![]() |
|
Plagegeister aller Art und deren Bekämpfung: ADWcleaner lässt sich nicht mehr starten.Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
![]() | ![]() ADWcleaner lässt sich nicht mehr starten. Hallo Jürgen, hier sind die gewünschten LogFiles: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-07-2014 Ran by Maddin at 2014-07-04 13:19:29 Running from C:\Users\Maddin\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader X (10.1.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated) Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc) Alice Software 4.9.2 (HKLM-x32\...\Alice Software) (Version: 4.9.2 - HanseNet Telekommunikation GmbH) Alice-Installationsdateien entfernen (HKLM-x32\...\Alice) (Version: - ) Antivirus Pro (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.5.450 - Avira) Apple Application Support (HKLM-x32\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Avira SearchFree Toolbar (HKLM-x32\...\{41564952-412D-5637-4300-A758B70C0A00}) (Version: 12.10.0.2951 - APN, LLC) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden Call of Duty(R) 2 (HKLM-x32\...\InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}) (Version: 1.00.0000 - Activision) Call of Duty(R) 2 (x32 Version: 1.00.0000 - Activision) Hidden Call of Duty: Black Ops - Multiplayer (HKLM-x32\...\Steam App 42710) (Version: - Treyarch) Call of Duty: Black Ops (HKLM-x32\...\Steam App 42700) (Version: - Treyarch) CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform) Copy (x32 Version: 130.0.366.000 - Hewlett-Packard) Hidden Corel Home Office 5.0.36 (HKLM-x32\...\{080FE95E-5A89-4A54-BAAA-D769971B7C2D}) (Version: 5 - Corel) Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC) DJ_AIO_06_F4500_SW_MIN (x32 Version: 130.0.406.000 - Hewlett-Packard) Hidden D-Link DWA-140 (HKLM-x32\...\{D7D2F494-89E3-42ED-8A2B-75BDD9B464CB}) (Version: - D-Link) Energy Settings (HKLM-x32\...\{7613592F-B20C-4E1B-B2DD-67F0784D4373}) (Version: 1.0.7 - Fujitsu Siemens Computers) F4500 (x32 Version: 130.0.406.000 - Hewlett-Packard) Hidden Free YouTube Download version 3.2.0.128 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.0.128 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 32.0.1700.102 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Google Updater (HKLM-x32\...\Google Updater) (Version: 2.4.1698.5652 - Google Inc.) GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP) HP Deskjet F4500 Printer Driver Software 13.0 Rel .6 (HKLM\...\{7F08A772-2816-4F46-84F1-49578502AD28}) (Version: 13.0 - HP) HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP) HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP) HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Update (HKLM-x32\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard) hpPrintProjects (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden hpWLPGInstaller (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden iTunes (HKLM\...\{5A68A656-979F-4168-8795-E2E368AA4DC2}) (Version: 11.2.2.3 - Apple Inc.) Logitech Vid (HKLM-x32\...\{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}) (Version: 1.01.1015 - Logitech Inc.) Logitech® Camera-Treiber (HKLM-x32\...\QcDrv) (Version: - ) MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}) (Version: 3.0.19.0 - Microsoft Corporation) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyFreeCodec (HKCU\...\MyFreeCodec) (Version: - ) Nero 7 Demo (HKLM-x32\...\{C7E1449D-7638-6832-426D-589655951031}) (Version: 7.00.1466 - Nero AG) Nero Reloaded PlugIn Pack 2.0.4 by GEAR (HKLM-x32\...\{F3D7915D-6B42-49FA-9FC8-5020479A6A57}) (Version: 2.0.4 - GoldEsel) Network64 (Version: 130.0.572.000 - Hewlett-Packard) Hidden NVIDIA 3D Vision Controller-Treiber 301.42 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 301.42 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation) NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.11.9713 - NVIDIA Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.59.37 - NVIDIA Corporation) NVIDIA ForceWare Network Access Manager (HKLM-x32\...\{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}) (Version: 1.00.7325.0 - NVIDIA Corporation) NVIDIA Grafiktreiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.108.688 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.12.0213 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.12.0213 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0213 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 311.06 (Version: 311.06 - NVIDIA Corporation) Hidden NVIDIA Update 1.11.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.11.3 - NVIDIA Corporation) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) Orban/Coding Technologies AAC/aacPlus Player Plugin™ 1.0 (HKLM-x32\...\{DB0A8A2A-4EA7-4FE3-802E-8A6DEE32696C}_is1) (Version: - Orban, Inc.) PVSonyDll (Version: 1.00.0001 - NVIDIA Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5772 - Realtek Semiconductor Corp.) S.T.A.L.K.E.R. - Shadow of Chernobyl (HKLM-x32\...\S.T.A.L.K.E.R. - Shadow of Chernobyl_is1) (Version: 1.0000 - THQ) Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP) Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.10.9560 - Skype Technologies S.A.) Skype™ 5.9 (HKLM-x32\...\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}) (Version: 5.9.123 - Skype Technologies S.A.) SmartWebPrinting (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden Sniper Elite: Zombie Army (HKLM-x32\...\Steam App 235700) (Version: - Rebellion) SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden StarCraft II (HKLM-x32\...\StarCraft II) (Version: - Blizzard Entertainment) Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) SynWrite version 6.4.760 (HKLM-x32\...\SynWrite_is1) (Version: 6.4.760 - UVViewSoft) SystemDiagnostics (HKLM-x32\...\{EF59DB7F-7426-426E-B862-7031F83ED304}) (Version: 2.04.0006 - Fujitsu Technology Solutions) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH) TerraTec Aureon 5.1 Audio Driver (HKLM\...\C-Media PCI Audio Driver) (Version: - ) Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden Tukui Client (HKLM-x32\...\{510CF4AB-E9C8-4F48-BB02-CDC11B880D68}) (Version: 2.2.7 - Tukui) Tukui Client (HKLM-x32\...\{6517882E-E5E0-40DC-B3B0-A531FF2A06E8}) (Version: 2.4.5 - Tukui) TuneUp Utilities (HKLM-x32\...\TuneUp Utilities) (Version: 9.0.6030.1 - TuneUp Software) TuneUp Utilities (x32 Version: 9.0.6030.1 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 10.0.4600.4 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 9.0.6030.1 - TuneUp Software) Hidden Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player 2.1.0 (HKLM-x32\...\VLC media player) (Version: 2.1.0 - VideoLAN) WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden Windows Live Anmelde-Assistent (HKLM-x32\...\{52B97218-98CB-4B8B-9283-D213C85E1AA4}) (Version: 5.000.818.5 - Microsoft Corporation) Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation) Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) Windows Vista Demo Screen Saver (HKLM-x32\...\{9605D5C2-F545-40F2-B39A-0462E4CD3811}) (Version: 1.1.5 - Ventuz Technology) Works Suite-Betriebssystem-Pack (x32 Version: 1.0.0.0000 - Microsoft Corporation) Hidden WorldofTanks (HKCU\...\WorldofTanks) (Version: - WorldofTanks) ==================== Restore Points ========================= 23-05-2014 18:17:07 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 23-05-2014 18:18:45 OpenOffice 4.1.0 wird installiert 31-05-2014 17:30:38 Windows Update 04-06-2014 00:15:05 Windows Update 10-06-2014 07:49:10 Windows Update 11-06-2014 17:32:58 Windows Update 17-06-2014 11:32:54 Windows Update 20-06-2014 17:38:26 Windows Update 20-06-2014 18:06:13 Entfernt Tom Clancy's Splinter Cell 22-06-2014 19:25:08 Geplanter Prüfpunkt 24-06-2014 06:10:19 Windows Update 02-07-2014 17:37:26 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2006-11-02 14:34 - 2006-09-18 23:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {03734EA4-6886-4FFF-BDC9-10BDB40D1B41} - System32\Tasks\Google Updater and Installer => C:\Users\Maddin\AppData\Local\Google\Update\GoogleUpdate.exe Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {0C53DB7C-3292-41C6-BBE2-E09C1AAC656F} - System32\Tasks\WOT WFRI1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {0D60C924-08F7-4AAE-A8C9-72FED50DAF8A} - \Plus-HD-2.2-chromeinstaller No Task File <==== ATTENTION Task: {133D8A4C-D133-4BB1-BE06-633AFE748C9C} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2011-05-10] (Hewlett-Packard) Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {1C26A2D5-BD29-4388-B66D-DD6D4A40B7A1} - System32\Tasks\WOT WMON1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {1F6F6465-1B1C-4B6C-BFFA-08B7DB938F46} - \Desk 365 RunAsStdUser No Task File <==== ATTENTION Task: {213121A8-BEDD-4D7E-AFAD-04C9767D7779} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated) Task: {22082927-5B18-4E51-9D24-37C1DC881406} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-30] (Google Inc.) Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {36A0BB86-DA41-4B87-B65D-1FF7F4604AE7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {39913DE5-5F6F-4DE9-BD8D-CF1DC0BC674E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-14] (Adobe Systems Incorporated) Task: {48C17C53-73B2-4132-863F-B783839616A6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-30] (Google Inc.) Task: {4C4EE77B-4F44-4CF1-9882-6653C0FB77D3} - System32\Tasks\Google Software Updater => C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-27] (Google) Task: {5B8E1D3C-500B-4185-9858-B8AE3B9B1B20} - \Plus-HD-2.2-updater No Task File <==== ATTENTION Task: {5BB20900-5D7E-4327-904C-767A634A161A} - System32\Tasks\WOT T => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {6372E08D-540D-440A-8D2F-5167B33D2D9A} - \Plus-HD-2.2-enabler No Task File <==== ATTENTION Task: {739DCE2D-7420-48CD-B30B-8091A8CBC200} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd) Task: {753EB692-0B14-4B0D-9B07-BC11ED29F8A8} - \HDvid Codec V1-enabler No Task File <==== ATTENTION Task: {7642C8FD-D96B-4CE9-9D00-6FAFFB248A0E} - \Plus-HD-2.2-firefoxinstaller No Task File <==== ATTENTION Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {80A71535-3608-4738-9FE8-7DE6C5FE5A14} - System32\Tasks\WOT W2 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {83EACCD6-FB00-4468-987B-40903B45B1EB} - System32\Tasks\{0E0B6708-828E-4F31-8073-8CCE8A0A7924} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2012-06-05] (Skype Technologies S.A.) Task: {9126A9BD-3BA0-45B2-8937-37FD34B7808C} - \DealPly