|
Alles rund um Windows: Beim Browser öffnen komisches FensterWindows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows. |
04.08.2014, 18:14 | #1 |
| Problem: Beim Browser öffnen komisches Fenster Hallo liebes Trojaner-Board Team, seit einiger Zeit sieht mein Browser Fenster beim öffnen so komisch aus, vielleicht kann mir wer sagen was das ist und wie es wieder weg geht oder ob es sich um Schadsoftware handelt. Schonmal vielen Dank im Voraus!!!!! Win 7 Starter / Google Chrome |
04.08.2014, 21:28 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Beim Browser öffnen komisches Fenster Anleitung / Hilfe Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
05.08.2014, 10:21 | #3 |
| Beim Browser öffnen komisches Fenster Details Hallo lieber Cosinus!
__________________Virenscanner & Malwarebytes hatten keine Funde, finde aber die Logs nicht mehr. AdwCleaner: Code:
ATTFilter # AdwCleaner v2.302 - Datei am 26/06/2013 um 17:09:27 erstellt # Aktualisiert am 06/06/2013 von Xplode # Betriebssystem : Windows 7 Starter Service Pack 1 (32 bits) # Benutzer : Ellen&Falko - NETBOOK # Bootmodus : Normal # Ausgeführt unter : C:\Users\Ellen&Falko\Desktop\adwcleaner2302.exe # Option [Suche] **** [Dienste] **** ***** [Dateien / Ordner] ***** ***** [Registrierungsdatenbank] ***** Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16618 [OK] Die Registrierungsdatenbank ist sauber. -\\ Google Chrome v27.0.1453.116 Datei : C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. -\\ Opera v [Version kann nicht ermittelt werden] Datei : C:\Users\Ellen&Falko\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [1401 octets] - [08/06/2013 21:18:54] AdwCleaner[R2].txt - [1202 octets] - [26/06/2013 17:09:27] AdwCleaner[S1].txt - [7891 octets] - [23/05/2013 12:45:36] AdwCleaner[S2].txt - [1525 octets] - [23/05/2013 19:22:58] ########## EOF - C:\AdwCleaner[R2].txt - [1382 octets] ########## FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:2-08-2014 Ran by Ellen&Falko (administrator) on NETBOOK on 05-08-2014 11:13:45 Running from C:\Users\Ellen&Falko\Desktop Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files\eMachines\Registration\GregHSRW.exe (Acer) C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Google Inc.) C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\prevhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\Run: [Google Update] => C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-04-07] (Google Inc.) HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\Policies\Explorer: [NoWinKeys] 1 HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\Policies\Explorer: [NoRecentDocsHistory] 1 HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\Policies\Explorer: [NoRecentDocsMenu] 1 HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\MountPoints2: {0e13dcec-1f7b-11e3-9a8c-705ab6412390} - D:\AutoRun.exe HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\MountPoints2: {c3674970-8e09-11e2-976a-705ab6412390} - E:\iLinker.exe HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\MountPoints2: {c54660b9-49a8-11e0-8aad-705ab6412390} - D:\NPSAI.exe HKU\S-1-5-21-1161967605-348264692-613214921-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Google Update] => C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-04-07] (Google Inc.) HKU\S-1-5-21-1161967605-348264692-613214921-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: [NoWinKeys] 1 HKU\S-1-5-21-1161967605-348264692-613214921-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: [NoRecentDocsHistory] 1 HKU\S-1-5-21-1161967605-348264692-613214921-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: [NoRecentDocsMenu] 1 HKU\S-1-5-21-1161967605-348264692-613214921-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {0e13dcec-1f7b-11e3-9a8c-705ab6412390} - D:\AutoRun.exe HKU\S-1-5-21-1161967605-348264692-613214921-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {c3674970-8e09-11e2-976a-705ab6412390} - E:\iLinker.exe HKU\S-1-5-21-1161967605-348264692-613214921-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {c54660b9-49a8-11e0-8aad-705ab6412390} - D:\NPSAI.exe BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.gamehitzone.com/?utm_source=FreightTrainSimulator&utm_medium=start HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/$22/ SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1211151.dll (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Ellen&Falko\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) Chrome: ======= CHR HomePage: chrome://newtab CHR StartupUrls: "hxxp://www.google.de/" CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.4.600\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\pdf.dll () CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (PDF-XChange Viewer) - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1211151.dll (Adobe Systems, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) CHR Extension: (WOT) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2013-03-19] CHR Extension: (Adblock Plus) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-08-20] CHR Extension: (Google Wallet) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR StartMenuInternet: Google Chrome - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ePowerSvc; C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe [727584 2009-10-01] (Acer Incorporated) R2 Greg_Service; C:\Program Files\eMachines\Registration\GregHSRW.exe [1150496 2009-08-28] (Acer Incorporated) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation) R2 Updater Service; C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [240160 2009-07-04] (Acer) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 DCamUSBSTK016; C:\Windows\System32\DRIVERS\STK016W2.sys [99476 2003-10-04] (Syntek Ltd.) S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1.sys [24424 2012-12-13] (Windows (R) Win 7 DDK provider) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-08-05] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation) S3 RTL8187; C:\Windows\System32\DRIVERS\rtl8187.sys [375808 2010-01-07] (Realtek Semiconductor Corporation ) S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation) S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation) S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation) S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation) S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation) S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-05 11:03 - 2014-08-05 11:13 - 00028949 _____ () C:\Users\Ellen&Falko\Desktop\Addition.txt 2014-08-05 11:00 - 2014-08-05 11:14 - 00013345 _____ () C:\Users\Ellen&Falko\Desktop\FRST.txt 2014-08-05 10:58 - 2014-08-05 11:13 - 00000000 ___DC () C:\FRST 2014-08-05 10:54 - 2014-08-05 10:54 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-05 10:53 - 2014-08-05 10:53 - 00001045 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-05 10:53 - 2014-08-05 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-05 10:52 - 2014-08-05 10:53 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-08-05 10:52 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-05 10:52 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-05 10:52 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-05 10:49 - 2014-08-05 10:49 - 01084928 _____ (Farbar) C:\Users\Ellen&Falko\Desktop\FRST.exe 2014-08-03 18:02 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-08-03 18:02 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-08-03 18:02 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-08-03 18:02 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-08-03 18:02 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-08-03 18:02 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-08-03 18:02 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-08-03 18:01 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-08-03 18:01 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-07-29 19:38 - 2014-08-05 10:41 - 00000672 _____ () C:\Windows\setupact.log 2014-07-29 19:38 - 2014-07-29 19:38 - 00095224 _____ () C:\Users\Ellen&Falko\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-29 19:38 - 2014-07-29 19:38 - 00000000 _____ () C:\Windows\setuperr.log 2014-07-29 19:37 - 2014-07-29 19:38 - 00385264 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-27 17:26 - 2014-07-28 18:07 