|
Log-Analyse und Auswertung: 0xc0000005 FehlermeldungWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
26.11.2014, 09:11 | #16 |
| 0xc0000005 Fehlermeldung Fix log: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 23-11-2014 01 Ran by Prensh at 2014-11-26 09:10:36 Run:1 Running from C:\Users\PJ\Desktop\Trojaner-Board Loaded Profiles: Prensh & PJ (Available profiles: Prensh & PJ) Boot Mode: Normal ============================================== Content of fixlist: ***************** AppInit_DLLs-x32: airfoilinject3.dll => "airfoilinject3.dll" File Not Found ***************** "airfoilinject3.dll" => Value Data removed successfully. ==== End of Fixlog ==== |
26.11.2014, 11:38 | #17 |
/// TB-Ausbilder | 0xc0000005 Fehlermeldung Gibts immer noch Fehlermeldungen beim Hochfahren ?
__________________Kanst du ggf. Screenshots der Fehlermeldung erstellen und beim Antwort als Anhang anfügen ?
__________________ |
26.11.2014, 11:46 | #18 |
| 0xc0000005 Fehlermeldung ja gibt es und zwar bei Spotify helper. diese bekomme ich nie weg. Desweiteren schlägt mein Java update auch immer fehl. ich poste dir gleich noch die Fehlermeldung dazu.
__________________ |
26.11.2014, 11:55 | #19 |
| 0xc0000005 Fehlermeldung Halt! ich habe mich vertan! Die Meldung kommt doch nicht mehr. Vielen Dank. Ist dieser Fehler jetzt durch einen Trojaner hervorgerufen worden? Weil Airfoil ja eigentlich ein seriöser Anbieter ist. |
26.11.2014, 12:07 | #20 |
/// TB-Ausbilder | 0xc0000005 Fehlermeldung Nö, das hat mit Trojaner nur soweit zu tun, das Airfoil als auch Schadsoftware den selben "Weg" nutzen, um sich in laufende Prozesse einzuklinken. Kannst du dann auch nochmal JRT Tool testen ob das jetzt funktioniert ? Achja und sorry, hab am Anfang bissl gepennt und nicht gleich gesehen.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
26.11.2014, 12:54 | #21 |
| 0xc0000005 Fehlermeldung JRT Log Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.3.9 (11.15.2014:2) OS: Windows 7 Professional x64 Ran by Prensh on 26.11.2014 at 12:45:57,02 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] "C:\Windows\wininit.ini" ~~~ Folders Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 26.11.2014 at 12:49:37,46 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Vielen Dank! |
26.11.2014, 13:18 | #22 | |
/// TB-Ausbilder | 0xc0000005 FehlermeldungZitat:
Hast du da noch ein "richtiges" Log gehabt ? Falls ja, bitte posten. Mach mal bitte so weiter: Downloade Dir bitte SecurityCheck und:
Starte noch einmal FRST.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
26.11.2014, 14:09 | #23 |
| 0xc0000005 Fehlermeldung nein, das war alles auf den JRT bezogen. Das log hatte ich dir bereits gepostet. Oder soll ich den Maleware vorischtshalber nochmal laufen lassen? Security Scan log: Code:
ATTFilter Results of screen317's Security Check version 0.99.90 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 60 Java version out of Date! Adobe Flash Player 15.0.0.223 Mozilla Firefox 14.0.1 Firefox out of Date! Mozilla Thunderbird (17.0.7) ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-11-2014 01 Ran by Prensh (administrator) on PRENSH-PC on 26-11-2014 14:07:03 Running from C:\Users\PJ\Desktop\Trojaner-Board Loaded Profiles: Prensh & PJ (Available profiles: Prensh & PJ) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () E:\Program Files (x86)\Steuertipps\AAVUpdateManager\aavus.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe () E:\Program Files (x86)\GNU\GnuPG\dirmngr.exe (Bdrive Inc.) D:\Program Files\NetDrive\ndsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (TeamViewer GmbH) E:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Sentelic Corporation) C:\Program Files\FSP\FspUip.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Learnpulse) C:\Users\PJ\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe () C:\Users\PJ\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe () E:\Program Files (x86)\spotimote\spotimote.exe (Spotify Ltd) C:\Users\PJ\AppData\Roaming\Spotify\spotify.exe (Dropbox, Inc.) C:\Users\PJ\AppData\Roaming\Dropbox\bin\Dropbox.exe (Acronis) E:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe (Apple Inc.) E:\Program Files (x86)\iTunes\iTunesHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe () C:\Users\PJ\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\PJ\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Windows\Samsung\PanelMgr\caller64.exe () C:\Users\PJ\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Spotify Ltd) C:\Users\PJ\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (MATESO GmbH) E:\Program Files (x86)\Password Safe and Repository 7\psr.exe () C:\Users\PJ\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Mozilla Corporation) E:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe () C:\Users\PJ\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Oracle Corporation) E:\Program Files (x86)\Java\bin\jp2launcher.exe (Oracle Corporation) E:\Program Files (x86)\Java\bin\java.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [357800 2009-09-12] (Acronis) HKLM\...\Run: [fspuip] => C:\Program Files\FSP\fspuip.exe [1096192 2009-06-19] (Sentelic Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [TrueImageMonitor.exe] => E:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5082488 2009-09-12] (Acronis) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de) HKLM-x32\...\Run: [Samsung PanelMgr] => C:\Windows\Samsung\PanelMgr\ssmmgr.exe [606208 2009-12-09] () HKLM-x32\...\Run: [iTunesHelper] => E:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-02-20] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => E:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707472 2013-12-12] (Cisco Systems, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703736 2014-11-18] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [124208 2014-10-22] (Avira Operations GmbH & Co. KG) HKLM\...\RunOnce: [*WerKernelReporting] => C:\Windows\SYSTEM32\WerFault.exe [415232 2009-07-14] (Microsoft Corporation) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \mbamdor.exe [54072 2014-10-01] (Malwarebytes Corporation) HKU\S-1-5-21-2645372535-3926414537-2128117785-1000\...\Run: [Spotify] => C:\Users\PJ\AppData\Roaming\Spotify\spotify.exe [6553144 2014-10-07] (Spotify Ltd) HKU\S-1-5-21-2645372535-3926414537-2128117785-1000\...\Run: [NetDrive] => D:\Program Files\NetDrive\NetDrive.exe [3587072 2013-02-25] (Bdrive Inc.) HKU\S-1-5-21-2645372535-3926414537-2128117785-1000\...\Run: [spotimote] => E:\Program Files (x86)\spotimote\spotimote.exe [2838952 2014-08-16] () HKU\S-1-5-21-2645372535-3926414537-2128117785-1000\...\MountPoints2: {2bc37e06-f04f-11e1-9038-001f1621d255} - I:\setup.exe HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\...\Run: [DAEMON Tools Lite] => E:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd) HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\...\Run: [Spotify Web Helper] => C:\Users\PJ\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1514040 2014-10-07] (Spotify Ltd) HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\...\Run: [Wunderlist] => C:\Users\PJ\AppData\Local\Apps\2.0\NCZ27Y3X.B74\XLMK8K9W.2J1\wund..tion_45ec1bcecca77a53_0002.0000_d3bc77299ece31af\Wunderlist.exe [6815232 2013-01-19] (6 Wunderkinder GmbH) HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\...\Run: [Screenpresso] => C:\Users\PJ\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe [10985488 2014-09-30] (Learnpulse) HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\...\Run: [Google Update] => C:\Users\PJ\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-02-17] (Google Inc.) HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22869088 2014-10-21] (Google) HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\PJ\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] () HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\...\Run: [spotimote] => E:\Program Files (x86)\spotimote\spotimote.exe [2838952 2014-08-16] () HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\...\Run: [Spotify] => C:\Users\PJ\AppData\Roaming\Spotify\spotify.exe [6553144 2014-10-07] (Spotify Ltd) HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\...\MountPoints2: {2bc37e06-f04f-11e1-9038-001f1621d255} - I:\PrimalHunt.exe HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\...\MountPoints2: {3bb72a63-11e5-11e4-a0f2-001f1621d255} - G:\avp2.exe HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\...\MountPoints2: {b8c16e5e-54b6-11e2-ba1e-001f1621d255} - G:\HTC_Sync_Manager_PC.exe Startup: C:\Users\PJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Prensh\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\PJ\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll No File ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\PJ\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll No File ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\PJ\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll No File ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\PJ\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll No File ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2645372535-3926414537-2128117785-1000\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKU\S-1-5-21-2645372535-3926414537-2128117785-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKU\S-1-5-21-2645372535-3926414537-2128117785-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKU\S-1-5-21-2645372535-3926414537-2128117785-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x1B2C20A129F0CD01 HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xD790096E510DCE01 HKU\S-1-5-21-2645372535-3926414537-2128117785-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation) BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: Samsung BHO Class -> {AA609D72-8482-4076-8991-8CDAE5B93BCB} -> E:\Program Files (x86)\Samsung AnyWeb Print\W2PBrowser.dll () BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Prensh\AppData\Roaming\Mozilla\Firefox\Profiles\dqa5971u.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.2 -> E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> E:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> E:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> E:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-2645372535-3926414537-2128117785-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKU\S-1-5-21-2645372535-3926414537-2128117785-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\PJ\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKU\S-1-5-21-2645372535-3926414537-2128117785-1001: @talk.google.com/O1DPlugin -> C:\Users\PJ\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKU\S-1-5-21-2645372535-3926414537-2128117785-1001: @tools.google.com/Google Update;version=3 -> C:\Users\PJ\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-2645372535-3926414537-2128117785-1001: @tools.google.com/Google Update;version=9 -> C:\Users\PJ\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-2645372535-3926414537-2128117785-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\PJ\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2013-02-27] FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2013-03-12] FF StartMenuInternet: FIREFOX.EXE - E:\Program Files (x86)\Mozilla Firefox\firefox.exe Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; E:\Program Files (x86)\Steuertipps\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2014-11-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2014-11-18] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [164656 2014-10-22] (Avira Operations GmbH & Co. KG) R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2436280 2014-09-25] (Microsoft Corporation) R2 DirMngr; E:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-07-16] () [File not signed] R2 ndsvc; D:\Program Files\NetDrive\ndsvc.exe [2789376 2013-02-25] (Bdrive Inc.) [File not signed] R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] R2 TeamViewer9; E:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [4799760 2014-09-12] (TeamViewer GmbH) S2 KMService; C:\Windows\system32\srvany.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-06-17] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-08-27] (DT Soft Ltd) S4 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R0 tdrpman251; C:\Windows\System32\DRIVERS\tdrpm251.sys [1455648 2012-08-27] (Acronis) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52080 2013-12-12] (Cisco Systems, Inc.) S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-26 14:01 - 2014-11-26 14:01 - 00638888 _____ (Oracle Corporation) C:\Users\PJ\Downloads\jxpiinstall(2).exe 2014-11-26 13:57 - 2014-11-26 13:57 - 00638888 _____ (Oracle Corporation) C:\Users\PJ\Downloads\jxpiinstall(1).exe 2014-11-26 13:54 - 2014-11-26 13:54 - 00638888 _____ (Oracle Corporation) C:\Users\PJ\Downloads\jxpiinstall.exe 2014-11-26 12:50 - 2014-11-26 12:50 - 00000000 ____D () C:\Users\Prensh\AppData\Local\Mozilla 2014-11-26 12:49 - 2014-11-26 12:49 - 00000753 _____ () C:\Users\Prensh\Desktop\JRT.txt 2014-11-26 11:57 - 2014-11-26 11:57 - 00000000 ____D () C:\ProgramData\Riot Games 2014-11-26 11:49 - 2014-11-26 11:49 - 00000022 _____ () C:\Windows\S.dirmngr 2014-11-26 10:59 - 2014-11-26 10:59 - 02952006 _____ () C:\Users\PJ\Downloads\lightning-3.3.1-tb+sm-windows.xpi 2014-11-26 10:59 - 2014-11-26 10:59 - 00070117 _____ () C:\Users\PJ\Downloads\provider_for_google_calendar-1.0.2-tb+sm.xpi 2014-11-25 15:40 - 2014-11-25 17:26 - 00000000 ____D () C:\Users\PJ\AppData\Roaming\tor 2014-11-21 18:36 - 2014-11-21 18:36 - 00001196 _____ () C:\Users\Prensh\Desktop\mbam.txt 2014-11-21 18:29 - 2014-11-21 18:29 - 00001220 _____ () C:\Users\PJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Express Burn Disc Burning Software.lnk 2014-11-21 18:29 - 2014-11-21 18:29 - 00001154 _____ () C:\Users\PJ\Desktop\Debut Video Capture Software.lnk 2014-11-21 18:29 - 2014-11-21 18:29 - 00001140 _____ () C:\Users\PJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk 2014-11-21 18:29 - 2014-11-21 18:29 - 00001136 _____ () C:\Users\PJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prism Video File Converter.lnk 2014-11-21 18:29 - 2014-11-21 18:29 - 00000000 ____D () C:\Users\PJ\AppData\Roaming\NCH Software 2014-11-21 18:29 - 2014-11-21 18:29 - 00000000 ____D () C:\ProgramData\NCH Software 2014-11-21 18:27 - 2014-11-21 18:28 - 01540672 _____ (NCH Software) C:\Users\PJ\Downloads\debutpsetup_1.82.exe 2014-11-21 18:04 - 2014-11-21 18:04 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\PJ\Downloads\mbam-setup-2.0.3.1025(1).exe 2014-11-21 18:04 - 2014-11-21 18:04 - 00000781 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-11-21 17:55 - 2014-11-21 17:55 - 00000000 ____D () C:\Windows\ERUNT 2014-11-21 17:44 - 2014-11-21 17:44 - 00000000 ____D () C:\Users\PJ\AppData\Local\CrashRpt 2014-11-21 17:35 - 2014-11-21 17:41 - 00000000 ____D () C:\AdwCleaner 2014-11-21 17:34 - 2014-11-21 17:34 - 02140160 _____ () C:\Users\PJ\Downloads\AdwCleaner_4.101.exe 2014-11-19 17:03 - 2014-11-19 17:03 - 02734600 _____ (Sandboxie Holdings, LLC) C:\Users\PJ\Downloads\Sandboxie414Install(1).exe 2014-11-19 08:36 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-19 08:36 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-19 08:36 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-11-19 08:36 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2014-11-18 09:36 - 2014-11-18 09:37 - 88093376 _____ (Swiss Academic Software) C:\Users\PJ\Downloads\Citavi4Setup.exe 2014-11-14 16:31 - 2014-11-14 16:32 - 00000000 ____D () C:\Windows\rescache 2014-11-12 09:46 - 2014-11-07 20:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-11-12 09:46 - 2014-11-07 20:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-11-12 09:46 - 2014-11-06 05:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-11-12 09:46 - 2014-11-06 05:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-11-12 09:46 - 2014-11-06 04:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-11-12 09:46 - 2014-11-06 04:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-11-12 09:46 - 2014-11-06 04:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-11-12 09:46 - 2014-11-06 04:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-11-12 09:46 - 2014-11-06 04:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-11-12 09:46 - 2014-11-06 04:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-11-12 09:46 - 2014-11-06 04:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-11-12 09:46 - 2014-11-06 04:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-11-12 09:46 - 2014-11-06 04:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-11-12 09:46 - 2014-11-06 04:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-11-12 09:46 - 2014-11-06 04:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-11-12 09:46 - 2014-11-06 04:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-11-12 09:46 - 2014-11-06 04:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-11-12 09:46 - 2014-11-06 04:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-11-12 09:46 - 2014-11-06 04:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-11-12 09:46 - 2014-11-06 04:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-11-12 09:46 - 2014-11-06 04:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-11-12 09:46 - 2014-11-06 04:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-11-12 09:46 - 2014-11-06 04:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-11-12 09:46 - 2014-11-06 04:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-11-12 09:46 - 2014-11-06 04:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-11-12 09:46 - 2014-11-06 04:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-11-12 09:46 - 2014-11-06 04:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-11-12 09:46 - 2014-11-06 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-11-12 09:46 - 2014-11-06 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-11-12 09:46 - 2014-11-06 03:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-11-12 09:46 - 2014-11-06 03:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-11-12 