlapia) C:\Program Files\sysTPL\sysTPLService.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (cyberlink) C:\Program Files\Cyberlink\Shared files\brs.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe () C:\Windows\vsnpstd3.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (cyberlink) C:\Program Files\Cyberlink\Shared files\brs.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe () C:\Windows\vsnpstd3.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_11_9_900_170_ActiveX.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\gundi\Downloads\FRST (2).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [178712 2007-10-08] (Intel Corporation) HKLM\...\Run: [BDRegion] - C:\Program Files\Cyberlink\Shared files\brs.exe [75048 2010-03-13] (cyberlink) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6724128 2009-02-03] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-02-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [snpstd3] - C:\Windows\vsnpstd3.exe [827392 2006-09-19] () HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [NeroFilterCheck] - C:\Windows\System32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-12] (Avira Operations GmbH & Co. KG) HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll",DllRegisterServer HKCU\...\Run: [EPSON SX100 Series] - C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\Windows\TEMP\E_S88DD.tmp" /EF "HKCU" HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation) HKCU\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess? HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) AppInit_DLLs: c:\docume~1\ settings\all users\application [ ] () ==================== Internet (Whitelisted) ==================== ProxyServer: http=127.0.0.1:8877;https=127.0.0.1:8877 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.facebook.de/ StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKLM - No Name - !{EEE6C35B-6118-11DC-9C72-001320C79847} - No File DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} MSN Games - Free Online Games DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Windows\system32\npdeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: Microsoft .NET Framework Assistant - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "https://www.facebook.com/logout.php" CHR Plugin: (Shockwave Flash) - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll No File CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll No File CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll No File CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll No File CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Unity Player) - C:\Users\gundi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\gundi\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Google Wallet) - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR HKLM\...\Chrome\Extension: [lbbbdmbjkgojacipgefbifkiebpcdjhn] - C:\Program Files\Movie2KDownloader.com\m2kDownloader10.crx ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-12] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG) R2 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-17] (SEIKO EPSON CORPORATION) R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 sysTPLMonitor.exe; C:\Program Files\sysTPL\sysTPLMonitor.exe [395888 2013-11-27] (Tlapia) R2 sysTPLService.exe; C:\Program Files\sysTPL\sysTPLService.exe [394352 2013-11-27] (Tlapia) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-12] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-12] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [554496 2007-09-21] (Ralink Technology Corp.) S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [506112 2006-11-20] (PixArt Imaging Inc.) S3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10252544 2007-03-27] (Sonix Co. Ltd.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-02-09] (Avira GmbH) R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl [87536 2010-03-13] (CyberLink Corp.) S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-06 15:13 - 2014-01-06 15:13 - 01064805 _____ (Farbar) C:\Users\gundi\Downloads\FRST (2).exe 2014-01-06 15:03 - 2014-01-06 15:03 - 00000064 _____ C:\Users\gundi\Desktop\Fixlist.txt 2014-01-06 14:56 - 2014-01-06 14:56 - 00000066 _____ C:\Users\Gast\Desktop\Fixlist.txt 2014-01-06 14:32 - 2014-01-06 14:32 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Malwarebytes 2014-01-06 14:30 - 2014-01-06 14:30 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Avira 2014-01-06 14:26 - 2014-01-06 14:26 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Adobe 2014-01-06 14:24 - 2014-01-06 14:24 - 00001967 _____ C:\Users\Gast\Desktop\Google Chrome.lnk 2014-01-04 19:03 - 2014-01-04 19:03 - 01064761 _____ (Farbar) C:\Users\gundi\Downloads\FRST (1).exe 2014-01-04 15:19 - 2014-01-04 15:19 - 00001706 _____ C:\Users\Public\Desktop\Defraggler.lnk 2014-01-04 15:19 - 2014-01-04 15:19 - 00000000 ____D C:\Program Files\Defraggler 2014-01-04 15:18 - 2014-01-04 15:18 - 04208656 _____ (Piriform Ltd) C:\Users\gundi\Downloads\dfsetup216.exe 2014-01-02 13:08 - 2014-01-02 13:08 - 00891200 _____ C:\Users\gundi\Downloads\SecurityCheck.exe 2014-01-02 10:03 - 2014-01-02 10:03 - 02347384 _____ (ESET) C:\Users\gundi\Downloads\esetsmartinstaller_enu.exe 2013-12-31 16:07 - 2013-12-31 16:07 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\gundi\Downloads\sc-cleaner.exe 2013-12-31 16:07 - 2013-12-31 16:07 - 00001814 _____ C:\sc-cleaner.txt 2013-12-31 16:04 - 2013-12-31 16:04 - 00005540 _____ C:\Users\gundi\Desktop\JRT.txt 2013-12-31 16:01 - 2013-12-31 16:01 - 00000000 ____D C:\Windows\ERUNT 2013-12-31 16:00 - 2013-12-31 16:00 - 01034531 _____ (Thisisu) C:\Users\gundi\Downloads\JRT.exe 2013-12-31 15:31 - 2014-01-01 16:48 - 00000000 ____D C:\AdwCleaner 2013-12-31 15:31 - 2013-12-31 15:31 - 01233962 _____ C:\Users\gundi\Downloads\adwcleaner.exe 2013-12-31 15:31 - 2013-12-31 15:31 - 00000000 ____D C:\Users\gundi\AppData\Roaming\Malwarebytes 2013-12-31 15:30 - 2013-12-31 15:30 - 00000910 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-31 15:30 - 2013-12-31 15:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-12-31 15:30 - 2013-12-31 15:30 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-12-31 15:30 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-12-31 15:29 - 2013-12-31 15:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\gundi\Downloads\mbam-setup-1.75.0.1300.exe 2013-12-31 14:34 - 2014-01-06 15:13 - 00017177 _____ C:\Users\gundi\Downloads\FRST.txt 2013-12-31 14:33 - 2013-12-31 14:33 - 01064333 _____ (Farbar) C:\Users\gundi\Downloads\FRST.exe 2013-12-31 14:33 - 2013-12-31 14:33 - 00000000 ____D C:\FRST 2013-12-31 14:32 - 2013-12-31 14:32 - 00000615 _____ C:\Users\Public\Desktop\iMesh-Installation fortsetzen.lnk 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\genienext 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\cache 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\.android 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 _____ C:\Users\gundi\daemonprocess.txt 2013-12-27 14:34 - 2013-12-27 14:38 - 186446085 _____ C:\Users\gundi\Desktop\2127343972001_2854723499001_EV108893-KleineHaendeGrossePfoten-source-ST.mp4 2013-12-27 14:16 - 2013-12-27 14:28 - 901182774 _____ C:\Users\gundi\Desktop\2127343972001_2854993219001_EV114583-SophieUndShiba-source-ST.mp4 2013-12-11 12:37 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-11 12:37 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-11 12:37 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-11 12:37 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-11 12:37 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-11 12:37 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-11 12:37 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 12:37 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-11 12:37 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 12:37 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 12:37 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-11 12:37 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 12:37 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-11 12:37 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 12:37 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-11 12:37 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-11 10:48 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-12-11 10:48 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 10:48 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-11 10:48 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 10:48 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 10:48 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 10:48 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 10:48 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-11 10:48 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 10:48 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe ==================== One Month Modified Files and Folders ======= 2014-01-06 15:13 - 2014-01-06 15:13 - 01064805 _____ (Farbar) C:\Users\gundi\Downloads\FRST (2).exe 2014-01-06 15:13 - 2013-12-31 14:34 - 00017177 _____ C:\Users\gundi\Downloads\FRST.txt 2014-01-06 15:03 - 2014-01-06 15:03 - 00000064 _____ C:\Users\gundi\Desktop\Fixlist.txt 2014-01-06 14:59 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-06 14:59 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-06 14:56 - 2014-01-06 14:56 - 00000066 _____ C:\Users\Gast\Desktop\Fixlist.txt 2014-01-06 14:41 - 2012-06-25 11:43 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-06 14:32 - 2014-01-06 14:32 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Malwarebytes 2014-01-06 14:30 - 2014-01-06 14:30 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Avira 2014-01-06 14:27 - 2010-05-21 14:53 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-06 14:26 - 2014-01-06 14:26 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Adobe 2014-01-06 14:25 - 2010-05-21 14:53 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-06 14:24 - 2014-01-06 14:24 - 00001967 _____ C:\Users\Gast\Desktop\Google Chrome.lnk 2014-01-06 14:24 - 2012-03-12 16:48 - 00000953 _____ C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-06 13:03 - 2011-10-13 13:50 - 00164380 _____ C:\Windows\WindowsUpdate.log 2014-01-06 12:59 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-06 09:59 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-04 19:03 - 2014-01-04 19:03 - 01064761 _____ (Farbar) C:\Users\gundi\Downloads\FRST (1).exe 2014-01-04 15:19 - 2014-01-04 15:19 - 00001706 _____ C:\Users\Public\Desktop\Defraggler.lnk 2014-01-04 15:19 - 2014-01-04 15:19 - 00000000 ____D C:\Program Files\Defraggler 2014-01-04 15:18 - 2014-01-04 15:18 - 04208656 _____ (Piriform Ltd) C:\Users\gundi\Downloads\dfsetup216.exe 2014-01-02 13:08 - 2014-01-02 13:08 - 00891200 _____ C:\Users\gundi\Downloads\SecurityCheck.exe 2014-01-02 11:45 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET 2014-01-02 