|
Log-Analyse und Auswertung: Ebay Mahnung Mail Anhang geöffnetWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
26.06.2014, 23:26 | #1 |
| Ebay Mahnung Mail Anhang geöffnet Hallo, meine Freundin hat an eine Mail mit einer angeblichen Mahnung von Ebay-Anwälten bekommen, hat aus Panik natürlich direkt den Anhang geöffnet und jetzt evtl nen Trojaner drauf? Ich habe bis jetzt wie in eurer Anleitung beschrieben defogger, frst und GMER drüberlaufen lassen. Die Logs dazu: FRST Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2014 Ran by Puschel (administrator) on KÖÖRRRT on 26-06-2014 23:13:36 Running from C:\Users\Puschel\Desktop Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\updrgui.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-20] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-25] (Synaptics Incorporated) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-09-18] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491632 2012-09-10] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKU\S-1-5-21-2799476594-3240853191-3070442433-1002\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe "C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.uk.msn.com/HPNOT13/4 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM-x32 - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323895&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPFC3980F7-DD7B-4E02-9782-CE5F08F4EC13&q={searchTerms}&SSPV= SearchScopes: HKCU - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll No File Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default FF NewTab: about:blank FF SelectedSearchEngine: Google FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF user.js: detected! => C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\user.js FF SearchPlugin: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\searchplugins\conduit-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: NoScript - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-19] FF Extension: Adblock Plus - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-19] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-09-18] (Advanced Micro Devices, Inc.) [File not signed] R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-06-17] (Avira Operations GmbH & Co. KG) R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed] S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36520 2012-09-14] (Advanced Micro Devices, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-28] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-22] (Avira Operations GmbH & Co. KG) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-10] (Disc Soft Ltd) R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-25] (Synaptics Incorporated) S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-25] (Synaptics Incorporated) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-26 23:13 - 2014-06-26 23:13 - 00011904 _____ () C:\Users\Puschel\Desktop\FRST.txt 2014-06-26 23:11 - 2014-06-26 23:13 - 00000000 ____D () C:\FRST 2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log 2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable 2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe 2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe 2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe 2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe 2014-06-26 22:00 - 2014-06-26 22:01 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps ==================== One Month Modified Files and Folders ======= 2014-06-26 23:13 - 2014-06-26 23:13 - 00011904 _____ () C:\Users\Puschel\Desktop\FRST.txt 2014-06-26 23:13 - 2014-06-26 23:11 - 00000000 ____D () C:\FRST 2014-06-26 23:11 - 2013-09-16 15:13 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2799476594-3240853191-3070442433-1002 2014-06-26 23:11 - 2012-10-20 07:07 - 00830120 _____ () C:\Windows\system32\perfh007.dat 2014-06-26 23:11 - 2012-10-20 07:07 - 00188224 _____ () C:\Windows\system32\perfc007.dat 2014-06-26 23:11 - 2012-07-26 09:28 - 01949368 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log 2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable 2014-06-26 23:10 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel 2014-06-26 23:07 - 2014-01-19 17:36 - 00000000 ____D () C:\Users\Puschel\AppData\Roaming\newnext.me 2014-06-26 23:06 - 2014-03-18 15:33 - 00437408 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-06-26 23:06 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-26 23:05 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-26 23:05 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-26 23:04 - 2013-09-16 15:06 - 01681996 _____ () C:\Windows\WindowsUpdate.log 2014-06-26 23:04 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-06-26 23:03 - 2014-04-10 19:04 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-26 23:02 - 2012-10-19 22:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-06-26 23:02 - 2012-08-04 00:37 - 00000000 ____D () C:\Program Files (x86)\MSBuild 2014-06-26 23:00 - 2012-07-26 09:52 - 00000000 ____D () C:\Windows\ShellNew 2014-06-26 23:00 - 2012-07-26 07:26 - 00000076 _____ () C:\Windows\win.ini 2014-06-26 22:58 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-06-26 22:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe 2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe 2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe 2014-06-26 22:37 - 2014-04-14 18:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe 2014-06-26 22:02 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-06-26 22:01 - 2014-06-26 22:00 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps 2014-06-26 22:00 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel\AppData\Local\VirtualStore 2014-06-17 20:03 - 2013-09-24 12:47 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-06-17 20:03 - 2013-09-24 12:47 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys Some content of TEMP: ==================== C:\Users\Puschel\AppData\Local\Temp\6_Offer_15.exe C:\Users\Puschel\AppData\Local\Temp\avgnt.exe C:\Users\Puschel\AppData\Local\Temp\BackupSetup.exe C:\Users\Puschel\AppData\Local\Temp\DownloadManager.exe C:\Users\Puschel\AppData\Local\Temp\nse6761.exe C:\Users\Puschel\AppData\Local\Temp\nse6BB5.exe C:\Users\Puschel\AppData\Local\Temp\nse8D89.exe C:\Users\Puschel\AppData\Local\Temp\nsq2AAE.exe C:\Users\Puschel\AppData\Local\Temp\nsu64B2.exe C:\Users\Puschel\AppData\Local\Temp\nsu6C52.exe C:\Users\Puschel\AppData\Local\Temp\nsu6E75.exe C:\Users\Puschel\AppData\Local\Temp\nsy69C0.exe C:\Users\Puschel\AppData\Local\Temp\nsy8B94.exe C:\Users\Puschel\AppData\Local\Temp\ose00000.exe C:\Users\Puschel\AppData\Local\Temp\SearchProtectINT.exe C:\Users\Puschel\AppData\Local\Temp\vcredist_x64.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-26 21:59 ==================== End Of Log ============================ GMER Beim Start von GMER kam direkt die Fehlermeldung "C:\Windows\System32\config\system Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird." Ich konnte danach aber ganz normal scannen. Nach dem Scan kam die gleiche Fehlermeldung für den Pfad C:\Users\Puschel\ntuser.dat Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-06-26 23:39:37 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002e TOSHIBA_MQ01ABD100 rev.AX001C 931,51GB Running: Gmer-19357.exe; Driver: C:\Users\Puschel\AppData\Local\Temp\kfroqpob.sys ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\csrss.exe [576:612] fffff9600092c5e8 Thread [1512:1528] 00000000773d50a7 Thread [1512:1536] 00000000749c8064 Thread [1512:1560] 00000000746bbfb4 Thread [1512:1576] 00000000746bbfb4 Thread [1512:1580] 00000000746bbfb4 Thread [1512:1584] 00000000746bbfb4 Thread [1512:1600] 00000000745f304c ---- Processes - GMER 2.1 ---- Library C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll (*** suspicious ***) @ C:\Windows\SysWOW64\rundll32.exe [2532] (NewNext Helper Engine/NewNextDotMe)(2014-01-19 15:36:14) 0000000072000000 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 27.06.2014 Scan Time: 00:07:28 Logfile: mbam.txt Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.06.26.09 Rootkit Database: v2014.06.23.02 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 8 CPU: x64 File System: NTFS User: Puschel Scan Type: Threat Scan Result: Completed Objects Scanned: 265594 Time Elapsed: 10 min, 30 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 7 PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, , [ce439edf7b0087afb1df182ef012659b], PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT, , [7a97b7c6a8d3e6503680f5dae220f60a], PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT2, , [b25f88f5691264d2a2155f70e81ae020], Registry Values: 3 PUP.Optional.NextLive.