|
Log-Analyse und Auswertung: Virenprogramme stürzen abWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
02.02.2014, 23:32 | #1 |
| Virenprogramme stürzen ab Hallo, habe mir über eine helperbar, welche sich von selber auf meinem Laptop installiert hat anscheinend Viren oder PUPs eingefangen. Jegliche Virenprogramme (Malwarebytes, Adwcleaner) finden zwar sehr viel, stürzen aber bei Löschungsversuchen ab. Mein Rechner verlangsamt sich zunehmends. Bitte um Hilfe! Hab gerade eben eine Logfile über Hijack this erstellt. LG B |
02.02.2014, 23:44 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenprogramme stürzen ab Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
03.02.2014, 00:09 | #3 |
| Virenprogramme stürzen ab Hallo, danke schon mal...ja heute hat Malwarebytes 966 infizierte Objekte gefunden, hat sich aber leider aufgehängt...
__________________Hier die Logfile : FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2014 03 Ran by Seppi (administrator) on MICHAEL-PC on 03-02-2014 00:03:14 Running from C:\Users\Seppi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\79ZXE6AZ Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Cisco Systems, Inc.) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_11_9_900_170_ActiveX.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [Dell Webcam Central] - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe [442536 2008-11-11] (Creative Technology Ltd.) HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1983816 2009-03-24] (CANON INC.) HKLM\...\Run: [CanonSolutionMenu] - C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [767312 2009-03-18] (CANON INC.) HKLM\...\Run: [ Malwarebytes Anti-Malware (reboot)] - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [887432 2013-04-04] (Malwarebytes Corporation) HKLM\...\Run: [H2O] - C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe [385024 2005-10-22] (Team H2O) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-19] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.) HKU\.DEFAULT\...\Run: [msnmsgr] - C:\Program Files\Windows Live\Messenger\msnmsgr.exe [3882312 2008-12-03] (Microsoft Corporation) HKU\.DEFAULT\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe -update activex HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\Run: [Ituvapxymi] - C:\Users\Seppi\AppData\Roaming\Paofon\gufio.exe HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil32_11_9_900_170_ActiveX.exe [839560 2013-12-11] (Adobe Systems Incorporated) HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\MountPoints2: {9d8c8a43-2261-11e0-8338-002219f09901} - F:\AUTOPLAY.EXE HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\MountPoints2: {c3025575-aa9f-11e2-a46e-bed9dace8f6b} - G:\Startme.exe HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\Winlogon: [Shell] Explorer.exe [2926592 2009-04-11] (Microsoft Corporation) <==== ATTENTION Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Michi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Seppi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8 SearchScopes: HKLM - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=07/01/2014&type=hp1000 SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=07/01/2014&type=hp1000 SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=07/01/2014&type=hp1000 SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=07/01/2014&type=hp1000 BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) BHO: No Name - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No File Toolbar: HKLM - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM - Yahoo Community Smartbar (by Linkury) - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKCU - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Toolbar: HKCU - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540104} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ] Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Seppi\AppData\Roaming\Mozilla\Firefox\Profiles\q79z9d8h.default FF NewTab: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=nt&fr=linkury-tb&installDate={installDate}&type=hp1000&q= FF DefaultSearchEngine: Web Search FF SelectedSearchEngine: Web Search FF Homepage: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=hp&fr=linkury-tb&installDate=07/01/2014&type=hp1000 FF Keyword.URL: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=ds&fr=linkury-tb&installDate=07/01/2014&type=hp1000&p= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX OVS Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Seppi\AppData\Roaming\Mozilla\Firefox\Profiles\q79z9d8h.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Plus-HD-4.8 - C:\Users\Seppi\AppData\Roaming\Mozilla\Firefox\Profiles\q79z9d8h.default\Extensions\9a1cadcd-98ec-4413-87d3-0f7c4253cd27@31f19576-e1e2-40bc-81ac-be7a5f1cf67c.com [2014-01-29] FF Extension: Microsoft .NET Framework Assistant - C:\Users\Seppi\AppData\Roaming\Mozilla\Firefox\Profiles\q79z9d8h.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2013-08-03] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-01-07] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-01-07] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-01-07] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKCU\...