|
Plagegeister aller Art und deren Bekämpfung: Win 7 64 Bit HP awesomehp und Delta-Search eingeschränkter InternetzugangWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
11.02.2014, 19:41 | #1 |
| Win 7 64 Bit HP awesomehp und Delta-Search eingeschränkter Internetzugang Habe den Rechner von einem Bekannten zur Prüfung bekommen. Internet geht nicht mehr, war die Fehlerbeschreibung. Blick in die installierten Programme = Katastrophe. Alle Unnütze deinstalliert. Fehler immer noch. Malwarebytes installiert, gescannt und geputzt. Fehler immer noch. ADW-Cleaner, JRT und Combifix probiert. Kein Erfolg. Bitte um Hilfe! Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-02-2014 01 Ran by Tino at 2014-02-11 18:28:06 Running from F:\ Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Internet Security (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Internet Security (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: avast! Internet Security (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0} ==================== Installed Programs ====================== 7-Zip 9.20 (x32 Version: - ) 802.11n Wireless LAN Card (x32 Version: 3.01.18.0 - Ralink) Adobe AIR (x32 Version: 4.0.0.1390 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 4.0.0.1390 - Adobe Systems Incorporated) Hidden Adobe Flash Player 12 ActiveX (x32 Version: 12.0.0.44 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.44 - Adobe Systems Incorporated) Adobe Reader X (10.1.9) - Deutsch (x32 Version: 10.1.9 - Adobe Systems Incorporated) Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden AMD APP SDK Runtime (Version: 2.4.595.10 - Advanced Micro Devices Inc.) Hidden AMD VISION Engine Control Center (x32 Version: 2011.0531.2216.38124 - ATI) Hidden ArcSoft PhotoStudio 5.5 (x32 Version: - ArcSoft) ATI Catalyst Install Manager (Version: 3.0.825.0 - ATI Technologies, Inc.) avast! Internet Security (x32 Version: 9.0.2013 - Avast Software) AVS Update Manager 1.0 (x32 Version: - Online Media Technologies Ltd.) AVS Video ReMaker 4.1.4.150 (x32 Version: 4.1.4.150 - Online Media Technologies Ltd.) Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden Blasterball 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden Bounce Symphony (x32 Version: 2.2.0.97 - WildTangent) Hidden Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden CameraHelperMsi (x32 Version: 13.30.1395.0 - Logitech) Hidden Canon MX350 series MP Drivers (Version: - ) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0531.2216.38124 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2011.0531.2216.38124 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2011.0531.2216.38124 - ATI) Hidden Catalyst Control Center Profiles Desktop (x32 Version: 2011.0531.2216.38124 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Czech (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Danish (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Dutch (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help English (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Finnish (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help French (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help German (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Greek (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Hungarian (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Italian (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Japanese (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Korean (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Norwegian (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Polish (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Portuguese (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Russian (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Spanish (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Swedish (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Thai (x32 Version: 2011.0531.2215.38124 - ATI) Hidden CCC Help Turkish (x32 Version: 2011.0531.2215.38124 - ATI) Hidden ccc-utility64 (Version: 2011.0531.2216.38124 - ATI) Hidden Chronicles of Albian (x32 Version: 2.2.0.95 - WildTangent) Hidden Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Cradle of Rome 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DolbyFiles (x32 Version: 2.0 - Nero AG) Hidden erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden Firebird SQL Server - MAGIX Edition (x32 Version: 2.1.32.0 - MAGIX AG) FormatFactory 2.80 (x32 Version: 2.80 - Free Time) FotoArchiv XL (x32 Version: Aktuelle Version - IN MEDIA KG) FotoWorks XL (x32 Version: Aktuelle Version - IN MEDIA KG) Free DVD MP3 Ripper 1.12 (x32 Version: - Jodix Technologies Ltd.) Free Studio version 5.7.4.918 (x32 Version: 5.7.4.918 - DVDVideoSoft Ltd.) Google Chrome (HKCU Version: 32.0.1700.107 - Google Inc.) Google Drive (x32 Version: 1.12.5329.1887 - Google, Inc.) Google Update Helper (x32 Version: 1.3.21.123 - Google Inc.) Hidden Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Auto (Version: 1.0.12935.3667 - Hewlett-Packard Company) Hidden HP Client Services (Version: 1.1.12938.3539 - Hewlett-Packard) Hidden HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden HP Games (x32 Version: 1.0.2.5 - WildTangent) HP LinkUp (x32 Version: 2.01.028 - Hewlett-Packard) HP Odometer (x32 Version: 2.10.0000 - Hewlett-Packard) HP Setup (x32 Version: 8.7.4747.3786 - Hewlett-Packard Company) HP Setup Manager (x32 Version: 1.1.13880.3792 - Hewlett-Packard Company) HP Support Assistant (x32 Version: 7.0.39.15 - Hewlett-Packard Company) HP Support Information (x32 Version: 10.1.1000 - Hewlett-Packard) HP Update (x32 Version: 5.003.001.001 - Hewlett-Packard) HP Vision Hardware Diagnostics (Version: 2.9.0.0 - Hewlett-Packard) HydraVision (x32 Version: 4.2.200.0 - ATI Technologies Inc.) Hidden ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden Internet-TV für Windows Media Center (x32 Version: 4.2.2.0 - Microsoft Corporation) InterVideo WinDVD Platinum (x32 Version: 4.5.28.88 - InterVideo Inc.) Java 7 Update 17 (64-bit) (Version: 7.0.170 - Oracle) Java 7 Update 51 (x32 Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden Jewel Quest: The Sleepless Star - Collector's Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LabelPrint (x32 Version: 2.5.3925 - CyberLink Corp.) LabelPrint (x32 Version: 2.5.3925 - CyberLink Corp.) Hidden Logitech Vid HD (x32 Version: 7.2 (7240) - Logitech Inc..) Logitech Webcam Software (x32 Version: 2.0 - Logitech Inc.) LWS Facebook (x32 Version: 13.30.1346.0 - Logitech) Hidden LWS Gallery (x32 Version: 13.30.1379.0 - Logitech) Hidden LWS Help_main (x32 Version: 13.30.1396.0 - Logitech) Hidden LWS Launcher (x32 Version: 13.30.1379.0 - Logitech) Hidden LWS Motion Detection (x32 Version: 13.30.1395.0 - Logitech) Hidden LWS Pictures And Video (x32 Version: 13.30.1395.0 - Logitech) Hidden LWS Twitter (x32 Version: 13.30.1346.0 - Logitech) Hidden LWS Video Mask Maker (x32 Version: 13.30.1379.0 - Logitech) Hidden LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden LWS Webcam Software (x32 Version: 13.30.1379.0 - Logitech) Hidden LWS WLM Plugin (x32 Version: 1.30.1201.0 - Logitech) Hidden LWS YouTube Plugin (x32 Version: 13.30.1346.0 - Logitech) Hidden MAGIX Foto Manager MX Deluxe (Version: 9.0.2.251 - MAGIX AG) Hidden MAGIX Foto Manager MX Deluxe (x32 Version: 9.0.2.251 - MAGIX AG) MAGIX Fotos auf CD & DVD 10 (x32 Version: 10.0.3.2 - MAGIX AG) MAGIX Fotos auf CD & DVD 10 (x32 Version: 10.0.3.2 - MAGIX AG) Hidden MAGIX Online Druck Service (x32 Version: 1.1.0 - myphotobook GmbH) Hidden MAGIX Online Druck Service (x32 Version: 1.1.0-478 - myphotobook GmbH) MAGIX Screenshare (x32 Version: 4.3.6.1987 - MAGIX AG) MAGIX Slideshow Maker 2 (Version: 2.0.1.9 - MAGIX AG) Hidden MAGIX Slideshow Maker 2 (x32 Version: 2.0.1.9 - MAGIX AG) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6 - MAGIX AG) MAGIX Video deluxe 2013 (Version: 12.0.3.4 - MAGIX AG) Hidden MAGIX Video deluxe 2013 (x32 Version: 12.0.3.4 - MAGIX AG) Mah Jong Medley (x32 Version: 2.2.0.95 - WildTangent) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) Menu Templates - Starter Kit (x32 Version: 9.6.0.0 - Nero AG) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Mathematics (x32 Version: 4.0 - Microsoft Corporation) Microsoft Office 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Professional Edition 2003 (x32 Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP1 English (x32 Version: 3.5.5692.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP1 x64 English (Version: 3.5.5692.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (x32 Version: 10.0.30319 - Microsoft Corporation) Movie Templates - Starter Kit (x32 Version: 9.6.0.0 - Nero AG) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0 - Microsoft Corporation) MusicStation (x32 Version: 2.0.5.71 - Omnifone) Mystery of Mortlake Mansion (x32 Version: 2.2.0.97 - WildTangent) Hidden Namco All-Stars: PAC-MAN (x32 Version: 2.2.0.95 - WildTangent) Hidden Nero 9 (x32 Version: - Nero AG) Nero BurnRights (x32 Version: 3.4.13.100 - Nero AG) Hidden Nero ControlCenter (x32 Version: 9.0.0.1 - Nero AG) Hidden Nero CoverDesigner (x32 Version: 1.0.0.0 - Nero AG) Hidden Nero Disc Copy Gadget (x32 Version: 2.4.43.0 - Nero AG) Hidden Nero DiscSpeed (x32 Version: 5.4.13.100 - Nero AG) Hidden Nero DriveSpeed (x32 Version: 4.4.12.100 - Nero AG) Hidden Nero InfoTool (x32 Version: 6.4.12.100 - Nero AG) Hidden Nero Installer (x32 Version: 4.4.9.0 - Nero AG) Hidden Nero PhotoSnap (x32 Version: 2.4.29.0 - Nero AG) Hidden Nero Recode (x32 Version: 4.4.40.0 - Nero AG) Hidden Nero Rescue Agent (x32 Version: 2.4.14.100 - Nero AG) Hidden Nero ShowTime (x32 Version: 5.4.27.100 - Nero AG) Hidden Nero StartSmart (x32 Version: 9.4.40.100 - Nero AG) Hidden Nero Vision (x32 Version: 6.4.19.100 - Nero AG) Hidden Nero WaveEditor (x32 Version: 5.4.39.0 - Nero AG) Hidden NeroBurningROM (x32 Version: 1.0.0.0 - Nero AG) Hidden NeroExpress (x32 Version: 1.0.0.0 - Nero AG) Hidden neroxml (x32 Version: 1.0.0 - Nero AG) Hidden Norton Online Backup (x32 Version: 2.1.17869 - Symantec Corporation) Paragon Partition Manager™ 11 Professional (x32 Version: 90.00.0003 - Paragon Software) PDF Complete Special Edition (x32 Version: 4.0.54 - PDF Complete, Inc) Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden Pixum Fotobuch (x32 Version: 5.0.1 - CEWE COLOR AG u Co. OHG) Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden PlayReady PC Runtime amd64 (Version: 1.3.0 - Microsoft Corporation) Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden Power2Go (x32 Version: 6.1.5331 - CyberLink Corp.) Power2Go (x32 Version: 6.1.5331 - CyberLink Corp.) Hidden Realtek High Definition Audio Driver (x32 Version: 6.0.1.6387 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.0.4320 - CyberLink Corp.) Hidden Remote Graphics Receiver (x32 Version: 5.4.5 - Hewlett-Packard) Saal Design Software (x32 Version: 3.1.26 - SSW Software GmbH) Saal Design Software (x32 Version: 3.1.26 - SSW Software GmbH) Hidden Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden SoundTap Audiostream-Rekorder (x32 Version: - NCH Software) SoundTrax (x32 Version: 4.4.39.0 - Nero AG) Hidden TomTom HOME (x32 Version: 2.9.6 - Ihr Firmenname) TomTom HOME Visual Studio Merge Modules (x32 Version: 1.0.2 - TomTom International B.V.) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Vacation Quest - The Hawaiian Islands (x32 Version: 2.2.0.97 - WildTangent) Hidden Virtual Villagers - The Secret City (x32 Version: 2.2.0.95 - WildTangent) Hidden VLC media player 2.0.6 (Version: 2.0.6 - VideoLAN) WildTangent Games App (HP Games) (x32 Version: 4.0.5.2 - WildTangent) Hidden Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Media Center Add-in for Silverlight (x32 Version: 4.7.3.0 - Microsoft Corporation) Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Hidden Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden ==================== Restore Points ========================= 10-02-2014 17:27:50 TuneUp Utilities 2013 wird entfernt 10-02-2014 17:28:35 TuneUp Utilities Language Pack (de-DE) wird entfernt 10-02-2014 17:34:45 Installed Java 7 Update 51 10-02-2014 19:16:03 avast! antivirus system restore point 10-02-2014 19:18:22 Gerätetreiber-Paketinstallation: Avast Netzwerkdienst 10-02-2014 19:22:04 Konfiguriert Power2Go 11-02-2014 17:24:45 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {08055C72-916B-4863-A4F9-BB8A97C0C557} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1003UA => C:\Users\Kathi\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-01] (Google Inc.) Task: {1963864A-A396-46BF-B1EC-D68283AF16DE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1001Core => C:\Users\Tino\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-27] (Google Inc.) Task: {2BD81678-3379-491A-B336-122EC976EEBF} - System32\Tasks\{DE8EB6D1-35F6-4B45-8761-180607AA8DB7} => Chrome.exe hxxp://ui.skype.com/ui/0/6.6.0.106/de/abandoninstall?page=tsMain Task: {31A3E4FC-D624-4F50-BBE1-5E349D6FA582} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated) Task: {34C1A6FA-E1E1-4483-8752-9C00B6BDF1DE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {3597C3BB-454A-40F4-A919-A695B0D92A47} - System32\Tasks\{8F6FCCA2-86C4-40A4-B0CC-9032FA47A280} => C:\Skat 2095 Special Edition\Skatse.exe Task: {3C455D34-4739-482B-8F9C-48BD601FB797} - System32\Tasks\HPCeeScheduleForTino => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard) Task: {3F92EE22-F9B4-4CBB-A49F-5253E24FA55F} - System32\Tasks\{11E01653-C44D-4DD6-92F3-BB0CD0AFEA83} => C:\Skat 2095 Special Edition\Skatse.exe Task: {48DA17F8-A8D4-4E48-91CB-0843CBC782C3} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1003Core => C:\Users\Kathi\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-01] (Google Inc.) Task: {4F0BCFCB-AEF9-4250-BB5F-E130AFC88CC0} - System32\Tasks\ServicePlan => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2011-06-15] () Task: {6DDF46F2-5A1D-4369-B3CB-B6AB585ABA7A} - System32\Tasks\{87BB4444-94A9-48AE-ADE9-B125E2E24816} => C:\Skat 2095 Special Edition\Skatse.exe Task: {76210B70-6374-4E11-910D-CA7605725326} - System32\Tasks\{F0F32E8E-E6CD-471F-A4CC-CC36C480B945} => C:\Skat 2095 Special Edition\Skatse.exe Task: {8D07C139-500B-4D6F-8448-2BBF011B13D7} - System32\Tasks\{BB7C8247-8659-42D3-8011-9C1590E452A1} => Chrome.exe hxxp://ui.skype.com/ui/0/6.6.0.106/de/eula Task: {9851A268-A1AA-4F2C-BD15-41A111EE181A} - System32\Tasks\FinishInstall igdhbblpcellaljokkpfhcjlagemhgjl => C:\Users\Tino\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl\minibarchrome.exe Task: {98E4129C-3518-4A55-A130-CA386FA63007} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-02-10] (AVAST Software) Task: {9B5E23C2-06A7-4B4A-A19B-4ED1AE92293F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {9C72E6BC-FA37-42FE-9459-8AE3C0115C99} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-27] (Google Inc.) Task: {A0258CC2-47A8-439F-A5AA-CC505E3877D1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-27] (Google Inc.) Task: {B7C3937E-BB2B-4F07-B397-F7E64C7D4072} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-04-01] (Hewlett-Packard Company) Task: {BBC57111-2BCD-4871-AAFB-6986A1EB7910} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {C1AF8361-5587-4DBA-9B93-30871ADD1836} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-11-22] (Hewlett-Packard) Task: {C3D77DA9-1DC5-4A6F-8F98-12529845CBD1} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2011-05-10] (Hewlett-Packard) Task: {DCD48F9A-44CA-4FBE-AC7E-3C95B485FCC9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1001UA => C:\Users\Tino\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-27] (Google Inc.) Task: {DF3F32FE-F5FE-4B40-B47C-416E23431894} - System32\Tasks\{184CA433-C3A5-45C6-97DA-A0710021A790} => C:\Skat 2095 Special Edition\Skatse.exe Task: {E7799E3E-6DF6-412D-88E6-051C9032174A} - System32\Tasks\Google Updater and Installer => C:\Users\Tino\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-27] (Google Inc.) Task: {EE0CC60E-5B71-4144-AC5C-0F71DC7B87D0} - System32\Tasks\{87B6185A-759B-44BD-8B23-296A5B4F2988} => C:\Skat 2095 Special Edition\Skatse.exe Task: {F2B35DC6-A14A-40E5-86B2-6234A532277B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-05] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1001Core.job => C:\Users\Tino\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1001UA.job => C:\Users\Tino\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1003Core.job => C:\Users\Kathi\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1003UA.job => C:\Users\Kathi\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HPCeeScheduleForTino.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============= 2012-01-19 19:08 - 2003-05-19 18:58 - 00126976 _____ () C:\Program Files (x86)\InterVideo\Common\Bin\WinCinemaMgr.exe 2011-06-01 06:14 - 2011-06-01 06:14 - 00243712 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2011-04-12 00:20 - 2011-04-12 00:20 - 00098304 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2011-04-12 00:20 - 2011-04-12 00:20 - 00028672 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\BrandingResources.dll 2014-02-10 19:48 - 2014-02-10 19:05 - 02172928 _____ () C:\Program Files\AVAST Software\Avast\defs\14021001\algo.dll 2014-02-11 18:18 - 2014-02-11 10:39 - 02172928 _____ () C:\Program Files\AVAST Software\Avast\defs\14021100\algo.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 02145304 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 07956504 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 00342552 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 00029208 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 00128536 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll 2013-11-20 19:26 - 2013-11-20 19:26 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:373E1720 AlternateDataStreams: C:\ProgramData\Temp:58DD92AC ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: avast! Firewall NDIS Filter Miniport Description: avast! Firewall NDIS Filter Miniport Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: ALWIL Software Service: aswNdis Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19) Resolution: A registry problem was detected. This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options: On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Error: (02/10/2014 10:17:50 PM) (Source: DCOM) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (02/10/2014 09:51:41 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (02/10/2014 09:48:19 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (02/10/2014 09:34:02 PM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 26% Total physical RAM: 8177.75 MB Available physical RAM: 6031.31 MB Total Pagefile: 16353.68 MB Available Pagefile: 13703.83 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:710.2 GB) (Free:566.51 GB) NTFS Drive d: (HP_RECOVERY) (Fixed) (Total:37.88 GB) (Free:26.74 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (TRANSCEND) (Removable) (Total:1.9 GB) (Free:1.29 GB) FAT32 Drive g: (Tino Sicherung) (Fixed) (Total:537.27 GB) (Free:536.49 GB) NTFS Drive h: (Kathi Sicherung) (Fixed) (Total:577.56 GB) (Free:576.74 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: B4CFD55F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=710 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=-1001981806592) - (Type=OF Extended) Partition 4: (Not Active) - (Size=38 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or Vista) (Size: 2 GB) (Disk ID: 162A9B08) Partition 1: (Active) - (Size=2 GB) - (Type=0B) Partition 2: (Not Active) - (Size=32 KB) - (Type=21) ==================== End Of Log ============================ - |
11.02.2014, 20:19 | #2 |
/// the machine /// TB-Ausbilder | Win 7 64 Bit HP awesomehp und Delta-Search eingeschränkter Internetzugang hi,
__________________So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Downloade dir bitte Shortcut Cleaner (by Grinler) auf deinen Desktop.