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|NextLive, C:\Windows\SysWOW64\rundll32.exe "C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l, , [62af077605763105851e9abf31d04cb4] PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT|Install, 1, , [7a97b7c6a8d3e6503680f5dae220f60a] PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT2|Install, 1, , [b25f88f5691264d2a2155f70e81ae020] Registry Data: 0 (No malicious items detected) Folders: 3 PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me, , [ec252a53e794ca6ca0f5bed6ff038c74], PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me\cache, , [ec252a53e794ca6ca0f5bed6ff038c74], PUP.Optional.BuzzIT.A, C:\Program Files (x86)\Buzz-it, , [3fd2bcc14437e056554da9fb4bb746ba], Files: 21 PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll, , [62af077605763105851e9abf31d04cb4], PUP.Optional.OutBrowse, C:\Users\Puschel\AppData\Local\Temp\DownloadManager.exe, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse6761.exe, , [20f1e39adc9f5fd7275215193fc247b9], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse6BB5.exe, , [f51c601da7d4191df188929cac55e917], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse8D89.exe, , [25ec7b02ff7cde58a7d26ec034cda45c], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsq2AAE.exe, , [d43d017c1d5e50e69bde1519fe039c64], PUP.Optional.SnapDo.A, C:\Users\Puschel\AppData\Local\Temp\Installer.msi, , [2de41469403bb2849eee0088a25f7789], PUP.Optional.Conduit.A, C:\Users\Puschel\AppData\Local\Temp\SearchProtectINT.exe, , [21f086f78bf0e94ddacd26fb877a857b], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu64B2.exe, , [32dfcfae1f5c96a0f881b27c986945bb], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu6C52.exe, , [36db2d50017a64d2ef8a4ee08879f907], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu6E75.exe, , [e52cfd8044371c1a9edb4fdfd62bd729], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsy69C0.exe, , [739e86f75625f244354463cb5da4cd33], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsy8B94.exe, , [838e196442390b2bd6a371bd9d649070], PUP.Optional.Outbrowse, C:\Users\Puschel\AppData\Local\Temp\l0ox0hvJ.exe.part, , [759ca3da1a612e08755211fe4bb9eb15], PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Local\genienext\nengine.dll, , [db36ed907efd40f62a79154436cb3ac6], PUP.Optional.Conduit.A, C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\searchplugins\conduit-search.xml, , [a46d75083b403105425714b1c73b26da], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\etxbsbelsd.pre, , [a9682f4eef8c360050eae8f11ce606fa], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\luahfxqpmy.pre, , [1df4aecf8eede94dd06a42970ef40df3], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\tyuhssockk.pre, , [c34e5429057691a5be7ce6f31de5c23e], PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.cookie, , [ec252a53e794ca6ca0f5bed6ff038c74], PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me\cache\spark.bin, , [ec252a53e794ca6ca0f5bed6ff038c74], Physical Sectors: 0 (No malicious items detected) (end) Grüße |
26.06.2014, 23:29 | #2 |
/// TB-Ausbilder /// Anleitungs-Guru | Ebay Mahnung Mail Anhang geöffnetMein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das...
Hinweis: Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden. Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert. Adware & Co. können wir sehr gut entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Du mein clean bekommst. Los geht's: Bitte auch die Addition.txt posten... Schritt 1 Bitte starte FRST erneut, markiere auch die checkbox und drücke auf Scan. Bitte poste mir den Inhalt der beiden Logs die erstellt werden.
__________________ |
27.06.2014, 09:08 | #3 |
| Ebay Mahnung Mail Anhang geöffnet Hier die Addition.txt
__________________Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-06-2014 Ran by Puschel at 2014-06-27 10:01:43 Running from C:\Users\Puschel\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.6.636 - Adobe Systems, Inc.) AMD Accelerated Video Transcoding (Version: 12.5.100.20918 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.938.2 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{3CEC10BE-CD7C-8E99-E3AC-DD31F4416C1C}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.) AMD Fuel (Version: 2012.0918.260.3365 - Ihr Firmenname) Hidden AMD VISION Engine Control Center (x32 Version: 2012.0918.260.3365 - Ihr Firmenname) Hidden AutomationML Editor (HKLM-x32\...\{1FF9E567-7A33-4278-87D3-2CB2E0E07DC9}) (Version: 3.0.0 - AutomationML) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.672 - Avira) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2.5712 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.2.5712 - CyberLink Corp.) Hidden CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.2.2114 - CyberLink Corp.) CyberLink Media Suite 10 (x32 Version: 10.0.2.2114 - CyberLink Corp.) Hidden CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.2.3317 - CyberLink Corp.) CyberLink PhotoDirector (x32 Version: 2.0.2.3317 - CyberLink Corp.) Hidden CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.2.2110 - CyberLink Corp.) CyberLink Power2Go 8 (x32 Version: 8.0.2.2110 - CyberLink Corp.) Hidden CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.2.2126 - CyberLink Corp.) CyberLink PowerDirector 10 (x32 Version: 10.0.2.2126 - CyberLink Corp.) Hidden CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.7.4528 - CyberLink Corp.) CyberLink PowerDVD (x32 Version: 10.0.7.4528 - CyberLink Corp.) Hidden CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.5.5811 - CyberLink Corp.) CyberLink YouCam (x32 Version: 3.5.5.5811 - CyberLink Corp.) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company) Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP 3D DriveGuard (HKLM\...\{2DEDBE5B-D538-43F3-83A7-B037D6B51A89}) (Version: 4.2.8.1 - Hewlett-Packard Company) HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden HP Postscript Converter (Version: 3.1.3591 - Hewlett-Packard) Hidden HP Recovery Manager (x32 Version: 8.00 - Hewlett-Packard) Hidden HP Wireless Button Driver (HKLM-x32\...\{941DE69D-6CEE-4171-8F1F-3D7E352AA498}) (Version: 1.0.6.1 - Hewlett-Packard Company) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Language Pack 2007 - German/Deutsch (HKLM-x32\...\OMUI.de-de) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office O MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office SharePoint Designer MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office X MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.12 - Synaptics Incorporated) VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN) ==================== Restore Points ========================= 04-05-2014 14:04:18 Geplanter Prüfpunkt 26-06-2014 20:51:10 Microsoft Office wird entfernt ==================== Hosts content: ========================== 2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {2A12643D-F816-4B74-9A8C-BFDEBD2F94C3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Task: {665ABA0F-C344-4F9D-84DF-A4B54EE8BFAA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-09-05] (Hewlett-Packard Company) Task: {6A135F4B-F40B-450A-B411-6107AE3BE08F} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-10-12] (CyberLink) Task: {75FDDF18-9E8C-4DAA-A853-5DDA76EBAAE7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-18] (Adobe Systems Incorporated) Task: {77D9D4FF-08A3-4CBB-A530-D72BA2C5AC46} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Opt-in For HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe Task: {895E8F71-0D37-41A9-BC80-F6880C747D2C} - System32\Tasks\HPGenoobeReminder => C:\Program Files (x86)\Hewlett-Packard\HP Registration Service\HP GenOOBE\HPGenOOBE.exe Task: {8C8824B8-BBAE-4997-A40C-5DBB12B8122A} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-08] (CyberLink) Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {AF8D4BBF-73F2-46FC-A798-06875FBCD3ED} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-01-31] (Microsoft Corporation) Task: {B81FF858-55E7-4D9F-A91D-751724FD10BB} - System32\Tasks\Microsoft\Windows\Setup\Windows Upgrade Notification Task => C:\Windows\system32\NotificationUI.exe [2014-01-31] (Microsoft Corporation) Task: {C515F61B-3573-490A-B552-98081D50927C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2012-09-18 04:12 - 2012-09-18 04:12 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2012-09-18 04:11 - 2012-09-18 04:11 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2012-09-18 03:58 - 2012-09-18 03:58 - 00369664 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2013-09-24 12:40 - 2014-06-11 14:33 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-03-27 04:46 - 2012-06-08 05:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2012-06-08 12:34 - 2012-06-08 12:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/27/2014 00:21:47 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm mbam.exe, Version 1.0.0.532 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: e78 Startzeit: 01cf9187bafb614c Endzeit: 0 Anwendungspfad: C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe Berichts-ID: 3faa6cf6-fd80-11e3-be8b-7446a0822eb5 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/26/2014 10:01:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.2.9200.16420, Zeitstempel: 0x505a96c3 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x77045f8c ID des fehlerhaften Prozesses: 0xed0 Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0 Pfad der fehlerhaften Anwendung: svchost.exe1 Pfad des fehlerhaften Moduls: svchost.exe2 Berichtskennung: svchost.exe3 Vollständiger Name des fehlerhaften Pakets: svchost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe5 Error: (06/26/2014 10:01:11 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.2.9200.16420, Zeitstempel: 0x505a96c3 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x77045f8c ID des fehlerhaften Prozesses: 0x898 Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0 Pfad der fehlerhaften Anwendung: svchost.exe1 Pfad des fehlerhaften Moduls: svchost.exe2 Berichtskennung: svchost.exe3 Vollständiger Name des fehlerhaften Pakets: svchost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe5 Error: (06/26/2014 10:00:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.2.9200.16420, Zeitstempel: 0x505a96c3 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x77045f8c ID des fehlerhaften Prozesses: 0xbe8 Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0 Pfad der fehlerhaften Anwendung: svchost.exe1 Pfad des fehlerhaften Moduls: svchost.exe2 Berichtskennung: svchost.exe3 Vollständiger Name des fehlerhaften Pakets: svchost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe5 Error: (05/15/2014 08:40:17 AM) (Source: MsiInstaller) (EventID: 1024) (User: Köörrrt) Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011007}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (03/16/2014 07:21:21 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: b28 Startzeit: 01cf2ff0d0a57d80 Endzeit: 4294967295 Anwendungspfad: C:\Windows\syswow64\wwahost.exe Berichts-ID: 4bc14c45-ad2f-11e3-be81-7446a0822eb5 Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App Error: (03/16/2014 06:26:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Köörrrt) Description: Das Paket „Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c“ wurde beendet, da das Anhalten zu lange dauerte. Error: (02/03/2014 04:33:16 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 440 Startzeit: 01cf20037ea29089 Endzeit: 4294967295 Anwendungspfad: C:\Windows\syswow64\wwahost.exe Berichts-ID: bd83e931-8cdf-11e3-be80-7446a0822eb5 Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App Error: (02/03/2014 04:30:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Köörrrt) Description: Das Paket „Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c“ wurde beendet, da das Anhalten zu lange dauerte. Error: (02/01/2014 08:40:24 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 58c Startzeit: 01cf1f638ae820c7 Endzeit: 4294967295 Anwendungspfad: C:\Windows\syswow64\wwahost.exe Berichts-ID: 4e339a66-8b70-11e3-be80-7446a0822eb5 Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App System errors: ============= Error: (06/27/2014 09:53:01 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 27.06.2014 um 00:27:12 unerwartet heruntergefahren. Error: (06/26/2014 11:33:20 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Audio Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/26/2014 11:28:22 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 26.06.2014 um 23:15:30 unerwartet heruntergefahren. Error: (06/17/2014 08:22:12 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (05/14/2014 10:16:26 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 13.05.2014 um 17:21:33 unerwartet heruntergefahren. Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (05/01/2014 09:16:42 AM) (Source: cdrom) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Microsoft Office Sessions: ========================= Error: (06/27/2014 00:21:47 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: mbam.exe1.0.0.532e7801cf9187bafb614c0C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe3faa6cf6-fd80-11e3-be8b-7446a0822eb5 Error: (06/26/2014 10:01:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: svchost.exe6.2.9200.16420505a96c3unknown0.0.0.000000000c000000577045f8ced001cf917967b2de1fC:\Windows\SysWOW64\svchost.exeunknowna731f674-fd6c-11e3-be88-7446a0822eb5 Error: (06/26/2014 10:01:11 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: svchost.exe6.2.9200.16420505a96c3unknown0.0.0.000000000c000000577045f8c89801cf91795f05f585C:\Windows\SysWOW64\svchost.exeunknown9e82ac94-fd6c-11e3-be88-7446a0822eb5 Error: (06/26/2014 10:00:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: svchost.exe6.2.9200.16420505a96c3unknown0.0.0.000000000c000000577045f8cbe801cf91794a8f9f9fC:\Windows\SysWOW64\svchost.exeunknown8a3672cb-fd6c-11e3-be88-7446a0822eb5 Error: (05/15/2014 08:40:17 AM) (Source: MsiInstaller) (EventID: 1024) (User: Köörrrt) Description: Adobe Reader XI - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011007}1625(NULL)(NULL)(NULL) Error: (03/16/2014 07:21:21 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.2.9200.16420b2801cf2ff0d0a57d804294967295C:\Windows\syswow64\wwahost.exe4bc14c45-ad2f-11e3-be81-7446a0822eb5Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5cApp Error: (03/16/2014 06:26:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Köörrrt) Description: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c Error: (02/03/2014 04:33:16 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.2.9200.1642044001cf20037ea290894294967295C:\Windows\syswow64\wwahost.exebd83e931-8cdf-11e3-be80-7446a0822eb5Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5cApp Error: (02/03/2014 04:30:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Köörrrt) Description: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c Error: (02/01/2014 08:40:24 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.2.9200.1642058c01cf1f638ae820c74294967295C:\Windows\syswow64\wwahost.exe4e339a66-8b70-11e3-be80-7446a0822eb5Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5cApp ==================== Memory info =========================== Percentage of memory in use: 18% Total physical RAM: 7650.26 MB Available physical RAM: 6198.35 MB Total Pagefile: 9954.26 MB Available Pagefile: 8404.2 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:914.06 GB) (Free:876.14 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:16.68 GB) (Free:2.15 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: D4AD0251) Partition: GPT Partition Type. ==================== End Of Log ============================ Die neue FRST.