|
Log-Analyse und Auswertung: TR/Kazy. 19411. 5Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
02.03.2014, 21:56 | #1 |
| TR/Kazy. 19411. 5 Hi...Habe ein Problem. Habe mir wohl den TR/Kazy. 19411.5 eingefangen. Wie werde ich den wieder los? Bin nicht besonders erprobt im Umgang mit dem PC. Wär schön, wenn mir trotzdem jemand helfen könnte! Liebe Grüsse Mandelauge |
02.03.2014, 23:14 | #2 |
Ruhe in Frieden † 2019 | TR/Kazy. 19411. 5Mein Name ist Sandra und ich werde Dir bei Deinem Problem behilflich sein.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist meist der schnellere und immer der sicherste Weg. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Dir jemand vom Team sagt, dass Du clean bist. Bitte füge die Logs immer in Code-Tags ein. Wenn Du das nicht machst, erschwert es mir sehr das Auswerten. Danke. Dazu:
Schritt 1 Bitte poste mir den Fund deines Antivirenprogramms Schritt 2 Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Geändert von Bootsektor (02.03.2014 um 23:19 Uhr) |
03.03.2014, 09:38 | #3 |
| TR/Kazy. 19411. 5 In der Datei 'C:\Windows\System32\spool\drivers\w32x86\3\ZSHP1600.EXE'
__________________wurde ein Virus oder unerwünschtes Programm 'TR/Kazy.19411.5' [trojan] gefunden. Ausgeführte Aktion: Zugriff erlauben |
03.03.2014, 11:17 | #5 |
| TR/Kazy. 19411. 5 In der Datei 'C:\Windows\System32\spool\drivers\w32x86\3\ZSHP1600.EXE' wurde ein Virus oder unerwünschtes Programm 'TR/Kazy.19411.5' [trojan] gefunden. Ausgeführte Aktion: Zugriff erlauben Weiss nicht genau, was ich jetzt machen muss. In der Systemregistrierung wurden 128 Infektionen gefunden. Nun wird mir eine kostenpflichtige Vollversion empfohlen. Lg Heidi |
03.03.2014, 11:22 | #6 |
Ruhe in Frieden † 2019 | TR/Kazy. 19411. 5 Hallo Heidi, ich brauche noch einen Scan mit FRST, wie in unten stehender Anleitung beschrieben, gucke dass du auch wirklich auf Download: Farbar Recovery Scan Tool drückst zum herunterladen und nicht auf den Werbebutton darunter. Schritt 1 Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ --> TR/Kazy. 19411. 5 |
03.03.2014, 13:53 | #7 |
| TR/Kazy. 19411. 5FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-03-2014 Ran by samuel (administrator) on SAMUEL-PC on 03-03-2014 13:46:44 Running from C:\Users\samuel\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forums ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Nico Mak Computing) C:\Program Files\WinZip Malware Protector\WinZipMalwareProtector.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe () C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe (Hewlett-Packard Company) c:\Program Files\Common Files\LightScribe\LSSrvc.exe (Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe () C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\system32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation) HKLM\...\Run: [KBD] - C:\HP\KBD\KbdStub.EXE HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4390912 2007-03-01] (Realtek Semiconductor) HKLM\...\Run: [] - [X] HKLM\...\Run: [NvSvc] - C:\Windows\system32\nvsvc.dll [86016 2007-08-28] (NVIDIA Corporation) HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [8473120 2007-08-28] (NVIDIA Corporation) HKLM\...\Run: [NvMediaCenter] - RUNDLL32.XXX C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-10-15] (Adobe Systems Incorporated) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [413696 2008-09-06] (Apple Inc.) HKLM\...\Run: [PinnacleDriverCheck] - C:\Windows\system32\PSDrvCheck.xxx HKLM\...\Run: [LogitechQuickCamRibbon] - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2793304 2009-10-14] () HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [TkBellExe] - c:\program files\real\realplayer\Update\realsched.exe [295512 2013-11-20] (RealNetworks, Inc.) HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1758160 2014-02-25] (APN) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3685655614-3132395603-930321327-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.xxx HKU\S-1-5-21-3685655614-3132395603-930321327-1000\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18705664 2013-01-08] (Skype Technologies S.A.) HKU\S-1-5-21-3685655614-3132395603-930321327-1000\...\MountPoints2: {78dc8226-ede5-11e1-b548-001bfcd11114} - F:\LaunchU3.exe -a HKU\S-1-5-21-3685655614-3132395603-930321327-1000\...\InprocServer32: [Default-pngfilt] <==== ATTENTION! ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Schweiz : Hotmail, Outlook, Skype download, Unterhaltung, Nachrichten, Sport, Lifestyle, Auto und mehr bei MSN CH HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Schweiz : Hotmail, Outlook, Skype download, Unterhaltung, Nachrichten, Sport, Lifestyle, Auto und mehr bei MSN CH HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Schweiz : Hotmail, Outlook, Skype download, Unterhaltung, Nachrichten, Sport, Lifestyle, Auto und mehr bei MSN CH SearchScopes: HKLM - {2A4E0066-3A41-450D-8AE4-213BEFC1C54C} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06 SearchScopes: HKLM - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.ch/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_de SearchScopes: HKCU - {080FBDF6-B230-4e4d-A4E7-7C7A56D7BABC} URL = hxxp://searchservice.myspace.com/index.cfm?fuseaction=sitesearch.results&qry={searchTerms}&type=Web&orig=IMC-IE SearchScopes: HKCU - {2A4E0066-3A41-450D-8AE4-213BEFC1C54C} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.ch/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_de SearchScopes: HKCU - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} hxxp://gfx2.hotmail.com/mail/w2/resources/VistaMSNPUpldde-ch.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {DCEA263C-75E9-4029-F6AA-37F011CC4EF1} hxxp://dialcom.com/spontania/download/SpontaniaVideoCollaboration.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUpldde-ch.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158 Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR DefaultSearchKeyword: ask search CHR DefaultSearchProvider: Ask Search CHR DefaultSearchURL: hxxp://www.search.ask.com/web?tpid=ORJ-V7C&o=APN11412&pf=V7&p2=%5EBBK%5EOSJ000%5EYY%5ECH&gct=&itbv=12.7.0.15&doi=2014-02-27&apn_uid=DB092DDD-F961-4A4C-9204-15C4DCAD8F15&apn_ptnrs=BBK&apn_dtid=%5EOSJ000%5EYY%5ECH&apn_dbr=cr_33.0.1750.117&psv=&trgb=CR&tbv=&crxv=&q={searchTerms} CHR DefaultNewTabURL: CHR Extension: (YouTube) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-01-11] CHR Extension: (Google-Suche) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-01-11] CHR Extension: (RealDownloader) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-11-20] CHR Extension: (Google Wallet) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-04] CHR Extension: (Google Mail) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-01-11] CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14] CHR HKLM\...\Chrome\Extension: [pljcgbedjplidkdjahbaalanadmjfgop] - C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-V7C\CRX\ToolbarCR.crx [2014-02-25] ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-20] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-25] (APN LLC.) S2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] () S3 stllssvr; "c:\Program Files\Common Files\SureThing Shared\stllssvr.exe" [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-19] (Avira Operations GmbH & Co. KG) R3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2Mon.sys [25752 2009-10-07] () R3 PID_PEPI; C:\Windows\System32\DRIVERS\LV302V32.SYS [2687512 2009-04-30] (Logitech Inc.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 Afc; system32\drivers\Afc.sys [X] S3 AVFSFilter; system32\DRIVERS\avfsfilter.sys [X] S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 ovt530; System32\Drivers\ov530vid.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-03 13:40 - 2014-03-03 13:46 - 00025426 _____ () C:\Users\samuel\Downloads\Addition.txt 2014-03-03 13:39 - 2014-03-03 13:46 - 00012340 _____ () C:\Users\samuel\Downloads\FRST.txt 2014-03-03 13:39 - 2014-03-03 13:46 - 00000000 ____D () C:\FRST 2014-03-03 13:36 - 2014-03-03 13:37 - 01145344 _____ (Farbar) C:\Users\samuel\Downloads\FRST.exe 2014-03-03 11:31 - 2014-03-03 11:31 - 00000533 _____ () C:\Users\samuel\Downloads\wzmp_8 (1) - Verknüpfung.lnk 2014-03-03 11:00 - 2014-03-03 11:00 - 00045000 _____ () C:\Users\samuel\Documents\log.xml 2014-03-03 10:00 - 2014-03-03 10:00 - 00000988 _____ () C:\Users\Public\Desktop\WinZip Malware Protector.lnk 2014-03-03 10:00 - 2014-03-03 10:00 - 00000000 ____D () C:\Users\samuel\AppData\Roaming\Nico Mak Computing 2014-03-03 10:00 - 2014-03-03 10:00 - 00000000 ____D () C:\ProgramData\Nico Mak Computing 2014-03-03 10:00 - 2014-03-03 10:00 - 00000000 ____D () C:\Program Files\WinZip Malware Protector 2014-03-03 10:00 - 2013-03-15 17:01 - 00016384 _____ () C:\Windows\system32\wsusnative32.exe 2014-03-03 09:43 - 2014-03-03 09:44 - 04892480 _____ (WinZip International LLC ) C:\Users\samuel\Downloads\wzmp_8 (1).exe 2014-02-27 09:21 - 2014-02-27 09:21 - 05249448 _____ (ParetoLogic Inc.) C:\Users\samuel\Downloads\ParetoLogic PC Health Advisor_de.exe 2014-02-27 09:10 - 2014-02-27 09:10 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-02-27 09:10 - 2014-02-27 09:10 - 00000000 ____D () C:\ProgramData\APN 2014-02-27 09:10 - 2014-02-27 09:10 - 00000000 ____D () C:\Program Files\AskPartnerNetwork 2014-02-27 09:08 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-02-27 09:07 - 2014-02-27 09:07 - 00005315 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-02-27 09:07 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-02-27 09:07 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-02-27 09:07 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-02-27 09:04 - 2014-02-27 09:04 - 00921000 _____ (Oracle Corporation) C:\Users\samuel\Downloads\chromeinstall-7u51 (1).exe 2014-02-27 09:01 - 2014-02-27 09:02 - 00921000 _____ (Oracle Corporation) C:\Users\samuel\Downloads\chromeinstall-7u51.exe 2014-02-12 07:10 - 2014-02-02 21:10 - 11111424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 06019584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 02005504 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-12 07:10 - 2014-02-02 21:10 - 01213440 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00916992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll 2014-02-12 07:10 - 2014-02-01 23:54 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-02-12 07:10 - 2014-02-01 23:47 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-12 07:10 - 2014-02-01 23:47 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-12 07:10 - 2014-02-01 23:46 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-12 07:10 - 2014-02-01 23:46 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-02-12 07:10 - 2013-12-22 16:42 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-12 07:10 - 2013-12-05 03:12 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-09 18:36 - 2014-02-09 18:36 - 00022389 _____ () C:\Users\samuel\Documents\brief maurizio.odt ==================== One Month Modified Files and Folders ======= 2014-03-03 13:46 - 2014-03-03 13:40 - 00025426 _____ () C:\Users\samuel\Downloads\Addition.txt 2014-03-03 13:46 - 2014-03-03 13:39 - 00012340 _____ () C:\Users\samuel\Downloads\FRST.txt 2014-03-03 13:46 - 2014-03-03 13:39 - 00000000 ____D () C:\FRST 2014-03-03 13:37 - 2014-03-03 13:36 - 01145344 _____ (Farbar) C:\Users\samuel\Downloads\FRST.exe 2014-03-03 13:36 - 2007-11-07 20:24 - 01057267 _____ () C:\Windows\WindowsUpdate.log 2014-03-03 13:35 - 2007-11-07 21:48 - 00000420 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{89158FFF-9FD1-4ACE-8298-DEE6F635CA31}.job 2014-03-03 13:31 - 2010-01-30 08:32 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-03 13:31 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-03 13:31 - 2006-11-02 13:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-03 13:31 - 2006-11-02 13:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-03 11:33 - 2006-11-02 14:01 - 00032628 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-03 11:31 - 2014-03-03 11:31 - 00000533 _____ () C:\Users\samuel\Downloads\wzmp_8 (1) - Verknüpfung.lnk 2014-03-03 11:18 - 2010-01-30 08:32 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-03 11:06 - 2013-01-11 16:11 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-03 11:00 - 2014-03-03 11:00 - 00045000 _____ () C:\Users\samuel\Documents\log.xml 2014-03-03 10:00 - 2014-03-03 10:00 - 00000988 _____ () C:\Users\Public\Desktop\WinZip Malware Protector.lnk 2014-03-03 10:00 - 2014-03-03 10:00 - 00000000 ____D () C:\Users\samuel\AppData\Roaming\Nico Mak Computing 2014-03-03 10:00 - 2014-03-03 10:00 - 00000000 ____D () C:\ProgramData\Nico Mak Computing 2014-03-03 10:00 - 2014-03-03 10:00 - 00000000 ____D () C:\Program Files\WinZip Malware Protector 2014-03-03 09:44 - 2014-03-03 09:43 - 04892480 _____ (WinZip International LLC ) C:\Users\samuel\Downloads\wzmp_8 (1).exe 2014-03-03 08:54 - 2007-12-24 14:16 - 00000000 ____D () C:\Users\samuel\AppData\Roaming\Skype 2014-03-01 07:35 - 2007-06-04 17:37 - 00268198 _____ () C:\Windows\PFRO.log 2014-03-01 07:34 - 2007-06-04 16:50 - 00000000 ____D () C:\Program Files\Hewlett-Packard 2014-03-01 07:22 - 2011-12-15 02:49 - 00071168 _____ () C:\Users\samuel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-02-27 09:21 - 2014-02-27 09:21 - 05249448 _____ (ParetoLogic Inc.) C:\Users\samuel\Downloads\ParetoLogic PC Health Advisor_de.exe 2014-02-27 09:10 - 2014-02-27 09:10 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-02-27 09:10 - 2014-02-27 09:10 - 00000000 ____D () C:\ProgramData\APN 2014-02-27 09:10 - 2014-02-27 09:10 - 00000000 ____D () C:\Program Files\AskPartnerNetwork 2014-02-27 09:08 - 2013-11-04 14:43 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-27 09:07 - 2014-02-27 09:07 - 00005315 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-02-27 09:07 - 2009-03-15 17:01 - 00000000 ____D () C:\Program Files\Java 2014-02-27 09:04 - 2014-02-27 09:04 - 00921000 _____ (Oracle Corporation) C:\Users\samuel\Downloads\chromeinstall-7u51 (1).exe 2014-02-27 09:02 - 2014-02-27 09:01 - 00921000 _____ (Oracle Corporation) C:\Users\samuel\Downloads\chromeinstall-7u51.exe 2014-02-20 22:50 - 2013-01-11 16:11 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-20 22:50 - 2011-05-30 13:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-12 07:31 - 2013-08-02 16:36 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-12 07:31 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-02-12 07:29 - 2006-11-02 11:24 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-02-09 18:36 - 2014-02-09 18:36 - 00022389 _____ () C:\Users\samuel\Documents\brief maurizio.odt 2014-02-02 21:10 - 2014-02-12 07:10 - 11111424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 06019584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 02005504 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-02 21:10 - 2014-02-12 07:10 - 01213440 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00916992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll 2014-02-01 23:54 - 2014-02-12 07:10 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-02-01 23:47 - 2014-02-12 07:10 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-01 23:47 - 2014-02-12 07:10 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-01 23:46 - 2014-02-12 07:10 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-01 23:46 - 2014-02-12 07:10 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe Files to move or delete: ==================== C:\ProgramData\ezsid.dat C:\Users\samuel\Firefox Setup 11.0.exe Some content of TEMP: ==================== C:\Users\samuel\AppData\Local\Temp\APNSetup.exe C:\Users\samuel\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-03 13:38 ==================== End Of Log ============================ |
03.03.2014, 22:29 | #8 |
Ruhe in Frieden † 2019 | TR/Kazy. 19411. 5 Hallo Heidi, danke schön. Bitte poste mir in deinem nächsten Post unbedingt die Addition.txt mit. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter (Nico Mak Computing) C:\Program Files\WinZip Malware Protector\WinZipMr.exe [1758160 201alwareProtector.exe HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1758160 2014-02-25] (APN) CHR DefaultSearchKeyword: ask search CHR DefaultSearchProvider: Ask Search CHR DefaultSearchURL: hxxp://www.search.ask.com/web?tpid=ORJ-V7C&o=APN11412&pf=V7&p2=%5EBBK%5EOSJ000%5EYY%5ECH&gct=&itbv=12.7.0.15&doi=2014-02-27&apn_uid=DB092DDD-F961-4A4C-9204-15C4DCAD8F15&apn_ptnrs=BBK&apn_dtid=%5EOSJ000%5EYY%5ECH&apn_dbr=cr_33.0.1750.117&psv=&trgb=CR&tbv=&crxv=&q={searchTerms} CHR DefaultNewTabURL: CHR HKLM\...\Chrome\Extension: [pljcgbedjplidkdjahbaalanadmjfgop] - C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-V7C\CRX\ToolbarCR.crx [2014-02-25] C:\Program Files\AskPartnerNetwork C:\Users\Public\Desktop\WinZip Malware Protectr\Updater\TBNotifier.exeor.lnk C:\Users\samuel\AppData\Roaming\Nico Mak Computing C:\ProgramData\Nico Mak Computing C:\Program Files\WinZip Malware Protector C:\Windows\system32\wsusnative32.exe C:\Users\samuel\Downloads\wzmp_8 (1).exe C:\Users\samuel\Downloads\ParetoLogic PC Health Advisor_de.exe C:\ProgramData\AskPartnerNetwork C:\ProgramData\APN C:\Users\samuel\Downloads\wzmp_8 (1) - Verknüpfung.lnk file: C:\Windows\System32\spool\drivers\w32x86\3\ZSHP1600.EXE Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3 Da der Scan mit Eset sehr gründlich ist, kann er unter Umständen mehrere Stunden dauern ESET Online Scanner
Schritt 4 Starte noch einmal FRST.
|
04.03.2014, 09:57 | #9 |
| TR/Kazy. 19411. 5 Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-03-2014 01 Ran by samuel (administrator) on SAMUEL-PC on 04-03-2014 08:27:22 Running from C:\Users\samuel\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forums ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe (Hewlett-Packard Company) c:\Program Files\Common Files\LightScribe\LSSrvc.exe (Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe (Nico Mak Computing) C:\Program Files\WinZip Malware Protector\WinZipMalwareProtector.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe () C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe () C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\samuel\Downloads\FRST (1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation) HKLM\...\Run: [KBD] - C:\HP\KBD\KbdStub.EXE HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4390912 2007-03-01] (Realtek Semiconductor) HKLM\...\Run: [] - [X] HKLM\...\Run: [NvSvc] - C:\Windows\system32\nvsvc.dll [86016 2007-08-28] (NVIDIA Corporation) HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [8473120 2007-08-28] (NVIDIA Corporation) HKLM\...\Run: [NvMediaCenter] - RUNDLL32.XXX C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-10-15] (Adobe Systems Incorporated) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [413696 2008-09-06] (Apple Inc.) HKLM\...\Run: [PinnacleDriverCheck] - C:\Windows\system32\PSDrvCheck.xxx HKLM\...\Run: [LogitechQuickCamRibbon] - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2793304 2009-10-14] () HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [TkBellExe] - c:\program files\real\realplayer\Update\realsched.exe [295512 2013-11-20] (RealNetworks, Inc.) HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1758160 2014-02-25] (APN) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3685655614-3132395603-930321327-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.xxx HKU\S-1-5-21-3685655614-3132395603-930321327-1000\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18705664 2013-01-08] (Skype Technologies S.A.) HKU\S-1-5-21-3685655614-3132395603-930321327-1000\...\MountPoints2: {78dc8226-ede5-11e1-b548-001bfcd11114} - F:\LaunchU3.exe -a HKU\S-1-5-21-3685655614-3132395603-930321327-1000\...\InprocServer32: [Default-pngfilt] <==== ATTENTION! ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Schweiz : Hotmail, Outlook, Skype download, Unterhaltung, Nachrichten, Sport, Lifestyle, Auto und mehr bei MSN CH HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Schweiz : Hotmail, Outlook, Skype download, Unterhaltung, Nachrichten, Sport, Lifestyle, Auto und mehr bei MSN CH HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Schweiz : Hotmail, Outlook, Skype download, Unterhaltung, Nachrichten, Sport, Lifestyle, Auto und mehr bei MSN CH SearchScopes: HKLM - {2A4E0066-3A41-450D-8AE4-213BEFC1C54C} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06 SearchScopes: HKLM - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.ch/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_de SearchScopes: HKCU - {080FBDF6-B230-4e4d-A4E7-7C7A56D7BABC} URL = hxxp://searchservice.myspace.com/index.cfm?fuseaction=sitesearch.results&qry={searchTerms}&type=Web&orig=IMC-IE SearchScopes: HKCU - {2A4E0066-3A41-450D-8AE4-213BEFC1C54C} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.ch/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_de SearchScopes: HKCU - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} hxxp://gfx2.hotmail.com/mail/w2/resources/VistaMSNPUpldde-ch.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {DCEA263C-75E9-4029-F6AA-37F011CC4EF1} hxxp://dialcom.com/spontania/download/SpontaniaVideoCollaboration.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUpldde-ch.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158 Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR DefaultSearchKeyword: ask search CHR DefaultSearchProvider: Ask Search CHR DefaultSearchURL: hxxp://www.search.ask.com/web?tpid=ORJ-V7C&o=APN11412&pf=V7&p2=%5EBBK%5EOSJ000%5EYY%5ECH&gct=&itbv=12.7.0.15&doi=2014-02-27&apn_uid=DB092DDD-F961-4A4C-9204-15C4DCAD8F15&apn_ptnrs=BBK&apn_dtid=%5EOSJ000%5EYY%5ECH&apn_dbr=cr_33.0.1750.117&psv=&trgb=CR&tbv=&crxv=&q={searchTerms} CHR DefaultNewTabURL: CHR Extension: (YouTube) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-01-11] CHR Extension: (Google-Suche) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-01-11] CHR Extension: (RealDownloader) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-11-20] CHR Extension: (Google Wallet) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-04] CHR Extension: (Google Mail) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-01-11] CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14] CHR HKLM\...\Chrome\Extension: [pljcgbedjplidkdjahbaalanadmjfgop] - C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-V7C\CRX\ToolbarCR.crx [2014-02-25] ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-20] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-25] (APN LLC.) R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] () S3 stllssvr; "c:\Program Files\Common Files\SureThing Shared\stllssvr.exe" [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-19] (Avira Operations GmbH & Co. KG) R3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2Mon.sys [25752 2009-10-07] () R3 PID_PEPI; C:\Windows\System32\DRIVERS\LV302V32.SYS [2687512 2009-04-30] (Logitech Inc.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 Afc; system32\drivers\Afc.sys [X] S3 AVFSFilter; system32\DRIVERS\avfsfilter.sys [X] S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 ovt530; System32\Drivers\ov530vid.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-04 08:13 - 2014-03-04 08:16 - 71199800 _____ (ZOHO Corporation) C:\Users\samuel\Downloads\ManageEngine_ServiceDesk_Plus.exe 2014-03-04 08:12 - 2014-03-04 08:12 - 01145344 _____ (Farbar) C:\Users\samuel\Downloads\FRST (1).exe 2014-03-04 08:05 - 2014-03-04 08:05 - 00001350 _____ () C:\Users\samuel\Documents\FRST.txt 2014-03-04 08:04 - 2014-03-04 08:04 - 00000000 ____D () C:\Users\samuel\Documents\Neuer Ordner 2014-03-03 15:39 - 2014-03-03 15:39 - 00976896 _____ () C:\Users\samuel\Downloads\MicrosoftFixit50052.msi 2014-03-03 15:39 - 2014-03-03 15:39 - 00976896 _____ () C:\Users\samuel\Downloads\MicrosoftFixit50052 (1).msi 2014-03-03 15:36 - 2014-03-03 15:36 - 00192456 _____ () C:\Windows\Minidump\Mini030314-01.dmp 2014-03-03 13:40 - 2014-03-03 13:47 - 00025426 _____ () C:\Users\samuel\Downloads\Addition.txt 2014-03-03 13:39 - 2014-03-04 08:27 - 00012473 _____ () C:\Users\samuel\Downloads\FRST.txt 2014-03-03 13:39 - 2014-03-04 08:27 - 00000000 ____D () C:\FRST 2014-03-03 13:36 - 2014-03-03 13:37 - 01145344 _____ (Farbar) C:\Users\samuel\Downloads\FRST.exe 2014-03-03 11:31 - 2014-03-03 11:31 - 00000533 _____ () C:\Users\samuel\Downloads\wzmp_8 (1) - Verknüpfung.lnk 2014-03-03 11:00 - 2014-03-03 11:00 - 00045000 _____ () C:\Users\samuel\Documents\log.xml 2014-03-03 10:00 - 2014-03-03 10:00 - 00000988 _____ () C:\Users\Public\Desktop\WinZip Malware Protector.lnk 2014-03-03 10:00 - 2014-03-03 10:00 - 00000000 ____D () C:\Users\samuel\AppData\Roaming\Nico Mak Computing 2014-03-03 10:00 - 2014-03-03 10:00 - 00000000 ____D () C:\ProgramData\Nico Mak Computing 2014-03-03 10:00 - 2014-03-03 10:00 - 00000000 ____D () C:\Program Files\WinZip Malware Protector 2014-03-03 10:00 - 2013-03-15 17:01 - 00016384 _____ () C:\Windows\system32\wsusnative32.exe 2014-03-03 09:43 - 2014-03-03 09:44 - 04892480 _____ (WinZip International LLC ) C:\Users\samuel\Downloads\wzmp_8 (1).exe 2014-02-27 09:21 - 2014-02-27 09:21 - 05249448 _____ (ParetoLogic Inc.) C:\Users\samuel\Downloads\ParetoLogic PC Health Advisor_de.exe 2014-02-27 09:10 - 2014-02-27 09:10 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-02-27 09:10 - 2014-02-27 09:10 - 00000000 ____D () C:\ProgramData\APN 2014-02-27 09:10 - 2014-02-27 09:10 - 00000000 ____D () C:\Program Files\AskPartnerNetwork 2014-02-27 09:08 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-02-27 09:07 - 2014-02-27 09:07 - 00005315 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-02-27 09:07 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-02-27 09:07 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-02-27 09:07 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-02-27 09:04 - 2014-02-27 09:04 - 00921000 _____ (Oracle Corporation) C:\Users\samuel\Downloads\chromeinstall-7u51 (1).exe 2014-02-27 09:01 - 2014-02-27 09:02 - 00921000 _____ (Oracle Corporation) C:\Users\samuel\Downloads\chromeinstall-7u51.exe 2014-02-12 07:10 - 2014-02-02 21:10 - 11111424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 06019584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 02005504 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-12 07:10 - 2014-02-02 21:10 - 01213440 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00916992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-12 07:10 - 2014-02-02 21:10 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll 2014-02-12 07:10 - 2014-02-01 23:54 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-02-12 07:10 - 2014-02-01 23:47 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-12 07:10 - 2014-02-01 23:47 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-12 07:10 - 2014-02-01 23:46 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-12 07:10 - 2014-02-01 23:46 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-02-12 07:10 - 2013-12-22 16:42 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-12 07:10 - 2013-12-05 03:12 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-09 18:36 - 2014-02-09 18:36 - 00022389 _____ () C:\Users\samuel\Documents\brief maurizio.odt ==================== One Month Modified Files and Folders ======= 2014-03-04 08:28 - 2014-03-03 13:39 - 00012473 _____ () C:\Users\samuel\Downloads\FRST.txt 2014-03-04 08:27 - 2014-03-03 13:39 - 00000000 ____D () C:\FRST 2014-03-04 08:25 - 2010-01-30 08:32 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-04 08:18 - 2010-01-30 08:32 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-04 08:16 - 2014-03-04 08:13 - 71199800 _____ (ZOHO Corporation) C:\Users\samuel\Downloads\ManageEngine_ServiceDesk_Plus.exe 2014-03-04 08:12 - 2014-03-04 08:12 - 01145344 _____ (Farbar) C:\Users\samuel\Downloads\FRST (1).exe 2014-03-04 08:06 - 2013-01-11 16:11 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-04 08:05 - 2014-03-04 08:05 - 00001350 _____ () C:\Users\samuel\Documents\FRST.txt 2014-03-04 08:04 - 2014-03-04 08:04 - 00000000 ____D () C:\Users\samuel\Documents\Neuer Ordner 2014-03-04 07:44 - 2007-11-07 20:24 - 01116069 _____ () C:\Windows\WindowsUpdate.log 2014-03-04 07:36 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-04 07:36 - 2006-11-02 13:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-04 07:36 - 2006-11-02 13:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-04 00:32 - 2006-11-02 14:01 - 00032628 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-03 15:39 - 2014-03-03 15:39 - 00976896 _____ () C:\Users\samuel\Downloads\MicrosoftFixit50052.msi 2014-03-03 15:39 - 2014-03-03 15:39 - 00976896 _____ () C:\Users\samuel\Downloads\MicrosoftFixit50052 (1).msi 2014-03-03 15:36 - 2014-03-03 15:36 - 00192456 _____ () C:\Windows\Minidump\Mini030314-01.dmp 2014-03-03 15:36 - 2007-12-24 19:20 - 258882687 _____ () C:\Windows\MEMORY.DMP 2014-03-03 15:36 - 2007-12-24 19:20 - 00000000 ____D () C:\Windows\Minidump 2014-03-03 13:47 - 2014-03-03 13:40 - 00025426 _____ () C:\Users\samuel\Downloads\Addition.txt 2014-03-03 13:37 - 2014-03-03 13:36 - 01145344 _____ (Farbar) C:\Users\samuel\Downloads\FRST.exe 2014-03-03 13:35 - 2007-11-07 21:48 - 00000420 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{89158FFF-9FD1-4ACE-8298-DEE6F635CA31}.job 2014-03-03 11:31 - 2014-03-03 11:31 - 00000533 _____ () C:\Users\samuel\Downloads\wzmp_8 (1) - Verknüpfung.lnk 2014-03-03 11:00 - 2014-03-03 11:00 - 00045000 _____ () C:\Users\samuel\Documents\log.xml 2014-03-03 10:00 - 2014-03-03 10:00 - 00000988 _____ () C:\Users\Public\Desktop\WinZip Malware Protector.lnk 2014-03-03 10:00 - 2014-03-03 10:00 - 00000000 ____D () C:\Users\samuel\AppData\Roaming\Nico Mak Computing 2014-03-03 10:00 - 2014-03-03 10:00 - 00000000 ____D () C:\ProgramData\Nico Mak Computing 2014-03-03 10:00 - 2014-03-03 10:00 - 00000000 ____D () C:\Program Files\WinZip Malware Protector 2014-03-03 09:44 - 2014-03-03 09:43 - 04892480 _____ (WinZip International LLC ) C:\Users\samuel\Downloads\wzmp_8 (1).exe 2014-03-03 08:54 - 2007-12-24 14:16 - 00000000 ____D () C:\Users\samuel\AppData\Roaming\Skype 2014-03-01 07:35 - 2007-06-04 17:37 - 00268198 _____ () C:\Windows\PFRO.log 2014-03-01 07:34 - 2007-06-04 16:50 - 00000000 ____D () C:\Program Files\Hewlett-Packard 2014-03-01 07:22 - 2011-12-15 02:49 - 00071168 _____ () C:\Users\samuel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-02-27 09:21 - 2014-02-27 09:21 - 05249448 _____ (ParetoLogic Inc.) C:\Users\samuel\Downloads\ParetoLogic PC Health Advisor_de.exe 2014-02-27 09:10 - 2014-02-27 09:10 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2014-02-27 09:10 - 2014-02-27 09:10 - 00000000 ____D () C:\ProgramData\APN 2014-02-27 09:10 - 2014-02-27 09:10 - 00000000 ____D () C:\Program Files\AskPartnerNetwork 2014-02-27 09:08 - 2013-11-04 14:43 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-27 09:07 - 2014-02-27 09:07 - 00005315 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-02-27 09:07 - 2009-03-15 17:01 - 00000000 ____D () C:\Program Files\Java 2014-02-27 09:04 - 2014-02-27 09:04 - 00921000 _____ (Oracle Corporation) C:\Users\samuel\Downloads\chromeinstall-7u51 (1).exe 2014-02-27 09:02 - 2014-02-27 09:01 - 00921000 _____ (Oracle Corporation) C:\Users\samuel\Downloads\chromeinstall-7u51.exe 2014-02-20 22:50 - 2013-01-11 16:11 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-20 22:50 - 2011-05-30 13:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-12 07:31 - 2013-08-02 16:36 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-12 07:31 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-02-12 07:29 - 2006-11-02 11:24 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-02-09 18:36 - 2014-02-09 18:36 - 00022389 _____ () C:\Users\samuel\Documents\brief maurizio.odt 2014-02-02 21:10 - 2014-02-12 07:10 - 11111424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 06019584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 02005504 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-02 21:10 - 2014-02-12 07:10 - 01213440 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00916992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-02 21:10 - 2014-02-12 07:10 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll Files to move or delete: ==================== C:\ProgramData\ezsid.dat C:\Users\samuel\Firefox Setup 11.0.exe Some content of TEMP: ==================== C:\Users\samuel\AppData\Local\Temp\APNSetup.exe C:\Users\samuel\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-04 07:47 Nico Mak Computing WinZip Malware Protector Datum der Überprüfung Dienstag, 4. März 2014 Datenbankversion 1699 Gefundene Elemente insgesamt 130 Überprüfte Objekte: 289808 Abgelaufene Zeit: 00:44:00 Name Gefundene Elemente Name der Infektion trojan.agent Kategorie Trojan Bedrohungsstufe High Durchgeführte Aktion NoActionTaken Elemente gefunden 2 Gefundener Bereich FileSystem Details Dateiname c:\users\samuel\downloads\frst (1).exe MD5 0 Signatur 8584407906768142050 Md5hash: 27bfad97f5483f4fb6194a9099c20f92 Gefundener Bereich FileSystem Details Dateiname c:\users\samuel\downloads\frst.exe MD5 0 Signatur 8584407906768142050 Md5hash: c1816a75bcb3adef974b98973bdeff01 Name der Infektion trojan-clicker.vbiframe Kategorie Clicker Trojan Bedrohungsstufe High Durchgeführte Aktion NoActionTaken Elemente gefunden 128 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f2c3-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f2c3-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f2c3-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f2c3-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f364-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f364-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f364-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f364-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51a-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51a-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51a-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51a-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51b-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51b-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51b-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51b-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51c-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51c-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51c-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51c-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51d-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51d-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51d-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f51d-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f523-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f523-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f523-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f523-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f524-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f524-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f524-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f524-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f53d-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f53d-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f53d-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f53d-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f541-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f541-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f541-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f541-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f542-