|
Plagegeister aller Art und deren Bekämpfung: Google Chrome öffnet sich...Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
17.03.2014, 15:06 | #31 |
| Google Chrome öffnet sich... Ist hoff ich endlich alles erledigt. Du hast mich aus einer richtig verzweifelten Situation gerettet Dir nochmal ein ganz dickes für deine tolle Hilfe, deine Zeit und für deine Mühen |
18.03.2014, 10:52 | #32 |
/// the machine /// TB-Ausbilder | Google Chrome öffnet sich... Gern Geschehen
__________________
__________________ |
23.04.2014, 16:28 | #33 |
| Google Chrome öffnet sich... Hallo Schrauber, ich hab das Problem seid gestern erneut malware check zeigte nichts an.
__________________ |
24.04.2014, 11:12 | #34 |
/// the machine /// TB-Ausbilder | Google Chrome öffnet sich... Frisches FRST Log bitte. problem bitte nochmal genau beschreiben
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.04.2014, 12:22 | #35 |
| Google Chrome öffnet sich... Es öffnet sich wieder eine Google Chrome Seite und dann geht der PC aus. Ich hatte auch wieder Zahlen in meinen Sätzen die ich geschrieben hatte. Wenn ich den PC neu starte und auf eine Seite gehen möchte dann kommt ein Fenster mit der Meldung das meine Einstellungen nicht gespeichert werden können .... ! Das klick ich weg und kann dann ganz normal eine Seite öffnen. FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-04-2014 Ran by Schnuppel (administrator) on SCHNUPPEL-PC on 24-04-2014 13:13:37 Running from C:\Users\Schnuppel\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Microsoft Corporation) C:\windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (McAfee, Inc.) C:\Windows\system32\mfevtps.exe (Intel Corporation) C:\WINDOWS\System32\igfxtray.exe (Intel Corporation) C:\WINDOWS\System32\hkcmd.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Intel Corporation) C:\WINDOWS\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (WebInternetSecurity) C:\Users\Schnuppel\AppData\Local\WebInternetSecurity\WebInternetSecurity.exe (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-05-27] (IDT, Inc.) HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [503942 2011-04-13] (Creative Technology Ltd) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-13] (Intel Corporation) HKLM-x32\...\Run: [Dell Registration] => C:\Program Files (x86)\System Registration\prodreg.exe [4165440 2011-08-04] (Dell, Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [RoxWatchTray] => c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions) HKLM-x32\...\Run: [Desktop Disc Tool] => c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] () HKLM-x32\...\Run: [AccuWeatherWidget] => C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe [968048 2012-02-01] () HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-4187171121-565255664-2242978531-1000\...\Run: [WebInternetSecurity] => C:\Users\Schnuppel\AppData\Local\WebInternetSecurity\WebInternetSecurity.exe [797184 2013-12-30] (WebInternetSecurity) HKU\S-1-5-21-4187171121-565255664-2242978531-1000\...\Run: [WebInternetSecurity Update Task] => C:\Users\Schnuppel\AppData\Local\WebInternetSecurity\uninstall.webinternetsecurity.exe [3548160 2014-03-31] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) ==================== Internet (Whitelisted) ==================== ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: http=127.0.0.1:49172;https=127.0.0.1:49172 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.facebook.de/ SearchScopes: HKCU - {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () Chrome: ======= CHR Extension: (Google Wallet) - C:\Users\Schnuppel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-24] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-20] (Avira Operations GmbH & Co. KG) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [199304 2012-05-26] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-11-04] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-11-04] (McAfee, Inc.) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia) S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia) ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-01] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-17] (Avira Operations GmbH & Co. KG) S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-11-04] (McAfee, Inc.) S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179792 2013-11-04] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311120 2013-11-04] (McAfee, Inc.) U3 mfeavfk01; No ImagePath R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519576 2013-11-04] (McAfee, Inc.) R2 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [782360 2013-11-04] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [100912 2012-02-22] (McAfee, Inc.) R2 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343696 2013-11-04] (McAfee, Inc.) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-24 13:13 - 2014-04-24 13:13 - 00011588 _____ () C:\Users\Schnuppel\Downloads\FRST.txt 2014-04-24 13:13 - 2014-04-24 13:13 - 00000000 ____D () C:\FRST 2014-04-24 13:12 - 2014-04-24 13:12 - 02061824 _____ (Farbar) C:\Users\Schnuppel\Downloads\FRST64.exe 2014-04-24 09:09 - 2014-04-24 09:09 - 00000056 _____ () C:\windows\setupact.log 2014-04-24 09:09 - 2014-04-24 09:09 - 00000000 _____ () C:\windows\setuperr.log 2014-04-17 14:51 - 2014-04-17 14:50 - 00313256 _____ (Oracle Corporation) C:\windows\system32\javaws.exe 2014-04-17 14:50 - 2014-04-17 14:50 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe 2014-04-17 14:50 - 2014-04-17 14:50 - 00189352 _____ (Oracle Corporation) C:\windows\system32\java.exe 2014-04-17 14:50 - 2014-04-17 14:50 - 00108968 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll 2014-04-17 14:50 - 2014-04-17 14:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-04-09 16:33 - 2014-03-13 08:33 - 02238976 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-04-09 16:33 - 2014-03-13 08:33 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-04-09 16:33 - 2014-03-13 08:33 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-04-09 16:33 - 2014-03-13 08:32 - 19273728 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-04-09 16:33 - 2014-03-13 08:32 - 03959808 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-04-09 16:33 - 2014-03-13 08:32 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2014-04-09 16:33 - 2014-03-13 08:32 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-04-09 16:33 - 2014-03-13 08:32 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-04-09 16:33 - 2014-03-13 08:32 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-04-09 16:33 - 2014-03-13 08:31 - 15404544 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-04-09 16:33 - 2014-03-13 08:31 - 02648576 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-04-09 16:33 - 2014-03-13 08:31 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-04-09 16:33 - 2014-03-13 08:31 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2014-04-09 16:33 - 2014-03-13 08:31 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-04-09 16:33 - 2014-03-13 08:31 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-04-09 16:33 - 2014-03-13 07:10 - 01766400 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-04-09 16:33 - 2014-03-13 07:10 - 01140736 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-04-09 16:33 - 2014-03-13 07:09 - 14358016 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-04-09 16:33 - 2014-03-13 07:09 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-04-09 16:33 - 2014-03-13 07:09 - 02877952 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-04-09 16:33 - 2014-03-13 07:09 - 02049536 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-04-09 16:33 - 2014-03-13 07:09 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2014-04-09 16:33 - 2014-03-13 07:09 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-04-09 16:33 - 2014-03-13 07:09 - 00391168 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2014-04-09 16:33 - 2014-03-13 07:09 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-04-09 16:33 - 2014-03-13 07:09 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll 2014-04-09 16:33 - 2014-03-13 07:09 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-04-09 16:33 - 2014-03-13 07:09 - 00039936 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-04-09 16:33 - 2014-03-13 07:09 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-04-09 16:33 - 2014-03-13 06:57 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-04-09 16:33 - 2014-03-13 06:47 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-04-09 16:33 - 2014-03-13 05:59 - 00089600 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2014-04-09 16:33 - 2014-03-13 05:51 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe 2014-04-09 16:32 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll 2014-04-09 16:32 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll 2014-04-09 16:32 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll 2014-04-09 16:32 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll 2014-04-09 16:32 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll 2014-04-09 16:32 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll 2014-04-09 16:32 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll 2014-04-09 16:32 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe 2014-04-09 16:32 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll 2014-04-09 16:32 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe 2014-04-09 16:32 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe 2014-04-09 16:32 - 2014-02-04 04:37 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys 2014-04-09 16:32 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys 2014-04-09 16:32 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys 2014-04-09 16:32 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll 2014-04-09 16:32 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll 2014-04-09 16:32 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys 2014-04-09 14:13 - 2014-04-09 14:13 - 00884712 _____ (Google Inc.) C:\Users\Schnuppel\Downloads\ChromeSetup (2).exe 2014-03-31 11:54 - 2014-03-31 11:54 - 00000000 ____D () C:\Users\Schnuppel\AppData\Local\WebInternetSecurity ==================== One Month Modified Files and Folders ======= 2014-04-24 13:13 - 2014-04-24 13:13 - 00011588 _____ () C:\Users\Schnuppel\Downloads\FRST.txt 2014-04-24 13:13 - 2014-04-24 13:13 - 00000000 ____D () C:\FRST 2014-04-24 13:12 - 2014-04-24 13:12 - 02061824 _____ (Farbar) C:\Users\Schnuppel\Downloads\FRST64.exe 2014-04-24 13:06 - 2014-03-10 13:38 - 00001116 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-24 13:06 - 2013-11-26 02:15 - 00000422 _____ () C:\windows\Tasks\SystemToolsDailyTest.job 2014-04-24 12:47 - 2014-03-12 21:31 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-04-24 09:21 - 2009-07-14 06:45 - 00020720 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-24 09:21 - 2009-07-14 06:45 - 00020720 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-24 09:13 - 2014-03-06 17:53 - 01217327 _____ () C:\windows\WindowsUpdate.log 2014-04-24 09:10 - 2013-11-26 02:09 - 00000000 ____D () C:\Users\Default\AppData\Local\SoftThinks 2014-04-24 09:10 - 2013-11-26 02:09 - 00000000 ____D () C:\Users\Default User\AppData\Local\SoftThinks 2014-04-24 09:10 - 2011-11-08 00:54 - 00000000 ____D () C:\Program Files (x86)\Dell DataSafe Local Backup 2014-04-24 09:09 - 2014-04-24 09:09 - 00000056 _____ () C:\windows\setupact.log 2014-04-24 09:09 - 2014-04-24 09:09 - 00000000 _____ () C:\windows\setuperr.log 2014-04-24 09:09 - 2014-03-10 13:38 - 00001112 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-24 09:09 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-04-23 15:08 - 2013-11-25 20:00 - 00003488 _____ () C:\windows\System32\Tasks\PCDEventLauncher 2014-04-23 15:07 - 2013-11-26 02:15 - 00003464 _____ () C:\windows\System32\Tasks\SystemToolsDailyTest 2014-04-21 21:34 - 2014-02-04 12:56 - 00000000 ____D () C:\Users\Schnuppel\AppData\Local\Paint.NET 2014-04-17 14:50 - 2014-04-17 14:51 - 00313256 _____ (Oracle Corporation) C:\windows\system32\javaws.exe 2014-04-17 14:50 - 2014-04-17 14:50 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe 2014-04-17 14:50 - 2014-04-17 14:50 - 00189352 _____ (Oracle Corporation) C:\windows\system32\java.exe 2014-04-17 14:50 - 2014-04-17 14:50 - 00108968 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll 2014-04-17 14:50 - 2014-04-17 14:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-04-17 14:50 - 2011-11-08 00:03 - 00000000 ____D () C:\Program Files\Java 2014-04-15 16:15 - 2013-11-26 02:08 - 00000000 ____D () C:\Users\Schnuppel 2014-04-11 18:03 - 2013-11-26 02:16 - 00000000 ____D () C:\Users\Schnuppel\Documents\Bluetooth-Exchange-Ordner 2014-04-09 23:06 - 2011-02-23 15:08 - 00000000 ____D () C:\windows\Panther 2014-04-09 20:04 - 2013-12-07 00:08 - 00000000 ____D () C:\windows\system32\MRT 2014-04-09 20:01 - 2013-12-07 00:08 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-04-09 14:13 - 2014-04-09 14:13 - 00884712 _____ (Google Inc.) C:\Users\Schnuppel\Downloads\ChromeSetup (2).exe 2014-04-09 14:06 - 2014-03-12 21:31 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-04-09 14:06 - 2014-01-12 15:20 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-04-09 14:06 - 2014-01-12 15:20 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-08 17:07 - 2011-11-08 01:40 - 00699666 _____ () C:\windows\system32\perfh007.dat 2014-04-08 17:07 - 2011-11-08 01:40 - 00149774 _____ () C:\windows\system32\perfc007.dat 2014-04-08 17:07 - 2009-07-14 07:13 - 01620612 _____ () C:\windows\system32\PerfStringBackup.INI 2014-03-31 16:46 - 2014-03-10 13:38 - 00004112 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-31 16:46 - 2014-03-10 13:38 - 00003860 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-31 14:41 - 2011-11-08 00:51 - 00000000 ____D () C:\ProgramData\McAfee 2014-03-31 11:54 - 2014-03-31 11:54 - 00000000 ____D () C:\Users\Schnuppel\AppData\Local\WebInternetSecurity 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\Schnuppel\AppData\Local\Temp\avgnt.exe C:\Users\Schnuppel\AppData\Local\Temp\System.Data.SQLite.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-04 13:52 ==================== End Of Log ============================ --- --- --- HTML-Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-04-2014 Ran by Schnuppel at 2014-04-24 13:14:11 Running from C:\Users\Schnuppel\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 13 ActiveX (HKLM-x32\...\{8F9B1C8E-F50E-4139-8701-45016021E102}) (Version: 13.0.0.182 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\{28ADCCAD-3C23-44A1-A93F-47AA176F7AD7}) (Version: 13.0.0.182 - Adobe Systems Incorporated) Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd) Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Biet-O-Matic v2.14.12 (HKLM-x32\...\Biet-O-Matic v2.14.12) (Version: 2.14.12 - BOM Development Team) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Build-a-lot 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.07 - Piriform) Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell Inc.) Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell Inc.) Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc) Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.) Dell PhotoStage (HKLM-x32\...\{E4335E82-17B3-460F-9E70-39D9BC269DB3}) (Version: 1.5.0.65 - ArcSoft) Dell Product Registration (HKLM-x32\...\{2A0F2CC5-3065-492C-8380-B03AA7106B1A}) (Version: 1.1.3 - Dell Inc.) Dell Stage (HKLM-x32\...\{E2F57269-065E-4B19-8CDA-AB6C401FAF1A}) (Version: 1.7.209.0 - Fingertapps) Dell Stage Remote (HKLM-x32\...\{AF4D3C63-009B-4A17-B02E-D395065DD3F0}) (Version: 2.0.0.43 - ArcSoft) Dell Support Center (HKLM\...\Dell Support Center) (Version: 3.1.5803.11 - Dell Inc.) Dell Support Center (Version: 3.1.5803.11 - PC-Doctor, Inc.) Hidden Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1207.101.225 - ALPS ELECTRIC CO., LTD.) Dell VideoStage (HKLM-x32\...\InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.) Dell VideoStage (x32 Version: 1.2.0.1712 - CyberLink Corp.) Hidden Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd) Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden DW WLAN Card (HKLM\...\DW WLAN Card) (Version: 5.100.82.88 - Dell Inc.) Escape Whisper Valley (TM) (x32 Version: 2.2.0.95 - WildTangent) Hidden Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden Final Drive Fury (x32 Version: 2.2.0.95 - WildTangent) Hidden Final Drive Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6341.0 - IDT) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2342 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation) iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.) Java 7 Update 55 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417055FF}) (Version: 7.0.550 - Oracle) Jewel Quest (x32 Version: 2.2.0.95 - WildTangent) Hidden Jewel Quest Solitaire 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Luxor (x32 Version: 2.2.0.95 - WildTangent) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Namco All-Stars PAC-MAN (x32 Version: 2.2.0.95 - WildTangent) Hidden Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC) Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.09.25 - Dell Inc.) RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30126 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Roxio Activation Module (x32 Version: 1.0 - Roxio) Hidden Roxio BackOnTrack (x32 Version: 1.3.3 - Roxio) Hidden Roxio Burn (x32 Version: 1.8 - Roxio) Hidden Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio) Roxio Creator Starter (x32 Version: 1.0.439 - Roxio) Hidden Roxio Creator Starter (x32 Version: 5.0.0 - Roxio) Hidden Roxio Express Labeler 3 (x32 Version: 3.2.2 - Roxio) Hidden Roxio File Backup (Version: 1.3.2 - Roxio) Hidden Samantha Swift (x32 Version: 2.2.0.95 - WildTangent) Hidden Secunia PSI (3.0.0.9016) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.9016 - Secunia) Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Wedding Dash - Ready, Aim, Love! (x32 Version: 2.2.0.95 - WildTangent) Hidden WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7600 - Broadcom Corporation) WildTangent Games App (Dell Games) (x32 Version: 4.0.5.2 - WildTangent) Hidden WildTangent-Spiele (HKLM-x32\...\WildTangent dell Master Uninstall) (Version: 1.0.2.5 - WildTangent) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden ==================== Restore Points ========================= 25-03-2014 09:10:42 Windows Update 28-03-2014 11:29:27 Windows Update 01-04-2014 13:08:26 Windows Update 03-04-2014 17:36:55 Revo Uninstaller's restore point - TuneUp Utilities 2013 03-04-2014 17:39:48 TuneUp Utilities 2013 wird entfernt 03-04-2014 17:41:15 TuneUp Utilities Language Pack (de-DE) wird entfernt 08-04-2014 10:34:55 Windows Update 09-04-2014 18:00:26 Windows Update 15-04-2014 06:01:50 Windows Update 18-04-2014 10:12:10 Windows Update 22-04-2014 10:11:41 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0B46897F-81ED-4213-87AD-C37EF374AE43} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-22] (Piriform Ltd) Task: {1DA2C733-3970-48A8-9FF1-41DD60CAC34A} - System32\Tasks\{F14A2CED-E183-40E0-93E3-0EA41C439715} => C:\Program Files (x86)\Dell DataSafe Local Backup\dslauncher.exe [2011-08-01] () Task: {275BC924-79C4-4974-9CB4-0E870C1D48FE} - System32\Tasks\{A0EAF53A-EAEA-4FF6-9F31-C6222DA5712B} => C:\Program Files (x86)\Dell DataSafe Local Backup\dslauncher.exe [2011-08-01] () Task: {474FB7DD-77D8-4353-AB1F-082DEC889689} - System32\Tasks\{61012C3F-26CC-4E01-A20A-37127768BDAE} => Chrome.exe Task: {57D99862-35F4-4C70-B521-DD9188E42DB4} - System32\Tasks\PCDoctorBackgroundMonitorTask => c:\Program Files\Dell Support Center\uaclauncher.exe [2011-03-22] (PC-Doctor, Inc.) Task: {5FF2ECA2-EED2-4352-BD50-B4BDB13D92A3} - System32\Tasks\SystemToolsDailyTest => c:\Program Files\Dell Support Center\pcdrcui.exe [2011-03-22] (PC-Doctor, Inc.) Task: {B41B2245-0259-47C3-AC2F-00C87BACDE8D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-10] (Google Inc.) Task: {C4E045DC-1C4B-4853-AF80-DAB32A767818} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-10] (Google Inc.) Task: {CFD69CB2-7081-4BFE-8B32-24175DBB55E1} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-09] (Adobe Systems Incorporated) Task: {D08EF8DB-53BA-4E30-99CB-9C1D9435BBF1} - System32\Tasks\{A2C75968-E758-47A2-A933-B9772D3786FD} => Chrome.exe Task: {F0F80572-7304-432E-883C-E652F71D3117} - System32\Tasks\PCDEventLauncher => c:\Program Files\Dell Support Center\sessionchecker.exe [2011-03-22] (PC-Doctor, Inc.) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\PCDoctorBackgroundMonitorTask.job => c:\Program Files\Dell Support Center\uaclauncher.exe Task: C:\windows\Tasks\SystemToolsDailyTest.job => c:\Program Files\Dell Support Center\pcdrcui.exe ==================== Loaded Modules (whitelisted) ============= 2011-11-08 01:14 - 2011-03-26 03:28 - 00094208 _____ () C:\WINDOWS\System32\IccLibDll_x64.dll 2011-11-08 00:54 - 2011-08-18 18:05 - 02751808 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE 2011-01-13 23:56 - 2011-01-13 23:56 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2013-11-26 02:35 - 2013-11-01 03:25 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2014-02-12 21:58 - 2014-02-12 21:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-12 21:58 - 2014-02-12 21:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-04-09 14:14 - 2014-04-02 03:57 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll 2014-02-13 10:45 - 2014-02-13 10:45 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\3e27ac2000641918e7215d97c63e957d\IsdiInterop.ni.dll 2011-11-08 00:03 - 2011-01-13 01:56 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2014-04-09 14:14 - 2014-04-02 03:57 - 00674632 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libglesv2.dll 