No Task File <==== ATTENTION Task: {92FCC7E2-AF62-4EF6-BE58-3DB1365A90B8} - \HDvid Codec V1-codedownloader No Task File <==== ATTENTION Task: {A97048A0-D205-49CE-8A2B-A98D2BEB34D3} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {AF91A651-088C-4086-9CD4-384F3BA1067B} - System32\Tasks\WOT WWED1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {B13A788C-6EA7-46F5-858E-990B10A0C088} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated) Task: {B6206A65-57D9-4506-AEF6-ABE2596CA1F9} - System32\Tasks\WOT WTUE1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {C8AED9DC-FEAF-4B53-BB4B-2B200DFAF959} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files (x86)\TuneUp Utilities 2010\OneClick.exe [2011-11-21] (TuneUp Software) Task: {D16C2F03-A27C-4D2E-B36C-D0064F83838E} - System32\Tasks\WOT W1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {E08A976F-F4F8-476D-AF80-CCF028FC15F6} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: {E335426E-2CFB-4C9F-ACA1-534DF8D85D45} - \HDvid Codec V1-updater No Task File <==== ATTENTION Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {EA9AA878-5CA3-4D7B-A5E1-E9CBCEF9A53D} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Maddin => C:\Program Files\Windows Calendar\WinCal.exe [2008-01-21] (Microsoft Corporation) Task: {EDE5B0EC-8FF1-4476-A6D2-F191E23DF60B} - \Plus-HD-2.2-codedownloader No Task File <==== ATTENTION Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-10 20:12 - 2010-06-03 14:36 - 00053248 _____ () C:\Program Files (x86)\D-Link\DWA-140 revB\ANIWConnService.exe 2012-06-18 20:29 - 2010-01-21 01:53 - 00496232 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe 2012-06-18 20:29 - 2010-01-21 01:52 - 00076392 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll 2012-06-18 20:29 - 2010-01-21 01:53 - 00731752 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll 2012-06-18 20:29 - 2010-01-21 01:53 - 00209000 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe 2011-01-03 23:00 - 2008-07-11 16:04 - 00200704 ____N () C:\Windows\SysWOW64\HsMgr.exe 2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-12 20:58 - 2014-02-12 20:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2008-08-28 12:08 - 2008-08-28 12:08 - 01287456 _____ () C:\Program Files (x86)\Corel Home Office\A4W195.dll 2008-08-28 12:08 - 2008-08-28 12:08 - 00546080 _____ () C:\Program Files (x86)\Corel Home Office\abdbcmn.dll 2008-08-28 12:09 - 2008-08-28 12:09 - 00808224 _____ () C:\Program Files (x86)\Corel Home Office\ABShare.DLL 2008-08-28 12:09 - 2008-08-28 12:09 - 00111904 _____ () C:\Program Files (x86)\Corel Home Office\ABViewForms.dll 2008-08-28 12:09 - 2008-08-28 12:09 - 00378144 _____ () C:\Program Files (x86)\Corel Home Office\ABMCmn.dll 2008-08-28 12:09 - 2008-08-28 12:09 - 00152864 _____ () C:\Program Files (x86)\Corel Home Office\abspel.dll 2008-08-28 12:10 - 2008-08-28 12:10 - 00066848 _____ () C:\Program Files (x86)\Corel Home Office\THXX.dll 2008-08-28 12:10 - 2008-08-28 12:10 - 00107808 _____ () C:\Program Files (x86)\Corel Home Office\VEXX.dll 2008-08-28 12:08 - 2008-08-28 12:08 - 00288032 _____ () C:\Program Files (x86)\Corel Home Office\abcomctrl.dll 2008-08-28 12:09 - 2008-08-28 12:09 - 00255264 _____ () C:\Program Files (x86)\Corel Home Office\IMAGE.dll 2008-08-28 12:09 - 2008-08-28 12:09 - 00230688 _____ () C:\Program Files (x86)\Corel Home Office\abpivot.dll 2008-08-28 12:09 - 2008-08-28 12:09 - 00980256 _____ () C:\Program Files (x86)\Corel Home Office\abo.dll 2008-08-28 12:09 - 2008-08-28 12:09 - 00787744 _____ () C:\Program Files (x86)\Corel Home Office\abow.dll 2008-08-28 12:09 - 2008-08-28 12:09 - 00161056 _____ () C:\Program Files (x86)\Corel Home Office\abimgsrc.dll 2008-08-28 12:09 - 2008-08-28 12:09 - 12563744 _____ () C:\Program Files (x86)\Corel Home Office\ABGerman.dll 2008-08-28 12:09 - 2008-08-28 12:09 - 01561888 _____ () C:\Program Files (x86)\Corel Home Office\abdrwngs.dll 2008-08-28 12:09 - 2008-08-28 12:09 - 00242976 _____ () C:\Program Files (x86)\Corel Home Office\abgfx.dll 2014-01-30 15:28 - 2014-01-23 07:56 - 04055320 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\pdf.dll 2014-01-30 15:28 - 2014-01-23 07:57 - 00399640 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\ppGoogleNaClPluginChrome.dll 2014-01-30 15:28 - 2014-01-23 07:55 - 01634584 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4 AlternateDataStreams: C:\ProgramData\TEMP:AD022376 ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup MSCONFIG\startupreg: ANIWZCS2Service => "C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe" MSCONFIG\startupreg: GDFirewallTray => C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe MSCONFIG\startupreg: ROC_roc_dec12 => "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 MSCONFIG\startupreg: vProt => "C:\Program Files (x86)\AVG Secure Search\vprot.exe" ==================== Faulty Device Manager Devices ============= Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-6zu4-Adapter #2 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-6zu4-Adapter #3 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-6zu4-Adapter #4 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-6zu4-Adapter #4 Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-ISATAP-Adapter #2 