Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: http://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=hp&fr=linkury-tb&inst

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 05.02.2014, 18:10   #1
Valli
 
http://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=hp&fr=linkury-tb&inst - Standard

http://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=hp&fr=linkury-tb&inst



Liebes Trojaner-Board-Team,

ich habe seit einigen Tagen Probleme mit meinem Browser. Unter Anderem habe ich die feed.helperbar, die mich stets auf die Yahoo-Startseite weiterleitet.

hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=hp&fr=linkury-tb&installDate=30/01/2014&type=hp1000

Außerdem funktioniert der Flashplayer nicht mehr richtig bzw. gar nicht, es erscheinen ständig Pop-Ups und manche Seiten werden nicht mehr richtig angezeigt.

Ich habe die Checkliste vor dem ersten Post so gut wie möglich abgearbeitet. Leider konnte ich die Datei GMER.txt nicht speichern, da bei dem Klick auf "Save" nur die Möglichkeit bestand, gmer.log zu speichern und man diese Datei auf dem Computer nicht finden konnte, obwohl "File saved successfully" angezeigt wurde. Beim Suchen kam als Suchergebnis nur eine Verknüpfung, die im Nichts endete.

Vielen Dank im Voraus!

Hier die restlichen log-files:

defogger_disable.log
Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 17:07 on 05/02/2014 (User)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-
         

Addition.txt

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 03-02-2014
Ran by User at 2014-02-05 17:11:51
Running from C:\Users\Bernadette\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Acer Backup Manager (Version: 2.0.1.60 - NewTech Infosystems)
Acer Crystal Eye webcam (Version: 1.0.2.0 - Liteon)
Acer ePower Management (Version: 5.00.3004 - Acer Incorporated)
Acer eRecovery Management (Version: 4.05.3011 - Acer Incorporated)
Acer Registration (Version: 1.03.3003 - Acer Incorporated)
Acer ScreenSaver (Version: 1.1.0203.2010 - Acer Incorporated)
Acer Updater (Version: 1.02.3001 - Acer Incorporated)
Acer VCM (Version: 4.05.3002 - Acer Incorporated)
Acrobat.com (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe AIR (Version: 1.5.0.7220 - Adobe Systems Inc.) Hidden
Adobe Flash Player 12 Plugin (Version: 12.0.0.43 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (Version: 11.0.06 - Adobe Systems Incorporated)
Audacity 1.2.6 (Version:  - )
Avira Free Antivirus (Version: 14.0.2.286 - Avira)
Avira SearchFree Toolbar (Version: 12.10.0.2948 - APN, LLC)
Backup Manager Advance (Version: 2.0.1.60 - NewTech Infosystems) Hidden
Bizzybolt (Version: 2014.01.16.002256 - Bizzybolt) <==== ATTENTION
Broadcom Gigabit NetLink Controller (Version: 12.52.04 - Broadcom Corporation)
Cambridge- English Grammar in Use (Version: 100A - Clarity Language Consultants Ltd)
CIB pdf brewer (Version: 2.6.0049 - CIB software GmbH)
Common Desktop Agent (Version: 1.62.0 - OEM) Hidden
eSobi v2 (Version: 2.0.4.000274 - esobi Inc.)
eSobi v2 (Version: 2.0.4.000274 - esobi Inc.) Hidden
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (Version: 7.5.4805.320 - Google Inc.)
Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden
Identity Card (Version: 1.00.3003 - Acer Incorporated)
Intel(R) Graphics Media Accelerator Driver (Version: 8.15.10.2104 - Intel Corporation)
Intel(R) Management Engine Components (Version: 6.0.0.1179 - Intel Corporation)
Intel(R) Rapid Storage Technology (Version: 9.6.2.1001 - Intel Corporation)
InterVideo WinDVD 8 (Version: 8.5.10.75 - InterVideo Inc.)
InterVideo WinDVD 8 (Version: 8.5.10.75 - InterVideo Inc.) Hidden
Java Auto Updater (Version: 2.0.2.4 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 22 (Version: 6.0.220 - Oracle)
Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Launch Manager (Version: 4.0.8 - Acer Inc.)
Lidl-Fotos (Version:  - )
Lollipop (HKCU Version:  - Lollipop Network, S.L.) <==== ATTENTION
MatheGrafix 10 (Version 10.1) (Version:  - )
McAfee Security Scan Plus (Version: 3.8.130.10 - McAfee, Inc.)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Choice Guard (Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Office 2010 (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - Deutsch (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Thunderbird (3.1.10) (Version: 3.1.10 (de) - Mozilla)
MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation)
NTI Backup Now 5 (Version: 5.1.2.628 - NewTech Infosystems)
NTI Backup Now Standard (Version: 5.1.2.628 - NewTech Infosystems) Hidden
NTI Media Maker 8 (Version: 8.0.12.6630 - NewTech Infosystems)
NTI Media Maker 8 (Version: 8.0.12.6630 - NewTech Infosystems) Hidden
OpenOffice.org 3.3 (Version: 3.3.9567 - OpenOffice.org)
PC Speed Repair (Version: 2.4.7 - ShieldApps)
Plus-HD-7.2 (Version: 1.33.153.1 - Plus HD) <==== ATTENTION
QuickTime 3.0 (Version:  - )
Realtek High Definition Audio Driver (Version: 6.0.1.6037 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (Version: 6.1.7600.30118 - Realtek Semiconductor Corp.)
Samsung Easy Printer Manager (Version: 1.02.74.00(06.11.2012) - Samsung Electronics Co., Ltd.)
Samsung ML-2160 Series (Version: 1.10 (22.11.2012) - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (Version: 1.01.00.04 - Samsung Electronics Co., Ltd.)
Skype™ 6.11 (Version: 6.11.102 - Skype Technologies S.A.)
StarOffice 8 (Version: 8.00.8945 - Sun Microsystems)
Synaptics Pointing Device Driver (Version: 14.0.19.0 - Synaptics Incorporated)
Tinypic 3.18 (Version: Tinypic 3.18 - E. Fiedler)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation)
Windows Live Anmelde-Assistent (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Call (Version: 14.0.8064.0206 - Microsoft Corporation) Hidden
Windows Live Communications Platform (Version: 14.0.8064.206 - Microsoft Corporation) Hidden
Windows Live Essentials (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live Essentials (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (Version: 14.0.8081.709 - Microsoft Corporation) Hidden
Windows Live Mail (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Messenger (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Movie Maker (Version: 14.0.8091.0730 - Microsoft Corporation) Hidden
Windows Live Sync (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live Writer (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live-Uploadtool (Version: 14.0.8014.1029 - Microsoft Corporation)
Yahoo Community Smartbar (Version: 10.179.66.13636 - Linkury Inc.) <==== ATTENTION
Yahoo Community Smartbar Engine (HKCU Version: 10.179.66.13636 - Linkury Inc.) <==== ATTENTION

