|
Log-Analyse und Auswertung: Rechner viel langsamer, stürzt häufig abWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
20.07.2014, 20:40 | #1 |
| Rechner viel langsamer, stürzt häufig ab hallo, - habe ws vista, avast antivirus und google chrome - rechner ist letzte tage viel langsamer geworden und chrome friert bald den cursor ein, dann ist jede taste ohne reaktion, habe eindruck, das bald nix mehr geht - bei anwendung von GMER ist mehrmals das gleiche passiert - defogger hat auf schwarzer fläche nix angezeigt - frst 32bit ergebnisse sende ich hier - avast ergebisse lassen kein kopieren zu; da steht: einige dateien können nicht überprüft werden; bei status: fehler: archiv ist kennwortgeschützt vielen dank , bis bald Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:20-07-2014 Ran by tm (administrator) on TM-PC on 20-07-2014 20:45:29 Running from C:\Users\tm\Downloads Platform: Microsoft® Windows Vista™ Home Premium (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 7 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe () C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe () C:\Program Files\Samsung\Samsung Recovery Solution II\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe () C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (FUJIFILM Corporation) C:\Program Files\FinePixViewer\QuickDCF2.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe () C:\Users\tm\Downloads\Defogger (6).exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Farbar) C:\Users\tm\Downloads\FRST (4).exe ==================== Registry (Whitelisted) ================== HKLM\...\RunOnce: [AvgUninstallURL] => cmd.exe /c start hxxp://www.avg.de/de.special-uninstallation-feedback-lsf?lic=OUxTRlJFRS1WUFVaNy1HMk (the data entry has 177 more characters). HKU\.DEFAULT\...\Run: [Samsung.PCSync] => C:\Program Files\Samsung\Samsung PC Studio 7\PcSync2.exe [1294336 2008-09-18] (Time Information Services Ltd.) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [SpybotSD TeaTimer] => C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-01-26] (Google Inc.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\tm\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=7dd42 (the data entry has 82 more characters). HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [S60 PC Suite Tray] => C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe [699392 2008-12-06] () HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: F - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {18cd0e19-9393-11e1-94c8-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {28fd0733-d443-11e1-9967-0013776453a9} - H:\Menu.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {461fa564-22c4-11e1-90b4-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {461fa566-22c4-11e1-90b4-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {48a8bbfd-560a-11df-9857-0013776453a9} - F:\LaunchU3.exe -a HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {9b7a5ae1-d13f-11dd-aae1-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {9b7a5b06-d13f-11dd-aae1-0013776453a9} - G:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {ddab0c5a-e9c0-11e0-837a-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {f8940028-8263-11e0-ba62-db1fa4e62d98} - F:\Menu.exe AppInit_DLLs: C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2010-06-10] (Google) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ExifLauncher2.lnk ShortcutTarget: ExifLauncher2.lnk -> C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/?LinkId=69157 URLSearchHook: HKCU - (No Name) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File URLSearchHook: HKCU - (No Name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File SearchScopes: HKLM - DefaultScope {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} SearchScopes: HKLM - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} SearchScopes: HKCU - {70D46D94-BF1E-45ED-B567-48701376298E} URL = hxxp://127.0.0.1:4664/search&s=FbRkhSNyuC927LohHs6Uav7tIHA?q={searchTerms} SearchScopes: HKCU - {A8221FCE-87F0-4F05-AFFC-6F4672A6D922} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms} SearchScopes: HKCU - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://search.avg.com/route/?d=0&v=6.103.18.1&i=&tp=chrome&q={searchTerms}&lng={language}&iy=&ychte=us BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll No File BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) BHO: No Name -> {B922D405-6D13-4A2B-AE89-08A030DA4402} -> No File Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - No Name - {A057A204-BACC-4D26-9990-79A187E2698E} - No File Toolbar: HKCU - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml FF DefaultSearchEngine: WEB.DE Suche FF SelectedSearchEngine: WEB.DE Suche FF Homepage: hxxp://go.web.de/tb/mff_startpage FF Keyword.URL: user_pref("keyword.URL", ""); FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\webde-suche.xml FF Extension: WEB.DE MailCheck - C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\Extensions\toolbar@web.de.xpi [2012-12-14] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-11-09] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-07-20] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://www.google.com/" CHR DefaultSearchKeyword: web.de CHR DefaultNewTabURL: CHR Extension: (Google Docs) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-09] CHR Extension: (Google Drive) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-09] CHR Extension: (YouTube) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-09] CHR Extension: (Google-Suche) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-09] CHR Extension: (avast! Online Security) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-11-09] CHR Extension: (Google Wallet) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-09] CHR Extension: (Google Mail) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-09] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-09] ========================== Services (Whitelisted) ================= R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [116040 2008-09-10] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-06] (AVAST Software) S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-10] (Google) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45408 2008-11-24] (Microsoft Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44544 2008-12-03] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2008-12-03] (Hewlett-Packard) [File not signed] R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [171040 2007-01-08] () [File not signed] S2 Samsung Update Plus; C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe [73728 2007-06-28] () [File not signed] R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S3 TDslMgrService; C:\Program Files\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) [File not signed] S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-01-06] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2014-01-06] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2013-11-09] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-01-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2014-01-06] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2014-01-06] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2014-01-06] () R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) S3 dsltestSp5; C:\Windows\System32\Drivers\dsltestSp5.sys [26816 2007-09-12] (Printing Communications Assoc., Inc. (PCAUSA)) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2007-07-11] (SAMSUNG ELECTRONICS CO., LTD.) S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation) S3 NPF; C:\Windows\System32\drivers\npf.sys [34064 2007-11-06] (CACE Technologies) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [113664 2009-12-08] (Huawei Technologies Co., Ltd.) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-20 20:45 - 2014-07-20 20:45 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (4).exe 2014-07-20 20:44 - 2014-07-20 20:44 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (6).exe 2014-07-20 20:26 - 2014-07-20 20:26 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (4).exe 2014-07-20 20:16 - 2014-07-20 20:17 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (3).exe 2014-07-20 20:16 - 2014-07-20 20:16 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (5).exe 2014-07-20 19:45 - 2014-07-20 19:45 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (3).exe 2014-07-20 19:41 - 2014-07-20 19:41 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (2).exe 2014-07-20 19:40 - 2014-07-20 19:40 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (4).exe 2014-07-20 19:27 - 2014-07-20 19:27 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (2).exe 2014-07-20 19:25 - 2014-07-20 19:25 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (1).exe 2014-07-20 19:13 - 2014-07-20 19:14 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (1).exe 2014-07-20 19:10 - 2014-07-20 19:11 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (3).exe 2014-07-20 04:33 - 2014-07-20 04:33 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357.exe 2014-07-20 04:14 - 2014-07-20 20:20 - 00035689 _____ () C:\Users\tm\Downloads\Addition.txt 2014-07-20 04:10 - 2014-07-20 20:45 - 00019297 _____ () C:\Users\tm\Downloads\FRST.txt 2014-07-20 04:09 - 2014-07-20 20:45 - 00000000 ____D () C:\FRST 2014-07-20 04:08 - 2014-07-20 04:08 - 01079808 _____ (Farbar) C:\Users\tm\Downloads\FRST.exe 2014-07-20 04:04 - 2014-07-20 20:44 - 00000466 _____ () C:\Users\tm\Downloads\defogger_disable.log 2014-07-20 04:04 - 2014-07-20 04:04 - 00000000 _____ () C:\Users\tm\defogger_reenable 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger.exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (2).exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (1).exe 2014-07-20 03:48 - 2014-07-20 04:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-20 03:45 - 2014-07-20 03:45 - 00000000 ____D () C:\Windows\SQL9_KB970892_ENU 2014-07-20 03:27 - 2008-06-20 03:18 - 00781344 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2014-07-20 03:27 - 2008-06-20 03:18 - 00326160 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2014-07-20 03:27 - 2008-06-20 03:18 - 00105016 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2014-07-20 03:27 - 2008-06-20 03:18 - 00043544 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2014-07-20 03:27 - 2008-06-20 03:17 - 00622080 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-07-20 03:27 - 2008-06-20 03:17 - 00097800 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-07-20 03:27 - 2008-06-20 03:17 - 00037384 _____ (Microsoft Corporation) C:\Windows\system32\infocardcpl.cpl 2014-07-20 03:27 - 2008-06-20 03:17 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-07-20 03:19 - 2014-07-20 03:26 - 00196608 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.perf 2014-07-20 03:19 - 2014-07-20 03:26 - 00065536 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.dpx 2014-07-20 03:06 - 2008-07-27 20:00 - 00096760 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2014-07-20 03:04 - 2008-07-27 20:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-07-20 03:02 - 2010-02-21 01:54 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\nshhttp.dll 2014-07-20 03:01 - 2010-02-21 01:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\httpapi.dll 2014-07-20 03:01 - 2010-02-20 23:30 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2014-07-12 20:56 - 2014-07-12 20:56 - 00031744 _____ () C:\Users\tm\Downloads\Firmenlauf_Bielefeld_Anmeldung2014.xls 2014-07-06 19:07 - 2006-12-14 13:42 - 00069120 ____R (AVM Berlin) C:\Windows\system32\avmadd32.dll ==================== One Month Modified Files and Folders ======= 2014-07-20 20:45 - 2014-07-20 20:45 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (4).exe 2014-07-20 20:45 - 2014-07-20 04:10 - 00019297 _____ () C:\Users\tm\Downloads\FRST.txt 2014-07-20 20:45 - 2014-07-20 04:09 - 00000000 ____D () C:\FRST 2014-07-20 20:45 - 2008-03-30 15:28 - 00000412 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{7DE789EB-2CEE-4FAA-A54E-B1DE1CF3B6DF}.job 2014-07-20 20:45 - 2008-01-25 05:31 - 00000434 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{D9B30BB4-63C0-47D4-A444-A174F9308500}.job 2014-07-20 20:44 - 2014-07-20 20:44 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (6).exe 2014-07-20 20:44 - 2014-07-20 04:04 - 00000466 _____ () C:\Users\tm\Downloads\defogger_disable.log 2014-07-20 20:40 - 2011-05-29 04:42 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-20 20:40 - 2008-03-30 14:59 - 00000000 ____D () C:\Users\tm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-07-20 20:40 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-20 20:40 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-20 20:40 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-20 20:26 - 2014-07-20 20:26 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (4).exe 2014-07-20 20:20 - 2014-07-20 04:14 - 00035689 _____ () C:\Users\tm\Downloads\Addition.txt 2014-07-20 20:18 - 2011-05-29 04:42 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-20 20:17 - 2014-07-20 20:16 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (3).exe 2014-07-20 20:16 - 2014-07-20 20:16 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (5).exe 2014-07-20 20:13 - 2008-01-25 06:20 - 01084991 _____ () C:\Windows\WindowsUpdate.log 2014-07-20 19:45 - 2014-07-20 19:45 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (3).exe 2014-07-20 19:41 - 2014-07-20 19:41 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (2).exe 2014-07-20 19:40 - 2014-07-20 19:40 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (4).exe 2014-07-20 19:27 - 2014-07-20 19:27 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (2).exe 2014-07-20 19:25 - 2014-07-20 19:25 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (1).exe 2014-07-20 19:14 - 2014-07-20 19:13 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (1).exe 2014-07-20 19:11 - 2014-07-20 19:10 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (3).exe 2014-07-20 18:54 - 2012-12-27 20:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-20 17:25 - 2009-08-26 12:57 - 00000000 ____D () C:\Program Files\PC Connectivity Solution 2014-07-20 12:54 - 2007-07-11 00:17 - 00000012 _____ () C:\Windows\bthservsdp.dat 2014-07-20 12:54 - 2006-11-02 15:01 - 00032538 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-20 12:53 - 2014-05-01 20:12 - 00035328 _____ () C:\Users\tm\Documents\infobook.xls 2014-07-20 11:22 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-07-20 11:17 - 2007-07-10 07:07 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE 2014-07-20 11:17 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\system32\XPSViewer 2014-07-20 11:17 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-07-20 11:16 - 2008-08-23 19:22 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-20 11:16 - 2007-07-11 01:28 - 00034152 _____ () C:\Windows\PFRO.log 2014-07-20 04:33 - 2014-07-20 04:33 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357.exe 2014-07-20 04:08 - 2014-07-20 04:08 - 01079808 _____ (Farbar) C:\Users\tm\Downloads\FRST.exe 2014-07-20 04:04 - 2014-07-20 04:04 - 00000000 _____ () C:\Users\tm\defogger_reenable 2014-07-20 04:04 - 2008-03-30 14:58 - 00000000 ____D () C:\Users\tm 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger.exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (2).exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (1).exe 2014-07-20 04:02 - 2014-07-20 03:48 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-20 03:46 - 2006-11-02 12:33 - 01492226 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-20 03:45 - 2014-07-20 03:45 - 00000000 ____D () C:\Windows\SQL9_KB970892_ENU 2014-07-20 03:45 - 2007-07-11 01:13 - 00000000 ____D () C:\Program Files\Microsoft SQL Server 2014-07-20 03:26 - 2014-07-20 03:19 - 00196608 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.perf 2014-07-20 03:26 - 2014-07-20 03:19 - 00065536 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.dpx 2014-07-20 03:26 - 2010-05-29 15:47 - 58916864 _____ () C:\Windows\ocsetup_install_NetFx3.etl 2014-07-20 03:01 - 2011-01-14 02:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-20 02:58 - 2010-05-29 15:35 - 00284204 _____ () C:\Windows\msxml4-KB954430-enu.LOG 2014-07-20 02:56 - 2010-05-29 15:34 - 00288290 _____ () C:\Windows\msxml4-KB973688-enu.LOG 2014-07-18 16:04 - 2013-11-09 06:07 - 00001963 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-12 20:56 - 2014-07-12 20:56 - 00031744 _____ () C:\Users\tm\Downloads\Firmenlauf_Bielefeld_Anmeldung2014.xls 2014-07-10 22:04 - 2008-04-15 23:06 - 00066048 _____ () C:\Users\tm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-08 22:59 - 2012-12-27 20:40 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-07-08 22:59 - 2011-06-27 23:52 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-07-06 19:08 - 2013-02-09 20:46 - 00002963 _____ () C:\Windows\avmadd32.log 2014-07-06 19:07 - 2013-02-09 20:46 - 00000000 ____D () C:\Program Files\FRITZ!Box 2014-06-26 17:38 - 2006-11-02 12:24 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe Some content of TEMP: ==================== C:\Users\tm\AppData\Local\Temp\DataCard_Setup.exe C:\Users\tm\AppData\Local\Temp\ResetDevice.exe C:\Users\tm\AppData\Local\Temp\UNINSTALL.EXE C:\Users\tm\AppData\Local\Temp\_is227F.exe C:\Users\tm\AppData\Local\Temp\_is4847.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-20 20:46 ==================== End Of Log ============================ Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:20-07-2014 Ran by tm (administrator) on TM-PC on 20-07-2014 20:46:39 Running from C:\Users\tm\Downloads Platform: Microsoft® Windows Vista™ Home Premium (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 7 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe () C:\Program Files\Samsung\Samsung Recovery Solution II\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe () C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (FUJIFILM Corporation) C:\Program Files\FinePixViewer\QuickDCF2.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe () C:\Users\tm\Downloads\Defogger (6).exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Farbar) C:\Users\tm\Downloads\FRST (4).exe () C:\Program Files\Samsung\Samsung Update Plus\SLUTrayNotifier.exe ==================== Registry (Whitelisted) ================== HKLM\...\RunOnce: [AvgUninstallURL] => cmd.exe /c start hxxp://www.avg.de/de.special-uninstallation-feedback-lsf?lic=OUxTRlJFRS1WUFVaNy1HMk (the data entry has 177 more characters). HKU\.DEFAULT\...\Run: [Samsung.PCSync] => C:\Program Files\Samsung\Samsung PC Studio 7\PcSync2.exe [1294336 2008-09-18] (Time Information Services Ltd.) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [SpybotSD TeaTimer] => C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-01-26] (Google Inc.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\tm\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=7dd42 (the data entry has 82 more characters). HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [S60 PC Suite Tray] => C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe [699392 2008-12-06] () HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: F - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {18cd0e19-9393-11e1-94c8-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {28fd0733-d443-11e1-9967-0013776453a9} - H:\Menu.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {461fa564-22c4-11e1-90b4-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {461fa566-22c4-11e1-90b4-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {48a8bbfd-560a-11df-9857-0013776453a9} - F:\LaunchU3.exe -a HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {9b7a5ae1-d13f-11dd-aae1-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {9b7a5b06-d13f-11dd-aae1-0013776453a9} - G:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {ddab0c5a-e9c0-11e0-837a-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {f8940028-8263-11e0-ba62-db1fa4e62d98} - F:\Menu.exe AppInit_DLLs: C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2010-06-10] (Google) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ExifLauncher2.lnk ShortcutTarget: ExifLauncher2.lnk -> C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/?LinkId=69157 URLSearchHook: HKCU - (No Name) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File URLSearchHook: HKCU - (No Name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File SearchScopes: HKLM - DefaultScope {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} SearchScopes: HKLM - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} SearchScopes: HKCU - {70D46D94-BF1E-45ED-B567-48701376298E} URL = hxxp://127.0.0.1:4664/search&s=FbRkhSNyuC927LohHs6Uav7tIHA?q={searchTerms} SearchScopes: HKCU - {A8221FCE-87F0-4F05-AFFC-6F4672A6D922} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms} SearchScopes: HKCU - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://search.avg.com/route/?d=0&v=6.103.18.1&i=&tp=chrome&q={searchTerms}&lng={language}&iy=&ychte=us BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll No File BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) BHO: No Name -> {B922D405-6D13-4A2B-AE89-08A030DA4402} -> No File Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - No Name - {A057A204-BACC-4D26-9990-79A187E2698E} - No File Toolbar: HKCU - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml FF DefaultSearchEngine: WEB.DE Suche FF SelectedSearchEngine: WEB.DE Suche FF Homepage: hxxp://go.web.de/tb/mff_startpage FF Keyword.URL: user_pref("keyword.URL", ""); FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\webde-suche.xml FF Extension: WEB.DE MailCheck - C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\Extensions\toolbar@web.de.xpi [2012-12-14] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-11-09] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-07-20] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://www.google.com/" CHR DefaultSearchKeyword: web.de CHR DefaultNewTabURL: CHR Extension: (Google Docs) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-09] CHR Extension: (Google Drive) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-09] CHR Extension: (YouTube) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-09] CHR Extension: (Google-Suche) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-09] CHR Extension: (avast! Online Security) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-11-09] CHR Extension: (Google Wallet) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-09] CHR Extension: (Google Mail) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-09] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-09] ========================== Services (Whitelisted) ================= R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [116040 2008-09-10] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-06] (AVAST Software) S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-10] (Google) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45408 2008-11-24] (Microsoft Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44544 2008-12-03] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2008-12-03] (Hewlett-Packard) [File not signed] R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [171040 2007-01-08] () [File not signed] S2 Samsung Update Plus; C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe [73728 2007-06-28] () [File not signed] R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S3 TDslMgrService; C:\Program Files\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) [File not signed] S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-01-06] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2014-01-06] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2013-11-09] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-01-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2014-01-06] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2014-01-06] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2014-01-06] () R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) S3 dsltestSp5; C:\Windows\System32\Drivers\dsltestSp5.sys [26816 2007-09-12] (Printing Communications Assoc., Inc. (PCAUSA)) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2007-07-11] (SAMSUNG ELECTRONICS CO., LTD.) S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation) S3 NPF; C:\Windows\System32\drivers\npf.sys [34064 2007-11-06] (CACE Technologies) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [113664 2009-12-08] (Huawei Technologies Co., Ltd.) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-20 20:45 - 2014-07-20 20:45 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (4).exe 2014-07-20 20:44 - 2014-07-20 20:44 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (6).exe 2014-07-20 20:26 - 2014-07-20 20:26 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (4).exe 2014-07-20 20:16 - 2014-07-20 20:17 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (3).exe 2014-07-20 20:16 - 2014-07-20 20:16 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (5).exe 2014-07-20 19:45 - 2014-07-20 19:45 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (3).exe 2014-07-20 19:41 - 2014-07-20 19:41 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (2).exe 2014-07-20 19:40 - 2014-07-20 19:40 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (4).exe 2014-07-20 19:27 - 2014-07-20 19:27 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (2).exe 2014-07-20 19:25 - 2014-07-20 19:25 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (1).exe 2014-07-20 19:13 - 2014-07-20 19:14 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (1).exe 2014-07-20 19:10 - 2014-07-20 19:11 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (3).exe 2014-07-20 04:33 - 2014-07-20 04:33 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357.exe 2014-07-20 04:14 - 2014-07-20 20:20 - 00035689 _____ () C:\Users\tm\Downloads\Addition.txt 2014-07-20 04:10 - 2014-07-20 20:46 - 00019207 _____ () C:\Users\tm\Downloads\FRST.txt 2014-07-20 04:09 - 2014-07-20 20:46 - 00000000 ____D () C:\FRST 2014-07-20 04:08 - 2014-07-20 04:08 - 01079808 _____ (Farbar) C:\Users\tm\Downloads\FRST.exe 2014-07-20 04:04 - 2014-07-20 20:44 - 00000466 _____ () C:\Users\tm\Downloads\defogger_disable.log 2014-07-20 04:04 - 2014-07-20 04:04 - 00000000 _____ () C:\Users\tm\defogger_reenable 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger.exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (2).exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (1).exe 2014-07-20 03:48 - 2014-07-20 04:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-20 03:45 - 2014-07-20 03:45 - 00000000 ____D () C:\Windows\SQL9_KB970892_ENU 2014-07-20 03:27 - 2008-06-20 03:18 - 00781344 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2014-07-20 03:27 - 2008-06-20 03:18 - 00326160 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2014-07-20 03:27 - 2008-06-20 03:18 - 00105016 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2014-07-20 03:27 - 2008-06-20 03:18 - 00043544 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2014-07-20 03:27 - 2008-06-20 03:17 - 00622080 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-07-20 03:27 - 2008-06-20 03:17 - 00097800 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-07-20 03:27 - 2008-06-20 03:17 - 00037384 _____ (Microsoft Corporation) C:\Windows\system32\infocardcpl.cpl 2014-07-20 03:27 - 2008-06-20 03:17 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-07-20 03:19 - 2014-07-20 03:26 - 00196608 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.perf 2014-07-20 03:19 - 2014-07-20 03:26 - 00065536 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.dpx 2014-07-20 03:06 - 2008-07-27 20:00 - 00096760 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2014-07-20 03:04 - 2008-07-27 20:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-07-20 03:02 - 2010-02-21 01:54 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\nshhttp.dll 2014-07-20 03:01 - 2010-02-21 01:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\httpapi.dll 2014-07-20 03:01 - 2010-02-20 23:30 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2014-07-12 20:56 - 2014-07-12 20:56 - 00031744 _____ () C:\Users\tm\Downloads\Firmenlauf_Bielefeld_Anmeldung2014.xls 2014-07-06 19:07 - 2006-12-14 13:42 - 00069120 ____R (AVM Berlin) C:\Windows\system32\avmadd32.dll ==================== One Month Modified Files and Folders ======= 2014-07-20 20:46 - 2014-07-20 04:10 - 00019207 _____ () C:\Users\tm\Downloads\FRST.txt 2014-07-20 20:46 - 2014-07-20 04:09 - 00000000 ____D () C:\FRST 2014-07-20 20:45 - 2014-07-20 20:45 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (4).exe 2014-07-20 20:45 - 2008-03-30 15:28 - 00000412 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{7DE789EB-2CEE-4FAA-A54E-B1DE1CF3B6DF}.job 2014-07-20 20:45 - 2008-01-25 05:31 - 00000434 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{D9B30BB4-63C0-47D4-A444-A174F9308500}.job 2014-07-20 20:44 - 2014-07-20 20:44 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (6).exe 2014-07-20 20:44 - 2014-07-20 04:04 - 00000466 _____ () C:\Users\tm\Downloads\defogger_disable.log 2014-07-20 20:43 - 2008-01-25 06:20 - 01084991 _____ () C:\Windows\WindowsUpdate.log 2014-07-20 20:40 - 2011-05-29 04:42 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-20 20:40 - 2008-03-30 14:59 - 00000000 ____D () C:\Users\tm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-07-20 20:40 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-20 20:40 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-20 20:40 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-20 20:26 - 2014-07-20 20:26 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (4).exe 2014-07-20 20:20 - 2014-07-20 04:14 - 00035689 _____ () C:\Users\tm\Downloads\Addition.txt 2014-07-20 20:18 - 2011-05-29 04:42 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-20 20:17 - 2014-07-20 20:16 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (3).exe 2014-07-20 20:16 - 2014-07-20 20:16 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (5).exe 2014-07-20 19:45 - 2014-07-20 19:45 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (3).exe 2014-07-20 19:41 - 2014-07-20 19:41 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (2).exe 2014-07-20 19:40 - 2014-07-20 19:40 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (4).exe 2014-07-20 19:27 - 2014-07-20 19:27 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (2).exe 2014-07-20 19:25 - 2014-07-20 19:25 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (1).exe 2014-07-20 19:14 - 2014-07-20 19:13 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (1).exe 2014-07-20 19:11 - 2014-07-20 19:10 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (3).exe 2014-07-20 18:54 - 2012-12-27 20:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-20 17:25 - 2009-08-26 12:57 - 00000000 ____D () C:\Program Files\PC Connectivity Solution 2014-07-20 12:54 - 2007-07-11 00:17 - 00000012 _____ () C:\Windows\bthservsdp.dat 2014-07-20 12:54 - 2006-11-02 15:01 - 00032538 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-20 12:53 - 2014-05-01 20:12 - 00035328 _____ () C:\Users\tm\Documents\infobook.xls 2014-07-20 11:22 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-07-20 11:17 - 2007-07-10 07:07 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE 2014-07-20 11:17 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\system32\XPSViewer 2014-07-20 11:17 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-07-20 11:16 - 2008-08-23 19:22 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-20 11:16 - 2007-07-11 01:28 - 00034152 _____ () C:\Windows\PFRO.log 2014-07-20 04:33 - 2014-07-20 04:33 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357.exe 2014-07-20 04:08 - 2014-07-20 04:08 - 01079808 _____ (Farbar) C:\Users\tm\Downloads\FRST.exe 2014-07-20 04:04 - 2014-07-20 04:04 - 00000000 _____ () C:\Users\tm\defogger_reenable 2014-07-20 04:04 - 2008-03-30 14:58 - 00000000 ____D () C:\Users\tm 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger.exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (2).exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (1).exe 2014-07-20 04:02 - 2014-07-20 03:48 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-20 03:46 - 2006-11-02 12:33 - 01492226 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-20 03:45 - 2014-07-20 03:45 - 00000000 ____D () C:\Windows\SQL9_KB970892_ENU 2014-07-20 03:45 - 2007-07-11 01:13 - 00000000 ____D () C:\Program Files\Microsoft SQL Server 2014-07-20 03:26 - 2014-07-20 03:19 - 00196608 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.perf 2014-07-20 03:26 - 2014-07-20 03:19 - 00065536 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.dpx 2014-07-20 03:26 - 2010-05-29 15:47 - 58916864 _____ () C:\Windows\ocsetup_install_NetFx3.etl 2014-07-20 03:01 - 2011-01-14 02:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-20 02:58 - 2010-05-29 15:35 - 00284204 _____ () C:\Windows\msxml4-KB954430-enu.LOG 2014-07-20 02:56 - 2010-05-29 15:34 - 00288290 _____ () C:\Windows\msxml4-KB973688-enu.LOG 2014-07-18 16:04 - 2013-11-09 06:07 - 00001963 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-12 20:56 - 2014-07-12 20:56 - 00031744 _____ () C:\Users\tm\Downloads\Firmenlauf_Bielefeld_Anmeldung2014.xls 2014-07-10 22:04 - 2008-04-15 23:06 - 00066048 _____ () C:\Users\tm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-08 22:59 - 2012-12-27 20:40 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-07-08 22:59 - 2011-06-27 23:52 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-07-06 19:08 - 2013-02-09 20:46 - 00002963 _____ () C:\Windows\avmadd32.log 2014-07-06 19:07 - 2013-02-09 20:46 - 00000000 ____D () C:\Program Files\FRITZ!Box 2014-06-26 17:38 - 2006-11-02 12:24 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe Some content of TEMP: ==================== C:\Users\tm\AppData\Local\Temp\DataCard_Setup.exe C:\Users\tm\AppData\Local\Temp\ResetDevice.exe C:\Users\tm\AppData\Local\Temp\UNINSTALL.EXE C:\Users\tm\AppData\Local\Temp\_is227F.exe C:\Users\tm\AppData\Local\Temp\_is4847.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-20 20:46 ==================== End Of Log ============================ |
20.07.2014, 21:06 | #2 |
/// the machine /// TB-Ausbilder | Rechner viel langsamer, stürzt häufig ab hi,
__________________So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Scan mit Combofix
__________________ |
20.07.2014, 22:54 | #3 |
| Rechner viel langsamer, stürzt häufig ab - strg+a funktioniert, aber bei strg+c tut sich nix
__________________- raute symbol nicht zu finden es ist soweit: Combofix Logfile: Code:
ATTFilter ComboFix 14-07-20.02 - tm 20.07.2014 23:16:32.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.49.1031.18.1790.843 [GMT 2:00] ausgeführt von:: c:\users\tm\Downloads\ComboFix.exe . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\tm\Documents\~WRL2201.tmp c:\users\tm\Documents\~WRL2292.tmp c:\users\tm\Documents\~WRL2775.tmp c:\users\tm\Documents\~WRL2891.tmp c:\users\tm\Documents\~WRL3393.tmp c:\windows\IsUn0407.exe . . ((((((((((((((((((((((( Dateien erstellt von 2014-06-20 bis 2014-07-20 )))))))))))))))))))))))))))))) . . 2014-07-20 21:30 . 2014-07-20 21:30 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-07-20 02:09 . 2014-07-20 20:21 -------- d-----w- C:\FRST 2014-07-20 01:48 . 2014-07-20 02:02 -------- d-----w- c:\windows\system32\MRT 2014-07-20 01:45 . 2014-07-20 01:45 -------- d-----w- c:\windows\SQL9_KB970892_ENU 2014-07-20 01:27 . 2008-06-20 01:17 97800 ----a-w- c:\windows\system32\infocardapi.dll 2014-07-20 01:27 . 2008-06-20 01:18 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2014-07-20 01:27 . 2008-06-20 01:17 622080 ----a-w- c:\windows\system32\icardagt.exe 2014-07-20 01:27 . 2008-06-20 01:17 37384 ----a-w- c:\windows\system32\infocardcpl.cpl 2014-07-20 01:27 . 2008-06-20 01:17 11264 ----a-w- c:\windows\system32\icardres.dll 2014-07-20 01:27 . 2008-06-20 01:18 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll 2014-07-20 01:27 . 2008-06-20 01:18 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll 2014-07-20 01:27 . 2008-06-20 01:18 326160 ----a-w- c:\windows\system32\PresentationHost.exe 2014-07-20 01:06 . 2008-07-27 18:00 96760 ----a-w- c:\windows\system32\dfshim.dll 2014-07-20 01:05 . 2008-07-27 18:00 282112 ----a-w- c:\windows\system32\mscoree.dll 2014-07-20 01:05 . 2008-07-27 18:00 41984 ----a-w- c:\windows\system32\netfxperf.dll 2014-07-20 01:05 . 2008-07-27 18:00 158720 ----a-w- c:\windows\system32\mscorier.dll 2014-07-20 01:04 . 2008-07-27 18:00 83968 ----a-w- c:\windows\system32\mscories.dll 2014-07-20 01:02 . 2010-02-20 23:54 24064 ----a-w- c:\windows\system32\nshhttp.dll 2014-07-20 01:01 . 2010-02-20 23:51 31232 ----a-w- c:\windows\system32\httpapi.dll 2014-07-20 01:01 . 2010-02-20 21:30 396800 ----a-w- c:\windows\system32\drivers\http.sys 2014-07-06 17:07 . 2006-12-14 11:42 69120 ----a-r- c:\windows\system32\avmadd32.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-07-08 20:59 . 2012-12-27 18:40 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2014-07-08 20:59 . 2011-06-27 21:52 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2014-01-05 22:40 259464 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 2159104] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-26 39408] "S60 PC Suite Tray"="c:\program files\Samsung\Samsung PC Studio 7\PCSuite.exe" [2008-12-05 699392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-23 857648] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-01-08 68640] "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256] "RtHDVCpl"="RtHDVCpl.exe" [2007-06-13 4489216] "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-10 30192] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-14 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-21 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672] "FreePDF Assistant"="c:\program files\FreePDF_XP\fpassist.exe" [2011-02-23 371200] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-01-05 3764024] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "AvgUninstallURL"="start hxxp://www.avg.de/de.special-uninstallation-feedback-lsf?lic=OUxTRlJFRS1WUFVaNy1HMkNNWC1SWFBXQS1QM05aSC05RDIwQy0zN1RT&inst=NzctNDk4MDQzMDcxLVQ1LVhMKzEtQkFSOUcrMS1GTCs5LVFJWDErNC1YMjAxMCsyLUNJQTEwKzItTElDKzctRkwxMCsxLVNQMSsxLVNVUCsy&prod=55&ver=10.0.1325" [?] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Samsung.PCSync"="c:\program files\Samsung\Samsung PC Studio 7\PcSync2.exe" [2008-09-18 1294336] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-24 723760] ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2008-4-12 303104] McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.130\SSScheduler.exe [2013-9-6 273296] Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE -b -l [2001-2-13 83360] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ DSL-Manager.lnk - c:\program files\DSL-Manager\DslMgr.exe [2008-12-20 1085440] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "NoHotStart"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-07-18 14:02 1104200 ----a-w- c:\program files\Google\Chrome\Application\36.0.1985.125\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-07-20 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-27 20:59] . 2014-07-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-05-29 02:42] . 2014-07-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-05-29 02:42] . 2014-07-20 c:\windows\Tasks\User_Feed_Synchronization-{7DE789EB-2CEE-4FAA-A54E-B1DE1CF3B6DF}.job - c:\windows\system32\msfeedssync.exe [2006-11-02 09:45] . 2014-07-20 c:\windows\Tasks\User_Feed_Synchronization-{D9B30BB4-63C0-47D4-A444-A174F9308500}.job - c:\windows\system32\msfeedssync.exe [2006-11-02 09:45] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.de/ uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\ FF - prefs.js: browser.search.selectedEngine - WEB.DE Suche FF - prefs.js: browser.startup.homepage - hxxp://go.web.de/tb/mff_startpage FF - prefs.js: keyword.URL - FF - prefs.js: network.proxy.type - 0 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file) Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) HKCU-Run-AVG-Secure-Search-Update_1213b - c:\users\tm\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\bm_installer.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2014-07-20 23:30 Windows 6.0.6000 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Zeit der Fertigstellung: 2014-07-20 23:36:04 ComboFix-quarantined-files.txt 2014-07-20 21:36 . Vor Suchlauf: 6.744.764.416 Bytes frei Nach Suchlauf: 7.274.266.624 Bytes frei . - - End Of File - - E4F66B5091E1D195BEF15FE22C367460 61A349592C4728853F4A90FF78F7628E |
21.07.2014, 12:18 | #4 |
/// the machine /// TB-Ausbilder | Rechner viel langsamer, stürzt häufig ab Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.07.2014, 22:05 | #5 |
| Rechner viel langsamer, stürzt häufig ab AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 23:40:35 # Aktualisiert 17/07/2014 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium (32 bits) # Benutzername : tm - TM-PC # Gestartet von : C:\Users\tm\Downloads\adwcleaner_3.216.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\11-suche.xml Ordner Gefunden : C:\ProgramData\AVG Security Toolbar Ordner Gefunden : C:\Users\tm\AppData\Local\PackageAware Ordner Gefunden : C:\Users\tm\AppData\LocalLow\AVG Security Toolbar Ordner Gefunden : C:\Users\tm\AppData\LocalLow\pdfforge Ordner Gefunden : C:\Users\tm\AppData\LocalLow\Search Settings Ordner Gefunden : C:\Users\tm\AppData\Roaming\pdfforge ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\AVG Security Toolbar Schlüssel Gefunden : HKCU\Software\AVG Secure Search Schlüssel Gefunden : HKCU\Software\ImInstaller Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{638482BC-3092-42DC-AEA1-735264911A77} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A0B139A7-E8D5-49E8-A7BF-12421E652208} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Schlüssel Gefunden : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B922D405-6D13-4A2B-AE89-08A030DA4402} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30C16B15B255BD349A1157B8A83E2AF9 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1CAE30F47D14B41B5FC8FA53658044 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{638482BC-3092-42DC-AEA1-735264911A77} Schlüssel Gefunden : HKLM\Software\pdfforge Schlüssel Gefunden : HKLM\Software\Uniblue Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] ***** [ Browser ] ***** # AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 23:40:35 # Aktualisiert 17/07/2014 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium (32 bits) # Benutzername : tm - TM-PC # Gestartet von : C:\Users\tm\Downloads\adwcleaner_3.216.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\11-suche.xml Ordner Gefunden : C:\ProgramData\AVG Security Toolbar Ordner Gefunden : C:\Users\tm\AppData\Local\PackageAware Ordner Gefunden : C:\Users\tm\AppData\LocalLow\AVG Security Toolbar Ordner Gefunden : C:\Users\tm\AppData\LocalLow\pdfforge Ordner Gefunden : C:\Users\tm\AppData\LocalLow\Search Settings Ordner Gefunden : C:\Users\tm\AppData\Roaming\pdfforge ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\AVG Security Toolbar Schlüssel Gefunden : HKCU\Software\AVG Secure Search Schlüssel Gefunden : HKCU\Software\ImInstaller Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{638482BC-3092-42DC-AEA1-735264911A77} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A0B139A7-E8D5-49E8-A7BF-12421E652208} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Schlüssel Gefunden : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B922D405-6D13-4A2B-AE89-08A030DA4402} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30C16B15B255BD349A1157B8A83E2AF9 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1CAE30F47D14B41B5FC8FA53658044 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{638482BC-3092-42DC-AEA1-735264911A77} Schlüssel Gefunden : HKLM\Software\pdfforge Schlüssel Gefunden : HKLM\Software\Uniblue Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] ***** [ Browser ] ***** -\\ Internet Explorer v7.0.6000.16982 -\\ Mozilla Firefox v24.0 (en-US) [ Datei : C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\prefs.js ] -\\ Google Chrome v36.0.1985.125 [ Datei : C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [5015 octets] - [21/07/2014 23:40:35] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [5075 octets] ########## AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 23:40:35 # Aktualisiert 17/07/2014 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium (32 bits) # Benutzername : tm - TM-PC # Gestartet von : C:\Users\tm\Downloads\adwcleaner_3.216.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\11-suche.xml Ordner Gefunden : C:\ProgramData\AVG Security Toolbar Ordner Gefunden : C:\Users\tm\AppData\Local\PackageAware Ordner Gefunden : C:\Users\tm\AppData\LocalLow\AVG Security Toolbar Ordner Gefunden : C:\Users\tm\AppData\LocalLow\pdfforge Ordner Gefunden : C:\Users\tm\AppData\LocalLow\Search Settings Ordner Gefunden : C:\Users\tm\AppData\Roaming\pdfforge ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\AVG Security Toolbar Schlüssel Gefunden : HKCU\Software\AVG Secure Search Schlüssel Gefunden : HKCU\Software\ImInstaller Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{638482BC-3092-42DC-AEA1-735264911A77} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A0B139A7-E8D5-49E8-A7BF-12421E652208} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Schlüssel Gefunden : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B922D405-6D13-4A2B-AE89-08A030DA4402} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30C16B15B255BD349A1157B8A83E2AF9 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1CAE30F47D14B41B5FC8FA53658044 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{638482BC-3092-42DC-AEA1-735264911A77} Schlüssel Gefunden : HKLM\Software\pdfforge Schlüssel Gefunden : HKLM\Software\Uniblue Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] ***** [ Browser ] ***** -\\ Internet Explorer v7.0.6000.16982 -\\ Mozilla Firefox v24.0 (en-US) [ Datei : C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\prefs.js ] -\\ Google Chrome v36.0.1985.125 [ Datei : C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [5015 octets] - [21/07/2014 23:40:35] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [5075 octets] ########## AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 23:40:35 # Aktualisiert 17/07/2014 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium (32 bits) # Benutzername : tm - TM-PC # Gestartet von : C:\Users\tm\Downloads\adwcleaner_3.216.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\11-suche.xml Ordner Gefunden : C:\ProgramData\AVG Security Toolbar Ordner Gefunden : C:\Users\tm\AppData\Local\PackageAware Ordner Gefunden : C:\Users\tm\AppData\LocalLow\AVG Security Toolbar Ordner Gefunden : C:\Users\tm\AppData\LocalLow\pdfforge Ordner Gefunden : C:\Users\tm\AppData\LocalLow\Search Settings Ordner Gefunden : C:\Users\tm\AppData\Roaming\pdfforge ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\AVG Security Toolbar Schlüssel Gefunden : HKCU\Software\AVG Secure Search Schlüssel Gefunden : HKCU\Software\ImInstaller Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{638482BC-3092-42DC-AEA1-735264911A77} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A0B139A7-E8D5-49E8-A7BF-12421E652208} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Schlüssel Gefunden : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B922D405-6D13-4A2B-AE89-08A030DA4402} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30C16B15B255BD349A1157B8A83E2AF9 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1CAE30F47D14B41B5FC8FA53658044 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{638482BC-3092-42DC-AEA1-735264911A77} Schlüssel Gefunden : HKLM\Software\pdfforge Schlüssel Gefunden : HKLM\Software\Uniblue Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] ***** [ Browser ] ***** -\\ Internet Explorer v7.0.6000.16982 -\\ Mozilla Firefox v24.0 (en-US) [ Datei : C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\prefs.js ] -\\ Google Chrome v36.0.1985.125 [ Datei : C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [5015 octets] - [21/07/2014 23:40:35] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [5075 octets] ########## -\\ Internet Explorer v7.0.6000.16982 -\\ Mozilla Firefox v24.0 (en-US) [ Datei : C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\prefs.js ] -\\ Google Chrome v36.0.1985.125 [ Datei : C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [5015 octets] - [21/07/2014 23:40:35] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [5075 octets] ########## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.3 (03.23.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by tm on 22.07.2014 at 21:43:15,51 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\features\cb2848362903cd24ea1a37254619a177 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\products\cb2848362903cd24ea1a37254619a177 Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-9990-79A187E26990} ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\tm\AppData\Roaming\mozilla\firefox\profiles\4774widz.default\minidumps [226 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 22.07.2014 at 21:54:14,80 Computer was rebooted End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:21-07-2014 Ran by tm (administrator) on TM-PC on 22-07-2014 22:52:58 Running from C:\Users\tm\Downloads Platform: Microsoft® Windows Vista™ Home Premium (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 7 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe () C:\Program Files\Samsung\Samsung Recovery Solution II\WCScheduler.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe () C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (FUJIFILM Corporation) C:\Program Files\FinePixViewer\QuickDCF2.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe () C:\Program Files\Samsung\Samsung Update Plus\SLUTrayNotifier.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office10\WINWORD.EXE (Microsoft Corporation) C:\Windows\System32\sdclt.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Farbar) C:\Users\tm\Downloads\FRST (6).exe ==================== Registry (Whitelisted) ================== HKLM\...\RunOnce: [AvgUninstallURL] => cmd.exe /c start hxxp://www.avg.de/de.special-uninstallation-feedback-lsf?lic=OUxTRlJFRS1WUFVaNy1HMk (the data entry has 177 more characters). HKU\.DEFAULT\...\Run: [Samsung.PCSync] => C:\Program Files\Samsung\Samsung PC Studio 7\PcSync2.exe [1294336 2008-09-18] (Time Information Services Ltd.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [SpybotSD TeaTimer] => C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-01-26] (Google Inc.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [S60 PC Suite Tray] => C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe [699392 2008-12-06] () AppInit_DLLs: C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2010-06-10] (Google) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ExifLauncher2.lnk ShortcutTarget: ExifLauncher2.lnk -> C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/?LinkId=69157 SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {A8221FCE-87F0-4F05-AFFC-6F4672A6D922} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms} BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll No File BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {A057A204-BACC-4D26-9990-79A187E2698E} - No File DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml FF DefaultSearchEngine: WEB.DE Suche FF SelectedSearchEngine: WEB.DE Suche FF Homepage: hxxp://go.web.de/tb/mff_startpage FF Keyword.URL: user_pref("keyword.URL", ""); FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\webde-suche.xml FF Extension: WEB.DE MailCheck - C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\Extensions\toolbar@web.de.xpi [2012-12-14] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-11-09] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-07-20] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://www.google.com/" CHR DefaultSearchKeyword: web.de CHR DefaultNewTabURL: CHR Extension: (Google Docs) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-09] CHR Extension: (Google Drive) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-09] CHR Extension: (YouTube) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-09] CHR Extension: (Google-Suche) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-09] CHR Extension: (avast! Online Security) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-11-09] CHR Extension: (Google Wallet) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-09] CHR Extension: (Google Mail) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-09] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-09] ========================== Services (Whitelisted) ================= R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [116040 2008-09-10] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-06] (AVAST Software) S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-10] (Google) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45408 2008-11-24] (Microsoft Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44544 2008-12-03] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2008-12-03] (Hewlett-Packard) [File not signed] R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [171040 2007-01-08] () [File not signed] S2 Samsung Update Plus; C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe [73728 2007-06-28] () [File not signed] R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S3 TDslMgrService; C:\Program Files\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) [File not signed] S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-01-06] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2014-01-06] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2013-11-09] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-01-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2014-01-06] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2014-01-06] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2014-01-06] () R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) S3 dsltestSp5; C:\Windows\System32\Drivers\dsltestSp5.sys [26816 2007-09-12] (Printing Communications Assoc., Inc. (PCAUSA)) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2007-07-11] (SAMSUNG ELECTRONICS CO., LTD.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-07-22] (Malwarebytes Corporation) S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation) S3 NPF; C:\Windows\System32\drivers\npf.sys [34064 2007-11-06] (CACE Technologies) U5 AppMgmt; C:\Windows\system32\svchost.exe [22016 2006-11-02] (Microsoft Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] S3 catchme; \??\C:\Users\tm\AppData\Local\Temp\catchme.sys [X] U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [113664 2009-12-08] (Huawei Technologies Co., Ltd.) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-22 22:52 - 2014-07-22 22:52 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (6).exe 2014-07-22 22:32 - 2014-07-22 22:32 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216 (3).exe 2014-07-22 21:54 - 2014-07-22 21:54 - 00001141 _____ () C:\Users\tm\Desktop\JRT.txt 2014-07-22 21:36 - 2014-07-22 21:36 - 00000000 ____D () C:\Windows\ERUNT 2014-07-22 21:35 - 2014-07-22 21:36 - 01016261 _____ (Thisisu) C:\Users\tm\Downloads\JRT.exe 2014-07-22 19:51 - 2014-07-22 19:51 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216 (2).exe 2014-07-22 19:50 - 2014-07-22 19:50 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216 (1).exe 2014-07-21 23:41 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-07-21 23:40 - 2014-07-22 22:35 - 00000000 ____D () C:\AdwCleaner 2014-07-21 23:39 - 2014-07-21 23:39 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216.exe 2014-07-21 23:11 - 2014-07-22 22:09 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-21 23:10 - 2014-07-21 23:10 - 00000899 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-21 23:10 - 2014-07-21 23:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-21 23:10 - 2014-07-21 23:10 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-21 23:10 - 2014-07-21 23:10 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-07-21 23:10 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-21 23:10 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-21 23:10 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-21 23:05 - 2014-07-21 23:06 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\tm\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-20 23:36 - 2014-07-20 23:36 - 00012035 _____ () C:\ComboFix.txt 2014-07-20 23:12 - 2014-07-20 23:36 - 00000000 ____D () C:\ComboFix 2014-07-20 23:12 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-20 23:12 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-20 23:12 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-20 23:12 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-20 23:12 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-20 23:12 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2014-07-20 23:12 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-20 23:12 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-20 23:12 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-20 23:11 - 2014-07-20 23:36 - 00000000 ____D () C:\Qoobox 2014-07-20 23:11 - 2014-07-20 23:33 - 00000000 ____D () C:\Windows\erdnt 2014-07-20 23:07 - 2014-07-20 23:07 - 05561612 ____R (Swearware) C:\Users\tm\Downloads\ComboFix.exe 2014-07-20 22:13 - 2014-07-20 22:13 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (5).exe 2014-07-20 20:45 - 2014-07-20 20:45 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (4).exe 2014-07-20 20:44 - 2014-07-20 20:44 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (6).exe 2014-07-20 20:26 - 2014-07-20 20:26 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (4).exe 2014-07-20 20:16 - 2014-07-20 20:17 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (3).exe 2014-07-20 20:16 - 2014-07-20 20:16 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (5).exe 2014-07-20 19:45 - 2014-07-20 19:45 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (3).exe 2014-07-20 19:41 - 2014-07-20 19:41 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (2).exe 2014-07-20 19:40 - 2014-07-20 19:40 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (4).exe 2014-07-20 19:27 - 2014-07-20 19:27 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (2).exe 2014-07-20 19:25 - 2014-07-20 19:25 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (1).exe 2014-07-20 19:13 - 2014-07-20 19:14 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (1).exe 2014-07-20 19:10 - 2014-07-20 19:11 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (3).exe 2014-07-20 04:33 - 2014-07-20 04:33 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357.exe 2014-07-20 04:14 - 2014-07-20 22:21 - 00035150 _____ () C:\Users\tm\Downloads\Addition.txt 2014-07-20 04:10 - 2014-07-22 22:52 - 00017795 _____ () C:\Users\tm\Downloads\FRST.txt 2014-07-20 04:09 - 2014-07-22 22:53 - 00000000 ____D () C:\FRST 2014-07-20 04:08 - 2014-07-20 04:08 - 01079808 _____ (Farbar) C:\Users\tm\Downloads\FRST.exe 2014-07-20 04:04 - 2014-07-20 20:44 - 00000466 _____ () C:\Users\tm\Downloads\defogger_disable.log 2014-07-20 04:04 - 2014-07-20 04:04 - 00000000 _____ () C:\Users\tm\defogger_reenable 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger.exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (2).exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (1).exe 2014-07-20 03:48 - 2014-07-20 04:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-20 03:45 - 2014-07-20 03:45 - 00000000 ____D () C:\Windows\SQL9_KB970892_ENU 2014-07-20 03:27 - 2008-06-20 03:18 - 00781344 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2014-07-20 03:27 - 2008-06-20 03:18 - 00326160 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2014-07-20 03:27 - 2008-06-20 03:18 - 00105016 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2014-07-20 03:27 - 2008-06-20 03:18 - 00043544 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2014-07-20 03:27 - 2008-06-20 03:17 - 00622080 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-07-20 03:27 - 2008-06-20 03:17 - 00097800 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-07-20 03:27 - 2008-06-20 03:17 - 00037384 _____ (Microsoft Corporation) C:\Windows\system32\infocardcpl.cpl 2014-07-20 03:27 - 2008-06-20 03:17 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-07-20 03:19 - 2014-07-20 03:26 - 00196608 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.perf 2014-07-20 03:19 - 2014-07-20 03:26 - 00065536 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.dpx 2014-07-20 03:06 - 2008-07-27 20:00 - 00096760 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2014-07-20 03:04 - 2008-07-27 20:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-07-20 03:02 - 2010-02-21 01:54 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\nshhttp.dll 2014-07-20 03:01 - 2010-02-21 01:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\httpapi.dll 2014-07-20 03:01 - 2010-02-20 23:30 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2014-07-12 20:56 - 2014-07-12 20:56 - 00031744 _____ () C:\Users\tm\Downloads\Firmenlauf_Bielefeld_Anmeldung2014.xls 2014-07-06 19:07 - 2006-12-14 13:42 - 00069120 ____R (AVM Berlin) C:\Windows\system32\avmadd32.dll ==================== One Month Modified Files and Folders ======= 2014-07-22 22:54 - 2012-12-27 20:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-22 22:53 - 2014-07-20 04:10 - 00017795 _____ () C:\Users\tm\Downloads\FRST.txt 2014-07-22 22:53 - 2014-07-20 04:09 - 00000000 ____D () C:\FRST 2014-07-22 22:52 - 2014-07-22 22:52 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (6).exe 2014-07-22 22:50 - 2008-03-30 15:28 - 00000412 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{7DE789EB-2CEE-4FAA-A54E-B1DE1CF3B6DF}.job 2014-07-22 22:50 - 2008-01-25 05:31 - 00000434 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{D9B30BB4-63C0-47D4-A444-A174F9308500}.job 2014-07-22 22:39 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-22 22:39 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-22 22:35 - 2014-07-21 23:40 - 00000000 ____D () C:\AdwCleaner 2014-07-22 22:32 - 2014-07-22 22:32 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216 (3).exe 2014-07-22 22:18 - 2011-05-29 04:42 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-22 22:09 - 2014-07-21 23:11 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-22 21:54 - 2014-07-22 21:54 - 00001141 _____ () C:\Users\tm\Desktop\JRT.txt 2014-07-22 21:40 - 2008-03-30 14:59 - 00000000 ____D () C:\Users\tm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-07-22 21:39 - 2011-05-29 04:42 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-22 21:39 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-22 21:38 - 2008-01-25 06:20 - 01153491 _____ () C:\Windows\WindowsUpdate.log 2014-07-22 21:38 - 2007-07-11 00:17 - 00000012 _____ () C:\Windows\bthservsdp.dat 2014-07-22 21:38 - 2006-11-02 15:01 - 00032538 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-22 21:37 - 2008-06-15 04:37 - 00002623 _____ () C:\Users\tm\Desktop\Microsoft Word.lnk 2014-07-22 21:36 - 2014-07-22 21:36 - 00000000 ____D () C:\Windows\ERUNT 2014-07-22 21:36 - 2014-07-22 21:35 - 01016261 _____ (Thisisu) C:\Users\tm\Downloads\JRT.exe 2014-07-22 21:14 - 2007-07-11 01:28 - 00035012 _____ () C:\Windows\PFRO.log 2014-07-22 19:51 - 2014-07-22 19:51 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216 (2).exe 2014-07-22 19:50 - 2014-07-22 19:50 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216 (1).exe 2014-07-21 23:39 - 2014-07-21 23:39 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216.exe 2014-07-21 23:10 - 2014-07-21 23:10 - 00000899 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-21 23:10 - 2014-07-21 23:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-21 23:10 - 2014-07-21 23:10 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-21 23:10 - 2014-07-21 23:10 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-07-21 23:06 - 2014-07-21 23:05 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\tm\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-20 23:36 - 2014-07-20 23:36 - 00012035 _____ () C:\ComboFix.txt 2014-07-20 23:36 - 2014-07-20 23:12 - 00000000 ____D () C:\ComboFix 2014-07-20 23:36 - 2014-07-20 23:11 - 00000000 ____D () C:\Qoobox 2014-07-20 23:36 - 2006-11-02 13:18 - 00000000 __RHD () C:\Users\Default 2014-07-20 23:36 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public 2014-07-20 23:33 - 2014-07-20 23:11 - 00000000 ____D () C:\Windows\erdnt 2014-07-20 23:31 - 2006-11-02 12:23 - 00000215 _____ () C:\Windows\system.ini 2014-07-20 23:07 - 2014-07-20 23:07 - 05561612 ____R (Swearware) C:\Users\tm\Downloads\ComboFix.exe 2014-07-20 22:21 - 2014-07-20 04:14 - 00035150 _____ () C:\Users\tm\Downloads\Addition.txt 2014-07-20 22:13 - 2014-07-20 22:13 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (5).exe 2014-07-20 20:45 - 2014-07-20 20:45 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (4).exe 2014-07-20 20:44 - 2014-07-20 20:44 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (6).exe 2014-07-20 20:44 - 2014-07-20 04:04 - 00000466 _____ () C:\Users\tm\Downloads\defogger_disable.log 2014-07-20 20:26 - 2014-07-20 20:26 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (4).exe 2014-07-20 20:17 - 2014-07-20 20:16 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (3).exe 2014-07-20 20:16 - 2014-07-20 20:16 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (5).exe 2014-07-20 19:45 - 2014-07-20 19:45 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (3).exe 2014-07-20 19:41 - 2014-07-20 19:41 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (2).exe 2014-07-20 19:40 - 2014-07-20 19:40 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (4).exe 2014-07-20 19:27 - 2014-07-20 19:27 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (2).exe 2014-07-20 19:25 - 2014-07-20 19:25 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (1).exe 2014-07-20 19:14 - 2014-07-20 19:13 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (1).exe 2014-07-20 19:11 - 2014-07-20 19:10 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (3).exe 2014-07-20 17:25 - 2009-08-26 12:57 - 00000000 ____D () C:\Program Files\PC Connectivity Solution 2014-07-20 12:53 - 2014-05-01 20:12 - 00035328 _____ () C:\Users\tm\Documents\infobook.xls 2014-07-20 11:22 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-07-20 11:17 - 2007-07-10 07:07 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE 2014-07-20 11:17 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\system32\XPSViewer 2014-07-20 11:17 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-07-20 11:16 - 2008-08-23 19:22 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-20 04:33 - 2014-07-20 04:33 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357.exe 2014-07-20 04:08 - 2014-07-20 04:08 - 01079808 _____ (Farbar) C:\Users\tm\Downloads\FRST.exe 2014-07-20 04:04 - 2014-07-20 04:04 - 00000000 _____ () C:\Users\tm\defogger_reenable 2014-07-20 04:04 - 2008-03-30 14:58 - 00000000 ____D () C:\Users\tm 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger.exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (2).exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (1).exe 2014-07-20 04:02 - 2014-07-20 03:48 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-20 03:46 - 2006-11-02 12:33 - 01492226 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-20 03:45 - 2014-07-20 03:45 - 00000000 ____D () C:\Windows\SQL9_KB970892_ENU 2014-07-20 03:45 - 2007-07-11 01:13 - 00000000 ____D () C:\Program Files\Microsoft SQL Server 2014-07-20 03:26 - 2014-07-20 03:19 - 00196608 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.perf 2014-07-20 03:26 - 2014-07-20 03:19 - 00065536 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.dpx 2014-07-20 03:26 - 2010-05-29 15:47 - 58916864 _____ () C:\Windows\ocsetup_install_NetFx3.etl 2014-07-20 03:01 - 2011-01-14 02:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-20 02:58 - 2010-05-29 15:35 - 00284204 _____ () C:\Windows\msxml4-KB954430-enu.LOG 2014-07-20 02:56 - 2010-05-29 15:34 - 00288290 _____ () C:\Windows\msxml4-KB973688-enu.LOG 2014-07-18 16:04 - 2013-11-09 06:07 - 00001963 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-12 20:56 - 2014-07-12 20:56 - 00031744 _____ () C:\Users\tm\Downloads\Firmenlauf_Bielefeld_Anmeldung2014.xls 2014-07-10 22:04 - 2008-04-15 23:06 - 00066048 _____ () C:\Users\tm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-08 22:59 - 2012-12-27 20:40 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-07-08 22:59 - 2011-06-27 23:52 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-07-06 19:08 - 2013-02-09 20:46 - 00002963 _____ () C:\Windows\avmadd32.log 2014-07-06 19:07 - 2013-02-09 20:46 - 00000000 ____D () C:\Program Files\FRITZ!Box 2014-06-26 17:38 - 2006-11-02 12:24 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-22 21:46 ==================== End Of Log ============================ bis bald, euer dieter |
23.07.2014, 15:40 | #6 |
/// the machine /// TB-Ausbilder | Rechner viel langsamer, stürzt häufig abESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Rechner viel langsamer, stürzt häufig ab |
25.07.2014, 21:17 | #7 |
| Rechner viel langsamer, stürzt häufig ab - ich habe den eset scanner seit 16stunden an, er ist jetzt bei 98%, der rechner war im ruhezustand in der nacht, die eset uhr ist aber weitergegangen - er hat bereits 10 infizierte dateien gefunden - ist das üblich, das das so lange dauert? jawoll, es ist soweit: ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=76bdcc2de68d0c43af9f7306214d3c01 # engine=19334 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-07-25 06:24:18 # local_time=2014-07-25 08:24:18 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.0.6000 NT # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 98 17278307 22346467 0 0 # compatibility_mode_1='' # compatibility_mode=5892 16776574 100 100 19101997 243845386 0 0 # scanned=147548 # found=10 # cleaned=0 # scan_time=75375 sh=D39337387252F3C67C67B40452DBD80C7A3CE2A5 ft=1 fh=c9d8a8c0ff01a86e vn="Variante von Win32/Riern.AA Trojaner" ac=I fn="C:\Users\tm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\tm\AppData\Roaming\Adobe\Update\flacor.dat" sh=EF097CD8073F19703A541003CA291A668E8BD219 ft=0 fh=0000000000000000 vn="HTML/Ransom.H Trojaner" ac=I fn="C:\Users\tm\AppData\Local\Mozilla\Firefox\Profiles\4774widz.default\Cache\9\4A\EA7E8d01" sh=C70B34671A8D78751C45EC3DD93E26F9D09ECE31 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\tm\AppData\LocalLow\Sun\Java\Deployment\cache\javapi\v1.0\jar\bzdufrxqcqipxw.jar-27093f0d-28a045e2.zip" sh=4C4EFBE3CF33F25B3BFC407AF2D60986C7707F91 ft=0 fh=0000000000000000 vn="Variante von Java/TrojanDownloader.OpenConnection.MU Trojaner" ac=I fn="C:\Users\tm\AppData\LocalLow\Sun\Java\Deployment\cache\javapi\v1.0\jar\ceptjust.jar-7057084d-4caf34b3.zip" sh=87117AE79FC23396658D402115227BE5AD7E98F0 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\tm\AppData\LocalLow\Sun\Java\Deployment\cache\javapi\v1.0\jar\javaobe.jar-5d04cda4-67996a01.zip" sh=122E9BC17C6D3BA220F10B91F6AE5CC55141890B ft=0 fh=0000000000000000 vn="Java/TrojanDownloader.Agent.NEW Trojaner" ac=I fn="C:\Users\tm\AppData\LocalLow\Sun\Java\Deployment\cache\javapi\v1.0\jar\pul.jar-6b476721-4b601169.zip" sh=8A4DE7D389D7A596C40F2B2D23C1FC141A955EE4 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\tm\AppData\LocalLow\Sun\Java\Deployment\cache\javapi\v1.0\jar\rox.jar-36741d87-53f2352f.zip" sh=51B2020A5C9F59DD907BEA7A33536860B333F35C ft=0 fh=0000000000000000 vn="Java/Agent.DU Trojaner" ac=I fn="C:\Users\tm\AppData\LocalLow\Sun\Java\Deployment\cache\javapi\v1.0\jar\worms.jar-615a03d4-774d41be.zip" sh=BCBD47A2AFB0A7956BBF88F9F625E00D17319CAB ft=1 fh=220efb76e017b9c0 vn="Win32/RegistryBooster evtl. unerwünschte Anwendung" ac=I fn="C:\Users\tm\Documents\registrybooster.exe" sh=1EA929535B44A59063BBE3001195697C7711C73F ft=0 fh=0000000000000000 vn="möglicherweise Variante von Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\f0973.msi" Results of screen317's Security Check version 0.99.85 Windows Vista x86 Out of date service pack!! Internet Explorer 7 Out of date! ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Out of date HijackThis installed! Spybot - Search & Destroy HijackThis 2.0.2 Java 2 Runtime Environment, SE v1.4.2_15 Java version out of Date! Adobe Flash Player 14.0.0.145 Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox 24.0 Firefox out of Date! Google Chrome 35.0.1916.153 Google Chrome 36.0.1985.125 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe ESET ESET Online Scanner OnlineScannerApp.exe Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe Malwarebytes Anti-Malware mbamscheduler.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:24-07-2014 01 Ran by tm (administrator) on TM-PC on 25-07-2014 22:07:24 Running from C:\Users\tm\Downloads Platform: Microsoft® Windows Vista™ Home Premium (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 7 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe () C:\Program Files\Samsung\Samsung Recovery Solution II\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe () C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (FUJIFILM Corporation) C:\Program Files\FinePixViewer\QuickDCF2.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe () C:\Program Files\Samsung\Samsung Update Plus\SLUTrayNotifier.exe (ESET) C:\Program Files\ESET\ESET Online Scanner\OnlineScannerApp.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\System32\sdclt.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office10\WINWORD.EXE (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe () C:\Users\tm\Downloads\SecurityCheck.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Farbar) C:\Users\tm\Downloads\FRST (9).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\RunOnce: [AvgUninstallURL] => cmd.exe /c start hxxp://www.avg.de/de.special-uninstallation-feedback-lsf?lic=OUxTRlJFRS1WUFVaNy1HMk (the data entry has 177 more characters). HKU\.DEFAULT\...\Run: [Samsung.PCSync] => C:\Program Files\Samsung\Samsung PC Studio 7\PcSync2.exe [1294336 2008-09-18] (Time Information Services Ltd.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [SpybotSD TeaTimer] => C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-01-26] (Google Inc.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [S60 PC Suite Tray] => C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe [699392 2008-12-06] () AppInit_DLLs: C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2010-06-10] (Google) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ExifLauncher2.lnk ShortcutTarget: ExifLauncher2.lnk -> C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/?LinkId=69157 SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {A8221FCE-87F0-4F05-AFFC-6F4672A6D922} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms} BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll No File BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {A057A204-BACC-4D26-9990-79A187E2698E} - No File DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml FF DefaultSearchEngine: WEB.DE Suche FF SelectedSearchEngine: WEB.DE Suche FF Homepage: hxxp://go.web.de/tb/mff_startpage FF Keyword.URL: user_pref("keyword.URL", ""); FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\webde-suche.xml FF Extension: WEB.DE MailCheck - C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\Extensions\toolbar@web.de.xpi [2012-12-14] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-11-09] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-07-20] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://www.google.com/" CHR DefaultSearchKeyword: web.de CHR DefaultNewTabURL: CHR Extension: (Google Docs) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-09] CHR Extension: (Google Drive) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-09] CHR Extension: (YouTube) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-09] CHR Extension: (Google-Suche) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-09] CHR Extension: (avast! Online Security) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-11-09] CHR Extension: (Google Wallet) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-09] CHR Extension: (Google Mail) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-09] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-09] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [116040 2008-09-10] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-06] (AVAST Software) S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-10] (Google) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45408 2008-11-24] (Microsoft Corporation) S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44544 2008-12-03] (Hewlett-Packard) [File not signed] S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2008-12-03] (Hewlett-Packard) [File not signed] R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [171040 2007-01-08] () [File not signed] S2 Samsung Update Plus; C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe [73728 2007-06-28] () [File not signed] R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S3 TDslMgrService; C:\Program Files\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) [File not signed] S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-01-06] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2014-01-06] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2013-11-09] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-01-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2014-01-06] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2014-01-06] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2014-01-06] () R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) S3 dsltestSp5; C:\Windows\System32\Drivers\dsltestSp5.sys [26816 2007-09-12] (Printing Communications Assoc., Inc. (PCAUSA)) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2007-07-11] (SAMSUNG ELECTRONICS CO., LTD.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-07-25] (Malwarebytes Corporation) S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation) S3 NPF; C:\Windows\System32\drivers\npf.sys [34064 2007-11-06] (CACE Technologies) U5 AppMgmt; C:\Windows\system32\svchost.exe [22016 2006-11-02] (Microsoft Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] S3 catchme; \??\C:\Users\tm\AppData\Local\Temp\catchme.sys [X] U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [113664 2009-12-08] (Huawei Technologies Co., Ltd.) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-07-25 22:07 - 2014-07-25 22:07 - 01084416 _____ (Farbar) C:\Users\tm\Downloads\FRST (9).exe 2014-07-25 22:05 - 2014-07-25 22:06 - 01084416 _____ (Farbar) C:\Users\tm\Downloads\FRST (8).exe 2014-07-25 22:05 - 2014-07-25 22:05 - 01084416 _____ (Farbar) C:\Users\tm\Downloads\FRST (7).exe 2014-07-25 21:39 - 2014-07-25 21:39 - 00854390 _____ () C:\Users\tm\Downloads\SecurityCheck.exe 2014-07-25 04:19 - 2014-07-20 12:53 - 00477696 _____ () C:\Users\tm\Documents\~WRL1129.tmp 2014-07-24 23:25 - 2014-07-24 23:25 - 02347384 _____ (ESET) C:\Users\tm\Downloads\esetsmartinstaller_deu (2).exe 2014-07-24 22:20 - 2014-07-24 22:20 - 00000000 ____D () C:\Program Files\ESET 2014-07-24 22:16 - 2014-07-24 22:17 - 02347384 _____ (ESET) C:\Users\tm\Downloads\esetsmartinstaller_deu (1).exe 2014-07-24 22:15 - 2014-07-24 22:16 - 02347384 _____ (ESET) C:\Users\tm\Downloads\esetsmartinstaller_deu.exe 2014-07-22 22:52 - 2014-07-22 22:52 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (6).exe 2014-07-22 22:32 - 2014-07-22 22:32 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216 (3).exe 2014-07-22 21:54 - 2014-07-22 21:54 - 00001141 _____ () C:\Users\tm\Desktop\JRT.txt 2014-07-22 21:36 - 2014-07-22 21:36 - 00000000 ____D () C:\Windows\ERUNT 2014-07-22 21:35 - 2014-07-22 21:36 - 01016261 _____ (Thisisu) C:\Users\tm\Downloads\JRT.exe 2014-07-22 19:51 - 2014-07-22 19:51 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216 (2).exe 2014-07-22 19:50 - 2014-07-22 19:50 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216 (1).exe 2014-07-21 23:41 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-07-21 23:40 - 2014-07-22 22:35 - 00000000 ____D () C:\AdwCleaner 2014-07-21 23:39 - 2014-07-21 23:39 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216.exe 2014-07-21 23:11 - 2014-07-25 21:29 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-21 23:10 - 2014-07-21 23:10 - 00000899 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-21 23:10 - 2014-07-21 23:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-21 23:10 - 2014-07-21 23:10 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-21 23:10 - 2014-07-21 23:10 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-07-21 23:10 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-21 23:10 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-21 23:10 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-21 23:05 - 2014-07-21 23:06 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\tm\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-20 23:36 - 2014-07-20 23:36 - 00012035 _____ () C:\ComboFix.txt 2014-07-20 23:12 - 2014-07-20 23:36 - 00000000 ____D () C:\ComboFix 2014-07-20 23:12 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-20 23:12 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-20 23:12 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-20 23:12 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-20 23:12 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-20 23:12 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2014-07-20 23:12 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-20 23:12 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-20 23:12 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-20 23:11 - 2014-07-20 23:36 - 00000000 ____D () C:\Qoobox 2014-07-20 23:11 - 2014-07-20 23:33 - 00000000 ____D () C:\Windows\erdnt 2014-07-20 23:07 - 2014-07-20 23:07 - 05561612 ____R (Swearware) C:\Users\tm\Downloads\ComboFix.exe 2014-07-20 22:13 - 2014-07-20 22:13 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (5).exe 2014-07-20 20:45 - 2014-07-20 20:45 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (4).exe 2014-07-20 20:44 - 2014-07-20 20:44 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (6).exe 2014-07-20 20:26 - 2014-07-20 20:26 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (4).exe 2014-07-20 20:16 - 2014-07-20 20:17 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (3).exe 2014-07-20 20:16 - 2014-07-20 20:16 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (5).exe 2014-07-20 19:45 - 2014-07-20 19:45 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (3).exe 2014-07-20 19:41 - 2014-07-20 19:41 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (2).exe 2014-07-20 19:40 - 2014-07-20 19:40 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (4).exe 2014-07-20 19:27 - 2014-07-20 19:27 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (2).exe 2014-07-20 19:25 - 2014-07-20 19:25 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (1).exe 2014-07-20 19:13 - 2014-07-20 19:14 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (1).exe 2014-07-20 19:10 - 2014-07-20 19:11 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (3).exe 2014-07-20 04:33 - 2014-07-20 04:33 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357.exe 2014-07-20 04:14 - 2014-07-20 22:21 - 00035150 _____ () C:\Users\tm\Downloads\Addition.txt 2014-07-20 04:10 - 2014-07-25 22:07 - 00018936 _____ () C:\Users\tm\Downloads\FRST.txt 2014-07-20 04:09 - 2014-07-25 22:07 - 00000000 ____D () C:\FRST 2014-07-20 04:08 - 2014-07-20 04:08 - 01079808 _____ (Farbar) C:\Users\tm\Downloads\FRST.exe 2014-07-20 04:04 - 2014-07-20 20:44 - 00000466 _____ () C:\Users\tm\Downloads\defogger_disable.log 2014-07-20 04:04 - 2014-07-20 04:04 - 00000000 _____ () C:\Users\tm\defogger_reenable 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger.exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (2).exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (1).exe 2014-07-20 03:48 - 2014-07-20 04:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-20 03:45 - 2014-07-20 03:45 - 00000000 ____D () C:\Windows\SQL9_KB970892_ENU 2014-07-20 03:27 - 2008-06-20 03:18 - 00781344 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2014-07-20 03:27 - 2008-06-20 03:18 - 00326160 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2014-07-20 03:27 - 2008-06-20 03:18 - 00105016 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2014-07-20 03:27 - 2008-06-20 03:18 - 00043544 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2014-07-20 03:27 - 2008-06-20 03:17 - 00622080 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-07-20 03:27 - 2008-06-20 03:17 - 00097800 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-07-20 03:27 - 2008-06-20 03:17 - 00037384 _____ (Microsoft Corporation) C:\Windows\system32\infocardcpl.cpl 2014-07-20 03:27 - 2008-06-20 03:17 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-07-20 03:19 - 2014-07-20 03:26 - 00196608 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.perf 2014-07-20 03:19 - 2014-07-20 03:26 - 00065536 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.dpx 2014-07-20 03:06 - 2008-07-27 20:00 - 00096760 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2014-07-20 03:04 - 2008-07-27 20:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-07-20 03:02 - 2010-02-21 01:54 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\nshhttp.dll 2014-07-20 03:01 - 2010-02-21 01:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\httpapi.dll 2014-07-20 03:01 - 2010-02-20 23:30 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2014-07-12 20:56 - 2014-07-12 20:56 - 00031744 _____ () C:\Users\tm\Downloads\Firmenlauf_Bielefeld_Anmeldung2014.xls 2014-07-06 19:07 - 2006-12-14 13:42 - 00069120 ____R (AVM Berlin) C:\Windows\system32\avmadd32.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-07-25 22:13 - 2014-05-01 20:12 - 00035840 _____ () C:\Users\tm\Documents\infobook.xls 2014-07-25 22:10 - 2014-07-20 04:10 - 00018936 _____ () C:\Users\tm\Downloads\FRST.txt 2014-07-25 22:10 - 2008-03-30 15:28 - 00000412 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{7DE789EB-2CEE-4FAA-A54E-B1DE1CF3B6DF}.job 2014-07-25 22:10 - 2008-01-25 05:31 - 00000434 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{D9B30BB4-63C0-47D4-A444-A174F9308500}.job 2014-07-25 22:07 - 2014-07-25 22:07 - 01084416 _____ (Farbar) C:\Users\tm\Downloads\FRST (9).exe 2014-07-25 22:07 - 2014-07-20 04:09 - 00000000 ____D () C:\FRST 2014-07-25 22:06 - 2014-07-25 22:05 - 01084416 _____ (Farbar) C:\Users\tm\Downloads\FRST (8).exe 2014-07-25 22:05 - 2014-07-25 22:05 - 01084416 _____ (Farbar) C:\Users\tm\Downloads\FRST (7).exe 2014-07-25 21:54 - 2012-12-27 20:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-25 21:39 - 2014-07-25 21:39 - 00854390 _____ () C:\Users\tm\Downloads\SecurityCheck.exe 2014-07-25 21:29 - 2014-07-21 23:11 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-25 21:26 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-25 21:26 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-25 21:18 - 2011-05-29 04:42 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-25 21:14 - 2008-01-25 06:20 - 01233549 _____ () C:\Windows\WindowsUpdate.log 2014-07-24 23:25 - 2014-07-24 23:25 - 02347384 _____ (ESET) C:\Users\tm\Downloads\esetsmartinstaller_deu (2).exe 2014-07-24 23:20 - 2011-05-29 04:42 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-24 23:20 - 2008-03-30 14:59 - 00000000 ____D () C:\Users\tm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-07-24 23:19 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-24 22:20 - 2014-07-24 22:20 - 00000000 ____D () C:\Program Files\ESET 2014-07-24 22:17 - 2014-07-24 22:16 - 02347384 _____ (ESET) C:\Users\tm\Downloads\esetsmartinstaller_deu (1).exe 2014-07-24 22:16 - 2014-07-24 22:15 - 02347384 _____ (ESET) C:\Users\tm\Downloads\esetsmartinstaller_deu.exe 2014-07-24 21:51 - 2007-07-11 00:17 - 00000012 _____ () C:\Windows\bthservsdp.dat 2014-07-24 21:51 - 2006-11-02 15:01 - 00032538 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-22 22:52 - 2014-07-22 22:52 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (6).exe 2014-07-22 22:35 - 2014-07-21 23:40 - 00000000 ____D () C:\AdwCleaner 2014-07-22 22:32 - 2014-07-22 22:32 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216 (3).exe 2014-07-22 21:54 - 2014-07-22 21:54 - 00001141 _____ () C:\Users\tm\Desktop\JRT.txt 2014-07-22 21:37 - 2008-06-15 04:37 - 00002623 _____ () C:\Users\tm\Desktop\Microsoft Word.lnk 2014-07-22 21:36 - 2014-07-22 21:36 - 00000000 ____D () C:\Windows\ERUNT 2014-07-22 21:36 - 2014-07-22 21:35 - 01016261 _____ (Thisisu) C:\Users\tm\Downloads\JRT.exe 2014-07-22 21:14 - 2007-07-11 01:28 - 00035012 _____ () C:\Windows\PFRO.log 2014-07-22 19:51 - 2014-07-22 19:51 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216 (2).exe 2014-07-22 19:50 - 2014-07-22 19:50 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216 (1).exe 2014-07-21 23:39 - 2014-07-21 23:39 - 01354223 _____ () C:\Users\tm\Downloads\adwcleaner_3.216.exe 2014-07-21 23:10 - 2014-07-21 23:10 - 00000899 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-21 23:10 - 2014-07-21 23:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-21 23:10 - 2014-07-21 23:10 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-21 23:10 - 2014-07-21 23:10 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-07-21 23:06 - 2014-07-21 23:05 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\tm\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-20 23:36 - 2014-07-20 23:36 - 00012035 _____ () C:\ComboFix.txt 2014-07-20 23:36 - 2014-07-20 23:12 - 00000000 ____D () C:\ComboFix 2014-07-20 23:36 - 2014-07-20 23:11 - 00000000 ____D () C:\Qoobox 2014-07-20 23:36 - 2006-11-02 13:18 - 00000000 __RHD () C:\Users\Default 2014-07-20 23:36 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public 2014-07-20 23:33 - 2014-07-20 23:11 - 00000000 ____D () C:\Windows\erdnt 2014-07-20 23:31 - 2006-11-02 12:23 - 00000215 _____ () C:\Windows\system.ini 2014-07-20 23:07 - 2014-07-20 23:07 - 05561612 ____R (Swearware) C:\Users\tm\Downloads\ComboFix.exe 2014-07-20 22:21 - 2014-07-20 04:14 - 00035150 _____ () C:\Users\tm\Downloads\Addition.txt 2014-07-20 22:13 - 2014-07-20 22:13 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (5).exe 2014-07-20 20:45 - 2014-07-20 20:45 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (4).exe 2014-07-20 20:44 - 2014-07-20 20:44 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (6).exe 2014-07-20 20:44 - 2014-07-20 04:04 - 00000466 _____ () C:\Users\tm\Downloads\defogger_disable.log 2014-07-20 20:26 - 2014-07-20 20:26 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (4).exe 2014-07-20 20:17 - 2014-07-20 20:16 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (3).exe 2014-07-20 20:16 - 2014-07-20 20:16 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (5).exe 2014-07-20 19:45 - 2014-07-20 19:45 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (3).exe 2014-07-20 19:41 - 2014-07-20 19:41 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (2).exe 2014-07-20 19:40 - 2014-07-20 19:40 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (4).exe 2014-07-20 19:27 - 2014-07-20 19:27 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (2).exe 2014-07-20 19:25 - 2014-07-20 19:25 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (1).exe 2014-07-20 19:14 - 2014-07-20 19:13 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (1).exe 2014-07-20 19:11 - 2014-07-20 19:10 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (3).exe 2014-07-20 17:25 - 2009-08-26 12:57 - 00000000 ____D () C:\Program Files\PC Connectivity Solution 2014-07-20 12:53 - 2014-07-25 04:19 - 00477696 _____ () C:\Users\tm\Documents\~WRL1129.tmp 2014-07-20 11:22 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-07-20 11:17 - 2007-07-10 07:07 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE 2014-07-20 11:17 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\system32\XPSViewer 2014-07-20 11:17 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-07-20 11:16 - 2008-08-23 19:22 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-20 04:33 - 2014-07-20 04:33 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357.exe 2014-07-20 04:08 - 2014-07-20 04:08 - 01079808 _____ (Farbar) C:\Users\tm\Downloads\FRST.exe 2014-07-20 04:04 - 2014-07-20 04:04 - 00000000 _____ () C:\Users\tm\defogger_reenable 2014-07-20 04:04 - 2008-03-30 14:58 - 00000000 ____D () C:\Users\tm 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger.exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (2).exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (1).exe 2014-07-20 04:02 - 2014-07-20 03:48 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-20 03:46 - 2006-11-02 12:33 - 01492226 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-20 03:45 - 2014-07-20 03:45 - 00000000 ____D () C:\Windows\SQL9_KB970892_ENU 2014-07-20 03:45 - 2007-07-11 01:13 - 00000000 ____D () C:\Program Files\Microsoft SQL Server 2014-07-20 03:26 - 2014-07-20 03:19 - 00196608 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.perf 2014-07-20 03:26 - 2014-07-20 03:19 - 00065536 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.dpx 2014-07-20 03:26 - 2010-05-29 15:47 - 58916864 _____ () C:\Windows\ocsetup_install_NetFx3.etl 2014-07-20 03:01 - 2011-01-14 02:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-20 02:58 - 2010-05-29 15:35 - 00284204 _____ () C:\Windows\msxml4-KB954430-enu.LOG 2014-07-20 02:56 - 2010-05-29 15:34 - 00288290 _____ () C:\Windows\msxml4-KB973688-enu.LOG 2014-07-18 16:04 - 2013-11-09 06:07 - 00001963 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-12 20:56 - 2014-07-12 20:56 - 00031744 _____ () C:\Users\tm\Downloads\Firmenlauf_Bielefeld_Anmeldung2014.xls 2014-07-10 22:04 - 2008-04-15 23:06 - 00066048 _____ () C:\Users\tm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-08 22:59 - 2012-12-27 20:40 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-07-08 22:59 - 2011-06-27 23:52 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-07-06 19:08 - 2013-02-09 20:46 - 00002963 _____ () C:\Windows\avmadd32.log 2014-07-06 19:07 - 2013-02-09 20:46 - 00000000 ____D () C:\Program Files\FRITZ!Box 2014-06-26 17:38 - 2006-11-02 12:24 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-24 23:26 ==================== End Of Log ============================ --- --- --- |
26.07.2014, 18:39 | #8 |
/// the machine /// TB-Ausbilder | Rechner viel langsamer, stürzt häufig ab Ja der dauert schon. Java, Adobe, Firefox und unbedingt Windows updaten. Da fehlt ein ganzes Servicepack. Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.07.2014, 22:24 | #9 |
| Rechner viel langsamer, stürzt häufig ab - konnte kein fixlog.txt erstellen; habe folgendes gemacht:- kopieren ins notepad-datei umbenennen in fixlog.txt-speichern unter-desktop-frst fix-ergebnis:no fixlist found - der rechner beginnt erst jetzt nach dem tfc schneller zu werden, auch ms office: war denn insgesamt ein virus schuld an dieser komplexen verlangsamung? - soll ich fortsetzen mit deinen tipps wie defogger und combofix etc.? |
29.07.2014, 11:20 | #10 |
/// the machine /// TB-Ausbilder | Rechner viel langsamer, stürzt häufig ab `Bei dir läuft FRST aus dem Download Ordner, also muss ide fixlist auch in den Download Ordner
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.07.2014, 18:05 | #11 |
| Rechner viel langsamer, stürzt häufig ab - wo finde ich den dowlnload order? - defogger konnte ich auf re-enable stellen - combofix/unnstall konnte nicht gefunden werden erschien nach ok; bin auf C: und habe es umbenannt mit gleichem ergebnis delfix hier: # DelFix v10.7 - Datei am 29/07/2014 um 18:51:33 erstellt # Aktualisiert am 27/04/2014 von Xplode # Benutzer : tm - TM-PC # Betriebssystem : Windows Vista (TM) Home Premium (32 bits) ~ Aktiviere die Benutzerkontensteuerung ... OK ~ Entferne die Bereinigungsprogramme ... Gelöscht : C:\Qoobox Gelöscht : C:\FRST Gelöscht : C:\AdwCleaner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hijackthis Gelöscht : C:\Program Files\Trend Micro\Hijackthis Gelöscht : C:\ComboFix.txt Gelöscht : C:\Users\tm\Desktop\JRT.txt Gelöscht : C:\Users\tm\Desktop\HijackThis.lnk Gelöscht : C:\Users\tm\Downloads\Addition.txt Gelöscht : C:\Users\tm\Downloads\adwcleaner_3.216 (1).exe Gelöscht : C:\Users\tm\Downloads\adwcleaner_3.216 (2).exe Gelöscht : C:\Users\tm\Downloads\adwcleaner_3.216 (3).exe Gelöscht : C:\Users\tm\Downloads\adwcleaner_3.216.exe Gelöscht : C:\Users\tm\Downloads\ComboFix.exe Gelöscht : C:\Users\tm\Downloads\Defogger (1).exe Gelöscht : C:\Users\tm\Downloads\Defogger (2).exe Gelöscht : C:\Users\tm\Downloads\Defogger (3).exe Gelöscht : C:\Users\tm\Downloads\Defogger (4).exe Gelöscht : C:\Users\tm\Downloads\Defogger (5).exe Gelöscht : C:\Users\tm\Downloads\Defogger (6).exe Gelöscht : C:\Users\tm\Downloads\Defogger (7).exe Gelöscht : C:\Users\tm\Downloads\Defogger (8).exe Gelöscht : C:\Users\tm\Downloads\Defogger.exe Gelöscht : C:\Users\tm\Downloads\defogger_disable.log Gelöscht : C:\Users\tm\Downloads\defogger_enable.log Gelöscht : C:\Users\tm\Downloads\esetsmartinstaller_deu (1).exe Gelöscht : C:\Users\tm\Downloads\esetsmartinstaller_deu (2).exe Gelöscht : C:\Users\tm\Downloads\esetsmartinstaller_deu.exe Gelöscht : C:\Users\tm\Downloads\FRST (1).exe Gelöscht : C:\Users\tm\Downloads\FRST (10).exe Gelöscht : C:\Users\tm\Downloads\FRST (11).exe Gelöscht : C:\Users\tm\Downloads\FRST (12).exe Gelöscht : C:\Users\tm\Downloads\FRST (13).exe Gelöscht : C:\Users\tm\Downloads\FRST (14).exe Gelöscht : C:\Users\tm\Downloads\FRST (2).exe Gelöscht : C:\Users\tm\Downloads\FRST (3).exe Gelöscht : C:\Users\tm\Downloads\FRST (4).exe Gelöscht : C:\Users\tm\Downloads\FRST (5).exe Gelöscht : C:\Users\tm\Downloads\FRST (6).exe Gelöscht : C:\Users\tm\Downloads\FRST (7).exe Gelöscht : C:\Users\tm\Downloads\FRST (8).exe Gelöscht : C:\Users\tm\Downloads\FRST (9).exe Gelöscht : C:\Users\tm\Downloads\FRST.exe Gelöscht : C:\Users\tm\Downloads\FRST.txt Gelöscht : C:\Users\tm\Downloads\JRT.exe Gelöscht : C:\Users\tm\Downloads\SecurityCheck.exe Gelöscht : C:\Users\tm\Downloads\TFC (1).exe Gelöscht : C:\Users\tm\Downloads\TFC (2).exe Gelöscht : C:\Users\tm\Downloads\TFC.exe Gelöscht : C:\Windows\grep.exe Gelöscht : C:\Windows\PEV.exe Gelöscht : C:\Windows\NIRCMD.exe Gelöscht : C:\Windows\MBR.exe Gelöscht : C:\Windows\SED.exe Gelöscht : C:\Windows\SWREG.exe Gelöscht : C:\Windows\SWSC.exe Gelöscht : C:\Windows\SWXCACLS.exe Gelöscht : C:\Windows\Zip.exe Gelöscht : HKLM\SOFTWARE\OldTimer Tools Gelöscht : HKLM\SOFTWARE\AdwCleaner Gelöscht : HKLM\SOFTWARE\Swearware Gelöscht : HKLM\SOFTWARE\TrendMicro\Hijackthis Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hijackthis Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\HijackThis.exe ~ Erstelle ein Backup der Registrierungsdatenbank ... OK ~ Lösche die Wiederherstellungspunkte ... Gelöscht : RP #1262 [ComboFix created restore point | 07/20/2014 21:12:37] Gelöscht : RP #1264 [Windows Update | 07/26/2014 18:54:29] Gelöscht : RP #1265 [Windows Update | 07/27/2014 08:21:44] Gelöscht : RP #1266 [Windows Update | 07/27/2014 08:29:16] Gelöscht : RP #1267 [Windows-Sicherung | 07/27/2014 17:00:35] Ein neuer Wiederherstellungspunkt wurde erstellt ! ~ Stelle die Systemeinstellungen wieder her ... OK ########## - EOF - ########## - gehe nun über zu deinen tipps zur absicherung |
30.07.2014, 13:37 | #12 |
/// the machine /// TB-Ausbilder | Rechner viel langsamer, stürzt häufig ab Im WIndows Explorer, dort ist links oben ein Ordner Downloads. Ich frage mich wie Du FRST gestartet hast wenn Du nicht weißt wo der Download Ordner ist.....
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
25.08.2014, 22:53 | #13 |
| Rechner viel langsamer, stürzt häufig ab - viel schneller ist mein Rechner leider nicht geworden, das Hauptproblem ist, dass google chrome alle 5 Minuten abstürzt, inzwischen nicht mehr auszuhalten! Habe es gelöscht und wieder drauf, aber keine Besserung! Vor Wochen hatte es aber funktioniert; was tun? - Mozilla tuts schon lange nicht; konnte zudem nicht gelöscht werden: Systemsteuerung-Programme-deinstallieren- nix tut sich - seit etlichen Monaten zeigt MS Vista an, das die Arbeitsspeicher voll sei und geleert werden sollte; wie geht das? bis bald Dieter |
26.08.2014, 18:57 | #14 |
/// the machine /// TB-Ausbilder | Rechner viel langsamer, stürzt häufig ab Revo Uninstaller - Download - Filepony damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.google.com/chrome/answer/3296214?hl=de Ist Chrome nun besser?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.08.2014, 23:06 | #15 |
| Rechner viel langsamer, stürzt häufig ab - habe beide Schritte ausgeführt, aber noch immer stürzt chrome ab - ms word braucht öfters ganze 60sek um zu öffnen, oder ist blockiert; furchtbar - es erscheint seit vielen Wochen -Arbeitsspeicher ist voll-! ist das wirklich der Fall? wie kann ich sie denn leeren? ein plug-in (shockwave-flash) funktioniert nicht-plug.in anhalten - ist eben erschienen, schon öfters |
Themen zu Rechner viel langsamer, stürzt häufig ab |
antivirus, desktop, explorer, flash player, google, homepage, html/ransom.h, java/agent.du, java/trojandownloader.agent.new, mozilla, newtab, registry, safer networking, security, services.exe, software, svchost.exe, win32/riern.aa, win32/toolbar.widgi, windows |