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Exploit 2014-07-27 17:26 - 2014-07-27 20:47 - 00000000 ____D () C:\ProgramData\Malwarebytes Anti-Exploit 2014-07-26 18:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-07-23 19:11 - 2014-07-23 19:11 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\Machinecode_Technologies 2014-07-23 19:10 - 2014-07-23 19:10 - 00000000 ____D () C:\Program Files\Machinecode Technologies 2014-07-23 19:09 - 2014-07-23 19:09 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\Downloaded Installations 2014-07-16 21:48 - 2014-07-16 21:48 - 00000000 ____D () C:\Users\Ellen&Falko\Desktop\Documents\Fax 2014-07-09 19:25 - 2014-06-19 02:54 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-09 19:25 - 2014-06-19 02:53 - 01766400 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-09 19:25 - 2014-06-19 02:53 - 01141760 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-09 19:25 - 2014-06-19 02:53 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-09 19:25 - 2014-06-19 02:53 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-09 19:25 - 2014-06-19 02:53 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 13732352 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 02863616 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 02051072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 01440768 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-09 19:25 - 2014-06-19 02:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-09 19:25 - 2014-06-19 02:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-09 19:24 - 2014-06-19 02:53 - 14368768 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-09 19:24 - 2014-06-19 02:52 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-07-09 19:23 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-09 19:23 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-09 19:23 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-09 19:22 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-09 19:21 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-07-09 19:21 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-07-09 19:21 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-07-09 19:21 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-07-09 19:21 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-07-09 19:21 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-07-09 19:21 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-07-09 19:20 - 2014-06-30 03:40 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-09 19:20 - 2014-06-30 03:36 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-07-09 19:20 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-07-08 21:20 - 2014-07-08 21:20 - 11204096 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-05 11:14 - 2014-08-05 11:00 - 00013345 _____ () C:\Users\Ellen&Falko\Desktop\FRST.txt 2014-08-05 11:13 - 2014-08-05 11:03 - 00028949 _____ () C:\Users\Ellen&Falko\Desktop\Addition.txt 2014-08-05 11:13 - 2014-08-05 10:58 - 00000000 ___DC () C:\FRST 2014-08-05 10:54 - 2014-08-05 10:54 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-05 10:53 - 2014-08-05 10:53 - 00001045 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-05 10:53 - 2014-08-05 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-05 10:53 - 2014-08-05 10:52 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-08-05 10:49 - 2014-08-05 10:49 - 01084928 _____ (Farbar) C:\Users\Ellen&Falko\Desktop\FRST.exe 2014-08-05 10:49 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-05 10:49 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-05 10:45 - 2012-06-23 15:12 - 01586470 _____ () C:\Windows\WindowsUpdate.log 2014-08-05 10:41 - 2014-07-29 19:38 - 00000672 _____ () C:\Windows\setupact.log 2014-08-05 10:41 - 2012-06-07 18:56 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-05 10:41 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-04 20:39 - 2012-06-07 18:56 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-04 20:37 - 2012-11-29 10:19 - 00001144 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000UA.job 2014-08-04 20:37 - 2012-11-29 10:19 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000Core.job 2014-08-04 20:20 - 2012-08-04 10:33 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-08-04 18:50 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-08-01 19:45 - 2012-07-08 11:25 - 00057856 _____ () C:\Users\Ellen&Falko\Desktop\Rechnungen.xlr 2014-08-01 19:45 - 2010-04-23 13:04 - 00012664 _____ () C:\Users\Ellen&Falko\AppData\Roaming\wklnhst.dat 2014-08-01 19:43 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp 2014-07-29 19:38 - 2014-07-29 19:38 - 00095224 _____ () C:\Users\Ellen&Falko\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-29 19:38 - 2014-07-29 19:38 - 00000000 _____ () C:\Windows\setuperr.log 2014-07-29 19:38 - 2014-07-29 19:37 - 00385264 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-28 18:07 - 2014-07-27 17:26 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Exploit 2014-07-27 20:47 - 2014-07-27 17:26 - 00000000 ____D () C:\ProgramData\Malwarebytes Anti-Exploit 2014-07-27 17:27 - 2012-02-12 23:19 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-27 17:17 - 2014-03-19 19:14 - 00000000 ___DC () C:\AdwCleaner 2014-07-25 18:59 - 2010-06-29 16:39 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-24 19:20 - 2013-03-14 15:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-23 19:29 - 2013-07-02 13:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure Banking 2014-07-23 19:27 - 2011-12-09 21:40 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\CrashDumps 2014-07-23 19:27 - 2007-07-12 03:49 - 00000000 ____D () C:\Windows\Panther 2014-07-23 19:25 - 2013-07-02 13:02 - 00000000 ____D () C:\Program Files\Secure Banking 2014-07-23 19:20 - 2012-12-02 15:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-07-23 19:20 - 2010-06-04 19:46 - 00000000 ____D () C:\Program Files\CCleaner 2014-07-23 19:11 - 2014-07-23 19:11 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\Machinecode_Technologies 2014-07-23 19:10 - 2014-07-23 19:10 - 00000000 ____D () C:\Program Files\Machinecode Technologies 2014-07-23 19:09 - 2014-07-23 19:09 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\Downloaded Installations 2014-07-17 16:01 - 2009-11-13 23:25 - 01644068 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-16 21:48 - 2014-07-16 21:48 - 00000000 ____D () C:\Users\Ellen&Falko\Desktop\Documents\Fax 2014-07-16 21:45 - 2010-07-02 15:23 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Roaming\PhotoScape 2014-07-16 21:41 - 2010-04-18 00:03 - 00000000 ____D () C:\Users\Ellen&Falko 2014-07-09 20:24 - 2014-05-03 20:18 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-09 19:53 - 2013-08-08 13:54 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-09 19:46 - 2010-04-18 12:48 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-08 21:20 - 2014-07-08 21:20 - 11204096 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe 2014-07-08 21:20 - 2012-04-06 23:20 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-07-08 21:20 - 2011-05-16 19:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2012-09-16 18:20 ==================== End Of Log ============================ Addition.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:2-08-2014 Ran by Ellen&Falko at 2014-08-05 11:15:45 Running from C:\Users\Ellen&Falko\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Acrobat.com (HKLM\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated) Acrobat.com (Version: 2.0.0 - Adobe Systems Incorporated) Hidden Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated) Adobe AIR (Version: 3.7.0.2090 - Adobe Systems Incorporated) Hidden Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.10 - Atheros Communications Inc.) Canon MP550 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP550_series) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.15 - Piriform) DivX-Setup (HKLM\...\DivX Setup) (Version: 2.6.3.22 - DivX, LLC) eMachines Power Management (HKLM\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 4.05.3004 - Acer Incorporated) eMachines Recovery Management (HKLM\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Acer Incorporated) eMachines Registration (HKLM\...\eMachines Registration) (Version: 1.02.3006 - Acer Incorporated) eMachines ScreenSaver (HKLM\...