==================== Restore Points  =========================

25-01-2014 07:16:59 Geplanter Prüfpunkt
01-02-2014 13:12:23 Geplanter Prüfpunkt
01-02-2014 17:00:31 TuneUp Utilities 2014 wird entfernt
01-02-2014 17:02:05 TuneUp Utilities 2014 (de-DE) wird entfernt
01-02-2014 17:17:01 eBay Worldwide wird entfernt
02-02-2014 08:41:53 Before PC Speed Repair fix

==================== Hosts content: ==========================

2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {08D1BEAF-F1D5-4022-B13A-5117DEE75372} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-05-18] (Google Inc.)
Task: {25DB627C-8A5E-4653-89F4-455CFDF615D5} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-12-21] (Adobe Systems Incorporated)
Task: {267DA56C-40F9-4101-B3D2-29C5E70A54A6} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14] (Sun Microsystems, Inc.)
Task: {5284B74A-D96B-4564-B68C-2153D7604CB8} - System32\Tasks\PCSpeedRepair_Popup => C:\Program Files\PC Speed Repair\Splash.exe [2014-01-21] ()
Task: {6825B075-172A-4998-AF14-8690A71E7A39} - System32\Tasks\Plus-HD-7.2-firefoxinstaller => C:\Program Files\Plus-HD-7.2\Plus-HD-7.2-firefoxinstaller.exe [2014-01-19] (Plus HD) <==== ATTENTION
Task: {6EAEBE89-9BB7-4F0B-AF12-9AEE293BA519} - System32\Tasks\PCSpeedRepair_Start => C:\Program Files\PC Speed Repair\PCSpeedRepair.exe [2014-01-21] ()
Task: {7EF5E12B-2C6D-4192-9812-1F7FC2FFD617} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {828A9AC2-9E7A-440F-A42D-6A6E4D67A36A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-21] (Adobe Systems Incorporated)
Task: {8CCEAA74-A4E8-4726-9AA7-73D725587108} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-05-18] (Google Inc.)
Task: {9D0091CE-12BA-4727-A593-C58BD8BE32F0} - System32\Tasks\Plus-HD-7.2-codedownloader => C:\Program Files\Plus-HD-7.2\Plus-HD-7.2-codedownloader.exe [2014-01-19] (Plus HD) <==== ATTENTION
Task: {AE99BCCF-996E-40E4-81F7-F971780D77DA} - System32\Tasks\Plus-HD-7.2-chromeinstaller => C:\Program Files\Plus-HD-7.2\Plus-HD-7.2-chromeinstaller.exe [2014-01-19] (Plus HD) <==== ATTENTION
Task: {C876CDEB-079F-4DF8-9C00-FF330C0935F0} - System32\Tasks\Plus-HD-7.2-enabler => C:\Program Files\Plus-HD-7.2\Plus-HD-7.2-enabler.exe [2014-01-19] (Plus HD) <==== ATTENTION
Task: {D6F52085-B18E-43FF-AD6F-0A7E5EE3B51F} - System32\Tasks\Plus-HD-7.2-updater => C:\Program Files\Plus-HD-7.2\Plus-HD-7.2-updater.exe [2014-01-19] (Plus HD) <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Plus-HD-7.2-chromeinstaller.job => C:\Program Files\Plus-HD-7.2\Plus-HD-7.2-chromeinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-7.2-codedownloader.job => C:\Program Files\Plus-HD-7.2\Plus-HD-7.2-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-7.2-enabler.job => C:\Program Files\Plus-HD-7.2\Plus-HD-7.2-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-7.2-firefoxinstaller.job => C:\Program Files\Plus-HD-7.2\Plus-HD-7.2-firefoxinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-7.2-updater.job => C:\Program Files\Plus-HD-7.2\Plus-HD-7.2-updater.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2010-03-09 01:18 - 2010-03-09 01:18 - 00465576 _____ () C:\Program Files\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2010-05-11 06:12 - 2009-05-20 07:02 - 00072200 _____ () C:\Program Files\Launch Manager\CdDirIo.dll
2012-02-20 22:22 - 2012-02-20 22:22 - 00050688 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll
2005-05-17 11:05 - 2005-05-17 11:05 - 00828416 _____ () C:\Program Files\Sun\StarOffice 8\program\libxml2.dll
2014-01-17 17:38 - 2013-12-05 20:36 - 03559024 _____ () C:\Users\Bernadette\AppData\Local\Mozilla Firefox\mozjs.dll
2014-01-21 19:49 - 2014-01-21 19:49 - 16287624 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Users\Bernadette\Documents\Abitur Seite 1.jpeg:3or4kl4x13tuuug3Byamue2s4b
AlternateDataStreams: C:\Users\Bernadette\Documents\Abitur Seite 1.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Bernadette\Documents\Adressenliste.eml:OECustomProperty
AlternateDataStreams: C:\Users\Bernadette\Documents\Linda Abi.eml:OECustomProperty

==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============

Name: Lexmark X422
Description: Lexmark X422
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Lexmark
Service: usbscan
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/02/2014 07:00:04 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "G:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)"

Error: (02/02/2014 05:33:07 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "G:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)"

Error: (02/02/2014 09:41:45 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.


Vorgang:
   Generatordaten werden gesammelt

Kontext:
   Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Generatorname: System Writer
   Generatorinstanz-ID: {dd18c5d0-825d-4ea6-ba29-113169c17240}

Error: (02/01/2014 02:09:44 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (02/01/2014 02:07:22 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (01/31/2014 08:35:07 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005

Error: (01/30/2014 10:45:12 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (01/30/2014 10:42:47 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (01/28/2014 07:50:44 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005

Error: (01/26/2014 07:00:04 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "G:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)"


System errors:
=============
Error: (02/05/2014 05:03:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.

Modulpfad: C:\Windows\system32\athExt.dll
Fehlercode: 126

Error: (02/05/2014 01:40:21 PM) (Source: NetBT) (User: )
Description: Der Name "USER-PC        :0" konnte nicht auf der Schnittstelle mit IP-Adresse 139.20.168.42
registriert werden. Der Computer mit IP-Adresse 139.20.168.64 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.

Error: (02/05/2014 01:38:52 PM) (Source: NetBT) (User: )
Description: Der Name "USER-PC        :20" konnte nicht auf der Schnittstelle mit IP-Adresse 139.20.168.42
registriert werden. Der Computer mit IP-Adresse 139.20.168.64 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.

Error: (02/05/2014 01:38:52 PM) (Source: Server) (User: )
Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{582A743E-C9AF-4DA9-9F0F-A08F14769316} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden.

Error: (02/05/2014 01:38:47 PM) (Source: NetBT) (User: )
Description: Der Name "USER-PC        :0" konnte nicht auf der Schnittstelle mit IP-Adresse 139.20.168.42
registriert werden. Der Computer mit IP-Adresse 139.20.168.64 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.

Error: (02/05/2014 01:38:46 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.

Modulpfad: C:\Windows\system32\athExt.dll
Fehlercode: 126

Error: (02/04/2014 07:55:39 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.

Modulpfad: C:\Windows\system32\athExt.dll
Fehlercode: 126

Error: (02/04/2014 06:58:40 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.

Modulpfad: C:\Windows\system32\athExt.dll
Fehlercode: 126

Error: (02/02/2014 04:52:36 PM) (Source: NetBT) (User: )
Description: Der Name "USER-PC        :0" konnte nicht auf der Schnittstelle mit IP-Adresse 139.20.168.42
registriert werden. Der Computer mit IP-Adresse 139.20.168.64 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.

Error: (02/02/2014 04:51:17 PM) (Source: NetBT) (User: )
Description: Der Name "USER-PC        :20" konnte nicht auf der Schnittstelle mit IP-Adresse 139.20.168.42
registriert werden. Der Computer mit IP-Adresse 139.20.168.64 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.


Microsoft Office Sessions:
=========================
Error: (02/02/2014 07:00:04 PM) (Source: Windows Backup)(User: )
Description: G:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)

Error: (02/02/2014 05:33:07 PM) (Source: Windows Backup)(User: )
Description: G:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)

Error: (02/02/2014 09:41:45 AM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert


Vorgang:
   Generatordaten werden gesammelt

Kontext:
   Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Generatorname: System Writer
   Generatorinstanz-ID: {dd18c5d0-825d-4ea6-ba29-113169c17240}

Error: (02/01/2014 02:09:44 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Samsung\samsung ml-2160 series\Setup\Setup\bin\wiainst64.exe

Error: (02/01/2014 02:07:22 PM) (Source: SideBySide)(User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3

Error: (01/31/2014 08:35:07 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005

Error: (01/30/2014 10:45:12 AM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Samsung\samsung ml-2160 series\Setup\Setup\bin\wiainst64.exe

Error: (01/30/2014 10:42:47 AM) (Source: SideBySide)(User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3

Error: (01/28/2014 07:50:44 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005

Error: (01/26/2014 07:00:04 PM) (Source: Windows Backup)(User: )
Description: G:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)


==================== Memory info =========================== 

Percentage of memory in use: 70%
Total physical RAM: 1782.71 MB
Available physical RAM: 532.73 MB
Total Pagefile: 3565.42 MB
Available Pagefile: 1774.44 MB
Total Virtual: 2047.88 MB
Available Virtual: 1910.15 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:138.95 GB) (Free:42.95 GB) NTFS
Drive d: (DATA) (Fixed) (Total:139.04 GB) (Free:128.81 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D4EE1119)
Partition 1: (Not Active) - (Size=20 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=139 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=139 GB) - (Type=07 NTFS)
 Could not read MBR for disk 1.

==================== End Of Log ============================
         
FRST.txt
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-02-2014
Ran by User (administrator) on USER-PC on 05-02-2014 17:10:07
Running from C:\Users\Bernadette\Downloads
Microsoft Windows 7 Professional  (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ 
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) ===================

(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Registration\GREGsvc.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
() C:\Program Files\Bizzybolt\updateBizzybolt.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
(Sun Microsystems, Inc.) C:\Program Files\Sun\StarOffice 8\program\soffice.exe
(Sun Microsystems, Inc.) C:\Program Files\Sun\StarOffice 8\program\soffice.bin
(Mozilla Corporation) C:\Users\Bernadette\AppData\Local\Mozilla Firefox\firefox.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Mozilla Corporation) C:\Users\Bernadette\AppData\Local\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe
() C:\Program Files\Iminent\WinkHandler.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
() C:\Program Files\Iminent\WinkHandler.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
() C:\Program Files\Bizzybolt\bin\utilBizzybolt.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
() C:\Users\Bernadette\Downloads\Defogger.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation)
HKLM\...\Run: [BackupManagerTray] - C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [260608 2010-03-09] (NewTech Infosystems, Inc.)
HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [908368 2010-04-08] (Dritek System Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1594664 2009-12-10] (Synaptics Incorporated)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8493600 2010-01-29] (Realtek Semiconductor)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [715296 2010-04-23] (Acer Incorporated)
HKLM\...\Run: [CDAServer] - C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [344064 2012-02-20] ()
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2014-01-20] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2522381907-3901972495-1069497290-1000\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-2522381907-3901972495-1069497290-1000\...\Run: [lollipop] - lollipop
HKU\S-1-5-21-2522381907-3901972495-1069497290-1000\...\Run: [Browser Infrastructure Helper] - C:\Users\User\AppData\Local\Smartbar\Application\Smartbar.exe [20760 2013-11-21] (Smartbar)
HKU\S-1-5-21-2522381907-3901972495-1069497290-1000\...\MountPoints2: {f3aa2995-c01d-11df-a358-806e6f6e6963} - E:\.\AutorunX\AutorunX.exe
HKU\S-1-5-21-2522381907-3901972495-1069497290-1002\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-11] (Google Inc.)
HKU\S-1-5-21-2522381907-3901972495-1069497290-1002\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2522381907-3901972495-1069497290-1002\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-2522381907-3901972495-1069497290-1002\...\MountPoints2: {7230bb49-ad08-11e2-b20d-e7f974c889b0} - G:\iLinker.exe
HKU\S-1-5-21-2522381907-3901972495-1069497290-1002\...\MountPoints2: {d351d142-eaff-11e1-ba9b-c8084af98d55} - G:\LaunchU3.exe -a
Startup: C:\Users\Bernadette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StarOffice 8.lnk
ShortcutTarget: StarOffice 8.lnk -> C:\Program Files\Sun\StarOffice 8\program\quickstart.exe ()
Startup: C:\Users\JKelemen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StarOffice 8.lnk
ShortcutTarget: StarOffice 8.lnk -> C:\Program Files\Sun\StarOffice 8\program\quickstart.exe ()
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PricePeepUpdater.lnk
ShortcutTarget: PricePeepUpdater.lnk -> C:\Program Files\PricePeep\PricePeepUpdater.exe (No File)
Startup: C:\Users\Valerie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StarOffice 8.lnk
ShortcutTarget: StarOffice 8.lnk -> C:\Programme\Sun\StarOffice 8\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=hp&fr=linkury-tb&installDate=30/01/2014&type=hp1000
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=travelmate_5740&r=27050411l325l0474z275x5762m69q
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=30/01/2014&type=hp1000
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=30/01/2014&type=hp1000
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=travelmate_5740&r=27050411l325l0474z275x5762m69q
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=travelmate_5740&r=27050411l325l0474z275x5762m69q
SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=30/01/2014&type=hp1000
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=30/01/2014&type=hp1000
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Plus-HD-7.2 - {11111111-1111-1111-1111-110411921194} - C:\Program Files\Plus-HD-7.2\Plus-HD-7.2-bho.dll (Plus HD)
BHO: Yahoo Community Smartbar (by Linkury)Engine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} -  No File
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: No Name - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -  No File
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} -  No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - No Name - {1FAFD711-ABF9-4F6A-8130-5166C7371427} -  No File
Toolbar: HKLM - Yahoo Community Smartbar (by Linkury) - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 139.20.165.230 8.8.8.8

FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1yjrfl80.default
FF NewTab: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=nt&fr=linkury-tb&installDate=30/01/2014&type=hp1000&q=
FF SelectedSearchEngine: Web Search
FF Homepage: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=hp&fr=linkury-tb&installDate=30/01/2014&type=hp1000
FF Keyword.URL: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=ds&fr=linkury-tb&installDate=30/01/2014&type=hp1000&p=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1yjrfl80.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\SearchTheWeb.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\StartWeb.xml
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2011-05-15]

========================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2014-01-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2014-01-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1011768 2014-01-20] (Avira Operations GmbH & Co. KG)
R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [735776 2010-04-23] (Acer Incorporated)
R2 GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [235216 2013-09-06] (McAfee, Inc.)
R2 NTI IScheduleSvc; C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [250368 2010-03-09] (NewTech Infosystems, Inc.)
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144640 2009-11-06] (NewTech Infosystems, Inc.)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
R2 Update Bizzybolt; C:\Program Files\Bizzybolt\updateBizzybolt.exe [103200 2014-01-30] ()
R2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group)
R2 Util Bizzybolt; C:\Program Files\Bizzybolt\bin\utilBizzybolt.exe [80160 2014-02-05] ()
R2 WinkHandler; C:\Program Files\Iminent\WinkHandler.exe [425792 2014-01-07] ()
S2 APNMCP; "C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe" [X]

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2014-01-20] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2014-01-20] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-01-20] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [69240 2014-01-20] (Avira Operations GmbH & Co. KG)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-01-20] (Avira GmbH)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-05 17:10 - 2014-02-05 17:11 - 00016741 _____ () C:\Users\Bernadette\Downloads\FRST.txt
2014-02-05 17:09 - 2014-02-05 17:10 - 00000000 ____D () C:\FRST
2014-02-05 17:08 - 2014-02-05 17:08 - 01137152 _____ (Farbar) C:\Users\Bernadette\Downloads\FRST.exe
2014-02-05 17:07 - 2014-02-05 17:07 - 00000470 _____ () C:\Users\Bernadette\Downloads\defogger_disable.log
2014-02-05 17:07 - 2014-02-05 17:07 - 00000000 _____ () C:\Users\User\defogger_reenable
2014-02-05 17:06 - 2014-02-05 17:06 - 00050477 _____ () C:\Users\Bernadette\Downloads\Defogger.exe
2014-02-02 09:39 - 2014-02-02 09:39 - 00000000 ____D () C:\Users\User\AppData\Local\PCSpeedRepair
2014-02-02 09:38 - 2014-02-02 09:43 - 00000000 ____D () C:\Users\User\Documents\PCSpeedRepair
2014-02-02 09:38 - 2014-02-02 09:38 - 00000973 _____ () C:\Users\Public\Desktop\PCSpeedRepair.lnk
2014-02-02 09:38 - 2014-02-02 09:38 - 00000000 __SHD () C:\Windows\system32\AI_RecycleBin
2014-02-02 09:38 - 2014-02-02 09:38 - 00000000 ____D () C:\Program Files\PC Speed Repair
2014-02-02 09:37 - 2014-02-02 09:37 - 05347320 _____ (ShieldApps) C:\Users\Bernadette\Downloads\PCSpeedRepairSetup.exe
2014-02-01 17:53 - 2014-02-01 17:53 - 04960768 _____ (Systweak Inc ) C:\Users\Bernadette\Downloads\regclean_my582531(1).exe
2014-02-01 17:53 - 2014-02-01 17:53 - 00319888 _____ () C:\Users\Bernadette\Downloads\Setup(2).exe
2014-02-01 15:01 - 2014-02-01 15:01 - 04960768 _____ (Systweak Inc ) C:\Users\Bernadette\Downloads\regclean_my582531.exe
2014-02-01 15:01 - 2014-02-01 15:01 - 00319888 _____ () C:\Users\Bernadette\Downloads\Setup(1).exe
2014-01-30 21:39 - 2014-01-30 21:39 - 00000000 ____D () C:\Users\Bernadette\AppData\Roaming\TuneUp Software
2014-01-30 21:33 - 2014-01-30 21:33 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-01-30 21:33 - 2014-01-30 21:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\TuneUp Software
2014-01-30 21:33 - 2014-01-30 21:33 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-01-30 21:32 - 2014-01-30 21:32 - 00002342 _____ () C:\Users\User\Desktop\Search.lnk
2014-01-30 21:32 - 2014-01-30 21:32 - 00000000 ____D () C:\Users\User\AppData\Local\Macromedia
2014-01-30 21:31 - 2014-01-30 21:32 - 00000000 ____D () C:\Users\User\AppData\Local\Smartbar
2014-01-30 21:31 - 2014-01-30 21:31 - 00000000 ____D () C:\Users\Bernadette\Documents\DVDVideoSoft
2014-01-30 21:31 - 2014-01-30 21:31 - 00000000 ____D () C:\Users\Bernadette\AppData\Roaming\DVDVideoSoft
2014-01-30 21:30 - 2014-02-01 17:59 - 00000000 ____D () C:\Users\User\AppData\Roaming\DVDVideoSoft
2014-01-30 21:30 - 2014-01-30 21:30 - 00000000 ____D () C:\Users\User\AppData\Roaming\OpenCandy
2014-01-30 21:30 - 2014-01-30 21:30 - 00000000 ____D () C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers
2014-01-30 21:29 - 2014-01-30 21:29 - 32132232 _____ (DVDVideoSoft Ltd. ) C:\Users\Bernadette\Desktop\FreeYouTubeToMP3Converter.exe
2014-01-30 21:27 - 2014-01-30 21:27 - 00401784 _____ (Softonic ) C:\Users\Bernadette\Downloads\SoftonicDownloader_fuer_free-youtube-to-mp3-converter.exe
2014-01-30 21:26 - 2014-01-30 21:26 - 00319888 _____ () C:\Users\Bernadette\Downloads\Setup.exe
2014-01-21 19:50 - 2014-01-21 19:50 - 00000000 ____D () C:\Users\Bernadette\AppData\Local\Macromedia
2014-01-21 19:49 - 2014-02-04 20:13 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-21 19:49 - 2014-01-21 19:49 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-01-21 19:49 - 2014-01-21 19:49 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-01-20 18:32 - 2014-01-20 18:32 - 00000000 ____D () C:\Users\Bernadette\AppData\Roaming\Avira
2014-01-20 18:31 - 2014-01-20 18:31 - 00001944 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-01-20 18:31 - 2014-01-20 18:24 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-01-20 18:31 - 2014-01-20 18:24 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-01-20 18:31 - 2014-01-20 18:24 - 00069240 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-01-20 18:31 - 2014-01-20 18:24 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-01-20 18:31 - 2014-01-20 18:24 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2014-01-20 18:30 - 2014-01-20 18:30 - 00000000 ____D () C:\Program Files\Avira
2014-01-19 12:03 - 2014-01-19 12:03 - 00002678 _____ () C:\Users\Bernadette\Documents\Mein Film.wlmp
2014-01-19 11:33 - 2014-02-05 17:03 - 00001314 _____ () C:\Windows\Tasks\Plus-HD-7.2-updater.job
2014-01-19 11:33 - 2014-02-05 17:03 - 00001266 _____ () C:\Windows\Tasks\Plus-HD-7.2-codedownloader.job
2014-01-19 11:33 - 2014-02-05 17:03 - 00001138 _____ () C:\Windows\Tasks\Plus-HD-7.2-enabler.job
2014-01-19 11:33 - 2014-01-21 18:17 - 00000000 ____D () C:\Program Files\Bizzybolt
2014-01-19 11:32 - 2014-02-05 17:03 - 00002100 _____ () C:\Windows\Tasks\Plus-HD-7.2-firefoxinstaller.job
2014-01-19 11:32 - 2014-02-05 17:03 - 00002088 _____ () C:\Windows\Tasks\Plus-HD-7.2-chromeinstaller.job
2014-01-19 11:32 - 2014-01-30 21:39 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-19 11:32 - 2014-01-30 21:39 - 00000000 ____D () C:\Users\User\AppData\Local\Lollipop
2014-01-19 11:32 - 2014-01-30 21:32 - 00000000 ____D () C:\Program Files\Iminent
2014-01-19 11:32 - 2014-01-30 21:32 - 00000000 ____D () C:\Program Files\Common Files\Umbrella
2014-01-19 11:32 - 2014-01-19 11:33 - 97243424 _____ () C:\Users\User\Desktop\avira_free_antivirus_de.exe
2014-01-19 11:32 - 2014-01-19 11:33 - 00000000 ____D () C:\Program Files\Plus-HD-7.2
2014-01-19 11:31 - 2014-01-19 11:31 - 00205168 _____ (Setup Process (r)) C:\Users\Bernadette\Downloads\Avira%20AntiVir%20Personal%20-%20Free%20Antivirus.exe
2014-01-19 11:30 - 2014-01-19 11:30 - 04435768 _____ (AVG Technologies) C:\Users\Bernadette\Downloads\avg_avct_stb_all_2014_4259_cm10.exe
2014-01-19 11:27 - 2014-01-19 11:57 - 00002016 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2014-01-19 11:27 - 2014-01-19 11:57 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-01-19 11:27 - 2014-01-19 11:27 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-01-19 11:26 - 2014-01-19 11:26 - 00001993 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-01-19 11:24 - 2014-01-19 11:24 - 01069920 _____ (Solid State Networks) C:\Users\Bernadette\Downloads\install_reader11_de_mssa_aaa_aih(1).exe
2014-01-18 19:09 - 2014-01-18 19:09 - 39546315 _____ () C:\Users\Bernadette\Downloads\null.zip
2014-01-18 10:15 - 2014-01-18 10:16 - 00283096 _____ (Mozilla) C:\Users\Bernadette\Downloads\Firefox Setup Stub 26.0(1).exe
2014-01-17 17:40 - 2014-01-17 17:40 - 01069920 _____ (Solid State Networks) C:\Users\Bernadette\Downloads\install_reader11_de_mssd_aaa_aih.exe
2014-01-17 17:38 - 2014-01-18 10:16 - 00001218 _____ () C:\Users\Bernadette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-01-17 17:38 - 2014-01-18 10:16 - 00001210 _____ () C:\Users\Bernadette\Desktop\Mozilla Firefox.lnk
2014-01-17 17:38 - 2014-01-18 10:16 - 00000000 ____D () C:\Users\Bernadette\AppData\Local\Mozilla Firefox
2014-01-17 17:37 - 2014-01-17 17:37 - 00283096 _____ (Mozilla) C:\Users\Bernadette\Downloads\Firefox Setup Stub 26.0.exe
2014-01-16 16:25 - 2014-01-16 16:28 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-16 16:25 - 2014-01-06 16:20 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-13 07:34 - 2014-01-13 07:34 - 00819160 _____ (Google Inc.) C:\Users\Bernadette\Downloads\GoogleEarthPluginSetup.exe
2014-01-07 13:28 - 2014-01-07 13:28 - 04113014 _____ () C:\Users\Bernadette\Desktop\Tutorium.zip
2014-01-07 13:28 - 2014-01-07 13:28 - 04111473 ____R () C:\Users\Bernadette\Desktop\Aufgaben_alteKlausuren.zip

==================== One Month Modified Files and Folders =======

2014-02-05 17:11 - 2014-02-05 17:10 - 00016741 _____ () C:\Users\Bernadette\Downloads\FRST.txt
2014-02-05 17:10 - 2014-02-05 17:09 - 00000000 ____D () C:\FRST
2014-02-05 17:08 - 2014-02-05 17:08 - 01137152 _____ (Farbar) C:\Users\Bernadette\Downloads\FRST.exe
2014-02-05 17:07 - 2014-02-05 17:07 - 00000470 _____ () C:\Users\Bernadette\Downloads\defogger_disable.log
2014-02-05 17:07 - 2014-02-05 17:07 - 00000000 _____ () C:\Users\User\defogger_reenable
2014-02-05 17:07 - 2010-09-14 17:38 - 01174331 _____ () C:\Windows\WindowsUpdate.log
2014-02-05 17:06 - 2014-02-05 17:06 - 00050477 _____ () C:\Users\Bernadette\Downloads\Defogger.exe
2014-02-05 17:03 - 2014-01-19 11:33 - 00001314 _____ () C:\Windows\Tasks\Plus-HD-7.2-updater.job
2014-02-05 17:03 - 2014-01-19 11:33 - 00001266 _____ () C:\Windows\Tasks\Plus-HD-7.2-codedownloader.job
2014-02-05 17:03 - 2014-01-19 11:33 - 00001138 _____ () C:\Windows\Tasks\Plus-HD-7.2-enabler.job
2014-02-05 17:03 - 2014-01-19 11:32 - 00002100 _____ () C:\Windows\Tasks\Plus-HD-7.2-firefoxinstaller.job
2014-02-05 17:03 - 2014-01-19 11:32 - 00002088 _____ () C:\Windows\Tasks\Plus-HD-7.2-chromeinstaller.job
2014-02-05 17:03 - 2011-05-18 17:50 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-05 17:03 - 2011-04-05 17:27 - 00000000 ____D () C:\Users\Bernadette\AppData\Roaming\StarOffice8
2014-02-05 17:03 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-05 17:03 - 2009-07-14 05:39 - 00206660 _____ () C:\Windows\setupact.log
2014-02-05 13:48 - 2009-07-14 05:34 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-05 13:48 - 2009-07-14 05:34 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-05 13:45 - 2011-05-18 17:50 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-04 20:41 - 2012-07-29 16:18 - 00000000 ____D () C:\Users\Bernadette\AppData\Roaming\Skype
2014-02-04 20:13 - 2014-01-21 19:49 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-02 09:43 - 2014-02-02 09:38 - 00000000 ____D () C:\Users\User\Documents\PCSpeedRepair
2014-02-02 09:39 - 2014-02-02 09:39 - 00000000 ____D () C:\Users\User\AppData\Local\PCSpeedRepair
2014-02-02 09:38 - 2014-02-02 09:38 - 00000973 _____ () C:\Users\Public\Desktop\PCSpeedRepair.lnk
2014-02-02 09:38 - 2014-02-02 09:38 - 00000000 __SHD () C:\Windows\system32\AI_RecycleBin
2014-02-02 09:38 - 2014-02-02 09:38 - 00000000 ____D () C:\Program Files\PC Speed Repair
2014-02-02 09:37 - 2014-02-02 09:37 - 05347320 _____ (ShieldApps) C:\Users\Bernadette\Downloads\PCSpeedRepairSetup.exe
2014-02-01 18:27 - 2010-09-14 17:34 - 00120330 _____ () C:\Windows\PFRO.log
2014-02-01 18:22 - 2011-04-05 17:58 - 00000000 ____D () C:\Users\User\AppData\Local\Google
2014-02-01 18:20 - 2011-04-05 13:03 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-01 18:19 - 2011-04-05 17:23 - 00000000 ____D () C:\Program Files\MatheGrafix
2014-02-01 18:16 - 2012-04-23 14:56 - 00001924 _____ () C:\Windows\wininit.ini
2014-02-01 18:16 - 2012-04-23 14:56 - 00000000 ____D () C:\Users\Bernadette\AppData\Roaming\Dropbox
2014-02-01 18:13 - 2012-04-23 15:15 - 00000000 ___RD () C:\Users\Bernadette\Dropbox
2014-02-01 17:59 - 2014-01-30 21:30 - 00000000 ____D () C:\Users\User\AppData\Roaming\DVDVideoSoft
2014-02-01 17:53 - 2014-02-01 17:53 - 04960768 _____ (Systweak Inc ) C:\Users\Bernadette\Downloads\regclean_my582531(1).exe
2014-02-01 17:53 - 2014-02-01 17:53 - 00319888 _____ () C:\Users\Bernadette\Downloads\Setup(2).exe
2014-02-01 15:01 - 2014-02-01 15:01 - 04960768 _____ (Systweak Inc ) C:\Users\Bernadette\Downloads\regclean_my582531.exe
2014-02-01 15:01 - 2014-02-01 15:01 - 00319888 _____ () C:\Users\Bernadette\Downloads\Setup(1).exe
2014-01-31 20:14 - 2011-04-05 16:54 - 00000000 ____D () C:\Users\Bernadette\AppData\Local\VirtualStore
2014-01-30 21:39 - 2014-01-30 21:39 - 00000000 ____D () C:\Users\Bernadette\AppData\Roaming\TuneUp Software
2014-01-30 21:39 - 2014-01-19 11:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-30 21:39 - 2014-01-19 11:32 - 00000000 ____D () C:\Users\User\AppData\Local\Lollipop
2014-01-30 21:33 - 2014-01-30 21:33 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-01-30 21:33 - 2014-01-30 21:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\TuneUp Software
2014-01-30 21:33 - 2014-01-30 21:33 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-01-30 21:32 - 2014-01-30 21:32 - 00002342 _____ () C:\Users\User\Desktop\Search.lnk
2014-01-30 21:32 - 2014-01-30 21:32 - 00000000 ____D () C:\Users\User\AppData\Local\Macromedia
2014-01-30 21:32 - 2014-01-30 21:31 - 00000000 ____D () C:\Users\User\AppData\Local\Smartbar
2014-01-30 21:32 - 2014-01-19 11:32 - 00000000 ____D () C:\Program Files\Iminent
2014-01-30 21:32 - 2014-01-19 11:32 - 00000000 ____D () C:\Program Files\Common Files\Umbrella
2014-01-30 21:31 - 2014-01-30 21:31 - 00000000 ____D () C:\Users\Bernadette\Documents\DVDVideoSoft
2014-01-30 21:31 - 2014-01-30 21:31 - 00000000 ____D () C:\Users\Bernadette\AppData\Roaming\DVDVideoSoft
2014-01-30 21:30 - 2014-01-30 21:30 - 00000000 ____D () C:\Users\User\AppData\Roaming\OpenCandy
2014-01-30 21:30 - 2014-01-30 21:30 - 00000000 ____D () C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers
2014-01-30 21:29 - 2014-01-30 21:29 - 32132232 _____ (DVDVideoSoft Ltd. ) C:\Users\Bernadette\Desktop\FreeYouTubeToMP3Converter.exe
2014-01-30 21:27 - 2014-01-30 21:27 - 00401784 _____ (Softonic ) C:\Users\Bernadette\Downloads\SoftonicDownloader_fuer_free-youtube-to-mp3-converter.exe
2014-01-30 21:27 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2014-01-30 21:26 - 2014-01-30 21:26 - 00319888 _____ () C:\Users\Bernadette\Downloads\Setup.exe
2014-01-22 08:00 - 2011-04-05 16:57 - 00000000 ____D () C:\Users\Bernadette\AppData\Roaming\Adobe
2014-01-21 19:50 - 2014-01-21 19:50 - 00000000 ____D () C:\Users\Bernadette\AppData\Local\Macromedia
2014-01-21 19:49 - 2014-01-21 19:49 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-01-21 19:49 - 2014-01-21 19:49 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-01-21 19:48 - 2011-04-05 13:17 - 00000000 ____D () C:\Users\User\AppData\Local\Adobe
2014-01-21 18:17 - 2014-01-19 11:33 - 00000000 ____D () C:\Program Files\Bizzybolt
2014-01-20 18:32 - 2014-01-20 18:32 - 00000000 ____D () C:\Users\Bernadette\AppData\Roaming\Avira
2014-01-20 18:31 - 2014-01-20 18:31 - 00001944 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-01-20 18:30 - 2014-01-20 18:30 - 00000000 ____D () C:\Program Files\Avira
2014-01-20 18:30 - 2013-08-02 08:39 - 00000000 ____D () C:\ProgramData\Avira
2014-01-20 18:24 - 2014-01-20 18:31 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-01-20 18:24 - 2014-01-20 18:31 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-01-20 18:24 - 2014-01-20 18:31 - 00069240 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-01-20 18:24 - 2014-01-20 18:31 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-01-20 18:24 - 2014-01-20 18:31 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2014-01-19 12:03 - 2014-01-19 12:03 - 00002678 _____ () C:\Users\Bernadette\Documents\Mein Film.wlmp
2014-01-19 11:57 - 2014-01-19 11:27 - 00002016 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2014-01-19 11:57 - 2014-01-19 11:27 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-01-19 11:33 - 2014-01-19 11:32 - 97243424 _____ () C:\Users\User\Desktop\avira_free_antivirus_de.exe
2014-01-19 11:33 - 2014-01-19 11:32 - 00000000 ____D () C:\Program Files\Plus-HD-7.2
2014-01-19 11:32 - 2011-04-05 12:50 - 00075056 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-19 11:31 - 2014-01-19 11:31 - 00205168 _____ (Setup Process (r)) C:\Users\Bernadette\Downloads\Avira%20AntiVir%20Personal%20-%20Free%20Antivirus.exe
2014-01-19 11:30 - 2014-01-19 11:30 - 04435768 _____ (AVG Technologies) C:\Users\Bernadette\Downloads\avg_avct_stb_all_2014_4259_cm10.exe
2014-01-19 11:27 - 2014-01-19 11:27 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-01-19 11:27 - 2010-05-11 05:45 - 00000000 ____D () C:\ProgramData\McAfee
2014-01-19 11:26 - 2014-01-19 11:26 - 00001993 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-01-19 11:26 - 2010-05-11 05:53 - 00000000 ____D () C:\ProgramData\Adobe
2014-01-19 11:26 - 2010-05-11 05:53 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-01-19 11:26 - 2010-05-11 05:53 - 00000000 ____D () C:\Program Files\Adobe
2014-01-19 11:24 - 2014-01-19 11:24 - 01069920 _____ (Solid State Networks) C:\Users\Bernadette\Downloads\install_reader11_de_mssa_aaa_aih(1).exe
2014-01-18 19:53 - 2010-05-11 05:29 - 01500294 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-01-18 19:09 - 2014-01-18 19:09 - 39546315 _____ () C:\Users\Bernadette\Downloads\null.zip
2014-01-18 10:16 - 2014-01-18 10:15 - 00283096 _____ (Mozilla) C:\Users\Bernadette\Downloads\Firefox Setup Stub 26.0(1).exe
2014-01-18 10:16 - 2014-01-17 17:38 - 00001218 _____ () C:\Users\Bernadette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-01-18 10:16 - 2014-01-17 17:38 - 00001210 _____ () C:\Users\Bernadette\Desktop\Mozilla Firefox.lnk
2014-01-18 10:16 - 2014-01-17 17:38 - 00000000 ____D () C:\Users\Bernadette\AppData\Local\Mozilla Firefox
2014-01-18 10:13 - 2011-04-05 17:23 - 00000000 ____D () C:\Users\Bernadette\AppData\Local\Google
2014-01-17 17:40 - 2014-01-17 17:40 - 01069920 _____ (Solid State Networks) C:\Users\Bernadette\Downloads\install_reader11_de_mssd_aaa_aih.exe
2014-01-17 17:38 - 2011-04-05 17:23 - 00000000 ____D () C:\Users\Bernadette\AppData\Local\Mozilla
2014-01-17 17:37 - 2014-01-17 17:37 - 00283096 _____ (Mozilla) C:\Users\Bernadette\Downloads\Firefox Setup Stub 26.0.exe
2014-01-16 16:28 - 2014-01-16 16:25 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-13 07:34 - 2014-01-13 07:34 - 00819160 _____ (Google Inc.) C:\Users\Bernadette\Downloads\GoogleEarthPluginSetup.exe
2014-01-10 16:54 - 2013-08-02 15:14 - 00000000 ___RD () C:\Program Files\Skype
2014-01-10 16:54 - 2012-07-16 14:04 - 00000000 ____D () C:\ProgramData\Skype
2014-01-09 19:35 - 2011-06-22 11:11 - 00000000 ____D () C:\Users\Bernadette\Documents\Studium
2014-01-07 13:28 - 2014-01-07 13:28 - 04113014 _____ () C:\Users\Bernadette\Desktop\Tutorium.zip
2014-01-07 13:28 - 2014-01-07 13:28 - 04111473 ____R () C:\Users\Bernadette\Desktop\Aufgaben_alteKlausuren.zip
2014-01-06 16:20 - 2014-01-16 16:25 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Some content of TEMP:
====================
C:\Users\Bernadette\AppData\Local\Temp\AskSLib.dll
C:\Users\Bernadette\AppData\Local\Temp\avgnt.exe
C:\Users\Bernadette\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Bernadette\AppData\Local\Temp\{C0983E17-76BE-481C-A835-48523C8634EE}-GoogleUpdateSetup.exe
C:\Users\Bernadette\AppData\Local\Temp\{FFAC364F-217F-4797-87D3-ED55E7F017B3}-GoogleToolbarInstaller_updater_signed.exe
C:\Users\Gast\AppData\Local\Temp\AskSLib.dll
C:\Users\JKelemen\AppData\Local\Temp\AskSLib.dll
C:\Users\JKelemen\AppData\Local\Temp\uq94zibl.dll
C:\Users\User\AppData\Local\Temp\AskSLib.dll
C:\Users\User\AppData\Local\Temp\umbrella.exe
C:\Users\Valerie\AppData\Local\Temp\AskSLib.dll


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-30 10:40

==================== End Of Log ============================
         

 

Themen zu http://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=hp&fr=linkury-tb&inst
adobe, antivirus, avira, checkliste, computer, defender, desktop, device driver, dvdvideosoft ltd., ebay, error, failed, flash player, gmer.log, internet, internet explorer, lollipop network, netzwerk, newtab, popup, registry, rundll, scan, security, server, services.exe, smartbar, software, svchost.exe, temp, usb, windows




Ähnliche Themen: http://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=hp&fr=linkury-tb&inst


  1. feed.safefinder.com entfernen und System auf Viren überprüfen
    Log-Analyse und Auswertung - 20.09.2014 (12)
  2. Windows 8 - Web Browser wird umgeleitet auf http://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&
    Log-Analyse und Auswertung - 09.05.2014 (7)
  3. WIN 8 feed.helperbar.com wird ständig aufgerufen
    Log-Analyse und Auswertung - 03.05.2014 (9)
  4. www.feed.plusnetwork.com ändert die websiten startseite immer um -.-*
    Plagegeister aller Art und deren Bekämpfung - 02.04.2014 (24)
  5. Grafikprogramm Picture Publisher 10 installieren
    Alles rund um Windows - 28.02.2014 (10)
  6. Microsoft Security Essentials meldet Fund: C:\Users\Eric\AppData\Local\lollipop\ und Browser zeigt: feed.helperbar.com
    Log-Analyse und Auswertung - 09.02.2014 (7)
  7. Trojaner yelp helperbar
    Log-Analyse und Auswertung - 24.01.2014 (9)
  8. redirecting auf yahoo Seite, wie bekomme ich die feed.helperbar los?
    Log-Analyse und Auswertung - 28.07.2013 (11)
  9. Feed.Helperbar Redirect Suchmaschine
    Log-Analyse und Auswertung - 15.02.2013 (7)
  10. http://www.searchnu.com/413?tag=newtab nac Inst. einiger Freeware für Filme
    Plagegeister aller Art und deren Bekämpfung - 11.08.2012 (9)
  11. Publisher-Kalender
    Alles rund um Windows - 30.12.2010 (0)
  12. the feed yard.com i brauch eure HILFE
    Plagegeister aller Art und deren Bekämpfung - 18.10.2009 (4)
  13. RSS-Feed erstellen
    Alles rund um Windows - 21.09.2009 (1)
  14. Publisher in PDF umwandeln
    Alles rund um Windows - 10.11.2008 (7)
  15. Fehler beim Inst von Antivir ! Ist das evt ein Virus ??
    Plagegeister aller Art und deren Bekämpfung - 17.10.2008 (4)
  16. Rechner neu inst., jetzt svchost.exe bei 99% Auslastung..
    Log-Analyse und Auswertung - 30.01.2007 (3)
  17. inst.exe
    Log-Analyse und Auswertung - 04.04.2005 (9)

Zum Thema http://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=hp&fr=linkury-tb&inst - Liebes Trojaner-Board-Team, ich habe seit einigen Tagen Probleme mit meinem Browser. Unter Anderem habe ich die feed.helperbar, die mich stets auf die Yahoo-Startseite weiterleitet. hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=hp&fr=linkury-tb&installDate=30/01/2014&type=hp1000 Außerdem funktioniert der Flashplayer nicht - http://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=hp&fr=linkury-tb&inst...
Archiv
Du betrachtest: http://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2baf921b-53df-f097-697f-d2eed28fec4b&searchtype=hp&fr=linkury-tb&inst auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.