und ein frisches FRST log bitte.
__________________ |
11.02.2014, 21:12 | #3 |
| Win 7 64 Bit HP awesomehp und Delta-Search eingeschränkter Internetzugang Danke erst einmal!
__________________Hatte nur die Logs angehängt, da Meldung, dass zu groß und dass ich gepackt anhängen soll. Hier die Logs: Code:
ATTFilter Malwarebytes Anti-Malware (PRO) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.02.11.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 Tino :: TINO-HP [Administrator] Schutz: Deaktiviert 11.02.2014 20:26:55 mbam-log-2014-02-11 (20-26-55).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 293553 Laufzeit: 5 Minute(n), 52 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 11/02/2014 um 20:44:44 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Tino - TINO-HP # Gestartet von : F:\adwcleaner-3.018.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Google Chrome v [ Datei : C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht : search_url Gelöscht : keyword [ Datei : C:\Users\Kathi\AppData\Local\Google\Chrome\User Data\Default\preferences ] [ Datei : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [10407 octets] - [10/02/2014 20:10:13] AdwCleaner[R1].txt - [1353 octets] - [10/02/2014 20:23:28] AdwCleaner[R2].txt - [1225 octets] - [11/02/2014 20:37:58] AdwCleaner[S0].txt - [9345 octets] - [10/02/2014 20:13:06] AdwCleaner[S1].txt - [1414 octets] - [10/02/2014 20:24:28] AdwCleaner[S2].txt - [1147 octets] - [11/02/2014 20:44:44] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1207 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.1 (02.04.2014:1) OS: Windows 7 Home Premium x64 Ran by Tino on 11.02.2014 at 20:48:15,45 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 11.02.2014 at 20:55:26,73 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Shortcut Cleaner 1.2.8 by Lawrence Abrams (Grinler) hxxp://www.bleepingcomputer.com/ Copyright 2008-2014 BleepingComputer.com More Information about Shortcut Cleaner can be found at this link: hxxp://www.bleepingcomputer.com/download/shortcut-cleaner/ Windows Version: Windows 7 Home Premium Service Pack 1 Program started at: 02/11/2014 09:01:27 PM. Scanning for registry hijacks: * No issues found in the Registry. Searching for Hijacked Shortcuts: Searching C:\Users\Tino\AppData\Roaming\Microsoft\Windows\Start Menu\ * Shortcut Cleaned: C:\Users\Tino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1391447732&from=tugs&uid=ST2000DL003-9VT166_5YD67Y9S * Shortcut Cleaned: C:\Users\Tino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => C:\Users\Tino\AppData\Local\Google\Chrome\Application\chrome.exe hxxp://www.awesomehp.com/?type=sc&ts=1391447732&from=tugs&uid=ST2000DL003-9VT166_5YD67Y9S * Shortcut Cleaned: C:\Users\Tino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1391447732&from=tugs&uid=ST2000DL003-9VT166_5YD67Y9S Searching C:\ProgramData\Microsoft\Windows\Start Menu\ Searching C:\Users\Tino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ * Shortcut Cleaned: C:\Users\Tino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1391447732&from=tugs&uid=ST2000DL003-9VT166_5YD67Y9S * Shortcut Cleaned: C:\Users\Tino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => C:\Users\Tino\AppData\Local\Google\Chrome\Application\chrome.exe hxxp://www.awesomehp.com/?type=sc&ts=1391447732&from=tugs&uid=ST2000DL003-9VT166_5YD67Y9S * Shortcut Cleaned: C:\Users\Tino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WEB.DE.lnk => C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1391447732&from=tugs&uid=ST2000DL003-9VT166_5YD67Y9S Searching C:\Users\Public\Desktop\ Searching C:\Users\Tino\Desktop 6 bad shortcuts found. Program finished at: 02/11/2014 09:01:29 PM Execution time: 0 hours(s), 0 minute(s), and 3 seconds(s) FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-02-2014 01 Ran by Tino (administrator) on TINO-HP on 11-02-2014 21:05:23 Running from F:\ Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe () C:\Program Files (x86)\InterVideo\Common\Bin\WinCinemaMgr.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Easybits) C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [hpsysdrv] - c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard) HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [1580368 2010-11-03] (Logitech, Inc.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-06-01] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation) HKLM-x32\...\Run: [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-05-06] (PDF Complete Inc) HKLM-x32\...\Run: [LWS] - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-08-12] (Logitech Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-10] (AVAST Software) HKLM-x32\...\Run: [Magic Desktop for HP notification] - C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1258504 2013-12-27] (Easybits) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-01-14] (Hewlett-Packard) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-771379982-2687441850-2496483240-1001\...\Run: [Logitech Vid] - C:\Program Files (x86)\Logitech\Vid HD\Vid.exe [5915480 2010-10-29] (Logitech Inc.) HKU\S-1-5-21-771379982-2687441850-2496483240-1001\...\Run: [GoogleChromeAutoLaunch_881275C6261D4361D619481AC556BC9C] - C:\Users\Tino\AppData\Local\Google\Chrome\Application\chrome.exe [866632 2014-02-02] (Google Inc.) HKU\S-1-5-21-771379982-2687441850-2496483240-1001\...\Run: [TomTomHOME.exe] - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-07-02] (TomTom) HKU\S-1-5-21-771379982-2687441850-2496483240-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.awesomehp.com/?type=hp&ts=1391447732&from=tugs&uid=ST2000DL003-9VT166_5YD67Y9S HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.awesomehp.com/web/?type=ds&ts=1391447732&from=tugs&uid=ST2000DL003-9VT166_5YD67Y9S&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {5BF9B35A-589D-4597-9205-B2897D7AE330} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKCU - {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = SearchScopes: HKCU - {5BF9B35A-589D-4597-9205-B2897D7AE330} URL = SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = BHO: Plus-HD-4.2 - {11111111-1111-1111-1111-110311921102} - C:\Program Files (x86)\Plus-HD-4.2\Plus-HD-4.2-bho64.dll No File BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Chrome: ======= CHR HomePage: CHR RestoreOnStartup: "spdy": { "servers": [ "i1.ytimg.com:443", "i2.ytimg.com:443", "ssl.gstatic.com:443", "ad-emea.doubleclick.net:443", "i4.ytimg.com:443", "static.doubleclick.net:443", "accounts.google.com:443", "plusone.google.com:443", "googleads.g.doubleclick.net:443", "toolbarqueries.google.com:443", "ad.doubleclick.net:443", "clients2.google.com:443", "www.google.com:443", "apis.google.com:443", "www.googleadservices.com:443", "ajax.googleapis.com:443", "maps.google.com:443" CHR DefaultSearchProvider: Delta Search CHR DefaultSearchURL: hxxp://www.google.com CHR DefaultNewTabURL: CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Tino\AppData\Local\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Tino\AppData\Local\Google\Chrome\Application\32.0.1700.107\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Tino\AppData\Local\Google\Chrome\Application\32.0.1700.107\gcswf32.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility) - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL No File CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (WildTangent Games App Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Extension: (YouTube) - C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-27] CHR Extension: (Google-Suche) - C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-27] CHR Extension: (avast! Online Security) - C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-09-11] CHR Extension: (DvdVideoSoft Free Youtube Download) - C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2013-08-25] CHR Extension: (Google Wallet) - C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31] CHR Extension: (Google Mail) - C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-27] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\Tino\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2012-10-01] CHR StartMenuInternet: Google Chrome - C:\Users\Tino\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-10] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [113704 2014-02-10] (AVAST Software) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation) R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-05-06] (PDF Complete Inc) ==================== Drivers (Whitelisted) ==================== R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2013-11-20] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-10] (AVAST