2014-04-09 14:14 - 2014-04-02 03:57 - 00093000 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libegl.dll 2014-04-09 14:14 - 2014-04-02 03:57 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll 2014-04-09 14:14 - 2014-04-02 03:58 - 13691720 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll 2014-04-09 14:14 - 2014-04-02 03:57 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll 2014-04-09 14:14 - 2014-04-02 03:58 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/24/2014 00:49:07 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2075 Error: (04/24/2014 00:49:07 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2075 Error: (04/24/2014 00:49:07 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/24/2014 00:49:06 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1061 Error: (04/24/2014 00:49:06 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1061 Error: (04/24/2014 00:49:06 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/24/2014 00:47:01 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1228867 Error: (04/24/2014 00:47:01 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1228867 Error: (04/24/2014 00:47:01 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/24/2014 00:26:33 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1092 System errors: ============= Error: (04/23/2014 09:33:05 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (04/22/2014 06:22:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Error: (04/22/2014 06:14:59 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 22.04.2014 um 16:20:03 unerwartet heruntergefahren. Error: (04/22/2014 04:20:03 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 22.04.2014 um 16:18:11 unerwartet heruntergefahren. Error: (04/22/2014 04:16:17 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 22.04.2014 um 16:15:33 unerwartet heruntergefahren. Error: (04/22/2014 09:12:10 AM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 21.04.2014 um 22:56:00 unerwartet heruntergefahren. Error: (04/21/2014 06:13:13 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/21/2014 06:13:13 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535. Error: (04/20/2014 10:34:16 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/20/2014 10:34:16 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535. Microsoft Office Sessions: ========================= Error: (04/24/2014 00:49:07 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2075 Error: (04/24/2014 00:49:07 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2075 Error: (04/24/2014 00:49:07 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/24/2014 00:49:06 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1061 Error: (04/24/2014 00:49:06 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1061 Error: (04/24/2014 00:49:06 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/24/2014 00:47:01 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1228867 Error: (04/24/2014 00:47:01 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1228867 Error: (04/24/2014 00:47:01 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/24/2014 00:26:33 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1092 ==================== Memory info =========================== Percentage of memory in use: 45% Total physical RAM: 4004.27 MB Available physical RAM: 2180.04 MB Total Pagefile: 8006.73 MB Available Pagefile: 5718.66 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:581.42 GB) (Free:536.96 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: 8637ECAB) Partition 1: (Not Active) - (Size=100 MB) - (Type=DE) Partition 2: (Active) - (Size=15 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=581 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
25.04.2014, 08:27 | #36 |
/// the machine /// TB-Ausbilder | Google Chrome öffnet sich... Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\S-1-5-21-4187171121-565255664-2242978531-1000\...\Run: [WebInternetSecurity] => C:\Users\Schnuppel\AppData\Local\WebInternetSecurity\WebInternetSecurity.exe [797184 2013-12-30] (WebInternetSecurity) HKU\S-1-5-21-4187171121-565255664-2242978531-1000\...\Run: [WebInternetSecurity Update Task] => C:\Users\Schnuppel\AppData\Local\WebInternetSecurity\uninstall.webinternetsecurity.exe [3548160 2014-03-31] () ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: http=127.0.0.1:49172;https=127.0.0.1:49172 CHR Extension: (Google Wallet) - C:\Users\Schnuppel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-24] 2014-03-31 11:54 - 2014-03-31 11:54 - 00000000 ____D () C:\Users\Schnuppel\AppData\Local\WebInternetSecurity Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ --> Google Chrome öffnet sich... |
25.04.2014, 19:46 | #37 |
| Google Chrome öffnet sich...HTML-Code: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-04-2014 01 Ran by Schnuppel at 2014-04-25 20:45:28 Run:1 Running from C:\Users\Schnuppel\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\S-1-5-21-4187171121-565255664-2242978531-1000\...\Run: [WebInternetSecurity] => C:\Users\Schnuppel\AppData\Local\WebInternetSecurity\WebInternetSecurity.exe [797184 2013-12-30] (WebInternetSecurity) HKU\S-1-5-21-4187171121-565255664-2242978531-1000\...\Run: [WebInternetSecurity Update Task] => C:\Users\Schnuppel\AppData\Local\WebInternetSecurity\uninstall.webinternetsecurity.exe [3548160 2014-03-31] () ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: http=127.0.0.1:49172;https=127.0.0.1:49172 CHR Extension: (Google Wallet) - C:\Users\Schnuppel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-24] 2014-03-31 11:54 - 2014-03-31 11:54 - 00000000 ____D () C:\Users\Schnuppel\AppData\Local\WebInternetSecurity ***************** HKU\S-1-5-21-4187171121-565255664-2242978531-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WebInternetSecurity => Value deleted successfully. HKU\S-1-5-21-4187171121-565255664-2242978531-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WebInternetSecurity Update Task => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully. C:\Users\Schnuppel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda => Moved successfully. C:\Users\Schnuppel\AppData\Local\WebInternetSecurity => Moved successfully. ==== End of Fixlog ==== |
26.04.2014, 15:41 | #38 |
/// the machine /// TB-Ausbilder | Google Chrome öffnet sich... Immer noch so Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
26.04.2014, 17:31 | #39 |
| Google Chrome öffnet sich... ich bin ebend erst on gekommen. werd heute abend oder morgen vormittag nochmal schreiben und berichten ob noch probleme aufgetreten sind |
27.04.2014, 17:56 | #40 |
| Google Chrome öffnet sich... hatte es gestern Abend wieder ganz extrem mit den Zahlen die sich ins geschriebene schleichen und gerade ebend kam wieder Google Chrome Hilfe und Aus war mein Lappi wieder Das geht manchmal bis zu 3x hintereinander so und dann gehts auch mal für 1-2 tage ohne diese Störungen. Dein Malware programm lass ich beinahe täglich durchlaufen, ohne Fund. Irgendwas vermute ich ist bei der Installation von Google Chrome nicht richtig , aber ich hab ja leider 0 Ahnung. |
28.04.2014, 08:46 | #41 |
/// the machine /// TB-Ausbilder | Google Chrome öffnet sich... Und diese Chrome Seite öffnet sich von alleine, ohne das Chrome ansich vorher lief? Andere Browser haben diese probleme nicht?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
30.04.2014, 19:18 | #42 |
| Google Chrome öffnet sich... Ich hab gestern die ganze zeit den IE benutzt und da war nichts (meine mich aber erinnern zu können das sich während dessen auch die google chrome hilfe seite vor einiger zeit mal öffnete). heute benutze ich nur den chrome browser und es war bis jetzt auch nichts. es tritt auch nicht immer auf. manchmal auch nur alle paar tage, manchmal 3x hintereinander. die besagte chrome seite öffnet sich nur wenn ich im internet surfe, egal wo auch immer. vor 3 tagen ging der pc aus ohne das sich diese seite vorher öffnete. |
01.05.2014, 16:35 | #43 |
/// the machine /// TB-Ausbilder | Google Chrome öffnet sich... Hmm, das ist für ne Fernwartung natürlich extrem sporadisch....
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.05.2014, 19:20 | #44 |
| Google Chrome öffnet sich... Vielleicht hilft das etwas weiter. Wenn ich CCleaner durchlaufen lasse und ich mach danach Chrome auf dann kommt diese Meldung: Google Chrome Ihre Einstellungen können nicht gelesen werden. Einige Funktionen sind möglicherweise nicht verfügbar und Änderungen an Einstellungen werden nicht gespeichert. |
02.05.2014, 16:44 | #45 |
/// the machine /// TB-Ausbilder | Google Chrome öffnet sich... Bist Du in einem Adminkonto unterwegs oder Standarduser?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |