|
Log-Analyse und Auswertung: Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dllWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
20.10.2014, 21:00 | #16 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dllZitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
21.10.2014, 00:57 | #17 |
| Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll Nö, soll ich´s nochmal versuchen?
__________________Ich muss ihn wohl immer zweimal bitten Hat jetzt 2014.10.20.06 - Suchlauf ist wieder aktiv Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 20.10.2014 Suchlauf-Zeit: 22:07:09 Logdatei: mbam.2.txt Administrator: Ja Version: 2.00.3.1025 Malware Datenbank: v2014.10.20.06 Rootkit Datenbank: v2014.10.17.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Martin Rinke Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 390689 Verstrichene Zeit: 20 Min, 21 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 0 (Keine schädliche Elemente erkannt) Registrierungswerte: 0 (Keine schädliche Elemente erkannt) Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 0 (Keine schädliche Elemente erkannt) Dateien: 0 (Keine schädliche Elemente erkannt) Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=4b9f1dba6915a34d8348ba96c28e066a # engine=20691 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-10-20 11:50:16 # local_time=2014-10-21 01:50:16 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 22249 165478866 0 0 # scanned=288171 # found=31 # cleaned=0 # scan_time=17630 sh=E9C216ADF17020C604FE37B57EE9EAEE43C846FB ft=0 fh=0000000000000000 vn="VBS/Runner.NBW Trojaner" ac=I fn="C:\Users\Martin Rinke\9zol3d5lnss4\23092.vbs" sh=EAE2784C9115FE9CFA44A116B74E72C1BCCFA7F6 ft=1 fh=2e79e77116fe19c4 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Martin Rinke\Downloads\MyPhoneExplorer_Setup_1.8.5.exe" sh=77801D0E0DC02E8C50CDC73562F4D7F13FC1C18B ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Anwendungsdaten\SearchProtect\ffprotect\application.js" sh=170ACC25B35BA845064591DF61F2D52142823738 ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Anwendungsdaten\SearchProtect\ffprotect\nsprotector.js" sh=8BE4C277A62F2400C3B0A20F39297D310774E2AC ft=1 fh=d69c639933d87dfe vn="Win32/Toolbar.SearchSuite evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter (1).exe" sh=8BE4C277A62F2400C3B0A20F39297D310774E2AC ft=1 fh=d69c639933d87dfe vn="Win32/Toolbar.SearchSuite evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter.exe" sh=CFCF0ADB9C1CF62D655041B7082EF3B017E1C3EF ft=1 fh=c3cf7631b8bb7034 vn="Win32/LoadTubes.D evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Eigene Dateien\Downloads\setup_codec_3dx.exe" sh=373374C26F18E43E9B7452405CC2A5DD4AC9F70E ft=1 fh=e95b08ab27f34774 vn="Win32/SoftonicDownloader.D evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe" sh=7A9A81DF947762FEEF571DD4EA78151F45A93FDC ft=1 fh=b435d59e704945b6 vn="Win32/SoftonicDownloader.D evtl. unerwünschte Anwendung" ac=I fn="H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_vso-downloader.exe" sh=890F1EDBA898E362BD225666AE3BDF862B343492 ft=1 fh=51f91afe2f642905 vn="Mehrere Bedrohungen" ac=I fn="H:\Katja\Eigene Dateien\Downloads\video_downloader.exe" sh=F6B71E6DF0EF3ED6289EE4B8A00F6A07A6A9D3D0 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Iminent.I evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2013-10-09 205300\Backup Files 2013-10-09 205300\Backup files 1.zip" sh=D93DFB48F135DD4DE95CB82544C3EDA3BAD2C753 ft=1 fh=d1199f70f2992f69 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2013-10-09 205300\Backup Files 2013-10-09 205300\C\Users\Martin Rinke\AppData\Local\DownloadGuide\Offers\plus-hd-3-8.exe" sh=38A38A0A5F21B87E2110E696B011AD4208388466 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Iminent.I evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2013-10-09 205300\Backup Files 2013-10-09 205300\C\Users\Martin Rinke\AppData\Roaming\Mozilla\Firefox\Profiles\5x1hhb18.default\extensions\webbooster@iminent.com.xpi" sh=1E46D343C6FEEF369583003B0047CDC0970A7987 ft=1 fh=6d53e81a0b77d269 vn="Win32/Toolbar.Montiera.B evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2013-10-09 205300\Backup Files 2013-10-09 205300\C\Users\Martin Rinke\AppData\Roaming\Mozilla\Firefox\Profiles\5x1hhb18.default\extensions\ffxtlbr@iminent.com\uninstall.exe" sh=A4C162AB072BACD82BEF5C23DFA743B8C57FC063 ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2013-10-16 121235\Backup Files 2013-10-16 121235\Backup files 2.zip" sh=B1D9F6E9C42C0589D956AD40E9CF8C5B71237214 ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2013-11-18 213935\Backup Files 2013-11-18 213935\Backup files 2.zip" sh=4336A730C03E3AAE359DB4F1C9EA7A4CB26BC674 ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-01-08 154935\Backup Files 2014-01-08 154935\Backup files 3.zip" sh=8E32DBA7C7DE7B414B07D610076C895CD1BA5A3B ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-01-20 082853\Backup Files 2014-01-20 082853\Backup files 3.zip" sh=40F27881F380661CC4FAB9E798C9E696080AC600 ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-01-20 082853\Backup Files 2014-01-20 082853\Backup files 6.zip" sh=BE2E6F82869EBC3E604CD4B2467E8E56CD949EB7 ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-01-29 125128\Backup Files 2014-01-29 125128\Backup files 3.zip" sh=0624A1478E8233B45843AF1BD39CD963A89E087A ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-01-29 125128\Backup Files 2014-01-29 125128\Backup files 6.zip" sh=4A263C35EAC2E8D3444FD6F68974B0E31F48512E ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-04-03 125403\Backup Files 2014-04-03 125403\Backup files 3.zip" sh=41C9F1EABF82ABF0C5D1162F3B1E17F955512368 ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-04-03 125403\Backup Files 2014-04-03 125403\Backup files 7.zip" sh=48C692928C243EB297DF1F3A86D3B076F07527D0 ft=0 fh=0000000000000000 vn="Win32/Packed.ScrambleWrapper.D evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-07-09 081309\Backup Files 2014-07-09 081309\Backup files 3.zip" sh=1127255B84A61DA6E2FE42ED1EEA5ED5D4CDB914 ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-07-09 081309\Backup Files 2014-07-09 081309\Backup files 6.zip" sh=E69DA8A766FBC786393D5BF3E5B0584B855E2260 ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="H:\MARTINRINKE-PC\Backup Set 2014-10-20 083256\Backup Files 2014-10-20 083256\Backup files 8.zip" sh=7D4A3CA3A3789D1EA7530FE4727D6BA8E8B47B83 ft=1 fh=4d32dd9dfb87fc86 vn="Win32/Conduit.SearchProtect.E evtl. unerwünschte Anwendung" ac=I fn="H:\Sicherung 2013-09-29\Kerstin\Anwendungsdaten\SearchProtect\bin\CltMngSvc.exe" sh=FC96B1F32B9320881BA847B4B84AF0EF096CB99D ft=1 fh=e2b5ce1f1ae776f7 vn="Win32/Conduit.SearchProtect.D evtl. unerwünschte Anwendung" ac=I fn="H:\Sicherung 2013-09-29\Kerstin\Anwendungsdaten\SearchProtect\bin\SPRunner.exe" sh=8202466E1DE3A815AB172AFF4383E4BD94278DCF ft=1 fh=89f70014390bbe76 vn="Win32/Conduit.SearchProtect.S evtl. unerwünschte Anwendung" ac=I fn="H:\Sicherung 2013-09-29\Kerstin\Anwendungsdaten\SearchProtect\bin\uninstall.exe" sh=77801D0E0DC02E8C50CDC73562F4D7F13FC1C18B ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="H:\Sicherung 2013-09-29\Kerstin\Anwendungsdaten\SearchProtect\ffprotect\application.js" sh=170ACC25B35BA845064591DF61F2D52142823738 ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="H:\Sicherung 2013-09-29\Kerstin\Anwendungsdaten\SearchProtect\ffprotect\nsprotector.js" |
21.10.2014, 14:52 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.
__________________Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Martin Rinke\9zol3d5lnss4 C:\Users\Martin Rinke\Downloads\MyPhoneExplorer_Setup_1.8.5.exe H:\Katja\Anwendungsdaten\SearchProtect\ffprotect H:\Katja\Anwendungsdaten\SearchProtect\ffprotect H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter (1).exe H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter.exe H:\Katja\Eigene Dateien\Downloads\setup_codec_3dx.exe H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_vso-downloader.exe H:\Katja\Eigene Dateien\Downloads\video_downloader.exe EmptyTemp: Hosts: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ |
21.10.2014, 21:09 | #19 |
| Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll Moin cosinus, schreibe hier von meinem Laptop. Zunächst vielen Dank für die Antwort. Heute morgen gegen 2:00 Uhr war der eset Virenscanner durch. Ich komme erst am Freitag wieder dazu, Deinem Rat zu folgen und die fixlist zu posten. Sorry, aber die Arbeit ruft, und ich bin bis Freitagabend nicht daheim. Mein Rechner bleibt bis dahin aus. Vielen vielen Dank bis dahin. CU on friday |
25.10.2014, 22:02 | #20 |
| Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll Moin cosinus, da bin ich wieder. Hier folgt der log Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-10-2014 Ran by Martin Rinke at 2014-10-25 22:57:19 Run:3 Running from C:\Users\Martin Rinke\Downloads Loaded Profiles: Martin Rinke & Acronis Agent User (Available profiles: Martin Rinke & Kerstin & Acronis Agent User) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Martin Rinke\9zol3d5lnss4 C:\Users\Martin Rinke\Downloads\MyPhoneExplorer_Setup_1.8.5.exe H:\Katja\Anwendungsdaten\SearchProtect\ffprotect H:\Katja\Anwendungsdaten\SearchProtect\ffprotect H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter (1).exe H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter.exe H:\Katja\Eigene Dateien\Downloads\setup_codec_3dx.exe H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_vso-downloader.exe H:\Katja\Eigene Dateien\Downloads\video_downloader.exe EmptyTemp: Hosts: ***************** "C:\Users\Martin Rinke\9zol3d5lnss4" => File/Directory not found. "C:\Users\Martin Rinke\Downloads\MyPhoneExplorer_Setup_1.8.5.exe" => File/Directory not found. "H:\Katja\Anwendungsdaten\SearchProtect\ffprotect" => File/Directory not found. "H:\Katja\Anwendungsdaten\SearchProtect\ffprotect" => File/Directory not found. "H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter (1).exe" => File/Directory not found. "H:\Katja\Eigene Dateien\Downloads\Setup21_FreeConverter.exe" => File/Directory not found. "H:\Katja\Eigene Dateien\Downloads\setup_codec_3dx.exe" => File/Directory not found. "H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe" => File/Directory not found. "H:\Katja\Eigene Dateien\Downloads\SoftonicDownloader_fuer_vso-downloader.exe" => File/Directory not found. "H:\Katja\Eigene Dateien\Downloads\video_downloader.exe" => File/Directory not found. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. EmptyTemp: => Removed 6.4 MB temporary data. The system needed a reboot. ==== End of Fixlog ==== |
25.10.2014, 22:05 | #21 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll Sieht soweit ok aus Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat. Ist aber nur optional. Um Usertracking zu verhindern kann man gut die Firefox-Erweiterung Ghostery verwenden. Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie ) Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird. Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________ --> Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll |
25.10.2014, 22:16 | #22 |
| Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll Moin und danke für Deine Hilfe. Beim Starten poppt immer noch diese Meldung hoch: Problem beim Starten von C:\Program Files (x86)\HomeTab\TBUpdate.dll Das angegeben Modul wurde nicht gefunden. Es beruhigt mich aber, dass das nicht weiter gefährlich ist. Zwar ein büschen lästig, aber die Meldung lässt sich einfach wegklicken. |
25.10.2014, 22:18 | #23 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Scan klicken
__________________ Logfiles bitte immer in CODE-Tags posten |
25.10.2014, 22:26 | #24 |
| Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-10-2014 Ran by Martin Rinke (administrator) on MARTINRINKE-PC on 25-10-2014 23:23:10 Running from C:\Users\Martin Rinke\Downloads Loaded Profiles: Martin Rinke & Acronis Agent User (Available profiles: Martin Rinke & Kerstin & Acronis Agent User) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (AMD) C:\Windows\System32\atieclxx.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Agent\agent.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Acronis) C:\Program Files (x86)\Acronis\ARSM\arsm.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Acronis) C:\Program Files (x86)\Acronis\BackupAndRecovery\mms.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Acronis) C:\Program Files (x86)\Acronis\TrayMonitor\TrayMonitor.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Vimicro Corporation) C:\Program Files (x86)\Vimicro Corporation\VMUVC\VMonitor.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe (Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Nitro PDF) C:\Program Files (x86)\Nitro PDF\Professional 7\NitroPDF.exe (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-13] (Realtek Semiconductor) HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395736 2013-10-02] (Acronis) HKLM\...\Run: [TrayMonitor.exe] => C:\Program Files (x86)\Acronis\TrayMonitor\TrayMonitor.exe [1498848 2013-10-02] (Acronis) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-16] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [VMonitorVMUVC] => C:\Program Files (x86)\Vimicro Corporation\VMUVC\VMonitor.exe [143360 2010-09-10] (Vimicro Corporation) HKLM-x32\...\Run: [BackupAndRecoveryMonitor.exe] => C:\Program Files (x86)\Acronis\BackupAndRecovery\BackupAndRecoveryMonitor.exe [1561240 2013-10-02] (Acronis) HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1104608 2013-01-22] (Acronis) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1743648 2013-06-13] (Wondershare) HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [305088 2011-04-25] (Citrix Systems, Inc.) HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2010-08-12] (Acresso Corporation) HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\Run: [w1Synt] => C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe [32768 2014-03-21] (Microsoft Corporation) HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\Run: [GoogleChromeAutoLaunch_EAAF700B7549734D0B66A4B86C39037C] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [854344 2014-10-10] (Google Inc.) HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\RunOnce: [Uninstall C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64" HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\RunOnce: [Uninstall C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217\amd64" HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\MountPoints2: G - G:\LaunchU3.exe -a HKU\S-1-5-21-4136266569-681284793-1319911660-1000\...\MountPoints2: {25358e3f-30b4-11e3-bfa4-b8975a476b92} - G:\LaunchU3.exe -a Startup: C:\Users\Martin Rinke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> (No File) Startup: C:\Users\Martin Rinke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\start.lnk ShortcutTarget: start.lnk -> (No File) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3218961A36BECE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://www.google.de/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab SearchScopes: HKCU - URL hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms} SearchScopes: HKCU - SuggestionsURL_JSON hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=99&gid=1&dbCode=1&command={searchTerms} SearchScopes: HKCU - TopResultURLFallback hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms} BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Martin Rinke\AppData\Roaming\Mozilla\Firefox\Profiles\5x1hhb18.default FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro PDF\Professional 7\npnitromozilla.dll ( ) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\cgpcfg.dll (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxmui.dll (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icafile.dll (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icalogon.dll (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPCltInst11.dll (BroadSoft, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\sslsdk_b.dll (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll (Citrix Systems, Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Personas Plus - C:\Users\Martin Rinke\AppData\Roaming\Mozilla\Firefox\Profiles\5x1hhb18.default\Extensions\personas@christopher.beard.xpi [2013-10-16] FF Extension: Adblock Plus - C:\Users\Martin Rinke\AppData\Roaming\Mozilla\Firefox\Profiles\5x1hhb18.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-03] Chrome: ======= CHR HomePage: Default -> https://www.xing.com/ CHR StartupUrls: Default -> "https://www.xing.com/de", "https://www.google.de/" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter} CHR Profile: C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default CHR Extension: (TooManyTabs für Chrome) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\amigcgbheognjmfkaieeeadojiibgbdp [2014-07-29] CHR Extension: (Google Docs) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-29] CHR Extension: (Lucidchart diagrammer – Online) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\apboafhkiegglekeafbckfjldecefkhn [2014-07-29] CHR Extension: (Google Drive) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-29] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-04] CHR Extension: (Turn Off the Lights) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2014-07-29] CHR Extension: (YouTube) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-29] CHR Extension: (New york themes (sublimes city)) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\cchhdpienadooplffongnkgpdoojkfgb [2014-07-29] CHR Extension: (Google-Suche) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-29] CHR Extension: (Office Editor) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\gbkeegbaiigmenfmjfclcdgdpimamgkj [2014-09-29] CHR Extension: (PDFescape Free PDF Editor) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\gdefoklganepljiopdnglodohlgfikkl [2014-07-29] CHR Extension: (AdBlock) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-07-29] CHR Extension: (Google Wallet) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-29] CHR Extension: (Google Mail) - C:\Users\Martin Rinke\AppData\Local\Google\Chrome\User Data\default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-29] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AcronisAgent; C:\Program Files (x86)\Common Files\Acronis\Agent\agent.exe [2059256 2012-12-29] (Acronis) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [806704 2014-10-16] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-10-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-16] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [994096 2014-10-16] (Avira Operations GmbH & Co. KG) R2 ARSM; C:\Program Files (x86)\Acronis\ARSM\arsm.exe [5851192 2013-10-02] (Acronis) R2 MMS; C:\Program Files (x86)\Acronis\BackupAndRecovery\mms.exe [11138464 2013-10-02] (Acronis) R2 NitroDriverReadSpool2; C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe [216072 2012-09-04] (Nitro PDF Software) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-16] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-16] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-09-30] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [43064 2014-10-16] (Avira Operations GmbH & Co. KG) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-10-20] (Malwarebytes Corporation) R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1119672 2013-12-03] (Acronis) R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [183224 2013-12-03] (Acronis) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-12-16] (TuneUp Software) R3 VMUVC; C:\Windows\System32\Drivers\VMUVC.sys [202112 2010-11-12] (Vimicro Corporation) R3 vvftUVC; C:\Windows\System32\drivers\vvftUVC.sys [303616 2008-07-01] (Vimicro Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-25 22:50 - 2014-10-25 22:50 - 00000000 ____D () C:\Users\Martin Rinke\Downloads\FRST-OlderVersion 2014-10-25 20:14 - 2014-10-25 22:06 - 00000000 ____D () C:\ProgramData\tmp 2014-10-25 20:14 - 2014-10-25 20:14 - 00001031 _____ () C:\Users\Public\Desktop\Mein CEWE FOTOBUCH.lnk 2014-10-25 20:14 - 2014-10-25 20:14 - 00001011 _____ () C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk 2014-10-25 19:30 - 2014-10-25 19:30 - 00000000 ____D () C:\Program Files\CEWE 2014-10-25 19:26 - 2014-10-25 19:26 - 01633192 _____ () C:\Users\Kerstin\Downloads\setup_Mein_CEWE_FOTOBUCH(1).exe 2014-10-20 22:29 - 2014-10-20 22:29 - 00001212 _____ () C:\Users\Martin Rinke\Downloads\mbam.2.txt 2014-10-20 21:47 - 2014-10-20 21:47 - 00001210 _____ () C:\Users\Martin Rinke\Downloads\mbam.txt 2014-10-20 21:29 - 2014-10-20 21:29 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-10-20 20:37 - 2014-10-20 20:38 - 02347384 _____ (ESET) C:\Users\Martin Rinke\Downloads\esetsmartinstaller_deu.exe 2014-10-20 20:29 - 2014-10-20 22:07 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-20 20:29 - 2014-10-20 21:11 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-20 20:29 - 2014-10-20 21:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-20 20:29 - 2014-10-20 21:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-10-20 20:29 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-10-20 20:29 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-10-20 20:29 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-10-20 20:25 - 2014-10-20 20:28 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Martin Rinke\Downloads\mbam-setup-2.0.3.1025.exe 2014-10-20 19:15 - 2014-10-20 19:15 - 00001417 _____ () C:\Users\Martin Rinke\Desktop\JRT.txt 2014-10-20 19:12 - 2014-10-20 19:12 - 00000000 ____D () C:\Windows\ERUNT 2014-10-20 19:11 - 2014-10-20 19:11 - 01705698 _____ (Thisisu) C:\Users\Martin Rinke\Downloads\JRT.exe 2014-10-20 19:02 - 2014-10-20 19:02 - 01976320 _____ () C:\Users\Martin Rinke\Downloads\AdwCleaner_4.000.exe 2014-10-17 10:13 - 2014-10-10 04:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-10-17 10:13 - 2014-10-10 04:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-10-17 10:13 - 2014-10-10 04:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-10-17 10:13 - 2014-10-07 04:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-10-17 10:13 - 2014-10-07 04:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-10-17 10:13 - 2014-09-29 02:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-10-17 10:13 - 2014-09-26 00:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-10-17 10:13 - 2014-09-26 00:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-10-17 10:13 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-10-17 10:13 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-10-17 10:13 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-10-17 10:13 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-10-17 10:13 - 2014-09-26 00:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-10-17 10:13 - 2014-09-19 04:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-10-17 10:13 - 2014-09-19 03:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-10-17 10:13 - 2014-09-19 03:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-10-17 10:13 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-10-17 10:13 - 2014-09-19 03:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-10-17 10:13 - 2014-09-19 03:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-10-17 10:13 - 2014-09-19 03:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-10-17 10:13 - 2014-09-19 03:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-10-17 10:13 - 2014-09-19 03:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-10-17 10:13 - 2014-09-19 03:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-10-17 10:13 - 2014-09-19 03:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-10-17 10:13 - 2014-09-19 03:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-10-17 10:13 - 2014-09-19 03:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-10-17 10:13 - 2014-09-19 03:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-10-17 10:13 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-10-17 10:13 - 2014-09-19 03:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-10-17 10:13 - 2014-09-19 03:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-10-17 10:13 - 2014-09-19 03:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-10-17 10:13 - 2014-09-19 03:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-10-17 10:13 - 2014-09-19 03:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-10-17 10:13 - 2014-09-19 03:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-10-17 10:13 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-10-17 10:13 - 2014-09-19 03:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-10-17 10:13 - 2014-09-19 03:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-10-17 10:13 - 2014-09-19 03:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-10-17 10:13 - 2014-09-19 03:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-10-17 10:13 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-10-17 10:13 - 2014-09-19 02:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-10-17 10:13 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-10-17 10:13 - 2014-09-19 02:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-10-17 10:13 - 2014-09-19 02:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-10-17 10:13 - 2014-09-19 02:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-10-17 10:13 - 2014-09-19 02:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-10-17 10:13 - 2014-09-19 02:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-10-17 10:13 - 2014-09-19 02:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-10-17 10:13 - 2014-09-19 02:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-10-17 10:13 - 2014-09-19 02:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-10-17 10:13 - 2014-09-19 02:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-10-17 10:13 - 2014-09-19 02:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-10-17 10:13 - 2014-09-19 02:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-10-17 10:13 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-10-17 10:13 - 2014-09-19 02:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-10-17 10:13 - 2014-09-19 02:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-10-17 10:13 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-10-17 10:13 - 2014-09-19 01:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-10-17 10:13 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-10-17 10:13 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-10-17 10:13 - 2014-06-19 00:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-17 10:13 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2014-10-17 10:13 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll 2014-10-17 10:13 - 2014-06-19 00:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-17 10:13 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll 2014-10-17 10:13 - 2014-06-19 00:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-17 10:12 - 2014-09-18 04:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-10-17 10:12 - 2014-09-18 03:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-10-17 10:12 - 2014-09-04 07:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-10-17 10:12 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll 2014-10-17 10:12 - 2014-08-29 04:07 - 05780480 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-10-17 10:12 - 2014-08-29 04:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-10-17 10:12 - 2014-08-29 04:07 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2014-10-17 10:12 - 2014-08-29 04:07 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-10-17 10:12 - 2014-08-29 04:06 - 01125888 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-10-17 10:12 - 2014-08-29 03:44 - 04922368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-10-17 10:12 - 2014-08-29 03:44 - 01050112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-10-17 10:12 - 2014-08-29 03:44 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2014-10-17 10:12 - 2014-08-29 03:44 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-10-17 10:12 - 2014-07-17 04:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-10-17 10:12 - 2014-07-17 04:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-10-17 10:12 - 2014-07-17 04:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2014-10-17 10:12 - 2014-07-17 04:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2014-10-17 10:12 - 2014-07-17 04:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-10-17 10:12 - 2014-07-17 04:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-10-17 10:12 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll 2014-10-17 10:12 - 2014-07-17 03:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-10-17 10:12 - 2014-07-17 03:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-10-17 10:12 - 2014-07-17 03:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-10-17 10:12 - 2014-07-17 03:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-10-17 10:11 - 2014-09-13 03:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-17 10:11 - 2014-09-13 03:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-10-04 22:56 - 2014-10-25 21:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-10-04 22:26 - 2014-10-04 22:27 - 00000000 ____D () C:\Users\Kerstin\Documents\Philips GoGear Betriebsanleitung 2014-10-01 11:14 - 2014-09-25 04:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-10-01 11:14 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2014-10-01 00:23 - 2014-10-01 00:23 - 00001517 _____ () C:\Users\Martin Rinke\Downloads\2014.10.01 Protokoll Malwarebytes.txt 2014-10-01 00:09 - 2014-10-01 00:10 - 00004680 _____ () C:\Users\Martin Rinke\Downloads\Ereignisse.txt 2014-09-30 17:19 - 2014-10-25 23:23 - 00023785 _____ () C:\Users\Martin Rinke\Downloads\FRST.txt 2014-09-30 17:19 - 2014-10-20 19:25 - 00018681 _____ () C:\Users\Martin Rinke\Downloads\Addition.txt 2014-09-30 17:18 - 2014-10-25 23:23 - 00000000 ____D () C:\FRST 2014-09-30 17:18 - 2014-10-25 22:50 - 02112512 _____ (Farbar) C:\Users\Martin Rinke\Downloads\FRST64.exe 2014-09-29 19:37 - 2014-09-29 19:37 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\ICAClient 2014-09-29 19:37 - 2014-09-29 19:37 - 00000000 ____D () C:\Users\Kerstin\AppData\Local\Citrix 2014-09-28 16:18 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-09-28 16:17 - 2014-10-20 19:05 - 00000000 ____D () C:\AdwCleaner 2014-09-26 16:48 - 2014-09-26 16:49 - 14153672 _____ (Citrix Systems, Inc.) C:\Users\Martin Rinke\Downloads\CitrixOnlinePluginWeb (1).exe 2014-09-26 16:46 - 2014-09-26 16:46 - 00000000 ____D () C:\ProgramData\Citrix 2014-09-26 16:45 - 2014-09-26 16:45 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Roaming\ICAClient 2014-09-26 16:45 - 2014-09-26 16:45 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Local\Citrix 2014-09-26 16:45 - 2014-09-26 16:45 - 00000000 ____D () C:\Program Files (x86)\Citrix 2014-09-26 16:40 - 2014-09-26 16:42 - 14153672 _____ (Citrix Systems, Inc.) C:\Users\Martin Rinke\Downloads\CitrixOnlinePluginWeb.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-25 23:22 - 2014-07-29 15:17 - 00001122 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-25 23:10 - 2013-10-04 12:59 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Roaming\Nitro PDF 2014-10-25 23:07 - 2009-07-14 06:45 - 00031680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-25 23:07 - 2009-07-14 06:45 - 00031680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-25 23:04 - 2013-10-02 01:22 - 01143584 _____ () C:\Windows\WindowsUpdate.log 2014-10-25 23:01 - 2013-10-09 13:23 - 00000000 ____D () C:\ProgramData\TEMP 2014-10-25 23:00 - 2013-10-09 10:43 - 00000000 ____D () C:\Users\Martin Rinke\Documents\Outlook-Dateien 2014-10-25 22:58 - 2014-07-29 15:17 - 00001118 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-25 22:58 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-25 22:58 - 2009-07-14 06:51 - 00066208 _____ () C:\Windows\setupact.log 2014-10-25 22:51 - 2010-11-21 05:47 - 02459596 _____ () C:\Windows\PFRO.log 2014-10-25 22:50 - 2013-10-01 01:28 - 00000000 ____D () C:\Users\Martin Rinke 2014-10-25 22:41 - 2013-10-03 13:47 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-25 19:35 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-10-25 18:56 - 2013-11-13 20:55 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Nitro PDF 2014-10-20 23:57 - 2014-06-23 19:37 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Roaming\UseNeXT 2014-10-20 23:55 - 2013-10-04 13:33 - 00000000 ____D () C:\Users\Martin Rinke\Documents\UseNeXT 2014-10-20 22:01 - 2013-10-01 01:38 - 00003982 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{A31852FC-9FB0-4155-B359-F8F56639749F} 2014-10-20 19:38 - 2013-10-03 15:57 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch 2014-10-20 12:45 - 2013-10-16 12:04 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Roaming\Canon 2014-10-20 10:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-10-20 09:44 - 2011-04-12 09:43 - 00699190 _____ () C:\Windows\system32\perfh007.dat 2014-10-20 09:44 - 2011-04-12 09:43 - 00149330 _____ () C:\Windows\system32\perfc007.dat 2014-10-20 09:44 - 2009-07-14 07:13 - 01619700 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-10-20 08:20 - 2009-07-14 06:45 - 00408392 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-20 08:20 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-10-20 08:17 - 2014-04-30 15:53 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-10-18 00:47 - 2013-10-01 09:59 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-10-18 00:43 - 2013-10-01 02:42 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-18 00:36 - 2013-10-01 02:42 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-10-17 15:53 - 2013-10-01 01:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-10-16 15:14 - 2013-10-02 13:16 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-10-16 15:14 - 2013-10-02 13:16 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-10-16 15:14 - 2013-10-02 13:16 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-10-02 15:53 - 2010-11-21 05:27 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-10-01 13:15 - 2013-10-02 13:45 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Roaming\vlc 2014-09-30 14:37 - 2013-10-03 16:54 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2014-09-30 14:36 - 2013-10-01 09:59 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Local\Microsoft Help 2014-09-29 19:39 - 2014-05-10 19:22 - 00000000 ____D () C:\Users\Kerstin\AppData\Roaming\Canon 2014-09-29 19:39 - 2013-11-06 19:05 - 00000000 ____D () C:\Users\Kerstin\Documents\Outlook-Dateien 2014-09-29 10:00 - 2013-10-01 01:41 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-09-25 12:28 - 2013-11-13 21:16 - 00000000 ____D () C:\Users\Kerstin\Documents\Fitness 2014-09-25 11:18 - 2013-11-13 21:16 - 00000000 ____D () C:\Users\Kerstin\Documents\Kontoauszüge 2014-09-25 01:07 - 2013-10-15 14:38 - 00000000 ____D () C:\Users\Martin Rinke\AppData\Roaming\Skype Some content of TEMP: ==================== C:\Users\Martin Rinke\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-17 15:12 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-10-2014 Ran by Martin Rinke at 2014-10-25 23:23:58 Running from C:\Users\Martin Rinke\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Acronis Backup & Recovery 11.5 Agent Core (HKLM-x32\...