|
Log-Analyse und Auswertung: Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPUWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
15.04.2014, 13:50 | #61 |
/// the machine /// TB-Ausbilder | Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Revo Uninstaller - Download - Filepony damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.google.com/chrome/answer/3296214?hl=de Frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.04.2014, 21:41 | #62 |
| Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Ich habe Crome deinstalliert und wollte es nun mit Hilfe von Internet Explorer wieder installieren. Das 1. Problem war dass die Hyperlinks der Suchergebnisse nicht mehr funktionierten. Ich bin jedoch auf die Downloadseite gekommen in dem ich die Webadresse von google vollständig eingegeben habe. Das 2. Problem ist dass dann kommt: "Dieser Computer verfügt bereits über eine neuere Version der Google Chrome-Komponenten. Bitte verwenden Sie einen neueren Installier."
__________________Dieser Revo Uninstaller macht doch alles nur viel schlimmer :/ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 Ran by Emilio (administrator) on EMILIOS-HP-PC on 17-04-2014 20:40:02 Running from C:\Users\Emilio\Desktop\FRST-OlderVersion Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Intel Corporation) C:\Windows\system32\IProsetMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Spotify Ltd) C:\Users\Emilio\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (FileHippo.com) C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (Dropbox, Inc.) C:\Users\Emilio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler64.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Avira Operations GmbH & Co. KG) C:\program files (x86)\avira\antivir desktop\ipmGui.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2014-04-05] (Realtek Semiconductor) HKLM\...\Run: [HPSYSDRV] => C:\Program Files (x86)\Hewlett-Packard\HP Odometer\HPSYSDRV.EXE [62768 2008-11-20] (Hewlett-Packard) HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-25] (Avira Operations GmbH & Co. KG) HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-04-08] (Hewlett-Packard) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3513785353-2090306979-4278820556-1000\...\Run: [Spotify Web Helper] => C:\Users\Emilio\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-13] (Spotify Ltd) HKU\S-1-5-21-3513785353-2090306979-4278820556-1000\...\Run: [FileHippo.com] => C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [307712 2012-11-23] (FileHippo.com) HKU\S-1-5-21-3513785353-2090306979-4278820556-1000\...\Run: [WinPatrol] => C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [527936 2014-03-22] (BillP Studios) Startup: C:\Users\Emilio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Emilio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=CMDTDFJS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=CMDTDFJS SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=CMDTDFJS SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM-x32 - No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5-x64 07 C:\Program Files\Bonjour\mdnsNSP.dll File Not found () Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF HKLM-x32\...\Firefox\Extensions: [12x3q4@3244516.com] - C:\Program Files (x86)\Better-Surf\ff FF HKLM-x32\...\Firefox\Extensions: [ext@bettersurfplusv1.com] - C:\Program Files (x86)\BetterSurf\BetterSurfPlusV1\ff Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1941.0\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1941.0\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1941.0\pdf.dll No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Extension: (Google Docs) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-16] CHR Extension: (Google Drive) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-16] CHR Extension: (WOT) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-02-02] CHR Extension: (YouTube) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-16] CHR Extension: (Adblock Plus) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-03-17] CHR Extension: (Google-Suche) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-16] CHR Extension: (Youtube Video Downloader) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpbkobkodledeibpmilbmnpfolihcnla [2013-06-08] CHR Extension: (Youtube Series Downloader) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\jghmjoeoeedipbgbgofflfgcfpineanf [2013-06-08] CHR Extension: (SmallringFX DarkBlue Theme) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfijmgohofmpjlcgmjplbpmkpchdhpk [2013-03-16] CHR Extension: (V-bates) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\khldgopgjjapmbkgflpoclebjjmkmbnk [2013-06-26] CHR Extension: (Skype Click to Call) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-04-13] CHR Extension: (Download Youtube as mp3) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\mepapnoaejebkkpkpacihjlfekoggahp [2013-10-05] CHR Extension: (Privacy Palette) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjkcflkplhgpebknipkekjggglimnone [2013-03-17] CHR Extension: (Google Wallet) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-06] CHR Extension: (Google Mail) - C:\Users\Emilio\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-16] CHR HKLM-x32\...\Chrome\Extension: [ajadlheagenmmedmhaoafgkdenfilcme] - C:\Program Files (x86)\BetterSurf\BetterSurfPlusV1\ch\BetterSurfPlusV1.crx [2013-03-16] CHR HKLM-x32\...\Chrome\Extension: [ieghcpafofcpcjmacgknimjbimfcdfoc] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta804\ch\VideoPlayerV3beta804.crx [2013-03-16] CHR HKLM-x32\...\Chrome\Extension: [iiahmooinmkibiblfkgkcckfabbkmojp] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha246\ch\WebexpEnhancedV1alpha246.crx [2013-03-16] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-03-03] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-25] (Avira Operations GmbH & Co. KG) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1134624 2012-07-18] (PDF Complete Inc) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-04-05] (Realtek Semiconductor) S2 Bonjour Service; "C:\Program Files\Bonjour\mDNSResponder.exe" [X] S2 Intel(R) Capability Licensing Service Interface; "c:\Program Files\Intel\iCLS Client\HeciServer.exe" [X] S3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [X] S3 osppsvc; "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-02-25] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-02-25] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) S3 IFCoEMP; C:\Windows\system32\drivers\ifM60x64.sys [348944 2011-06-15] (Intel(R) Corporation) S3 IFCoEVB; C:\Windows\system32\drivers\ifP60X64.sys [70928 2011-06-15] (Intel(R) Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-17 20:19 - 2014-04-17 20:19 - 00884720 _____ (Google Inc.) C:\Users\Emilio\Downloads\ChromeSetup (1).exe 2014-04-13 17:28 - 2014-04-13 17:28 - 00000000 ____D () C:\Users\Emilio\AppData\Local\Adobe 2014-04-13 17:25 - 2014-04-13 17:25 - 00844464 _____ (Adobe Systems Incorporated) C:\Users\Emilio\Downloads\flashplayer13_uninstall_win.exe 2014-04-13 17:22 - 2014-04-13 17:22 - 23995416 _____ (Mozilla) C:\Users\Emilio\Downloads\Thunderbird Setup 28.0b1.exe 2014-04-13 17:13 - 2014-04-13 17:13 - 01066536 _____ (BillP Studios) C:\Users\Emilio\Downloads\wpsetup (1).exe 2014-04-13 17:10 - 2014-04-13 17:10 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-04-13 17:10 - 2014-04-13 17:10 - 00000000 ____D () C:\Users\Emilio\AppData\Local\Skype 2014-04-13 17:08 - 2014-04-13 17:08 - 01678496 _____ (Skype Technologies S.A.) C:\Users\Emilio\Downloads\SkypeSetup.exe 2014-04-13 17:05 - 2014-04-13 17:05 - 17529160 _____ (Google Inc.) C:\Users\Emilio\Downloads\picasa39-setup.exe 2014-04-13 17:04 - 2014-04-13 17:04 - 00884720 _____ (Google Inc.) C:\Users\Emilio\Downloads\ChromeSetup.exe 2014-04-13 17:02 - 2014-04-13 17:02 - 03767984 _____ (foobar2000.org) C:\Users\Emilio\Downloads\foobar2000_v1.3.2.exe 2014-04-13 16:43 - 2014-04-13 16:43 - 00264757 _____ () C:\Users\Emilio\Downloads\FHSetup.exe 2014-04-13 16:43 - 2014-04-13 16:43 - 00002005 _____ () C:\Users\Emilio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Update Checker.lnk 2014-04-13 16:43 - 2014-04-13 16:43 - 00001975 _____ () C:\Users\Emilio\Desktop\Update Checker.lnk 2014-04-13 16:43 - 2014-04-13 16:43 - 00000000 ____D () C:\Program Files (x86)\FileHippo.com 2014-04-11 14:49 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-11 14:49 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-11 14:49 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-11 14:49 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-11 14:49 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-11 14:49 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-11 14:49 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-11 14:49 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-11 14:49 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-11 