|
Plagegeister aller Art und deren Bekämpfung: Avira findet TR/Patched.Ren.Gen. - wie kann ich ihn entfernen?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
18.08.2014, 12:49 | #1 |
| Avira findet TR/Patched.Ren.Gen. - wie kann ich ihn entfernen? Hallo liebe Trojaner-Board Community, wie einige andere User bekomme auch ich in letzter Zeit vemehrt die Meldung von Avira-Echtzeitscanner, dass 'TR/Patched.Ren.Gen' gefunden wurde. Ein System-Scan mit „Ad-Aware Antivirus“ brachte keinen Fund, ebensowenig ein weiterer Scan mit „Avira“, lediglich der Echtzeit-Scanner von Avira schlägt an, trägt aber nichts zur Entfernung bei. Durch die Beiträge in diesem Forum weiß ich mittlerweile, dass diese Kombination (Ad-Aware und Avira) Schrott ist Ich hoffe, ihr könnt mir helfen Aus den anderen Beiträgen zu diesem Thema habe ich gesehen, dass ihr die Logs von Avira und FRST braucht und habe diese einkopiert. Allein traue ich mich aber nicht, die weiteren Schritte durchzuführen. Schon mal vielen Dank im Voraus! Code:
ATTFilter Exportierte Ereignisse: 18.08.2014 10:13 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\c2f71a67-b862-4276-9c18-f9bb20882812\tmp000066f6\tmp0000658b' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 18.08.2014 10:12 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\a865893d-f1f6-48e9-ba7e-5b931e0d03f9\tmp00001fe0\tmp00004018' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 18.08.2014 10:12 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\a865893d-f1f6-48e9-ba7e-5b931e0d03f9\tmp00001fe0\tmp00002cb3' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 18.08.2014 10:12 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\58b66c02-8fb8-4f33-b0d5-fc921ed348d9\tmp00004953\tmp00002bd9' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 18.08.2014 10:07 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\4c58bd97-4460-4bea-8e0e-1a33c66fbf02\tmp00001e87\tmp00003fa7' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 18.08.2014 09:01 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\4c58bd97-4460-4bea-8e0e-1a33c66fbf02\tmp00001e87\tmp000024eb' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 17.08.2014 12:02 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\12962880-ca74-406d-a841-db3ac9e61ee7\tmp000041c9\tmp00005f3c' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 17.08.2014 10:29 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\58b66c02-8fb8-4f33-b0d5-fc921ed348d9\tmp00004953\tmp00002bd9' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 16.08.2014 14:10 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\58b66c02-8fb8-4f33-b0d5-fc921ed348d9\tmp00004953\tmp00002bd9' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 16.08.2014 13:13 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\a865893d-f1f6-48e9-ba7e-5b931e0d03f9\tmp00001fe0\tmp00004018' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 16.08.2014 13:10 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\a865893d-f1f6-48e9-ba7e-5b931e0d03f9\tmp00001fe0\tmp00002cb3' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 16.08.2014 13:09 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\a865893d-f1f6-48e9-ba7e-5b931e0d03f9\tmp00001fe0\tmp00002894' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 15.08.2014 12:04 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\58b66c02-8fb8-4f33-b0d5-fc921ed348d9\tmp00004953\tmp00002bd9' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 15.08.2014 12:04 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\58b66c02-8fb8-4f33-b0d5-fc921ed348d9\tmp00004953\tmp000027ba' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 14.08.2014 12:02 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\c2f71a67-b862-4276-9c18-f9bb20882812\tmp000066f6\tmp0000658b' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 14.08.2014 12:01 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\c2f71a67-b862-4276-9c18-f9bb20882812\tmp000066f6\tmp0000617b' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern Urlaub - Rechner aus 02.08.2014 12:03 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\41b42fb1-864c-4439-8612-5065d7f0b6ef\tmp000036e2\tmp000036df' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 02.08.2014 12:02 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\41b42fb1-864c-4439-8612-5065d7f0b6ef\tmp000036e2\tmp000036c1' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 02.08.2014 12:02 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\41b42fb1-864c-4439-8612-5065d7f0b6ef\tmp000036e2\tmp0000356f' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 02.08.2014 12:01 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\Temp\41b42fb1-864c-4439-8612-5065d7f0b6ef\tmp000036e2\tmp00002448' wurde ein Virus oder unerwünschtes Programm 'TR/Patched.Ren.Gen' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:17-08-2014 01 Ran by Kerris (administrator) on KERRIS-PC on 18-08-2014 11:34:13 Running from C:\Users\Kerris\Downloads Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Microsoft Corporation) C:\Windows\System32\lpksetup.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareService.exe (WDC) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (Memeo) C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.) C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE (Adobe Systems Inc.) C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareTray.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (WDC) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Lavasoft.) C:\ProgramData\Search Protection\SearchProtection.exe (Western Digital) C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\WINWORD.EXE (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKU\S-1-5-21-3482048904-2170786804-2948257647-1000\...\MountPoints2: {697d5687-4551-11e2-ab87-00245488a7a7} - "F:\WD SmartWare.exe" autoplay=true Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WDDMStatus.lnk ShortcutTarget: WDDMStatus.lnk -> C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (WDC) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WDSmartWare.lnk ShortcutTarget: WDSmartWare.lnk -> C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe (Western Digital) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://securesearch.lavasoft.com/?source=f439e2c0&tbp=homepage&toolbarid=adawaretb&v=2_5&u=1E7140C6A1A3CD424326EC512D016BCC HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xBFF49BB35ED9CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://lavasoft.blekko.com/ws/?source=f439e2c0&tbp=rbox&toolbarid=adawaretb&u=1E7140C6A1A3CD424326EC512D016BCC&q={searchTerms} BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO: Ad-Aware Security Add-on -> {6c97a91e-4524-4019-86af-2aa2d567bf5c} -> C:\Program Files\adawaretb\adawareDx.dll () BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM - Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll () DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Kerris\AppData\Roaming\Mozilla\Firefox\Profiles\73p1lo5i.default FF Homepage: about:home FF Keyword.URL: hxxp://lavasoft.blekko.com/ws/?source=f439e2c0&tbp=url&toolbarid=adawaretb&u=1E7140C6A1A3CD424326EC512D016BCC&q= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira Browser Safety - C:\Users\Kerris\AppData\Roaming\Mozilla\Firefox\Profiles\73p1lo5i.default\Extensions\abs@avira.com [2014-08-15] FF Extension: Lavasoft Search Plugin - C:\Users\Kerris\AppData\Roaming\Mozilla\Firefox\Profiles\73p1lo5i.default\Extensions\jid1-yZwVFzbsyfMrqQ@jetpack [2012-12-13] FF Extension: Ad-Aware Security Add-on - C:\Users\Kerris\AppData\Roaming\Mozilla\Firefox\Profiles\73p1lo5i.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} [2013-02-26] Chrome: ======= CHR HKLM\...\Chrome\Extension: [lfffjahnfbocnaooecgijfnbpcfekoik] - C:\ProgramData\adawaretb\shortcuts\chrome\adawaretb.crx [2013-02-04] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-08-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-14] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [149296 2014-08-04] (Avira Operations GmbH & Co. KG) S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2012-12-20] (Macrovision Europe Ltd.) [File not signed] R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareService.exe [655352 2014-06-03] () R2 WDDMService; C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [110592 2009-11-13] (WDC) [File not signed] R2 WDSmartWareBackgroundService; C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [20480 2009-06-16] (Memeo) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [97648 2014-06-26] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-02-26] (GFI Software) S3 RRNetCap; C:\Windows\System32\DRIVERS\rrnetcap.sys [31848 2013-03-20] (RapidSolution Software AG) R3 RRNetCapMP; C:\Windows\System32\DRIVERS\rrnetcap.sys [31848 2013-03-20] (RapidSolution Software AG) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) R3 tbhsd; C:\Windows\System32\drivers\tbhsd.sys [39048 2013-03-20] (RapidSolution Software AG) R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [360376 2014-04-22] (BitDefender S.R.L.) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-18 11:34 - 2014-08-18 11:34 - 00011640 _____ () C:\Users\Kerris\Downloads\FRST.txt 2014-08-18 11:33 - 2014-08-18 11:34 - 00000000 ____D () C:\FRST 2014-08-18 11:32 - 2014-08-18 11:33 - 01093632 _____ (Farbar) C:\Users\Kerris\Downloads\FRST.exe 2014-08-16 13:14 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-16 13:14 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-16 13:14 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-16 13:14 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-15 12:25 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-15 12:25 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-15 12:25 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-15 12:25 - 2014-07-25 15:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-15 12:25 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-15 12:25 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-15 12:25 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-15 12:25 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-15 12:25 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-15 12:25 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-15 12:25 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-15 12:25 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-15 12:25 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-15 12:25 - 2014-07-25 14:10 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-15 12:25 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-15 12:25 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-15 12:25 - 2014-07-25 13:59 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-15 12:25 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-15 12:25 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-15 12:25 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-15 12:25 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-15 12:25 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-15 12:25 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-15 12:25 - 2014-07-25 13:09 - 00663040 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-15 12:25 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-15 12:25 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-15 12:25 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-15 12:25 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-15 12:25 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-15 12:25 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-15 12:25 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-15 12:25 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-15 12:25 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2014-08-15 12:25 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2014-08-15 12:21 - 2014-08-07 03:43 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-15 12:21 - 2014-08-07 03:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-15 12:21 - 2014-07-16 04:47 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-15 12:21 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-15 12:21 - 2014-07-16 03:47 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-15 12:21 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-15 12:21 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-15 12:21 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-15 12:21 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-15 12:16 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-15 12:16 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-15 12:16 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-15 12:16 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-15 12:16 - 2014-07-09 03:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-15 12:16 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-15 12:16 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-14 12:23 - 2014-08-14 12:24 - 04574968 _____ (Avira Operations GmbH & Co. KG) C:\Users\Kerris\Downloads\avira_de_av_40136506_dy0dn8cbxc0iax2xb7k0_wd.exe 2014-08-14 12:04 - 2014-08-14 12:27 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-14 12:04 - 2014-08-14 12:26 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-01 11:27 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-08-01 11:27 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-08-01 11:27 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-08-01 11:27 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-08-01 11:27 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-08-01 11:27 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-08-01 11:27 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-08-01 11:27 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-08-01 11:27 