|
Log-Analyse und Auswertung: Avira wird durch Gruppenrichtlinien gesperrt.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
25.06.2014, 20:58 | #1 |
| Avira wird durch Gruppenrichtlinien gesperrt. Hallo, mein Onkel hat an seinem PC folgendes Problem: Zunächst ist bei jedem Start ein Fehler durch die regsvr32.exe aufgefallen und da hat er mich zu Rate gezogen. Da ist mir aufgefallen, dass sein Antivirenprogramm (Avira Free) nicht mehr funktioniert und durch Gruppenrichtlinien blockiert wird. Ich bitte euch daher mir etwas zu Hilfe zu sein bei der Bereinigung dieses, offensichtlich schon durch andere Threads bekannten, Virus. Mit freundlichen Grüßen, Laobiz |
25.06.2014, 21:05 | #2 |
Ruhe in Frieden † 2019 | Avira wird durch Gruppenrichtlinien gesperrt.Mein Name ist Sandra und ich werde Dir bei Deinem Problem behilflich sein.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist meist der schnellere und bei einem Befall durch Malware immer der sicherste Weg. Adware lässt sich in den allermeisten Fällen problemlos entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Dir jemand vom Team sagt, dass Du clean bist. Posten in Code Tags Bitte füge die Logs immer in Code-Tags ein. Wenn Du das nicht machst, erschwert es mir sehr das Auswerten. Danke. Dazu:
Schritt 1 Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
26.06.2014, 06:42 | #3 |
| Avira wird durch Gruppenrichtlinien gesperrt. FRST.txt:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:25-06-2014 Ran by Ernst-Werner Bluhm (administrator) on PC on 26-06-2014 07:37:28 Running from C:\Users\Ernst-Werner Bluhm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4HZMP0V0 Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Cisco Systems, Inc.) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Windows\System32\PnkBstrA.exe (Realtek) C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtlService.exe (Realtek Semiconductor Corp.) C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtWLan.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (ScanSoft, Inc.) C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe () C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe () C:\Program Files\NETGEAR\WG111v3\WG111v3.exe () C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-05-07] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.) HKLM\...\Run: [SSBkgdUpdate] => C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [185896 2006-09-28] (Nuance Communications, Inc.) HKLM\...\Run: [OpwareSE4] => C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [75304 2006-10-11] (ScanSoft, Inc.) HKLM\...\Run: [WrtMon.exe] => C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe [20480 2006-09-20] () HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM\...\Run: [TkBellExe] => c:\program files\real\realplayer\Update\realsched.exe [273528 2011-09-06] (RealNetworks, Inc.) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-06] (Apple Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-03] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.) HKLM Group Policy restriction on software: C:\Program Files\Common Files\Symantec Shared <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Symantec <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\Avira <====== ATTENTION HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-2443736403-4259669802-2429435372-1003\...\Run: [avoxqq] => regsvr32.exe " Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v3 Setup-Assistent.lnk ShortcutTarget: NETGEAR WG111v3 Setup-Assistent.lnk -> C:\Program Files\NETGEAR\WG111v3\WG111v3.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\VPN Client.lnk ShortcutTarget: VPN Client.lnk -> C:\Windows\Installer\{B0BF7057-6869-4E4B-920C-EA2A58DA07F0}\Icon3E5562ED7.ico () Startup: C:\Users\Julian D. Bluhm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Ernst-Werner Bluhm\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x80068EAAC572CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ SearchScopes: HKLM - DefaultScope {2896495D-3682-48B2-9738-9B3F41F1E321} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKLM - {2896495D-3682-48B2-9738-9B3F41F1E321} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - DefaultScope {2896495D-3682-48B2-9738-9B3F41F1E321} URL = BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.6.0_07\bin\jp2ssv.dll No File DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=hxxp://www.astonmartin.com/configurator/v8vantage_load.html DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} hxxp://dl.tvunetworks.com/TVUAx.cab DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} hxxp://static.pe.studivz.net/photouploader/ImageUploader5.cab?nocache=1225890629 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} hxxp://as.photoprintit.de/ips-opdata/layout/default_cms01/activex/IPSUploader4.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{4CB4B1CF-9BFA-4AE2-8D8C-D0ABC9278400}: [NameServer]184.106.242.193,67.23.7.56 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprjplug;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpchromebrowserrecordext;version=12.0.1.666 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprphtml5videoshim;version=12.0.1.666 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @unity3d.com/UnityPlayer - C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin: @viewpoint.com/VMP - C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll No File FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-21] Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Ernst-Werner Bluhm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-23] CHR Extension: (Google Drive) - C:\Users\Ernst-Werner Bluhm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-23] CHR Extension: (Google Wallet) - C:\Users\Ernst-Werner Bluhm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-07] ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1039440 2014-06-03] (Avira Operations GmbH & Co. KG) R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1528616 2010-03-23] (Cisco Systems, Inc.) R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75064 2010-05-03] () R2 Realtek11nSU; C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) [File not signed] S3 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [652800 2010-01-26] (Nokia) [File not signed] ==================== Drivers (Whitelisted) ==================== R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdLH3.sys [82960 2011-10-17] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [93528 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-29] (Avira Operations GmbH & Co. KG) S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.) R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [308859 2010-03-23] (Cisco Systems, Inc.) [File not signed] R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.) R3 MTSBDA; C:\Windows\System32\Drivers\MtsBda.sys [253968 2008-02-18] (TechniSat Provide) R3 MtsHID; C:\Windows\System32\drivers\MtsHID.sys [23568 2008-02-18] (TechniSat Provide) S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl.sys [18432 2011-08-02] (Apple Inc.) [File not signed] R3 RTL8187B; C:\Windows\System32\DRIVERS\wg111v3.sys [348160 2009-10-14] (NETGEAR Inc. ) R1 RtlProt; C:\Windows\System32\DRIVERS\rtlprot.sys [25896 2007-04-23] (Windows (R) Codename Longhorn DDK provider) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2009-11-11] () [File not signed] R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-29] (Avira GmbH) S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [44544 2012-09-28] (Apple, Inc.) [File not signed] S3 xnacc; C:\Windows\System32\DRIVERS\xnacc.sys [521216 2008-01-21] (Microsoft Corporation) U3 adg0v8yi; C:\Windows\system32\Drivers\adg0v8yi.sys [0 ] (Microsoft Corporation) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 lvpopflt; system32\DRIVERS\lvpopflt.sys [X] S3 LVRS; system32\DRIVERS\lvrs.sys [X] S3 LVUVC; system32\DRIVERS\lvuvc.sys [X] S3 nmwcdnsu; system32\drivers\nmwcdnsu.sys [X] S3 nmwcdnsuc; system32\drivers\nmwcdnsuc.sys [X] S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 taphss; system32\DRIVERS\taphss.sys [X] S3 taphss6; system32\DRIVERS\taphss6.sys [X] S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-26 07:37 - 2014-06-26 07:37 - 00000000 ____D () C:\FRST 2014-06-25 21:49 - 2014-06-25 21:49 - 00000881 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-06-25 21:41 - 2014-06-25 21:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Ernst-Werner Bluhm\Downloads\avira_de_av_4003445277__ws.exe 2014-06-25 19:07 - 2014-06-25 19:07 - 00001841 _____ () C:\Users\Ernst-Werner Bluhm\Desktop\Entfernen des Avira EU-Cleaners.lnk 2014-06-25 19:07 - 2014-06-25 19:07 - 00001785 _____ () C:\Users\Ernst-Werner Bluhm\Desktop\Avira EU-Cleaner.lnk 2014-06-25 19:02 - 2014-06-25 19:02 - 00000000 __SHD () C:\found.001 2014-06-10 21:54 - 2014-05-28 18:48 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-10 21:54 - 2014-05-28 18:39 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-10 21:54 - 2014-05-28 18:38 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-10 21:54 - 2014-05-28 18:33 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-10 21:54 - 2014-05-28 18:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-10 21:54 - 2014-05-28 18:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-10 21:54 - 2014-05-28 18:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-06-10 21:54 - 2014-05-28 18:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-10 21:54 - 2014-05-28 18:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-06-10 21:54 - 2014-05-28 18:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-10 21:54 - 2014-05-28 18:29 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-10 21:54 - 2014-05-28 18:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-10 21:54 - 2014-05-28 18:29 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-06-10 21:54 - 2014-05-28 18:29 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-06-10 21:54 - 2014-05-28 18:28 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-10 21:54 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-10 21:54 - 2014-04-05 04:42 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-10 21:54 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-10 21:54 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-05-30 17:48 - 2014-05-30 17:48 - 00001668 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\Program Files\iTunes 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\Program Files\iPod ==================== One