14:49 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-11 14:49 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-11 14:49 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-11 14:49 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-11 14:49 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-11 14:49 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-11 14:49 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-11 14:49 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-11 14:49 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-11 14:49 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-11 14:49 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-11 14:49 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-05 12:59 - 2014-04-05 12:59 - 00001078 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-04-05 11:46 - 2014-04-05 11:45 - 03849304 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2014-04-05 11:46 - 2014-04-05 11:45 - 02825432 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2014-04-05 11:46 - 2014-04-05 11:45 - 02787032 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2014-04-05 11:46 - 2014-04-05 11:45 - 01958616 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2014-04-05 11:46 - 2014-04-05 11:45 - 01286872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2014-04-05 11:46 - 2014-04-05 11:45 - 01022680 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2014-04-05 11:46 - 2014-04-05 11:45 - 00624344 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll 2014-04-05 11:46 - 2014-04-05 11:44 - 48657408 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat 2014-04-05 11:46 - 2014-04-05 11:44 - 02770976 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2014-04-05 11:46 - 2014-04-05 11:44 - 00732833 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT 2014-04-05 11:46 - 2014-04-05 11:44 - 00209096 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2014-04-05 11:46 - 2014-04-05 11:44 - 00156888 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2014-04-05 11:46 - 2014-04-05 11:44 - 00113576 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2014-03-25 04:01 - 2014-03-25 04:00 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-03-24 14:47 - 2014-04-13 16:28 - 00000336 _____ () C:\Windows\Tasks\HPCeeScheduleForEmilio.job 2014-03-24 14:47 - 2014-04-11 14:51 - 00003192 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForEmilio 2014-03-24 14:42 - 2014-03-24 14:42 - 00000000 ____D () C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F} 2014-03-24 14:41 - 2014-03-24 14:41 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\hpqLog 2014-03-24 14:39 - 2014-03-24 14:39 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\Avira 2014-03-24 14:34 - 2014-02-25 12:41 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-03-24 14:34 - 2014-02-25 12:41 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-03-24 14:34 - 2014-02-25 12:41 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-03-24 14:33 - 2014-04-05 12:59 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-03-24 14:32 - 2014-03-24 14:33 - 04051104 _____ (Avira Operations GmbH & Co. KG) C:\Users\Emilio\Downloads\avira_de_av___ws (1).exe 2014-03-18 23:58 - 2014-03-18 23:58 - 00000000 ____D () C:\WINSSLog 2014-03-18 23:55 - 2014-03-18 23:55 - 00756776 _____ (Microsoft Corporation) C:\Users\Emilio\Downloads\OneCareCleanup (2).exe 2014-03-18 23:55 - 2014-03-18 23:55 - 00756776 _____ (Microsoft Corporation) C:\Users\Emilio\Downloads\OneCareCleanup (1).exe 2014-03-18 23:51 - 2014-03-18 23:51 - 13697720 _____ (Microsoft Corporation) C:\Users\Emilio\Downloads\mseinstall (3).exe 2014-03-18 23:45 - 2014-03-18 23:45 - 00756776 _____ (Microsoft Corporation) C:\Users\Emilio\Downloads\OneCareCleanup.exe 2014-03-18 23:25 - 2014-04-13 17:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-18 22:23 - 2014-03-18 22:23 - 00000000 ____D () C:\Users\Emilio\Desktop\Der neue Tugendterror 2014-03-18 21:39 - 2014-03-18 22:16 - 112357896 _____ () C:\Users\Emilio\Downloads\342-TS-DNT-G87136A.part08.rar ==================== One Month Modified Files and Folders ======= 2014-04-17 20:40 - 2014-02-02 16:07 - 00000000 ____D () C:\FRST 2014-04-17 20:40 - 2014-01-26 16:39 - 00000000 ____D () C:\Users\Emilio\Desktop\FRST-OlderVersion 2014-04-17 20:33 - 2014-02-07 12:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-17 20:22 - 2013-03-16 15:11 - 00003954 