10:03 - 2014-01-02 10:03 - 02347384 _____ (ESET) C:\Users\gundi\Downloads\esetsmartinstaller_enu.exe 2014-01-01 16:48 - 2013-12-31 15:31 - 00000000 ____D C:\AdwCleaner 2014-01-01 14:03 - 2006-11-02 11:33 - 01539286 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-31 16:07 - 2013-12-31 16:07 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\gundi\Downloads\sc-cleaner.exe 2013-12-31 16:07 - 2013-12-31 16:07 - 00001814 _____ C:\sc-cleaner.txt 2013-12-31 16:04 - 2013-12-31 16:04 - 00005540 _____ C:\Users\gundi\Desktop\JRT.txt 2013-12-31 16:01 - 2013-12-31 16:01 - 00000000 ____D C:\Windows\ERUNT 2013-12-31 16:00 - 2013-12-31 16:00 - 01034531 _____ (Thisisu) C:\Users\gundi\Downloads\JRT.exe 2013-12-31 15:53 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\LiveKernelReports 2013-12-31 15:51 - 2013-06-28 13:42 - 00000979 _____ C:\Users\gundi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-31 15:51 - 2012-10-03 13:05 - 00001079 _____ C:\Users\gundi\Desktop\Google Chrome.lnk 2013-12-31 15:31 - 2013-12-31 15:31 - 01233962 _____ C:\Users\gundi\Downloads\adwcleaner.exe 2013-12-31 15:31 - 2013-12-31 15:31 - 00000000 ____D C:\Users\gundi\AppData\Roaming\Malwarebytes 2013-12-31 15:30 - 2013-12-31 15:30 - 00000910 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-12-31 15:30 - 2013-12-31 15:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-12-31 15:30 - 2013-12-31 15:30 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-12-31 15:29 - 2013-12-31 15:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\gundi\Downloads\mbam-setup-1.75.0.1300.exe 2013-12-31 14:33 - 2013-12-31 14:33 - 01064333 _____ (Farbar) C:\Users\gundi\Downloads\FRST.exe 2013-12-31 14:33 - 2013-12-31 14:33 - 00000000 ____D C:\FRST 2013-12-31 14:32 - 2013-12-31 14:32 - 00000615 _____ C:\Users\Public\Desktop\iMesh-Installation fortsetzen.lnk 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\genienext 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\cache 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\.android 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 _____ C:\Users\gundi\daemonprocess.txt 2013-12-31 13:54 - 2009-06-06 12:46 - 00000000 ____D C:\Users\gundi 2013-12-29 13:09 - 2010-10-20 20:12 - 00000000 ____D C:\Windows\Minidump 2013-12-27 14:38 - 2013-12-27 14:34 - 186446085 _____ C:\Users\gundi\Desktop\2127343972001_2854723499001_EV108893-KleineHaendeGrossePfoten-source-ST.mp4 2013-12-27 14:28 - 2013-12-27 14:16 - 901182774 _____ C:\Users\gundi\Desktop\2127343972001_2854993219001_EV114583-SophieUndShiba-source-ST.mp4 2013-12-21 15:10 - 2009-06-08 14:06 - 00007408 _____ C:\Users\gundi\AppData\Roaming\wklnhst.dat 2013-12-12 13:12 - 2013-02-09 23:04 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-12 13:12 - 2013-02-09 23:04 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-11 19:41 - 2012-06-25 11:43 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-11 19:41 - 2011-08-12 21:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-11 15:43 - 2006-11-02 13:47 - 00398720 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-11 15:40 - 2009-04-02 14:28 - 00000000 ____D C:\Windows\system32\RTCOM 2013-12-11 12:40 - 2013-08-14 10:55 - 00000000 ____D C:\Windows\system32\MRT 2013-12-11 12:38 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe Some content of TEMP: ==================== C:\Users\Gast\AppData\Local\Temp\avgnt.exe C:\Users\gundi\AppData\Local\Temp\avgnt.exe C:\Users\gundi\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-06 13:05 ==================== End Of Log ============================ |
07.01.2014, 09:50 | #10 | |
/// the machine /// TB-Ausbilder | hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoomZitat:
Oder stand da was andres mit Zeile in Notepad als Textdatei speichern und so?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.01.2014, 16:03 | #11 |
| hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom sorry ich blick da jetzt echt nicht mehr durch.. das mit dem notepad habe ich gemacht dann erschien ein leeres fesnster da musste ich die zeile rein tun dann hab ich den frst gestartet, hab den fix button gedrückt es erschien ein text aber nich in dem fast leren fenster und diesen text habe ich dir gepostet...das ist echt sehr schwer für mich ^^ was fehlt denn noch?? ^^ |
08.01.2014, 09:26 | #12 | |
/// the machine /// TB-Ausbilder | hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom Du musst Notepad öffnen, die Zeile einfügen, das dann aber zuerst als fixlist.txt speichern, und zwar neben FRST Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.01.2014, 17:05 | #13 | |
| hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoomZitat:
ja so hab ich es gemacht ich habe es im download gespeichert wenn ich dann bei frst auf fix drücke schreibt er sorry no fixlist gefunden so ungefähr... |
09.01.2014, 11:26 | #14 |
/// the machine /// TB-Ausbilder | hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom Screenshot bitte vom geöffneten Download Ordner.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.01.2014, 10:38 | #15 |
| hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom jetzt hat er das gemacht.... Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 10-01-2014 Ran by gundi at 2014-01-10 10:34:55 Run:1 Running from C:\Users\gundi\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** Running from C:\Users\gundi\Downloads ***************** ==== End of Fixlog ==== wie ein screenshot hier reingemacht wird weiß ich net ..aber das da oben ist das ergebnis ^^ |