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2014 Ran by Puschel (administrator) on KÖÖRRRT on 27-06-2014 10:01:10 Running from C:\Users\Puschel\Desktop Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-20] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-25] (Synaptics Incorporated) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-09-18] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491632 2012-09-10] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKU\S-1-5-21-2799476594-3240853191-3070442433-1002\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe "C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.uk.msn.com/HPNOT13/4 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM-x32 - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323895&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPFC3980F7-DD7B-4E02-9782-CE5F08F4EC13&q={searchTerms}&SSPV= SearchScopes: HKCU - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll No File Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default FF NewTab: about:blank FF SelectedSearchEngine: Google FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF user.js: detected! => C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\user.js FF SearchPlugin: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\searchplugins\conduit-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: NoScript - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-19] FF Extension: Adblock Plus - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-19] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-09-18] (Advanced Micro Devices, Inc.) [File not signed] R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-06-17] (Avira Operations GmbH & Co. KG) R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed] S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36520 2012-09-14] (Advanced Micro Devices, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-28] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-22] (Avira Operations GmbH & Co. KG) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-10] (Disc Soft Ltd) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-27] (Malwarebytes Corporation) R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-25] (Synaptics Incorporated) S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-25] (Synaptics Incorporated) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-27 00:21 - 2014-06-27 00:21 - 00005709 _____ () C:\mbam.txt 2014-06-26 23:43 - 2014-06-27 00:21 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-26 23:43 - 2014-06-26 23:43 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-26 23:43 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-26 23:43 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-26 23:43 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-26 23:39 - 2014-06-26 23:39 - 00002446 _____ () C:\Users\Puschel\Desktop\GMER.txt 2014-06-26 23:14 - 2014-06-27 09:59 - 00025923 _____ () C:\Users\Puschel\Desktop\Addition.txt 2014-06-26 23:13 - 2014-06-27 10:01 - 00011745 _____ () C:\Users\Puschel\Desktop\FRST.txt 2014-06-26 23:11 - 2014-06-27 10:01 - 00000000 ____D () C:\FRST 2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log 2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable 2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe 2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe 2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe 2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe 2014-06-26 22:00 - 2014-06-26 22:01 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps ==================== One Month Modified Files and Folders ======= 2014-06-27 10:01 - 2014-06-26 23:13 - 00011745 _____ () C:\Users\Puschel\Desktop\FRST.txt 2014-06-27 10:01 - 2014-06-26 23:11 - 00000000 ____D () C:\FRST 2014-06-27 10:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-06-27 09:59 - 2014-06-26 23:14 - 00025923 _____ () C:\Users\Puschel\Desktop\Addition.txt 2014-06-27 09:59 - 2012-10-20 07:07 - 00830120 _____ () C:\Windows\system32\perfh007.dat 2014-06-27 09:59 - 2012-10-20 07:07 - 00188224 _____ () C:\Windows\system32\perfc007.dat 2014-06-27 09:59 - 2012-07-26 09:28 - 01949368 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-27 09:53 - 2014-01-19 17:36 - 00000000 ____D () C:\Users\Puschel\AppData\Roaming\newnext.me 2014-06-27 09:53 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-27 00:21 - 2014-06-27 00:21 - 00005709 _____ () C:\mbam.txt 2014-06-27 00:21 - 2014-06-26 23:43 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-27 00:18 - 2013-09-16 15:13 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2799476594-3240853191-3070442433-1002 2014-06-26 23:43 - 2014-06-26 23:43 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-26 23:41 - 2013-09-16 15:06 - 01812375 _____ () C:\Windows\WindowsUpdate.log 2014-06-26 23:39 - 2014-06-26 23:39 - 00002446 _____ () C:\Users\Puschel\Desktop\GMER.txt 2014-06-26 23:37 - 2014-04-14 18:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-26 23:19 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log 2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable 2014-06-26 23:10 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel 2014-06-26 23:06 - 2014-03-18 15:33 - 00437408 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-06-26 23:05 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-26 23:05 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-26 23:04 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-06-26 23:03 - 2014-04-10 19:04 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-26 23:02 - 2012-08-04 00:37 - 00000000 ____D () C:\Program Files (x86)\MSBuild 2014-06-26 23:00 - 2012-07-26 09:52 - 00000000 ____D () C:\Windows\ShellNew 2014-06-26 23:00 - 2012-07-26 07:26 - 00000076 _____ () C:\Windows\win.ini 2014-06-26 22:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe 2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe 2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe 2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe 2014-06-26 22:01 - 2014-06-26 22:00 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps 2014-06-26 22:00 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel\AppData\Local\VirtualStore 2014-06-17 20:03 - 2013-09-24 12:47 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-06-17 20:03 - 2013-09-24 12:47 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys Some content of TEMP: ==================== C:\Users\Puschel\AppData\Local\Temp\6_Offer_15.exe C:\Users\Puschel\AppData\Local\Temp\avgnt.exe C:\Users\Puschel\AppData\Local\Temp\BackupSetup.exe C:\Users\Puschel\AppData\Local\Temp\DownloadManager.exe C:\Users\Puschel\AppData\Local\Temp\nse6761.exe C:\Users\Puschel\AppData\Local\Temp\nse6BB5.exe C:\Users\Puschel\AppData\Local\Temp\nse8D89.exe C:\Users\Puschel\AppData\Local\Temp\nsq2AAE.exe C:\Users\Puschel\AppData\Local\Temp\nsu64B2.exe C:\Users\Puschel\AppData\Local\Temp\nsu6C52.exe C:\Users\Puschel\AppData\Local\Temp\nsu6E75.exe C:\Users\Puschel\AppData\Local\Temp\nsy69C0.exe C:\Users\Puschel\AppData\Local\Temp\nsy8B94.exe C:\Users\Puschel\AppData\Local\Temp\ose00000.exe C:\Users\Puschel\AppData\Local\Temp\SearchProtectINT.exe C:\Users\Puschel\AppData\Local\Temp\vcredist_x64.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-27 00:27 ==================== End Of Log ============================ |
27.06.2014, 13:04 | #4 |
/// TB-Ausbilder /// Anleitungs-Guru | Ebay Mahnung Mail Anhang geöffnet Schritt 1 Download: Emsisoft MBR Master
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
27.06.2014, 13:54 | #5 |
| Ebay Mahnung Mail Anhang geöffnet Inhalt der MBRMastr_2014.06.27_14.47.55: Code:
ATTFilter Detected Windows version: 6.2 Build 9200 Driver connection handle: 0x00000148 1 valid drive(s) found. Details for Disk 0 - TOSHIBA MQ01ABD100 Rev AX001C: Device name : \\.\PhysicalDrive0 Geometry (C/H/S) : 121601/255/63 Boot loader reputation : Unknown Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : 639AC5CDF8A5CF3245975932C6A4215450A7B98F MD5 : 5FB38429D5D77768867C76DCBDB35194 |
27.06.2014, 14:03 | #6 |
/// TB-Ausbilder /// Anleitungs-Guru | Ebay Mahnung Mail Anhang geöffnet Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Scan mit Malwarebytes Antimalware Unter Erkennung und Schutz setze bitte einen Haken bei "Suche nach Rootkits". Klicke im Anschluss auf "Suchlauf", wähle den Bedrohungssuchlauf aus, aktualisiere die Datenbanken und klicke auf "Suchlauf jetzt starten". Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. (geht so...) Poste mir den Inhalt der Logdatei. Klicke dazu auf Verlauf und dann auf Anwendungsprotokolle. Wähle das neueste Suchlauf-Protokoll aus und klicke auf Ansicht. Klicke auf "In Zwischenablage kopieren" poste mir den Inhalt in Code-Tags als Antwort in den Thread. Schritt 3 ESET Online Scanner
Schritt 4 Bitte starte FRST erneut, markiere auch die checkbox und drücke auf Scan. Bitte poste mir den Inhalt der beiden Logs die erstellt werden. Gibt es jetzt noch Probleme mit dem PC? Wenn ja, welche?