\eMachines Screensaver) (Version: 1.1.1027 - Acer Incorporated) eMachines Updater (HKLM\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.01.3017 - Acer Incorporated) Facebook Video Calling 1.2.0.159 (HKLM\...\{7CAC6A44-C3DE-4153-ACA6-7524602C789E}) (Version: 1.2.159 - Skype Limited) Feedback Tool (HKLM\...\{13A5E785-5197-4EAD-8EE3-D660271E49BC}) (Version: 1.2.0 - Microsoft Corporation) Feedback Tool (HKLM\...\{90024193-9F13-4877-89D5-A1CDF0CBBF28}) (Version: 1.1.0 - Microsoft Corporation) Google Chrome (HKCU\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.) Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden Identity Card (HKLM\...\Identity Card) (Version: 1.00.3002 - Acer Incorporated) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Launch Manager (HKLM\...\LManager) (Version: 3.0.01 - eMachines) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Choice Guard (Version: 2.0.48.0 - Microsoft Corporation) Hidden Microsoft Rechner-Plus (HKLM\...\{437C19B3-7E20-4E39-B868-CA6BAA820E1C}) (Version: 1.0.0 - Microsoft) Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM\...\{62F7DA7E-CCCB-439C-A760-00C3926E761F}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Thunderbird 24.6.0 (x86 de) (HKLM\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla) MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden OpenOffice 4.0.0 (HKLM\...\{B28DBCBA-60F8-40ED-B35B-F510C327946C}) (Version: 4.00.9702 - Apache Software Foundation) PDF24 Creator 5.7.0 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.210.0 - Tracker Software Products Ltd) PhotoScape (HKLM\...\PhotoScape) (Version: - ) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5888 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7100.30094 - Realtek Semiconductor Corp.) SAMSUNG Intelli-studio (HKLM\...\Intelli-studio) (Version: 3.1.32.1 - Samsung Electronics Co., Ltd.) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden Video Web Camera (HKLM\...\{51F026FA-5146-4232-A8BA-1364740BD053}) (Version: 0.934 - Ihr Firmenname) Welcome Center (HKLM\...\eMachines Welcome Center) (Version: 1.00.3009 - Acer Incorporated) Windows Live Call (Version: 14.0.8064.0206 - Microsoft Corporation) Hidden Windows Live Communications Platform (Version: 14.0.8064.206 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live Essentials (Version: 14.0.8089.726 - Microsoft Corporation) Hidden Windows Live Fotogalerie (Version: 14.0.8081.709 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{3A999A50-AB25-4A20-90A9-08F71FCE320F}\InprocServer32 -> C:\Windows\system32\spool\DRIVERS\W32X86\3\HPCDMC32.DLL (HP) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\delegate_execute.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{98087D89-B93F-4BCF-A998-AE4D9F607C14}\InprocServer32 -> C:\Windows\system32\spool\DRIVERS\W32X86\3\HPCDMC32.DLL (HP) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{B286F068-5B17-4AE8-989B-8F9A199C47BA}\InprocServer32 -> C:\Windows\system32\spool\DRIVERS\W32X86\3\HPCDMC32.DLL (HP) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\psuser.dll (Google Inc.) ==================== Restore Points ========================= 17-07-2014 13:20:42 Windows Update 20-07-2014 18:10:37 Windows Update 23-07-2014 17:10:05 Installed Secure Banking. 23-07-2014 17:26:07 Removed Secure Banking. 24-07-2014 17:12:11 Windows Update 28-07-2014 16:25:24 Windows Update 31-07-2014 17:22:21 Windows Update 03-08-2014 15:59:44 Windows Update 04-08-2014 17:06:50 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2013-05-26 21:06 - 00892876 ____R C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 www.10sek.com 127.0.0.1 10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 www.123fporn.info 127.0.0.1 123fporn.info 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1FCF7B78-CF2A-404E-AF2F-7A96317DDC40} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-06-07] (Google Inc.) Task: {1FF9449B-629D-496E-A0EA-A107A940FEB3} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000Core => C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe Task: {2A6D4D7E-F53D-4E8D-B966-32D1BB11E447} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1161967605-348264692-613214921-1000 Task: {5A8DD78E-926B-463B-B2FD-DA087C3F2639} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08] (Adobe Systems Incorporated) Task: {97EDEC00-DD7A-43D7-82EA-63EB2AAD6646} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000UA => C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe Task: {BE79EA30-7A70-42AB-A57D-E4C39C5F38FA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-06-07] (Google Inc.) Task: {C283DB9E-1F00-4E17-B2E2-1A37B21165F6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-06-24] (Piriform Ltd) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000Core.job => C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000UA.job => C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-07-18 15:52 - 2014-07-15 11:24 - 08537928 _____ () C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\pdf.dll 2014-07-18 15:52 - 2014-07-15 11:24 - 00353096 _____ () C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll 2014-07-18 15:52 - 2014-07-15 11:24 - 01732936 _____ () C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll 2014-04-11 18:54 - 2014-02-10 13:44 - 04592128 _____ () C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll 2014-04-11 18:54 - 2014-02-10 13:44 - 00112128 _____ () C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\startupreg: DivXMediaServer => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe MSCONFIG\startupreg: DivXUpdate => "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/05/2014 10:53:35 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/05/2014 10:42:15 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/03/2014 05:55:47 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/02/2014 05:41:06 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/02/2014 09:05:56 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/01/2014 07:02:04 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/31/2014 07:05:51 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/30/2014 06:54:10 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/30/2014 03:51:35 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/29/2014 07:38:36 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". System errors: ============= Error: (08/05/2014 10:42:05 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/05/2014 10:41:58 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/04/2014 06:50:49 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/04/2014 06:50:25 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/03/2014 05:55:42 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/03/2014 05:55:30 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/02/2014 05:40:54 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/02/2014 05:40:47 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/02/2014 09:05:46 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/02/2014 09:05:37 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Microsoft Office Sessions: ========================= Error: (08/05/2014 10:53:35 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/05/2014 10:42:15 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/03/2014 05:55:47 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/02/2014 05:41:06 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/02/2014 09:05:56 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/01/2014 07:02:04 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (07/31/2014 07:05:51 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (07/30/2014 06:54:10 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (07/30/2014 03:51:35 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (07/29/2014 07:38:36 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe CodeIntegrity Errors: =================================== Date: 2014-05-26 18:10:51.307 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-26 18:04:16.608 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-26 17:57:37.814 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 21:45:02.436 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 20:15:24.574 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 19:18:28.945 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 18:58:43.042 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 18:52:34.308 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 12:25:47.539 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 12:17:31.253 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 84% Total physical RAM: 1013.95 MB Available physical RAM: 155.06 MB Total Pagefile: 2037.95 MB Available Pagefile: 706.91 MB Total Virtual: 2047.88 MB Available Virtual: 1905.39 MB ==================== Drives ================================ Drive c: (eMachines) (Fixed) (Total:136.95 GB) (Free:109.98 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 42A62716) Partition 1: (Not Active) - (Size=12 GB) - (Type=27) Partition 2: (Active) - (Size=102 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=137 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Viele Liebe Grüße und schonmal ein dickes Dankeschön |