Month Modified Files and Folders ======= 2014-06-26 07:37 - 2014-06-26 07:37 - 00000000 ____D () C:\FRST 2014-06-26 07:37 - 2008-09-30 10:39 - 01307198 _____ () C:\Windows\WindowsUpdate.log 2014-06-26 07:33 - 2011-08-21 17:38 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-26 07:33 - 2008-12-11 17:55 - 00065536 _____ () C:\Windows\system32\Ikeext.etl 2014-06-26 07:33 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-26 07:33 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-26 07:33 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-25 22:01 - 2006-11-02 15:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-06-25 21:49 - 2014-06-25 21:49 - 00000881 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-06-25 21:48 - 2013-12-29 02:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-06-25 21:48 - 2013-12-29 02:21 - 00000000 ____D () C:\ProgramData\Avira 2014-06-25 21:48 - 2013-12-29 02:21 - 00000000 ____D () C:\Program Files\Avira 2014-06-25 21:41 - 2014-06-25 21:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Ernst-Werner Bluhm\Downloads\avira_de_av_4003445277__ws.exe 2014-06-25 21:41 - 2011-08-21 17:38 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-25 21:19 - 2014-05-04 21:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-25 19:11 - 2008-01-21 09:16 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-25 19:07 - 2014-06-25 19:07 - 00001841 _____ () C:\Users\Ernst-Werner Bluhm\Desktop\Entfernen des Avira EU-Cleaners.lnk 2014-06-25 19:07 - 2014-06-25 19:07 - 00001785 _____ () C:\Users\Ernst-Werner Bluhm\Desktop\Avira EU-Cleaner.lnk 2014-06-25 19:07 - 2006-11-02 14:52 - 00164924 _____ () C:\Windows\setupact.log 2014-06-25 19:02 - 2014-06-25 19:02 - 00000000 __SHD () C:\found.001 2014-06-25 18:45 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\tracing 2014-06-22 14:22 - 2010-06-21 13:21 - 00000494 ____H () C:\Windows\Tasks\Norton Security Scan for Julian D. Bluhm.job 2014-06-11 22:29 - 2008-08-04 13:59 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-11 22:27 - 2014-05-05 22:04 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-11 22:25 - 2006-11-02 12:24 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-06-03 21:13 - 2013-12-29 02:21 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-06-03 21:13 - 2013-12-29 02:21 - 00093528 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-30 17:48 - 2014-05-30 17:48 - 00001668 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\Program Files\iTunes 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\Program Files\iPod 2014-05-30 17:48 - 2012-04-16 19:34 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-05-28 18:48 - 2014-06-10 21:54 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-28 18:39 - 2014-06-10 21:54 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-05-28 18:38 - 2014-06-10 21:54 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-05-28 18:33 - 2014-06-10 21:54 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-05-28 18:32 - 2014-06-10 21:54 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-05-28 18:32 - 2014-06-10 21:54 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-05-28 18:31 - 2014-06-10 21:54 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-05-28 18:31 - 2014-06-10 21:54 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-05-28 18:30 - 2014-06-10 21:54 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-05-28 18:30 - 2014-06-10 21:54 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-05-28 18:30 - 2014-06-10 21:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-05-28 18:30 - 2014-06-10 21:54 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-05-28 18:30 - 2014-06-10 21:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-05-28 18:30 - 2014-06-10 21:54 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-05-28 18:30 - 2014-06-10 21:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-05-28 18:29 - 2014-06-10 21:54 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-28 18:29 - 2014-06-10 21:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-05-28 18:29 - 2014-06-10 21:54 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-28 18:29 - 2014-06-10 21:54 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-05-28 18:29 - 2014-06-10 21:54 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-05-28 18:28 - 2014-06-10 21:54 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll Some content of TEMP: ==================== C:\Users\Ernst-Werner Bluhm\AppData\Local\Temp\AskSLib.dll C:\Users\Ernst-Werner Bluhm\AppData\Local\Temp\avgnt.exe C:\Users\Ernst-Werner Bluhm\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\Ernst-Werner Bluhm\AppData\Local\Temp\Offercast_AVIRAV7_.exe C:\Users\Gast\AppData\Local\Temp\SkypeSetup.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\13616E~1.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\6ACC2D~1.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\718631~1.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\AskSLib.dll C:\Users\Julian D. Bluhm\AppData\Local\Temp\askToolbarInstaller-1.9.0.0.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\bbxlinst.dll C:\Users\Julian D. Bluhm\AppData\Local\Temp\bcalinst.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\bfntinst.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\bkbdinst.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\brwsupd.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\bxlaupd.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\DelayInst.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\DivXSetup.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\dnt2inst.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\drm_dyndata_7400009.dll C:\Users\Julian D. Bluhm\AppData\Local\Temp\DWPUpgradeInstaller.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\FlashPlayerUpdate01.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\FlashPlayerUpdate02.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\FlashPlayerUpdate03.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\FlashPlayerUpdate04.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\FlashPlayerUpdate05.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\FlashPlayerUpdate06.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\FlashPlayerUpdate07.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\FlashPlayerUpdate08.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\fldfind.dll C:\Users\Julian D. Bluhm\AppData\Local\Temp\GDMBC3E.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\IcqUpdater.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\installservice.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\instmsi.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\instmsiw.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\lws_lws.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\NEventMessages.dll C:\Users\Julian D. Bluhm\AppData\Local\Temp\NOSEventMessages.dll C:\Users\Julian D. Bluhm\AppData\Local\Temp\ose00001.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\pfmsetup.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\SCC.dll C:\Users\Julian D. Bluhm\AppData\Local\Temp\SkypeSetup.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\tbftsetup.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\Uninstall.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\vpnclient_setup.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\_isB22E.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\_isF857.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-26 07:40 ==================== End Of Log ============================ Addition.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:25-06-2014 Ran by Ernst-Werner Bluhm at 2014-06-26 07:38:53 Running from C:\Users\Ernst-Werner Bluhm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4HZMP0V0 Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Out of date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Out of date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{90120000-001A-0000-0000-0000000FF1CE}_OUTLOOK_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Captivate 2 (HKLM\...\{4B8B4A35-7347-47F9-8293-E47A14E75F0E}) (Version: 2.0.0.0 - Adobe Systems, Inc.) Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader 9.3 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-A93000000001}) (Version: 9.3.0 - Adobe Systems Incorporated) Adobe Shockwave Player 11 (HKLM\...\Adobe Shockwave Player) (Version: 11 - Adobe Systems, Inc.) AMD APP SDK Runtime (Version: 10.0.831.4 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{A942958E-AF92-7901-861B-7F373A1B6ABA}) (Version: 3.0.855.0 - Advanced Micro Devices, Inc.) Apple Application Support (HKLM\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.4.672 - Avira) Axis & Allies (HKLM\...\{47836B39-2465-4F39-9D7E-52F70A1C3D72}) (Version: 1.00.000 - ) BCool Gadget (HKLM\...\{8B1881C3-A40C-4DF3-BFD2-CCD2FEDD7D83}) (Version: 1.0 - BCool Gadget) Beijing 2008 (HKLM\...\{2076B142-10FA-4536-B488-3FDCBB1013D3}) (Version: 1.00.0000 - SEGA) Bloomberg Excel Tools (HKLM\...\Bloomberg Excel Tools) (Version: - ) Bloomberg Keyboard v10.4 (HKLM\...\Bloomberg Keyboard v10.4) (Version: v10.4 - Bloomberg L.P.) Bloomberg PFM Upload Tool for Microsoft Excel (HKLM\...\Bloomberg PFM Upload Tool for Microsoft Excel) (Version: - ) Bloomberg SFD Data Dictionary (HKLM\...\Bloomberg SFD Data Dictionary) (Version: - ) Bloomberg, V.05.07.09 (HKLM\...\Bloomberg, V.05.07.09) (Version: - ) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Bus-Simulator 2008 Bonus-Pack 1 (inkl. Patch 1+2) (HKLM\...\Bus-Simulator 2008 Bonus-Pack 1 (inkl. Patch 1+2)_is1) (Version: - astragon Software GmbH) Bus-Simulator 2008 Bonus-Pack 3 (inkl. BP1+2, Patch 1-3) (HKLM\...\Bus-Simulator 2008 Bonus-Pack 3 (inkl. BP1+2, Patch 1-3)_is1) (Version: - astragon Software GmbH) Bus-Simulator 2008 Patch 1: Gelenkbusse (HKLM\...\Bus-Simulator 2008 Patch 1: Gelenkbusse_is1) (Version: - astragon Software GmbH) Call of Duty(R) - World at War(TM) 1.1 Patch (Version: - ) Hidden Canon MP Navigator 2.2 (HKLM\...\MP Navigator 2.2) (Version: - ) Canon MP830 (HKLM\...\{0D25F7CC-B99C-44ee-9945-B14532B2BB7B}) (Version: - ) Canon Utilities Easy-PhotoPrint (HKLM\...\Easy-PhotoPrint) (Version: - ) CD-LabelPrint (HKLM\...\MediaNavigation.CDLabelPrint) (Version: - ) Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{B0BF7057-6869-4E4B-920C-EA2A58DA07F0}) (Version: 5.0.6 - Cisco Systems, Inc.) Citavi (HKLM\...\{E12C6653-1FF0-4686-ADB8-589C13AE761F}) (Version: 3.1.15.0 - Swiss Academic Software) Citrix XenApp Web Plugin (HKLM\...\{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}) (Version: 11.0.0.5357 - Citrix Systems, Inc.) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Contenta Converter BASIC (HKLM\...\ContentaConverter-BASIC) (Version: - Contenta Software) DivX Setup (HKLM\...\DivX Setup) (Version: 2.6.0.34 - DivX, LLC) Duden Korrektor kompakt (HKLM\...\InstallShield_{B24A47B6-1DE9-45FF-9DE8-D0EF46022CC3}) (Version: 5.00.1502.00 - Duden) Duden Korrektor kompakt (Version: 5.00.1502.00 - Duden) Hidden DVBViewer TE2 (HKLM\...\DVBViewer TE2_is1) (Version: - CM&V) DVBViewer Technisat Edition (HKLM\...\DVBViewer_is1) (Version: - CM&V) ElsterFormular (HKLM\...\ElsterFormular 13.1.1.8479p) (Version: 13.1.1.8479p - Landesfinanzdirektion Thüringen) EPL Pro Evolution Soccer 2010 Demo by we6wa6 1.0 (HKLM\...\EPL Pro Evolution Soccer 2010 Demo by we6wa6 1.0) (Version: - ) FILEminimizer Suite (HKLM\...\FILEminimizer Suite_is1) (Version: - balesio AG) Free Audio CD Burner version 1.2 (HKLM\...\Free Audio CD Burner_is1) (Version: - DVDVideoSoft Limited.) Free YouTube to MP3 Converter version 3.10.17.221 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.10.17.221 - DVDVideoSoft Ltd.) Furnplan now! by hülsta 9.2 (HKLM\...\Furnplan now! by hülsta 9.2) (Version: - ) GMATPrep(TM) (HKLM\...\{BFE903DE-4845-4387-9C6C-98B21B8445A3}) (Version: 2.3.601.409 - Graduate Management Admission Council ®) Google Chrome (HKLM\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.) Google SketchUp 7 (HKLM\...\{597E70FF-7C46-4EED-8092-91B7C2E0529D}) (Version: 2.1.6860 - Google, Inc.) Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden iCloud (HKLM\...\{79BD66B2-4DAE-4C3B-B08E-DC72E507C163}) (Version: 2.1.3.25 - Apple Inc.) ICQ6.5 (HKLM\...\{60DE4033-9503-48D1-A483-7846BD217CA9}) (Version: 6.5 - ICQ) Intel(R) Network Connections 13.0.42.0 (HKLM\...\PROSetDX) (Version: 13.0.42.0 - Intel) Intel(R) Network Connections 13.0.42.0 (Version: 13.0.42.0 - Intel) Hidden Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) iTunes (HKLM\...\{0718A90E-93AA-49AF-A4FE-0165ACD91DF0}) (Version: 11.2.2.3 - Apple Inc.) Java 7 Update 55 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217055FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 7 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160070}) (Version: 1.6.0.70 - Sun Microsystems, Inc.) LetsTrade Komponenten (HKLM\...\LetsTrade) (Version: - ) MainConcept DTV Decoder Pro (HKLM\...\{DFB561FC-E7F8-4774-9CF6-343F19061BC9}) (Version: 1.1.15295.1 - MainConcept AG) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-001A-0000-0000-0000000FF1CE}_OUTLOOK_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook 2007 (HKLM\...\OUTLOOK) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Outlook 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint Viewer 2007 (German) (HKLM\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mozilla Firefox (3.6.20) (HKLM\...\Mozilla Firefox (3.6.20)) (Version: 3.6.20 (de) - Mozilla) Mozilla Thunderbird (2.0.0.24) (HKLM\...\Mozilla Thunderbird (2.0.0.24)) (Version: 2.0.0.24 (de) - Mozilla) MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) NBA 2K9 (HKLM\...\Steam App 7740) (Version: - Visual Concepts) Nero 8 Essentials (HKLM\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031}) (Version: 8.3.124 - Nero AG) neroxml (Version: 1.0.0 - Nero AG) Hidden NETGEAR WG111v3 wireless USB 2.0 adapter (HKLM\...\InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}) (Version: 1.01.10 - NETGEAR) NETGEAR WG111v3 wireless USB 2.0 adapter (Version: 1.01.10 - NETGEAR) Hidden NHL® 08 (HKLM\...\{A7AA93B6-6909-4073-B4EC-45CCDEFD4665}) (Version: 2.0.1.0 - Electronic Arts) Nokia Photos (HKLM\...\{0EABFEF6-6D10-4C12-8667-3029C481D355}) (Version: 1.6.434 - Nokia) Nokia Software Updater (HKLM\...\{D8DDC00B-2881-407D-AAC2-44AEE70AF0B7}) (Version: 02.04.006.41579 - Nokia Corporation) Nokia_Multimedia_Common_Components_2_5 (HKLM\...\{70B31335-50EE-4834-8431-27412CDE62BD}) (Version: 2.6.86 - Nokia) Norton Security Scan (HKLM\...\NSS) (Version: 2.7.3.34 - Symantec Corporation) Office-Bibliothek (HKLM\...\{5C81B189-5456-40C4-9313-7FE6FA6DD64C}) (Version: 5.00.3 - Bibliographisches Institut & F.A. Brockhaus AG) OpenOffice 4.1.0 (HKLM\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) PC Connectivity Solution (HKLM\...\{7397EDED-F38A-4654-B669-BF61065803D0}) (Version: 10.6.2.0 - Nokia) PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 0.9.6 - Frank Heindörfer, Philip Chinery) Presto! PageManager 7.15.14 (HKLM\...\{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}) (Version: 7.15.14G - NewSoft) PunkBuster Services (HKLM\...\PunkBusterSvc) (Version: 0.988 - Even Balance, Inc.) QuickTime 7 (HKLM\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM\...\RealPlayer 12.0) (Version: - RealNetworks) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5618 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver and Utility (HKLM\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0142 - REALTEK Semiconductor Corp.) RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden RTL Winter Sports 2009 (Demo) (HKLM\...\RTL Winter Sports 2009 (Demo)) (Version: - ) ScanSoft OmniPage SE 4.0 (HKLM\...\{C1E693A4-B1D5-4DCD-B68D-2087835B7184}) (Version: 15.00.0020 - Nuance Communications, Inc.) Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SopCast 3.2.9 (HKLM\...\SopCast) (Version: 3.2.9 - www.sopcast.com) Spelling Dictionaries Support For Adobe Reader 9 (HKLM\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated) SPSS 13.0 for Windows (HKLM\...\{DB8CEC42-30B1-4F49-BD06-9393EB81CCF7}) (Version: 13.0 - SPSS Inc.) Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve) Sweet Home 3D version 2.2 (HKLM\...\Sweet Home 3D_is1) (Version: - eTeks) TechniSat DVB-PC TV Star (HKLM\...\{CE9F9FBC-5253-46D2-9883-09E55003D794}) (Version: 1.0.0 - TechniSat) Ulead PhotoImpact 12 (HKLM\...\{11AFE21E-B193-430D-B57A-DFF7815BB962}) (Version: 12.0 - Ulead System) Uninstall 1.0.0.1 (HKLM\...\Uninstall_is1) (Version: - ) Unity Web Player (HKLM\...\UnityWebPlayer) (Version: 2.5.0f5_21627 - Unity Technologies ApS) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-001A-0000-0000-0000000FF1CE}_OUTLOOK_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{90120000-001A-0000-0000-0000000FF1CE}_OUTLOOK_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{90120000-001A-0000-0000-0000000FF1CE}_OUTLOOK_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{90120000-001A-0000-0000-0000000FF1CE}_OUTLOOK_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_OUTLOOK_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM\...\{90120000-001A-0000-0000-0000000FF1CE}_OUTLOOK_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2881065) 32-Bit Edition (HKLM\...\{90120000-001A-0000-0000-0000000FF1CE}_OUTLOOK_{B7EF38F7-1D58-4085-A9A4-0F6C69A5AA1E}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_OUTLOOK_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden Viewpoint Media Player (HKLM\...\ViewpointMediaPlayer) (Version: - ) Vision-Patch 2009 v2.0 (HKLM\...\Vision-Patch 2009_is1) (Version: - ) VLC media player 0.9.8a (HKLM\...\VLC media player) (Version: 0.9.8a - VideoLAN Team) Winamp (HKLM\...\Winamp) (Version: 5.541 - Nullsoft, Inc) Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) (HKLM\...\504244733D18C8F63FF584AEB290E3904E791693) (Version: 08/22/2008 7.0.0.0 - Nokia) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) WISO Mein Geld 2008 Professional (HKLM\...\{D8D22773-14BF-4178-A683-3DBA515C2A26}) (Version: 9.00.01.0023 - Buhl Data Service GmbH) ==================== Restore Points ========================= 25-05-2014 20:14:26 Geplanter Prüfpunkt 27-05-2014 20:07:44 Geplanter Prüfpunkt 29-05-2014 07:19:08 Geplanter Prüfpunkt 30-05-2014 05:57:06 Geplanter Prüfpunkt 07-06-2014 07:42:31 Geplanter Prüfpunkt 07-06-2014 22:00:02 Geplanter Prüfpunkt 08-06-2014 14:15:40 Geplanter Prüfpunkt 09-06-2014 12:32:21 Geplanter Prüfpunkt 11-06-2014 20:21:14 Windows Update 12-06-2014 20:09:54 Geplanter Prüfpunkt 14-06-2014 20:06:56 Geplanter Prüfpunkt 19-06-2014 08:43:42 Geplanter Prüfpunkt 21-06-2014 07:50:59 Geplanter Prüfpunkt 22-06-2014 09:36:09 Geplanter Prüfpunkt 25-06-2014 19:39:43 Avira EU-Cleaner - 25.06.2014 21:39 ==================== Hosts content: ========================== 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3715CFBF-57C1-4661-8147-F10028CFA607} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2443736403-4259669802-2429435372-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-08-11] (RealNetworks, Inc.) Task: {3B8DEA83-0CD5-4AEE-8830-862B8D54F9A8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-21] (Google Inc.) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {599B963A-0674-405D-911B-D92689283FE6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-21] (Google Inc.) Task: {59D45BB3-BA28-4E6E-A31B-45584D473A5C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {7BD2E701-E23E-40F1-8BED-4F9E56BDA7CD} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: {A00B1D02-FA2E-4574-BE2E-5EDE630F019F} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2443736403-4259669802-2429435372-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-08-11] (RealNetworks, Inc.) Task: {A04188E8-F4DC-4D66-B34B-2FBB9B309443} - System32\Tasks\{8B22775D-C293-4F46-93D1-3C6D4771C700} => C:\Program Files\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {ECF9808C-7129-43B8-B718-572F489E4F62} - System32\Tasks\Norton Security Scan for Julian D. Bluhm => C:\Program Files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-06-28] (Symantec Corporation) Task: {F6409025-6D23-4B09-81B4-3876C044D9D6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-13] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Norton Security Scan for Julian D. Bluhm.job => C:\Program Files\Norton Security Scan\Engine\2.7.3.34\Nss.exe ==================== Loaded Modules (whitelisted) ============= 2008-09-30 11:42 - 2001-10-28 17:42 - 00116224 _____ () C:\Windows\System32\pdfcmnnt.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2010-03-23 14:26 - 2010-03-23 14:26 - 00201512 _____ () C:\Windows\system32\vpnapi.dll 2009-11-11 13:52 - 2010-05-03 23:27 - 00075064 _____ () C:\Windows\system32\PnkBstrA.exe 2010-06-30 22:58 - 2009-12-09 21:20 - 00126976 _____ () C:\Program Files\Realtek\11n USB Wireless LAN Utility\EnumDevLib.dll 2011-09-08 18:51 - 2011-09-08 18:51 - 00037376 _____ () C:\Windows\system32\atitmpxx.dll 2008-09-30 13:04 - 2006-09-20 08:35 - 00020480 _____ () C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe 2011-07-29 01:08 - 2011-07-29 01:08 - 01259376 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe 2011-07-29 01:09 - 2011-07-29 01:09 - 00096112 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll 2009-11-06 14:41 - 2009-11-06 14:41 - 02080768 _____ () C:\Program Files\NETGEAR\WG111v3\WG111v3.exe 2009-03-04 09:52 - 2009-03-04 09:52 - 00372736 _____ () C:\Program Files\NETGEAR\WG111v3\WlanDll.dll 2008-12-29 17:13 - 2008-12-29 17:13 - 00204800 _____ () C:\Program Files\NETGEAR\WG111v3\KJLog.dll 2008-09-30 13:04 - 2006-09-19 16:05 - 00024576 _____ () C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Windows:70EECF74D560B183 ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^VPN Client.lnk => C:\Windows\pss\VPN Client.lnk.CommonStartup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: ICQ => "C:\Program Files\ICQ6.5\ICQ.exe" silent MSCONFIG\startupreg: IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 MSCONFIG\startupreg: NokiaMServer => C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup MSCONFIG\startupreg: NokiaMusic FastStart => "C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe" /command:faststart MSCONFIG\startupreg: NokiaOviSuite2 => C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized MSCONFIG\startupreg: Steam => "C:\Program Files\Steam\Steam.exe" -silent MSCONFIG\startupreg: TkBellExe => "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot MSCONFIG\startupreg: toolbar_eula_launcher => C:\Program Files\GoogleEULA\EULALauncher.exe MSCONFIG\startupreg: WinampAgent => "C:\Program Files\Winamp\winampa.exe" ==================== Faulty Device Manager Devices ============= Name: Microsoft-6zu4-Adapter #2 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Microsoft-6zu4-Adapter #16 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Microsoft-6zu4-Adapter #210 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Microsoft-6zu4-Adapter #24 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Microsoft-6zu4-Adapter #211 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Microsoft-6zu4-Adapter #61 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Microsoft-6zu4-Adapter #212 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Microsoft-6zu4-Adapter #83 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Microsoft-6zu4-Adapter #213 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Cisco Systems VPN Adapter Description: Cisco Systems VPN Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: CVirtA Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (06/25/2014 09:39:43 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {b87193cb-372f-4c8f-9f18-e3bffb2f9ee9} Error: (06/09/2014 09:14:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung chrome.exe, Version 35.0.1916.114, Zeitstempel 0x53726019, fehlerhaftes Modul ntdll.dll, Version 6.0.6002.18881, Zeitstempel 0x51da3e27, Ausnahmecode 0xc0000374, Fehleroffset 0x000b06fc, Prozess-ID 0x1400, Anwendungsstartzeit chrome.exe0. Error: (06/09/2014 03:02:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung chrome.exe, Version 35.0.1916.114, Zeitstempel 0x53726019, fehlerhaftes Modul ntdll.dll, Version 6.0.6002.18881, Zeitstempel 0x51da3e27, Ausnahmecode 0xc0000374, Fehleroffset 0x000b06fc, Prozess-ID 0xc70, Anwendungsstartzeit chrome.exe0. Error: (06/09/2014 02:56:30 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung chrome.exe, Version 35.0.1916.114, Zeitstempel 0x53726019, fehlerhaftes Modul ntdll.dll, Version 6.0.6002.18881, Zeitstempel 0x51da3e27, Ausnahmecode 0xc0000374, Fehleroffset 0x000b06fc, Prozess-ID 0x1548, Anwendungsstartzeit chrome.exe0. Error: (06/09/2014 02:55:18 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung chrome.exe, Version 35.0.1916.114, Zeitstempel 0x53726019, fehlerhaftes Modul chrome.dll, Version 35.0.1916.114, Zeitstempel 0x53725d18, Ausnahmecode 0xc0000005, Fehleroffset 0x00728bc8, Prozess-ID 0xff0, Anwendungsstartzeit chrome.exe0. Error: (05/25/2014 11:36:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung iexplore.exe, Version 9.0.8112.16545, Zeitstempel 0x531a4f73, fehlerhaftes Modul ntdll.dll, Version 6.0.6002.18881, Zeitstempel 0x51da3e27, Ausnahmecode 0xc0000374, Fehleroffset 0x000b06fc, Prozess-ID 0x1c98, Anwendungsstartzeit iexplore.exe0. Error: (05/20/2014 10:29:48 PM) (Source: Microsoft Office 12) (EventID: 2001) (User: ) Description: Rejected Safe Mode action : Microsoft Office Word. Error: (05/20/2014 10:28:58 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung WINWORD.EXE, Version 12.0.6695.5000, Zeitstempel 0x5329c5d9, fehlerhaftes Modul ntdll.dll, Version 6.0.6002.18881, Zeitstempel 0x51da3e27, Ausnahmecode 0xc0000005, Fehleroffset 0x0003dd6d, Prozess-ID 0x12f4, Anwendungsstartzeit WINWORD.EXE0. Error: (05/18/2014 08:18:57 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung af_proxy_cmd_rep.exe, Version 3.41.0.25000, Zeitstempel 0x53750bd9, fehlerhaftes Modul af_proxy.dll, Version 6.0.6002.18881, Zeitstempel 0x51da3e27, Ausnahmecode 0xc0000135, Fehleroffset 0x00009f5d, Prozess-ID 0x171c, Anwendungsstartzeit af_proxy_cmd_rep.exe0. Error: (05/18/2014 08:17:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung hsscp.exe, Version 3.41.0.25000, Zeitstempel 0x53750c5d, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset 0x0113da53, Prozess-ID 0x13d4, Anwendungsstartzeit hsscp.exe0. System errors: ============= Error: (06/25/2014 07:06:12 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: 30000Realtek11nSU Error: (06/22/2014 10:17:29 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: 30000Realtek11nSU Error: (06/19/2014 00:54:24 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: 30000Realtek11nSU Error: (06/11/2014 10:28:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Windows Search%%1053 Error: (06/11/2014 10:28:52 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Windows Search Error: (06/11/2014 10:28:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Windows Search%%1053 Error: (06/11/2014 10:28:08 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Windows Search Error: (06/11/2014 10:24:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Windows Search%%1053 Error: (06/11/2014 10:24:55 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Windows Search Error: (06/11/2014 10:24:55 PM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1053WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Microsoft Office Sessions: ========================= Error: (05/20/2014 10:28:57 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6695.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 32 seconds with 0 seconds of active time. This session ended with a crash. Error: (04/18/2013 03:19:26 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 4021 seconds with 1620 seconds of active time. This session ended with a crash. Error: (04/18/2013 02:10:04 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 1193 seconds with 540 seconds of active time. This session ended with a crash. Error: (03/28/2013 00:27:23 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 718 seconds with 600 seconds of active time. This session ended with a crash. Error: (03/28/2013 05:57:39 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2393 seconds with 2340 seconds of active time. This session ended with a crash. Error: (03/28/2013 05:15:38 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 8017 seconds with 7260 seconds of active time. This session ended with a crash. Error: (03/15/2013 00:09:00 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 3492 seconds with 3180 seconds of active time. This session ended with a crash. Error: (12/31/2012 06:44:12 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2494 seconds with 2100 seconds of active time. This session ended with a crash. Error: (12/29/2012 00:27:23 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 22835 seconds with 6420 seconds of active time. This session ended with a crash. Error: (12/03/2012 09:52:55 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 37317 seconds with 1500 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2010-07-17 18:11:13.349 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\msiltcfg.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-07-15 22:27:42.314 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\msiltcfg.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-07-15 22:22:45.711 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\msiltcfg.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 3069.45 MB Available physical RAM: 1706.2 MB Total Pagefile: 6339.91 MB Available Pagefile: 4918.58 MB Total Virtual: 2047.88 MB Available Virtual: 1897.42 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:576.16 GB) (Free:323.82 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:20 GB) (Free:12.37 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 596 GB) (Disk ID: BF587EF3) Partition 1: (Active) - (Size=576 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
26.06.2014, 10:20 | #4 | |
Ruhe in Frieden † 2019 | Avira wird durch Gruppenrichtlinien gesperrt. Hallo Laobiz, Zitat:
Herrje, der Firefox muss dringend neu, das ist eine der ältesten Versionen, die ich hier bislang gesehen habe Updates machen wir dann im Anschluss der Bereinigung. Bitte auch alle Passwörter von einem sauberen PC aus ändern! Funktioniert Avira nach folgenden Schritten wieder? Schritt 1 Bitte deinstalliere folgende Programme: Java 7 Update 55 Java(TM) 6 Update 7 Dazu gehe auf Start --> Systemsteuerung -- > Programme --> Programme deinstallieren --> suche das Programm in der Liste --> entfernen Falls du ein Programm nicht deinstallieren kannst, lade dir von hier den Revo-uninstaller herunter und deinstalliere es damit, wähle dabei den moderaten Modus. Schritt 2 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM Group Policy restriction on software: C:\Program Files\Common Files\Symantec Shared <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Symantec <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\Avira <====== ATTENTION HKU\S-1-5-21-2443736403-4259669802-2429435372-1003\...\Run: [avoxqq] => regsvr32.exe " AlternateDataStreams: C:\Windows:70EECF74D560B183 C:\Users\Julian D. Bluhm\AppData\Local\Temp\*.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\*.dll Reboot: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 3 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 4 Starte noch einmal FRST.
|
26.06.2014, 17:11 | #5 |
| Avira wird durch Gruppenrichtlinien gesperrt. Dann habe ich hier die Logs für dich Fixlog.txt: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:25-06-2014 Ran by Ernst-Werner Bluhm at 2014-06-26 17:04:13 Run:1 Running from C:\Users\Ernst-Werner Bluhm\Desktop\FRST Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM Group Policy restriction on software: C:\Program Files\Common Files\Symantec Shared <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Symantec <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\Avira <====== ATTENTION HKU\S-1-5-21-2443736403-4259669802-2429435372-1003\...\Run: [avoxqq] => regsvr32.exe " AlternateDataStreams: C:\Windows:70EECF74D560B183 C:\Users\Julian D. Bluhm\AppData\Local\Temp\*.exe C:\Users\Julian D. Bluhm\AppData\Local\Temp\*.dll Reboot: ***************** HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKU\S-1-5-21-2443736403-4259669802-2429435372-1003\Software\Microsoft\Windows\CurrentVersion\Run\\avoxqq => value deleted successfully. C:\Windows => ":70EECF74D560B183" ADS removed successfully. C:\Users\Julian D. Bluhm\AppData\Local\Temp\*.exe => Moved successfully. C:\Users\Julian D. Bluhm\AppData\Local\Temp\*.dll => Moved successfully. The system needed a reboot. ==== End of Fixlog ==== Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Update, 26.06.2014 17:12:26, SYSTEM, PC, Manual, Rootkit Database, 2014.2.20.1, 2014.6.23.2, Update, 26.06.2014 17:12:50, SYSTEM, PC, Manual, Malware Database, 2014.3.4.9, 2014.6.26.5, (end) FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:25-06-2014 Ran by Ernst-Werner Bluhm (administrator) on PC on 26-06-2014 18:04:12 Running from C:\Users\Ernst-Werner Bluhm\Desktop\FRST Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Cisco Systems, Inc.) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Windows\System32\PnkBstrA.exe (Realtek) C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtlService.exe (Realtek Semiconductor Corp.) C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtWLan.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (ScanSoft, Inc.) C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe () C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe () C:\Program Files\NETGEAR\WG111v3\WG111v3.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe () C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-05-07] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.) HKLM\...\Run: [SSBkgdUpdate] => C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [185896 2006-09-28] (Nuance Communications, Inc.) HKLM\...\Run: [OpwareSE4] => C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [75304 2006-10-11] (ScanSoft, Inc.) HKLM\...\Run: [WrtMon.exe] => C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe [20480 2006-09-20] () HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM\...\Run: [TkBellExe] => c:\program files\real\realplayer\Update\realsched.exe [273528 2011-09-06] (RealNetworks, Inc.) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-06] (Apple Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-03] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.) HKLM\...\RunOnce: [ Malwarebytes Anti-Malware (cleanup)] - "C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \mbamdor.exe" "C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware " [54072 2014-05-12] (Malwarebytes Corporation) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [CLRHost] => C:\blp\API\Office Tools\bbxlcmd.exe [102400 2009-04-21] () HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [MobileDocuments] => C:\Program Files\Common Files\Apple\Internet Services\ubd.exe HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-10-31] (Apple Inc.) HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-10-31] (Apple Inc.) HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [SkyDrive] => C:\Users\Julian D. Bluhm\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [256600 2013-04-21] (Microsoft Corporation) HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\MountPoints2: {3c5dfd1e-6eb2-11de-8b4a-d62b1d331587} - I:\ HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\MountPoints2: {cc8854e5-cead-11de-93cc-8664663fff4e} - F:\setup\rsrc\Autorun.exe HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [CLRHost] => C:\blp\API\Office Tools\bbxlcmd.exe [102400 2009-04-21] () HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [MobileDocuments] => C:\Program Files\Common Files\Apple\Internet Services\ubd.exe HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-10-31] (Apple Inc.) HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-10-31] (Apple Inc.) HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SkyDrive] => C:\Users\Julian D. Bluhm\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [256600 2013-04-21] (Microsoft Corporation) HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {3c5dfd1e-6eb2-11de-8b4a-d62b1d331587} - I:\ HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {cc8854e5-cead-11de-93cc-8664663fff4e} - F:\setup\rsrc\Autorun.exe HKU\S-1-5-21-2443736403-4259669802-2429435372-501-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-2443736403-4259669802-2429435372-501-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [Logitech Vid] => "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode HKU\S-1-5-21-2443736403-4259669802-2429435372-501-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\MountPoints2: E - E:\cdstart.exe HKU\S-1-5-21-2443736403-4259669802-2429435372-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-2443736403-4259669802-2429435372-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Logitech Vid] => "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode HKU\S-1-5-21-2443736403-4259669802-2429435372-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: E - E:\cdstart.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v3 Setup-Assistent.lnk ShortcutTarget: NETGEAR WG111v3 Setup-Assistent.lnk -> C:\Program Files\NETGEAR\WG111v3\WG111v3.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\VPN Client.lnk ShortcutTarget: VPN Client.lnk -> C:\Windows\Installer\{B0BF7057-6869-4E4B-920C-EA2A58DA07F0}\Icon3E5562ED7.ico () Startup: C:\Users\Julian D. Bluhm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Ernst-Werner Bluhm\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x80068EAAC572CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ SearchScopes: HKLM - DefaultScope {2896495D-3682-48B2-9738-9B3F41F1E321} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKLM - {2896495D-3682-48B2-9738-9B3F41F1E321} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - DefaultScope {2896495D-3682-48B2-9738-9B3F41F1E321} URL = BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.6.0_07\bin\jp2ssv.dll No File DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=hxxp://www.astonmartin.com/configurator/v8vantage_load.html DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} hxxp://dl.tvunetworks.com/TVUAx.cab DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} hxxp://static.pe.studivz.net/photouploader/ImageUploader5.cab?nocache=1225890629 DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} hxxp://as.photoprintit.de/ips-opdata/layout/default_cms01/activex/IPSUploader4.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{4CB4B1CF-9BFA-4AE2-8D8C-D0ABC9278400}: [NameServer]184.106.242.193,67.23.7.56 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprjplug;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpchromebrowserrecordext;version=12.0.1.666 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprphtml5videoshim;version=12.0.1.666 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @unity3d.com/UnityPlayer - C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin: @viewpoint.com/VMP - C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll No File FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-21] Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Ernst-Werner Bluhm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-23] CHR Extension: (Google Drive) - C:\Users\Ernst-Werner Bluhm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-23] CHR Extension: (Google Wallet) - C:\Users\Ernst-Werner Bluhm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-07] ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1039440 2014-06-03] (Avira Operations GmbH & Co. KG) R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1528616 2010-03-23] (Cisco Systems, Inc.) R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75064 2010-05-03] () R2 Realtek11nSU; C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) [File not signed] S3 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [652800 2010-01-26] (Nokia) [File not signed] ==================== Drivers (Whitelisted) ==================== R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdLH3.sys [82960 2011-10-17] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [93528 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-29] (Avira Operations GmbH & Co. KG) S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.) R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [308859 2010-03-23] (Cisco Systems, Inc.) [File not signed] R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.) R3 MTSBDA; C:\Windows\System32\Drivers\MtsBda.sys [253968 2008-02-18] (TechniSat Provide) R3 MtsHID; C:\Windows\System32\drivers\MtsHID.sys [23568 2008-02-18] (TechniSat Provide) S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl.sys [18432 2011-08-02] (Apple Inc.) [File not signed] R3 RTL8187B; C:\Windows\System32\DRIVERS\wg111v3.sys [348160 2009-10-14] (NETGEAR Inc. ) R1 RtlProt; C:\Windows\System32\DRIVERS\rtlprot.sys [25896 2007-04-23] (Windows (R) Codename Longhorn DDK provider) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2009-11-11] () [File not signed] R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-29] (Avira GmbH) U0 ucsio; C:\Windows\System32\drivers\jenlu.sys [52440 2014-06-26] (Malwarebytes Corporation) S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [44544 2012-09-28] (Apple, Inc.) [File not signed] S3 xnacc; C:\Windows\System32\DRIVERS\xnacc.sys [521216 2008-01-21] (Microsoft Corporation) U3 ai9jin87; C:\Windows\system32\Drivers\ai9jin87.sys [0 ] (Microsoft Corporation) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 lvpopflt; system32\DRIVERS\lvpopflt.sys [X] S3 LVRS; system32\DRIVERS\lvrs.sys [X] S3 LVUVC; system32\DRIVERS\lvuvc.sys [X] S3 nmwcdnsu; system32\drivers\nmwcdnsu.sys [X] S3 nmwcdnsuc; system32\drivers\nmwcdnsuc.sys [X] S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 taphss; system32\DRIVERS\taphss.sys [X] S3 taphss6; system32\DRIVERS\taphss6.sys [X] S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-26 18:04 - 2014-06-26 18:04 - 00052440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\jenlu.sys 2014-06-26 17:12 - 2014-06-26 17:13 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-26 17:12 - 2014-06-26 17:12 - 00000903 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-26 17:12 - 2014-06-26 17:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-26 17:12 - 2014-06-26 17:12 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-26 17:12 - 2014-06-26 17:12 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-06-26 17:12 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-26 17:12 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-26 17:12 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-26 17:09 - 2014-06-26 17:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ernst-Werner Bluhm\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-26 17:03 - 2014-06-26 17:03 - 01073152 _____ (Farbar) C:\Users\Ernst-Werner Bluhm\Downloads\FRST.exe 2014-06-26 17:02 - 2014-06-26 18:04 - 00000000 ____D () C:\Users\Ernst-Werner Bluhm\Desktop\FRST 2014-06-26 07:37 - 2014-06-26 18:04 - 00000000 ____D () C:\FRST 2014-06-25 21:49 - 2014-06-25 21:49 - 00000881 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-06-25 21:41 - 2014-06-25 21:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Ernst-Werner Bluhm\Downloads\avira_de_av_4003445277__ws.exe 2014-06-25 19:07 - 2014-06-25 19:07 - 00001841 _____ () C:\Users\Ernst-Werner Bluhm\Desktop\Entfernen des Avira EU-Cleaners.lnk 2014-06-25 19:07 - 2014-06-25 19:07 - 00001785 _____ () C:\Users\Ernst-Werner Bluhm\Desktop\Avira EU-Cleaner.lnk 2014-06-25 19:02 - 2014-06-25 19:02 - 00000000 __SHD () C:\found.001 2014-06-10 21:54 - 2014-05-28 18:48 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-10 21:54 - 2014-05-28 18:39 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-10 21:54 - 2014-05-28 18:38 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-10 21:54 - 2014-05-28 18:33 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-10 21:54 - 2014-05-28 18:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-10 21:54 - 2014-05-28 18:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-10 21:54 - 2014-05-28 18:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-06-10 21:54 - 2014-05-28 18:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-10 21:54 - 2014-05-28 18:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-06-10 21:54 - 2014-05-28 18:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-10 21:54 - 2014-05-28 18:29 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-10 21:54 - 2014-05-28 18:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-10 21:54 - 2014-05-28 18:29 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-06-10 21:54 - 2014-05-28 18:29 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-06-10 21:54 - 2014-05-28 18:28 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-10 21:54 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-10 21:54 - 2014-04-05 04:42 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-10 21:54 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-10 21:54 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-05-30 17:48 - 2014-05-30 17:48 - 00001668 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\Program Files\iTunes 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\Program Files\iPod ==================== One Month Modified Files and Folders ======= 2014-06-26 18:04 - 2014-06-26 18:04 - 00052440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\jenlu.sys 2014-06-26 18:04 - 2014-06-26 17:02 - 00000000 ____D () C:\Users\Ernst-Werner Bluhm\Desktop\FRST 2014-06-26 18:04 - 2014-06-26 07:37 - 00000000 ____D () C:\FRST 2014-06-26 17:48 - 2011-08-21 17:38 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-26 17:48 - 2011-08-21 17:38 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-26 17:19 - 2014-05-04 21:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-26 17:13 - 2014-06-26 17:12 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-26 17:12 - 2014-06-26 17:12 - 00000903 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-26 17:12 - 2014-06-26 17:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-26 17:12 - 2014-06-26 17:12 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-26 17:12 - 2014-06-26 17:12 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-06-26 17:12 - 2008-01-21 09:16 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-26 17:10 - 2014-06-26 17:09 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ernst-Werner Bluhm\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-26 17:09 - 2008-09-30 10:39 - 01325116 _____ () C:\Windows\WindowsUpdate.log 2014-06-26 17:06 - 2008-12-11 17:55 - 00065536 _____ () C:\Windows\system32\Ikeext.etl 2014-06-26 17:06 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-26 17:06 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-26 17:06 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-26 17:04 - 2006-11-02 15:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-06-26 17:03 - 2014-06-26 17:03 - 01073152 _____ (Farbar) C:\Users\Ernst-Werner Bluhm\Downloads\FRST.exe 2014-06-25 21:49 - 2014-06-25 21:49 - 00000881 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-06-25 21:48 - 2013-12-29 02:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-06-25 21:48 - 2013-12-29 02:21 - 00000000 ____D () C:\ProgramData\Avira 2014-06-25 21:48 - 2013-12-29 02:21 - 00000000 ____D () C:\Program Files\Avira 2014-06-25 21:41 - 2014-06-25 21:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Ernst-Werner Bluhm\Downloads\avira_de_av_4003445277__ws.exe 2014-06-25 19:07 - 2014-06-25 19:07 - 00001841 _____ () C:\Users\Ernst-Werner Bluhm\Desktop\Entfernen des Avira EU-Cleaners.lnk 2014-06-25 19:07 - 2014-06-25 19:07 - 00001785 _____ () C:\Users\Ernst-Werner Bluhm\Desktop\Avira EU-Cleaner.lnk 2014-06-25 19:07 - 2006-11-02 14:52 - 00164924 _____ () C:\Windows\setupact.log 2014-06-25 19:02 - 2014-06-25 19:02 - 00000000 __SHD () C:\found.001 2014-06-25 18:45 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\tracing 2014-06-22 14:22 - 2010-06-21 13:21 - 00000494 ____H () C:\Windows\Tasks\Norton Security Scan for Julian D. Bluhm.job 2014-06-11 22:29 - 2008-08-04 13:59 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-11 22:27 - 2014-05-05 22:04 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-11 22:25 - 2006-11-02 12:24 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-06-03 21:13 - 2013-12-29 02:21 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-06-03 21:13 - 2013-12-29 02:21 - 00093528 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-30 17:48 - 2014-05-30 17:48 - 00001668 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\Program Files\iTunes 2014-05-30 17:48 - 2014-05-30 17:48 - 00000000 ____D () C:\Program Files\iPod 2014-05-30 17:48 - 2012-04-16 19:34 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-05-28 18:48 - 2014-06-10 21:54 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-28 18:39 - 2014-06-10 21:54 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-05-28 18:38 - 2014-06-10 21:54 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-05-28 18:33 - 2014-06-10 21:54 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-05-28 18:32 - 2014-06-10 21:54 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-05-28 18:32 - 2014-06-10 21:54 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-05-28 18:31 - 2014-06-10 21:54 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-05-28 18:31 - 2014-06-10 21:54 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-05-28 18:30 - 2014-06-10 21:54 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-05-28 18:30 - 2014-06-10 21:54 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-05-28 18:30 - 2014-06-10 21:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-05-28 18:30 - 2014-06-10 21:54 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-05-28 18:30 - 2014-06-10 21:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-05-28 18:30 - 2014-06-10 21:54 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-05-28 18:30 - 2014-06-10 21:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-05-28 18:29 - 2014-06-10 21:54 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-28 18:29 - 2014-06-10 21:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-05-28 18:29 - 2014-06-10 21:54 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-28 18:29 - 2014-06-10 21:54 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-05-28 18:29 - 2014-06-10 21:54 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-05-28 18:28 - 2014-06-10 21:54 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll Some content of TEMP: ==================== C:\Users\Ernst-Werner Bluhm\AppData\Local\Temp\AskSLib.dll C:\Users\Ernst-Werner Bluhm\AppData\Local\Temp\avgnt.exe C:\Users\Ernst-Werner Bluhm\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\Ernst-Werner Bluhm\AppData\Local\Temp\Offercast_AVIRAV7_.exe C:\Users\Gast\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-26 17:12 ==================== End Of Log ============================ --- --- --- PS: Avira lässt sich nun wieder starten Geändert von Laobiz (26.06.2014 um 18:00 Uhr) |
26.06.2014, 22:41 | #6 |
Ruhe in Frieden † 2019 | Avira wird durch Gruppenrichtlinien gesperrt. Hallo Laobiz, super! Schritt 1 Bitte poste mir noch das Suchlaufslog von Malwarebytes, dieses ist das Protectionslog.
__________________ --> Avira wird durch Gruppenrichtlinien gesperrt. |
27.06.2014, 10:05 | #7 |
| Avira wird durch Gruppenrichtlinien gesperrt. Entschuldige, dass habe ich wohl falsch gesehen bitte sehr: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 26.06.2014 Suchlauf-Zeit: 17:13:58 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.06.26.05 Rootkit Datenbank: v2014.06.23.02 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows Vista Service Pack 2 CPU: x86 Dateisystem: NTFS Benutzer: Ernst-Werner Bluhm Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 359220 Verstrichene Zeit: 20 Min, 5 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 1 PUP.Optional.Softonic.A, HKU\S-1-5-21-2443736403-4259669802-2429435372-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Löschen bei Neustart, [e7269be28deee25497f3edd1758d0ef2], Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 3 PUP.Optional.Conduit.A, C:\Users\Julian D. Bluhm\Downloads\HSS-2.06-install-anchorfree-244-ask4.exe, In Quarantäne, [cf3e1a637803023416af6fdc4eb3c53b], PUP.OfferBundler.ST, C:\Users\Julian D. Bluhm\Downloads\SoftonicDownloader_fuer_memorylifter.exe, In Quarantäne, [34d996e7d4a7ce68cef8c7c82dd3b54b], PUP.Optional.Softonic.A, C:\Users\Julian D. Bluhm\Downloads\SoftonicDownloader_fuer_contenta-converter.exe, In Quarantäne, [010cbfbebbc053e3f630879e1ae7b14f], Physische Sektoren: 0 (No malicious items detected) (end) |
27.06.2014, 20:42 | #8 | |
Ruhe in Frieden † 2019 | Avira wird durch Gruppenrichtlinien gesperrt. Hallo Laobiz, Zitat:
Ist das unblock-us? Machen wir noch einen abschließenden Kontrollscan mit Eset. Schritt 1 Da der Scan mit Eset sehr gründlich ist, kann er unter Umständen mehrere Stunden dauern ESET Online Scanner
Schritt 1 Starte noch einmal FRST.
|
28.06.2014, 16:53 | #9 |
| Avira wird durch Gruppenrichtlinien gesperrt. Der Scan läuft grade. Unblock-Us ist meines Wissens nach nicht installiert. Ich danke dir hier schonmal für deine Hilfe, Sandra. Ich bin jetzt erstmal eine Woche in Berlin und mein Onkel wird wahrscheinlich nichts weiter in der Hinsicht unternehmen. Ich folge den Schritten weiter sobald ich wieder zu Hause bin. Das dürfte dann in genau einer Woche sein. Grüße, Laobiz |
28.06.2014, 22:35 | #10 |
Ruhe in Frieden † 2019 | Avira wird durch Gruppenrichtlinien gesperrt. Ok, danke für das Bescheidgeben, melde dich dann einfach wieder hier. Wenn du es zeitlichhinbekommst dann aktualisiere bitte noch den Firefox, der ist wirklich sehr sehr alt. |
03.07.2014, 17:44 | #11 |
| Avira wird durch Gruppenrichtlinien gesperrt. Hi, ich bin wieder aus Berlin zurück und kann dir jetzt auch endlich die Logs schicken FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:01-07-2014 Ran by Ernst-Werner Bluhm (administrator) on PC on 03-07-2014 18:41:43 Running from C:\Users\Ernst-Werner Bluhm\Desktop\FRST Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Cisco Systems, Inc.) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Windows\System32\PnkBstrA.exe (Realtek) C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtlService.exe (Realtek Semiconductor Corp.) C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtWLan.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (ScanSoft, Inc.) C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe () C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe () C:\Program Files\NETGEAR\WG111v3\WG111v3.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe () C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-05-07] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.) HKLM\...\Run: [SSBkgdUpdate] => C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [185896 2006-09-28] (Nuance Communications, Inc.) HKLM\...\Run: [OpwareSE4] => C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [75304 2006-10-11] (ScanSoft, Inc.) HKLM\...\Run: [WrtMon.exe] => C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe [20480 2006-09-20] () HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM\...\Run: [TkBellExe] => c:\program files\real\realplayer\Update\realsched.exe [273528 2011-09-06] (RealNetworks, Inc.) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-06] (Apple Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-03] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v3 Setup-Assistent.lnk ShortcutTarget: NETGEAR WG111v3 Setup-Assistent.lnk -> C:\Program Files\NETGEAR\WG111v3\WG111v3.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\VPN Client.lnk ShortcutTarget: VPN Client.lnk -> C:\Windows\Installer\{B0BF7057-6869-4E4B-920C-EA2A58DA07F0}\Icon3E5562ED7.ico () Startup: C:\Users\Julian D. Bluhm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Ernst-Werner Bluhm\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x80068EAAC572CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ SearchScopes: HKLM - DefaultScope {2896495D-3682-48B2-9738-9B3F41F1E321} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKLM - {2896495D-3682-48B2-9738-9B3F41F1E321} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - DefaultScope {2896495D-3682-48B2-9738-9B3F41F1E321} URL = BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.6.0_07\bin\jp2ssv.dll No File DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=hxxp://www.astonmartin.com/configurator/v8vantage_load.html DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} hxxp://dl.tvunetworks.com/TVUAx.cab DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} hxxp://static.pe.studivz.net/photouploader/ImageUploader5.cab?nocache=1225890629 DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} hxxp://as.photoprintit.de/ips-opdata/layout/default_cms01/activex/IPSUploader4.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{4CB4B1CF-9BFA-4AE2-8D8C-D0ABC9278400}: [NameServer]184.106.242.193,67.23.7.56 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprjplug;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpchromebrowserrecordext;version=12.0.1.666 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprphtml5videoshim;version=12.0.1.666 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @unity3d.com/UnityPlayer - C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin: @viewpoint.com/VMP - C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll No File FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-21] Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Ernst-Werner Bluhm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-23] CHR Extension: (Google Drive) - C:\Users\Ernst-Werner Bluhm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-23] CHR Extension: (Google Wallet) - C:\Users\Ernst-Werner Bluhm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-07] ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1039440 2014-06-03] (Avira Operations GmbH & Co. KG) R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1528616 2010-03-23] (Cisco Systems, Inc.) R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75064 2010-05-03] () R2 Realtek11nSU; C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) [File not signed] S3 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [652800 2010-01-26] (Nokia) [File not signed] ==================== Drivers (Whitelisted) ==================== R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdLH3.sys [82960 2011-10-17] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [93528 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-29] (Avira Operations GmbH & Co. KG) S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.) R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [308859 2010-03-23] (Cisco Systems, Inc.) [File not signed] R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.) R3 MTSBDA; C:\Windows\System32\Drivers\MtsBda.sys [253968 2008-02-18] (TechniSat Provide) R3 MtsHID; C:\Windows\System32\drivers\MtsHID.sys [23568 2008-02-18] (TechniSat Provide) S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl.sys [18432 2011-08-02] (Apple Inc.) [File not signed] R3 RTL8187B; C:\Windows\System32\DRIVERS\wg111v3.sys [348160 2009-10-14] (NETGEAR Inc. ) R1 RtlProt; C:\Windows\System32\DRIVERS\rtlprot.sys [25896 2007-04-23] (Windows (R) Codename Longhorn DDK provider) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2009-11-11] () [File not signed] R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-29] (Avira GmbH) S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [44544 2012-09-28] (Apple, Inc.) [File not signed] S3 xnacc; C:\Windows\System32\DRIVERS\xnacc.sys [521216 2008-01-21] (Microsoft Corporation) U3 aybqxliz; C:\Windows\system32\Drivers\aybqxliz.sys [0 ] (Microsoft Corporation) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 lvpopflt; system32\DRIVERS\lvpopflt.sys [X] S3 LVRS; system32\DRIVERS\lvrs.sys [X] S3 LVUVC; system32\DRIVERS\lvuvc.sys [X] S3 nmwcdnsu; system32\drivers\nmwcdnsu.sys [X] S3 nmwcdnsuc; system32\drivers\nmwcdnsuc.sys [X] S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 taphss; system32\DRIVERS\taphss.sys [X] S3 taphss6; system32\DRIVERS\taphss6.sys [X] S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-28 16:02 - 2014-06-28 16:02 - 02347384 _____ (ESET) C:\Users\Ernst-Werner Bluhm\Downloads\esetsmartinstaller_deu.exe 2014-06-28 16:02 - 2014-06-28 16:02 - 00000000 ____D () C:\Program Files\ESET 2014-06-27 11:00 - 2014-06-28 15:57 - 00001808 _____ () C:\Windows\PFRO.log 2014-06-26 18:52 - 2014-06-26 18:52 - 00000808 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-06-26 18:52 - 2014-06-26 18:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-06-26 18:52 - 2014-06-26 18:52 - 00000000 ____D () C:\Program Files\CCleaner 2014-06-26 17:12 - 2014-06-27 11:03 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-26 17:12 - 2014-06-26 17:12 - 00000903 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-26 17:12 - 2014-06-26 17:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-26 17:12 - 2014-06-26 17:12 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-26 17:12 - 2014-06-26 17:12 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-06-26 17:12 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-26 17:12 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-26 17:12 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-26 17:09 - 2014-06-26 17:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ernst-Werner Bluhm\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-26 17:03 - 2014-06-26 17:03 - 01073152 _____ (Farbar) C:\Users\Ernst-Werner Bluhm\Downloads\FRST.exe 2014-06-26 17:02 - 2014-07-03 18:41 - 00000000 ____D () C:\Users\Ernst-Werner Bluhm\Desktop\FRST 2014-06-26 07:37 - 2014-07-03 18:41 - 00000000 ____D () C:\FRST 2014-06-25 21:49 - 2014-06-25 21:49 - 00000881 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-06-25 21:41 - 2014-06-25 21:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Ernst-Werner Bluhm\Downloads\avira_de_av_4003445277__ws.exe 2014-06-25 19:07 - 2014-06-25 19:07 - 00001841 _____ () C:\Users\Ernst-Werner Bluhm\Desktop\Entfernen des Avira EU-Cleaners.lnk 2014-06-25 19:07 - 2014-06-25 19:07 - 00001785 _____ () C:\Users\Ernst-Werner Bluhm\Desktop\Avira EU-Cleaner.lnk 2014-06-25 19:02 - 2014-06-25 19:02 - 00000000 __SHD () C:\found.001 2014-06-10 21:54 - 2014-05-28 18:48 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-10 21:54 - 2014-05-28 18:39 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-10 21:54 - 2014-05-28 18:38 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-10 21:54 - 2014-05-28 18:33 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-10 21:54 - 2014-05-28 18:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-10 21:54 - 2014-05-28 18:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-10 21:54 - 2014-05-28 18:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-06-10 21:54 - 2014-05-28 18:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-10 21:54 - 2014-05-28 18:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-10 21:54 - 2014-05-28 18:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-06-10 21:54 - 2014-05-28 18:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-10 21:54 - 2014-05-28 18:29 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-10 21:54 - 2014-05-28 18:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-10 21:54 - 2014-05-28 18:29 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-06-10 21:54 - 2014-05-28 18:29 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-06-10 21:54 - 2014-05-28 18:28 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-10 21:54 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-10 21:54 - 2014-04-05 04:42 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-10 21:54 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-10 21:54 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll ==================== One Month Modified Files and Folders ======= 2014-07-03 18:41 - 2014-06-26 17:02 - 00000000 ____D () C:\Users\Ernst-Werner Bluhm\Desktop\FRST 2014-07-03 18:41 - 2014-06-26 07:37 - 00000000 ____D () C:\FRST 2014-07-03 18:41 - 2008-09-30 10:39 - 01438795 _____ () C:\Windows\WindowsUpdate.log 2014-07-03 18:37 - 2011-08-21 17:38 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-03 18:37 - 2008-12-11 17:55 - 00065536 _____ () C:\Windows\system32\Ikeext.etl 2014-07-03 18:37 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-03 18:37 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-03 18:37 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-02 23:26 - 2006-11-02 15:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-02 23:19 - 2014-05-04 21:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-02 22:48 - 2011-08-21 17:38 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-02 22:43 - 2008-01-21 09:16 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-02 22:15 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\tracing 2014-06-29 14:22 - 2010-06-21 13:21 - 00000494 ____H () C:\Windows\Tasks\Norton Security Scan for Julian D. Bluhm.job 2014-06-28 16:02 - 2014-06-28 16:02 - 02347384 _____ (ESET) C:\Users\Ernst-Werner Bluhm\Downloads\esetsmartinstaller_deu.exe 2014-06-28 16:02 - 2014-06-28 16:02 - 00000000 ____D () C:\Program Files\ESET 2014-06-28 15:57 - 2014-06-27 11:00 - 00001808 _____ () C:\Windows\PFRO.log 2014-06-27 11:03 - 2014-06-26 17:12 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-26 19:34 - 2010-05-22 23:31 - 00000000 ____D () C:\Windows\Minidump 2014-06-26 19:34 - 2010-03-02 13:32 - 00000000 ____D () C:\Program Files\Steam 2014-06-26 19:34 - 2008-09-30 11:42 - 00000000 ____D () C:\Program Files\PDFCreator 2014-06-26 19:34 - 2008-08-04 11:38 - 00000000 ____D () C:\Windows\Panther 2014-06-26 18:52 - 2014-06-26 18:52 - 00000808 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-06-26 18:52 - 2014-06-26 18:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-06-26 18:52 - 2014-06-26 18:52 - 00000000 ____D () C:\Program Files\CCleaner 2014-06-26 17:12 - 2014-06-26 17:12 - 00000903 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-26 17:12 - 2014-06-26 17:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-26 17:12 - 2014-06-26 17:12 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-26 17:12 - 2014-06-26 17:12 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-06-26 17:10 - 2014-06-26 17:09 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ernst-Werner Bluhm\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-26 17:03 - 2014-06-26 17:03 - 01073152 _____ (Farbar) C:\Users\Ernst-Werner Bluhm\Downloads\FRST.exe 2014-06-25 21:49 - 2014-06-25 21:49 - 00000881 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-06-25 21:48 - 2013-12-29 02:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-06-25 21:48 - 2013-12-29 02:21 - 00000000 ____D () C:\ProgramData\Avira 2014-06-25 21:48 - 2013-12-29 02:21 - 00000000 ____D () C:\Program Files\Avira 2014-06-25 21:41 - 2014-06-25 21:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Ernst-Werner Bluhm\Downloads\avira_de_av_4003445277__ws.exe 2014-06-25 19:07 - 2014-06-25 19:07 - 00001841 _____ () C:\Users\Ernst-Werner Bluhm\Desktop\Entfernen des Avira EU-Cleaners.lnk 2014-06-25 19:07 - 2014-06-25 19:07 - 00001785 _____ () C:\Users\Ernst-Werner Bluhm\Desktop\Avira EU-Cleaner.lnk 2014-06-25 19:02 - 2014-06-25 19:02 - 00000000 __SHD () C:\found.001 2014-06-11 22:29 - 2008-08-04 13:59 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-11 22:27 - 2014-05-05 22:04 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-11 22:25 - 2006-11-02 12:24 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-06-03 21:13 - 2013-12-29 02:21 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-06-03 21:13 - 2013-12-29 02:21 - 00093528 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys Some content of TEMP: ==================== C:\Users\Ernst-Werner Bluhm\AppData\Local\Temp\avgnt.exe C:\Users\Gast\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-03 18:43 ==================== End Of Log ============================ log von ESET: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=b8ef2d2077f86f46853514c17f7603d8 # engine=18929 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-06-28 03:55:16 # local_time=2014-06-28 05:55:16 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 7077 148523094 0 0 # compatibility_mode_1='' # compatibility_mode=5892 16776574 100 100 15821200 241503644 0 0 # scanned=271746 # found=0 # cleaned=0 # scan_time=6508 |
03.07.2014, 22:22 | #12 |
Ruhe in Frieden † 2019 | Avira wird durch Gruppenrichtlinien gesperrt. Hallo Laobiz, Schritt 1 Bitte deinstalliere folgende Programme: BCool Gadget Dazu gehe auf Start --> Systemsteuerung -- > Programme --> Programme deinstallieren --> suche das Programm in der Liste --> entfernen Falls du ein Programm nicht deinstallieren kannst, lade dir von hier den Revo-uninstaller herunter und deinstalliere es damit, wähle dabei den moderaten Modus. OK So wie ich es sehe, haben wir damit alles Schadhafte entfernt. Deine Logs sind sauber. Abschließend räumen wir noch etwas auf, führen Updates durch und dann bekommst du noch etwas Lesestoff von mir. Falls dein Onkel seine Passwörter noch nicht geändert hat, sollte er das noch unbedingt machen! Wurde der Firefox aktualisiert?
Lade dir bitte von hier den aktuellen Firefox herunter. Schritt 1 Falls Du Malwarebytes-Antimalware und den ESET-Onlinescan nicht mehr benötigst, kannst Du beide Programme einfach über die Programmdeinstallation deinstallieren. Ich empfehle Dir aber zumindest Malwarebytes zu behalten, und damit einmal die Woche einen Kontrollscan zu machen. Schritt 2 Downloade dir bitte delfix auf deinen Desktop.
Updates / Programme aktualisieren
Stelle sicher, dass dein FlashPlayer nach Updates sucht. Den FlashPlayer kann man direkt bei der Installation so konfigurieren, dass er nach Updates automatisch sucht, nachträglich kann man das über folgenden Link machen: Adobe - Flash Player: Einstellungsmanager - Globale Benachrichtigungseinstellungen
Deinstalliere Deinen Reader und lade Dir die neueste Version von hier herunter. Schaue, ob sich noch etwas mit installieren möchte und entferne den Haken gegebenenfalls. Nun zum Schluss noch ein paar Tipps zur Absicherung deines Systems. Aktualität des Systems Es ist extrem wichtig, dass sowohl dein System als auch die darauf installierte sicherheitsrelevante Software (Flash Player, PDF-Reader und besonders Java, sofern vorhanden) aktuell sind.
Falls du Java doch unbedingt benötigst, dann
Dazu:
Hier findest du eine Anleitung dazu. Antivirensoftware
Zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der Internet Explorer, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Systemleistung Lösche regelmäßig deine temporären Dateien. Ich empfehle hierzu die Datenträgerbereinigung von Windows. Windows Vista
Windows 7
Windows 8
Halte dich fern von jeglichen Registry Cleanern. Diese schaden deinem System mehr als dass sie es schneller machen. Verhaltensregeln zum sichereren Surfen
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen. Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind. Falls Du Lob oder Kritik abgeben möchtest, kannst Du das sehr gerne hier tun. Wenn Du etwas für das Forum und unsere Arbeit spenden möchtest, so kannst Du das hier tun. |
04.07.2014, 12:55 | #13 |
| Avira wird durch Gruppenrichtlinien gesperrt. Hallo Sandra, ich habe alle deine Schritte befolgt und nun dürfte alles auf einem recht aktuellen Stand sein. Ich danke dir hier schonmal vielmals für deine Hilfe. Ich werde auch noch in der "Lob" Sektion einen Thread dazu eröffnen. Vielleicht hört man ja mal unter besseren Umständen voneinander Liebe Grüße, Laobiz |
04.07.2014, 21:54 | #14 |
Ruhe in Frieden † 2019 | Avira wird durch Gruppenrichtlinien gesperrt. Hallo Laobiz, vielen Dank für deine Rückmeldung. Schön, dass ich dir helfen konnte und danke für dein Lob. .... und .... man "sieht" sich bekanntlich immer zweimal im Leben |
Themen zu Avira wird durch Gruppenrichtlinien gesperrt. |
andere, antivirenprogramm, bekannte, bereinigung, blockiert, folgendes, funktionier, funktioniert, gesperrt, gruppenrichtlinie, gruppenrichtlinien, nicht mehr, programm, pup.offerbundler.st, pup.optional.conduit.a, pup.optional.softonic.a, threads, zunächst |