09:46 - 2014-11-06 03:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-11-12 09:46 - 2014-11-06 03:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-11-12 09:46 - 2014-11-06 03:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-11-12 09:46 - 2014-11-06 03:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-11-12 09:46 - 2014-11-06 03:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-11-12 09:46 - 2014-11-06 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-11-12 09:46 - 2014-11-06 03:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-11-12 09:46 - 2014-11-06 03:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-11-12 09:46 - 2014-11-06 03:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-11-12 09:46 - 2014-11-06 03:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-11-12 09:46 - 2014-11-06 03:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-11-12 09:46 - 2014-11-06 03:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-11-12 09:46 - 2014-11-06 03:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-11-12 09:46 - 2014-11-06 03:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-11-12 09:46 - 2014-11-06 03:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-11-12 09:46 - 2014-11-06 02:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-11-12 09:46 - 2014-11-06 02:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-11-12 09:46 - 2014-11-06 02:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-11-12 09:46 - 2014-11-06 02:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-11-12 09:46 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-12 09:46 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-11-12 09:46 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-12 09:46 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-12 09:46 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-12 09:46 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-11-12 09:46 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-11-12 09:46 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2014-11-12 09:46 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2014-11-12 09:45 - 2014-11-06 05:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-11-12 09:45 - 2014-11-06 04:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-11-12 09:45 - 2014-11-06 04:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-11-12 09:45 - 2014-11-06 04:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-11-12 09:45 - 2014-11-06 04:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-11-12 09:45 - 2014-11-06 03:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-11-12 09:44 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-11-12 09:44 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-11-12 09:44 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-11-12 09:44 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-11-12 09:44 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-11-12 09:44 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL 2014-11-12 09:43 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-12 09:43 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-11-12 09:43 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-11-12 09:43 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-11-12 09:43 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-12 09:43 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-12 09:43 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-12 09:43 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-11-12 09:43 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-11-12 09:43 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-12 09:43 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2014-11-12 09:43 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2014-11-12 09:43 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2014-11-12 09:43 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-12 09:43 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-11-12 09:43 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-11-12 09:43 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-11-12 09:43 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-11-12 09:43 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-11-12 09:43 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-11-12 09:43 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-11-12 09:43 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2014-11-12 09:43 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-11-12 09:43 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-11-12 09:43 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-11-12 09:42 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-12 09:42 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2014-11-10 15:35 - 2014-11-10 15:35 - 06036856 _____ (TeamViewer) C:\Users\PJ\Downloads\TeamViewerQS.exe 2014-11-10 15:34 - 2014-11-10 15:34 - 00000841 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2014-11-10 15:34 - 2014-11-10 15:34 - 00000000 ____D () C:\Users\Prensh\AppData\Roaming\TeamViewer 2014-11-10 15:33 - 2014-11-10 15:33 - 07822880 _____ (TeamViewer GmbH) C:\Users\PJ\Downloads\TeamViewer_Setup.exe 2014-11-08 19:54 - 2014-11-08 19:54 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-11-05 22:14 - 2014-11-05 22:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-11-05 18:37 - 2014-11-26 14:07 - 00000000 ____D () C:\Users\PJ\Desktop\Trojaner-Board 2014-11-05 18:12 - 2014-11-05 18:12 - 01453240 _____ (Microsoft Corporation) C:\Users\PJ\Downloads\Setup.X64.de-de_O365ProPlusRetail_65208466-c2ea-4294-a305-2691a2436839_TX_PR_(1).exe 2014-11-05 17:38 - 2014-11-05 17:38 - 00000000 ____D () C:\Users\PJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TreeSize Personal 2014-11-05 17:37 - 2014-11-05 17:38 - 17498176 _____ (JAM Software ) C:\Users\PJ\Downloads\TreeSizePersonal-x86-Demo.exe 2014-11-05 17:33 - 2014-11-05 18:13 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2014-11-05 17:32 - 2014-11-05 17:32 - 01453240 _____ (Microsoft Corporation) C:\Users\PJ\Downloads\Setup.X64.de-de_O365ProPlusRetail_65208466-c2ea-4294-a305-2691a2436839_TX_PR_.exe 2014-11-02 22:37 - 2014-11-02 22:38 - 00000000 ____D () C:\Users\PJ\Downloads\Freeze 2014-11-02 22:08 - 2014-11-02 22:08 - 05249448 _____ (ParetoLogic Inc.) C:\Users\PJ\Downloads\ParetoLogic PC Health Advisor_de.exe 2014-11-02 11:41 - 2014-11-26 11:49 - 00008299 _____ () C:\Windows\setupact.log 2014-11-02 11:41 - 2014-11-02 11:41 - 00000000 _____ () C:\Windows\setuperr.log 2014-10-29 16:37 - 2014-10-29 16:37 - 00001115 _____ () C:\Users\PJ\Downloads\BAHN_Fahrplan.ics 2014-10-27 06:02 - 2014-10-27 06:02 - 00114328 _____ () C:\Users\PJ\Desktop\provider_for_google_calendar-0.32-tb+sm.xpi ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-26 14:08 - 2012-08-27 09:53 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-11-26 14:07 - 2014-09-12 10:30 - 00000000 ____D () C:\FRST 2014-11-26 14:04 - 2013-10-26 12:56 - 00000000 ____D () C:\ProgramData\Oracle 2014-11-26 14:03 - 2014-07-02 17:14 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-11-26 14:02 - 2012-09-06 11:50 - 00000000 ____D () C:\Program Files (x86)\Java 2014-11-26 14:00 - 2012-08-28 06:11 - 00000000 ____D () C:\Users\PJ\AppData\Roaming\Spotify 2014-11-26 13:55 - 2013-10-26 12:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit 2014-11-26 13:55 - 2013-10-26 12:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-11-26 13:31 - 2012-08-28 08:04 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-26 13:19 - 2013-04-03 21:41 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2645372535-3926414537-2128117785-1001UA.job 2014-11-26 13:06 - 2012-08-27 09:31 - 01567064 _____ () C:\Windows\WindowsUpdate.log 2014-11-26 12:52 - 2013-04-03 10:04 - 00000000 ____D () C:\Users\PJ\AppData\Roaming\Dropbox 2014-11-26 12:51 - 2012-08-28 08:04 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-26 12:50 - 2013-04-02 15:43 - 00000000 ____D () C:\Users\Prensh\AppData\Roaming\Mozilla 2014-11-26 12:45 - 2012-08-27 09:35 - 00000000 ____D () C:\Users\Prensh 2014-11-26 12:00 - 2009-07-14 05:45 - 00021088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-26 12:00 - 2009-07-14 05:45 - 00021088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-26 11:49 - 2014-03-01 11:10 - 00234876 _____ () C:\ndsvc.log 2014-11-26 11:49 - 2012-09-05 13:26 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-11-26 11:49 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-25 19:43 - 2012-09-22 09:37 - 00000000 ____D () C:\Users\PJ\AppData\Local\Microsoft Help 2014-11-24 21:20 - 2012-09-20 06:36 - 00000000 ____D () C:\Users\PJ\AppData\Roaming\Swiss Academic Software 2014-11-24 18:19 - 2013-04-03 21:41 - 00001056 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2645372535-3926414537-2128117785-1001Core.job 2014-11-24 16:57 - 2012-08-28 06:12 - 00000000 ____D () C:\Users\PJ\AppData\Local\Spotify 2014-11-24 09:57 - 2011-04-12 08:43 - 00703192 _____ () C:\Windows\system32\perfh007.dat 2014-11-24 09:57 - 2011-04-12 08:43 - 00150800 _____ () C:\Windows\system32\perfc007.dat 2014-11-24 09:57 - 2009-07-14 06:13 - 01629348 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-21 18:29 - 2013-03-24 09:40 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software 2014-11-21 18:05 - 2014-10-25 12:43 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-11-21 18:04 - 2014-10-25 12:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-11-21 17:42 - 2013-09-18 17:02 - 00570076 _____ () C:\Windows\PFRO.log 2014-11-20 09:52 - 2013-07-11 07:10 - 00000000 ____D () C:\Users\PJ\AppData\Roaming\spotimote 2014-11-18 09:29 - 2012-08-27 10:02 - 00110672 _____ () C:\Users\Prensh\AppData\Local\GDIPFONTCACHEV1.DAT 2014-11-14 13:05 - 2013-04-03 10:06 - 00000000 ____D () C:\Users\PJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-11-13 18:14 - 2013-04-03 21:41 - 00004072 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2645372535-3926414537-2128117785-1001UA 2014-11-13 18:14 - 2013-04-03 21:41 - 00003676 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2645372535-3926414537-2128117785-1001Core 2014-11-13 17:51 - 2009-07-14 05:45 - 00438760 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-13 01:24 - 2013-07-11 22:59 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-13 01:16 - 2012-08-27 10:31 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-13 00:40 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-11-12 19:26 - 2012-08-28 08:04 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-11-12 19:26 - 2012-08-28 08:04 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-11-12 11:08 - 2012-08-27 09:53 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-11-12 11:08 - 2012-08-27 09:53 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-11-12 11:08 - 2012-08-27 09:53 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-11-10 16:17 - 2012-08-27 17:59 - 00110672 _____ () C:\Users\PJ\AppData\Local\GDIPFONTCACHEV1.DAT 2014-11-08 19:55 - 2014-06-26 05:06 - 00000000 ____D () C:\ProgramData\Package Cache 2014-11-08 19:54 - 2014-06-26 05:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-11-08 19:54 - 2012-12-20 07:44 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-11-05 18:41 - 2012-08-27 15:55 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-11-05 18:39 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-11-05 18:35 - 2011-04-12 08:55 - 00000000 ____D () C:\Windows\ShellNew 2014-11-05 18:18 - 2012-08-28 14:33 - 00000000 ____D () C:\Program Files\Microsoft Office 2014-11-05 17:39 - 2013-01-22 10:20 - 00000000 ____D () C:\Users\Prensh\AppData\Roaming\JAM Software 2014-11-05 17:38 - 2013-01-22 10:19 - 00000000 ____D () C:\Users\PJ\AppData\Roaming\JAM Software 2014-11-04 23:31 - 2013-06-25 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2014-11-04 14:30 - 2010-11-21 04:27 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-11-02 22:16 - 2014-07-23 14:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fox Interactive 2014-11-01 23:18 - 2013-08-27 18:37 - 00000000 ____D () C:\Users\PJ\AppData\Roaming\Skype 2014-11-01 21:47 - 2012-08-27 14:58 - 00000000 ____D () C:\Windows\Minidump 2014-11-01 15:43 - 2014-07-23 13:57 - 00000000 ____D () C:\Users\PJ\AppData\Roaming\BitTorrent Some content of TEMP: ==================== C:\Users\PJ\AppData\Local\Temp\avgnt.exe C:\Users\PJ\AppData\Local\Temp\burnsetup.exe C:\Users\PJ\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpzqfpkt.dll C:\Users\PJ\AppData\Local\Temp\Foxit Reader Updater.exe C:\Users\Prensh\AppData\Local\Temp\avgnt.exe C:\Users\Prensh\AppData\Local\Temp\Quarantine.exe C:\Users\Prensh\AppData\Local\Temp\SandboxieInstall-64-bit-2723980.exe C:\Users\Prensh\AppData\Local\Temp\SandboxieInstall-64-bit-2759018.exe C:\Users\Prensh\AppData\Local\Temp\SandboxieInstall-64-bit-5782613.exe C:\Users\Prensh\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-18 08:41 ==================== End Of Log ============================ --- --- --- |
27.11.2014, 09:32 | #24 |
/// TB-Ausbilder | 0xc0000005 Fehlermeldung Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
ESET Online Scanner
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
27.11.2014, 17:50 | #25 |