\Firefox\Extensions: [{184AA5E6-741D-464a-820E-94B3ABC2F3B4}] - C:\Users\Seppi\AppData\Roaming\01003 FF Extension: Java String Helper - C:\Users\Seppi\AppData\Roaming\01003 [2012-02-08] ========================== Services (Whitelisted) ================= R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [81920 2009-03-20] (Andrea Electronics Corporation) R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-19] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-19] (Avira Operations GmbH & Co. KG) R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1528616 2010-03-23] (Cisco Systems, Inc.) R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-12-18] (Stardock Corporation) S3 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] () S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) R2 sprtsvc_DellSupportCenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2009-01-30] (SupportSoft, Inc.) R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe [254042 2009-03-20] (IDT, Inc.) ==================== Drivers (Whitelisted) ==================== S3 61883; C:\Windows\System32\DRIVERS\61883.sys [45696 2008-01-21] (Microsoft Corporation) R2 Aspi32; C:\Windows\system32\Drivers\Aspi32.sys [25244 1999-09-10] (Adaptec) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-19] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-19] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-25] (Avira Operations GmbH & Co. KG) R3 CLEDX; C:\Windows\System32\DRIVERS\cledx.sys [33792 2005-05-09] (Team H2O) S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.) R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [308859 2010-03-23] (Cisco Systems, Inc.) R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.) R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [26024 2009-12-17] (Elaborate Bytes AG) R3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2014-02-02] (Malwarebytes Corporation) R3 OA008Ufd; C:\Windows\System32\DRIVERS\OA008Ufd.sys [133472 2009-02-10] (Creative Technology Ltd.) R3 OA008Vid; C:\Windows\System32\DRIVERS\OA008Vid.sys [271616 2009-02-10] (Creative Technology Ltd.) S3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1083520 2006-11-02] (Philips Semiconductors GmbH) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-15] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\Users\Michael\AppData\Local\Temp\catchme.sys [x] U1 d3dsbe; \??\C:\Windows\system32\drivers\d3dsbe.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S2 Nsynas32; No ImagePath S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S2 Parclass; \SystemRoot\System32\Drivers\Parclass.sys [x] S3 PCD5SRVC{3F6A8B78-EC003E00-05040104}; \??\C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [x] S3 StarOpen; No ImagePath ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-03 00:01 - 2014-02-03 00:03 - 00000000 ____D () C:\FRST 2014-02-02 23:49 - 2014-02-02 23:50 - 01137152 _____ (Farbar) C:\Users\Seppi\Downloads\FRST.exe 2014-02-02 23:42 - 2014-02-02 23:43 - 00000472 _____ () C:\Users\Seppi\Desktop\defogger_disable.log 2014-02-02 23:42 - 2014-02-02 23:42 - 00000000 _____ () C:\Users\Seppi\defogger_reenable 2014-02-02 23:22 - 2014-02-02 23:22 - 00009460 _____ () C:\Users\Seppi\Desktop\hijackthis2.txt 2014-02-02 23:21 - 2014-02-02 23:21 - 00008711 _____ () C:\Users\Seppi\Desktop\hijackthis.log 2014-02-01 20:23 - 2014-02-01 20:23 - 00139616 _____ () C:\Windows\Minidump\Mini020114-01.dmp 2014-01-13 21:57 - 2014-01-13 21:58 - 00139616 _____ () C:\Windows\Minidump\Mini011314-01.dmp 2014-01-10 20:35 - 2014-01-10 20:36 - 00139616 _____ () C:\Windows\Minidump\Mini011014-01.dmp 2014-01-08 20:17 - 2014-02-02 23:54 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys 2014-01-08 20:17 - 2014-01-08 20:17 - 00000868 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-08 20:17 - 2014-01-08 20:17 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-01-08 20:17 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-08 20:13 - 2014-01-08 20:16 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Seppi\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-07 23:48 - 2014-01-07 23:48 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\TuneUp Software 2014-01-07 23:40 - 2014-01-07 23:49 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-01-07 23:40 - 2014-01-07 23:41 - 34008992 _____ (DVDVideoSoft Ltd. ) C:\Users\Seppi\Downloads\FreeYouTubeToMP3Converter-3.12.20.1230.exe 2014-01-07 23:40 - 2014-01-07 23:40 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-01-07 23:36 - 2014-01-07 23:36 - 00002139 _____ () C:\Users\Seppi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2014-01-07 23:36 - 2014-01-07 23:36 - 00002109 _____ () C:\Users\Seppi\Desktop\Search.lnk 2014-01-07 23:35 - 2014-01-07 23:36 - 00000000 ____D () C:\Users\Seppi\AppData\Local\Smartbar 2014-01-07 23:34 - 2014-01-08 20:03 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\DVDVideoSoft 2014-01-07 23:34 - 2014-01-07 23:34 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\OpenCandy 2014-01-07 23:32 - 2014-01-07 23:33 - 32244744 _____ (DVDVideoSoft Ltd. ) C:\Users\Seppi\Downloads\FreeYouTubeDownload-3.2.20.1230.exe 