__________________ --> Ebay Mahnung Mail Anhang geöffnet |
27.06.2014, 15:47 | #7 |
| Ebay Mahnung Mail Anhang geöffnet Adwcleaner log: Code:
ATTFilter # AdwCleaner v3.213 - Bericht erstellt am 27/06/2014 um 15:09:39 # Aktualisiert 23/06/2014 von Xplode # Betriebssystem : Windows 8 (64 bits) # Benutzername : Puschel - KÖÖRRRT # Gestartet von : C:\Users\Puschel\Desktop\adwcleaner_3.213.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Program Files (x86)\Mobogenie Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup Ordner Gelöscht : C:\Users\Puschel\AppData\Local\genienext Ordner Gelöscht : C:\Users\Puschel\AppData\Local\lollipop Ordner Gelöscht : C:\Users\Puschel\AppData\Local\Mobogenie Ordner Gelöscht : C:\Users\Puschel\AppData\Roaming\newnext.me Ordner Gelöscht : C:\Users\Puschel\AppData\Roaming\Systweak Ordner Gelöscht : C:\Users\Puschel\Documents\Mobogenie Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\Puschel\daemonprocess.txt Datei Gelöscht : C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\searchplugins\conduit-search.xml Datei Gelöscht : C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NextLive] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Schlüssel Gelöscht : HKCU\Software\lollipop Schlüssel Gelöscht : HKCU\Software\SearchProtectINT Schlüssel Gelöscht : HKCU\Software\SearchProtectInt2 Schlüssel Gelöscht : HKCU\Software\SmartBar Schlüssel Gelöscht : HKCU\Software\systweak Schlüssel Gelöscht : HKLM\Software\systweak ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16537 -\\ Mozilla Firefox v29.0.1 (de) [ Datei : C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\prefs.js ] Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false); Zeile gelöscht : user_pref("extensions.helperbar.Visibility", false); Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "de"); Zeile gelöscht : user_pref("extensions.helperbar.downloadprovider", "ry_2908"); Zeile gelöscht : user_pref("extensions.helperbar.externalJsFiles", "{\"d\":\"[{\\\"ExcludeDomains\\\":[\\\"snap.do\\\",\\\"snapdo.com\\\"],\\\"hxxpInjection\\\":\\\"hxxp:\\\\\\/\\\\\\/i.shopopjs.info\\\\\\/opop\\\\\\/[...] Zeile gelöscht : user_pref("extensions.helperbar.installationid", "0d3416dd-ebc1-456e-be6a-b5c51eeb57e8"); Zeile gelöscht : user_pref("extensions.helperbar.installdate", "19/01/2014"); Zeile gelöscht : user_pref("extensions.helperbar.lastExternalJsUpdate", "1390145792710"); Zeile gelöscht : user_pref("extensions.helperbar.publisher", "shopobrw"); ************************* AdwCleaner[R0].txt - [4546 octets] - [27/06/2014 15:08:35] AdwCleaner[S0].txt - [4061 octets] - [27/06/2014 15:09:39] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4121 octets] ########## Code:
ATTFilter mbam log: Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 27.06.2014 Scan Time: 15:14:10 Logfile: Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.06.27.05 Rootkit Database: v2014.06.23.02 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 8 CPU: x64 File System: NTFS User: Puschel Scan Type: Threat Scan Result: Completed Objects Scanned: 266289 Time Elapsed: 14 min, 27 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 1 PUP.Optional.BuzzIT.A, C:\Program Files (x86)\Buzz-it, Quarantined, [a04a82f9106b0d29050fcbda7d85c937], Files: 16 PUP.Optional.OutBrowse, C:\Users\Puschel\AppData\Local\Temp\DownloadManager.exe, Quarantined, [9a50aad1daa1e254df2e59c547b9bd43], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse6761.exe, Quarantined, [e307c0bb54271a1c345c40ee926fa35d], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse6BB5.exe, Quarantined, [a9414338ef8c1c1ad2be1d11847dd22e], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse8D89.exe, Quarantined, [ea000378215a06309cf4cf5f44bded13], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsq2AAE.exe, Quarantined, [9e4c1566a5d6191d167acd612ed3f709], PUP.Optional.SnapDo.A, C:\Users\Puschel\AppData\Local\Temp\Installer.msi, Quarantined, [3fabd9a248330f2781256325fc05aa56], PUP.Optional.Conduit.A, C:\Users\Puschel\AppData\Local\Temp\SearchProtectINT.exe, Quarantined, [42a87dfe4833da5c447a67baec15a957], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu64B2.exe, Quarantined, [32b82b500a7115216d237eb09a679e62], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu6C52.exe, Quarantined, [de0c1a61661550e6cbc5fa3442bff808], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu6E75.exe, Quarantined, [3dade4975c1fee48f49c5fcfb54ce020], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsy69C0.exe, Quarantined, [08e23c3fe497eb4b4d43c9652cd5f30d], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsy8B94.exe, Quarantined, [8f5b4e2d7efd2a0c7c149c92be436e92], PUP.Optional.Outbrowse, C:\Users\Puschel\AppData\Local\Temp\l0ox0hvJ.exe.part, Quarantined, [b4366615df9cd6605aed2fe03fc5af51], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\etxbsbelsd.pre, Quarantined, [49a1b4c7106b59dd18bf8058857d20e0], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\luahfxqpmy.pre, Quarantined, [edfdd1aa4a319f97d205f4e462a0b24e], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\tyuhssockk.pre, Quarantined, [11d9ea9187f41d1923b4a92fab57eb15], Physical Sectors: 0 (No malicious items detected) (end) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=e40d0de937a5ff47bd05c903fb75034d # engine=18917 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-06-27 02:29:11 # local_time=2014-06-27 04:29:11 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 23412 23859871 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 5379312 25552621 0 0 # scanned=179379 # found=9 # cleaned=0 # scan_time=2768 sh=8E6A6992A3C7FEC4000FA1A4D764DD597109E0B5 ft=1 fh=c71c0011cd00713e vn="Win32/NextLive.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Mobogenie\nengine.dll.vir" sh=8E6A6992A3C7FEC4000FA1A4D764DD597109E0B5 ft=1 fh=c71c0011cd00713e vn="Win32/NextLive.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Puschel\AppData\Local\genienext\nengine.dll.vir" sh=8E6A6992A3C7FEC4000FA1A4D764DD597109E0B5 ft=1 fh=c71c0011cd00713e vn="Win32/NextLive.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll.vir" sh=24BD4959CB8BA2D14453D3D2FE97A3D34550146E ft=1 fh=e247b72675f4f200 vn="Variante von Win32/Speedchecker.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Puschel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3QT7GS4M\pcspeedupSetup[1].exe" sh=F61C6750D1032B04DFBEA218AE579B30A1DD1F45 ft=1 fh=e0df02dd5fbc1171 vn="Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Puschel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3QT7GS4M\SPSetup[1].exe" sh=BC4111FE207B65C53AFFCBDEFA61F68D7B6C2E9C ft=1 fh=beafc52420be7958 vn="Win32/Mobogenie.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Puschel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QUKTG73J\Mobogenie_Setup_INT[1].exe" sh=0934D2C2CEF97C188A533CDA1C6E79B8FE452A95 ft=1 fh=a3228e9da12970f7 vn="Variante von MSIL/Toolbar.Linkury.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Puschel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QUKTG73J\Shopop_Setup[1].exe" sh=C4A6FCE0772792ED441793FBD22AC0E5605D1E89 ft=1 fh=8163f89546a047a4 vn="Win32/Toolbar.Conduit.R evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Puschel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QW7DYVJD\SearchProtectGeneric[1].exe" sh=8BCEACCD38FD5D335AB197C66FD12A4D8D5EDBCA ft=0 fh=0000000000000000 vn="Variante von Generik.MCDRKTL Trojaner" ac=I fn="C:\Users\Puschel\AppData\Local\Temp\Paypal Ausgleich stornierten Zahlung Ihrer Bestellung vom 26.06.2014 an Daria Simstedt.zip" FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2014 Ran by Puschel (administrator) on KÖÖRRRT on 27-06-2014 16:37:46 Running from C:\Users\Puschel\Desktop Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-20] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-25] (Synaptics Incorporated) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-09-18] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491632 2012-09-10] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.uk.msn.com/HPNOT13/4 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKLM-x32 - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKCU - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default FF NewTab: about:blank FF SelectedSearchEngine: Google FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: NoScript - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-19] FF Extension: Adblock Plus - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-19] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-09-18] (Advanced Micro Devices, Inc.) [File not signed] R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-06-17] (Avira Operations GmbH & Co. KG) R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed] S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36520 2012-09-14] (Advanced Micro Devices, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-28] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-22] (Avira Operations GmbH & Co. KG) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-10] (Disc Soft Ltd) R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-25] (Synaptics Incorporated) S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-25] (Synaptics Incorporated) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.) S3 a2dda; \??\C:\Users\Puschel\Desktop\MBRMastr.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-27 15:38 - 2014-06-27 15:38 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-06-27 15:37 - 2014-06-27 15:37 - 02347384 _____ (ESET) C:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe 2014-06-27 15:35 - 2014-06-27 15:36 - 00003147 _____ () C:\Users\Puschel\Desktop\mbam.txt 2014-06-27 15:11 - 2014-06-27 15:11 - 00004213 _____ () C:\Users\Puschel\Desktop\AdwCleaner[S0].txt 2014-06-27 15:08 - 2014-06-27 15:09 - 00000000 ____D () C:\AdwCleaner 2014-06-27 15:08 - 2014-06-27 15:08 - 01342659 _____ () C:\Users\Puschel\Desktop\adwcleaner_3.213.exe 2014-06-27 14:48 - 2014-06-27 14:48 - 00000153 _____ () C:\Users\Puschel\Desktop\unknown.zip 2014-06-27 14:47 - 2014-06-27 14:47 - 00788728 _____ (Emsisoft GmbH) C:\Users\Puschel\Desktop\mbrmastr.exe 2014-06-27 14:47 - 2014-06-27 14:47 - 00000528 _____ () C:\Users\Puschel\Desktop\MBRMastr_2014.06.27_14.47.55.txt 2014-06-27 14:47 - 2014-06-27 14:47 - 00000512 _____ () C:\Users\Puschel\Desktop\unknown.mbr 2014-06-27 00:21 - 2014-06-27 00:21 - 00005709 _____ () C:\mbam.txt 2014-06-26 23:43 - 2014-06-27 15:34 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-26 23:43 - 2014-06-26 23:43 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-26 23:43 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-26 23:43 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-26 23:43 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-26 23:39 - 2014-06-26 23:39 - 00002446 _____ () C:\Users\Puschel\Desktop\GMER.txt 2014-06-26 23:14 - 2014-06-27 10:02 - 00025922 _____ () C:\Users\Puschel\Desktop\Addition.txt 2014-06-26 23:13 - 2014-06-27 16:38 - 00010376 _____ () C:\Users\Puschel\Desktop\FRST.txt 2014-06-26 23:11 - 2014-06-27 16:37 - 00000000 ____D () C:\FRST 2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log 2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable 2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe 2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe 2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe 2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe 2014-06-26 22:00 - 2014-06-27 14:47 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps ==================== One Month Modified Files and Folders ======= 2014-06-27 16:38 - 2014-06-26 23:13 - 00010376 _____ () C:\Users\Puschel\Desktop\FRST.txt 2014-06-27 16:37 - 2014-06-26 23:11 - 00000000 ____D () C:\FRST 2014-06-27 16:37 - 2014-04-14 18:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-27 16:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-06-27 15:38 - 2014-06-27 15:38 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-06-27 15:38 - 2012-10-20 07:07 - 00830120 _____ () C:\Windows\system32\perfh007.dat 2014-06-27 15:38 - 2012-10-20 07:07 - 00188224 _____ () C:\Windows\system32\perfc007.dat 2014-06-27 15:38 - 2012-07-26 09:28 - 01949368 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-27 15:37 - 2014-06-27 15:37 - 02347384 _____ (ESET) C:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe 2014-06-27 15:36 - 2014-06-27 15:35 - 00003147 _____ () C:\Users\Puschel\Desktop\mbam.txt 2014-06-27 15:36 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-27 15:36 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-27 15:34 - 2014-06-26 23:43 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-27 15:34 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-27 15:33 - 2012-08-04 00:23 - 00511272 _____ () C:\Windows\PFRO.log 2014-06-27 15:11 - 2014-06-27 15:11 - 00004213 _____ () C:\Users\Puschel\Desktop\AdwCleaner[S0].txt 2014-06-27 15:09 - 2014-06-27 15:08 - 00000000 ____D () C:\AdwCleaner 2014-06-27 15:09 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel 2014-06-27 15:08 - 2014-06-27 15:08 - 01342659 _____ () C:\Users\Puschel\Desktop\adwcleaner_3.213.exe 2014-06-27 14:48 - 2014-06-27 14:48 - 00000153 _____ () C:\Users\Puschel\Desktop\unknown.zip 2014-06-27 14:47 - 2014-06-27 14:47 - 00788728 _____ (Emsisoft GmbH) C:\Users\Puschel\Desktop\mbrmastr.exe 2014-06-27 14:47 - 2014-06-27 14:47 - 00000528 _____ () C:\Users\Puschel\Desktop\MBRMastr_2014.06.27_14.47.55.txt 2014-06-27 14:47 - 2014-06-27 14:47 - 00000512 _____ () C:\Users\Puschel\Desktop\unknown.mbr 2014-06-27 14:47 - 2014-06-26 22:00 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps 2014-06-27 10:02 - 