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{F6BA0110-D05B-4941-A2AC-C1C89CCDA816} 2014-04-17 20:19 - 2014-04-17 20:19 - 00884720 _____ (Google Inc.) C:\Users\Emilio\Downloads\ChromeSetup (1).exe 2014-04-17 20:19 - 2013-03-17 00:01 - 01297413 _____ () C:\Windows\WindowsUpdate.log 2014-04-17 20:18 - 2014-03-09 12:27 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-04-17 20:18 - 2009-07-14 06:45 - 00016768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-17 20:18 - 2009-07-14 06:45 - 00016768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-17 20:17 - 2013-01-03 05:19 - 00686006 _____ () C:\Windows\system32\perfh007.dat 2014-04-17 20:17 - 2013-01-03 05:19 - 00145580 _____ () C:\Windows\system32\perfc007.dat 2014-04-17 20:17 - 2009-07-14 07:13 - 01622164 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-17 20:15 - 2013-03-16 21:31 - 00000000 ___RD () C:\Users\Emilio\Dropbox 2014-04-17 20:15 - 2013-03-16 21:19 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\Dropbox 2014-04-17 20:15 - 2013-03-16 16:05 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-17 20:14 - 2013-01-03 05:47 - 00000000 ____D () C:\ProgramData\PDFC 2014-04-17 20:13 - 2014-02-01 23:14 - 00003295 _____ () C:\Windows\setupact.log 2014-04-17 20:13 - 2013-03-22 00:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-04-17 20:13 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-13 20:12 - 2013-04-02 00:26 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\Spotify 2014-04-13 20:12 - 2013-03-16 16:05 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-13 19:45 - 2013-03-25 02:44 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-04-13 19:45 - 2013-03-25 02:44 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-04-13 19:39 - 2013-03-16 18:30 - 00000000 ____D () C:\Users\Emilio\AppData\Local\PMB Files 2014-04-13 19:39 - 2013-03-16 18:29 - 00000000 ____D () C:\ProgramData\PMB Files 2014-04-13 18:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-13 17:40 - 2013-04-02 00:27 - 00000000 ____D () C:\Users\Emilio\AppData\Local\Spotify 2014-04-13 17:28 - 2014-04-13 17:28 - 00000000 ____D () C:\Users\Emilio\AppData\Local\Adobe 2014-04-13 17:28 - 2014-02-07 12:04 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-13 17:28 - 2014-02-07 12:04 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-13 17:28 - 2014-02-07 12:04 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-13 17:25 - 2014-04-13 17:25 - 00844464 _____ (Adobe Systems Incorporated) C:\Users\Emilio\Downloads\flashplayer13_uninstall_win.exe 2014-04-13 17:25 - 2013-03-22 00:07 - 00000000 ____D () C:\Users\Emilio\AppData\Local\Thunderbird 2014-04-13 17:23 - 2014-03-18 23:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-13 17:23 - 2013-03-22 00:07 - 00002092 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk 2014-04-13 17:22 - 2014-04-13 17:22 - 23995416 _____ (Mozilla) C:\Users\Emilio\Downloads\Thunderbird Setup 28.0b1.exe 2014-04-13 17:19 - 2014-02-01 23:14 - 00356318 _____ () C:\Windows\PFRO.log 2014-04-13 17:16 - 2013-04-05 21:27 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\Skype 2014-04-13 17:13 - 2014-04-13 17:13 - 01066536 _____ (BillP Studios) C:\Users\Emilio\Downloads\wpsetup (1).exe 2014-04-13 17:13 - 2014-02-02 16:42 - 00000000 ____D () C:\ProgramData\InstallMate 2014-04-13 17:10 - 2014-04-13 17:10 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-04-13 17:10 - 2014-04-13 17:10 - 00000000 ____D () C:\Users\Emilio\AppData\Local\Skype 2014-04-13 17:10 - 2013-04-05 21:27 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-04-13 17:10 - 2013-04-05 21:27 - 00000000 ____D () C:\ProgramData\Skype 2014-04-13 17:08 - 2014-04-13 17:08 - 01678496 _____ (Skype Technologies S.A.) C:\Users\Emilio\Downloads\SkypeSetup.exe 2014-04-13 17:07 - 2013-03-16 16:43 - 00001112 _____ () C:\Users\Public\Desktop\Picasa 3.lnk 2014-04-13 17:06 - 2013-09-30 12:50 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\foobar2000 2014-04-13 17:05 - 2014-04-13 17:05 - 17529160 _____ (Google Inc.) C:\Users\Emilio\Downloads\picasa39-setup.exe 2014-04-13 17:04 - 2014-04-13 17:04 - 00884720 _____ (Google Inc.) C:\Users\Emilio\Downloads\ChromeSetup.exe 2014-04-13 17:03 - 2013-09-30 12:50 - 00001037 _____ () C:\Users\Public\Desktop\foobar2000.lnk 2014-04-13 17:03 - 2013-09-30 12:50 - 00000000 ____D () C:\Program Files (x86)\foobar2000 2014-04-13 17:02 - 2014-04-13 17:02 - 03767984 _____ (foobar2000.org) C:\Users\Emilio\Downloads\foobar2000_v1.3.2.exe 2014-04-13 16:43 - 2014-04-13 16:43 - 00264757 _____ () C:\Users\Emilio\Downloads\FHSetup.exe 2014-04-13 16:43 - 2014-04-13 16:43 - 00002005 _____ () C:\Users\Emilio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Update Checker.lnk 2014-04-13 16:43 - 2014-04-13 16:43 - 00001975 _____ () C:\Users\Emilio\Desktop\Update Checker.lnk 2014-04-13 16:43 - 2014-04-13 16:43 - 00000000 ____D () C:\Program Files (x86)\FileHippo.com 2014-04-13 16:28 - 2014-03-24 14:47 - 00000336 _____ () C:\Windows\Tasks\HPCeeScheduleForEmilio.job 2014-04-11 15:47 - 2013-08-17 16:42 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-11 15:46 - 2013-03-29 16:05 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-11 15:07 - 2013-03-16 16:05 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-11 15:07 - 2013-03-16 16:05 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-11 14:51 - 2014-03-24 14:47 - 00003192 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForEmilio 2014-04-05 12:59 - 2014-04-05 12:59 - 00001078 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-04-05 12:59 - 2014-03-24 14:33 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-04-05 12:59 - 2014-01-03 13:21 - 00000000 ____D () C:\ProgramData\Avira 2014-04-05 12:57 - 2014-02-02 16:49 - 00000000 ____D () C:\Program Files (x86)\SpywareBlaster 2014-04-05 11:47 - 2013-01-03 05:36 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM 2014-04-05 11:45 - 2014-04-05 11:46 - 03849304 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2014-04-05 11:45 - 2014-04-05 11:46 - 02825432 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2014-04-05 11:45 - 2014-04-05 11:46 - 02787032 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2014-04-05 11:45 - 2014-04-05 11:46 - 01958616 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2014-04-05 11:45 - 2014-04-05 11:46 - 01286872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2014-04-05 11:45 - 2014-04-05 11:46 - 01022680 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2014-04-05 11:45 - 2014-04-05 11:46 - 00624344 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll 2014-04-05 11:45 - 2011-02-11 18:32 - 00000000 ____D () C:\SWSETUP 2014-04-05 11:44 - 2014-04-05 11:46 - 48657408 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat 2014-04-05 11:44 - 2014-04-05 11:46 - 02770976 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2014-04-05 11:44 - 2014-04-05 11:46 - 00732833 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT 2014-04-05 11:44 - 2014-04-05 11:46 - 00209096 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2014-04-05 11:44 - 2014-04-05 11:46 - 00156888 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2014-04-05 11:44 - 2014-04-05 11:46 - 00113576 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2014-04-05 11:44 - 2013-01-03 05:41 - 02080472 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll 2014-03-31 03:16 - 2014-04-11 14:49 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-11 14:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-11 14:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-11 14:49 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-25 04:00 - 2014-03-25 04:01 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-03-24 14:46 - 2013-01-03 05:41 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-03-24 14:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2014-03-24 14:42 - 2014-03-24 14:42 - 00000000 ____D () C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F} 2014-03-24 14:42 - 2013-01-03 05:40 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard 2014-03-24 14:41 - 2014-03-24 14:41 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\hpqLog 2014-03-24 14:41 - 2013-01-03 05:40 - 00000000 ____D () C:\ProgramData\Hewlett-Packard 2014-03-24 14:39 - 2014-03-24 14:39 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\Avira 2014-03-24 14:33 - 2014-03-24 14:32 - 04051104 _____ (Avira Operations GmbH & Co. KG) C:\Users\Emilio\Downloads\avira_de_av___ws (1).exe 2014-03-22 01:38 - 2013-03-16 15:51 - 00000000 ____D () C:\Users\Emilio\AppData\Roaming\SoftGrid Client 2014-03-21 17:20 - 2014-03-15 19:50 - 00001083 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2014-03-19 00:14 - 2013-01-03 05:48 - 00002122 _____ () C:\Windows\epplauncher.mif 2014-03-18 23:58 - 2014-03-18 23:58 - 00000000 ____D () C:\WINSSLog 2014-03-18 23:55 - 2014-03-18 23:55 - 00756776 _____ (Microsoft Corporation) C:\Users\Emilio\Downloads\OneCareCleanup (2).exe 2014-03-18 23:55 - 2014-03-18 23:55 - 00756776 _____ (Microsoft Corporation) C:\Users\Emilio\Downloads\OneCareCleanup (1).exe 2014-03-18 23:51 - 2014-03-18 23:51 - 13697720 _____ (Microsoft Corporation) C:\Users\Emilio\Downloads\mseinstall (3).exe 2014-03-18 23:45 - 2014-03-18 23:45 - 00756776 _____ (Microsoft Corporation) C:\Users\Emilio\Downloads\OneCareCleanup.exe 2014-03-18 22:23 - 2014-03-18 22:23 - 00000000 ____D () C:\Users\Emilio\Desktop\Der neue Tugendterror 2014-03-18 22:16 - 2014-03-18 21:39 - 112357896 _____ () C:\Users\Emilio\Downloads\342-TS-DNT-G87136A.part08.rar 2014-03-18 22:05 - 2013-05-04 15:02 - 00000000 ____D () C:\Users\Emilio\Documents\Kontoauszüge Some content of TEMP: ==================== C:\Users\Emilio\AppData\Local\Temp\avgnt.exe C:\Users\Emilio\AppData\Local\Temp\Extract.exe C:\Users\Emilio\AppData\Local\Temp\SkypeSetup.exe C:\Users\Emilio\AppData\Local\Temp\sp64126.exe C:\Users\Emilio\AppData\Local\Temp\SP65606.exe C:\Users\Emilio\AppData\Local\Temp\UninstallHPSA.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-11 15:05 ==================== End Of Log ============================ --- --- --- --- --- --- ... Mozilla kann ich auch nicht installieren weil es nach draufklicken nicht runtergeladen wird |
18.04.2014, 16:55 | #63 |
/// the machine /// TB-Ausbilder | Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Setze folgendermassen den Internet Explorer zurück:
__________________
Jetzt Chrome und FF nochmal laden.
__________________ |
18.04.2014, 17:58 | #64 |
| Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Danke der Internet Explorer funktioniert wieder und ich konnte mir Firefox runterladen. Trotzdem kann ich immernochnicht Crome herunterladen |
19.04.2014, 10:36 | #65 |
/// the machine /// TB-Ausbilder | Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Lade SystemLook von jpshortstuff von einem der folgenden Spiegel herunter und speichere das Tool auf dem Desktop. SystemLook (64 bit)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.04.2014, 20:20 | #66 | |
| Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Bitteschön Zitat:
|
20.04.2014, 18:06 | #67 |
/// the machine /// TB-Ausbilder | Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Hast Du Chrome mit Revo deinstalliert und auch die Reste entfernen lassen?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.04.2014, 19:50 | #68 |
| Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Ja habe ich alles gemacht. |
21.04.2014, 20:14 | #69 |
/// the machine /// TB-Ausbilder | Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Program Files (x86)\Google Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Jetzt nochmal versuchen Chrome zu installieren.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.05.2014, 19:04 | #70 | |
| Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Fixlog: Zitat:
|
02.05.2014, 16:42 | #71 |
/// the machine /// TB-Ausbilder | Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Gibts doch nit. Immer noch die gleiche Fehlermeldung? Du bist in einem Adminkonto?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.05.2014, 11:55 | #72 |
| Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Wo sieht man das denn? Ist es vllt besser wenn ich den Computer Wiederherstelle, also alles auf anfang mache? |
04.05.2014, 19:58 | #73 |
/// the machine /// TB-Ausbilder | Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Dann musste aber vorher alle DAten sichern und alle Programme neu installieren. Schau mal Systemsteuerung > Benutzerkonten. Dort steht als was Du unterwegs bist.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.05.2014, 21:14 | #74 |
| Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Ja ich bin Admin Ja wenn das jetzt nicht anders geht.. dann muss das wohl so sein :/ |
10.05.2014, 17:47 | #75 |
/// the machine /// TB-Ausbilder | Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU Besser is das.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Virus: Avira kann nicht geupdated werden/ verbraucht sehr viel CPU |
administrator, adware.vplayer, adware/adware.gen, canon, nicht installiert, pup.bprotector, pup.optional.babylontoolbar.a, pup.optional.bprotector.a, pup.optional.datamngr.a, pup.optional.delta, pup.optional.delta.a, pup.optional.filescout.a, pup.optional.iminent, pup.optional.iminent.a, pup.optional.softwareupdater, pup.optional.sweetpacks.a, pup.optional.vbateshelper.a, pup.optional.videodownloader.a, pup.optional.webexp, pup.software.updater, zugriff verweigert |