\{9CC39EA2-7D3A-4389-BD2C-FF0A4375F01F}) (Version: 11.5.37975 - Acronis) Acronis Backup & Recovery 11.5 Bootable Media Builder (HKLM-x32\...\{49B581BF-C3E1-4E8C-8BD2-47009A26D42F}) (Version: 11.5.37975 - Acronis) Acronis Backup & Recovery 11.5 Command-Line Tool (HKLM-x32\...\{4C2B4759-7625-4894-BF16-52828D2C9FDE}) (Version: 11.5.37975 - Acronis) Acronis Backup & Recovery 11.5 Tray Monitor (HKLM-x32\...\{08C0CADB-4DC6-450A-A8CE-761173DCFC42}) (Version: 11.5.37975 - Acronis) Acronis Backup & Recovery 11.5*Agent für Windows (HKLM-x32\...\{D9DC5B4F-1BAD-471E-A827-B3969AD24994}) (Version: 11.5.37975 - Acronis) Acronis Backup & Recovery 11.5*Management*Console (HKLM-x32\...\{784BE313-D87B-4EBC-A1A6-48AA605C40BC}) (Version: 11.5.37975 - Acronis) Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated) Antivirus Pro (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.306 - Avira) AudioCon (HKLM-x32\...\AudioCon) (Version: 1.0 - Basement Softworks) AVM FRITZ!Box Dokumentation (HKLM-x32\...\AVMFBox) (Version: - AVM Berlin) AVM FRITZ!Box Druckeranschluss (HKLM-x32\...\AVMFBoxPrinter) (Version: - AVM Berlin) BURY Update Manager 1.4.1 (HKLM-x32\...\BURY Update Manager_is1) (Version: - BURY Gmbh & Co. KG) CanoScan Toolbox Ver4.6 (HKLM-x32\...\{088A077A-8028-408C-AE7B-4512AE2A65A0}) (Version: - ) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4291 - CDBurnerXP) Citrix Online Plug-in - Web (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 12.1.44.1 - Citrix Systems, Inc.) Citrix Online Plug-in (DV) (x32 Version: 12.1.44.1 - Citrix Systems, Inc.) Hidden Citrix Online Plug-in (HDX) (x32 Version: 12.1.44.1 - Citrix Systems, Inc.) Hidden Citrix Online Plug-in (USB) (x32 Version: 12.1.44.1 - Citrix Systems, Inc.) Hidden Citrix Online Plug-in (Web) (x32 Version: 12.1.44.1 - Citrix Systems, Inc.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DesignPro 5 (HKLM-x32\...\InstallShield_{F82C6574-AD88-4B40-A432-970BC77F1BD2}) (Version: 5.5.708 - Avery Dennison) DesignPro 5 (x32 Version: 5.5.708 - Avery Dennison) Hidden Dragon NaturallySpeaking 11 (HKLM-x32\...\{EFFA53BC-8C04-2E21-3D90-A13B1697B0CA}) (Version: 11.50.100 - Nuance Communications Inc.) ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 15.0.20140212 - Landesfinanzdirektion Thüringen) Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.104 - Google Inc.) Google Earth (HKLM-x32\...\{A2264E8F-1649-11E3-8BED-B8AC6F98CCE3}) (Version: 7.1.2.2019 - Google) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden iLinc 11 Client (HKLM-x32\...\iLincClient.11) (Version: - ) Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation) Mein CEWE FOTOBUCH (HKLM-x32\...\Mein CEWE FOTOBUCH) (Version: 5.1.6 - CEWE Stiftung u Co. KGaA) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft OneDrive (HKCU\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 32.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0.2 (x86 de)) (Version: 32.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.5 - F.J. Wechselberger) Nitro Pro 7 (HKLM\...\{EEF9C83C-5D22-4BB8-8453-0F4F5F2328D2}) (Version: 7.5.0.29 - Nitro PDF Software) Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.1 - pdfforge) Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6690 - Realtek Semiconductor Corp.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SoftSkies (HKLM-x32\...\SoftSkies) (Version: 1.7 - SoundSpectrum) TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.340 - TuneUp Software) TuneUp Utilities 2014 (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 13.0.4000.245 - TuneUp Software) Hidden UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.) Vimicro UVC USB2.0 PC Camera (HKLM-x32\...\{71A51A91-E7D3-11DB-A386-005056C00008}) (Version: 2009.03.18 - Vimicro Corporation) Visual C++ 9.0 Runtime for Dragon NaturallySpeaking 64bit (x64) (HKLM\...\{4A5A427F-BA39-4BF0-7777-9A47FBE60C9F}) (Version: 11.0.0 - Nuance Communications Inc.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation) WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) WinX Free DVD to MPEG Ripper 4.4.26 (HKLM-x32\...\WinX Free DVD to MPEG Ripper_is1) (Version: - Digiarty Software,Inc.) XING Outlook Connector (HKLM\...\{3B8AF990-AE63-481C-BC4B-8BB8D7A93B80}) (Version: 2.2.0 - XING) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-4136266569-681284793-1319911660-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4136266569-681284793-1319911660-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4136266569-681284793-1319911660-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4136266569-681284793-1319911660-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4136266569-681284793-1319911660-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Martin Rinke\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 20-10-2014 06:33:24 Windows-Sicherung 20-10-2014 19:25:03 Dragon NaturallySpeaking 11 wurde entfernt. 25-10-2014 16:48:50 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2014-10-25 22:57 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {175CC5A7-269A-4226-A679-11C883D6F376} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-24] (Adobe Systems Incorporated) Task: {192D3862-44C1-43F8-8FB1-4AB2351D3C4E} - System32\Tasks\Browser Updater\Browser Updater => Rundll32.exe "C:\Program Files (x86)\HomeTab\TBUpdater.dll",TBCheckForUpdate Task: {38F8E9B8-CFCA-4B33-BD53-5F3334EBD275} - \{5B2F6C6D-7973-4195-A550-81033A447A93} No Task File <==== ATTENTION Task: {4805B0FA-735D-4B0D-AF50-5C691DADF634} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2014-07-16] (TuneUp Software) Task: {688906B1-ED7E-4830-B7F8-2CE948F84935} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-29] (Google Inc.) Task: {694CD1AC-1694-4F58-B3A7-D5039301BE8E} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {AFAFDF05-67D2-4355-8DFA-C978B422D027} - System32\Tasks\Xing Social Recommendations => C:\Program Files\XING\XING Outlook Connector\32-bit\XingSocial.exe [2014-01-08] (XING AG) Task: {E5E051A9-3542-44E2-92CC-533CA218D4D5} - System32\Tasks\xingoscupdate => C:\Program Files\XING\XING Outlook Connector\xingoscupdate.exe [2014-01-08] (XING) Task: {F49F24ED-AA1D-4568-8324-0A35266A88C7} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21] (Adobe Systems Incorporated) Task: {FE3276A4-52C2-4550-ACD4-6BEC0780BDA0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-29] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-12-18 18:49 - 2013-08-23 14:36 - 00721263 _____ () C:\Windows\SysWOW64\WSCM64.dll 2013-10-02 12:50 - 2006-06-27 16:28 - 00322048 _____ () C:\Windows\system32\CNQL3203.DLL 2014-07-16 10:24 - 2014-07-16 10:24 - 00699704 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll 2013-10-02 02:57 - 2013-10-02 02:57 - 00284304 _____ () C:\Program Files (x86)\Common Files\Acronis\BackupAndRecovery\Common\fnls.dll 2013-10-02 02:57 - 2013-10-02 02:57 - 00327040 _____ () C:\Program Files (x86)\Common Files\Acronis\BackupAndRecovery\Common\events_trace.dll 2013-10-02 02:58 - 2013-10-02 02:58 - 00441512 _____ () C:\Program Files (x86)\Common Files\Acronis\BackupAndRecovery\Common\FileTrace.dll 2013-10-02 03:00 - 2013-10-02 03:00 - 00921024 _____ () C:\Program Files (x86)\Acronis\BackupAndRecovery\human_resolving_mms.dll 2013-01-22 14:30 - 2013-01-22 14:30 - 00013120 _____ () C:\Program Files (x86)\Common Files\Acronis\TibMounter\icudt38.dll 2014-10-16 15:27 - 2014-10-10 04:03 - 01042760 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libglesv2.dll 2014-10-16 15:27 - 2014-10-10 04:03 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libegl.dll 2014-10-16 15:27 - 2014-10-10 04:04 - 08910664 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\pdf.dll 2014-10-16 15:27 - 2014-10-10 04:03 - 01681224 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\ffmpegsumo.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf 2013-02-14 15:46 - 2013-02-14 15:46 - 01044048 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll 2012-09-04 22:40 - 2012-09-04 22:40 - 07751688 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\npdf.dll 2012-09-04 22:39 - 2012-09-04 22:39 - 01649152 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPActions.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 02971136 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPAnnotations.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 01051136 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPAttachments.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 01587200 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPBookmarks.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 01776128 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPCreatePDF.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 02603520 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPDigitalSignature.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 01793024 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPExport.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 02861568 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPForms.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 01741312 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPLinks.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 02118656 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPObjectTool.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 00823816 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\idrskrn14.dll 2012-09-04 22:39 - 2012-09-04 22:39 - 01525760 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPOptimizer.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 01856000 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPPageEdit.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 01470464 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPPrint.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 01522176 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPScan2PDF.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 01785856 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPSetSecurity.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 02069504 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPStamper.npp 2012-09-04 22:39 - 2012-09-04 22:39 - 01861632 _____ () C:\Program Files (x86)\Nitro PDF\Professional 7\plug_ins\NPWatermarks.npp ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:7FFED16F ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Acronis Agent User (S-1-5-21-4136266569-681284793-1319911660-1003 - Administrator - Enabled) => C:\Users\Acronis Agent User Administrator (S-1-5-21-4136266569-681284793-1319911660-500 - Administrator - Disabled) Gast (S-1-5-21-4136266569-681284793-1319911660-501 - Limited - Disabled) Kerstin (S-1-5-21-4136266569-681284793-1319911660-1001 - Limited - Enabled) => C:\Users\Kerstin Martin Rinke (S-1-5-21-4136266569-681284793-1319911660-1000 - Administrator - Enabled) => C:\Users\Martin Rinke ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/25/2014 11:00:21 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/25/2014 10:53:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/25/2014 10:06:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe, Version: 0.0.0.0, Zeitstempel: 0x53db7f75 Name des fehlerhaften Moduls: Qt5Core.dll, Version: 5.1.1.0, Zeitstempel: 0x52a8888d Ausnahmecode: 0xc000041d Fehleroffset: 0x00000000001b1d9b ID des fehlerhaften Prozesses: 0x1210 Startzeit der fehlerhaften Anwendung: 0xMein CEWE FOTOBUCH.exe0 Pfad der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe1 Pfad des fehlerhaften Moduls: Mein CEWE FOTOBUCH.exe2 Berichtskennung: Mein CEWE FOTOBUCH.exe3 Error: (10/25/2014 10:06:21 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe, Version: 0.0.0.0, Zeitstempel: 0x53db7f75 Name des fehlerhaften Moduls: Qt5Core.dll, Version: 5.1.1.0, Zeitstempel: 0x52a8888d Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000001b1d9b ID des fehlerhaften Prozesses: 0x1210 Startzeit der fehlerhaften Anwendung: 0xMein CEWE FOTOBUCH.exe0 Pfad der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe1 Pfad des fehlerhaften Moduls: Mein CEWE FOTOBUCH.exe2 Berichtskennung: Mein CEWE FOTOBUCH.exe3 Error: (10/25/2014 09:38:32 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe, Version: 0.0.0.0, Zeitstempel: 0x53db7f75 Name des fehlerhaften Moduls: Qt5Core.dll, Version: 5.1.1.0, Zeitstempel: 0x52a8888d Ausnahmecode: 0xc000041d Fehleroffset: 0x00000000001b1d9b ID des fehlerhaften Prozesses: 0xb18 Startzeit der fehlerhaften Anwendung: 0xMein CEWE FOTOBUCH.exe0 Pfad der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe1 Pfad des fehlerhaften Moduls: Mein CEWE FOTOBUCH.exe2 Berichtskennung: Mein CEWE FOTOBUCH.exe3 Error: (10/25/2014 09:38:10 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe, Version: 0.0.0.0, Zeitstempel: 0x53db7f75 Name des fehlerhaften Moduls: Qt5Core.dll, Version: 5.1.1.0, Zeitstempel: 0x52a8888d Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000001b1d9b ID des fehlerhaften Prozesses: 0xb18 Startzeit der fehlerhaften Anwendung: 0xMein CEWE FOTOBUCH.exe0 Pfad der fehlerhaften Anwendung: Mein CEWE FOTOBUCH.exe1 Pfad des fehlerhaften Moduls: Mein CEWE FOTOBUCH.exe2 Berichtskennung: Mein CEWE FOTOBUCH.exe3 Error: (10/25/2014 06:43:23 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/21/2014 01:52:33 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (10/20/2014 08:49:28 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (10/20/2014 