2014-06-26 23:14 - 00025922 _____ () C:\Users\Puschel\Desktop\Addition.txt 2014-06-27 00:21 - 2014-06-27 00:21 - 00005709 _____ () C:\mbam.txt 2014-06-27 00:18 - 2013-09-16 15:13 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2799476594-3240853191-3070442433-1002 2014-06-26 23:43 - 2014-06-26 23:43 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-26 23:41 - 2013-09-16 15:06 - 01812375 _____ () C:\Windows\WindowsUpdate.log 2014-06-26 23:39 - 2014-06-26 23:39 - 00002446 _____ () C:\Users\Puschel\Desktop\GMER.txt 2014-06-26 23:19 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log 2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable 2014-06-26 23:06 - 2014-03-18 15:33 - 00437408 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-06-26 23:04 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-06-26 23:03 - 2014-04-10 19:04 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-26 23:02 - 2012-08-04 00:37 - 00000000 ____D () C:\Program Files (x86)\MSBuild 2014-06-26 23:00 - 2012-07-26 09:52 - 00000000 ____D () C:\Windows\ShellNew 2014-06-26 23:00 - 2012-07-26 07:26 - 00000076 _____ () C:\Windows\win.ini 2014-06-26 22:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe 2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe 2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe 2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe 2014-06-26 22:00 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel\AppData\Local\VirtualStore 2014-06-17 20:03 - 2013-09-24 12:47 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-06-17 20:03 - 2013-09-24 12:47 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys Some content of TEMP: ==================== C:\Users\Puschel\AppData\Local\Temp\6_Offer_15.exe C:\Users\Puschel\AppData\Local\Temp\avgnt.exe C:\Users\Puschel\AppData\Local\Temp\BackupSetup.exe C:\Users\Puschel\AppData\Local\Temp\ose00000.exe C:\Users\Puschel\AppData\Local\Temp\Quarantine.exe C:\Users\Puschel\AppData\Local\Temp\vcredist_x64.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-27 10:14 ==================== End Of Log ============================ --- --- --- --- --- --- Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-06-2014 Ran by Puschel at 2014-06-27 16:38:25 Running from C:\Users\Puschel\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.6.636 - Adobe Systems, Inc.) AMD Accelerated Video Transcoding (Version: 12.5.100.20918 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.938.2 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{3CEC10BE-CD7C-8E99-E3AC-DD31F4416C1C}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.) AMD Fuel (Version: 2012.0918.260.3365 - Ihr Firmenname) Hidden AMD VISION Engine Control Center (x32 Version: 2012.0918.260.3365 - Ihr Firmenname) Hidden AutomationML Editor (HKLM-x32\...\{1FF9E567-7A33-4278-87D3-2CB2E0E07DC9}) (Version: 3.0.0 - AutomationML) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.672 - Avira) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2.5712 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.2.5712 - CyberLink Corp.) Hidden CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.2.2114 - CyberLink Corp.) CyberLink Media Suite 10 (x32 Version: 10.0.2.2114 - CyberLink Corp.) Hidden CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.2.3317 - CyberLink Corp.) CyberLink PhotoDirector (x32 Version: 2.0.2.3317 - CyberLink Corp.) Hidden CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.2.2110 - CyberLink Corp.) CyberLink Power2Go 8 (x32 Version: 8.0.2.2110 - CyberLink Corp.) Hidden CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.2.2126 - CyberLink Corp.) CyberLink PowerDirector 10 (x32 Version: 10.0.2.2126 - CyberLink Corp.) Hidden CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.7.4528 - CyberLink Corp.) CyberLink PowerDVD (x32 Version: 10.0.7.4528 - CyberLink Corp.) Hidden CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.5.5811 - CyberLink Corp.) CyberLink YouCam (x32 Version: 3.5.5.5811 - CyberLink Corp.) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP 3D DriveGuard (HKLM\...\{2DEDBE5B-D538-43F3-83A7-B037D6B51A89}) (Version: 4.2.8.1 - Hewlett-Packard Company) HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden HP Postscript Converter (Version: 3.1.3591 - Hewlett-Packard) Hidden HP Recovery Manager (x32 Version: 8.00 - Hewlett-Packard) Hidden HP Wireless Button Driver (HKLM-x32\...\{941DE69D-6CEE-4171-8F1F-3D7E352AA498}) (Version: 1.0.6.1 - Hewlett-Packard Company) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Language Pack 2007 - German/Deutsch (HKLM-x32\...\OMUI.de-de) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office O MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office SharePoint Designer MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office X MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 30.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.12 - Synaptics Incorporated) VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN) ==================== Restore Points ========================= 04-05-2014 14:04:18 Geplanter Prüfpunkt 26-06-2014 20:51:10 Microsoft Office wird entfernt ==================== Hosts content: ========================== 2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {2A12643D-F816-4B74-9A8C-BFDEBD2F94C3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Task: {665ABA0F-C344-4F9D-84DF-A4B54EE8BFAA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-09-05] (Hewlett-Packard Company) Task: {6A135F4B-F40B-450A-B411-6107AE3BE08F} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-10-12] (CyberLink) Task: {75FDDF18-9E8C-4DAA-A853-5DDA76EBAAE7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-18] (Adobe Systems Incorporated) Task: {77D9D4FF-08A3-4CBB-A530-D72BA2C5AC46} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Opt-in For HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe Task: {895E8F71-0D37-41A9-BC80-F6880C747D2C} - System32\Tasks\HPGenoobeReminder => C:\Program Files (x86)\Hewlett-Packard\HP Registration Service\HP GenOOBE\HPGenOOBE.exe Task: {8C8824B8-BBAE-4997-A40C-5DBB12B8122A} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-08] (CyberLink) Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {AF8D4BBF-73F2-46FC-A798-06875FBCD3ED} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-01-31] (Microsoft Corporation) Task: {B81FF858-55E7-4D9F-A91D-751724FD10BB} - System32\Tasks\Microsoft\Windows\Setup\Windows Upgrade Notification Task => C:\Windows\system32\NotificationUI.exe [2014-01-31] (Microsoft Corporation) Task: {C515F61B-3573-490A-B552-98081D50927C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2012-09-18 04:12 - 2012-09-18 04:12 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2012-09-18 04:11 - 2012-09-18 04:11 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2012-09-18 03:58 - 2012-09-18 03:58 - 00369664 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2013-03-27 04:46 - 2012-06-08 05:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2012-06-08 12:34 - 2012-06-08 12:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll 2013-09-24 12:40 - 2014-06-27 15:36 - 03852912 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/27/2014 04:35:30 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. Error: (06/27/2014 04:31:10 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. Error: (06/27/2014 03:38:08 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. Error: (06/27/2014 03:38:08 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. Error: (06/27/2014 03:38:01 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. Error: (06/27/2014 03:38:01 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. Error: (06/27/2014 03:38:01 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. Error: (06/27/2014 03:37:46 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest. Error: (06/27/2014 02:47:32 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: mbrmastr.exe, Version: 1.0.0.349, Zeitstempel: 0x5093115e Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e Ausnahmecode: 0xc000070a Fehleroffset: 0x000b0e7a ID des fehlerhaften Prozesses: 0x540 Startzeit der fehlerhaften Anwendung: 0xmbrmastr.exe0 Pfad der fehlerhaften Anwendung: mbrmastr.exe1 Pfad des fehlerhaften Moduls: mbrmastr.exe2 Berichtskennung: mbrmastr.exe3 Vollständiger Name des fehlerhaften Pakets: mbrmastr.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: mbrmastr.exe5 Error: (06/27/2014 00:21:47 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm mbam.exe, Version 1.0.0.532 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: e78 Startzeit: 01cf9187bafb614c Endzeit: 0 Anwendungspfad: C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe Berichts-ID: 3faa6cf6-fd80-11e3-be8b-7446a0822eb5 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: System errors: ============= Error: (06/27/2014 09:53:01 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 27.06.2014 um 00:27:12 unerwartet heruntergefahren. Error: (06/26/2014 11:33:20 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Audio Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/26/2014 11:28:22 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 26.06.2014 um 23:15:30 unerwartet heruntergefahren. Error: (06/17/2014 08:22:12 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (05/14/2014 10:16:26 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 13.05.2014 um 17:21:33 unerwartet heruntergefahren. Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (05/01/2014 09:16:42 AM) (Source: cdrom) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Microsoft Office Sessions: ========================= Error: (06/27/2014 04:35:30 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (06/27/2014 04:31:10 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (06/27/2014 03:38:08 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe Error: (06/27/2014 03:38:08 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe Error: (06/27/2014 03:38:01 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe Error: (06/27/2014 03:38:01 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe Error: (06/27/2014 03:38:01 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe Error: (06/27/2014 03:37:46 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe Error: (06/27/2014 02:47:32 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: mbrmastr.exe1.0.0.3495093115entdll.dll6.2.9200.16578515fac6ec000070a000b0e7a54001cf9205ed512c87C:\Users\Puschel\Desktop\mbrmastr.exeC:\Windows\SYSTEM32\ntdll.dll342bdef0-fdf9-11e3-be8c-7446a0822eb5 Error: (06/27/2014 00:21:47 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: mbam.exe1.0.0.532e7801cf9187bafb614c0C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe3faa6cf6-fd80-11e3-be8b-7446a0822eb5 ==================== Memory info =========================== Percentage of memory in use: 21% Total physical RAM: 7650.26 MB Available physical RAM: 6016.3 MB Total Pagefile: 9954.26 MB Available Pagefile: 8039.7 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:914.06 GB) (Free:875.98 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:16.68 GB) (Free:2.15 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: D4AD0251) Partition: GPT Partition Type. ==================== End Of Log ============================ |
27.06.2014, 16:03 | #8 |
/// TB-Ausbilder /// Anleitungs-Guru | Ebay Mahnung Mail Anhang geöffnet Hi, Datenträgerbereinigung
Flashplayer updaten bei Gelegenheit. Aufräumen: Defogger: Falls benutzt worden, Defogger nochmal starten und auf re-enable klicken. Anschließend: Gibts jetzt noch Probleme mit Deinem Rechner? Oder hast Du noch Fragen? NEIN? Alle Logs gepostet? Ja! Dann lade Dir bitte DelFix herunter.
Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst. Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen. >>clean<< Wir haben es geschafft! Die Logs sehen für mich im Moment sauber aus. Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...und/oder das Forum mit einer kleinen Spende unterstützen. Es bleibt mir nur noch, Dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen. Epilog: Tipps, Dos & Don'ts Aktualität von System und Software Das Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die automatischen Updates aktiviert sind. Auch die installierte Software sollte immer in der aktuellsten Version vorliegen. Speziell gilt das für die Browser , Java , Flash-Player und PDF-Reader , denn bekannte Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim bloßen Besuch einer präparierten Website per Drive-by Download Malware zu installieren. Das kann sogar auf normalerweise legitimen Websites geschehen, wenn es einem Angreifer gelungen ist, seinen Code in die Seite einzuschleusen, und ist deshalb relativ unberechenbar.
Sicherheits-Software Eine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine infizierte Datei nicht erkennt). Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt. Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons als Empfehlung gibt:
(Un-)Sicheres Verhalten im Internet Nebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert. Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
Allgemeine Hinweise Abschließend noch ein paar grundsätzliche Bemerkungen:
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer Geändert von deeprybka (27.06.2014 um 16:08 Uhr) |
27.06.2014, 16:25 | #9 |
| Ebay Mahnung Mail Anhang geöffnet Danke für die hervorragende Hilfe! Ich wünsche dir noch ein angenehmes Wochenende und hoffentlich auf Nimmerwiedersehen |
27.06.2014, 16:26 | #10 |
/// TB-Ausbilder /// Anleitungs-Guru | Ebay Mahnung Mail Anhang geöffnet OK... Alles Gute!
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |