|
Plagegeister aller Art und deren Bekämpfung: Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallierenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.02.2014, 00:29 | #1 |
| Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallieren Hallo, ich habe schon seit längerem ein paar kleinere Probleme mit meinem Windows 7, die ich aber bisher ignoriert habe, da sie mich nicht großartig eingeschränkt haben. Zunächst fing es an, als ich in den Windows/Fonts Ordner eine neue Schriftart einfügen wollte. "Dieses Programm kann nicht ausgeführt werden Mit der angegebenen Datei ist bereits ein Benachrichtigungs GUID verknüpft." Die gleiche Meldung tauchte dann auch ab, als ich ein Windows Update installieren wollte. Mittlerweile ist es soweit, dass ich nichts mehr installieren/oder deinstallieren kann. Es kommt jedes mal die Meldung: "C:/Users/...(Pfad zur .exe die ausgeführt werden soll) Dateisystemfehler (-1073741515)" Kann daher auch keine der hier empfohlenen Programme installieren. Ich wollte vorhin meine Festplatte mit der Windows Fehlerüberprüfung abchecken, aber nach einem Klick auf dem Button geschah gar nichts. Avira habe ich bereits durchlaufen lassen, es wurde nichts gefunden. Allerdings kann ich den Scan nicht als Admin ausführen, es erscheint wieder der "Dateisystemfehler" Logfiles von HijackThis wollt ihr zwar nicht mehr sehen, aber ich habs gerade einfach mal testen lassen und es kam öfters eine Meldung wie diese: "Der angebliche Systemprozess läuft nicht im System32 Ordner und ist deshalb als schädlich einzustufen. Dieser Dienst (lsass.exe) scheint schädlich zu sein. Prozess läuft nicht im System32 Ordner!" Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 - Unknown - C:\Windows\system32\lsass.exe (file missing) |
09.02.2014, 08:09 | #2 |
/// the machine /// TB-Ausbilder | Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallieren hi,
__________________Suchlauf mit rKill Bitte lade dir rKill von Grinler auf deinen Desktop von einem der folgenden Links: RKill oder http://www.trojaner-board.de/85629-rkill-download.html
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
09.02.2014, 13:37 | #3 |
| Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallierenCode:
ATTFilter Rkill 2.6.5 by Lawrence Abrams (Grinler) hxxp://www.bleepingcomputer.com/ Copyright 2008-2014 BleepingComputer.com More Information about Rkill can be found at this link: hxxp://www.bleepingcomputer.com/forums/topic308364.html Program started at: 02/09/2014 01:04:06 PM in x64 mode. (Safe Mode) Windows Version: Windows 7 Home Premium Service Pack 1 Checking for Windows services to stop: * No malware services found to stop. Checking for processes to terminate: * No malware processes found to kill. Checking Registry for malware related settings: * No issues found in the Registry. Resetting .EXE, .COM, & .BAT associations in the Windows Registry. Performing miscellaneous checks: * Windows Defender Disabled [HKLM\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware" = dword:00000001 Checking Windows Service Integrity: * COM+-Ereignissystem (EventSystem) is not Running. Startup Type set to: Automatic * Windows Defender (WinDefend) is not Running. Startup Type set to: Manual * Sicherheitscenter (wscsvc) is not Running. Startup Type set to: Automatic (Delayed Start) * Windows Update (wuauserv) is not Running. Startup Type set to: Automatic (Delayed Start) Searching for Missing Digital Signatures: * No issues found. Checking HOSTS File: * No issues found. Program finished at: 02/09/2014 01:07:38 PM Execution time: 0 hours(s), 3 minute(s), and 31 seconds(s) FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-02-2014 Ran by Jens (administrator) on JENS-PC on 09-02-2014 13:05:49 Running from C:\Users\Jens\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Safe Mode (with Networking) ==================== Processes (Whitelisted) ================= (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Bleeping Computer, LLC) C:\Users\Jens\Desktop\rkill.com (Bleeping Computer, LLC) C:\Users\Jens\Desktop\rkill64.com (Farbar) C:\Users\Jens\Downloads\FRST64(1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.) HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] () HKLM\...\Run: [fssui] - C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [453984 2008-12-08] (Microsoft Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-22] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] () HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=7850BCAEC506EED7&affID=122471&tsp=5021 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKCU - DefaultScope {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=7850BCAEC506EED7&affID=122471&tsp=5021 SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {8BD52629-20FB-49BF-9462-620B4C3B98BA} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=2A22FE29-29AD-4375-9BFE-11119F682D1C&apn_sauid=B4A214E1-598E-4D33-8E1A-4FFC7234639E BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files (x86)\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL No File Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default FF user.js: detected! => C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\user.js FF NewTab: www.google.de FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @graphisoft.com/GDL Web Plug-in - C:\Program Files (x86)\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll (Graphisoft SE) FF Plugin-x32: @java.com/DTPlugin,version=10.13.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\searchplugins\icqplugin.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\ich@maltegoetz.de [2013-12-12] FF Extension: YouTube Unblocker - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\youtubeunblocker@unblocker.yt [2014-01-16] FF Extension: ColorZilla - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2013-06-08] FF Extension: Bitdefender QuickScan - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2014-02-08] FF Extension: Stylish - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2014-02-08] FF Extension: {5557abbf-cefe-48eb-a400-4001db9881c8} - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{5557abbf-cefe-48eb-a400-4001db9881c8}.xpi [2013-10-30] FF Extension: Unity Web Player Updater Plus - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{a646c941-170c-4004-bdb2-bed2e7c1f89a}.xpi [2013-11-05] FF Extension: LeechBlock - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{a95d8332-e4b4-6e7f-98ac-20b733364387}.xpi [2012-10-24] FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-21] FF Extension: Adblock Plus - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-05-17] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-02-06] FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ [] ==================== Services (Whitelisted) ================= S2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] () ==================== Drivers (Whitelisted) ==================== S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2013-09-18] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2013-09-18] () S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () U3 tmlwf; U3 tmwfp; U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-09 13:05 - 2014-02-09 13:06 - 00011410 _____ () C:\Users\Jens\Downloads\FRST.txt 2014-02-09 13:05 - 2014-02-09 13:05 - 00000000 ____D () C:\FRST 2014-02-09 13:04 - 2014-02-09 13:04 - 01057016 _____ (Bleeping Computer, LLC) C:\Users\Jens\Desktop\rkill64.com 2014-02-09 13:04 - 2014-02-09 13:04 - 00001690 _____ () C:\Users\Jens\Desktop\Rkill.txt 2014-02-09 13:03 - 2014-02-09 13:03 - 02170368 _____ (Farbar) C:\Users\Jens\Downloads\FRST64(1).exe 2014-02-09 12:58 - 2014-02-09 12:58 - 02170368 _____ (Farbar) C:\Users\Jens\Downloads\FRST64.exe 2014-02-09 12:56 - 2014-02-09 12:56 - 02347384 _____ (ESET) C:\Users\Jens\Desktop\esetsmartinstaller_deu.exe 2014-02-09 12:50 - 2014-02-09 12:50 - 00000816 _____ () C:\Windows\PFRO.log 2014-02-09 12:45 - 2014-02-09 12:49 - 81604608 _____ () C:\Users\Jens\Downloads\ess_nt64_deu.msi 2014-02-09 12:27 - 2014-02-09 12:29 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Jens\Desktop\rkill.com 2014-02-09 12:16 - 2014-02-09 12:16 - 01582904 _____ (ESET) C:\Users\Jens\Downloads\eset_smart_security_live_installer_v7.exe 2014-02-09 01:00 - 2014-02-09 13:00 - 00000336 _____ () C:\Windows\setupact.log 2014-02-09 01:00 - 2014-02-09 01:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-09 00:43 - 2014-02-09 00:43 - 00553687 _____ () C:\Users\Jens\Downloads\RegCleaner.exe 2014-02-09 00:36 - 2014-02-09 00:36 - 00200192 _____ (SC BitDefender , Romania) C:\Users\Jens\Downloads\Anti-Generic.IMRobot-EN.exe 2014-02-09 00:33 - 2014-02-09 00:33 - 00532480 _____ (Trend Micro Incorporated) C:\Users\Jens\Desktop\cwshredder_2.19.exe 2014-02-09 00:32 - 2014-02-09 00:32 - 00401752 _____ (Softonic ) C:\Users\Jens\Downloads\SoftonicDownloader_fuer_cwshredder.exe 2014-02-08 23:56 - 2014-02-08 23:56 - 00010860 _____ () C:\Users\Jens\Desktop\hijackthis.log 2014-02-08 23:53 - 2014-02-09 00:43 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\QuickScan 2014-02-08 19:43 - 2014-02-08 19:43 - 00001205 _____ () C:\Users\Jens\Downloads\FixNCR.reg 2014-02-08 19:41 - 2014-02-08 19:41 - 00000335 _____ () C:\Users\Jens\Desktop\FixExe.reg 2014-02-08 19:32 - 2014-02-08 19:32 - 05249448 _____ (ParetoLogic Inc.) C:\Users\Jens\Downloads\ParetoLogic PC Health Advisor_de.exe 2014-02-08 19:25 - 2014-02-08 19:25 - 00614792 _____ (Chip Digital GmbH) C:\Users\Jens\Downloads\HijackThis - CHIP-Downloader.exe 2014-02-08 18:58 - 2014-02-08 18:58 - 07472232 _____ (Botkind Inc ) C:\Users\Jens\Downloads\allwaysync-14-0-1.exe 2014-02-08 15:06 - 2014-02-08 15:06 - 00000000 ____D () C:\Users\Jens\Downloads\PasAccXXX 08--02--14 2014-02-08 15:05 - 2014-02-08 15:06 - 03180397 _____ () C:\Users\Jens\Downloads\PasAccXXX 08--02--14.rar 2014-02-06 14:48 - 2014-02-06 14:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-06 01:32 - 2014-02-06 01:32 - 00066176 _____ () C:\Users\Jens\Downloads\tycho-1.jpeg 2014-02-03 19:56 - 2014-02-03 19:59 - 00005632 ___SH () C:\Users\Jens\Thumbs.db 2014-02-03 18:30 - 2014-02-03 19:57 - 00249778 _____ () C:\Users\Jens\Grunriss.dwg 2014-02-03 18:30 - 2014-02-03 19:57 - 00236400 _____ () C:\Users\Jens\Grunriss.bak 2014-02-02 11:03 - 2014-02-02 11:04 - 01069512 _____ (Solid State Networks) C:\Users\Jens\Downloads\install_flashplayer12x32au_mssa_aaa_aih.exe 2014-01-24 13:56 - 2014-01-24 13:56 - 01815525 _____ () C:\Users\Jens\Documents\Schwarzplan.dwg 2014-01-14 08:51 - 2014-01-14 08:51 - 00000000 __SHD () C:\found.000 ==================== One Month Modified Files and Folders ======= 2014-02-09 13:06 - 2014-02-09 13:05 - 00011410 _____ () C:\Users\Jens\Downloads\FRST.txt 2014-02-09 13:05 - 2014-02-09 13:05 - 00000000 ____D () C:\FRST 2014-02-09 13:04 - 2014-02-09 13:04 - 01057016 _____ (Bleeping Computer, LLC) C:\Users\Jens\Desktop\rkill64.com 2014-02-09 13:04 - 2014-02-09 13:04 - 00001690 _____ () C:\Users\Jens\Desktop\Rkill.txt 2014-02-09 13:03 - 2014-02-09 13:03 - 02170368 _____ (Farbar) C:\Users\Jens\Downloads\FRST64(1).exe 2014-02-09 13:00 - 2014-02-09 01:00 - 00000336 _____ () C:\Windows\setupact.log 2014-02-09 13:00 - 2013-05-04 04:20 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-09 13:00 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-09 12:58 - 2014-02-09 12:58 - 02170368 _____ (Farbar) C:\Users\Jens\Downloads\FRST64.exe 2014-02-09 12:58 - 2009-07-14 05:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-09 12:58 - 2009-07-14 05:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-09 12:56 - 2014-02-09 12:56 - 02347384 _____ (ESET) C:\Users\Jens\Desktop\esetsmartinstaller_deu.exe 2014-02-09 12:56 - 2009-08-04 10:51 - 00697212 _____ () C:\Windows\system32\perfh007.dat 2014-02-09 12:56 - 2009-08-04 10:51 - 00148492 _____ () C:\Windows\system32\perfc007.dat 2014-02-09 12:56 - 2009-07-14 06:13 - 01612484 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-09 12:50 - 2014-02-09 12:50 - 00000816 _____ () C:\Windows\PFRO.log 2014-02-09 12:49 - 2014-02-09 12:45 - 81604608 _____ () C:\Users\Jens\Downloads\ess_nt64_deu.msi 2014-02-09 12:36 - 2013-08-05 21:14 - 00000000 ____D () C:\ProgramData\Avira 2014-02-09 12:29 - 2014-02-09 12:27 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Jens\Desktop\rkill.com 2014-02-09 12:16 - 2014-02-09 12:16 - 01582904 _____ (ESET) C:\Users\Jens\Downloads\eset_smart_security_live_installer_v7.exe 2014-02-09 12:15 - 2012-06-12 22:04 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\Skype 2014-02-09 11:48 - 2013-05-04 04:20 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-09 01:00 - 2014-02-09 01:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-09 00:43 - 2014-02-09 00:43 - 00553687 _____ () C:\Users\Jens\Downloads\RegCleaner.exe 2014-02-09 00:43 - 2014-02-08 23:53 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\QuickScan 2014-02-09 00:36 - 