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f542-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f542-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f542-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f544-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f544-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f544-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f544-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f545-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f545-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f545-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f545-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f546-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f546-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f546-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f546-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f548-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f548-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f548-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f548-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f54d-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f54d-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f54d-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f54d-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f561-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f561-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f561-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f561-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f563-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f563-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f563-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f563-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f57f-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f57f-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f57f-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f57f-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f583-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f583-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f583-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f583-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f587-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f587-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f587-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f587-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f589-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f589-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f589-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f589-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58b-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58b-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58b-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58b-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58c-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58c-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58c-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58c-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58d-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58d-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58d-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58d-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58f-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58f-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58f-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f58f-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61a-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61a-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61a-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61a-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61b-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61b-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61b-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61b-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61c-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61c-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61c-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61c-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61d-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61d-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61d-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f61d-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f623-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f623-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f623-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f623-98b5-11cf-bb82-00aa00bdce0b}\typelib Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f6bd-98b5-11cf-bb82-00aa00bdce0b} Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f6bd-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f6bd-98b5-11cf-bb82-00aa00bdce0b}\proxystubclsid32 Gefundener Bereich Registry Details Registrierungsschlüssel hkey_current_user software\classes\interface\{3050f6bd-98b5-11cf-bb82-00aa00bdce0b}\typelib © 2013 WinZip International LLC. All rights reserved. liebe sandra....ich bin völlig überfordert und denke es ist besser wir brechen ab....finde die sachen nicht die du von mir verlangst und alles kommt mir vor wie chinesisch vor....bin wohl wirklich zu sehr laie um all dies auszuführen....was meinst du? lg heidi |
10.03.2014, 10:26 | #11 |
Ruhe in Frieden † 2019 | TR/Kazy. 19411. 5 Hallo Heidi, ich habe schon länger keine Antwort mehr von Dir erhalten. Benötigst Du weiterhin noch Hilfe? Wenn ich in den nächsten 24 Stunden nichts von Dir höre, gehe ich davon aus, dass sich das Thema erledigt hat. Hinweis: Wir sind noch nicht fertig! Auch wenn die Symptome verschwunden sein sollten, kann dein System weiterhin infiziert sein und über Sicherheitslücken verfügen, welche eine erneute Infektion möglich machen. |
Themen zu TR/Kazy. 19411. 5 |
besonders, liebe, schön, umgang |