Software) R1 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [440672 2014-02-10] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-20] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-20] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-10] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-10] (AVAST Software) S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-10] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-30] () R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [37392 2010-05-20] (Paragon Software Group) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 stdriver; C:\Windows\System32\DRIVERS\stdriverx64.sys [32536 2013-03-16] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-11 20:55 - 2014-02-11 20:55 - 00000624 _____ () C:\Users\Tino\Desktop\JRT.txt 2014-02-11 18:27 - 2014-02-11 18:27 - 00380416 _____ () C:\Users\Tino\Downloads\Gmer-19357.exe 2014-02-11 18:26 - 2014-02-11 21:05 - 00000000 ____D () C:\FRST 2014-02-11 18:25 - 2014-02-11 18:25 - 00000470 _____ () C:\Users\Tino\Desktop\defogger_disable.log 2014-02-11 18:25 - 2014-02-11 18:25 - 00000000 _____ () C:\Users\Tino\defogger_reenable 2014-02-10 21:55 - 2014-02-10 21:55 - 00038681 _____ () C:\ComboFix.txt 2014-02-10 21:43 - 2014-02-10 21:55 - 00000000 ____D () C:\Qoobox 2014-02-10 21:43 - 2014-02-10 21:52 - 00000000 ____D () C:\Windows\erdnt 2014-02-10 21:43 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-10 21:43 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-10 21:43 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-10 21:43 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-10 21:43 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-10 21:43 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-10 21:43 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-10 21:43 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-10 20:29 - 2014-02-10 20:29 - 00000000 ____D () C:\Windows\ERUNT 2014-02-10 20:10 - 2014-02-11 20:45 - 00000000 ____D () C:\AdwCleaner 2014-02-10 19:33 - 2014-02-10 19:33 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\Malwarebytes 2014-02-10 19:32 - 2014-02-10 19:32 - 00001111 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-10 19:32 - 2014-02-10 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-10 19:32 - 2014-02-10 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-10 19:32 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-10 18:35 - 2014-02-10 18:35 - 00005933 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-02-10 18:35 - 2014-02-10 18:35 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-10 18:35 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-02-10 18:35 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-02-10 18:35 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-02-10 18:35 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-02-07 10:55 - 2014-02-07 10:55 - 00074810 _____ () C:\Users\Kathi\Desktop\WEB.DE FreeMail.htm 2014-02-06 20:41 - 2014-02-06 20:41 - 00074777 _____ () C:\Users\Kathi\Desktop\Pdf Bewerbung.htm 2014-02-06 20:41 - 2014-02-06 20:41 - 00000000 ____D () C:\Users\Kathi\Desktop\Pdf Bewerbung_files 2014-02-06 15:12 - 2014-02-06 15:12 - 00074726 _____ () C:\Users\Kathi\Desktop\Lebenslauf.htm 2014-02-06 15:12 - 2014-02-06 15:12 - 00000000 ____D () C:\Users\Kathi\Desktop\Lebenslauf_files 2014-02-06 15:11 - 2014-02-06 15:11 - 00074743 _____ () C:\Users\Kathi\Desktop\Anschreiben.htm 2014-02-06 15:11 - 2014-02-06 15:11 - 00000000 ____D () C:\Users\Kathi\Desktop\Anschreiben_files 2014-02-06 15:10 - 2014-02-07 10:55 - 00000000 ____D () C:\Users\Kathi\Desktop\WEB.DE FreeMail_files 2014-02-03 18:26 - 2014-02-05 18:02 - 00001077 _____ () C:\Users\Tino\Desktop\Continue VuuPC Installation.lnk 2014-02-03 18:15 - 2014-02-03 19:16 - 00000000 ____D () C:\ProgramData\WPM 2014-02-03 18:15 - 2014-02-03 19:16 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-01-31 06:58 - 2014-01-31 06:58 - 00588672 _____ ( ) C:\Users\Tino\Downloads\Setup (3).exe 2014-01-31 06:58 - 2014-01-31 06:58 - 00588672 _____ ( ) C:\Users\Tino\Downloads\Setup (2).exe 2014-01-28 14:54 - 2014-01-28 14:54 - 00000000 ____D () C:\Users\Tino\Documents\My Albums 2014-01-28 14:54 - 2014-01-28 14:54 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\ArcSoft 2014-01-28 14:52 - 2014-01-28 14:52 - 00000000 ____D () C:\Program Files (x86)\ArcSoft 2014-01-28 14:34 - 2014-02-10 18:29 - 00003572 _____ () C:\Windows\System32\Tasks\FinishInstall igdhbblpcellaljokkpfhcjlagemhgjl 2014-01-28 14:32 - 2014-01-28 14:32 - 03502168 _____ () C:\Users\Tino\Downloads\UpdateMyDrivers.exe 2014-01-28 14:32 - 2014-01-28 14:32 - 03502168 _____ () C:\Users\Tino\Downloads\UpdateMyDrivers (1).exe 2014-01-28 14:07 - 2014-01-28 14:07 - 00001071 _____ () C:\Users\Tino\Desktop\CanoScan - Verknüpfung.lnk 2014-01-28 13:53 - 1995-07-31 13:44 - 00212480 _____ (Eastman Kodak) C:\Windows\PCDLIB32.DLL 2014-01-26 15:03 - 2012-03-14 05:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMLMA6.DLL 2014-01-26 15:00 - 2011-01-06 13:09 - 01324544 _____ (CANON INC.) C:\Windows\system32\CNC350C.dll 2014-01-26 15:00 - 2011-01-06 13:09 - 00109568 _____ (CANON INC.) C:\Windows\system32\CNC350I.dll 2014-01-26 15:00 - 2011-01-06 13:07 - 00102400 _____ (CANON INC.) C:\Windows\SysWOW64\CNC350U.dll 2014-01-26 15:00 - 2009-10-19 16:30 - 00346624 _____ (CANON INC.) C:\Windows\system32\CNC350L.dll 2014-01-26 15:00 - 2009-10-19 16:29 - 00307200 _____ (CANON INC.) C:\Windows\SysWOW64\CNC350L.dll 2014-01-26 14:58 - 2014-01-26 14:58 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information 2014-01-26 14:57 - 2014-01-26 14:57 - 30995856 _____ () C:\Users\Tino\Downloads\PixmaMX3501.04.exe 2014-01-26 14:25 - 2012-03-14 05:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMXLMA6.DLL 2014-01-26 14:24 - 2014-01-26 14:24 - 23477400 _____ () C:\Users\Tino\Downloads\xp68-win-mx350-5_56-ea24.exe 2014-01-26 13:12 - 2014-01-26 13:12 - 00000000 ____D () C:\Users\Kathi\Desktop\Dateien Bewerbung 2014-01-26 10:11 - 2014-01-26 10:11 - 00046243 _____ () C:\Users\Kathi\Downloads\eBayISAPI (2).gz 2014-01-16 06:16 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-16 06:16 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-16 06:16 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-16 06:16 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-16 06:16 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-16 06:16 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-16 06:16 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-16 06:16 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-16 06:16 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys ==================== One Month Modified Files and Folders ======= 2014-02-11 21:05 - 2014-02-11 18:26 - 00000000 ____D () C:\FRST 2014-02-11 21:04 - 2011-11-01 21:16 - 00000000 ____D () C:\ProgramData\PDFC 2014-02-11 21:03 - 2011-12-27 16:14 - 01900152 _____ () C:\Windows\WindowsUpdate.log 2014-02-11 21:03 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-11 21:03 - 2009-07-14 05:51 - 00205243 _____ () C:\Windows\setupact.log 2014-02-11 21:01 - 2011-12-27 16:20 - 00001423 _____ () C:\Users\Tino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-11 20:56 - 2011-12-27 16:20 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{5CE2A2CC-EC72-4B0D-A299-4E994079C444} 2014-02-11 20:55 - 2014-02-11 20:55 - 00000624 _____ () C:\Users\Tino\Desktop\JRT.txt 2014-02-11 20:53 - 2009-07-14 05:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-11 20:53 - 2009-07-14 05:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-11 20:52 - 2011-11-01 20:42 - 00697072 _____ () C:\Windows\system32\perfh007.dat 2014-02-11 20:52 - 2011-11-01 20:42 - 00148110 _____ () C:\Windows\system32\perfc007.dat 2014-02-11 20:52 - 2009-07-14 06:13 - 01614036 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-11 20:45 - 2014-02-10 20:10 - 00000000 ____D () C:\AdwCleaner 2014-02-11 20:43 - 2012-01-01 12:11 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1003UA.job 2014-02-11 20:35 - 2011-12-27 17:39 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1001UA.job 2014-02-11 19:16 - 2013-02-27 16:29 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-11 19:00 - 2011-12-30 06:54 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\Skype 2014-02-11 18:58 - 2012-02-01 18:38 - 00000000 ____D () C:\Windows\Minidump 2014-02-11 18:57 - 2011-11-01 21:50 - 00286795 ____N () C:\Windows\Minidump\021114-20888-01.dmp 2014-02-11 18:27 - 2014-02-11 18:27 - 00380416 _____ () C:\Users\Tino\Downloads\Gmer-19357.exe 2014-02-11 18:25 - 2014-02-11 18:25 - 00000470 _____ () C:\Users\Tino\Desktop\defogger_disable.log 