2014-01-07 21:29 - 2014-01-29 22:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-02-03 00:03 - 2014-02-03 00:01 - 00000000 ____D () C:\FRST 2014-02-02 23:59 - 2012-06-18 21:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-02 23:58 - 2012-02-25 01:14 - 01456798 _____ () C:\Windows\WindowsUpdate.log 2014-02-02 23:54 - 2014-01-08 20:17 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys 2014-02-02 23:50 - 2014-02-02 23:49 - 01137152 _____ (Farbar) C:\Users\Seppi\Downloads\FRST.exe 2014-02-02 23:43 - 2014-02-02 23:42 - 00000472 _____ () C:\Users\Seppi\Desktop\defogger_disable.log 2014-02-02 23:42 - 2014-02-02 23:42 - 00000000 _____ () C:\Users\Seppi\defogger_reenable 2014-02-02 23:42 - 2011-02-12 16:36 - 00000000 ____D () C:\Users\Seppi 2014-02-02 23:40 - 2009-12-14 00:11 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-02 23:22 - 2014-02-02 23:22 - 00009460 _____ () C:\Users\Seppi\Desktop\hijackthis2.txt 2014-02-02 23:21 - 2014-02-02 23:21 - 00008711 _____ () C:\Users\Seppi\Desktop\hijackthis.log 2014-02-02 23:14 - 2013-10-01 10:17 - 00000000 ____D () C:\AdwCleaner 2014-02-02 23:02 - 2011-03-21 21:48 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\Skype 2014-02-02 22:55 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-02 22:55 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-02 16:59 - 2009-12-14 00:11 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-02 16:55 - 2010-08-27 14:45 - 00000000 ____D () C:\Program Files\Common Files\Akamai 2014-02-02 16:55 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-02 15:15 - 2006-11-02 14:01 - 00032562 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-01 20:23 - 2014-02-01 20:23 - 00139616 _____ () C:\Windows\Minidump\Mini020114-01.dmp 2014-02-01 20:23 - 2013-07-22 11:15 - 299486590 _____ () C:\Windows\MEMORY.DMP 2014-02-01 20:23 - 2010-03-26 12:38 - 00000000 ____D () C:\Windows\Minidump 2014-01-30 20:00 - 2013-08-03 12:03 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-01-29 22:18 - 2014-01-07 21:29 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-01-29 22:18 - 2013-08-03 12:03 - 00000808 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-26 13:52 - 2010-12-08 17:20 - 00001022 _____ () C:\Windows\Tasks\Google Software Updater.job 2014-01-13 21:58 - 2014-01-13 21:57 - 00139616 _____ () C:\Windows\Minidump\Mini011314-01.dmp 2014-01-10 20:36 - 2014-01-10 20:35 - 00139616 _____ () C:\Windows\Minidump\Mini011014-01.dmp 2014-01-08 20:17 - 2014-01-08 20:17 - 00000868 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-08 20:17 - 2014-01-08 20:17 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-01-08 20:16 - 2014-01-08 20:13 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Seppi\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-08 20:03 - 2014-01-07 23:34 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\DVDVideoSoft 2014-01-08 00:43 - 2011-10-06 20:14 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\Audacity 2014-01-08 00:36 - 2012-12-04 21:34 - 00039176 _____ () C:\Windows\PFRO.log 2014-01-08 00:33 - 2013-07-08 21:40 - 00000000 ____D () C:\Users\Seppi\Desktop\Neuer Ordner 2014-01-07 23:49 - 2014-01-07 23:40 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-01-07 23:48 - 2014-01-07 23:48 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\TuneUp Software 2014-01-07 23:41 - 2014-01-07 23:40 - 34008992 _____ (DVDVideoSoft Ltd. ) C:\Users\Seppi\Downloads\FreeYouTubeToMP3Converter-3.12.20.1230.exe 2014-01-07 23:40 - 2014-01-07 23:40 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-01-07 23:36 - 2014-01-07 23:36 - 00002139 _____ () C:\Users\Seppi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2014-01-07 23:36 - 2014-01-07 23:36 - 00002109 _____ () C:\Users\Seppi\Desktop\Search.lnk 2014-01-07 23:36 - 2014-01-07 23:35 - 00000000 ____D () C:\Users\Seppi\AppData\Local\Smartbar 2014-01-07 23:34 - 2014-01-07 23:34 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\OpenCandy 2014-01-07 23:33 - 2014-01-07 23:32 - 32244744 _____ (DVDVideoSoft Ltd. ) C:\Users\Seppi\Downloads\FreeYouTubeDownload-3.2.20.1230.exe 2014-01-07 22:25 - 2011-03-23 14:07 - 00035840 _____ () C:\Users\Seppi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini Files to move or delete: ==================== C:\Users\Michael\AppData\Roaming\desktop.ini C:\Users\Michael\avira_antivir_personal403_de.exe C:\Users\Seppi\avira_antivir_personal403_de.exe C:\Users\Seppi\CTX.DAT Some content of TEMP: ==================== C:\Users\Michael\AppData\Local\temp\AUTOPLAY.EXE C:\Users\Michael\AppData\Local\temp\BOOTDISK.EXE C:\Users\Michael\AppData\Local\temp\CPUID.EXE C:\Users\Michael\AppData\Local\temp\DivXSetup.exe C:\Users\Michael\AppData\Local\temp\DOS4GW.EXE C:\Users\Michael\AppData\Local\temp\EREGLIB.DLL C:\Users\Michael\AppData\Local\temp\FlashPlayerUpdate.exe C:\Users\Michael\AppData\Local\temp\HAVEVESA.EXE C:\Users\Michael\AppData\Local\temp\HDDTEC.EXE C:\Users\Michael\AppData\Local\temp\INSTALL.EXE C:\Users\Michael\AppData\Local\temp\SETUP.EXE C:\Users\Michael\AppData\Local\temp\SETUP32.EXE C:\Users\Michael\AppData\Local\temp\SETUPL.DLL C:\Users\Michael\AppData\Local\temp\UVCONFIG.EXE C:\Users\Michael\AppData\Local\temp\WHAT.EXE C:\Users\Michael\AppData\Local\temp\_SETUP.EXE C:\Users\Seppi\AppData\Local\temp\avgnt.exe C:\Users\Seppi\AppData\Local\temp\jre-7u17-windows-i586-iftw.exe C:\Users\Seppi\AppData\Local\temp\jre-7u21-windows-i586-iftw.exe C:\Users\Seppi\AppData\Local\temp\jre-7u45-windows-i586-iftw.exe C:\Users\Seppi\AppData\Local\temp\jre-7u51-windows-i586-iftw.exe C:\Users\Seppi\AppData\Local\temp\m2eyqkpa.dll C:\Users\Seppi\AppData\Local\temp\Quarantine.exe C:\Users\Seppi\AppData\Local\temp\SkypeSetup.exe C:\Users\Seppi\AppData\Local\temp\Upgrade.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-02 17:05 ==================== End Of Log ============================ |
03.02.2014, 00:19 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenprogramme stürzen ab Log von MBAM posten, ohne die Funde zu entfernen...damit ich besser sehe womit wird es zu tun haben Und das andere Log von FRST fehlt
__________________ Logfiles bitte immer in CODE-Tags posten |
03.02.2014, 00:25 | #5 |
| Virenprogramme stürzen ab Hi, da sich Malwarebytes aufgehängt hat...hab ich da kein logfile...soll ichs nochmal mit nem scan probieren? Adition logfile kommt : Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-02-2014 03 Ran by Seppi at 2014-02-03 00:03:44 Running from C:\Users\Seppi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\79ZXE6AZ Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (Version: - Microsoft) 7-Zip 4.65 (Version: - ) Adobe AIR (Version: 3.2.0.2070 - Adobe Systems Incorporated) Adobe AIR (Version: 3.2.0.2070 - Adobe Systems Incorporated) Hidden Adobe Anchor Service CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Asset Services CS3 (Version: 3 - Adobe Systems Incorporated) Hidden Adobe Bridge CS3 (Version: 2 - Adobe Systems Incorporated) Hidden Adobe Bridge Start Meeting (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Camera Raw 4.0 (Version: 4.0 - Adobe Systems Incorporated) Hidden Adobe CMaps (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Color Common Settings (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Default Language CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Device Central CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe ExtendScript Toolkit 2 (Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Fonts All (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Help Viewer CS3 (Version: 1 - Adobe Systems Incorporated) Hidden Adobe Linguistics CS3 (Version: 3.0.0 - Adobe Systems Incorporated) Hidden Adobe PDF Library Files (Version: 8.0 - Adobe Systems Incorporated) Hidden Adobe Premiere Pro CS3 (Version: 3 - Adobe Systems Incorporated) Adobe Premiere Pro CS3 (Version: 3 - Adobe Systems Incorporated) Hidden Adobe Premiere Pro CS3 Functional Content (Version: 8 - Adobe Systems Incorporated) Hidden Adobe Premiere Pro CS3 Third Party Content (Version: 3 - Adobe Systems Incorporated) Hidden Adobe Reader 9.5.5 - Deutsch (Version: 9.5.5 - Adobe Systems Incorporated) Adobe Setup (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Type Support (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe Update Manager CS3 (Version: 5.1.0 - Adobe Systems Incorporated) Hidden Adobe Version Cue CS3 Client (Version: 3 - Adobe Systems Incorporated) Hidden Adobe XMP DVA Panels CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden Adobe XMP Panels CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden Advanced Audio FX Engine (Version: 1.12.05 - Creative Technology Ltd) Akamai NetSession Interface (HKCU Version: - ) Akamai NetSession Interface Service (Version: - ) Apple Application Support (Version: 2.3.2 - Apple Inc.) Apple Mobile Device Support (Version: 6.0.1.3 - Apple Inc.) Apple Software Update (Version: 2.1.3.127 - Apple Inc.) Ashampoo Burning Studio 2010 Advanced (Version: 9.2.4 - ashampoo GmbH & Co. KG) ATI Catalyst Control Center (Version: 2.008.1114.2148 - ) Audacity 1.3.12 (Unicode) (Version: - Audacity Team) AudibleManager (Version: 326928.-2.1999990966.1999989980 - Audible, Inc.) Avira Free Antivirus (Version: 14.0.2.286 - Avira) AviSynth 2.5 (Version: - ) BitTorrent (Version: 7.2.0 - ) BlueVoda Website Builder 11.4G (Version: - ) Bonjour (Version: 3.0.0.10 - Apple Inc.) Bowling Evolution (Version: - ) Canon Easy-WebPrint EX (Version: - ) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (Version: - ) Canon MP Navigator EX 3.0 (Version: - ) Canon MP550 series Benutzerregistrierung (Version: - ) Canon MP550 series MP Drivers (Version: - ) Canon Utilities Easy-PhotoPrint EX (Version: - ) Canon Utilities My Printer (Version: - ) Canon Utilities Solution Menu (Version: - ) Catalyst Control Center - Branding (Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Core Implementation (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Graphics Full Existing (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Graphics Full New (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Graphics Light (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Graphics Previews Common (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center InstallProxy (Version: 2008.1114.2149.39131 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization Chinese Standard (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization Chinese Traditional (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization Danish (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization Dutch (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization Finnish (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization French (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization German (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization Italian (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization Japanese (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization Korean (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization Norwegian (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization Portuguese (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization Russian (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization Spanish (Version: 2008.1114.2149.39131 - ATI) Hidden Catalyst Control Center Localization Swedish (Version: 2008.1114.2149.39131 - ATI) Hidden CCC Help Chinese Standard (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help Chinese Traditional (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help Danish (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help Dutch (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help English (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help Finnish (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help French (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help German (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help Italian (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help Japanese (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help Korean (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help Norwegian (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help Portuguese (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help Russian (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help Spanish (Version: 2008.1114.2148.39131 - ATI) Hidden CCC Help Swedish (Version: 2008.1114.2148.39131 - ATI) Hidden ccc-core-static (Version: 2008.1114.2149.39131 - ATI) Hidden ccc-utility (Version: 2008.1114.2149.39131 - ATI) Hidden CCleaner (Version: 2.30 - Piriform) CDBurnerXP (Version: 4.3.8.2474 - CDBurnerXP) Choice Guard (Version: 1.2.87.0 - Microsoft Corporation) Hidden Chrysler Golf Challenge (Version: - ) Cisco Systems VPN Client 5.0.07.0290 (Version: 5.0.6 - Cisco Systems, Inc.) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000 - Microsoft Corporation) Dell DataSafe Online (Version: 1.1.0023 - Dell, Inc.) Dell Dock (Version: 1.0.0 - Dell) Dell Edoc Viewer (Version: 1.0.0 - Dell Inc) Dell Getting Started Guide (Version: 1.00.0000 - Dell Inc.) Dell Support Center (Support Software) (Version: 2.2.09085 - Dell) Dell Touchpad (Version: 12.0.1.0 - Synaptics) Dell Video Chat (Version: 6.0 (6567) - SightSpeed Inc.) Dell Webcam Central (Version: 1.02.06 - Creative Technology Ltd) Dell-eBay (Version: 1.00.0000 - Dell) DivX Version Checker (Version: 7.1.0.9 - DivX, Inc.) DivX-Setup (Version: 2.3.0.20 - DivX, LLC) Dropbox (HKCU Version: 2.0.22 - Dropbox, Inc.) ElsterFormular (Version: 14.1.20130301 - Landesfinanzdirektion Thüringen) eMule (Version: - ) EVEREST Home Edition v2.20 (Version: 2.20 - Lavalys Inc) FormatFactory 2.50 (Version: 2.50 - Free Time) G*Power 3.1.3 (Version: 3.1.3 - Franz Faul, Uni Kiel, Germany) GIMP 2.6.11 (Version: 2.6.11 - The GIMP Team) Google Earth (Version: 7.1.2.2041 - Google) Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden Google Toolbar for Internet Explorer (Version: 7.5.4805.320 - Google Inc.) Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden Google Updater (Version: 2.4.2432.1652 - Google Inc.) GoToAssist 8.0.0.514 (Version: - ) GUI for dvdauthor 1.07 (Version: 1.07 - Boraxsoft) HijackThis 2.0.2 (Version: 2.0.2 - TrendMicro) Integrated Webcam Driver (1.02.02.0106) (Version: 1.02.02.0106 - Creative Technology Ltd.) IsoBuster 2.8.5 (Version: 2.8.5 - Smart Projects) iTunes (Version: 11.0.1.12 - Apple Inc.) Java 7 Update 45 (Version: 7.0.450 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JDownloader 0.9 (Version: 0.9 - AppWork GmbH) Junk Mail filter update (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden LECTURNITY Player (Version: 4.0.0000 - imc AG) Leisure Suit Larry 7 (Version: 1.0.59 - Sierra) LimeWire 5.1.3 (Version: 5.1.3 - Lime Wire, LLC) Logic Audio Platinum v5.10 (Version: - ) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300 - Malwarebytes Corporation) Media Go (Version: 2.4.256 - Sony) Media Go Video Playback Engine 1.116.101.02020 (Version: 1.116.101.02020 - Sony) Mendeley Desktop 0.9.9 (Version: 0.9.9 - Mendeley Ltd.) MFC RunTime files (Version: 1.0.0 - Extensoft) Hidden Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Suite Activation Assistant (Version: 2.9 - Microsoft Corporation) Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (Version: 5.1.20513.