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-07-30 17:07 - 2014-07-30 17:08 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-07-29 18:33 - 2014-07-29 20:58 - 611597939 _____ () C:\Users\Kerris\Downloads\00014.MTS.part 2014-07-29 17:43 - 2014-07-29 17:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-07-29 17:43 - 2014-07-29 17:43 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-07-29 17:43 - 2014-07-11 03:02 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-07-29 17:43 - 2014-07-11 02:56 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-07-29 17:43 - 2014-07-11 02:56 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-07-29 17:43 - 2014-07-11 02:55 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-07-23 15:25 - 2014-08-17 10:22 - 00002305 _____ () C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk 2014-07-23 15:25 - 2014-07-23 15:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus 2014-07-23 15:22 - 2014-07-23 15:22 - 00000000 ____D () C:\Program Files\Lavasoft 2014-07-23 15:16 - 2014-07-23 15:16 - 00000000 ____D () C:\Users\Kerris\AppData\Roaming\Lavasoft 2014-07-22 12:08 - 2014-07-22 12:08 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-07-22 12:02 - 2014-07-22 12:02 - 01707144 _____ () C:\Users\Kerris\Downloads\Adaware_Installer(2).exe 2014-07-21 19:08 - 2014-07-21 19:08 - 00000000 ____D () C:\Users\Kerris\restore 2014-07-21 19:04 - 2014-07-21 21:34 - 00000000 ____D () C:\ProgramData\tmp 2014-07-21 19:04 - 2014-07-21 21:34 - 00000000 ____D () C:\ProgramData\hps 2014-07-21 19:04 - 2014-07-21 19:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dm-Fotowelt 2014-07-21 18:35 - 2014-07-21 18:35 - 00000000 ____D () C:\Program Files\dm 2014-07-21 18:33 - 2014-07-21 18:34 - 01627192 _____ () C:\Users\Kerris\Downloads\setup_dm_Fotowelt.exe 2014-07-20 21:31 - 2014-07-20 21:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2014-07-20 21:31 - 2014-07-20 21:31 - 00000000 ____D () C:\Program Files\7-Zip 2014-07-20 21:30 - 2014-07-20 21:30 - 01110476 _____ () C:\Users\Kerris\Downloads\7z920.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-18 11:34 - 2014-08-18 11:34 - 00011640 _____ () C:\Users\Kerris\Downloads\FRST.txt 2014-08-18 11:34 - 2014-08-18 11:33 - 00000000 ____D () C:\FRST 2014-08-18 11:34 - 2013-03-06 20:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-08-18 11:33 - 2014-08-18 11:32 - 01093632 _____ (Farbar) C:\Users\Kerris\Downloads\FRST.exe 2014-08-18 11:08 - 2012-12-11 15:23 - 01800156 _____ () C:\Windows\WindowsUpdate.log 2014-08-17 10:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-08-17 10:27 - 2009-07-14 06:34 - 00026240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-17 10:27 - 2009-07-14 06:34 - 00026240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-17 10:23 - 2012-12-13 20:48 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection 2014-08-17 10:22 - 2014-07-23 15:25 - 00002305 _____ () C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk 2014-08-17 10:22 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-17 10:22 - 2009-07-14 06:39 - 00043847 _____ () C:\Windows\setupact.log 2014-08-17 10:20 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-08-17 10:06 - 2012-12-11 14:53 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-16 13:47 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-08-16 13:37 - 2009-07-14 06:33 - 00348064 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-16 13:35 - 2014-05-07 09:02 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-16 13:20 - 2013-08-20 22:16 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-16 13:20 - 2013-01-01 17:22 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-08-16 13:18 - 2012-12-14 00:04 - 96303304 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-14 12:27 - 2014-08-14 12:04 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-14 12:26 - 2014-08-14 12:04 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-14 12:26 - 2012-12-13 20:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-14 12:26 - 2012-12-13 20:41 - 00000000 ____D () C:\Program Files\Avira 2014-08-14 12:24 - 2014-08-14 12:23 - 04574968 _____ (Avira Operations GmbH & Co. KG) C:\Users\Kerris\Downloads\avira_de_av_40136506_dy0dn8cbxc0iax2xb7k0_wd.exe 2014-08-14 12:04 - 2012-12-13 20:41 - 00000000 ____D () C:\ProgramData\Avira 2014-08-14 11:44 - 2012-12-13 20:26 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-08-07 03:43 - 2014-08-15 12:21 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 03:39 - 2014-08-15 12:21 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-05 09:20 - 2012-12-13 20:30 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-08-01 01:16 - 2014-08-15 12:25 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-30 17:08 - 2014-07-30 17:07 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-07-29 20:58 - 2014-07-29 18:33 - 611597939 _____ () C:\Users\Kerris\Downloads\00014.MTS.part 2014-07-29 17:43 - 2014-07-29 17:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-07-29 17:43 - 2014-07-29 17:43 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-07-29 17:43 - 2013-10-22 19:31 - 00000000 ____D () C:\ProgramData\Oracle 2014-07-29 17:43 - 2013-07-06 17:46 - 00000000 ____D () C:\Program Files\Java 2014-07-26 17:09 - 2013-01-23 23:41 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-25 22:09 - 2013-01-23 23:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-25 16:53 - 2013-05-07 21:38 - 00035848 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-07-25 15:51 - 2014-08-15 12:25 - 17524224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-25 15:04 - 2014-08-15 12:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-25 15:03 - 2014-08-15 12:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-07-25 14:34 - 2014-08-15 12:25 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-25 14:34 - 2014-08-15 12:25 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-25 14:33 - 2014-08-15 12:25 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-07-25 14:30 - 2014-08-15 12:25 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-07-25 14:21 - 2014-08-15 12:25 - 02184704 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-25 14:18 - 2014-08-15 12:25 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-25 14:17 - 2014-08-15 12:25 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-25 14:12 - 2014-08-15 12:25 - 00438784 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-25 14:10 - 2014-08-15 12:25 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-25 14:10 - 2014-08-15 12:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-07-25 14:08 - 2014-08-15 12:25 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-07-25 14:06 - 2014-08-15 12:25 - 04204032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-25 13:59 - 2014-08-15 12:25 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-07-25 13:52 - 2014-08-15 12:25 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-25 13:43 - 2014-08-15 12:25 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-07-25 13:36 - 2014-08-15 12:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-25 13:34 - 2014-08-15 12:25 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-25 13:29 - 2014-08-15 12:25 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-25 13:13 - 2014-08-15 12:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-25 13:09 - 2014-08-15 12:25 - 00663040 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-25 13:07 - 2014-08-15 12:25 - 02001920 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-25 13:07 - 2014-08-15 12:25 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-07-25 13:03 - 2014-08-15 12:25 - 11772928 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-25 12:09 - 2014-08-15 12:25 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-07-25 12:05 - 2014-08-15 12:25 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-25 12:00 - 2014-08-15 12:25 - 01169920 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-23 15:25 - 2014-07-23 15:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus 2014-07-23 15:22 - 2014-07-23 15:22 - 00000000 ____D () C:\Program Files\Lavasoft 2014-07-23 15:16 - 2014-07-23 15:16 - 00000000 ____D () C:\Users\Kerris\AppData\Roaming\Lavasoft 2014-07-23 14:34 - 2013-04-24 20:39 - 00000000 ____D () C:\Users\Kerris\Documents\Hochzeit 2014-07-22 12:08 - 2014-07-22 12:08 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-07-22 12:05 - 2012-12-13 20:48 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-07-22 12:02 - 2014-07-22 12:02 - 01707144 _____ () C:\Users\Kerris\Downloads\Adaware_Installer(2).exe 2014-07-21 21:34 - 2014-07-21 19:04 - 00000000 ____D () C:\ProgramData\tmp 2014-07-21 21:34 - 2014-07-21 19:04 - 00000000 ____D () C:\ProgramData\hps 2014-07-21 19:08 - 2014-07-21 19:08 - 00000000 ____D () C:\Users\Kerris\restore 2014-07-21 19:08 - 2012-12-11 15:23 - 00000000 ____D () C:\Users\Kerris 2014-07-21 19:04 - 2014-07-21 19:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dm-Fotowelt 2014-07-21 18:35 - 2014-07-21 18:35 - 00000000 ____D () C:\Program Files\dm 2014-07-21 18:34 - 2014-07-21 18:33 - 01627192 _____ () C:\Users\Kerris\Downloads\setup_dm_Fotowelt.exe 2014-07-20 21:31 - 2014-07-20 21:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2014-07-20 21:31 - 2014-07-20 21:31 - 00000000 ____D () C:\Program Files\7-Zip 2014-07-20 21:30 - 2014-07-20 21:30 - 01110476 _____ () C:\Users\Kerris\Downloads\7z920.exe Some content of TEMP: ==================== C:\Users\Kerris\AppData\Local\Temp\6394vcr1.dll C:\Users\Kerris\AppData\Local\Temp\7afde6ed-7fe8-4284-9e6e-347f7cc0ed81.exe C:\Users\Kerris\AppData\Local\Temp\AskSLib.dll C:\Users\Kerris\AppData\Local\Temp\avgnt.exe C:\Users\Kerris\AppData\Local\Temp\b49676e9-314c-4c25-b166-0194467ef9b9.exe C:\Users\Kerris\AppData\Local\Temp\d8907f01-92f2-4a36-bbc7-be1d27d05ecb.exe C:\Users\Kerris\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Kerris\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Kerris\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Kerris\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Kerris\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\Kerris\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe C:\Users\Kerris\AppData\Local\Temp\MSETUP4.EXE C:\Users\Kerris\AppData\Local\Temp\ose00000.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-17 10:51 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:17-08-2014 01 Ran by Kerris at 2014-08-18 11:34:54 Running from C:\Users\Kerris\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Ad-Aware Antivirus (Disabled - Out of date) {D87B6541-12A1-DAEA-0033-9B8057AAB996} AS: Ad-Aware Antivirus (Disabled - Out of date) {631A84A5-349B-D564-3A83-A0F22C2DF32B} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Ad-Aware Firewall (Disabled) {E040E464-58CE-DBB2-2B6C-32B5A979FEED} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) Ad-Aware Antivirus (HKLM\...\{CB799B5A-84B8-46A2-BEB5-4FD7D5230361}_AdAwareUpdater) (Version: 11.2.5952.0 - Lavasoft) Ad-Aware Security Add-on (HKLM\...\adawaretb) (Version: 2.5.0.6 - Lavasoft) AdAwareInstaller (Version: 11.2.5952.0 - Lavasoft) Hidden AdAwareUpdater (Version: 11.2.5952.0 - Lavasoft) Hidden Adobe Acrobat 9 Pro - English, Français, Deutsch (HKLM\...\{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}) (Version: 9.5.5 - Adobe Systems) Adobe Acrobat 9 Pro - English, Français, Deutsch (Version: 9.5.5 - Adobe Systems) Hidden Adobe Acrobat 9.5.5 - CPSID_83708 (HKLM\...\{AC76BA86-1033-F400-7760-000000000004}_955) (Version: - Adobe Systems Incorporated) Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Reader XI (11.0.08) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) AntimalwareEngine (Version: 3.0.0.56 - Lavasoft) Hidden Atheros Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros) Audials (HKLM\...\{5B58108C-6290-4172-ADA4-C54E327FEFCE}) (Version: 10.2.14806.600 - Audials AG) Avira (HKLM\...\{e67154a7-9cc5-4167-b782-f3982bc6c70d}) (Version: 1.1.19.30000 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.19.30000 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.6.552 - Avira) Canon Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version: - ) Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data (HKLM\...\Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data) (Version: - ) Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data (HKLM\...\Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data) (Version: - ) Canon Easy-PhotoPrint Pro (HKLM\...\Easy-PhotoPrint Pro) (Version: - ) Canon Easy-WebPrint EX (HKLM\...\Easy-WebPrint EX) (Version: - ) Canon MG6100 series Benutzerregistrierung (HKLM\...\Canon MG6100 series Benutzerregistrierung) (Version: - ) Canon MG6100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6100_series) (Version: - ) Canon MP Navigator EX 4.0 (HKLM\...\MP Navigator EX 4.0) (Version: - ) Canon My Printer (HKLM\...\CanonMyPrinter) (Version: - ) Canon Solution Menu EX (HKLM\...\CanonSolutionMenuEX) (Version: - ) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.4003 - CDBurnerXP) CD-LabelPrint (HKLM\...\MediaNavigation.CDLabelPrint) (Version: - ) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{132D27B8-C656-44BD-8C16-73C54EA8A85F}) (Version: - Microsoft) dm-Fotowelt (HKLM\...\dm-Fotowelt) (Version: 5.1.5 - CEWE Stiftung u Co. KGaA) Easy Display Manager (HKLM\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.) Java 7 Update 65 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.650 - Oracle) Java Auto Updater (Version: 2.1.65.20 - Oracle, Inc.) Hidden Marvell Miniport Driver (HKLM\...