05.08.2014, 11:04 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Lösung: Beim Browser öffnen komisches Fenster Adware/Junkware/Toolbars entfernen (alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen aus den Desktop!) 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
05.08.2014, 19:19 | #5 |
| Wie Beim Browser öffnen komisches Fenster adwCleaner: Code:
ATTFilter # AdwCleaner v3.302 - Bericht erstellt am 05/08/2014 um 18:54:33 # Aktualisiert 30/07/2014 von Xplode # Betriebssystem : Windows 7 Starter Service Pack 1 (32 bits) # Benutzername : Ellen&Falko - NETBOOK # Gestartet von : C:\Users\Ellen&Falko\Desktop\adwcleaner_3.302.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA} ***** [ Browser ] ***** -\\ Internet Explorer v0.0.0.0 -\\ Google Chrome v [ Datei : C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [5449 octets] - [19/03/2014 19:14:16] AdwCleaner[R1].txt - [951 octets] - [20/03/2014 18:49:27] AdwCleaner[R2].txt - [1994 octets] - [26/07/2014 18:13:33] AdwCleaner[R3].txt - [1163 octets] - [27/07/2014 17:15:33] AdwCleaner[R4].txt - [1359 octets] - [05/08/2014 18:51:00] AdwCleaner[S0].txt - [5512 octets] - [19/03/2014 19:16:39] AdwCleaner[S1].txt - [1011 octets] - [20/03/2014 18:52:00] AdwCleaner[S2].txt - [2059 octets] - [26/07/2014 18:42:25] AdwCleaner[S3].txt - [1280 octets] - [05/08/2014 18:54:33] ########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1340 octets] ########## JRT : Hab ich durchlaufen lassen hat aber leine Log Datei erstellt. FRST: Hat nur einen Log erstellt : FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:2-08-2014 Ran by Ellen&Falko (administrator) on NETBOOK on 05-08-2014 20:10:40 Running from C:\Users\Ellen&Falko\Desktop Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files\eMachines\Registration\GregHSRW.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\Run: [Google Update] => C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-04-07] (Google Inc.) HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\Policies\Explorer: [NoWinKeys] 1 HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\Policies\Explorer: [NoRecentDocsHistory] 1 HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\Policies\Explorer: [NoRecentDocsMenu] 1 HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\MountPoints2: {0e13dcec-1f7b-11e3-9a8c-705ab6412390} - D:\AutoRun.exe HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\MountPoints2: {c3674970-8e09-11e2-976a-705ab6412390} - E:\iLinker.exe HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\MountPoints2: {c54660b9-49a8-11e0-8aad-705ab6412390} - D:\NPSAI.exe BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.gamehitzone.com/?utm_source=FreightTrainSimulator&utm_medium=start HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/$22/ SearchScopes: HKLM - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1211151.dll (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Ellen&Falko\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) Chrome: ======= CHR HomePage: chrome://newtab CHR StartupUrls: "hxxp://www.google.de/" CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.4.600\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\pdf.dll () CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (PDF-XChange Viewer) - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1211151.dll (Adobe Systems, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) CHR Extension: (WOT) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2013-03-19] CHR Extension: (Adblock Plus) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-08-20] CHR Extension: (Google Wallet) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR StartMenuInternet: Google Chrome - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ePowerSvc; C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe [727584 2009-10-01] (Acer Incorporated) R2 Greg_Service; C:\Program Files\eMachines\Registration\GregHSRW.exe [1150496 2009-08-28] (Acer Incorporated) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation) S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation) S2 Updater Service; C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [240160 2009-07-04] (Acer) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 DCamUSBSTK016; C:\Windows\System32\DRIVERS\STK016W2.sys [99476 2003-10-04] (Syntek Ltd.) S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1.sys [24424 2012-12-13] (Windows (R) Win 7 DDK provider) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-08-05] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation) S3 RTL8187; C:\Windows\System32\DRIVERS\rtl8187.sys [375808 2010-01-07] (Realtek Semiconductor Corporation ) S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation) S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation) S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation) S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation) S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation) S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-05 20:10 - 2014-08-05 20:10 - 00011535 _____ () C:\Users\Ellen&Falko\Desktop\FRST.txt 2014-08-05 18:55 - 2014-08-05 18:55 - 00000310 _____ () C:\Windows\PFRO.log 2014-08-05 18:49 - 2014-08-05 18:46 - 01361309 _____ () C:\Users\Ellen&Falko\Desktop\adwcleaner_3.302.exe 2014-08-05 18:47 - 2014-08-05 18:48 - 01016261 _____ (Thisisu) C:\Users\Ellen&Falko\Desktop\JRT.exe 2014-08-05 10:58 - 2014-08-05 20:10 - 00000000 ___DC () C:\FRST 2014-08-05 10:54 - 2014-08-05 20:10 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-05 10:53 - 2014-08-05 10:53 - 00001045 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-05 10:53 - 2014-08-05 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-05 10:52 - 2014-08-05 10:53 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-08-05 10:52 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-05 10:52 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-05 10:52 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-05 10:49 - 2014-08-05 10:49 - 01084928 _____ (Farbar) C:\Users\Ellen&Falko\Desktop\FRST.exe 2014-08-03 18:02 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-08-03 18:02 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-08-03 18:02 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-08-03 18:02 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-08-03 18:02 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-08-03 18:02 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-08-03 18:02 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-08-03 18:01 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-08-03 18:01 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-07-29 19:38 - 2014-08-05 19:51 - 00000896 _____ () C:\Windows\setupact.log 2014-07-29 19:38 - 2014-07-29 19:38 - 00095224 _____ () C:\Users\Ellen&Falko\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-29 19:38 - 2014-07-29 19:38 - 00000000 _____ () C:\Windows\setuperr.log 2014-07-29 19:37 - 2014-07-29 19:38 - 00385264 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-27 17:26 - 2014-07-28 18:07 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Exploit 2014-07-27 17:26 - 2014-07-27 20:47 - 00000000 ____D () C:\ProgramData\Malwarebytes Anti-Exploit 2014-07-26 18:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-07-23 19:11 - 2014-07-23 19:11 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\Machinecode_Technologies 2014-07-23 19:10 - 2014-07-23 