| 0xc0000005 Fehlermeldung Fixlog Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-11-2014 01 Ran by Prensh at 2014-11-27 11:52:01 Run:2 Running from C:\Users\PJ\Desktop\Trojaner-Board Loaded Profiles: Prensh & PJ (Available profiles: Prensh & PJ) Boot Mode: Normal ============================================== Content of fixlist: ***************** emptytemp: ***************** EmptyTemp: => Removed 544.5 MB temporary data. The system needed a reboot. ==== End of Fixlog ==== Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=12 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=de01e86302eed947b2605d78d1a2b74b # engine=21290 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-11-27 04:44:52 # local_time=2014-11-27 05:44:52 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 99 43184 14091534 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 21099 168736542 0 0 # scanned=267496 # found=13 # cleaned=0 # scan_time=20323 sh=B341B70EF66000ADB004FC29B08E047B4BAED163 ft=1 fh=6ef6373658cb81dd vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\PJ\AppData\Roaming\NCH Software\Program Files\Debut\debut.exe.vir" sh=E27DDC0524343F61A920256EF18288D7233B1E91 ft=1 fh=7e15088d40e766d0 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\PJ\AppData\Roaming\NCH Software\Program Files\Debut\debutsetup_v1.74.exe.vir" sh=F4D041F5193E1F1118546B525990E28B6CAB9115 ft=1 fh=81dbc95793ec5f88 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\PJ\AppData\Roaming\NCH Software\Program Files\VideoPad\videopad.exe.vir" sh=BE9581EE3E11F23C33A7DD7FC09C450F1F0AE59F ft=1 fh=2cd603b9de733b01 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\PJ\AppData\Roaming\NCH Software\Program Files\VideoPad\videopadsetup_v3.02.exe.vir" sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Prensh\AppData\Local\Temp\OCS\ocs_v71b.exe.vir" sh=74736C9A54C385AF16A42795E231B4C3425D9338 ft=1 fh=f92a8b260b274c8c vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\PJ\AppData\Roaming\NCH Software\Program Files\Debut\debut.exe" sh=B3F76FB12066DC4F51780F3F9DABA5A9018F359F ft=1 fh=70d549a263d539ed vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\PJ\AppData\Roaming\NCH Software\Program Files\Debut\debutsetup_v1.82.exe" sh=B3F76FB12066DC4F51780F3F9DABA5A9018F359F ft=1 fh=70d549a263d539ed vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\PJ\Downloads\debutpsetup_1.82.exe" sh=E27DDC0524343F61A920256EF18288D7233B1E91 ft=1 fh=7e15088d40e766d0 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="E:\Eigene Dateien\Downloads\debut178psetup.exe" sh=563E1B707747F87BD96829B81E92CA1EE04E83FD ft=1 fh=421b349ff9c9cc9b vn="Win32/InstallMonetizer.AF evtl. unerwünschte Anwendung" ac=I fn="E:\Eigene Dateien\Downloads\freeocr.exe" sh=84E767D9BDDD1D2EE3465F79A596A403101B79B9 ft=1 fh=baef668dd276aa58 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Eigene Dateien\Downloads\MemTest - CHIP-Installer.exe" sh=2BD661EBEF3E999A3C4207A6F769835AEF30A35E ft=1 fh=e27ca218f271f23e vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="E:\Eigene Dateien\Downloads\SoftonicDownloader_fuer_photo-booth-fur-windows-7.exe" sh=D17A7B072ABCF6AC03D4BA2B6CA0B7F663BBC295 ft=1 fh=ed7d29ff40b01fdb vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="E:\Eigene Dateien\Downloads\SoftonicDownloader_fuer_windows-xp-service-pack.exe" |
28.11.2014, 11:00 | #26 | |
/// TB-Ausbilder | 0xc0000005 Fehlermeldung Ok. Nichts wildes mehr zu sehen. Zitat:
Chip/Softonic Downloader: Bei Chip.de und Softonic gibt es beim Download zwei Möglichkeiten: einmal den Chip Downloader mit DownloadSponsor, der Werbung mitbringt und gern versucht, den User dazu zu überreden, noch diese und jene Toolbar zu installieren. Und es gibt immer den alternativen Download, das ist die eigentliche Anwendung als Setup, so wie sie vom Hersteller kommt. Der Alternativlink ist genau unter der Chip Download-Schaltfläche. Firefox hast du scheinbar 2 Versionen drauf beide nicht aktuell. Gibts ansonsten noch Fehlermeldungen ? Falls nein: Die Reihenfolge ist hier entscheidend.
Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ändere regelmäßig alle deine Passwörter, jetzt, nach der Bereinigung ist ein idealer Zeitpunkt dafür
Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti-Viren-Programm und zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden. Mozilla Firefox
Performance
Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
28.11.2014, 21:32 | #27 |
| 0xc0000005 Fehlermeldung Timo, Vielen Dank für die Mühen. Klappt alles wieder wunderbar. |
Themen zu 0xc0000005 Fehlermeldung |
4d36e972-e325-11ce-bfc1-08002be10318, antivir, antivirus, avira, avp, browser, converter, desktop, downloader, dvdvideosoft ltd., excel, failed, firefox, flash player, google, homepage, ip-hilfsdienst, koyote, mozilla, mp3, problem, registry, scan, security, software, spotify web helper, starten, svchost.exe, trojaner, windows |