\Marvell Miniport Driver) (Version: 11.29.4.3 - Marvell) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 31.0 (x86 de) (HKLM\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10 - NVIDIA Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (Version: - Microsoft) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.15.1 - Synaptics Incorporated) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Excel 2010 (KB2837600) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4ACD847E-547D-493F-9A86-F73EAE1B5174}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0D672F7-883E-4279-8E75-D97A5445AB46}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B9B89E01-5B6B-4F73-BC34-B2C0D8ACB4CD}) (Version: - Microsoft) WD SmartWare (HKLM\...\{232DB76D-4751-41A9-9EC2-CDC0DAC1FAB6}) (Version: 1.2.0.8 - Western Digital) Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) XnView 2.03 (HKLM\...\XnView_is1) (Version: 2.03 - Gougelet Pierre-e) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 01-08-2014 09:26:51 Windows Update 14-08-2014 11:58:46 Geplanter Prüfpunkt 15-08-2014 10:04:24 Windows Update 16-08-2014 11:07:12 Windows Update 17-08-2014 08:02:55 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {64BC5FAA-9AED-4AB6-BBC9-13A38B3C2DA0} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2010-06-08] (Samsung Electronics Co., Ltd.) Task: {69785A6E-39B3-45B4-9360-613426CF0665} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09] (Adobe Systems Incorporated) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2014-06-03 16:12 - 2014-06-03 16:12 - 00655352 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareService.exe 2014-06-03 16:22 - 2014-06-03 16:22 - 00087928 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\boost_thread-vc100-mt-1_55.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00022392 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\boost_system-vc100-mt-1_55.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00030072 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\boost_chrono-vc100-mt-1_55.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00048512 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\boost_date_time-vc100-mt-1_55.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00107904 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\boost_filesystem-vc100-mt-1_55.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 08386920 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareServiceKernel.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00541008 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\SQLite.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 02421064 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\RCF.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00638328 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\boost_regex-vc100-mt-1_55.dll 2014-06-03 16:21 - 2014-06-03 16:21 - 00478056 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareActivation.dll 2014-06-03 16:23 - 2014-06-03 16:23 - 00131920 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\pugixml.dll 2014-06-03 16:21 - 2014-06-03 16:21 - 00300920 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareApplicationUpdater.dll 2014-06-03 16:23 - 2014-06-03 16:23 - 00122704 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\libssh2.dll 2014-06-03 16:23 - 2014-06-03 16:23 - 00148808 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\zlib.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00119656 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareGamingMode.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00087384 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareReset.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00105304 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareTime.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00248184 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareDefinitionsUpdater.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00170376 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareDefinitionsUpdaterScheduler.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00342376 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareIgnoreList.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00205160 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareQuarantine.dll 2014-06-03 16:21 - 2014-06-03 16:21 - 00277872 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareAntiMalwareEngine.dll 2014-06-03 16:21 - 2014-06-03 16:21 - 00174960 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareAntiRootkitEngine.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00367472 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareScannerHistory.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00503648 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareScanner.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00030584 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\boost_timer-vc100-mt-1_55.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00270192 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareScannerScheduler.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00372600 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareRealTimeProtection.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00190824 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareIncompatibles.dll 2014-06-03 16:21 - 2014-06-03 16:21 - 00179552 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareAntiSpam.dll 2014-06-03 16:21 - 2014-06-03 16:21 - 00143720 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareAntiPhishing.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00633712 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareParentalControl.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 01873768 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareWebProtection.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00344944 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareEmailProtection.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00513392 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareNetworkProtection.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00298840 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwarePromo.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00248160 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareFeedback.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00313720 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareThreatWorkAlliance.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00123744 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\SecurityCenter.dll 2014-08-04 14:20 - 2014-08-04 14:20 - 00139056 _____ () C:\Program Files\Avira\My Avira\Avira.OE.NativeCore.dll 2014-08-04 14:20 - 2014-08-04 14:20 - 00067832 _____ () C:\Program Files\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2012-12-12 12:13 - 2006-08-12 13:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll 2014-08-14 12:04 - 2014-08-04 14:20 - 00052472 _____ () C:\Users\Kerris\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2013-05-28 21:58 - 2009-02-27 17:39 - 00019968 _____ () C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.deu 2014-06-03 16:22 - 2014-06-03 16:22 - 06699864 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareTray.exe 2014-06-03 16:22 - 2014-06-03 16:22 - 00405880 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\boost_locale-vc100-mt-1_55.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00310624 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\HtmlFramework.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00056664 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\DllStorage.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00804208 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareTrayDefaultSkin.dll 2014-06-03 16:22 - 2014-06-03 16:22 - 00118104 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\Localization.dll 2009-08-19 16:49 - 2009-08-19 16:49 - 00049152 _____ () C:\Program Files\Western Digital\WD SmartWare\Front Parlor\Memeo.API.dll 2009-07-29 16:24 - 2009-07-29 16:24 - 00504293 _____ () C:\Program Files\Western Digital\WD SmartWare\Front Parlor\sqlite3.DLL 2014-07-30 17:07 - 2014-07-30 17:08 - 03800688 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf 2011-02-18 11:04 - 2011-02-18 11:04 - 00196448 _____ () C:\Program Files\Microsoft Office\Office14\IEAWSDC.DLL ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/18/2014 11:30:13 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/18/2014 11:30:13 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/18/2014 10:56:50 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/18/2014 10:55:45 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/18/2014 10:55:40 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/18/2014 10:55:25 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/17/2014 11:13:22 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/17/2014 11:13:22 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/17/2014 10:52:55 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/17/2014 10:52:11 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". System errors: ============= Error: (08/16/2014 01:22:04 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0902 fehlgeschlagen: Sicherheitsupdate für Windows 7 (KB2978668) Error: (08/16/2014 01:22:03 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0902 fehlgeschlagen: Kumulatives Sicherheitsupdate für Internet Explorer 11 unter Windows 7 (KB2976627) Error: (07/23/2014 07:28:23 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2} Error: (07/21/2014 01:01:10 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (07/21/2014 01:01:02 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (07/21/2014 01:00:53 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (07/21/2014 00:54:53 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (07/21/2014 00:54:45 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (07/21/2014 00:54:37 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (07/21/2014 00:54:29 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Microsoft Office Sessions: ========================= Error: (08/18/2014 11:30:13 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL Error: (08/18/2014 11:30:13 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL Error: (08/18/2014 10:56:50 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Samsung\easy display manager\RunGfxUI64.exe Error: (08/18/2014 10:55:45 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files\Audials\Audials 10\tbhsd\tools64\install.exe Error: (08/18/2014 10:55:40 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files\Audials\Audials 10\tbhsd\tools64\uninstall.exe Error: (08/18/2014 10:55:25 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files\Audials\Audials 10\tbhsd\tools64\cleanup.exe Error: (08/17/2014 11:13:22 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL Error: (08/17/2014 11:13:22 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL Error: (08/17/2014 10:52:55 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Samsung\easy display manager\RunGfxUI64.exe Error: (08/17/2014 10:52:11 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files\Audials\Audials 10\tbhsd\tools64\install.exe CodeIntegrity Errors: =================================== Date: 2013-04-14 04:17:13.025 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-04-14 02:18:12.046 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-04-13 23:50:49.940 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-04-13 23:45:26.990 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-04-13 23:30:38.208 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-04-13 23:29:43.493 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-04-13 23:25:43.372 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-04-13 23:24:50.099 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-04-13 23:22:21.105 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-04-13 23:20:31.388 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5 CPU M 430 @ 2.27GHz Percentage of memory in use: 65% Total physical RAM: 3565.63 MB Available physical RAM: 1230.95 MB Total Pagefile: 7129.54 MB Available Pagefile: 5117.04 MB Total Virtual: 2047.88 MB Available Virtual: 1900.13 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:170.8 GB) (Free:74.5 GB) NTFS Drive d: () (Fixed) (Total:294.86 GB) (Free:224.13 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 2C3A599D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=170.8 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=294.9 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
18.08.2014, 15:26 | #2 |
/// the machine /// TB-Ausbilder | Avira findet TR/Patched.Ren.Gen. - wie kann ich ihn entfernen?__________________
__________________ |
18.08.2014, 20:23 | #3 |
| Avira findet TR/Patched.Ren.Gen. - wie kann ich ihn entfernen? Hallo Schrauber,
__________________vielen Dank für die Antwort. Ich habe jetzt probehalber die Datei C:\Windows\Temp\4c58bd97-4460-4bea-8e0e-1a33c66fbf02\tmp00001e87\tmp00003fa7 bei virustotal hochgeladen und lasse sie scannen. Ist das so richtig und soll ich das dann für jede von Antivir gefundene Datei machen? Das ist die Auswertung von virustotal für diese Datei Code:
ATTFilter SHA256: eef0ed5c0c9cded18d7bd42b3c9117633bc6028d8cfb974c3357c5a7a0fb1c0c Dateiname: tmp00003fa7 Erkennungsrate: 2 / 53 Analyse-Datum: 2014-08-18 15:49:16 UTC ( vor 1 Minute ) Bkav W32.HfsAutoB.5219 20140818 K7GW Virus ( f10001071 ) 20140818 AVG 20140818 AVware 20140818 Ad-Aware 20140818 AegisLab 20140818 Agnitum 20140818 AhnLab-V3 20140818 AntiVir 20140818 Antiy-AVL 20140818 Avast 20140818 Baidu-International 20140818 BitDefender 20140818 ByteHero 20140818 CAT-QuickHeal 20140818 CMC 20140818 ClamAV 20140818 Commtouch 20140818 Comodo 20140818 DrWeb 20140818 ESET-NOD32 20140818 Emsisoft 20140818 F-Prot 20140818 F-Secure 20140818 Fortinet 20140818 GData 20140818 Ikarus 20140818 Jiangmin 20140815 K7AntiVirus 20140818 Kaspersky 20140818 Malwarebytes 20140818 McAfee 20140818 McAfee-GW-Edition 20140818 MicroWorld-eScan 20140818 Microsoft 20140818 NANO-Antivirus 20140818 Norman 20140818 Panda 20140818 Qihoo-360 20140818 Rising 20140818 SUPERAntiSpyware 20140817 Sophos 20140818 Symantec 20140818 Tencent 20140818 TheHacker 20140817 TotalDefense 20140818 TrendMicro 20140818 TrendMicro-HouseCall 20140818 VBA32 20140818 VIPRE 20140818 ViRobot 20140818 Zillya 20140807 nProtect 20140818 MD5 c4aad95a44b87f73cb9d6a834b34a9a8 SHA1 6d8e34009e995cabc36a01590b320ca287bf648d SHA256 eef0ed5c0c9cded18d7bd42b3c9117633bc6028d8cfb974c3357c5a7a0fb1c0c ssdeep 393216:wJAkPVUxrbSHjgq68/AFr56xixzQA7/K4//8+COACVJdqV+MWzfTO4xyOqYubbd:CDxPRETrT7otleG6pN6Q3Mj7 imphash 4dfa9395729497fdfe17dfd86fac8afa File size 24.6 MB ( 25776128 bytes ) File type Win32 DLL Magic literal PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bit TrID Generic Win/DOS Executable (49.9%) DOS Executable Generic (49.8%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%) Tags pedll VirusTotal metadata First submission 2014-08-18 15:49:16 UTC ( vor 4 Minuten ) Last submission 2014-08-18 15:49:16 UTC ( vor 4 Minuten ) Dateinamen tmp00003fa7 Advanced heuristic and reputation engines ClamAV PUA Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: hxxp://www.clamav.net/index.php?s=pua&lang=en . Symantec reputation Suspicious.Insight Hallo Schrauber, hier kommen die restlichen Analysedaten von virustotal. Bei den älteren Avira-Funden sind die Temp-Ordner mittlerweile leer bzw. beinhalten nicht mehr alle gefundenen Dateien. Code:
ATTFilter SHA256: e586fcfa0c09062d53b4f42a0218ba50c73aa682093f73ce911752cdfc2522ad Dateiname: tmp0000658b Erkennungsrate: 2 / 52 Analyse-Datum: 2014-08-18 16:37:02 UTC ( vor 1 Minute ) Bkav W32.HfsAutoB.2125 20140818 K7GW Virus ( f10001071 ) 20140818 AVG 20140818 AVware 20140818 Ad-Aware 20140818 AegisLab 20140818 Agnitum 20140818 AhnLab-V3 20140818 AntiVir 20140818 Antiy-AVL 20140818 Avast 20140818 Baidu-International 20140818 BitDefender 20140818 ByteHero 20140818 CAT-QuickHeal 20140818 CMC 20140818 ClamAV 20140818 Commtouch 20140818 Comodo 20140818 DrWeb 20140818 ESET-NOD32 20140818 Emsisoft 20140818 F-Prot 20140818 F-Secure 20140818 Fortinet 20140818 GData 20140818 Ikarus 20140818 Jiangmin 20140815 K7AntiVirus 20140818 Kaspersky 20140818 Kingsoft 20140818 Malwarebytes 20140818 McAfee 20140818 McAfee-GW-Edition 20140818 MicroWorld-eScan 20140818 Microsoft 20140818 NANO-Antivirus 20140818 Norman 20140818 Panda 20140818 Qihoo-360 20140818 Rising 20140818 SUPERAntiSpyware 20140818 Sophos 20140818 Symantec 20140818 Tencent 20140818 TheHacker 20140817 TotalDefense 20140818 TrendMicro 20140818 TrendMicro-HouseCall 20140818 VBA32 20140818 VIPRE 20140818 ViRobot 20140818 nProtect 20140818 File identification MD5 2547c68e45cf2d6549e5db591c2afeff SHA1 9900f0d2c7ee7200c0784aea2e935f0a50a82f1a SHA256 e586fcfa0c09062d53b4f42a0218ba50c73aa682093f73ce911752cdfc2522ad ssdeep 393216:WqgQS+i0QAbI/A2pXu/e0VI+iJqMU8ahxCu+UjccJ5K1BZzXMURqJXgOIJZJAw6:fTaCGyI7mXXpqeGjbB+MOj7 File size 24.6 MB ( 25776128 bytes ) File type Win32 EXE Magic literal PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bit TrID Generic Win/DOS Executable (49.9%) DOS Executable Generic (49.8%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%) Tags peexe VirusTotal metadata First submission 2014-08-18 16:37:02 UTC ( vor 4 Minuten ) Last submission 2014-08-18 16:37:02 UTC ( vor 4 Minuten ) Dateinamen tmp0000658b Advanced heuristic and reputation engines ClamAV PUA Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: hxxp://www.clamav.net/index.php?s=pua&lang=en . Symantec reputation Suspicious.Insight Code:
ATTFilter SHA256: c4c16e4ee6beea1cba3f353ac91bfb9c5aedc426a9ff706794b669d911d7f619 Dateiname: tmp00004018 Erkennungsrate: 1 / 53 Analyse-Datum: 2014-08-18 17:28:18 UTC ( vor 1 Minute ) Bkav W32.HfsAutoB.9c2c 20140818 AVG 20140818 AVware 20140818 Ad-Aware 20140818 AegisLab 20140818 Agnitum 20140818 AhnLab-V3 20140818 AntiVir 20140818 Antiy-AVL 20140818 Avast 20140818 Baidu-International 20140818 BitDefender 20140818 ByteHero 20140818 CAT-QuickHeal 20140818 CMC 20140818 ClamAV 20140818 Commtouch 20140818 Comodo 20140818 DrWeb 20140818 ESET-NOD32 20140818 Emsisoft 20140818 F-Prot 20140818 F-Secure 20140818 Fortinet 20140818 GData 20140818 Ikarus 20140818 Jiangmin 20140815 K7AntiVirus 20140818 K7GW 20140818 Kaspersky 20140818 Kingsoft 20140818 Malwarebytes 20140818 McAfee 20140818 McAfee-GW-Edition 20140818 MicroWorld-eScan 20140818 Microsoft 20140818 NANO-Antivirus 20140818 Norman 20140818 Panda 20140818 Qihoo-360 20140818 Rising 20140818 SUPERAntiSpyware 20140818 Sophos 20140818 Symantec 20140818 Tencent 20140818 TheHacker 20140817 TotalDefense 20140818 TrendMicro 20140818 TrendMicro-HouseCall 20140818 VBA32 20140818 VIPRE 20140818 ViRobot 20140818 nProtect 20140818 MD5 26efde7502fdc4061b2fa2f077c5412d SHA1 15380c537ff642ba58e3218b1ee1c34fa9f1d87e SHA256 c4c16e4ee6beea1cba3f353ac91bfb9c5aedc426a9ff706794b669d911d7f619 ssdeep 786432:uEtEpQkb/RoUfiLiDDt+POS1bAhcqqleFpuZMkZ+zUTYZ+zn2pPrr:dtej/RoUfiLkt+POS1bAhcqqleFpuZr File size 29.3 MB ( 30765056 bytes ) File type Win32 DLL Magic literal PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bit TrID Win32 Executable (generic) (52.9%) Generic Win/DOS Executable (23.5%) DOS Executable Generic (23.4%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) Tags pedll VirusTotal metadata First submission 2014-08-18 17:28:18 UTC ( vor 4 Minuten ) Last submission 2014-08-18 17:28:18 UTC ( vor 4 Minuten ) Dateinamen AcroRd32.dll tmp00004018 Advanced heuristic and reputation engines Symantec reputation Suspicious.Insight Code:
ATTFilter SHA256: a05f87eec6358ee703269bde81804b16bbe65561fa3c67c53d3cadd2cfce753b Dateiname: tmp00002cb3 Erkennungsrate: 2 / 49 Analyse-Datum: 2014-08-18 18:32:37 UTC ( vor 1 Minute ) Bkav W32.HfsAutoB.2d71 20140818 K7GW Virus ( f10001071 ) 20140818 AVG 20140818 AVware 20140818 Ad-Aware 20140818 AegisLab 20140818 Agnitum 20140818 AhnLab-V3 20140818 Antiy-AVL 20140818 Avast 20140818 Baidu-International 20140818 BitDefender 20140818 ByteHero 20140818 CAT-QuickHeal 20140818 CMC 20140818 ClamAV 20140818 Commtouch 20140818 Emsisoft 20140818 F-Prot 20140818 F-Secure 20140818 Fortinet 20140818 GData 20140818 Ikarus 20140818 Jiangmin 20140815 K7AntiVirus 20140818 Kaspersky 20140818 Kingsoft 20140818 Malwarebytes 20140818 McAfee 20140818 McAfee-GW-Edition 20140818 MicroWorld-eScan 20140818 Microsoft 20140818 NANO-Antivirus 20140818 Norman 20140818 Panda 20140818 Qihoo-360 20140818 Rising 20140818 SUPERAntiSpyware 20140818 Sophos 20140818 Symantec 20140818 Tencent 20140818 TheHacker 20140817 TotalDefense 20140818 TrendMicro 20140818 TrendMicro-HouseCall 20140818 VBA32 20140818 VIPRE 20140818 ViRobot 20140818 nProtect 20140818 MD5 38d9d67fda7aa2f5375c6974ee748e70 SHA1 53a5b3b27a41373f32a572a96675f884f4f10444 SHA256 a05f87eec6358ee703269bde81804b16bbe65561fa3c67c53d3cadd2cfce753b ssdeep 393216:UqgQS+i0QAbI/A2pXu/e0VI+iJqMU8ahxCu+UjccJ5K1BZzXMURqJXgOIJZJAw6:pTaCGyI7mXXpqeGjbB+MOj7 File size 24.6 MB ( 25776128 bytes ) File type Win32 DLL Magic literal PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bit TrID Generic Win/DOS Executable (49.9%) DOS Executable Generic (49.8%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%) Tags pedll VirusTotal metadata First submission 2014-08-18 18:32:37 UTC ( vor 3 Minuten ) Last submission 2014-08-18 18:32:37 UTC ( vor 3 Minuten ) Dateinamen tmp00002cb3 Advanced heuristic and reputation engines ClamAV PUA Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: hxxp://www.clamav.net/index.php?s=pua&lang=en . Symantec reputation Suspicious.Insight ExifTool file metadata MIMEType application/octet-stream Subsystem Windows GUI MachineType Intel 386 or later, and compatibles TimeStamp 2014:07:17 06:24:36+01:00 FileType Win32 DLL PEType PE32 CodeSize 17138176 LinkerVersion 10.0 FileAccessDate 2014:08:18 19:32:54+01:00 EntryPoint 0x88c8a7 InitializedDataSize 8621056 SubsystemVersion 5.1 ImageVersion 0.0 OSVersion 5.1 FileCreateDate 2014:08:18 19:32:54+01:00 UninitializedDataSize 0 Code:
ATTFilter SHA256: 90d990c4bb3a361d5ed0a8b5ceb10fdca29eb476fa785772c30f3fd473859710 Dateiname: tmp00002bd9 Erkennungsrate: 2 / 52 Analyse-Datum: 2014-08-18 19:04:39 UTC ( vor 1 Minute ) Bkav W32.HfsAutoB.0d16 20140818 K7GW Virus ( f10001071 ) 20140818 AVG 20140818 AVware 20140818 Ad-Aware 20140818 AegisLab 20140818 Agnitum 20140818 AhnLab-V3 20140818 AntiVir 20140818 Antiy-AVL 20140818 Avast 20140818 Baidu-International 20140818 BitDefender 20140818 ByteHero 20140818 CAT-QuickHeal 20140818 CMC 20140818 ClamAV 20140818 Commtouch 20140818 Comodo 20140818 DrWeb 20140818 ESET-NOD32 20140818 Emsisoft 20140818 F-Prot 20140818 F-Secure 20140818 Fortinet 20140818 GData 20140818 Ikarus 20140818 Jiangmin 20140815 K7AntiVirus 20140818 Kaspersky 20140818 Malwarebytes 20140818 McAfee 20140818 McAfee-GW-Edition 20140818 MicroWorld-eScan 20140818 Microsoft 20140818 NANO-Antivirus 20140818 Norman 20140818 Panda 20140818 Qihoo-360 20140818 Rising 20140818 SUPERAntiSpyware 20140818 Sophos 20140818 Symantec 20140818 Tencent 20140818 TheHacker 20140817 TotalDefense 20140818 TrendMicro 20140818 TrendMicro-HouseCall 20140818 VBA32 20140818 VIPRE 20140818 ViRobot 20140818 nProtect 20140818 MD5 0ff41bb5f580a0e9c4e2b3537b0533db SHA1 a7950a3d9b253c0cbc63831979ae3494cf092845 SHA256 90d990c4bb3a361d5ed0a8b5ceb10fdca29eb476fa785772c30f3fd473859710 ssdeep 393216:9qgQS+i0QAbI/A2pXu/e0VI+iJqMU8ahxCu+UjccJ5K1BZzXMURqJXgOIJZJAw6:8TaCGyI7mXXpqeGjbB+Mkj7 imphash 4dfa9395729497fdfe17dfd86fac8afa File size 24.6 MB ( 25776128 bytes ) File type Win32 DLL Magic literal PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bit TrID Generic Win/DOS Executable (49.9%) DOS Executable Generic (49.8%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%) Tags pedll VirusTotal metadata First submission 2014-08-18 19:04:39 UTC ( vor 2 Minuten ) Last submission 2014-08-18 19:04:39 UTC ( vor 2 Minuten ) Dateinamen tmp00002bd9 Advanced heuristic and reputation engines ClamAV PUA Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: hxxp://www.clamav.net/index.php?s=pua&lang=en . Symantec reputation Suspicious.Insight The file being studied is a Portable Executable file! More specifically, it is a Win32 DLL file for the Windows GUI subsystem. Copyright License: MPL 2 Publisher Mozilla Foundation Product Firefox File version 31.0 PE header basic information Target machine Intel 386 or later processors and compatible processors Compilation timestamp 2014-07-17 05:24:36 Entry Point 0x0088C8A7 Number of sections 1 PE sections Name Virtual address Virtual size Raw size Entropy MD5 .avx 4096 25772032 25772032 6.69 4b3bd218e29d04e2c195ce479fdd2fb5 PE imports [+] ADVAPI32.dll [+] GDI32.dll [+] IMM32.dll [+] IPHLPAPI.DLL [+] KERNEL32.dll [+] MSIMG32.dll [+] MSVCP100.dll [+] MSVCR100.dll [+] NETAPI32.dll [+] OLEAUT32.dll [+] SETUPAPI.dll [+] SHELL32.dll [+] SHLWAPI.dll [+] USER32.dll [+] USP10.dll [+] UxTheme.dll [+] VERSION.dll [+] WINMM.dll [+] WINTRUST.dll [+] WS2_32.dll [+] WSOCK32.dll [+] gkmedias.dll [+] icuin52.dll [+] mozalloc.dll [+] mozglue.dll [+] mozjs.dll [+] nss3.dll [+] ole32.dll PE exports ??0_Mutex@std@@QAE@W4_Uninitialized@1@@Z ??4_Init_locks@std@@QAEAAV01@ABV01@@Z ?NewBufferFromStorageStream@scache@mozilla@@YA?AW4tag_nsresult@@PAVnsIStorageStream@@PAPADPAI@Z ?NewObjectInputStreamFromBuffer@scache@mozilla@@YA?AW4tag_nsresult@@PADIPAPAVnsIObjectInputStream@@@Z ?NewObjectOutputWrappedStorageStream@scache@mozilla@@YA?AW4tag_nsresult@@PAPAVnsIObjectOutputStream@@PAPAVnsIStorageStream@@_N@Z ?PathifyURI@scache@mozilla@@YA?AW4tag_nsresult@@PAVnsIURI@@AAVnsACString_internal@@@Z ?SupportImageWithMimeType@imgLoader@@SG_NPBD@Z ?_external_GetAccessibilityService@services@mozilla@@YG?AU?$already_AddRefed@VnsIAccessibilityService@@@@XZ ?_external_GetChromeRegistryService@services@mozilla@@YG?AU?$already_AddRefed@VnsIChromeRegistry@@@@XZ ?_external_GetHistoryService@services@mozilla@@YG?AU?$already_AddRefed@VIHistory@mozilla@@@@XZ Number of PE resources by type RT_GROUP_CURSOR 11 RT_CURSOR 11 RT_DIALOG 1 RT_VERSION 1 Number of PE resources by language ENGLISH US 24 ExifTool file metadata MIMEType application/octet-stream Subsystem Windows GUI MachineType Intel 386 or later, and compatibles TimeStamp 2014:07:17 06:24:36+01:00 FileType Win32 DLL PEType PE32 CodeSize 17138176 LinkerVersion 10.0 FileAccessDate 2014:08:18 20:01:16+01:00 EntryPoint 0x88c8a7 InitializedDataSize 8621056 SubsystemVersion 5.1 ImageVersion 0.0 OSVersion 5.1 FileCreateDate 2014:08:18 20:01:16+01:00 UninitializedDataSize 0 |
19.08.2014, 11:59 | #4 |
/// the machine /// TB-Ausbilder | Avira findet TR/Patched.Ren.Gen. - wie kann ich ihn entfernen? wie erwartet, alles Fehlalarme
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.08.2014, 12:07 | #5 |
| Avira findet TR/Patched.Ren.Gen. - wie kann ich ihn entfernen? Heißt das dann, mein Rechner ist sauber?? Ich muss nichts weiter tun? Das wäre ja zu schön Falls ja, würde ich dennoch gerne etwas besseres als Avira gegen Viren/Malware und Ad-Aware gegen Spyware verwenden. Hast Du da einen Tipp für mich? nochmals |
20.08.2014, 08:05 | #6 |
/// the machine /// TB-Ausbilder | Avira findet TR/Patched.Ren.Gen. - wie kann ich ihn entfernen? Ja ist er. Ich empfehle immer Emsisoft
__________________ --> Avira findet TR/Patched.Ren.Gen. - wie kann ich ihn entfernen? |
Themen zu Avira findet TR/Patched.Ren.Gen. - wie kann ich ihn entfernen? |
adobe, adware, avira, browser, canon, cpu, defender, desktop, device driver, entfernen, excel, fehler, firefox, flash player, home, homepage, installation, malware, mozilla, programm, registry, scan, security, services.exe, svchost.exe, temp, windows |