19:10 - 00000000 ____D () C:\Program Files\Machinecode Technologies 2014-07-23 19:09 - 2014-07-23 19:09 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\Downloaded Installations 2014-07-16 21:48 - 2014-07-16 21:48 - 00000000 ____D () C:\Users\Ellen&Falko\Desktop\Documents\Fax 2014-07-09 19:25 - 2014-06-19 02:54 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-09 19:25 - 2014-06-19 02:53 - 01766400 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-09 19:25 - 2014-06-19 02:53 - 01141760 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-09 19:25 - 2014-06-19 02:53 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-09 19:25 - 2014-06-19 02:53 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-09 19:25 - 2014-06-19 02:53 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 13732352 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 02863616 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 02051072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 01440768 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-09 19:25 - 2014-06-19 02:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-09 19:25 - 2014-06-19 02:52 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-09 19:25 - 2014-06-19 02:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-09 19:24 - 2014-06-19 02:53 - 14368768 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-09 19:24 - 2014-06-19 02:52 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-07-09 19:23 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-09 19:23 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-09 19:23 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-09 19:22 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-09 19:21 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-07-09 19:21 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-07-09 19:21 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-07-09 19:21 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-07-09 19:21 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-07-09 19:21 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-07-09 19:21 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-07-09 19:20 - 2014-06-30 03:40 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-09 19:20 - 2014-06-30 03:36 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-07-09 19:20 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-07-08 21:20 - 2014-07-08 21:20 - 11204096 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-05 20:11 - 2014-08-05 20:10 - 00011535 _____ () C:\Users\Ellen&Falko\Desktop\FRST.txt 2014-08-05 20:10 - 2014-08-05 10:58 - 00000000 ___DC () C:\FRST 2014-08-05 20:10 - 2014-08-05 10:54 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-05 19:58 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-05 19:58 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-05 19:51 - 2014-07-29 19:38 - 00000896 _____ () C:\Windows\setupact.log 2014-08-05 19:51 - 2012-06-07 18:56 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-05 19:51 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-05 19:50 - 2012-06-23 15:12 - 01654930 _____ () C:\Windows\WindowsUpdate.log 2014-08-05 19:39 - 2012-06-07 18:56 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-05 19:37 - 2012-11-29 10:19 - 00001144 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000UA.job 2014-08-05 19:20 - 2012-08-04 10:33 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-08-05 18:55 - 2014-08-05 18:55 - 00000310 _____ () C:\Windows\PFRO.log 2014-08-05 18:54 - 2014-03-19 19:14 - 00000000 ___DC () C:\AdwCleaner 2014-08-05 18:48 - 2014-08-05 18:47 - 01016261 _____ (Thisisu) C:\Users\Ellen&Falko\Desktop\JRT.exe 2014-08-05 18:46 - 2014-08-05 18:49 - 01361309 _____ () C:\Users\Ellen&Falko\Desktop\adwcleaner_3.302.exe 2014-08-05 11:33 - 2012-07-08 11:25 - 00057856 _____ () C:\Users\Ellen&Falko\Desktop\Rechnungen.xlr 2014-08-05 11:33 - 2010-04-23 13:04 - 00012664 _____ () C:\Users\Ellen&Falko\AppData\Roaming\wklnhst.dat 2014-08-05 11:33 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp 2014-08-05 10:53 - 2014-08-05 10:53 - 00001045 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-05 10:53 - 2014-08-05 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-05 10:53 - 2014-08-05 10:52 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-08-05 10:49 - 2014-08-05 10:49 - 01084928 _____ (Farbar) C:\Users\Ellen&Falko\Desktop\FRST.exe 2014-08-04 20:37 - 2012-11-29 10:19 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000Core.job 2014-08-04 18:50 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-07-29 19:38 - 2014-07-29 19:38 - 00095224 _____ () C:\Users\Ellen&Falko\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-29 19:38 - 2014-07-29 19:38 - 00000000 _____ () C:\Windows\setuperr.log 2014-07-29 19:38 - 2014-07-29 19:37 - 00385264 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-28 18:07 - 2014-07-27 17:26 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Exploit 2014-07-27 20:47 - 2014-07-27 17:26 - 00000000 ____D () C:\ProgramData\Malwarebytes Anti-Exploit 2014-07-27 17:27 - 2012-02-12 23:19 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-25 18:59 - 2010-06-29 16:39 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-24 19:20 - 2013-03-14 15:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-23 19:29 - 2013-07-02 13:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure Banking 2014-07-23 19:27 - 2011-12-09 21:40 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\CrashDumps 2014-07-23 19:27 - 2007-07-12 03:49 - 00000000 ____D () C:\Windows\Panther 2014-07-23 19:25 - 2013-07-02 13:02 - 00000000 ____D () C:\Program Files\Secure Banking 2014-07-23 19:20 - 2012-12-02 15:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-07-23 19:20 - 2010-06-04 19:46 - 00000000 ____D () C:\Program Files\CCleaner 2014-07-23 19:11 - 2014-07-23 19:11 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\Machinecode_Technologies 2014-07-23 19:10 - 2014-07-23 19:10 - 00000000 ____D () C:\Program Files\Machinecode Technologies 2014-07-23 19:09 - 2014-07-23 19:09 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\Downloaded Installations 2014-07-17 16:01 - 2009-11-13 23:25 - 01644068 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-16 21:48 - 2014-07-16 21:48 - 00000000 ____D () C:\Users\Ellen&Falko\Desktop\Documents\Fax 2014-07-16 21:45 - 2010-07-02 15:23 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Roaming\PhotoScape 2014-07-16 21:41 - 2010-04-18 00:03 - 00000000 ____D () C:\Users\Ellen&Falko 2014-07-09 20:24 - 2014-05-03 20:18 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-09 19:53 - 2013-08-08 13:54 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-09 19:46 - 2010-04-18 12:48 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-08 21:20 - 2014-07-08 21:20 - 11204096 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe 2014-07-08 21:20 - 2012-04-06 23:20 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-07-08 21:20 - 2011-05-16 19:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl Some content of TEMP: ==================== C:\Users\Ellen&Falko\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2012-09-16 18:20 ==================== End Of Log ============================ |
06.08.2014, 00:38 | #6 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Wo Beim Browser öffnen komisches Fenster Lösung!Zitat:
Wenn nicht schau in das Verzeichnis nach wo du JRT abgelegt hast
__________________ --> Beim Browser öffnen komisches Fenster |
06.08.2014, 17:56 | #7 |
| Beim Browser öffnen komisches Fenster Jup, liegt aufm Dektop. Find nix anderes aufm PC- |
06.08.2014, 23:32 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Beim Browser öffnen komisches Fenster JRT mal neu runterladen auf den Desktop, bestehende (alte) JRT.exe überschreiben und JRT nochmal ausführen
__________________ Logfiles bitte immer in CODE-Tags posten |
07.08.2014, 19:50 | #9 |
| Beim Browser öffnen komisches Fenster Gemacht, läuft auch durch, aber erstellt keine Log :/ Steht überall "Das System kann den angegebenen Pfad nicht finden" Danach schließt sich das Fenster. -> Keine Log Hab auch nen Screenshot: |
07.08.2014, 21:14 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Beim Browser öffnen komisches Fenster [gelöst] Du führst JRT auch per rechtsklick als Admin aus?