2014-02-09 00:36 - 00200192 _____ (SC BitDefender , Romania) C:\Users\Jens\Downloads\Anti-Generic.IMRobot-EN.exe 2014-02-09 00:33 - 2014-02-09 00:33 - 00532480 _____ (Trend Micro Incorporated) C:\Users\Jens\Desktop\cwshredder_2.19.exe 2014-02-09 00:32 - 2014-02-09 00:32 - 00401752 _____ (Softonic ) C:\Users\Jens\Downloads\SoftonicDownloader_fuer_cwshredder.exe 2014-02-09 00:03 - 2012-05-31 13:33 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\Dropbox 2014-02-08 23:56 - 2014-02-08 23:56 - 00010860 _____ () C:\Users\Jens\Desktop\hijackthis.log 2014-02-08 23:20 - 2012-05-17 22:21 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\vlc 2014-02-08 19:43 - 2014-02-08 19:43 - 00001205 _____ () C:\Users\Jens\Downloads\FixNCR.reg 2014-02-08 19:41 - 2014-02-08 19:41 - 00000335 _____ () C:\Users\Jens\Desktop\FixExe.reg 2014-02-08 19:32 - 2014-02-08 19:32 - 05249448 _____ (ParetoLogic Inc.) C:\Users\Jens\Downloads\ParetoLogic PC Health Advisor_de.exe 2014-02-08 19:25 - 2014-02-08 19:25 - 00614792 _____ (Chip Digital GmbH) C:\Users\Jens\Downloads\HijackThis - CHIP-Downloader.exe 2014-02-08 18:58 - 2014-02-08 18:58 - 07472232 _____ (Botkind Inc ) C:\Users\Jens\Downloads\allwaysync-14-0-1.exe 2014-02-08 15:06 - 2014-02-08 15:06 - 00000000 ____D () C:\Users\Jens\Downloads\PasAccXXX 08--02--14 2014-02-08 15:06 - 2014-02-08 15:05 - 03180397 _____ () C:\Users\Jens\Downloads\PasAccXXX 08--02--14.rar 2014-02-08 14:48 - 2013-04-06 20:58 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-02-06 23:15 - 2012-05-17 18:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-06 14:48 - 2014-02-06 14:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-06 01:32 - 2014-02-06 01:32 - 00066176 _____ () C:\Users\Jens\Downloads\tycho-1.jpeg 2014-02-05 23:50 - 2013-10-28 18:10 - 00007123 _____ () C:\Users\Jens\Documents\plot.log 2014-02-04 17:26 - 2012-05-17 22:17 - 00000000 ____D () C:\Users\Jens\AppData\Local\cache 2014-02-03 19:59 - 2014-02-03 19:56 - 00005632 ___SH () C:\Users\Jens\Thumbs.db 2014-02-03 19:57 - 2014-02-03 18:30 - 00249778 _____ () C:\Users\Jens\Grunriss.dwg 2014-02-03 19:57 - 2014-02-03 18:30 - 00236400 _____ () C:\Users\Jens\Grunriss.bak 2014-02-03 19:57 - 2012-05-17 18:44 - 00000000 ____D () C:\Users\Jens 2014-02-02 11:04 - 2014-02-02 11:03 - 01069512 _____ (Solid State Networks) C:\Users\Jens\Downloads\install_flashplayer12x32au_mssa_aaa_aih.exe 2014-01-24 13:56 - 2014-01-24 13:56 - 01815525 _____ () C:\Users\Jens\Documents\Schwarzplan.dwg 2014-01-22 21:17 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-14 08:51 - 2014-01-14 08:51 - 00000000 __SHD () C:\found.000 2014-01-12 15:32 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF Some content of TEMP: ==================== C:\Users\Jens\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-09 03:47 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-02-2014 Ran by Jens at 2014-02-09 13:06:56 Running from C:\Users\Jens\Downloads Boot Mode: Safe Mode (with Networking) ========================================================== ==================== Security Center ======================== AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (x32 Version: - Microsoft) Acrobat.com (x32 Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.2.0.2070 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.2.0.2070 - Adobe Systems Incorporated) Hidden Adobe Download Assistant (x32 Version: 1.2 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.2 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.152 - Adobe Systems Incorporated) Adobe Help Manager (x32 Version: 4.0.244 - Adobe Systems Incorporated) Adobe Help Manager (x32 Version: 4.0.244 - Adobe Systems Incorporated) Hidden Adobe InDesign CS6 (x32 Version: 8.0 - Adobe Systems Incorporated) Adobe Photoshop CS6 (x32 Version: 13.0 - Adobe Systems Incorporated) Adobe Reader 9.5.5 MUI (x32 Version: 9.5.5 - Adobe Systems Incorporated) Age of Empires II: HD Edition (x32 Version: - ) Any PDF to DWG Converter 2010 (x32 Version: - AnyDWG Software, Inc.) ArchiCAD 16 GER (Version: 16.0 - GRAPHISOFT) ASUS AP Bank (x32 Version: 1.0.0.0 - ASUSTEK) ASUS CopyProtect (x32 Version: 1.0.0015 - ASUS) ASUS Data Security Manager (x32 Version: 1.00.0014 - ASUS) ASUS FancyStart (x32 Version: 1.0.8 - ASUSTeK Computer Inc.) ASUS LifeFrame3 (x32 Version: 3.0.20 - ASUS) ASUS Live Update (x32 Version: 2.5.9 - ASUS) ASUS MultiFrame (x32 Version: 1.0.0021 - ASUS) ASUS Power4Gear Hybrid (Version: 1.1.37 - ASUS) ASUS SmartLogon (x32 Version: 1.0.0008 - ASUS) ASUS Splendid Video Enhancement Technology (x32 Version: 1.02.0028 - ASUS) ASUS Virtual Camera (x32 Version: 1.0.20 - asus) ATI AVIVO64 Codecs (Version: 10.12.0.00122 - ATI Technologies Inc.) Hidden ATI Catalyst Install Manager (Version: 3.0.758.0 - ATI Technologies, Inc.) ATK Package (x32 Version: 1.0.0005 - ASUS) Audiograbber 1.83 SE (x32 Version: 1.83 SE - Audiograbber) Audiograbber MP3-Plugin (64 bit) (x32 Version: 1.0 - AG) AutoCAD 2012 - Deutsch (Version: 18.2.51.0 - Autodesk) AutoCAD 2012 - Deutsch (Version: 18.2.51.0 - Autodesk) Hidden AutoCAD 2012 Language Pack - Deutsch (Version: 18.2.51.0 - Autodesk) Hidden Autodesk Content Service (x32 Version: 2.0.90 - Autodesk) Autodesk Material Library 2012 (x32 Version: 2.5.0.8 - Autodesk) Autodesk Material Library Base Resolution Image Library 2012 (x32 Version: 2.5.0.8 - Autodesk) Bing Bar (x32 Version: 7.0.850.0 - Microsoft Corporation) Boingo Wi-Fi (x32 Version: 1.7.0048 - Boingo Wireless, Inc.) Canon MP280 series MP Drivers (Version: - ) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Core Implementation (x32 Version: 2010.0122.858.16002 - ATI) Hidden Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0122.858.16002 - ATI) Hidden Catalyst Control Center Graphics Full New (x32 Version: 2010.0122.858.16002 - ATI) Hidden Catalyst Control Center Graphics Light (x32 Version: 2010.0122.858.16002 - ATI) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0122.858.16002 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0122.858.16002 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.0122.858.16002 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2010.0122.858.16002 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Czech (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Danish (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Dutch (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help English (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Finnish (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help French (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help German (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Greek (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Hungarian (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Italian (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Japanese (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Korean (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Norwegian (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Polish (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Portuguese (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Russian (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Spanish (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Swedish (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Thai (x32 Version: 2010.0122.0857.16002 - ATI) Hidden CCC Help Turkish (x32 Version: 2010.0122.0857.16002 - ATI) Hidden ccc-core-static (x32 Version: 2010.0122.858.16002 - ATI) Hidden ccc-utility64 (Version: 2010.0122.858.16002 - ATI) Hidden CCleaner (Version: 3.21 - Piriform) Choice Guard (x32 Version: 1.2.87.0 - Microsoft Corporation) Hidden Conexant HD Audio (Version: 4.98.18.65 - Conexant) ControlDeck (x32 Version: 1.0.8 - ASUS) Diablo III (x32 Version: - Blizzard Entertainment) Dropbox (HKCU Version: 1.6.18 - Dropbox, Inc.) EnerCalC 4.41.88 (x32 Version: 4.41.88 - Markus Lichtmeß) EPSON Scan (x32 Version: - Seiko Epson Corporation) EPSON SX235 Series Printer Uninstall (Version: - SEIKO EPSON Corporation) ETDWare PS/2-x64 7.0.5.11_WHQL (Version: 7.0.5.11 - ELAN Microelectronics Corp.) FARO LS 1.1.406.58 (x32 Version: 4.6.58.2 - FARO Scanner Production) Fast Boot (Version: 1.0.6 - ASUS) Free YouTube Download version 3.2.0.128 (x32 Version: 3.2.0.128 - DVDVideoSoft Ltd.) GIMP 2.8.4 (Version: 2.8.4 - The GIMP Team) Google Earth (x32 Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden Half-Life 2 (x32 Version: - Valve) Half-Life 2: Deathmatch (x32 Version: - Valve) Half-Life 2: Episode One (x32 Version: - Valve) Half-Life 2: Episode Two (x32 Version: - Valve) Half-Life 2: Lost Coast (x32 Version: - Valve) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179 - Intel Corporation) IrfanView (remove only) (x32 Version: 4.32 - Irfan Skiljan) Java 7 Update 13 (x32 Version: 7.0.130 - Oracle) Java Auto Updater (x32 Version: 2.1.9.0 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 32 (x32 Version: 6.0.320 - Oracle) JavaFX 2.1.1 (x32 Version: 2.1.1 - Oracle Corporation) JDiskReport 1.4.0 (x32 Version: 1.4.0 (2012-01-20 11:38:43) - JGoodies Karsten Lentzsch) JMicron Ethernet Adapter NDIS Driver (x32 Version: 6.0.17.1 - JMicron Technology Corp.) JMicron Flash Media Controller Driver (x32 Version: 1.0.33.2 - JMicron Technology Corp.) Junk Mail filter update (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden K_Series_ScreenSaver_EN (x32 Version: - ) K-Lite Codec Pack 9.9.5 (Standard) (x32 Version: 9.9.5 - ) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (x32 Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (x32 Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (x32 Version: 9.0.30411 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (x32 Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden MouseServer Version 1.2.0 (x32 Version: 1.2.0 - Necta Co.) Mozilla Firefox 27.0 (x86 de) (x32 Version: 27.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 27.0 - Mozilla) MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0 - Microsoft Corporation) Panorado Flyer (x64) (Version: 1.2 - Simple Software) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden pdfsam (HKCU Version: 2.2.1 - ) PDF-Viewer (Version: 2.5.213.1 - Tracker Software Products Ltd) SketchUp 8 (x32 Version: 3.0.16846 - Trimble Navigation Limited) Skype Click to Call (x32 Version: 6.3.11079 - Skype Technologies S.A.) Skype™ 6.7 (x32 Version: 6.7.102 - Skype Technologies S.A.) StarCraft II (x32 Version: - Blizzard Entertainment) Steam (x32 Version: 1.0.0.0 - Valve Corporation) syncables desktop SE (x32 Version: 5.5.746.11492 - syncables) System Requirements Lab CYRI (x32 Version: 4.5.1.0 - Husdawg, LLC) Total War: SHOGUN 2 (x32 Version: - The Creative Assembly) Unlocker 1.9.2 (Version: 1.9.2 - Cedrick Collomb) Update for 2007 Microsoft Office System (KB967642) (x32 Version: - Microsoft) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (x32 Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (x32 Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32 Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32 Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (x32 Version: - Microsoft) USB2.0 UVC VGA WebCam (Version: 5.8.54000.207 - Sonix) VLC media player 2.0.1 (x32 Version: 2.0.1 - VideoLAN) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.6 - Microsoft Corporation) Windows Live Call (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Windows Live Essentials (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 14.0.8052.1208 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 14.0.8051.1204 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live Sync (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Windows Live Writer (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Windows Live-Uploadtool (x32 Version: 14.0.8014.1029 - Microsoft Corporation) WinFlash (x32 Version: 2.30.3 - ASUS) WinRAR 4.11 (64-Bit) (Version: 4.11.0 - win.rar GmbH) Wireless Console 3 (x32 Version: 3.0.17 - ASUS) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1E2CE2DB-0F5F-41DA-81D3-D1B9E1EAEFD5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-06-02] (Google Inc.) Task: {3C81DBAD-AFB1-4E1C-9C7C-42EF2D521109} - System32\Tasks\ASPG => C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS) Task: {4A9D13C6-EBA6-4B1C-991F-6DBA9978A9B2} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-05-28] (ATK) Task: {59483D0E-3544-4F18-9881-9D5D1B74F572} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK) Task: {7E94BADD-4E32-4466-83DA-64DF528DE826} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-06-02] (Google Inc.) Task: {8CD51779-0EC6-4002-909B-88CDCF5603CA} - System32\Tasks\ASUSControlDeck => C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe [2010-06-09] (asus) Task: {A468A891-D8DA-4946-BDA7-5D6672F283B1} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-07-31] (ASUS) Task: {B40F8CCD-A8BF-4C0F-B4D4-8F25095E62F0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-07-24] (Piriform Ltd) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2007-06-15 18:28 - 2007-06-15 18:28 - 00104960 _____ () C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt64.dll 2007-06-02 00:52 - 2007-06-02 00:52 - 00159744 _____ () C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll 2014-02-06 14:48 - 2014-02-06 14:48 - 03583600 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2007-06-15 18:28 - 2007-06-15 18:28 - 00147456 _____ () C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll 2007-06-02 01:08 - 2007-06-02 01:08 - 00143360 _____ () C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Windows:nlsPreferences ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2" ==================== Faulty Device Manager Devices ============= Name: Security Processor Loader Driver Description: Security Processor Loader Driver Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: spldr Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (02/09/2014 01:02:30 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 00:57:33 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 00:57:30 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 00:57:30 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 00:57:23 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 00:57:17 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 00:57:08 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 00:57:04 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 00:56:59 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 00:56:54 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Error: (02/09/2014 01:05:35 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (02/09/2014 01:05:35 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (02/09/2014 01:05:35 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (02/09/2014 01:05:35 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (02/09/2014 01:05:35 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (02/09/2014 01:05:35 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (02/09/2014 01:04:25 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (02/09/2014 01:04:25 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (02/09/2014 01:04:25 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (02/09/2014 01:02:29 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Microsoft Office Sessions: ========================= Error: (06/11/2012 10:25:07 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 3406 seconds with 1980 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Percentage of memory in use: 25% Total physical RAM: 3948.55 MB Available physical RAM: 2958.4 MB Total Pagefile: 7895.28 MB Available Pagefile: 7030.2 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:74.52 GB) (Free:3.64 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:204.03 GB) (Free:136.69 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: E0C5913D) Partition 1: (Not Active) - (Size=20 GB) - (Type=1C) Partition 2: (Active) - (Size=75 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=204 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
10.02.2014, 09:59 | #4 |
/// the machine /// TB-Ausbilder | Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallieren hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.02.2014, 19:04 | #5 |
| Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallierenCode:
ATTFilter ComboFix 14-02-05.02 - Jens 10.02.2014 16:51:01.1.2 - x64 NETWORK Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3949.2861 [GMT 1:00] ausgeführt von:: c:\users\Jens\Desktop\ComboFix.exe SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . ADS - Windows: deleted 192 bytes in 1 streams. . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\esupport\eDriver\Software\ASUS\MultiFrame\XP32_Vista32_Vista64_Win7_32_Win7_64_1.0.0021\Desktop_.ini c:\program files (x86)\Common Files\ASPG_icon.ico c:\windows\msvcr71.dll c:\windows\security\Database\tmp.edb . Infizierte Kopie von c:\windows\system32\Services.exe wurde gefunden und desinfiziert Kopie von - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe wurde wiederhergestellt . . ((((((((((((((((((((((( Dateien erstellt von 2014-01-10 bis 2014-02-10 )))))))))))))))))))))))))))))) . . 2014-02-10 16:01 . 2014-02-10 16:01 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-02-09 23:13 . 2014-02-09 23:15 -------- d-----w- c:\users\Administrator 2014-02-09 22:38 . 2014-02-09 22:38 194560 ----a-w- c:\windows\system32\puiapi.dll 2014-02-09 21:59 . 2014-02-09 22:03 -------- d-----w- c:\users\Jens\AppData\Roaming\Wise Registry Cleaner 2014-02-09 21:59 . 2014-02-09 21:59 -------- d-----w- c:\program files (x86)\Wise 2014-02-09 21:13 . 2014-02-09 21:19 -------- d-----w- C:\AdwCleaner 2014-02-09 19:33 . 2014-02-09 19:33 -------- d-----w- c:\users\Jens\AppData\Local\ElevatedDiagnostics 2014-02-09 16:15 . 2014-02-09 16:15 -------- d-----w- c:\users\Jens\AppData\Roaming\Malwarebytes 2014-02-09 16:15 . 2014-02-09 16:15 -------- d-----w- c:\programdata\Malwarebytes 2014-02-09 16:15 . 2014-02-09 16:15 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2014-02-09 16:15 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-02-09 15:51 . 2014-02-09 15:52 -------- d-----w- c:\program files (x86)\RegCleaner 2014-02-09 12:09 . 2014-02-09 12:09 -------- d-----w- c:\program files (x86)\ESET 2014-02-09 12:05 . 2014-02-09 12:07 -------- d-----w- C:\FRST 2014-02-08 22:53 . 2014-02-08 23:43 -------- d-----w- c:\users\Jens\AppData\Roaming\QuickScan 2014-01-14 07:51 . 2014-01-14 07:51 -------- d-----w- C:\found.000 . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-14 15:25 . 2012-06-24 09:40 90708896 ----a-w- c:\windows\system32\MRT.exe 2013-12-10 00:12 . 2013-12-10 00:12 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-12-10 00:12 . 2013-12-10 00:12 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-12-10 00:12 . 2013-12-10 00:12 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-12-10 00:12 . 2013-12-10 00:12 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2013-12-10 00:12 . 2013-12-10 00:12 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-12-10 00:12 . 2013-12-10 00:12 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2013-12-10 00:12 . 2013-12-10 00:12 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2013-12-10 00:12 . 2013-12-10 00:12 337408 ----a-w- c:\windows\SysWow64\html.iec 2013-12-10 00:12 . 2013-12-10 00:12 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-12-10 00:12 . 2013-12-10 00:12 235008 ----a-w- c:\windows\system32\elshyph.dll 2013-12-10 00:12 . 2013-12-10 00:12 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2013-12-10 00:12 . 2013-12-10 00:12 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-12-10 00:12 . 2013-12-10 00:12 942592 ----a-w- c:\windows\system32\jsIntl.dll 2013-12-10 00:12 . 2013-12-10 00:12 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-12-10 00:12 . 2013-12-10 00:12 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-12-10 00:12 . 2013-12-10 00:12 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-12-10 00:12 . 2013-12-10 00:12 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2013-12-10 00:12 . 2013-12-10 00:12 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2013-12-10 00:12 . 2013-12-10 00:12 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-12-10 00:12 . 2013-12-10 00:12 454656 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-12-10 00:12 . 2013-12-10 00:12 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-12-10 00:12 . 2013-12-10 00:12 247808 ----a-w- c:\windows\system32\msls31.dll 2013-12-10 00:12 . 2013-12-10 00:12 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-12-10 00:12 . 2013-12-10 00:12 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2013-12-10 00:12 . 2013-12-10 00:12 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2013-12-10 00:12 . 2013-12-10 00:12 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-12-10 00:12 . 2013-12-10 00:12 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-12-10 00:12 . 2013-12-10 00:12 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-12-10 00:12 . 2013-12-10 00:12 84992 ----a-w- c:\windows\system32\mshtmled.dll 2013-12-10 00:12 . 2013-12-10 00:12 81408 ----a-w- c:\windows\system32\icardie.dll 2013-12-10 00:12 . 2013-12-10 00:12 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-12-10 00:12 . 2013-12-10 00:12 626176 ----a-w- c:\windows\system32\msfeeds.dll 2013-12-10 00:12 . 2013-12-10 00:12 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2013-12-10 00:12 . 2013-12-10 00:12 548352 ----a-w- c:\windows\system32\vbscript.dll 2013-12-10 00:12 . 2013-12-10 00:12 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-12-10 00:12 . 2013-12-10 00:12 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-12-10 00:12 . 2013-12-10 00:12 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2013-12-10 00:12 . 2013-12-10 00:12 413696 ----a-w- c:\windows\system32\html.iec 2013-12-10 00:12 . 2013-12-10 00:12 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2013-12-10 00:12 . 2013-12-10 00:12 30208 ----a-w- c:\windows\system32\licmgr10.dll 2013-12-10 00:12 . 2013-12-10 00:12 296960 ----a-w- c:\windows\system32\dxtrans.dll 2013-12-10 00:12 . 2013-12-10 00:12 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2013-12-10 00:12 . 2013-12-10 00:12 243200 ----a-w- c:\windows\system32\webcheck.dll 2013-12-10 00:12 . 2013-12-10 00:12 235520 ----a-w- c:\windows\system32\url.dll 2013-12-10 00:12 . 2013-12-10 00:12 195584 ----a-w- c:\windows\system32\msrating.dll 2013-12-10 00:12 . 2013-12-10 00:12 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-12-10 00:12 . 2013-12-10 00:12 143872 ----a-w- c:\windows\system32\wextract.exe 2013-12-10 00:12 . 2013-12-10 00:12 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2013-12-10 00:12 . 2013-12-10 00:12 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-12-10 00:12 . 2013-12-10 00:12 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-12-10 00:12 . 2013-12-10 00:12 105984 ----a-w- c:\windows\system32\iesysprep.dll 2013-12-10 00:12 . 2013-12-10 00:12 101376 ----a-w- c:\windows\system32\inseng.dll 2013-12-10 00:12 . 2013-12-10 00:12 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2013-12-10 00:12 . 2013-12-10 00:12 774144 ----a-w- c:\windows\system32\jscript.dll 2013-12-10 00:12 . 2013-12-10 00:12 62464 ----a-w- c:\windows\system32\pngfilt.dll 2013-12-10 00:12 . 2013-12-10 00:12 48128 ----a-w- c:\windows\system32\imgutil.dll 2013-12-10 00:12 . 2013-12-10 00:12 147968 ----a-w- c:\windows\system32\occache.dll 2013-12-10 00:12 . 2013-12-10 00:12 13824 ----a-w- c:\windows\system32\mshta.exe 2013-12-10 00:12 . 2013-12-10 00:12 135680 ----a-w- c:\windows\system32\iepeers.dll 2013-11-26 11:54 . 2013-12-11 09:21 23183360 ----a-w- c:\windows\system32\mshtml.dll 2013-11-26 10:19 . 2013-12-11 09:21 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2013-11-26 10:18 . 2013-12-11 09:21 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2013-11-26 09:48 . 2013-12-11 09:21 66048 ----a-w- c:\windows\system32\iesetup.dll 2013-11-26 09:46 . 2013-12-11 09:21 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2013-11-26 09:41 . 2013-12-11 09:21 2764288 ----a-w- c:\windows\system32\iertutil.dll 2013-11-26 09:29 . 2013-12-11 09:21 53760 ----a-w- c:\windows\system32\jsproxy.dll 2013-11-26 09:27 . 2013-12-11 09:21 33792 ----a-w- c:\windows\system32\iernonce.dll 2013-11-26 09:23 . 2013-12-11 09:21 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2013-11-26 09:21 . 2013-12-11 09:21 574976 ----a-w- c:\windows\system32\ieui.dll 2013-11-26 09:18 . 2013-12-11 09:21 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2013-11-26 09:18 . 2013-12-11 09:21 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2013-11-26 09:16 . 2013-12-11 09:21 708608 ----a-w- c:\windows\system32\jscript9diag.dll 2013-11-26 08:57 . 2013-12-11 09:21 218624 ----a-w- c:\windows\system32\ie4uinit.exe 2013-11-26 08:35 . 2013-12-11 09:21 5769216 ----a-w- c:\windows\system32\jscript9.dll 2013-11-26 08:28 . 2013-12-11 09:21 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2013-11-26 08:16 . 2013-12-11 09:21 4243968 ----a-w- c:\windows\SysWow64\jscript9.dll 2013-11-26 08:02 . 2013-12-11 09:21 1995264 ----a-w- c:\windows\system32\inetcpl.cpl 2013-11-26 07:48 . 2013-12-11 09:21 12996608 ----a-w- c:\windows\system32\ieframe.dll 2013-11-26 07:32 . 2013-12-11 09:21 1928192 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-11-26 07:07 . 2013-12-11 09:21 2334208 ----a-w- c:\windows\system32\wininet.dll 2013-11-26 06:40 . 2013-12-11 09:21 1395200 ----a-w- c:\windows\system32\urlmon.dll 2013-11-26 06:34 . 2013-12-11 09:21 817664 ----a-w- c:\windows\system32\ieapfltr.dll 2013-11-26 06:33 . 2013-12-11 09:21 1820160 ----a-w- c:\windows\SysWow64\wininet.dll 2013-11-23 18:26 . 2013-12-11 08:34 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-11-23 17:47 . 2013-12-11 08:34 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-11-22 15:25 . 2012-05-20 01:27 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-11-22 15:25 . 2012-05-20 01:27 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll 2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-02 00:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-07-25 20687728] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-07-02 1597440] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [x] R4 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [x] R4 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x] R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys;c:\windows\SYSNATIVE\DRIVERS\lullaby.sys [x] S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x] S2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x] S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [x] S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE;c:\windows\SysWOW64\NLSSRV32.EXE [x] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x] S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x] S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys;c:\windows\SYSNATIVE\DRIVERS\JME.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . Inhalt des "geplante Tasks" Ordners . 2014-02-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-02 00:03] . 2014-02-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-02 00:03] . 2014-02-09 c:\windows\Tasks\{EEAE2512-9FA5-4A75-BF5A-45282FE2BAFE}.job - c:\program files (x86)\mozilla firefox\firefox.exe [2014-02-06 13:48] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-01 23:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768] "fssui"="c:\program files (x86)\Windows Live\Family Safety\fsui.exe" [2008-12-08 453984] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\ FF - prefs.js: browser.startup.homepage - www.google.de FF - ExtSQL: !HIDDEN! 2013-02-18 11:42; {ACAA314B-EEBA-48e4-AD47-84E31C44796C}; c:\program files (x86)\Common Files\DVDVideoSoft\plugins\ff . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) HKLM-Run-ETDWare - c:\program files (x86)\Elantech\ETDCtrl.exe AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Classes\CLSID] @DACL=(02 0000) . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*„Dp] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*„Dp\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ÀR]] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ÀR]\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*Å|Ir] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*Å|Ir\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ˆ»d] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ˆ»d\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*‡ˆvq] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*‡ˆvq\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*w*=] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*w*=\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ô¿ßr] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ô¿ßr\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ÿä<u] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ÿä<u\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*rþµJ] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*rþµJ\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*A*d*a*àþú3\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*a*t*•—x\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*a*v*þeQ`\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*o*c*k*_*s*t*a*‹ðj\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*D*o*l*¦z¿B\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*D*o*l*éîßU\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*F*¡F"] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*F*¡F"\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*H*L-oZ] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*H*L-oZ\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*H*•GÐo] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*H*•GÐo\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*H*¿žK@] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*H*¿žK@\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*M*P*4*-*K*T*R*_*m*o*éê?\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*m*p*4*Jmÿ'\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*o*u*t*d*o*o*r*Û5ñf\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID] @DACL=(02 0000) . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}] @DACL=(02 0000) @="Dropbox Autoplay COM Server" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{5E4405B0-5374-11CE-8E71-0020AF04B1D7}] @DACL=(02 0000) "AutoTreatAs"="{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}" "TreatAs"="{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{6D7AE628-FF41-4CD3-91DD-34825BB1A251}] @DACL=(02 0000) @="AutoCAD Application" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{B77E471C-FBF3-4CB5-880F-D7528AD4B349}] @DACL=(02 0000) . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{C92FB640-AD4D-498A-9979-A51A2540C977}] @DACL=(02 0000) . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}] @DACL=(02 0000) @="AutoCAD Drawing" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}] @DACL=(02 0000) @="AutoCAD Icon Shell Extension" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] @DACL=(02 0000) @="DropboxExt" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] @DACL=(02 0000) @="DropboxExt" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] @DACL=(02 0000) @="DropboxExt" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] @DACL=(02 0000) @="DropboxExt" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe c:\program files (x86)\Windows Live\Family Safety\fsssvc.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe c:\program files (x86)\ASUS\ControlDeck\ControlDeck.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-02-10 17:08:05 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-02-10 16:08 . Vor Suchlauf: 3.569.401.856 Bytes frei Nach Suchlauf: 3.603.050.496 Bytes frei . - - End Of File - - 1060717241CD2B9C98E19832E63EB2FF Wüsste gerne noch woran es gelegen hat, hat vielleicht jemand eine Erklärung? Vielen Dank auf jeden Fall für die kompetente Hilfe hier!! Edit: Ich konnte einige Probleme beheben, aber die Meldung mit dem "Dateisystemfehler" tritt bei einigen Programmen nachwievor auf. Wollte eben z.B skype als Admin ausführen und es erschien der oben beschriebene Fehler! Beim deinstallieren von Programmen gab es jedoch keine Probleme. Jetzt scheint wieder alles gleich schlecht zu funktionieren. Bei jedem Programm was ich neu installieren willl, die gleiche Meldung. Stehe wieder am Anfang. Habe ComboFix ein zweites Mal durchlaufen lassen (im abgesicherten Modus, da sonst der Dateisystemfehler kam) Code:
ATTFilter ComboFix 14-02-05.02 - Jens 10.02.2014 18:42:34.2.2 - x64 NETWORK Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3949.2869 [GMT 1:00] ausgeführt von:: c:\users\Jens\Desktop\ComboFix.exe AV: ESET Smart Security 7.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289} FW: ESET Personal Firewall *Enabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2} SP: ESET Smart Security 7.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . ADS - Windows: deleted 0 bytes in 1 streams. . ((((((((((((((((((((((( Dateien erstellt von 2014-01-10 bis 2014-02-10 )))))))))))))))))))))))))))))) . . 2014-02-10 17:50 . 2014-02-10 17:50 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-02-10 16:47 . 2014-02-10 16:47 -------- d-----w- c:\program files (x86)\Common Files\Skype 2014-02-10 16:47 . 2014-02-10 16:47 -------- d-----r- c:\program files (x86)\Skype 2014-02-10 16:30 . 2014-02-10 16:30 -------- d-----w- c:\users\Jens\AppData\Local\Skype 2014-02-10 16:21 . 2014-02-10 16:21 -------- d-----w- c:\users\Jens\AppData\Local\ESET 2014-02-10 16:20 . 2014-02-10 16:20 -------- d-----w- c:\program files\ESET 2014-02-09 23:13 . 2014-02-09 23:15 -------- d-----w- c:\users\Administrator 2014-02-09 22:38 . 2014-02-09 22:38 194560 ----a-w- c:\windows\system32\puiapi.dll 2014-02-09 21:13 . 2014-02-09 21:19 -------- d-----w- C:\AdwCleaner 2014-02-09 19:33 . 2014-02-10 17:04 -------- d-----w- c:\users\Jens\AppData\Local\ElevatedDiagnostics 2014-02-09 16:15 . 2014-02-09 16:15 -------- d-----w- c:\users\Jens\AppData\Roaming\Malwarebytes 2014-02-09 16:15 . 2014-02-09 16:15 -------- d-----w- c:\programdata\Malwarebytes 2014-02-09 15:51 . 2014-02-09 15:52 -------- d-----w- c:\program files (x86)\RegCleaner 2014-02-09 12:09 . 2014-02-09 12:09 -------- d-----w- c:\program files (x86)\ESET 2014-02-09 12:05 . 2014-02-09 12:07 -------- d-----w- C:\FRST 2014-02-08 22:53 . 2014-02-08 23:43 -------- d-----w- c:\users\Jens\AppData\Roaming\QuickScan 2014-01-14 07:51 . 2014-01-14 07:51 -------- d-----w- C:\found.000 . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-14 15:25 . 2012-06-24 09:40 90708896 ----a-w- c:\windows\system32\MRT.exe 2013-12-10 00:12 . 2013-12-10 00:12 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-12-10 00:12 . 2013-12-10 00:12 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-12-10 00:12 . 2013-12-10 00:12 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-12-10 00:12 . 2013-12-10 00:12 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2013-12-10 00:12 . 2013-12-10 00:12 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-12-10 00:12 . 2013-12-10 00:12 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2013-12-10 00:12 . 2013-12-10 00:12 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2013-12-10 00:12 . 2013-12-10 00:12 337408 ----a-w- c:\windows\SysWow64\html.iec 2013-12-10 00:12 . 2013-12-10 00:12 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-12-10 00:12 . 2013-12-10 00:12 235008 ----a-w- c:\windows\system32\elshyph.dll 2013-12-10 00:12 . 2013-12-10 00:12 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2013-12-10 00:12 . 2013-12-10 00:12 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-12-10 00:12 . 2013-12-10 00:12 942592 ----a-w- c:\windows\system32\jsIntl.dll 2013-12-10 00:12 . 2013-12-10 00:12 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-12-10 00:12 . 2013-12-10 00:12 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-12-10 00:12 . 2013-12-10 00:12 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-12-10 00:12 . 2013-12-10 00:12 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2013-12-10 00:12 . 2013-12-10 00:12 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2013-12-10 00:12 . 2013-12-10 00:12 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-12-10 00:12 . 2013-12-10 00:12 454656 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-12-10 00:12 . 2013-12-10 00:12 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-12-10 00:12 . 2013-12-10 00:12 247808 ----a-w- c:\windows\system32\msls31.dll 2013-12-10 00:12 . 2013-12-10 00:12 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-12-10 00:12 . 2013-12-10 00:12 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2013-12-10 00:12 . 2013-12-10 00:12 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2013-12-10 00:12 . 2013-12-10 00:12 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-12-10 00:12 . 2013-12-10 00:12 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-12-10 00:12 . 2013-12-10 00:12 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-12-10 00:12 . 2013-12-10 00:12 84992 ----a-w- c:\windows\system32\mshtmled.dll 2013-12-10 00:12 . 2013-12-10 00:12 81408 ----a-w- c:\windows\system32\icardie.dll 2013-12-10 00:12 . 2013-12-10 00:12 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-12-10 00:12 . 2013-12-10 00:12 626176 ----a-w- c:\windows\system32\msfeeds.dll 2013-12-10 00:12 . 2013-12-10 00:12 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2013-12-10 00:12 . 2013-12-10 00:12 548352 ----a-w- c:\windows\system32\vbscript.dll 2013-12-10 00:12 . 2013-12-10 00:12 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-12-10 00:12 . 2013-12-10 00:12 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-12-10 00:12 . 2013-12-10 00:12 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2013-12-10 00:12 . 2013-12-10 00:12 413696 ----a-w- c:\windows\system32\html.iec 2013-12-10 00:12 . 2013-12-10 00:12 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2013-12-10 00:12 . 2013-12-10 00:12 30208 ----a-w- c:\windows\system32\licmgr10.dll 2013-12-10 00:12 . 2013-12-10 00:12 296960 ----a-w- c:\windows\system32\dxtrans.dll 2013-12-10 00:12 . 2013-12-10 00:12 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2013-12-10 00:12 . 2013-12-10 00:12 243200 ----a-w- c:\windows\system32\webcheck.dll 2013-12-10 00:12 . 2013-12-10 00:12 235520 ----a-w- c:\windows\system32\url.dll 2013-12-10 00:12 . 2013-12-10 00:12 195584 ----a-w- c:\windows\system32\msrating.dll 2013-12-10 00:12 . 