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla) Mozilla Maintenance Service (Version: 26.0 - Mozilla) MPEG4E VFW - H.264/MPEG-4 AVC codec (remove only) (Version: - ) MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) Nero Control Center 10 (Version: 10.0.13100.3.1 - Nero AG) Hidden Nero ControlCenter 10 Help (CHM) (Version: 1.0.10700 - Nero AG) Hidden Nero Core Components 10 (Version: 2.0.15100.0.1 - Nero AG) Hidden Nvu 1.0 (Version: 1.0 - Thorsten Fritz) OpenOffice.org 3.1 (Version: 3.1.9399 - OpenOffice.org) PlayStation(R)Store (Version: 4.14.6.15183 - Sony Computer Entertainment Inc.) PowerDVD (Version: 8.1 - Dell) QuickSet (Version: 9.2.13 - Dell Inc.) Roxio Creator Audio (Version: 3.7.0 - Roxio) Hidden Roxio Creator Copy (Version: 3.7.0 - Roxio) Hidden Roxio Creator Data (Version: 3.7.0 - Roxio) Hidden Roxio Creator DE (Version: 10.1 - Roxio) Roxio Creator DE (Version: 3.7.0 - Roxio) Hidden Roxio Creator Tools (Version: 3.7.0 - Roxio) Hidden Roxio Express Labeler 3 (Version: 3.2.1 - Roxio) Hidden Roxio Update Manager (Version: 6.0.0 - Roxio) Hidden Shape Collage (Version: - Shape Collage Inc.) simfy (Version: 1.6.9 - simfy GmbH) simfy (Version: 1.6.9 - simfy GmbH) Hidden Skins (Version: 2008.1114.2149.39131 - ATI) Hidden Skype Click to Call (Version: 5.9.9216 - Skype Technologies S.A.) Skype™ 6.11 (Version: 6.11.102 - Skype Technologies S.A.) SmartSound Common Data (Version: 1.1.0 - SmartSound Software Inc.) SmartSound Common Data (Version: 1.1.0 - SmartSound Software Inc.) Hidden SmartSound Quicktracks 5 (Version: 5.1.6 - SmartSound Software Inc.) SmartSound Quicktracks 5 (Version: 5.1.6 - SmartSound Software Inc.) Hidden Sony Ericsson Update Engine (Version: 2.13.6.201305161305 - Sony Ericsson Communications AB) Sony PC Companion 2.10.181 (Version: 2.10.181 - Sony) SopCast 3.2.4 (Version: 3.2.4 - SopCast.com) Steinberg Groove Agent 2 (Version: 2.0.0 - Steinberg) Steinberg Groove Agent 2 v2.0.0.28 (Version: - ) Stream Torrent 1.0 (Version: - ) SyncroSoft Emu (Remove only) (Version: - ) Syncrosofts Lizenz Kontrolle (Version: - Syncrosoft Hard- Und Software GmbH) TVUPlayer 2.5.2.2 (Version: 2.5.2.2 - TVU networks) Two Worlds Pinball (Version: 1.00 - TopWare Interactive Inc.) Uniblue RegistryBooster (Version: - Uniblue Systems Ltd) Update for 2007 Microsoft Office System (KB967642) (Version: - Microsoft) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (Version: - Microsoft) Vampireville . (Version: - ) VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0 - DivX, Inc) Hidden VirtualCloneDrive (Version: - Elaborate Bytes) VLC media player 1.0.1 (Version: 1.0.1 - VideoLAN Team) vShare.tv plugin 1.3 (Version: 1.3 - vShare.tv, Inc.) <==== ATTENTION Windows Live Call (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Communications Platform (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Essentials (Version: 14.0.8050.1202 - Microsoft Corporation) Windows Live Essentials (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Fotogalerie (Version: 14.0.8051.1204 - Microsoft Corporation) Hidden Windows Live Mail (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Messenger (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Sync (Version: 14.0.8050.1202 - Microsoft Corporation) Windows Live Toolbar (Version: 14.0.8052.1208 - Microsoft Corporation) Hidden Windows Live Writer (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live-Uploadtool (Version: 14.0.8014.1029 - Microsoft Corporation) Windows Media Encoder 9 Series (Version: - ) Windows Media Encoder 9 Series (Version: 9.00.3374 - Microsoft Corporation) Hidden Yahoo Community Smartbar (Version: 10.179.66.13636 - Linkury Inc.) <==== ATTENTION Yahoo Community Smartbar Engine (HKCU Version: 10.179.66.13636 - Linkury Inc.) <==== ATTENTION Zattoo 3.3.4 Beta (Version: 3.3.4 Beta - Zattoo Inc.) Zattoo4 4.0.5 (Version: 4.0.5 - Zattoo Inc.) ==================== Restore Points ========================= 10-01-2014 22:23:19 Geplanter Prüfpunkt 14-01-2014 21:25:56 Geplanter Prüfpunkt 16-01-2014 15:00:58 Geplanter Prüfpunkt 17-01-2014 16:44:36 Geplanter Prüfpunkt 24-01-2014 13:29:43 Geplanter Prüfpunkt 30-01-2014 23:40:08 Geplanter Prüfpunkt 31-01-2014 15:18:15 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {4FD8B278-1024-41F6-BA4E-8D7D3EF242C2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-14] (Google Inc.) Task: {6CEC5231-C292-4CDB-9129-C7CF8E11B1CA} - System32\Tasks\SaveSense => C:\Users\Seppi\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {8DEC571A-97A0-416F-B37E-A5275E54456E} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Michael => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation) Task: {995B789E-8327-45B3-BFFA-8B2DFD36AC31} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {9A957BBA-74F5-4CFB-BA51-4C52162D78B4} - System32\Tasks\Google Software Updater => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-21] (Google) Task: {B53A7D6F-CC86-4028-8120-4BEA0262D305} - System32\Tasks\{84F7D839-ED02-4268-91E6-BA8910CD21DB} => C:\Program Files\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.) Task: {BD1AE1AD-2346-4629-8C98-A125EB06364C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-14] (Google Inc.) Task: {CAD2ED30-6D9F-4BCC-9873-FFC6822F68A6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {E8B4B199-B07A-4E79-BB26-77D4BF04FB09} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Seppi => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation) Task: {F3CD334F-2B45-4D35-90B1-5532B0312727} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\SaveSense.job => C:\Users\Seppi\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2009-05-23 03:34 - 2008-12-01 06:42 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service" ==================== Faulty Device Manager Devices ============= Name: Microsoft-ISATAP-Adapter #5 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Microsoft-ISATAP-Adapter #18 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Microsoft-ISATAP-Adapter #23 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: ADS Instant HDTV PCI Description: ADS Instant HDTV PCI Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318} Manufacturer: ADS Technologies Service: Ph3xIB32 Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Cisco Systems VPN Adapter Description: Cisco Systems VPN Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: CVirtA Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (02/02/2014 11:58:47 PM) (Source: ESENT) (User: ) Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (02/02/2014 11:58:47 PM) (Source: ESENT) (User: ) Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (02/02/2014 11:58:47 PM) (Source: ESENT) (User: ) Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (02/02/2014 11:58:47 PM) (Source: ESENT) (User: ) Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (02/02/2014 11:28:47 PM) (Source: ESENT) (User: ) Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (02/02/2014 11:28:47 PM) (Source: ESENT) (User: ) Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (02/02/2014 11:28:47 PM) (Source: ESENT) (User: ) Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (02/02/2014 11:28:47 PM) (Source: ESENT) (User: ) Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (02/02/2014 10:58:47 PM) (Source: ESENT) (User: ) Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (02/02/2014 10:58:47 PM) (Source: ESENT) (User: ) Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. System errors: ============= Error: (02/02/2014 11:56:36 PM) (Source: atapi) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden. Error: (02/02/2014 10:20:25 PM) (Source: atapi) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden. Error: (02/02/2014 06:58:31 PM) (Source: Schannel) (User: ) Description: Eine SSL-Verbindungsanforderung wurde von einer Remoteclientanwendung übermittelt, aber keine der Verschlüsselungssammlungen, die von der Clientanwendung unterstützt werden, werden vom Server unterstützt. Die SSL-Verbindungsanforderung ist fehlgeschlagen. Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: ) Description: Windows Driver Foundation - Benutzermodus-Treiberframework11200001Neustart des Diensts Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: ) Description: Enumeratordienst für tragbare Geräte11200001Neustart des Diensts Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: ) Description: Automatische WLAN-Konfiguration11200001Neustart des Diensts Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: ) Description: Diagnosesystemhost1 Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: ) Description: Sitzungs-Manager für Desktopfenster-Manager11200001Neustart des Diensts Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: ) Description: Überwachung verteilter Verknüpfungen (Client)11200001Neustart des Diensts Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: ) Description: Tablet PC-Eingabedienst1600001Neustart des Diensts Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2014-01-07 23:56:52.183 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\verifier.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-01-07 23:05:38.233 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\verifier.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-08-20 22:48:10.603 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\verifier.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-04 23:30:14.424 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\verifier.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-15 21:43:44.033 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\verifier.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 51% Total physical RAM: 3065.94 MB Available physical RAM: 1490.11 MB Total Pagefile: 6332.91 MB Available Pagefile: 4506.97 MB Total Virtual: 2047.88 MB Available Virtual: 1883.2 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:283.4 GB) (Free:60.46 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:6.25 GB) NTFS Drive g: (Volume) (Fixed) (Total:167.67 GB) (Free:167.58 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 3FBE4D3F) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Not Active) - (Size=15 GB) - (Type=07 NTFS) Partition 3: (Active) - (Size=283 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=168 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
03.02.2014, 00:26 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenprogramme stürzen ab Hast du nen Quick oder Fullscan mit mbam gemacht?
__________________ --> Virenprogramme stürzen ab |
03.02.2014, 00:27 | #7 |
| Virenprogramme stürzen ab Quickscan |
03.02.2014, 00:30 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenprogramme stürzen ab Dann mach dennochmal aber entferne die Funde nicht, damit du ans Log kommst
__________________ Logfiles bitte immer in CODE-Tags posten |
03.02.2014, 00:53 | #9 |
| Virenprogramme stürzen ab Hallo, bin noch da, der hat nur ewig gebraucht...hier die logfile : Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2014.02.02.05 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Seppi :: MICHAEL-PC [administrator] 03.02.2014 00:28:24 MBAM-log-2014-02-03 (00-52-30).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 308392 Time elapsed: 23 minute(s), 50 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 43 C:\Users\Seppi\AppData\Local\Smartbar (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\CSS (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\PublisherImages (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\ar (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\Configs (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\de (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\es (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\fr (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\he (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\helperbar@helperbar.com (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\PublisherImages (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\nl (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\pt (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\it (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\ru (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Application\tr (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Common (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Common\Configs (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Common\icons (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Common\iconsWide (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Common\ServicesPlugins (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\DistributionFiles (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\DistributionFiles\Configs (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\DistributionFiles\Profiles (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\DistributionFiles\RollBack (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\DistributionFiles\RollBack\Profiles (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Smartbar.exe_StrongName_vuedtbpoockmp1sq45awfxuouevabx0i (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Local\Smartbar\Smartbar.exe_StrongName_vuedtbpoockmp1sq45awfxuouevabx0i\10.179.66.13636 (PUP.Optional.SmartBar.A) -> No action taken. C:\Users\Seppi\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> No action taken. C:\Users\Seppi\AppData\Roaming\OpenCandy\BF96F10940144AC6B8B2C9BD208EE2CD (PUP.Optional.OpenCandy) -> No action taken. C:\Users\Seppi\AppData\Roaming\OpenCandy\F78A7195B32E48CA870189C219DE3BBD (PUP.Optional.OpenCandy) -> No action taken. C:\Users\Seppi\AppData\Roaming\SaveSense (PUP.Optional.SaveSense) -> No action taken. C:\Users\Seppi\AppData\Roaming\SaveSense\UpdateProc (PUP.Optional.SaveSense) -> No action taken. C:\Users\Seppi\AppData\Local\SaveSenseLive (PUP.Optional.SaveSense.A) -> No action taken. C:\Users\Seppi\AppData\Local\SaveSenseLive\CrashReports (PUP.Optional.SaveSense.A) -> No action taken. C:\Users\Seppi\AppData\Local\Plus-HD-4.8 (PUP.Optional.PlusHD.A) -> No action taken. Files Detected: 0 (No malicious items detected) (end) |
03.02.2014, 00:55 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenprogramme stürzen ab Scheint nur Adware nur sein, aber lass mal tiefer scannen mit MBAR Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ Logfiles bitte immer in CODE-Tags posten |
03.02.2014, 01:06 | #11 |
| Virenprogramme stürzen ab Hallo, der kann den DDA driver nicht laden...soll ich dann rebooten? |
03.02.2014, 01:09 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenprogramme stürzen ab Wirst du nicht gefragt ob ja oder nein?
__________________ Logfiles bitte immer in CODE-Tags posten |
03.02.2014, 01:10 | #13 |
| Virenprogramme stürzen ab Doch...wollt dich nur nochmal fragen |
03.02.2014, 01:12 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenprogramme stürzen ab Klick auf nein und ohn Reboot scannen lassen
__________________ Logfiles bitte immer in CODE-Tags posten |
03.02.2014, 01:13 | #15 |
| Virenprogramme stürzen ab Nächste Nachricht : Could not install driver on boot. Scan can´t contnue... |
Themen zu Virenprogramme stürzen ab |
adwcleaner, bitte um hilfe, erstell, hijack this, hilfe, installiert, logfile, malwarebytes, programme, pup.optional.opencandy, pup.optional.plushd.a, pup.optional.savesense, pup.optional.savesense.a, pup.optional.smartbar.a, rechner, rechner verlangsamt, stürzen, verlangsamt, viren, virenprogramme, von selber |