2014-02-11 18:25 - 2014-02-11 18:25 - 00000000 _____ () C:\Users\Tino\defogger_reenable 2014-02-11 18:25 - 2011-12-27 16:15 - 00000000 ____D () C:\Users\Tino 2014-02-11 18:16 - 2010-11-21 04:47 - 01321070 _____ () C:\Windows\PFRO.log 2014-02-10 21:55 - 2014-02-10 21:55 - 00038681 _____ () C:\ComboFix.txt 2014-02-10 21:55 - 2014-02-10 21:43 - 00000000 ____D () C:\Qoobox 2014-02-10 21:55 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-02-10 21:52 - 2014-02-10 21:43 - 00000000 ____D () C:\Windows\erdnt 2014-02-10 21:51 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-10 20:29 - 2014-02-10 20:29 - 00000000 ____D () C:\Windows\ERUNT 2014-02-10 20:19 - 2013-11-22 05:41 - 00000000 ____D () C:\Users\Tino\AppData\Local\Mobogenie 2014-02-10 20:18 - 2013-11-20 19:26 - 00002034 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-02-10 20:18 - 2013-03-25 20:22 - 00001974 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk 2014-02-10 20:17 - 2013-12-30 12:26 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-10 20:17 - 2013-03-25 20:32 - 00440672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys 2014-02-10 20:17 - 2013-03-25 20:22 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-10 20:17 - 2013-03-25 20:22 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-02-10 20:17 - 2013-03-25 20:22 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-10 20:17 - 2013-03-25 20:22 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-02-10 20:17 - 2013-03-25 20:21 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-10 20:17 - 2011-12-27 17:54 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-10 20:07 - 2012-01-11 18:03 - 00003180 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForTino 2014-02-10 20:07 - 2012-01-11 18:03 - 00000328 _____ () C:\Windows\Tasks\HPCeeScheduleForTino.job 2014-02-10 19:46 - 2013-11-22 05:41 - 00000000 ____D () C:\Users\Tino\AppData\Local\genienext 2014-02-10 19:33 - 2014-02-10 19:33 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\Malwarebytes 2014-02-10 19:32 - 2014-02-10 19:32 - 00001111 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-10 19:32 - 2014-02-10 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-10 19:32 - 2014-02-10 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-10 18:35 - 2014-02-10 18:35 - 00005933 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-02-10 18:35 - 2014-02-10 18:35 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-10 18:35 - 2013-08-06 16:30 - 00000000 ____D () C:\Program Files (x86)\Java 2014-02-10 18:29 - 2014-01-28 14:34 - 00003572 _____ () C:\Windows\System32\Tasks\FinishInstall igdhbblpcellaljokkpfhcjlagemhgjl 2014-02-10 18:28 - 2012-10-01 15:21 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-02-10 18:27 - 2012-10-02 10:00 - 00003676 _____ () C:\Windows\System32\Tasks\HP-Online-Aktualisierungsprogramm 2014-02-10 18:27 - 2011-12-27 16:19 - 00003404 _____ () C:\Windows\System32\Tasks\ServicePlan 2014-02-10 18:23 - 2011-12-30 08:30 - 00000000 ____D () C:\Users\Kathi\AppData\Roaming\SoftGrid Client 2014-02-10 18:19 - 2011-12-28 07:48 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{B05A2130-CB43-43B8-9B7E-2C5B53C0D083} 2014-02-10 18:18 - 2011-12-30 08:30 - 00110624 _____ () C:\Users\Kathi\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-08 10:46 - 2013-11-22 05:41 - 00000000 ____D () C:\Users\Tino\AppData\Local\cache 2014-02-07 18:58 - 2013-08-26 13:24 - 00000000 ____D () C:\Users\Kathi\Desktop\Bewerbung 2014-02-07 18:58 - 2011-12-30 09:05 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\SoftGrid Client 2014-02-07 18:40 - 2011-12-28 11:48 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\SoftGrid Client 2014-02-07 17:35 - 2011-12-27 17:39 - 00001064 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1001Core.job 2014-02-07 10:55 - 2014-02-07 10:55 - 00074810 _____ () C:\Users\Kathi\Desktop\WEB.DE FreeMail.htm 2014-02-07 10:55 - 2014-02-06 15:10 - 00000000 ____D () C:\Users\Kathi\Desktop\WEB.DE FreeMail_files 2014-02-06 20:41 - 2014-02-06 20:41 - 00074777 _____ () C:\Users\Kathi\Desktop\Pdf Bewerbung.htm 2014-02-06 20:41 - 2014-02-06 20:41 - 00000000 ____D () C:\Users\Kathi\Desktop\Pdf Bewerbung_files 2014-02-06 15:12 - 2014-02-06 15:12 - 00074726 _____ () C:\Users\Kathi\Desktop\Lebenslauf.htm 2014-02-06 15:12 - 2014-02-06 15:12 - 00000000 ____D () C:\Users\Kathi\Desktop\Lebenslauf_files 2014-02-06 15:11 - 2014-02-06 15:11 - 00074743 _____ () C:\Users\Kathi\Desktop\Anschreiben.htm 2014-02-06 15:11 - 2014-02-06 15:11 - 00000000 ____D () C:\Users\Kathi\Desktop\Anschreiben_files 2014-02-05 18:02 - 2014-02-03 18:26 - 00001077 _____ () C:\Users\Tino\Desktop\Continue VuuPC Installation.lnk 2014-02-05 17:53 - 2013-11-25 09:40 - 00000000 ____D () C:\Users\Kathi\AppData\Local\Mobogenie 2014-02-05 15:16 - 2013-02-27 16:29 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-05 15:16 - 2013-02-27 16:29 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-05 15:16 - 2011-11-01 21:11 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-04 22:08 - 2011-11-01 21:50 - 00286603 ____N () C:\Windows\Minidump\020414-19812-01.dmp 2014-02-04 19:30 - 2011-11-01 21:50 - 00286603 ____N () C:\Windows\Minidump\020414-20763-01.dmp 2014-02-04 19:29 - 2012-01-22 16:56 - 00000000 ____D () C:\Users\Tino\Desktop\Gebraucht 2014-02-04 19:20 - 2011-11-01 21:50 - 00287371 ____N () C:\Windows\Minidump\020414-20592-01.dmp 2014-02-03 19:16 - 2014-02-03 18:15 - 00000000 ____D () C:\ProgramData\WPM 2014-02-03 19:16 - 2014-02-03 18:15 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-02-03 18:49 - 2011-12-27 16:20 - 00000000 ___RD () C:\Users\Tino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-02 18:17 - 2013-02-03 11:07 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\vlc 2014-02-02 15:46 - 2012-10-02 10:00 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2014-01-31 06:58 - 2014-01-31 06:58 - 00588672 _____ ( ) C:\Users\Tino\Downloads\Setup (3).exe 2014-01-31 06:58 - 2014-01-31 06:58 - 00588672 _____ ( ) C:\Users\Tino\Downloads\Setup (2).exe 2014-01-28 14:54 - 2014-01-28 14:54 - 00000000 ____D () C:\Users\Tino\Documents\My Albums 2014-01-28 14:54 - 2014-01-28 14:54 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\ArcSoft 2014-01-28 14:54 - 2012-02-21 16:33 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\Canon 2014-01-28 14:52 - 2014-01-28 14:52 - 00000000 ____D () C:\Program Files (x86)\ArcSoft 2014-01-28 14:52 - 2011-11-01 21:03 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-01-28 14:32 - 2014-01-28 14:32 - 03502168 _____ () C:\Users\Tino\Downloads\UpdateMyDrivers.exe 2014-01-28 14:32 - 2014-01-28 14:32 - 03502168 _____ () C:\Users\Tino\Downloads\UpdateMyDrivers (1).exe 2014-01-28 14:07 - 2014-01-28 14:07 - 00001071 _____ () C:\Users\Tino\Desktop\CanoScan - Verknüpfung.lnk 2014-01-28 07:43 - 2012-01-01 12:11 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1003Core.job 2014-01-26 14:58 - 2014-01-26 14:58 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information 2014-01-26 14:57 - 2014-01-26 14:57 - 30995856 _____ () C:\Users\Tino\Downloads\PixmaMX3501.04.exe 2014-01-26 14:24 - 2014-01-26 14:24 - 23477400 _____ () C:\Users\Tino\Downloads\xp68-win-mx350-5_56-ea24.exe 2014-01-26 14:16 - 2012-01-06 17:42 - 00000000 ____D () C:\Program Files (x86)\Canon 2014-01-26 14:14 - 2012-02-21 16:33 - 00000000 ___HD () C:\ProgramData\CanonIJScan 2014-01-26 14:14 - 2012-01-08 10:27 - 00000000 ____D () C:\Users\Kathi\AppData\Roaming\Canon 2014-01-26 14:00 - 2011-12-30 06:56 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\HpUpdate 2014-01-26 13:12 - 2014-01-26 13:12 - 00000000 ____D () C:\Users\Kathi\Desktop\Dateien Bewerbung 2014-01-26 10:11 - 2014-01-26 10:11 - 00046243 _____ () C:\Users\Kathi\Downloads\eBayISAPI (2).gz 2014-01-26 09:57 - 2009-07-14 05:45 - 00399840 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-22 20:07 - 2012-12-13 05:50 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-01-22 20:07 - 2012-02-22 20:37 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-01-22 20:06 - 2011-12-30 07:01 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\HP Support Assistant 2014-01-17 09:03 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-16 06:18 - 2009-07-14 03:34 - 00000499 _____ () C:\Windows\win.ini 2014-01-16 06:17 - 2013-08-14 07:48 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-16 06:14 - 2011-12-28 07:41 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\Tino\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-10 21:13 ==================== End Of Log ============================ |
12.02.2014, 18:14 | #4 |
/// the machine /// TB-Ausbilder | Win 7 64 Bit HP awesomehp und Delta-Search eingeschränkter InternetzugangESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.02.2014, 20:52 | #5 |
| Win 7 64 Bit HP awesomehp und Delta-Search eingeschränkter InternetzugangCode:
ATTFilter ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=53336fa50b76254588117686c2a32033 # engine=17045 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-02-12 07:36:36 # local_time=2014-02-12 08:36:36 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=772 16777213 83 82 177035 7265427 0 0 # compatibility_mode=5893 16776573 100 94 97759 143863646 0 0 # scanned=249163 # found=4 # cleaned=0 # scan_time=7292 sh=FC08D67921A9E902CA36DB47DDB093A0B4C4C31B ft=0 fh=0000000000000000 vn="Win32/LockScreen.AKW trojan" ac=I fn="C:\Users\Kathi\AppData\Local\IM\Identities\{A373BE7A-F30F-4DF9-95F2-3E75C1388C30}\Message Store\Attachments\2012.zip" sh=B0F1D806CE934E0E96B33475A3E0CC141A5F9A39 ft=0 fh=0000000000000000 vn="Win32/Trustezeb.C trojan" ac=I fn="C:\Users\Kathi\AppData\Local\IM\Identities\{A373BE7A-F30F-4DF9-95F2-3E75C1388C30}\Message Store\Attachments\Vorderung.zip" sh=5B48F0538FF0003EFE651320F3B8E5F78B09E484 ft=1 fh=7d62b807732f6622 vn="Win32/Adware.Lollipop.D application" ac=I fn="C:\Users\Tino\Downloads\SopCast-3.5.0 (1).exe" sh=5B48F0538FF0003EFE651320F3B8E5F78B09E484 ft=1 fh=7d62b807732f6622 vn="Win32/Adware.Lollipop.D application" ac=I fn="C:\Users\Tino\Downloads\SopCast-3.5.0.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Internet Security Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 51 Adobe Flash Player 12.0.0.43 Flash Player out of Date! Adobe Reader 10.1.9 Adobe Reader out of Date! Google Chrome 32.0.1700.102 Google Chrome 32.0.1700.107 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes' Anti-Malware mbamscheduler.exe Symantec Norton Online Backup NOBuAgent.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast afwServ.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-02-2014 Ran by Tino (administrator) on TINO-HP on 12-02-2014 20:44:17 Running from F:\ Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe () C:\Program Files (x86)\InterVideo\Common\Bin\WinCinemaMgr.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Easybits) C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Logitech, Inc.) C:\Users\Tino\AppData\Local\Logitech® Webcam-Software\Logishrd\LU2.0\LULnchr.exe (Logitech, Inc.) C:\Users\Tino\AppData\Local\Logitech® Webcam-Software\Logishrd\LU2.0\LogitechUpdate.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [hpsysdrv] - c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard) HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [1580368 2010-11-03] (Logitech, Inc.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-06-01] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation) HKLM-x32\...\Run: [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-05-06] (PDF Complete Inc) HKLM-x32\...\Run: [LWS] - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-08-12] (Logitech Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-10] (AVAST Software) HKLM-x32\...\Run: [Magic Desktop for HP notification] - C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1258504 2013-12-27] (Easybits) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\RunOnce: [NCPluginUpdater] - "c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\NCPluginUpdater.exe" Update [21720 2014-01-28] (Hewlett-Packard) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-771379982-2687441850-2496483240-1001\...\Run: [Logitech Vid] - C:\Program Files (x86)\Logitech\Vid HD\Vid.exe [5915480 2010-10-29] (Logitech Inc.) HKU\S-1-5-21-771379982-2687441850-2496483240-1001\...\Run: [GoogleChromeAutoLaunch_881275C6261D4361D619481AC556BC9C] - C:\Users\Tino\AppData\Local\Google\Chrome\Application\chrome.exe [866632 2014-02-02] (Google Inc.) HKU\S-1-5-21-771379982-2687441850-2496483240-1001\...\Run: [TomTomHOME.exe] - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-07-02] (TomTom) HKU\S-1-5-21-771379982-2687441850-2496483240-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.awesomehp.com/?type=hp&ts=1391447732&from=tugs&uid=ST2000DL003-9VT166_5YD67Y9S HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.awesomehp.com/web/?type=ds&ts=1391447732&from=tugs&uid=ST2000DL003-9VT166_5YD67Y9S&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {5BF9B35A-589D-4597-9205-B2897D7AE330} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKCU - {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = SearchScopes: HKCU - {5BF9B35A-589D-4597-9205-B2897D7AE330} URL = SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = BHO: Plus-HD-4.2 - {11111111-1111-1111-1111-110311921102} - C:\Program Files (x86)\Plus-HD-4.2\Plus-HD-4.2-bho64.dll No File BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Chrome: ======= CHR HomePage: CHR RestoreOnStartup: "spdy": { "servers": [ "i1.ytimg.com:443", "i2.ytimg.com:443", "ssl.gstatic.com:443", "ad-emea.doubleclick.net:443", "i4.ytimg.com:443", "static.doubleclick.net:443", "accounts.google.com:443", "plusone.google.com:443", "googleads.g.doubleclick.net:443", "toolbarqueries.google.com:443", "ad.doubleclick.net:443", "clients2.google.com:443", "www.google.com:443", "apis.google.com:443", "www.googleadservices.com:443", "ajax.googleapis.com:443", "maps.google.com:443" CHR DefaultSearchProvider: Delta Search CHR DefaultSearchURL: hxxp://www.google.com CHR DefaultNewTabURL: CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Tino\AppData\Local\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Tino\AppData\Local\Google\Chrome\Application\32.0.1700.107\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Tino\AppData\Local\Google\Chrome\Application\32.0.1700.107\gcswf32.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility) - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL No File CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (WildTangent Games App Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Extension: (YouTube) - C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-27] CHR Extension: (Google-Suche) - C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-27] CHR Extension: (avast! Online Security) - C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-09-11] CHR Extension: (DvdVideoSoft Free Youtube Download) - C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2013-08-25] CHR Extension: (Google Wallet) - C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31] CHR Extension: (Google Mail) - C:\Users\Tino\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-27] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\Tino\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2012-10-01] CHR StartMenuInternet: Google Chrome - C:\Users\Tino\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-10] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [113704 2014-02-10] (AVAST Software) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation) R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-05-06] (PDF Complete Inc) ==================== Drivers (Whitelisted) ==================== R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2013-11-20] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-10] (AVAST Software) R1 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [440672 2014-02-10] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-20] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-20] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-10] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-10] (AVAST Software) S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-10] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-30] () R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [37392 2010-05-20] (Paragon Software Group) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 stdriver; C:\Windows\System32\DRIVERS\stdriverx64.sys [32536 2013-03-16] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-11 20:55 - 2014-02-11 20:55 - 00000624 _____ () C:\Users\Tino\Desktop\JRT.txt 2014-02-11 18:27 - 2014-02-11 18:27 - 00380416 _____ () C:\Users\Tino\Downloads\Gmer-19357.exe 2014-02-11 18:26 - 2014-02-12 20:44 - 00000000 ____D () C:\FRST 2014-02-11 18:25 - 2014-02-11 18:25 - 00000470 _____ () C:\Users\Tino\Desktop\defogger_disable.log 2014-02-11 18:25 - 2014-02-11 18:25 - 00000000 _____ () C:\Users\Tino\defogger_reenable 2014-02-10 21:55 - 2014-02-10 21:55 - 00038681 _____ () C:\ComboFix.txt 2014-02-10 21:43 - 2014-02-10 21:55 - 00000000 ____D () C:\Qoobox 2014-02-10 21:43 - 2014-02-10 21:52 - 00000000 ____D () C:\Windows\erdnt 2014-02-10 21:43 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-10 21:43 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-10 21:43 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-10 21:43 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-10 21:43 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-10 21:43 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-10 21:43 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-10 21:43 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-10 20:29 - 2014-02-10 20:29 - 00000000 ____D () C:\Windows\ERUNT 2014-02-10 20:10 - 2014-02-11 20:45 - 00000000 ____D () C:\AdwCleaner 2014-02-10 19:33 - 2014-02-10 19:33 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\Malwarebytes 2014-02-10 19:32 - 2014-02-10 19:32 - 00001111 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-10 19:32 - 2014-02-10 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-10 19:32 - 2014-02-10 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-10 19:32 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-10 18:35 - 2014-02-10 18:35 - 00005933 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-02-10 18:35 - 2014-02-10 18:35 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-10 18:35 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-02-10 18:35 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-02-10 18:35 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-02-10 18:35 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-02-07 10:55 - 2014-02-07 10:55 - 00074810 _____ () C:\Users\Kathi\Desktop\WEB.DE FreeMail.htm 2014-02-06 20:41 - 2014-02-06 20:41 - 00074777 _____ () C:\Users\Kathi\Desktop\Pdf Bewerbung.htm 2014-02-06 20:41 - 2014-02-06 20:41 - 00000000 ____D () C:\Users\Kathi\Desktop\Pdf Bewerbung_files 2014-02-06 15:12 - 2014-02-06 15:12 - 00074726 _____ () C:\Users\Kathi\Desktop\Lebenslauf.htm 2014-02-06 15:12 - 2014-02-06 15:12 - 00000000 ____D () C:\Users\Kathi\Desktop\Lebenslauf_files 2014-02-06 15:11 - 2014-02-06 15:11 - 00074743 _____ () C:\Users\Kathi\Desktop\Anschreiben.htm 2014-02-06 15:11 - 2014-02-06 15:11 - 00000000 ____D () C:\Users\Kathi\Desktop\Anschreiben_files 2014-02-06 15:10 - 2014-02-07 10:55 - 00000000 ____D () C:\Users\Kathi\Desktop\WEB.DE FreeMail_files 2014-02-03 18:26 - 2014-02-05 18:02 - 00001077 _____ () C:\Users\Tino\Desktop\Continue VuuPC Installation.lnk 2014-02-03 18:15 - 2014-02-03 19:16 - 00000000 ____D () C:\ProgramData\WPM 2014-02-03 18:15 - 2014-02-03 19:16 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-01-31 06:58 - 2014-01-31 06:58 - 00588672 _____ ( ) C:\Users\Tino\Downloads\Setup (3).exe 2014-01-31 06:58 - 2014-01-31 06:58 - 00588672 _____ ( ) C:\Users\Tino\Downloads\Setup (2).exe 2014-01-28 14:54 - 2014-01-28 14:54 - 00000000 ____D () C:\Users\Tino\Documents\My Albums 2014-01-28 14:54 - 2014-01-28 14:54 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\ArcSoft 2014-01-28 14:52 - 2014-01-28 14:52 - 00000000 ____D () C:\Program Files (x86)\ArcSoft 2014-01-28 14:34 - 2014-02-10 18:29 - 00003572 _____ () C:\Windows\System32\Tasks\FinishInstall igdhbblpcellaljokkpfhcjlagemhgjl 2014-01-28 14:32 - 2014-01-28 14:32 - 03502168 _____ () C:\Users\Tino\Downloads\UpdateMyDrivers.exe 2014-01-28 14:32 - 2014-01-28 14:32 - 03502168 _____ () C:\Users\Tino\Downloads\UpdateMyDrivers (1).exe 2014-01-28 14:07 - 2014-01-28 14:07 - 00001071 _____ () C:\Users\Tino\Desktop\CanoScan - Verknüpfung.lnk 2014-01-28 13:53 - 1995-07-31 13:44 - 00212480 _____ (Eastman Kodak) C:\Windows\PCDLIB32.DLL 2014-01-26 15:03 - 2012-03-14 05:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMLMA6.DLL 2014-01-26 15:00 - 2011-01-06 13:09 - 01324544 _____ (CANON INC.) C:\Windows\system32\CNC350C.dll 2014-01-26 15:00 - 2011-01-06 13:09 - 00109568 _____ (CANON INC.) C:\Windows\system32\CNC350I.dll 2014-01-26 15:00 - 2011-01-06 13:07 - 00102400 _____ (CANON INC.) C:\Windows\SysWOW64\CNC350U.dll 2014-01-26 15:00 - 2009-10-19 16:30 - 00346624 _____ (CANON INC.) C:\Windows\system32\CNC350L.dll 2014-01-26 15:00 - 2009-10-19 16:29 - 00307200 _____ (CANON INC.) C:\Windows\SysWOW64\CNC350L.dll 2014-01-26 14:58 - 2014-01-26 14:58 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information 2014-01-26 14:57 - 2014-01-26 14:57 - 30995856 _____ () C:\Users\Tino\Downloads\PixmaMX3501.04.exe 2014-01-26 14:25 - 2012-03-14 05:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMXLMA6.DLL 2014-01-26 14:24 - 2014-01-26 14:24 - 23477400 _____ () C:\Users\Tino\Downloads\xp68-win-mx350-5_56-ea24.exe 2014-01-26 13:12 - 2014-01-26 13:12 - 00000000 ____D () C:\Users\Kathi\Desktop\Dateien Bewerbung 2014-01-26 10:11 - 2014-01-26 10:11 - 00046243 _____ () C:\Users\Kathi\Downloads\eBayISAPI (2).gz 2014-01-16 06:16 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-16 06:16 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-16 06:16 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-16 06:16 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-16 06:16 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-16 06:16 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-16 06:16 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-16 06:16 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-16 06:16 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys ==================== One Month Modified Files and Folders ======= 2014-02-12 20:44 - 2014-02-11 18:26 - 00000000 ____D () C:\FRST 2014-02-12 20:43 - 2012-01-01 12:11 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1003UA.job 2014-02-12 20:35 - 2011-12-27 17:39 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1001UA.job 2014-02-12 20:17 - 2012-02-22 20:37 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-02-12 20:16 - 2013-02-27 16:29 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-12 20:16 - 2012-12-13 05:50 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-02-12 20:15 - 2011-12-30 07:01 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\HP Support Assistant 2014-02-12 20:15 - 2011-12-30 06:56 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\HpUpdate 2014-02-12 19:36 - 2011-12-27 16:14 - 01060123 _____ () C:\Windows\WindowsUpdate.log 2014-02-12 18:34 - 2009-07-14 05:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-12 18:34 - 2009-07-14 05:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-12 18:32 - 2011-11-01 20:42 - 00697072 _____ () C:\Windows\system32\perfh007.dat 2014-02-12 18:32 - 2011-11-01 20:42 - 00148110 _____ () C:\Windows\system32\perfc007.dat 2014-02-12 18:32 - 2009-07-14 06:13 - 01614036 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-12 18:27 - 2011-11-01 21:16 - 00000000 ____D () C:\ProgramData\PDFC 2014-02-12 18:27 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-12 18:27 - 2009-07-14 05:51 - 00205299 _____ () C:\Windows\setupact.log 2014-02-11 21:01 - 2011-12-27 16:20 - 00001423 _____ () C:\Users\Tino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-11 20:56 - 2011-12-27 16:20 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{5CE2A2CC-EC72-4B0D-A299-4E994079C444} 2014-02-11 20:55 - 2014-02-11 20:55 - 00000624 _____ () C:\Users\Tino\Desktop\JRT.txt 2014-02-11 20:45 - 2014-02-10 20:10 - 00000000 ____D () C:\AdwCleaner 2014-02-11 19:00 - 2011-12-30 06:54 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\Skype 2014-02-11 18:58 - 2012-02-01 18:38 - 00000000 ____D () C:\Windows\Minidump 2014-02-11 18:57 - 2011-11-01 21:50 - 00286795 ____N () C:\Windows\Minidump\021114-20888-01.dmp 2014-02-11 18:27 - 2014-02-11 18:27 - 00380416 _____ () C:\Users\Tino\Downloads\Gmer-19357.exe 2014-02-11 18:25 - 2014-02-11 18:25 - 00000470 _____ () C:\Users\Tino\Desktop\defogger_disable.log 2014-02-11 18:25 - 2014-02-11 18:25 - 00000000 _____ () C:\Users\Tino\defogger_reenable 2014-02-11 18:25 - 2011-12-27 16:15 - 00000000 ____D () C:\Users\Tino 2014-02-11 18:16 - 2010-11-21 04:47 - 01321070 _____ () C:\Windows\PFRO.log 2014-02-10 21:55 - 2014-02-10 21:55 - 00038681 _____ () C:\ComboFix.txt 2014-02-10 21:55 - 2014-02-10 21:43 - 00000000 ____D () C:\Qoobox 2014-02-10 21:55 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-02-10 21:52 - 2014-02-10 21:43 - 00000000 ____D () C:\Windows\erdnt 2014-02-10 21:51 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-10 20:29 - 2014-02-10 20:29 - 00000000 ____D () C:\Windows\ERUNT 2014-02-10 20:19 - 2013-11-22 05:41 - 00000000 ____D () C:\Users\Tino\AppData\Local\Mobogenie 2014-02-10 20:18 - 2013-11-20 19:26 - 00002034 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-02-10 20:18 - 2013-03-25 20:22 - 00001974 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk 2014-02-10 20:17 - 2013-12-30 12:26 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-10 20:17 - 2013-03-25 20:32 - 