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Deskjet F4500 series Description: Deskjet F4500 series Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} Manufacturer: HP Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (07/04/2014 01:12:11 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/03/2014 08:25:50 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/02/2014 07:45:49 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/02/2014 07:43:36 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm avcenter.exe, Version 14.0.5.396 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen. Prozess-ID: fc8 Anfangszeit: 01cf9616cde16379 Zeitpunkt der Beendigung: 51262 Error: (07/02/2014 06:54:34 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/01/2014 07:52:59 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/01/2014 02:01:07 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/01/2014 09:00:06 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/30/2014 07:55:40 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/26/2014 09:57:02 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (07/04/2014 01:13:55 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Windows Media Player-NetzwerkfreigabedienstUPnP-Gerätehost%%1058 Error: (07/04/2014 01:13:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: NVIDIA Update Service Daemon%%1069 Error: (07/04/2014 01:13:55 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: nvUpdatusService.\UpdatusUser%%1330 Error: (07/04/2014 01:13:55 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: KtmRm für Distributed Transaction Coordinator2147942438 (0x80070026) Error: (07/04/2014 01:12:12 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Windows Media Player-NetzwerkfreigabedienstUPnP-Gerätehost%%1058 Error: (07/03/2014 08:27:48 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Windows Media Player-NetzwerkfreigabedienstUPnP-Gerätehost%%1058 Error: (07/03/2014 08:27:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: NVIDIA Update Service Daemon%%1069 Error: (07/03/2014 08:27:48 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: nvUpdatusService.\UpdatusUser%%1330 Error: (07/03/2014 08:27:48 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: KtmRm für Distributed Transaction Coordinator2147942438 (0x80070026) Error: (07/03/2014 08:25:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Windows Media Player-NetzwerkfreigabedienstUPnP-Gerätehost%%1058 Microsoft Office Sessions: ========================= Error: (07/04/2014 01:12:11 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/03/2014 08:25:50 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/02/2014 07:45:49 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/02/2014 07:43:36 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: avcenter.exe14.0.5.396fc801cf9616cde1637951262 Error: (07/02/2014 06:54:34 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/01/2014 07:52:59 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/01/2014 02:01:07 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/01/2014 09:00:06 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/30/2014 07:55:40 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/26/2014 09:57:02 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2012-11-19 12:16:20.136 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\dxgi.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-12-15 16:24:42.006 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\lgscroll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-12-15 16:24:41.906 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\GameHook.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-12-15 16:24:41.802 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\lgscroll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-12-15 16:24:41.698 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\GameHook.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-12-15 16:24:41.582 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\lgscroll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-12-15 16:24:41.464 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\GameHook.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-12-15 16:24:41.354 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\lgscroll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-12-15 16:24:41.254 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\GameHook.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-12-15 16:24:41.153 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\lgscroll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 48% Total physical RAM: 4094.32 MB Available physical RAM: 2123.83 MB Total Pagefile: 8391.92 MB Available Pagefile: 6228.07 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (SYSTEM) (Fixed) (Total:327.54 GB) (Free:162.05 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive e: (DATA) (Fixed) (Total:592.25 GB) (Free:428.3 GB) NTFS Drive f: (DJ_AIO_06_F4500_) (CDROM) (Total:0.32 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: C347115F) Partition 1: (Not Active) - (Size=12 GB) - (Type=27) Partition 2: (Active) - (Size=328 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=592 GB) - (Type=07 NTFS) ==================== End Of Log ============================ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-07-2014 Ran by Maddin (administrator) on MARTIN on 04-07-2014 13:24:18 Running from C:\Users\Maddin\Downloads Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\D-Link\DWA-140 revB\ANIWConnService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Fujitsu Technology Solutions) C:\Program Files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesApp64.exe () C:\Windows\SysWOW64\HsMgr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Corel) C:\Program Files (x86)\Corel Home Office\CORELC~1.