__________________ Logfiles bitte immer in CODE-Tags posten |
08.08.2014, 18:04 | #11 |
| Beim Browser öffnen komisches Fenster [gelöst] Ja, hab ich gemacht. |
08.08.2014, 20:09 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Beim Browser öffnen komisches Fenster [gelöst] Hm, dann kein JRT Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Scan klicken
__________________ Logfiles bitte immer in CODE-Tags posten |
09.08.2014, 13:40 | #13 |
| Beim Browser öffnen komisches Fenster [gelöst] FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:2-08-2014 Ran by Ellen&Falko (administrator) on NETBOOK on 09-08-2014 14:37:49 Running from C:\Users\Ellen&Falko\Desktop Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files\eMachines\Registration\GregHSRW.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Acer) C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\Run: [Google Update] => C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-04-07] (Google Inc.) HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\Policies\Explorer: [NoWinKeys] 1 HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\Policies\Explorer: [NoRecentDocsHistory] 1 HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\Policies\Explorer: [NoRecentDocsMenu] 1 HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\MountPoints2: {0e13dcec-1f7b-11e3-9a8c-705ab6412390} - D:\AutoRun.exe HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\MountPoints2: {c3674970-8e09-11e2-976a-705ab6412390} - E:\iLinker.exe HKU\S-1-5-21-1161967605-348264692-613214921-1000\...\MountPoints2: {c54660b9-49a8-11e0-8aad-705ab6412390} - D:\NPSAI.exe BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.gamehitzone.com/?utm_source=FreightTrainSimulator&utm_medium=start HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/$22/ SearchScopes: HKLM - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1211151.dll (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Ellen&Falko\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) Chrome: ======= CHR HomePage: chrome://newtab CHR StartupUrls: "hxxp://www.google.de/" CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.4.600\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\pdf.dll () CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (PDF-XChange Viewer) - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1211151.dll (Adobe Systems, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) CHR Extension: (WOT) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2013-03-19] CHR Extension: (Adblock Plus) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-08-20] CHR Extension: (Google Wallet) - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR StartMenuInternet: Google Chrome - C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ePowerSvc; C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe [727584 2009-10-01] (Acer Incorporated) R2 Greg_Service; C:\Program Files\eMachines\Registration\GregHSRW.exe [1150496 2009-08-28] (Acer Incorporated) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation) R2 Updater Service; C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [240160 2009-07-04] (Acer) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 DCamUSBSTK016; C:\Windows\System32\DRIVERS\STK016W2.sys [99476 2003-10-04] (Syntek Ltd.) S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1.sys [24424 2012-12-13] (Windows (R) Win 7 DDK provider) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-08-09] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation) S3 RTL8187; C:\Windows\System32\DRIVERS\rtl8187.sys [375808 2010-01-07] (Realtek Semiconductor Corporation ) S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation) S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation) S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation) S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation) S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation) S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-09 14:37 - 2014-08-09 14:38 - 00011686 _____ () C:\Users\Ellen&Falko\Desktop\FRST.txt 2014-08-07 21:01 - 2014-08-09 14:24 - 00000168 _____ () C:\Windows\setupact.log 2014-08-07 21:01 - 2014-08-07 21:01 - 00000000 _____ () C:\Windows\setuperr.log 2014-08-07 21:00 - 2014-08-07 21:01 - 00385264 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-07 20:49 - 2014-08-07 20:49 - 00095224 _____ () C:\Users\Ellen&Falko\AppData\Local\GDIPFONTCACHEV1.DAT 2014-08-07 19:54 - 2014-08-07 19:54 - 00002102 _____ () C:\Users\Ellen&Falko\Desktop\Microsoft Security Essentials.lnk 2014-08-07 18:56 - 2014-08-07 18:59 - 01016261 _____ (Thisisu) C:\Users\Ellen&Falko\Desktop\JRT.exe 2014-08-05 18:49 - 2014-08-05 18:46 - 01361309 _____ () C:\Users\Ellen&Falko\Desktop\adwcleaner_3.302.exe 2014-08-05 10:58 - 2014-08-09 14:37 - 00000000 ___DC () C:\FRST 2014-08-05 10:54 - 2014-08-09 14:26 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-05 10:53 - 2014-08-05 10:53 - 00001045 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-05 10:53 - 2014-08-05 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-05 10:52 - 2014-08-05 10:53 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-08-05 10:52 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-05 10:52 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-05 10:52 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-05 10:49 - 2014-08-05 10:49 - 01084928 _____ (Farbar) C:\Users\Ellen&Falko\Desktop\FRST.exe 2014-08-03 18:02 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-08-03 18:02 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-08-03 18:02 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-08-03 18:02 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-08-03 18:02 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-08-03 18:02 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-08-03 18:02 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-08-03 18:01 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-08-03 18:01 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-07-27 17:26 - 2014-07-28 18:07 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Exploit 2014-07-27 17:26 - 2014-07-27 20:47 - 00000000 ____D () C:\ProgramData\Malwarebytes Anti-Exploit 2014-07-26 18:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-07-23 19:11 - 2014-07-23 19:11 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\Machinecode_Technologies 2014-07-23 19:10 - 2014-07-23 19:10 - 00000000 ____D () C:\Program Files\Machinecode Technologies 2014-07-23 19:09 - 2014-07-23 19:09 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\Downloaded Installations 2014-07-16 21:48 - 2014-07-16 21:48 - 00000000 ____D () C:\Users\Ellen&Falko\Desktop\Documents\Fax ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-09 14:39 - 2012-06-07 18:56 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-09 14:38 - 2014-08-09 14:37 - 00011686 _____ () C:\Users\Ellen&Falko\Desktop\FRST.txt 2014-08-09 14:37 - 2014-08-05 10:58 - 00000000 ___DC () C:\FRST 2014-08-09 14:37 - 2012-11-29 10:19 - 00001144 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000UA.job 2014-08-09 14:34 - 2012-06-23 15:12 - 01795176 _____ () C:\Windows\WindowsUpdate.log 2014-08-09 14:33 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-09 14:33 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-09 14:26 - 2014-08-05 10:54 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-09 14:24 - 2014-08-07 21:01 - 00000168 _____ () C:\Windows\setupact.log 2014-08-09 14:24 - 2012-06-07 18:56 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-09 14:24 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-08 20:37 - 2012-11-29 10:19 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000Core.job 2014-08-08 20:20 - 2012-08-04 10:33 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-08-07 21:01 - 2014-08-07 21:01 - 00000000 _____ () C:\Windows\setuperr.log 2014-08-07 21:01 - 2014-08-07 21:00 - 00385264 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-07 20:49 - 2014-08-07 20:49 - 00095224 _____ () C:\Users\Ellen&Falko\AppData\Local\GDIPFONTCACHEV1.DAT 2014-08-07 19:54 - 2014-08-07 19:54 - 00002102 _____ () C:\Users\Ellen&Falko\Desktop\Microsoft Security Essentials.lnk 2014-08-07 18:59 - 2014-08-07 18:56 - 01016261 _____ (Thisisu) C:\Users\Ellen&Falko\Desktop\JRT.exe 2014-08-05 18:54 - 2014-03-19 19:14 - 00000000 ___DC () C:\AdwCleaner 2014-08-05 18:46 - 2014-08-05 18:49 - 01361309 _____ () C:\Users\Ellen&Falko\Desktop\adwcleaner_3.302.exe 2014-08-05 11:33 - 2012-07-08 11:25 - 00057856 _____ () C:\Users\Ellen&Falko\Desktop\Rechnungen.xlr 2014-08-05 11:33 - 2010-04-23 13:04 - 00012664 _____ () C:\Users\Ellen&Falko\AppData\Roaming\wklnhst.dat 2014-08-05 11:33 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp 2014-08-05 10:53 - 2014-08-05 10:53 - 00001045 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-05 10:53 - 2014-08-05 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-05 10:53 - 2014-08-05 10:52 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-08-05 10:49 - 2014-08-05 10:49 - 01084928 _____ (Farbar) C:\Users\Ellen&Falko\Desktop\FRST.exe 2014-08-04 18:50 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-07-28 18:07 - 2014-07-27 17:26 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Exploit 2014-07-27 20:47 - 2014-07-27 17:26 - 00000000 ____D () C:\ProgramData\Malwarebytes Anti-Exploit 2014-07-27 17:27 - 2012-02-12 23:19 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-25 18:59 - 2010-06-29 16:39 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-24 19:20 - 2013-03-14 15:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-23 19:29 - 2013-07-02 13:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure Banking 2014-07-23 19:27 - 2011-12-09 21:40 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\CrashDumps 2014-07-23 19:27 - 2007-07-12 03:49 - 00000000 ____D () C:\Windows\Panther 2014-07-23 19:25 - 2013-07-02 13:02 - 00000000 ____D () C:\Program Files\Secure Banking 2014-07-23 19:20 - 2012-12-02 15:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-07-23 19:20 - 2010-06-04 19:46 - 00000000 ____D () C:\Program Files\CCleaner 2014-07-23 19:11 - 2014-07-23 19:11 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\Machinecode_Technologies 2014-07-23 19:10 - 2014-07-23 19:10 - 00000000 ____D () C:\Program Files\Machinecode Technologies 2014-07-23 19:09 - 2014-07-23 19:09 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Local\Downloaded Installations 2014-07-17 16:01 - 2009-11-13 23:25 - 01644068 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-16 21:48 - 2014-07-16 21:48 - 00000000 ____D () C:\Users\Ellen&Falko\Desktop\Documents\Fax 2014-07-16 21:45 - 2010-07-02 15:23 - 00000000 ____D () C:\Users\Ellen&Falko\AppData\Roaming\PhotoScape 2014-07-16 21:41 - 2010-04-18 00:03 - 00000000 ____D () C:\Users\Ellen&Falko ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2012-09-16 18:20 ==================== End Of Log ============================ Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:2-08-2014 Ran by Ellen&Falko at 2014-08-09 14:39:51 Running from C:\Users\Ellen&Falko\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Acrobat.com (HKLM\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated) Acrobat.com (Version: 2.0.0 - Adobe Systems Incorporated) Hidden Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated) Adobe AIR (Version: 3.7.0.2090 - Adobe Systems Incorporated) Hidden Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.10 - Atheros Communications Inc.) Canon MP550 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP550_series) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.15 - Piriform) DivX-Setup (HKLM\...\DivX Setup) (Version: 2.6.3.22 - DivX, LLC) eMachines Power Management (HKLM\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 4.05.3004 - Acer Incorporated) eMachines Recovery Management (HKLM\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Acer Incorporated) eMachines Registration (HKLM\...\eMachines Registration) (Version: 1.02.3006 - Acer Incorporated) eMachines ScreenSaver (HKLM\...\eMachines Screensaver) (Version: 1.1.1027 - Acer Incorporated) Facebook Video Calling 1.2.0.159 (HKLM\...\{7CAC6A44-C3DE-4153-ACA6-7524602C789E}) (Version: 1.2.159 - Skype Limited) Feedback Tool (HKLM\...\{13A5E785-5197-4EAD-8EE3-D660271E49BC}) (Version: 1.2.0 - Microsoft Corporation) Feedback Tool (HKLM\...\{90024193-9F13-4877-89D5-A1CDF0CBBF28}) (Version: 1.1.0 - Microsoft Corporation) Google Chrome (HKCU\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.) Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden Identity Card (HKLM\...\Identity Card) (Version: 1.00.3002 - Acer Incorporated) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Launch Manager (HKLM\...\LManager) (Version: 3.0.01 - eMachines) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Choice Guard (Version: 2.0.48.0 - Microsoft Corporation) Hidden Microsoft Rechner-Plus (HKLM\...\{437C19B3-7E20-4E39-B868-CA6BAA820E1C}) (Version: 1.0.0 - Microsoft) Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM\...\{62F7DA7E-CCCB-439C-A760-00C3926E761F}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Thunderbird 24.6.0 (x86 de) (HKLM\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla) MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden OpenOffice 4.0.0 (HKLM\...\{B28DBCBA-60F8-40ED-B35B-F510C327946C}) (Version: 4.00.9702 - Apache Software Foundation) PDF24 Creator 5.7.0 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.210.0 - Tracker Software Products Ltd) PhotoScape (HKLM\...\PhotoScape) (Version: - ) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5888 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7100.30094 - Realtek Semiconductor Corp.) SAMSUNG Intelli-studio (HKLM\...\Intelli-studio) (Version: 3.1.32.1 - Samsung Electronics Co., Ltd.) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden Video Web Camera (HKLM\...\{51F026FA-5146-4232-A8BA-1364740BD053}) (Version: 0.934 - Ihr Firmenname) Welcome Center (HKLM\...\eMachines Welcome Center) (Version: 1.00.3009 - Acer Incorporated) Windows Live Call (Version: 14.0.8064.0206 - Microsoft Corporation) Hidden Windows Live Communications Platform (Version: 14.0.8064.206 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live Essentials (Version: 14.0.8089.726 - Microsoft Corporation) Hidden Windows Live Fotogalerie (Version: 14.0.8081.709 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{3A999A50-AB25-4A20-90A9-08F71FCE320F}\InprocServer32 -> C:\Windows\system32\spool\DRIVERS\W32X86\3\HPCDMC32.DLL (HP) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Chrome\Application\36.0.1985.125\delegate_execute.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{98087D89-B93F-4BCF-A998-AE4D9F607C14}\InprocServer32 -> C:\Windows\system32\spool\DRIVERS\W32X86\3\HPCDMC32.DLL (HP) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{B286F068-5B17-4AE8-989B-8F9A199C47BA}\InprocServer32 -> C:\Windows\system32\spool\DRIVERS\W32X86\3\HPCDMC32.DLL (HP) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1161967605-348264692-613214921-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Ellen&Falko\AppData\Local\Google\Update\1.3.24.15\psuser.dll (Google Inc.) ==================== Restore Points ========================= 20-07-2014 18:10:37 Windows Update 23-07-2014 17:10:05 Installed Secure Banking. 23-07-2014 17:26:07 Removed Secure Banking. 24-07-2014 17:12:11 Windows Update 28-07-2014 16:25:24 Windows Update 31-07-2014 17:22:21 Windows Update 03-08-2014 15:59:44 Windows Update 04-08-2014 17:06:50 Windows Update 07-08-2014 17:11:03 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2013-05-26 21:06 - 00892876 ____R C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 www.10sek.com 127.0.0.1 10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 www.123fporn.info 127.0.0.1 123fporn.info 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1FCF7B78-CF2A-404E-AF2F-7A96317DDC40} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-06-07] (Google Inc.) Task: {1FF9449B-629D-496E-A0EA-A107A940FEB3} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000Core => C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe Task: {2A6D4D7E-F53D-4E8D-B966-32D1BB11E447} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1161967605-348264692-613214921-1000 Task: {5A8DD78E-926B-463B-B2FD-DA087C3F2639} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08] (Adobe Systems Incorporated) Task: {97EDEC00-DD7A-43D7-82EA-63EB2AAD6646} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000UA => C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe Task: {BE79EA30-7A70-42AB-A57D-E4C39C5F38FA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-06-07] (Google Inc.) Task: {C283DB9E-1F00-4E17-B2E2-1A37B21165F6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-06-24] (Piriform Ltd) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000Core.job => C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1161967605-348264692-613214921-1000UA.job => C:\Users\Ellen&Falko\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\startupreg: DivXMediaServer => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe MSCONFIG\startupreg: DivXUpdate => "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/09/2014 02:25:19 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/08/2014 07:00:55 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/07/2014 09:01:48 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/07/2014 06:43:30 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/06/2014 06:49:05 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/05/2014 08:28:00 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/05/2014 07:51:44 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/05/2014 07:21:33 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/05/2014 06:57:01 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/05/2014 06:34:47 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1". Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". System errors: ============= Error: (08/09/2014 02:25:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/09/2014 02:24:51 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/08/2014 07:00:36 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/08/2014 07:00:27 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/07/2014 09:03:15 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: Der Dienst Gruppenrichtlinienclient konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (08/07/2014 09:02:10 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/07/2014 09:01:41 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (08/07/2014 08:40:41 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/07/2014 07:36:56 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/07/2014 07:23:41 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Microsoft Office Sessions: ========================= Error: (08/09/2014 02:25:19 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/08/2014 07:00:55 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/07/2014 09:01:48 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/07/2014 06:43:30 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/06/2014 06:49:05 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/05/2014 08:28:00 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/05/2014 07:51:44 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/05/2014 07:21:33 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/05/2014 06:57:01 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe Error: (08/05/2014 06:34:47 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe CodeIntegrity Errors: =================================== Date: 2014-05-26 18:10:51.307 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-26 18:04:16.608 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-26 17:57:37.814 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 21:45:02.436 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 20:15:24.574 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 19:18:28.945 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 18:58:43.042 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 18:52:34.308 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 12:25:47.539 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 12:17:31.253 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 54% Total physical RAM: 1013.95 MB Available physical RAM: 462.36 MB Total Pagefile: 2037.95 MB Available Pagefile: 1239.07 MB Total Virtual: 2047.88 MB Available Virtual: 1915.7 MB ==================== Drives ================================ Drive c: (eMachines) (Fixed) (Total:136.95 GB) (Free:110.66 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 42A62716) Partition 1: (Not Active) - (Size=12 GB) - (Type=27) Partition 2: (Active) - (Size=102 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=137 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
09.08.2014, 23:16 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Beim Browser öffnen komisches Fenster [gelöst] Sieht doch gut aus (ich bin etwas ) TFC - Temp File Cleaner Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
Sieht soweit ok aus Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat. Ist aber nur optional. Um Usertracking zu verhindern kann man gut die Firefox-Erweiterung Ghostery verwenden. Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie ) Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird. Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________ Logfiles bitte immer in CODE-Tags posten |
12.08.2014, 19:36 | #15 |
| Beim Browser öffnen komisches Fenster [gelöst] Sieht gut aus! Vielen lieben Dank für die investierte Zeit & Hilfe Ihr seid die Besten! Danke lieber Cosinus |
Themen zu Beim Browser öffnen komisches Fenster |
browser, einiger, fenster, google, komisch, komisches, schadsoftware, troja, trojaner-board, wieder weg, öffnen |