00440672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys 2014-02-10 20:17 - 2013-03-25 20:22 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-10 20:17 - 2013-03-25 20:22 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-02-10 20:17 - 2013-03-25 20:22 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-10 20:17 - 2013-03-25 20:22 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-02-10 20:17 - 2013-03-25 20:21 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-10 20:17 - 2011-12-27 17:54 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-10 20:07 - 2012-01-11 18:03 - 00003180 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForTino 2014-02-10 20:07 - 2012-01-11 18:03 - 00000328 _____ () C:\Windows\Tasks\HPCeeScheduleForTino.job 2014-02-10 19:46 - 2013-11-22 05:41 - 00000000 ____D () C:\Users\Tino\AppData\Local\genienext 2014-02-10 19:33 - 2014-02-10 19:33 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\Malwarebytes 2014-02-10 19:32 - 2014-02-10 19:32 - 00001111 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-10 19:32 - 2014-02-10 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-10 19:32 - 2014-02-10 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-10 18:35 - 2014-02-10 18:35 - 00005933 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-02-10 18:35 - 2014-02-10 18:35 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-10 18:35 - 2013-08-06 16:30 - 00000000 ____D () C:\Program Files (x86)\Java 2014-02-10 18:29 - 2014-01-28 14:34 - 00003572 _____ () C:\Windows\System32\Tasks\FinishInstall igdhbblpcellaljokkpfhcjlagemhgjl 2014-02-10 18:28 - 2012-10-01 15:21 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-02-10 18:27 - 2012-10-02 10:00 - 00003676 _____ () C:\Windows\System32\Tasks\HP-Online-Aktualisierungsprogramm 2014-02-10 18:27 - 2011-12-27 16:19 - 00003404 _____ () C:\Windows\System32\Tasks\ServicePlan 2014-02-10 18:23 - 2011-12-30 08:30 - 00000000 ____D () C:\Users\Kathi\AppData\Roaming\SoftGrid Client 2014-02-10 18:19 - 2011-12-28 07:48 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{B05A2130-CB43-43B8-9B7E-2C5B53C0D083} 2014-02-10 18:18 - 2011-12-30 08:30 - 00110624 _____ () C:\Users\Kathi\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-08 10:46 - 2013-11-22 05:41 - 00000000 ____D () C:\Users\Tino\AppData\Local\cache 2014-02-07 18:58 - 2013-08-26 13:24 - 00000000 ____D () C:\Users\Kathi\Desktop\Bewerbung 2014-02-07 18:58 - 2011-12-30 09:05 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\SoftGrid Client 2014-02-07 18:40 - 2011-12-28 11:48 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\SoftGrid Client 2014-02-07 17:35 - 2011-12-27 17:39 - 00001064 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1001Core.job 2014-02-07 10:55 - 2014-02-07 10:55 - 00074810 _____ () C:\Users\Kathi\Desktop\WEB.DE FreeMail.htm 2014-02-07 10:55 - 2014-02-06 15:10 - 00000000 ____D () C:\Users\Kathi\Desktop\WEB.DE FreeMail_files 2014-02-06 20:41 - 2014-02-06 20:41 - 00074777 _____ () C:\Users\Kathi\Desktop\Pdf Bewerbung.htm 2014-02-06 20:41 - 2014-02-06 20:41 - 00000000 ____D () C:\Users\Kathi\Desktop\Pdf Bewerbung_files 2014-02-06 15:12 - 2014-02-06 15:12 - 00074726 _____ () C:\Users\Kathi\Desktop\Lebenslauf.htm 2014-02-06 15:12 - 2014-02-06 15:12 - 00000000 ____D () C:\Users\Kathi\Desktop\Lebenslauf_files 2014-02-06 15:11 - 2014-02-06 15:11 - 00074743 _____ () C:\Users\Kathi\Desktop\Anschreiben.htm 2014-02-06 15:11 - 2014-02-06 15:11 - 00000000 ____D () C:\Users\Kathi\Desktop\Anschreiben_files 2014-02-05 18:02 - 2014-02-03 18:26 - 00001077 _____ () C:\Users\Tino\Desktop\Continue VuuPC Installation.lnk 2014-02-05 17:53 - 2013-11-25 09:40 - 00000000 ____D () C:\Users\Kathi\AppData\Local\Mobogenie 2014-02-05 15:16 - 2013-02-27 16:29 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-05 15:16 - 2013-02-27 16:29 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-05 15:16 - 2011-11-01 21:11 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-04 22:08 - 2011-11-01 21:50 - 00286603 ____N () C:\Windows\Minidump\020414-19812-01.dmp 2014-02-04 19:30 - 2011-11-01 21:50 - 00286603 ____N () C:\Windows\Minidump\020414-20763-01.dmp 2014-02-04 19:29 - 2012-01-22 16:56 - 00000000 ____D () C:\Users\Tino\Desktop\Gebraucht 2014-02-04 19:20 - 2011-11-01 21:50 - 00287371 ____N () C:\Windows\Minidump\020414-20592-01.dmp 2014-02-03 19:16 - 2014-02-03 18:15 - 00000000 ____D () C:\ProgramData\WPM 2014-02-03 19:16 - 2014-02-03 18:15 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-02-03 18:49 - 2011-12-27 16:20 - 00000000 ___RD () C:\Users\Tino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-02 18:17 - 2013-02-03 11:07 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\vlc 2014-02-02 15:46 - 2012-10-02 10:00 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2014-01-31 06:58 - 2014-01-31 06:58 - 00588672 _____ ( ) C:\Users\Tino\Downloads\Setup (3).exe 2014-01-31 06:58 - 2014-01-31 06:58 - 00588672 _____ ( ) C:\Users\Tino\Downloads\Setup (2).exe 2014-01-28 14:54 - 2014-01-28 14:54 - 00000000 ____D () C:\Users\Tino\Documents\My Albums 2014-01-28 14:54 - 2014-01-28 14:54 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\ArcSoft 2014-01-28 14:54 - 2012-02-21 16:33 - 00000000 ____D () C:\Users\Tino\AppData\Roaming\Canon 2014-01-28 14:52 - 2014-01-28 14:52 - 00000000 ____D () C:\Program Files (x86)\ArcSoft 2014-01-28 14:52 - 2011-11-01 21:03 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-01-28 14:32 - 2014-01-28 14:32 - 03502168 _____ () C:\Users\Tino\Downloads\UpdateMyDrivers.exe 2014-01-28 14:32 - 2014-01-28 14:32 - 03502168 _____ () C:\Users\Tino\Downloads\UpdateMyDrivers (1).exe 2014-01-28 14:07 - 2014-01-28 14:07 - 00001071 _____ () C:\Users\Tino\Desktop\CanoScan - Verknüpfung.lnk 2014-01-28 07:43 - 2012-01-01 12:11 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-771379982-2687441850-2496483240-1003Core.job 2014-01-26 14:58 - 2014-01-26 14:58 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information 2014-01-26 14:57 - 2014-01-26 14:57 - 30995856 _____ () C:\Users\Tino\Downloads\PixmaMX3501.04.exe 2014-01-26 14:24 - 2014-01-26 14:24 - 23477400 _____ () C:\Users\Tino\Downloads\xp68-win-mx350-5_56-ea24.exe 2014-01-26 14:16 - 2012-01-06 17:42 - 00000000 ____D () C:\Program Files (x86)\Canon 2014-01-26 14:14 - 2012-02-21 16:33 - 00000000 ___HD () C:\ProgramData\CanonIJScan 2014-01-26 14:14 - 2012-01-08 10:27 - 00000000 ____D () C:\Users\Kathi\AppData\Roaming\Canon 2014-01-26 13:12 - 2014-01-26 13:12 - 00000000 ____D () C:\Users\Kathi\Desktop\Dateien Bewerbung 2014-01-26 10:11 - 2014-01-26 10:11 - 00046243 _____ () C:\Users\Kathi\Downloads\eBayISAPI (2).gz 2014-01-26 09:57 - 2009-07-14 05:45 - 00399840 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-17 09:03 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-16 06:18 - 2009-07-14 03:34 - 00000499 _____ () C:\Windows\win.ini 2014-01-16 06:17 - 2013-08-14 07:48 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-16 06:14 - 2011-12-28 07:41 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\Tino\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-10 21:13 ==================== End Of Log ============================ Vielen Dank bis dahin! Guter Teilerfolg! awesomehp und die Internetblockaden sind, soweit ich das bisher sehe, weg. :-) In der Suchmaschinenverwaltung von Chrome ist aber immer noch Delta-Search und lässt sich nicht löschen. Sucht man mit der obersten Zeile von Chrome, wird tatsächlich delta-Search als Suchmaschine verwendet. Ruft man Google auf und googelt, sucht man mit Google. |
13.02.2014, 21:41 | #6 |
/// the machine /// TB-Ausbilder | Win 7 64 Bit HP awesomehp und Delta-Search eingeschränkter Internetzugang Revo Uninstaller - Download - Filepony damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren.
__________________ --> Win 7 64 Bit HP awesomehp und Delta-Search eingeschränkter Internetzugang |
14.02.2014, 21:18 | #7 |
| Win 7 64 Bit HP awesomehp und Delta-Search eingeschränkter Internetzugang Hallo Schrauber, soweit ich das jetzt überblicken kann, geht wieder alles. Super! Vielen Dank! |
15.02.2014, 18:13 | #8 |
/// the machine /// TB-Ausbilder | Win 7 64 Bit HP awesomehp und Delta-Search eingeschränkter Internetzugang Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Win 7 64 Bit HP awesomehp und Delta-Search eingeschränkter Internetzugang |
4d36e972-e325-11ce-bfc1-08002be10318, adw-cleaner, awesomehp, awesomehp entfernen, branding, desktop, diagnostics, dvdvideosoft ltd., flash player, geht nicht mehr, installation, malwarebytes, microsoft, mobogenie, mobogenie entfernen, registry, software, wildtangent games, win32/adware.lollipop.d, win32/lockscreen.akw, win32/trustezeb.c, windows |