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Cmaudio8768GX] => C:\Windows\syswow64\HsMgr.exe [200704 2008-07-11] () HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [6962720 2009-01-06] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-01-06] (Realtek Semiconductor Corp.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-07-01] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [] => [X] HKU\.DEFAULT\...\Run: [Picasa Media Detector] => C:\Program Files (x86)\Picasa2\PicasaMediaDetector.exe HKU\.DEFAULT\...\Run: [fsc-reg] => c:\fsc-reg\fscreg.exe [380688 2008-08-01] (Fujitsu Siemens) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3559629360-2871224288-528010784-1000\...\MountPoints2: {171db5d8-f2aa-11dd-ad52-806e6f6e6963} - F:\Setup.exe HKU\S-1-5-21-3559629360-2871224288-528010784-1000\...\MountPoints2: {7ebde948-31da-11de-b5c8-00242110eaf6} - D:\SH3Autorun.exe Startup: C:\Users\Maddin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () BootExecute: ==================== Internet (Whitelisted) ==================== URLSearchHook: HKLM-x32 - (No Name) - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {301B60B5-4EE1-421E-95C2-22CB96AA0A8F} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=501549&p={searchTerms} BHO: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg64.dll (Google Inc.) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - No Name - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - No File Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.) Toolbar: HKCU - No Name - {E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} - No File Toolbar: HKCU - No Name - {62D40876-DF18-411F-9D34-A9DD7A197BC5} - No File Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pack.google.com/Google Updater;version=13 - C:\Program Files (x86)\Google\Google Updater\2.4.1698.5652\npCIDetect13.dll (Google) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Extension: FoxyDeal - C:\Users\Maddin\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{F58A62EB-38DC-43C4-A539-DC52E135208D} [2013-05-10] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-20] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-04-03] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011-06-20] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011-06-20] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://www.google.de/" CHR Extension: (Google Docs) - C:\Users\Maddin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-20] CHR Extension: (Google Drive) - C:\Users\Maddin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-20] CHR Extension: (YouTube) - C:\Users\Maddin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-20] CHR Extension: (Adblock Plus) - C:\Users\Maddin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-03-05] CHR Extension: (Google-Suche) - C:\Users\Maddin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-20] CHR Extension: (Google Wallet) - C:\Users\Maddin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-20] CHR Extension: (Google Mail) - C:\Users\Maddin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-20] CHR HKLM-x32\...\Chrome\Extension: [bbecdmcnlcoebdcidcfdkoimbjkcegbc] - C:\Users\Maddin\AppData\Roaming\Browser Extensions\amazonsh_1.0.crx [2013-11-20] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-03-02] CHR HKLM-x32\...\Chrome\Extension: [nlcphjankhppgohedpkjonpadimhaoof] - C:\Users\Maddin\AppData\Roaming\Browser Extensions\sh_1.0.crx [2012-03-02] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= ATTENTION: => Could not perform signature verification. Cryptographic Service is not running. R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [801872 2014-07-01] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1028688 2014-07-01] (Avira Operations GmbH & Co. KG) S4 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.) R2 D-Link Wireless N DWA-140_WPS; C:\Program Files (x86)\D-Link\DWA-140 revB\ANIWConnService.exe [53248 2010-06-03] () R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] () R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] () R2 TestHandler; C:\Program Files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe [341264 2009-02-19] (Fujitsu Technology Solutions) S3 TuneUp.Defrag; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [607040 2013-05-14] (TuneUp Software) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [1403200 2011-11-21] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R1 anodlwf; C:\Windows\System32\DRIVERS\anodlwfx.sys [15872 2009-03-06] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-01] (Avira Operations GmbH & Co. KG) S4 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [39768 2013-02-25] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-20] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG) R3 cmuda3; C:\Windows\System32\drivers\cmudax3.sys [1155072 2009-05-22] (C-Media Inc) R3 netr28ux; C:\Windows\System32\DRIVERS\Dnetr28ux.sys [1035104 2010-04-29] (Ralink Technology Corp.) S3 PDNMp50; C:\Windows\SysWOW64\drivers\PDNMp50.sys [28224 2006-11-28] (Printing Communications Assoc., Inc. (PCAUSA)) S3 PDNSp50; C:\Windows\SysWOW64\drivers\PDNSp50.sys [27072 2006-11-28] (Printing Communications Assoc., Inc. (PCAUSA)) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [11856 2009-10-14] (TuneUp Software) R1 {55685567-4840-4a91-962b-49a412e9485a}Gt64; C:\Windows\System32\drivers\{55685567-4840-4a91-962b-49a412e9485a}Gt64.sys [60088 2014-05-28] (StdLib) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 LVcKap64; system32\DRIVERS\LVcKap64.sys [X] S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 PDNSp50a64; System32\Drivers\PDNSp50a64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-04 13:19 - 2014-07-04 13:24 - 00038379 _____ () C:\Users\Maddin\Downloads\Addition.txt 2014-07-04 13:17 - 2014-07-04 13:24 - 00016025 _____ () C:\Users\Maddin\Downloads\FRST.txt 2014-07-04 13:17 - 2014-07-04 13:24 - 00000000 ____D () C:\FRST 2014-07-04 13:16 - 2014-07-04 13:16 - 02083840 _____ (Farbar) C:\Users\Maddin\Downloads\FRST64.exe 2014-07-02 19:41 - 2014-07-02 19:41 - 00537974 _____ () C:\Users\Maddin\Downloads\noscript-2.6.8.31.xpi.zip 2014-06-26 22:09 - 2014-06-26 22:09 - 00000921 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-06-26 22:09 - 2014-06-26 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client 2014-06-26 22:09 - 2014-06-26 22:09 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-06-26 22:07 - 2014-06-26 22:08 - 29256752 _____ (TeamSpeak Systems GmbH) C:\Users\Maddin\Downloads\TeamSpeak3-Client-win64-3.0.15.exe 2014-06-26 10:13 - 2014-06-26 10:13 - 00000000 ____D () C:\New Folder 2014-06-26 10:10 - 2014-07-02 19:41 - 00000000 ____D () C:\Users\Maddin\AppData\Roaming\SynWrite 2014-06-26 10:10 - 2014-07-02 19:41 - 00000000 ____D () C:\SynWrite 2014-06-26 10:10 - 2014-06-26 10:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SynWrite 2014-06-26 10:08 - 2014-06-26 10:10 - 13642531 _____ (UVViewSoft ) C:\Users\Maddin\Downloads\synwrite (1).exe 2014-06-26 10:04 - 2014-06-26 10:06 - 13642531 _____ (UVViewSoft ) C:\Users\Maddin\Downloads\synwrite.exe 2014-06-25 22:29 - 2014-06-26 08:02 - 00000666 _____ () C:\Users\Public\Desktop\StarCraft II.lnk 2014-06-25 22:28 - 2014-07-01 14:11 - 00000000 ____D () C:\Users\Maddin\Documents\StarCraft II 2014-06-25 22:28 - 2014-06-26 08:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II 2014-06-24 20:55 - 2014-06-24 20:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-06-24 20:46 - 2014-06-24 20:46 - 01342659 _____ () C:\Users\Maddin\Downloads\adwcleaner_3.213.exe 2014-06-24 20:42 - 2014-06-24 21:44 - 00002114 _____ () C:\Windows\PFRO.log 2014-06-24 08:28 - 2014-06-24 08:28 - 02804344 _____ (TeamViewer GmbH) C:\Users\Maddin\Downloads\customermodule_avira_support_de.exe 2014-06-24 08:28 - 2014-06-24 08:28 - 00000000 ____D () C:\Users\Maddin\AppData\Roaming\TeamViewer 2014-06-23 11:04 - 2014-06-23 11:04 - 01333465 _____ () C:\Users\Maddin\Downloads\adwcleaner_3.212 (1).exe 2014-06-19 21:59 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-19 21:57 - 2014-06-19 21:57 - 01333465 _____ () C:\Users\Maddin\Downloads\adwcleaner_3.212.exe 2014-06-19 15:52 - 2014-06-19 15:52 - 00011965 _____ () C:\Users\Maddin\Documents\Unbenannt 1.ods 2014-06-19 14:35 - 2014-06-19 14:35 - 00448512 _____ (OldTimer Tools) C:\Users\Maddin\Downloads\TFC (1).exe 2014-06-12 21:57 - 2014-06-12 21:57 - 00000000 ____D () C:\ProgramData\HPSSUPPLY 2014-06-11 08:54 - 2014-05-28 20:53 - 17857536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-11 08:54 - 2014-05-28 20:37 - 02338816 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-11 08:54 - 2014-05-28 20:35 - 10890240 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-11 08:54 - 2014-05-28 20:31 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-11 08:54 - 2014-05-28 20:31 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-11 08:54 - 2014-05-28 20:30 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-11 08:54 - 2014-05-28 20:30 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-06-11 08:54 - 2014-05-28 20:29 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-11 08:54 - 2014-05-28 20:29 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-11 08:54 - 2014-05-28 20:29 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-11 08:54 - 2014-05-28 20:29 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-11 08:54 - 2014-05-28 20:29 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-11 08:54 - 2014-05-28 20:29 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-11 08:54 - 2014-05-28 20:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-11 08:54 - 2014-05-28 20:28 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-11 08:54 - 2014-05-28 20:28 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-11 08:54 - 2014-05-28 20:28 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-11 08:54 - 2014-05-28 20:28 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-06-11 08:54 - 2014-05-28 20:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-06-11 08:54 - 2014-05-28 20:28 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-06-11 08:54 - 2014-05-28 20:27 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-11 08:54 - 2014-05-28 18:48 - 12356608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-11 08:54 - 2014-05-28 18:39 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-11 08:54 - 2014-05-28 18:38 - 09711104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-11 08:54 - 2014-05-28 18:33 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-11 08:54 - 2014-05-28 18:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-11 08:54 - 2014-05-28 18:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-11 08:54 - 2014-05-28 18:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-06-11 08:54 - 2014-05-28 18:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-11 08:54 - 2014-05-28 18:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-11 08:54 - 2014-05-28 18:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-06-11 08:54 - 2014-05-28 18:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-11 08:54 - 2014-05-28 18:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-06-11 08:54 - 2014-05-28 18:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-11 08:54 - 2014-05-28 18:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-06-11 08:54 - 2014-05-28 18:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-06-11 08:54 - 2014-05-28 18:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-11 08:54 - 2014-05-28 18:29 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-11 08:54 - 2014-05-28 18:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-11 08:54 - 2014-05-28 18:29 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-06-11 08:54 - 2014-05-28 18:29 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-06-11 08:54 - 2014-05-28 18:28 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-06-11 08:54 - 2014-04-26 20:21 - 00622592 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-11 08:54 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-11 08:54 - 2014-04-05 11:10 - 01422784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-11 08:54 - 2014-03-10 08:26 - 01869824 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-11 08:54 - 2014-03-10 08:26 - 01794560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-11 08:54 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-11 08:54 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-05 15:25 - 2014-06-05 15:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-06-05 15:24 - 2014-06-05 15:25 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-06-05 15:24 - 2014-06-05 15:25 - 00000000 ____D () C:\Program Files\iTunes 2014-06-05 15:24 - 2014-06-05 15:25 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-06-05 15:24 - 2014-06-05 15:24 - 00000000 ____D () C:\Program Files\iPod ==================== One Month Modified Files and Folders ======= 2014-07-04 13:24 - 2014-07-04 13:19 - 00038379 _____ () C:\Users\Maddin\Downloads\Addition.txt 2014-07-04 13:24 - 2014-07-04 13:17 - 00016025 _____ () C:\Users\Maddin\Downloads\FRST.txt 2014-07-04 13:24 - 2014-07-04 13:17 - 00000000 ____D () C:\FRST 2014-07-04 13:16 - 2014-07-04 13:16 - 02083840 _____ (Farbar) C:\Users\Maddin\Downloads\FRST64.exe 2014-07-04 13:15 - 2014-05-09 19:49 - 01243299 _____ () C:\Windows\WindowsUpdate.log 2014-07-04 13:14 - 2009-12-04 19:15 - 00004140 _____ () C:\Windows\System32\Tasks\Google Software Updater 2014-07-04 13:14 - 2009-08-27 21:27 - 00001034 _____ () C:\Windows\Tasks\Google Software Updater.job 2014-07-04 13:12 - 2014-01-30 15:27 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-04 13:11 - 2009-01-26 12:49 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-04 13:11 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-04 13:11 - 2006-11-02 17:22 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-04 13:11 - 2006-11-02 17:22 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-03 21:17 - 2009-07-04 16:33 - 00000000 ____D () C:\Users\Maddin\AppData\Roaming\CorelHomeOffice 2014-07-03 21:17 - 2006-11-02 17:42 - 00032586 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-03 21:04 - 2014-01-30 15:27 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-03 20:55 - 2013-01-29 20:29 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-02 23:07 - 2014-04-19 00:19 - 00000000 ____D () C:\Users\Maddin\AppData\Local\Battle.net 2014-07-02 23:07 - 2010-11-19 21:26 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-07-02 23:07 - 2009-12-30 21:40 - 00000000 ____D () C:\Users\Maddin\AppData\Roaming\TS3Client 2014-07-02 19:41 - 2014-07-02 19:41 - 00537974 _____ () C:\Users\Maddin\Downloads\noscript-2.6.8.31.xpi.zip 2014-07-02 19:41 - 2014-06-26 10:10 - 00000000 ____D () C:\Users\Maddin\AppData\Roaming\SynWrite 2014-07-02 19:41 - 2014-06-26 10:10 - 00000000 ____D () C:\SynWrite 2014-07-02 19:33 - 2011-05-19 18:49 - 00003686 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{D93DBACB-AE77-466D-9B91-FD8EC005C83B} 2014-07-01 14:11 - 2014-06-25 22:28 - 00000000 ____D () C:\Users\Maddin\Documents\StarCraft II 2014-07-01 14:05 - 2013-03-27 20:49 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-06-26 22:09 - 2014-06-26 22:09 - 00000921 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-06-26 22:09 - 2014-06-26 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client 2014-06-26 22:09 - 2014-06-26 22:09 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-06-26 22:08 - 2014-06-26 22:07 - 29256752 _____ (TeamSpeak Systems GmbH) C:\Users\Maddin\Downloads\TeamSpeak3-Client-win64-3.0.15.exe 2014-06-26 22:06 - 2009-12-30 21:39 - 00000000 ____D () C:\Program Files (x86)\TeamSpeak 3 Client 2014-06-26 10:13 - 2014-06-26 10:13 - 00000000 ____D () C:\New Folder 2014-06-26 10:10 - 2014-06-26 10:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SynWrite 2014-06-26 10:10 - 2014-06-26 10:08 - 13642531 _____ (UVViewSoft ) C:\Users\Maddin\Downloads\synwrite (1).exe 2014-06-26 10:06 - 2014-06-26 10:04 - 13642531 _____ (UVViewSoft ) C:\Users\Maddin\Downloads\synwrite.exe 2014-06-26 08:02 - 2014-06-25 22:29 - 00000666 _____ () C:\Users\Public\Desktop\StarCraft II.lnk 2014-06-26 08:02 - 2014-06-25 22:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II 2014-06-25 22:29 - 2010-04-07 14:41 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment 2014-06-25 22:26 - 2014-04-19 00:18 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-06-24 21:44 - 2014-06-24 20:42 - 00002114 _____ () C:\Windows\PFRO.log 2014-06-24 20:55 - 2014-06-24 20:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-06-24 20:48 - 2013-02-16 13:14 - 00000000 ____D () C:\Program Files (x86)\Amazon 2014-06-24 20:47 - 2013-12-13 16:22 - 00000000 ____D () C:\AdwCleaner 2014-06-24 20:46 - 2014-06-24 20:46 - 01342659 _____ () C:\Users\Maddin\Downloads\adwcleaner_3.213.exe 2014-06-24 08:28 - 2014-06-24 08:28 - 02804344 _____ (TeamViewer GmbH) C:\Users\Maddin\Downloads\customermodule_avira_support_de.exe 2014-06-24 08:28 - 2014-06-24 08:28 - 00000000 ____D () C:\Users\Maddin\AppData\Roaming\TeamViewer 2014-06-23 11:04 - 2014-06-23 11:04 - 01333465 _____ () C:\Users\Maddin\Downloads\adwcleaner_3.212 (1).exe 2014-06-22 20:37 - 2014-04-28 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader 2014-06-22 20:37 - 2013-05-31 04:21 - 00003786 _____ () C:\Windows\System32\Tasks\Adobe Reader and Acrobat Manager 2014-06-20 20:07 - 2014-03-24 16:39 - 00000000 ____D () C:\Program Files (x86)\Ubi Soft 2014-06-20 20:07 - 2009-04-09 17:00 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-06-20 20:01 - 2013-11-13 18:15 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-06-20 19:59 - 2014-01-30 15:27 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-20 19:59 - 2014-01-30 15:27 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-20 19:42 - 2013-03-27 20:49 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-06-19 22:01 - 2009-04-09 17:00 - 00000000 ____D () C:\ProgramData\ICQ 2014-06-19 22:00 - 2009-04-03 16:44 - 00000000 ____D () C:\Users\Maddin 2014-06-19 21:57 - 2014-06-19 21:57 - 01333465 _____ () C:\Users\Maddin\Downloads\adwcleaner_3.212.exe 2014-06-19 15:52 - 2014-06-19 15:52 - 00011965 _____ () C:\Users\Maddin\Documents\Unbenannt 1.ods 2014-06-19 15:41 - 2010-11-27 21:19 - 00009725 _____ () C:\ProgramData\hpzinstall.log 2014-06-19 15:26 - 2010-11-27 21:19 - 00225436 _____ () C:\Windows\hpoins46.dat 2014-06-19 15:26 - 2006-11-02 14:34 - 00000281 _____ () C:\Windows\win.ini 2014-06-19 14:35 - 2014-06-19 14:35 - 00448512 _____ (OldTimer Tools) C:\Users\Maddin\Downloads\TFC (1).exe 2014-06-17 13:33 - 2013-12-20 21:53 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-13 08:44 - 2008-01-21 13:10 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-13 08:44 - 2008-01-21 13:09 - 00674024 _____ () C:\Windows\system32\perfh007.dat 2014-06-13 08:44 - 2008-01-21 13:09 - 00146036 _____ () C:\Windows\system32\perfc007.dat 2014-06-12 21:57 - 2014-06-12 21:57 - 00000000 ____D () C:\ProgramData\HPSSUPPLY 2014-06-11 19:40 - 2013-08-14 14:48 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-11 19:37 - 2006-11-02 14:35 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-06-11 12:02 - 2012-06-19 11:45 - 00000000 ____D () C:\Program Files (x86)\Diablo III 2014-06-05 15:25 - 2014-06-05 15:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-06-05 15:25 - 2014-06-05 15:24 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-06-05 15:25 - 2014-06-05 15:24 - 00000000 ____D () C:\Program Files\iTunes 2014-06-05 15:25 - 2014-06-05 15:24 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-06-05 15:24 - 2014-06-05 15:24 - 00000000 ____D () C:\Program Files\iPod 2014-06-05 15:24 - 2014-04-28 11:15 - 00000000 ____D () C:\ProgramData\Apple Computer Files to move or delete: ==================== C:\Users\Public\AlexaNSISPlugin.4500.dll Some content of TEMP: ==================== C:\Users\Maddin\AppData\Local\Temp\avgnt.exe C:\Users\Maddin\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-07-04 13:24 ==================== End Of Log ============================ 1111111[/CODE] Bitte schön, die angeforderten LogFiles Mfg Jojobin |
![]() | #2 |
/// TB-Ausbilder /// Anleitungs-Guru ![]() ![]() ![]() ![]() ![]() | ![]() ADWcleaner lässt sich nicht mehr starten. Hi,
__________________Schritt 1 ![]()
__________________ |
![]() |