2013-12-10 00:12 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-12-10 00:12 . 2013-12-10 00:12 143872 ----a-w- c:\windows\system32\wextract.exe 2013-12-10 00:12 . 2013-12-10 00:12 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2013-12-10 00:12 . 2013-12-10 00:12 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-12-10 00:12 . 2013-12-10 00:12 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-12-10 00:12 . 2013-12-10 00:12 105984 ----a-w- c:\windows\system32\iesysprep.dll 2013-12-10 00:12 . 2013-12-10 00:12 101376 ----a-w- c:\windows\system32\inseng.dll 2013-12-10 00:12 . 2013-12-10 00:12 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2013-12-10 00:12 . 2013-12-10 00:12 774144 ----a-w- c:\windows\system32\jscript.dll 2013-12-10 00:12 . 2013-12-10 00:12 62464 ----a-w- c:\windows\system32\pngfilt.dll 2013-12-10 00:12 . 2013-12-10 00:12 48128 ----a-w- c:\windows\system32\imgutil.dll 2013-12-10 00:12 . 2013-12-10 00:12 147968 ----a-w- c:\windows\system32\occache.dll 2013-12-10 00:12 . 2013-12-10 00:12 13824 ----a-w- c:\windows\system32\mshta.exe 2013-12-10 00:12 . 2013-12-10 00:12 135680 ----a-w- c:\windows\system32\iepeers.dll 2013-11-26 11:54 . 2013-12-11 09:21 23183360 ----a-w- c:\windows\system32\mshtml.dll 2013-11-26 10:19 . 2013-12-11 09:21 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2013-11-26 10:18 . 2013-12-11 09:21 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2013-11-26 09:48 . 2013-12-11 09:21 66048 ----a-w- c:\windows\system32\iesetup.dll 2013-11-26 09:46 . 2013-12-11 09:21 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2013-11-26 09:41 . 2013-12-11 09:21 2764288 ----a-w- c:\windows\system32\iertutil.dll 2013-11-26 09:29 . 2013-12-11 09:21 53760 ----a-w- c:\windows\system32\jsproxy.dll 2013-11-26 09:27 . 2013-12-11 09:21 33792 ----a-w- c:\windows\system32\iernonce.dll 2013-11-26 09:23 . 2013-12-11 09:21 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2013-11-26 09:21 . 2013-12-11 09:21 574976 ----a-w- c:\windows\system32\ieui.dll 2013-11-26 09:18 . 2013-12-11 09:21 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2013-11-26 09:18 . 2013-12-11 09:21 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2013-11-26 09:16 . 2013-12-11 09:21 708608 ----a-w- c:\windows\system32\jscript9diag.dll 2013-11-26 08:57 . 2013-12-11 09:21 218624 ----a-w- c:\windows\system32\ie4uinit.exe 2013-11-26 08:35 . 2013-12-11 09:21 5769216 ----a-w- c:\windows\system32\jscript9.dll 2013-11-26 08:28 . 2013-12-11 09:21 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2013-11-26 08:16 . 2013-12-11 09:21 4243968 ----a-w- c:\windows\SysWow64\jscript9.dll 2013-11-26 08:02 . 2013-12-11 09:21 1995264 ----a-w- c:\windows\system32\inetcpl.cpl 2013-11-26 07:48 . 2013-12-11 09:21 12996608 ----a-w- c:\windows\system32\ieframe.dll 2013-11-26 07:32 . 2013-12-11 09:21 1928192 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-11-26 07:07 . 2013-12-11 09:21 2334208 ----a-w- c:\windows\system32\wininet.dll 2013-11-26 06:40 . 2013-12-11 09:21 1395200 ----a-w- c:\windows\system32\urlmon.dll 2013-11-26 06:34 . 2013-12-11 09:21 817664 ----a-w- c:\windows\system32\ieapfltr.dll 2013-11-26 06:33 . 2013-12-11 09:21 1820160 ----a-w- c:\windows\SysWow64\wininet.dll 2013-11-23 18:26 . 2013-12-11 08:34 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-11-23 17:47 . 2013-12-11 08:34 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-11-22 15:25 . 2012-05-20 01:27 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-11-22 15:25 . 2012-05-20 01:27 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll 2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-02 00:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-07-02 1597440] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x] R1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x] R1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x] R2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] R2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] R2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x] R2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x] R2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x] R2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE;c:\windows\SysWOW64\NLSSRV32.EXE [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [x] R4 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [x] S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys;c:\windows\SYSNATIVE\DRIVERS\lullaby.sys [x] S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x] S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys;c:\windows\SYSNATIVE\DRIVERS\JME.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2014-02-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-02 00:03] . 2014-02-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-02 00:03] . 2014-02-09 c:\windows\Tasks\{EEAE2512-9FA5-4A75-BF5A-45282FE2BAFE}.job - c:\program files (x86)\mozilla firefox\firefox.exe [2014-02-06 13:48] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-01 23:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ETDWare"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU] "SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768] "fssui"="c:\program files (x86)\Windows Live\Family Safety\fsui.exe" [2008-12-08 453984] "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2013-09-12 5618456] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\ FF - prefs.js: browser.startup.homepage - www.google.de FF - ExtSQL: !HIDDEN! 2013-02-18 11:42; {ACAA314B-EEBA-48e4-AD47-84E31C44796C}; c:\program files (x86)\Common Files\DVDVideoSoft\plugins\ff . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Classes\CLSID] @DACL=(02 0000) . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*„Dp] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*„Dp\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ÀR]] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ÀR]\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*Å|Ir] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*Å|Ir\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ˆ»d] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ˆ»d\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*‡ˆvq] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*‡ˆvq\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*w*=] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*w*=\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ô¿ßr] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ô¿ßr\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ÿä<u] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*ÿä<u\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*rþµJ] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*7*rþµJ\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*A*d*a*àþú3\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*a*t*•—x\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*a*v*þeQ`\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*o*c*k*_*s*t*a*‹ðj\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*D*o*l*¦z¿B\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*D*o*l*éîßU\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*F*¡F"] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*F*¡F"\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*H*L-oZ] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*H*L-oZ\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*H*•GÐo] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*H*•GÐo\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*H*¿žK@] @Class="Shell" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*H*¿žK@\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*M*P*4*-*K*T*R*_*m*o*éê?\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*m*p*4*Jmÿ'\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*o*u*t*d*o*o*r*Û5ñf\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID] @DACL=(02 0000) . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}] @DACL=(02 0000) @="Dropbox Autoplay COM Server" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{5E4405B0-5374-11CE-8E71-0020AF04B1D7}] @DACL=(02 0000) "AutoTreatAs"="{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}" "TreatAs"="{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{6D7AE628-FF41-4CD3-91DD-34825BB1A251}] @DACL=(02 0000) @="AutoCAD Application" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{B77E471C-FBF3-4CB5-880F-D7528AD4B349}] @DACL=(02 0000) . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{C92FB640-AD4D-498A-9979-A51A2540C977}] @DACL=(02 0000) . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}] @DACL=(02 0000) @="AutoCAD Drawing" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}] @DACL=(02 0000) @="AutoCAD Icon Shell Extension" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] @DACL=(02 0000) @="DropboxExt" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] @DACL=(02 0000) @="DropboxExt" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] @DACL=(02 0000) @="DropboxExt" . [HKEY_USERS\S-1-5-21-1196340009-827326040-3575104631-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] @DACL=(02 0000) @="DropboxExt" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-02-10 18:53:25 ComboFix-quarantined-files.txt 2014-02-10 17:53 ComboFix2.txt 2014-02-10 16:08 . Vor Suchlauf: 5.042.786.304 Bytes frei Nach Suchlauf: 4.939.288.576 Bytes frei . - - End Of File - - AE391C2C73A1B43CD29926AA3EA0DDF8 |
11.02.2014, 16:40 | #6 | |
/// the machine /// TB-Ausbilder | Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallierenZitat:
Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallieren |
11.02.2014, 23:14 | #7 |
| Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallierenCode:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.02.11.09 Windows 7 Service Pack 1 x64 NTFS (Abgesichertenmodus/Netzwerkfähig) Internet Explorer 11.0.9600.16476 Jens :: JENS-PC [Administrator] 11.02.2014 22:12:31 mbam-log-2014-02-11 (22-12-31).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 246407 Laufzeit: 3 Minute(n), 40 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Habe noch eine ältere Logdatei, da ich Malewarebytes schon vorher installiert habe, bevor du es mir empfohlen hast. Hatte damit auch ein paar Funde. Hier der Log Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.02.09.04 Windows 7 Service Pack 1 x64 NTFS (Abgesichertenmodus/Netzwerkfähig) Internet Explorer 11.0.9600.16476 Jens :: JENS-PC [Administrator] 09.02.2014 17:16:20 mbam-log-2014-02-09 (17-16-20).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 214587 Laufzeit: 4 Minute(n), 54 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 6 HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\DataMngr (PUP.Optional.DataMngr.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\delta LTD (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\AppDataLow\SProtector (PUP.Optional.SProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\BabSolution\Updater (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 1 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.StartPage.A) -> Bösartig: (hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=7850BCAEC506EED7&affID=122471&tsp=5021) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\ProgramData\DSearchLink\DSearchLink.exe (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jens\Downloads\SoftonicDownloader_fuer_cwshredder.exe (PUP.Optional.Softonic.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 11/02/2014 um 22:28:23 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Jens - JENS-PC # Gestartet von : C:\Users\Jens\Downloads\adwcleaner.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\foxydeal.sqlite ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v27.0 (de) [ Datei : C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\prefs.js ] ************************* AdwCleaner[R0].txt - [8196 octets] - [09/02/2014 22:13:16] AdwCleaner[R1].txt - [1336 octets] - [09/02/2014 22:18:35] AdwCleaner[R2].txt - [884 octets] - [11/02/2014 22:28:23] AdwCleaner[S0].txt - [7680 octets] - [09/02/2014 22:14:50] AdwCleaner[S1].txt - [1353 octets] - [09/02/2014 22:19:09] ########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [1063 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.1 (02.04.2014:1) OS: Windows 7 Home Premium x64 Ran by Jens on 11.02.2014 at 22:36:32,77 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1196340009-827326040-3575104631-1001\Software\sweetim Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8BD52629-20FB-49BF-9462-620B4C3B98BA} ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Jens\AppData\Roaming\mozilla\firefox\profiles\4ulxy0ah.default\minidumps [920 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 11.02.2014 at 22:39:44,88 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Emptied folder: C:\Users\Jens\AppData\Roaming\mozilla\firefox\profiles\4ulxy0ah.default\minidumps [920 files] FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-02-2014 01 Ran by Jens (administrator) on JENS-PC on 11-02-2014 23:12:12 Running from C:\Users\Jens\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Safe Mode (with Networking) ==================== Processes (Whitelisted) ================= (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.) HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] () HKLM\...\Run: [fssui] - C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [453984 2008-12-08] (Microsoft Corporation) HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5618456 2013-09-12] (ESET) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-22] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] () HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files (x86)\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default FF NewTab: www.google.de FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @graphisoft.com/GDL Web Plug-in - C:\Program Files (x86)\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll (Graphisoft SE) FF Plugin-x32: @java.com/DTPlugin,version=10.13.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ColorZilla - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2013-06-08] FF Extension: Stylish - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2014-02-08] FF Extension: {5557abbf-cefe-48eb-a400-4001db9881c8} - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{5557abbf-cefe-48eb-a400-4001db9881c8}.xpi [2013-10-30] FF Extension: Adblock Plus - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-05-17] FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-02-10] FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-02-10] ==================== Services (Whitelisted) ================= S2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] () S2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337752 2013-09-12] (ESET) ==================== Drivers (Whitelisted) ==================== S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2013-09-18] () S1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET) S1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET) S2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET) S0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2013-09-18] () S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET) U3 tmlwf; U3 tmwfp; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-11 23:12 - 2014-02-11 23:12 - 00008821 _____ () C:\Users\Jens\Downloads\FRST.txt 2014-02-11 23:04 - 2014-02-11 23:05 - 02151424 _____ (Farbar) C:\Users\Jens\Downloads\FRST64.exe 2014-02-11 22:47 - 2014-02-11 22:47 - 00000624 _____ () C:\Users\Jens\Desktop\JRT.txt 2014-02-11 22:36 - 2014-02-11 22:36 - 01037530 _____ (Thisisu) C:\Users\Jens\Downloads\JRT.exe 2014-02-11 22:36 - 2014-02-11 22:36 - 00000000 ____D () C:\Windows\ERUNT 2014-02-11 22:27 - 2014-02-11 22:27 - 01166132 _____ () C:\Users\Jens\Downloads\adwcleaner.exe 2014-02-11 15:45 - 2014-02-11 16:56 - 00221315 _____ () C:\Users\Jens\Documents\Zeichnung2.bak 2014-02-11 11:55 - 2014-02-11 11:55 - 00001111 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-11 11:55 - 2014-02-11 11:55 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-11 11:55 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-11 11:54 - 2014-02-11 11:55 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jens\Downloads\mbam-setup-1.75.0.1300.exe 2014-02-10 21:38 - 2014-02-10 21:38 - 00000000 _____ () C:\Users\Jens\Desktop\Neues Textdokument.txt 2014-02-10 18:53 - 2014-02-10 18:53 - 00031066 _____ () C:\ComboFix.txt 2014-02-10 18:30 - 2014-02-10 18:30 - 07472232 _____ (Botkind Inc ) C:\Users\Jens\Downloads\allwaysync-14-0-1.exe 2014-02-10 17:59 - 2014-02-10 17:59 - 00002950 _____ () C:\Windows\System32\Tasks\{7ED303BA-33BA-46E8-965A-C906D49B3A73} 2014-02-10 17:59 - 2014-02-10 17:59 - 00002950 _____ () C:\Windows\System32\Tasks\{6690417E-CCB4-4210-8EA8-B114B54DFDD7} 2014-02-10 17:59 - 2014-02-10 17:59 - 00002950 _____ () C:\Windows\System32\Tasks\{1A7D06E0-2C53-4488-A755-D02654ABC725} 2014-02-10 17:47 - 2014-02-10 17:47 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-02-10 17:47 - 2014-02-10 17:47 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-10 17:44 - 2014-02-10 17:44 - 01659552 _____ (Skype Technologies S.A.) C:\Users\Jens\Downloads\SkypeSetup.exe 2014-02-10 17:32 - 2014-02-11 22:51 - 00011627 _____ () C:\Windows\WindowsUpdate.log 2014-02-10 17:30 - 2014-02-10 17:30 - 00000000 ____D () C:\Users\Jens\AppData\Local\Skype 2014-02-10 17:21 - 2014-02-10 17:21 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\ESET 2014-02-10 17:21 - 2014-02-10 17:21 - 00000000 ____D () C:\Users\Jens\AppData\Local\ESET 2014-02-10 17:20 - 2014-02-10 17:20 - 00000000 ____D () C:\ProgramData\ESET 2014-02-10 17:20 - 2014-02-10 17:20 - 00000000 ____D () C:\Program Files\ESET 2014-02-10 16:49 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-10 16:49 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-10 16:49 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-10 16:49 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-10 16:49 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-10 16:49 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-10 16:49 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-10 16:49 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-10 16:48 - 2014-02-10 18:53 - 00000000 ____D () C:\Qoobox 2014-02-10 16:48 - 2014-02-10 17:06 - 00000000 ____D () C:\Windows\erdnt 2014-02-10 16:40 - 2014-02-10 16:41 - 05180173 ____R (Swearware) C:\Users\Jens\Desktop\ComboFix.exe 2014-02-10 00:16 - 2014-02-10 00:16 - 00008224 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-10 00:16 - 2014-02-10 00:16 - 00001423 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-10 00:16 - 2014-02-10 00:16 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-02-10 00:15 - 2014-02-10 00:15 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-10 00:15 - 2014-02-10 00:15 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-02-10 00:13 - 2014-02-10 00:15 - 00000000 ____D () C:\Users\Administrator 2014-02-10 00:13 - 2014-02-10 00:13 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten 2014-02-10 00:13 - 2012-06-08 10:28 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Microsoft Help 2014-02-10 00:13 - 2012-05-17 19:13 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia 2014-02-10 00:13 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-02-10 00:13 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-02-09 23:38 - 2014-02-09 23:38 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll 2014-02-09 22:37 - 2014-02-09 22:37 - 00000000 ____D () C:\Users\Jens\Downloads\tdsskiller 2014-02-09 22:13 - 2014-02-11 22:31 - 00000000 ____D () C:\AdwCleaner 2014-02-09 17:15 - 2014-02-09 17:15 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\Malwarebytes 2014-02-09 17:15 - 2014-02-09 17:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-09 16:51 - 2014-02-09 16:52 - 00000000 ____D () C:\Program Files (x86)\RegCleaner 2014-02-09 16:51 - 2014-02-09 16:51 - 00000960 _____ () C:\Users\Jens\Desktop\RegCleaner.lnk 2014-02-09 16:41 - 2014-02-09 16:41 - 00000380 _____ () C:\Windows\Tasks\{EEAE2512-9FA5-4A75-BF5A-45282FE2BAFE}.job 2014-02-09 13:09 - 2014-02-09 13:09 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-02-09 13:05 - 2014-02-11 23:12 - 00000000 ____D () C:\FRST 2014-02-09 12:50 - 2014-02-10 18:54 - 00003262 _____ () C:\Windows\PFRO.log 2014-02-09 01:00 - 2014-02-11 23:08 - 00004213 _____ () C:\Windows\setupact.log 2014-02-09 01:00 - 2014-02-09 01:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-09 00:33 - 2014-02-09 00:33 - 00532480 _____ (Trend Micro Incorporated) C:\Users\Jens\Desktop\cwshredder_2.19.exe 2014-02-08 23:56 - 2014-02-08 23:56 - 00010860 _____ () C:\Users\Jens\Desktop\hijackthis.log 2014-02-08 23:53 - 2014-02-09 00:43 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\QuickScan 2014-02-08 15:06 - 2014-02-08 15:06 - 00000000 ____D () C:\Users\Jens\Downloads\PasAccXXX 08--02--14 2014-02-06 14:48 - 2014-02-06 14:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-03 19:56 - 2014-02-03 19:59 - 00005632 ___SH () C:\Users\Jens\Thumbs.db 2014-02-03 18:30 - 2014-02-03 19:57 - 00249778 _____ () C:\Users\Jens\Grunriss.dwg 2014-02-03 18:30 - 2014-02-03 19:57 - 00236400 _____ () C:\Users\Jens\Grunriss.bak 2014-01-24 13:56 - 2014-01-24 13:56 - 01815525 _____ () C:\Users\Jens\Documents\Schwarzplan.dwg 2014-01-14 08:51 - 2014-01-14 08:51 - 00000000 ____D () C:\found.000 ==================== One Month Modified Files and Folders ======= 2014-02-11 23:12 - 2014-02-11 23:12 - 00008821 _____ () C:\Users\Jens\Downloads\FRST.txt 2014-02-11 23:12 - 2014-02-09 13:05 - 00000000 ____D () C:\FRST 2014-02-11 23:08 - 2014-02-09 01:00 - 00004213 _____ () C:\Windows\setupact.log 2014-02-11 23:08 - 2013-05-04 04:20 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-11 23:08 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-11 23:05 - 2014-02-11 23:04 - 02151424 _____ (Farbar) C:\Users\Jens\Downloads\FRST64.exe 2014-02-11 23:01 - 2009-07-14 05:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-11 23:01 - 2009-07-14 05:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-11 22:58 - 2009-08-04 10:51 - 00697212 _____ () C:\Windows\system32\perfh007.dat 2014-02-11 22:58 - 2009-08-04 10:51 - 00148492 _____ () C:\Windows\system32\perfc007.dat 2014-02-11 22:58 - 2009-07-14 06:13 - 01612484 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-11 22:51 - 2014-02-10 17:32 - 00011627 _____ () C:\Windows\WindowsUpdate.log 2014-02-11 22:47 - 2014-02-11 22:47 - 00000624 _____ () C:\Users\Jens\Desktop\JRT.txt 2014-02-11 22:36 - 2014-02-11 22:36 - 01037530 _____ (Thisisu) C:\Users\Jens\Downloads\JRT.exe 2014-02-11 22:36 - 2014-02-11 22:36 - 00000000 ____D () C:\Windows\ERUNT 2014-02-11 22:31 - 2014-02-09 22:13 - 00000000 ____D () C:\AdwCleaner 2014-02-11 22:27 - 2014-02-11 22:27 - 01166132 _____ () C:\Users\Jens\Downloads\adwcleaner.exe 2014-02-11 21:48 - 2013-05-04 04:20 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-11 16:56 - 2014-02-11 15:45 - 00221315 _____ () C:\Users\Jens\Documents\Zeichnung2.bak 2014-02-11 11:55 - 2014-02-11 11:55 - 00001111 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-11 11:55 - 2014-02-11 11:55 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-11 11:55 - 2014-02-11 11:54 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jens\Downloads\mbam-setup-1.75.0.1300.exe 2014-02-11 00:42 - 2012-06-12 22:04 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\Skype 2014-02-10 21:38 - 2014-02-10 21:38 - 00000000 _____ () C:\Users\Jens\Desktop\Neues Textdokument.txt 2014-02-10 18:54 - 2014-02-09 12:50 - 00003262 _____ () C:\Windows\PFRO.log 2014-02-10 18:53 - 2014-02-10 18:53 - 00031066 _____ () C:\ComboFix.txt 2014-02-10 18:53 - 2014-02-10 16:48 - 00000000 ____D () C:\Qoobox 2014-02-10 18:50 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-10 18:30 - 2014-02-10 18:30 - 07472232 _____ (Botkind Inc ) C:\Users\Jens\Downloads\allwaysync-14-0-1.exe 2014-02-10 18:23 - 2010-10-28 12:38 - 00002158 _____ () C:\Windows\system32\AutoRunFilter.ini 2014-02-10 18:23 - 2010-10-28 12:38 - 00001516 _____ () C:\Windows\system32\ServiceFilter.ini 2014-02-10 17:59 - 2014-02-10 17:59 - 00002950 _____ () C:\Windows\System32\Tasks\{7ED303BA-33BA-46E8-965A-C906D49B3A73} 2014-02-10 17:59 - 2014-02-10 17:59 - 00002950 _____ () C:\Windows\System32\Tasks\{6690417E-CCB4-4210-8EA8-B114B54DFDD7} 2014-02-10 17:59 - 2014-02-10 17:59 - 00002950 _____ () C:\Windows\System32\Tasks\{1A7D06E0-2C53-4488-A755-D02654ABC725} 2014-02-10 17:47 - 2014-02-10 17:47 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-02-10 17:47 - 2014-02-10 17:47 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-10 17:47 - 2012-10-30 14:15 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\Graphisoft 2014-02-10 17:47 - 2012-10-29 19:16 - 00000000 ____D () C:\Program Files\GRAPHISOFT 2014-02-10 17:47 - 2012-06-12 22:03 - 00000000 ____D () C:\ProgramData\Skype 2014-02-10 17:46 - 2012-10-29 19:21 - 00000000 _____ () C:\Windows\vpd.properties 2014-02-10 17:44 - 2014-02-10 17:44 - 01659552 _____ (Skype Technologies S.A.) C:\Users\Jens\Downloads\SkypeSetup.exe 2014-02-10 17:30 - 2014-02-10 17:30 - 00000000 ____D () C:\Users\Jens\AppData\Local\Skype 2014-02-10 17:21 - 2014-02-10 17:21 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\ESET 2014-02-10 17:21 - 2014-02-10 17:21 - 00000000 ____D () C:\Users\Jens\AppData\Local\ESET 2014-02-10 17:20 - 2014-02-10 17:20 - 00000000 ____D () C:\ProgramData\ESET 2014-02-10 17:20 - 2014-02-10 17:20 - 00000000 ____D () C:\Program Files\ESET 2014-02-10 17:08 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-02-10 17:06 - 2014-02-10 16:48 - 00000000 ____D () C:\Windows\erdnt 2014-02-10 16:41 - 2014-02-10 16:40 - 05180173 ____R (Swearware) C:\Users\Jens\Desktop\ComboFix.exe 2014-02-10 14:33 - 2012-05-17 22:17 - 00000000 ____D () C:\Users\Jens\AppData\Local\cache 2014-02-10 00:16 - 2014-02-10 00:16 - 00008224 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-10 00:16 - 2014-02-10 00:16 - 00001423 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-10 00:16 - 2014-02-10 00:16 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-02-10 00:15 - 2014-02-10 00:15 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-10 00:15 - 2014-02-10 00:15 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-02-10 00:15 - 2014-02-10 00:13 - 00000000 ____D () C:\Users\Administrator 2014-02-10 00:13 - 2014-02-10 00:13 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten 2014-02-09 23:38 - 2014-02-09 23:38 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll 2014-02-09 22:37 - 2014-02-09 22:37 - 00000000 ____D () C:\Users\Jens\Downloads\tdsskiller 2014-02-09 17:15 - 2014-02-09 17:15 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\Malwarebytes 2014-02-09 17:15 - 2014-02-09 17:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-09 16:52 - 2014-02-09 16:51 - 00000000 ____D () C:\Program Files (x86)\RegCleaner 2014-02-09 16:51 - 2014-02-09 16:51 - 00000960 _____ () C:\Users\Jens\Desktop\RegCleaner.lnk 2014-02-09 16:41 - 2014-02-09 16:41 - 00000380 _____ () C:\Windows\Tasks\{EEAE2512-9FA5-4A75-BF5A-45282FE2BAFE}.job 2014-02-09 13:09 - 2014-02-09 13:09 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-02-09 12:36 - 2013-08-05 21:14 - 00000000 ____D () C:\ProgramData\Avira 2014-02-09 01:00 - 2014-02-09 01:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-09 00:43 - 2014-02-08 23:53 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\QuickScan 2014-02-09 00:33 - 2014-02-09 00:33 - 00532480 _____ (Trend Micro Incorporated) C:\Users\Jens\Desktop\cwshredder_2.19.exe 2014-02-08 23:56 - 2014-02-08 23:56 - 00010860 _____ () C:\Users\Jens\Desktop\hijackthis.log 2014-02-08 23:20 - 2012-05-17 22:21 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\vlc 2014-02-08 15:06 - 2014-02-08 15:06 - 00000000 ____D () C:\Users\Jens\Downloads\PasAccXXX 08--02--14 2014-02-08 14:48 - 2013-04-06 20:58 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-02-06 23:15 - 2012-05-17 18:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-06 14:48 - 2014-02-06 14:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-05 23:50 - 2013-10-28 18:10 - 00007123 _____ () C:\Users\Jens\Documents\plot.log 2014-02-03 19:59 - 2014-02-03 19:56 - 00005632 ___SH () C:\Users\Jens\Thumbs.db 2014-02-03 19:57 - 2014-02-03 18:30 - 00249778 _____ () C:\Users\Jens\Grunriss.dwg 2014-02-03 19:57 - 2014-02-03 18:30 - 00236400 _____ () C:\Users\Jens\Grunriss.bak 2014-02-03 19:57 - 2012-05-17 18:44 - 00000000 ____D () C:\Users\Jens 2014-01-24 13:56 - 2014-01-24 13:56 - 01815525 _____ () C:\Users\Jens\Documents\Schwarzplan.dwg 2014-01-22 21:17 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-14 08:51 - 2014-01-14 08:51 - 00000000 ____D () C:\found.000 2014-01-12 15:32 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF Files to move or delete: ==================== C:\Windows\Tasks\{EEAE2512-9FA5-4A75-BF5A-45282FE2BAFE}.job Some content of TEMP: ==================== C:\Users\Jens\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-09 03:47 ==================== End Of Log ============================ --- --- --- |
12.02.2014, 18:30 | #8 |
/// the machine /// TB-Ausbilder | Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallierenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.02.2014, 00:43 | #9 |
| Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallierenCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=2b6109ad6086514287c83dc1ac69309f # engine=17003 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-02-09 01:25:19 # local_time=2014-02-09 02:25:19 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 66 85 18474554 143582169 0 0 # scanned=274208 # found=0 # cleaned=0 # scan_time=4459 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=2b6109ad6086514287c83dc1ac69309f # engine=17048 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-02-12 11:08:32 # local_time=2014-02-13 12:08:32 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 66 85 18768747 143876362 0 0 # scanned=259997 # found=0 # cleaned=0 # scan_time=5941 # nod_component=V3 Build:0x30000000 Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Security Center service is not running! This report may not be accurate! ESET Smart Security 7.0 Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 JavaFX 2.1.1 Java(TM) 6 Update 32 Java 7 Update 13 Java version out of Date! Adobe Flash Player 11.9.900.152 Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox (27.0) ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-02-2014 01 Ran by Jens (administrator) on JENS-PC on 13-02-2014 00:22:27 Running from C:\Users\Jens\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Safe Mode (with Networking) ==================== Processes (Whitelisted) ================= (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.) HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] () HKLM\...\Run: [fssui] - C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe [453984 2008-12-08] (Microsoft Corporation) HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5618456 2013-09-12] (ESET) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-22] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] () HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files (x86)\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default FF NewTab: www.google.de FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @graphisoft.com/GDL Web Plug-in - C:\Program Files (x86)\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll (Graphisoft SE) FF Plugin-x32: @java.com/DTPlugin,version=10.13.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ColorZilla - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2013-06-08] FF Extension: Stylish - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2014-02-08] FF Extension: {5557abbf-cefe-48eb-a400-4001db9881c8} - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{5557abbf-cefe-48eb-a400-4001db9881c8}.xpi [2013-10-30] FF Extension: Adblock Plus - C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\4ulxy0ah.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-05-17] FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-02-10] FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-02-10] ==================== Services (Whitelisted) ================= S2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] () S2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337752 2013-09-12] (ESET) ==================== Drivers (Whitelisted) ==================== S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2013-09-18] () S1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET) S1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET) S2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET) S0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2013-09-18] () S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET) U3 tmlwf; U3 tmwfp; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-13 00:22 - 2014-02-13 00:22 - 00000000 ____D () C:\Users\Jens\Downloads\FRST-OlderVersion 2014-02-13 00:18 - 2014-02-13 00:18 - 00987425 _____ () C:\Users\Jens\Desktop\SecurityCheck.exe 2014-02-12 22:23 - 2014-02-12 22:23 - 02347384 _____ (ESET) C:\Users\Jens\Downloads\esetsmartinstaller_enu.exe 2014-02-11 23:12 - 2014-02-13 00:22 - 00009079 _____ () C:\Users\Jens\Downloads\FRST.txt 2014-02-11 23:04 - 2014-02-13 00:22 - 02152448 _____ (Farbar) C:\Users\Jens\Downloads\FRST64.exe 2014-02-11 22:47 - 2014-02-11 22:47 - 00000624 _____ () C:\Users\Jens\Desktop\JRT.txt 2014-02-11 22:36 - 2014-02-11 22:36 - 01037530 _____ (Thisisu) C:\Users\Jens\Downloads\JRT.exe 2014-02-11 22:36 - 2014-02-11 22:36 - 00000000 ____D () C:\Windows\ERUNT 2014-02-11 22:27 - 2014-02-11 22:27 - 01166132 _____ () C:\Users\Jens\Downloads\adwcleaner.exe 2014-02-11 15:45 - 2014-02-11 16:56 - 00221315 _____ () C:\Users\Jens\Documents\Zeichnung2.bak 2014-02-11 11:55 - 2014-02-11 11:55 - 00001111 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-11 11:55 - 2014-02-11 11:55 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-11 11:55 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-11 11:54 - 2014-02-11 11:55 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jens\Downloads\mbam-setup-1.75.0.1300.exe 2014-02-10 21:38 - 2014-02-10 21:38 - 00000000 _____ () C:\Users\Jens\Desktop\Neues Textdokument.txt 2014-02-10 18:53 - 2014-02-10 18:53 - 00031066 _____ () C:\ComboFix.txt 2014-02-10 18:30 - 2014-02-10 18:30 - 07472232 _____ (Botkind Inc ) C:\Users\Jens\Downloads\allwaysync-14-0-1.exe 2014-02-10 17:59 - 2014-02-10 17:59 - 00002950 _____ () C:\Windows\System32\Tasks\{7ED303BA-33BA-46E8-965A-C906D49B3A73} 2014-02-10 17:59 - 2014-02-10 17:59 - 00002950 _____ () C:\Windows\System32\Tasks\{6690417E-CCB4-4210-8EA8-B114B54DFDD7} 2014-02-10 17:59 - 2014-02-10 17:59 - 00002950 _____ () C:\Windows\System32\Tasks\{1A7D06E0-2C53-4488-A755-D02654ABC725} 2014-02-10 17:47 - 2014-02-10 17:47 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-02-10 17:47 - 2014-02-10 17:47 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-10 17:44 - 2014-02-10 17:44 - 01659552 _____ (Skype Technologies S.A.) C:\Users\Jens\Downloads\SkypeSetup.exe 2014-02-10 17:32 - 2014-02-12 20:16 - 00015859 _____ () C:\Windows\WindowsUpdate.log 2014-02-10 17:30 - 2014-02-10 17:30 - 00000000 ____D () C:\Users\Jens\AppData\Local\Skype 2014-02-10 17:21 - 2014-02-10 17:21 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\ESET 2014-02-10 17:21 - 2014-02-10 17:21 - 00000000 ____D () C:\Users\Jens\AppData\Local\ESET 2014-02-10 17:20 - 2014-02-10 17:20 - 00000000 ____D () C:\ProgramData\ESET 2014-02-10 17:20 - 2014-02-10 17:20 - 00000000 ____D () C:\Program Files\ESET 2014-02-10 16:49 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-10 16:49 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-10 16:49 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-10 16:49 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-10 16:49 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-10 16:49 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-10 16:49 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-10 16:49 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-10 16:48 - 2014-02-10 18:53 - 00000000 ____D () C:\Qoobox 2014-02-10 16:48 - 2014-02-10 17:06 - 00000000 ____D () C:\Windows\erdnt 2014-02-10 16:40 - 2014-02-10 16:41 - 05180173 ____R (Swearware) C:\Users\Jens\Desktop\ComboFix.exe 2014-02-10 00:16 - 2014-02-10 00:16 - 00008224 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-10 00:16 - 2014-02-10 00:16 - 00001423 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-10 00:16 - 2014-02-10 00:16 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-02-10 00:15 - 2014-02-10 00:15 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-10 00:15 - 2014-02-10 00:15 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-02-10 00:13 - 2014-02-10 00:15 - 00000000 ____D () C:\Users\Administrator 2014-02-10 00:13 - 2014-02-10 00:13 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten 2014-02-10 00:13 - 2012-06-08 10:28 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Microsoft Help 2014-02-10 00:13 - 2012-05-17 19:13 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia 2014-02-10 00:13 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-02-10 00:13 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-02-09 23:38 - 2014-02-09 23:38 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll 2014-02-09 22:37 - 2014-02-09 22:37 - 00000000 ____D () C:\Users\Jens\Downloads\tdsskiller 2014-02-09 22:13 - 2014-02-11 22:31 - 00000000 ____D () C:\AdwCleaner 2014-02-09 17:15 - 2014-02-09 17:15 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\Malwarebytes 2014-02-09 17:15 - 2014-02-09 17:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-09 16:51 - 2014-02-09 16:52 - 00000000 ____D () C:\Program Files (x86)\RegCleaner 2014-02-09 16:51 - 2014-02-09 16:51 - 00000960 _____ () C:\Users\Jens\Desktop\RegCleaner.lnk 2014-02-09 16:41 - 2014-02-09 16:41 - 00000380 _____ () C:\Windows\Tasks\{EEAE2512-9FA5-4A75-BF5A-45282FE2BAFE}.job 2014-02-09 13:05 - 2014-02-13 00:22 - 00000000 ____D () C:\FRST 2014-02-09 12:50 - 2014-02-10 18:54 - 00003262 _____ () C:\Windows\PFRO.log 2014-02-09 01:00 - 2014-02-12 21:34 - 00005682 _____ () C:\Windows\setupact.log 2014-02-09 01:00 - 2014-02-09 01:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-09 00:33 - 2014-02-09 00:33 - 00532480 _____ (Trend Micro Incorporated) C:\Users\Jens\Desktop\cwshredder_2.19.exe 2014-02-08 23:56 - 2014-02-08 23:56 - 00010860 _____ () C:\Users\Jens\Desktop\hijackthis.log 2014-02-08 23:53 - 2014-02-09 00:43 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\QuickScan 2014-02-08 15:06 - 2014-02-08 15:06 - 00000000 ____D () C:\Users\Jens\Downloads\PasAccXXX 08--02--14 2014-02-06 14:48 - 2014-02-06 14:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-03 19:56 - 2014-02-03 19:59 - 00005632 ___SH () C:\Users\Jens\Thumbs.db 2014-02-03 18:30 - 2014-02-03 19:57 - 00249778 _____ () C:\Users\Jens\Grunriss.dwg 2014-02-03 18:30 - 2014-02-03 19:57 - 00236400 _____ () C:\Users\Jens\Grunriss.bak 2014-01-24 13:56 - 2014-01-24 13:56 - 01815525 _____ () C:\Users\Jens\Documents\Schwarzplan.dwg 2014-01-14 08:51 - 2014-01-14 08:51 - 00000000 ____D () C:\found.000 ==================== One Month Modified Files and Folders ======= 2014-02-13 00:22 - 2014-02-13 00:22 - 00000000 ____D () C:\Users\Jens\Downloads\FRST-OlderVersion 2014-02-13 00:22 - 2014-02-11 23:12 - 00009079 _____ () C:\Users\Jens\Downloads\FRST.txt 2014-02-13 00:22 - 2014-02-11 23:04 - 02152448 _____ (Farbar) C:\Users\Jens\Downloads\FRST64.exe 2014-02-13 00:22 - 2014-02-09 13:05 - 00000000 ____D () C:\FRST 2014-02-13 00:18 - 2014-02-13 00:18 - 00987425 _____ () C:\Users\Jens\Desktop\SecurityCheck.exe 2014-02-12 23:54 - 2012-06-12 22:04 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\Skype 2014-02-12 22:23 - 2014-02-12 22:23 - 02347384 _____ (ESET) C:\Users\Jens\Downloads\esetsmartinstaller_enu.exe 2014-02-12 21:48 - 2013-05-04 04:20 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-12 21:34 - 2014-02-09 01:00 - 00005682 _____ () C:\Windows\setupact.log 2014-02-12 21:18 - 2009-08-04 10:51 - 00697212 _____ () C:\Windows\system32\perfh007.dat 2014-02-12 21:18 - 2009-08-04 10:51 - 00148492 _____ () C:\Windows\system32\perfc007.dat 2014-02-12 21:18 - 2009-07-14 06:13 - 01612484 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-12 20:21 - 2009-07-14 05:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-12 20:21 - 2009-07-14 05:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-12 20:16 - 2014-02-10 17:32 - 00015859 _____ () C:\Windows\WindowsUpdate.log 2014-02-12 20:16 - 2013-05-04 04:20 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-12 20:13 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-12 18:07 - 2013-10-28 18:10 - 00007929 _____ () C:\Users\Jens\Documents\plot.log 2014-02-11 22:47 - 2014-02-11 22:47 - 00000624 _____ () C:\Users\Jens\Desktop\JRT.txt 2014-02-11 22:36 - 2014-02-11 22:36 - 01037530 _____ (Thisisu) C:\Users\Jens\Downloads\JRT.exe 2014-02-11 22:36 - 2014-02-11 22:36 - 00000000 ____D () C:\Windows\ERUNT 2014-02-11 22:31 - 2014-02-09 22:13 - 00000000 ____D () C:\AdwCleaner 2014-02-11 22:27 - 2014-02-11 22:27 - 01166132 _____ () C:\Users\Jens\Downloads\adwcleaner.exe 2014-02-11 16:56 - 2014-02-11 15:45 - 00221315 _____ () C:\Users\Jens\Documents\Zeichnung2.bak 2014-02-11 11:55 - 2014-02-11 11:55 - 00001111 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-11 11:55 - 2014-02-11 11:55 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-11 11:55 - 2014-02-11 11:54 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jens\Downloads\mbam-setup-1.75.0.1300.exe 2014-02-10 21:38 - 2014-02-10 21:38 - 00000000 _____ () C:\Users\Jens\Desktop\Neues Textdokument.txt 2014-02-10 18:54 - 2014-02-09 12:50 - 00003262 _____ () C:\Windows\PFRO.log 2014-02-10 18:53 - 2014-02-10 18:53 - 00031066 _____ () C:\ComboFix.txt 2014-02-10 18:53 - 2014-02-10 16:48 - 00000000 ____D () C:\Qoobox 2014-02-10 18:50 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-10 18:30 - 2014-02-10 18:30 - 07472232 _____ (Botkind Inc ) C:\Users\Jens\Downloads\allwaysync-14-0-1.exe 2014-02-10 18:23 - 2010-10-28 12:38 - 00002158 _____ () C:\Windows\system32\AutoRunFilter.ini 2014-02-10 18:23 - 2010-10-28 12:38 - 00001516 _____ () C:\Windows\system32\ServiceFilter.ini 2014-02-10 17:59 - 2014-02-10 17:59 - 00002950 _____ () C:\Windows\System32\Tasks\{7ED303BA-33BA-46E8-965A-C906D49B3A73} 2014-02-10 17:59 - 2014-02-10 17:59 - 00002950 _____ () C:\Windows\System32\Tasks\{6690417E-CCB4-4210-8EA8-B114B54DFDD7} 2014-02-10 17:59 - 2014-02-10 17:59 - 00002950 _____ () C:\Windows\System32\Tasks\{1A7D06E0-2C53-4488-A755-D02654ABC725} 2014-02-10 17:47 - 2014-02-10 17:47 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-02-10 17:47 - 2014-02-10 17:47 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-10 17:47 - 2012-10-30 14:15 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\Graphisoft 2014-02-10 17:47 - 2012-10-29 19:16 - 00000000 ____D () C:\Program Files\GRAPHISOFT 2014-02-10 17:47 - 2012-06-12 22:03 - 00000000 ____D () C:\ProgramData\Skype 2014-02-10 17:46 - 2012-10-29 19:21 - 00000000 _____ () C:\Windows\vpd.properties 2014-02-10 17:44 - 2014-02-10 17:44 - 01659552 _____ (Skype Technologies S.A.) C:\Users\Jens\Downloads\SkypeSetup.exe 2014-02-10 17:30 - 2014-02-10 17:30 - 00000000 ____D () C:\Users\Jens\AppData\Local\Skype 2014-02-10 17:21 - 2014-02-10 17:21 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\ESET 2014-02-10 17:21 - 2014-02-10 17:21 - 00000000 ____D () C:\Users\Jens\AppData\Local\ESET 2014-02-10 17:20 - 2014-02-10 17:20 - 00000000 ____D () C:\ProgramData\ESET 2014-02-10 17:20 - 2014-02-10 17:20 - 00000000 ____D () C:\Program Files\ESET 2014-02-10 17:08 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-02-10 17:06 - 2014-02-10 16:48 - 00000000 ____D () C:\Windows\erdnt 2014-02-10 16:41 - 2014-02-10 16:40 - 05180173 ____R (Swearware) C:\Users\Jens\Desktop\ComboFix.exe 2014-02-10 14:33 - 2012-05-17 22:17 - 00000000 ____D () C:\Users\Jens\AppData\Local\cache 2014-02-10 00:16 - 2014-02-10 00:16 - 00008224 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-10 00:16 - 2014-02-10 00:16 - 00001423 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-10 00:16 - 2014-02-10 00:16 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-02-10 00:15 - 2014-02-10 00:15 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-10 00:15 - 2014-02-10 00:15 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-02-10 00:15 - 2014-02-10 00:13 - 00000000 ____D () C:\Users\Administrator 2014-02-10 00:13 - 2014-02-10 00:13 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-02-10 00:13 - 2014-02-10 00:13 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten 2014-02-09 23:38 - 2014-02-09 23:38 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll 2014-02-09 22:37 - 2014-02-09 22:37 - 00000000 ____D () C:\Users\Jens\Downloads\tdsskiller 2014-02-09 17:15 - 2014-02-09 17:15 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\Malwarebytes 2014-02-09 17:15 - 2014-02-09 17:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-09 16:52 - 2014-02-09 16:51 - 00000000 ____D () C:\Program Files (x86)\RegCleaner 2014-02-09 16:51 - 2014-02-09 16:51 - 00000960 _____ () C:\Users\Jens\Desktop\RegCleaner.lnk 2014-02-09 16:41 - 2014-02-09 16:41 - 00000380 _____ () C:\Windows\Tasks\{EEAE2512-9FA5-4A75-BF5A-45282FE2BAFE}.job 2014-02-09 12:36 - 2013-08-05 21:14 - 00000000 ____D () C:\ProgramData\Avira 2014-02-09 01:00 - 2014-02-09 01:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-09 00:43 - 2014-02-08 23:53 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\QuickScan 2014-02-09 00:33 - 2014-02-09 00:33 - 00532480 _____ (Trend Micro Incorporated) C:\Users\Jens\Desktop\cwshredder_2.19.exe 2014-02-08 23:56 - 2014-02-08 23:56 - 00010860 _____ () C:\Users\Jens\Desktop\hijackthis.log 2014-02-08 23:20 - 2012-05-17 22:21 - 00000000 ____D () C:\Users\Jens\AppData\Roaming\vlc 2014-02-08 15:06 - 2014-02-08 15:06 - 00000000 ____D () C:\Users\Jens\Downloads\PasAccXXX 08--02--14 2014-02-08 14:48 - 2013-04-06 20:58 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-02-06 23:15 - 2012-05-17 18:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-06 14:48 - 2014-02-06 14:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-03 19:59 - 2014-02-03 19:56 - 00005632 ___SH () C:\Users\Jens\Thumbs.db 2014-02-03 19:57 - 2014-02-03 18:30 - 00249778 _____ () C:\Users\Jens\Grunriss.dwg 2014-02-03 19:57 - 2014-02-03 18:30 - 00236400 _____ () C:\Users\Jens\Grunriss.bak 2014-02-03 19:57 - 2012-05-17 18:44 - 00000000 ____D () C:\Users\Jens 2014-01-24 13:56 - 2014-01-24 13:56 - 01815525 _____ () C:\Users\Jens\Documents\Schwarzplan.dwg 2014-01-22 21:17 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-14 08:51 - 2014-01-14 08:51 - 00000000 ____D () C:\found.000 Files to move or delete: ==================== C:\Windows\Tasks\{EEAE2512-9FA5-4A75-BF5A-45282FE2BAFE}.job Some content of TEMP: ==================== C:\Users\Jens\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-09 03:47 ==================== End Of Log ============================ --- --- --- --- --- --- Alles wie beschrieben ausgeführt. Probleme bestehen nachwievor. |
13.02.2014, 22:22 | #10 |
/// the machine /// TB-Ausbilder | Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallieren Java und Adobe updten. Downloade dir bitte Windows Repair (All In One) von hier.
Downloade dir bitte Farbar Service Scanner
Poste bitte den Inhalt hier.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.02.2014, 12:01 | #11 |
| Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallieren Adobe konnte ich updaten, im abgesicherten Modus, Java leider nicht. Das Tweaking tool lief auch nur im abgesicherten Modus, weswegen eine Meldung gezeigt wurde, das einige Reperaturen wohl nicht funktionieren. Im normalen Modus kann ich es nicht starten, da es sich durch Doppelklick als Administator startet. Gibt es vielleicht eine Möglichkeit das zu umgehen? Code:
ATTFilter Farbar Service Scanner Version: 02-02-2014 Ran by Jens (administrator) on 15-02-2014 at 11:44:25 Running from "C:\Users\Jens\Downloads" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Network **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ SDRSVC Service is not running. Checking service configuration: The start type of SDRSVC service is OK. The ImagePath of SDRSVC service is OK. The ServiceDll of SDRSVC service is OK. VSS Service is not running. Checking service configuration: The start type of VSS service is OK. The ImagePath of VSS service is OK. System Restore Disabled Policy: ======================== Action Center: ============ wscsvc Service is not running. Checking service configuration: The start type of wscsvc service is OK. The ImagePath of wscsvc service is OK. The ServiceDll of wscsvc service is OK. Windows Update: ============ wuauserv Service is not running. Checking service configuration: The start type of wuauserv service is OK. The ImagePath of wuauserv service is OK. The ServiceDll of wuauserv service is OK. BITS Service is not running. Checking service configuration: The start type of BITS service is set to Demand. The default start type is Auto. The ImagePath of BITS service is OK. The ServiceDll of BITS service is OK. EventSystem Service is not running. Checking service configuration: The start type of EventSystem service is OK. The ImagePath of EventSystem service is OK. The ServiceDll of EventSystem service is OK. Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Windows Defender Disabled Policy: ========================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=DWORD:1 Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** |
16.02.2014, 07:15 | #12 | |
/// the machine /// TB-Ausbilder | Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallierenZitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.02.2014, 11:42 | #13 |
| Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallieren Doch, das ist mein Rechner und ich bin auch "eigentlich" der Admin. Aber scheinbar besteht ja irgendein Defekt, der mir nicht mehr alle Adminrechte einräumt. Hin und wieder kam auch die Fehlermeldung (ich glaube, als ich etwas deinstallieren wollte) "Der Systemadminstrator hat Richtilinien erlassen...." |
17.02.2014, 13:14 | #14 | ||
/// the machine /// TB-Ausbilder | Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallierenZitat:
Zitat:
was genau passiert wenn Du nen Doppelklick auf Tweaking machst?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.02.2014, 14:41 | #15 | |
| Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallierenZitat:
Das gilt auch für alle anderen Programme, wenn ich diese mit Rechtsklick und "Als Adminstrator ausführen" starten möchte. Auf dem Icon von Tweaking und auch von Combo Fix ist dieses blau gelbe Schild. Deswegen gehe ich davon aus, dass es sich durch einen Doppelklick automatisch als Administrator ausführt. Geändert von seki (18.02.2014 um 14:49 Uhr) |
Themen zu Kann keine exe Dateien mehr ausführen um neue Programme zu installieren/deinstallieren |
button, dateien, eingeschränkt, exe, hijackthis, lsass.exe, neue, probleme, programm, programme, pup.optional.babylon.a, pup.optional.datamngr.a, pup.optional.delta.a, pup.optional.softonic.a, pup.optional.sprotector.a, pup.optional.startpage.a, schriftart, system32, systemprozess, update, windows update |