08:38:42 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Error: (10/25/2014 10:58:33 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (10/25/2014 10:58:33 PM) (Source: atikmdag) (EventID: 19468) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (10/25/2014 10:51:57 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (10/25/2014 10:51:57 PM) (Source: atikmdag) (EventID: 19468) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (10/25/2014 10:44:51 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (10/25/2014 10:44:27 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (10/25/2014 10:06:34 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (10/25/2014 06:41:36 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (10/25/2014 06:41:36 PM) (Source: atikmdag) (EventID: 19468) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (10/20/2014 08:36:45 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Microsoft Office Sessions: ========================= Error: (10/25/2014 11:00:21 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/25/2014 10:53:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/25/2014 10:06:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Mein CEWE FOTOBUCH.exe0.0.0.053db7f75Qt5Core.dll5.1.1.052a8888dc000041d00000000001b1d9b121001cff08b5a52fcfcC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exeC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Qt5Core.dll6c5f8f1b-5c82-11e4-acf9-b8975a476b92 Error: (10/25/2014 10:06:21 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Mein CEWE FOTOBUCH.exe0.0.0.053db7f75Qt5Core.dll5.1.1.052a8888dc000000500000000001b1d9b121001cff08b5a52fcfcC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exeC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Qt5Core.dll634eb172-5c82-11e4-acf9-b8975a476b92 Error: (10/25/2014 09:38:32 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Mein CEWE FOTOBUCH.exe0.0.0.053db7f75Qt5Core.dll5.1.1.052a8888dc000041d00000000001b1d9bb1801cff07fcaecb64fC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exeC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Qt5Core.dll7ffe31fb-5c7e-11e4-acf9-b8975a476b92 Error: (10/25/2014 09:38:10 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Mein CEWE FOTOBUCH.exe0.0.0.053db7f75Qt5Core.dll5.1.1.052a8888dc000000500000000001b1d9bb1801cff07fcaecb64fC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exeC:\Program Files\CEWE\Mein CEWE FOTOBUCH\Qt5Core.dll72f74a1e-5c7e-11e4-acf9-b8975a476b92 Error: (10/25/2014 06:43:23 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/21/2014 01:52:33 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (10/20/2014 08:49:28 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Martin Rinke\Downloads\esetsmartinstaller_deu.exe Error: (10/20/2014 08:38:42 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Martin Rinke\Downloads\esetsmartinstaller_deu.exe ==================== Memory info =========================== Processor: AMD FX(tm)-6300 Six-Core Processor Percentage of memory in use: 30% Total physical RAM: 7935.3 MB Available physical RAM: 5537.03 MB Total Pagefile: 15868.79 MB Available Pagefile: 13186.44 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:116.31 GB) (Free:49.93 GB) NTFS Drive d: () (Fixed) (Total:116.48 GB) (Free:115.54 GB) NTFS Drive h: (Volume) (Fixed) (Total:1397.26 GB) (Free:251.12 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: D294D294) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=116.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=116.5 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1397.3 GB) (Disk ID: 40D6E131) Partition 1: (Not Active) - (Size=1397.3 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
25.10.2014, 22:57 | #25 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab SearchScopes: HKCU - URL http://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms} SearchScopes: HKCU - SuggestionsURL_JSON http://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=99&gid=1&dbCode=1&command={searchTerms} SearchScopes: HKCU - TopResultURLFallback http://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms} Task: {38F8E9B8-CFCA-4B33-BD53-5F3334EBD275} - \{5B2F6C6D-7973-4195-A550-81033A447A93} No Task File <==== ATTENTION Task: {192D3862-44C1-43F8-8FB1-4AB2351D3C4E} - System32\Tasks\Browser Updater\Browser Updater => Rundll32.exe "C:\Program Files (x86)\HomeTab\TBUpdater.dll",TBCheckForUpdate C:\Program Files (x86)\HomeTab Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
25.10.2014, 23:13 | #26 |
| Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dllCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-10-2014 Ran by Martin Rinke at 2014-10-26 00:12:52 Run:4 Running from C:\Users\Martin Rinke\Downloads Loaded Profiles: Martin Rinke & Acronis Agent User (Available profiles: Martin Rinke & Kerstin & Acronis Agent User) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab SearchScopes: HKCU - URL hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms} SearchScopes: HKCU - SuggestionsURL_JSON hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=99&gid=1&dbCode=1&command={searchTerms} SearchScopes: HKCU - TopResultURLFallback hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms} Task: {38F8E9B8-CFCA-4B33-BD53-5F3334EBD275} - \{5B2F6C6D-7973-4195-A550-81033A447A93} No Task File <==== ATTENTION Task: {192D3862-44C1-43F8-8FB1-4AB2351D3C4E} - System32\Tasks\Browser Updater\Browser Updater => Rundll32.exe "C:\Program Files (x86)\HomeTab\TBUpdater.dll",TBCheckForUpdate C:\Program Files (x86)\HomeTab ***************** HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON => value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\TopResultURLFallback => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{38F8E9B8-CFCA-4B33-BD53-5F3334EBD275}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{38F8E9B8-CFCA-4B33-BD53-5F3334EBD275}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5B2F6C6D-7973-4195-A550-81033A447A93}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{192D3862-44C1-43F8-8FB1-4AB2351D3C4E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{192D3862-44C1-43F8-8FB1-4AB2351D3C4E}" => Key deleted successfully. C:\Windows\System32\Tasks\Browser Updater\Browser Updater => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Updater\Browser Updater" => Key deleted successfully. "C:\Program Files (x86)\HomeTab" => File/Directory not found. ==== End of Fixlog ==== |
25.10.2014, 23:15 | #27 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll Fehlermeledung beim Start weg?
__________________ Logfiles bitte immer in CODE-Tags posten |
25.10.2014, 23:32 | #28 |
| Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll Ich starte mal neu Meldung ist weg! Halleluja!!!! Macht es Strass, mir noch drei Fragen zu beantworten? 1. War das irgendwas Gefährliches? 2. Was wurde auf meinem Rechner gemacht/geändert? 3. Das wichtigste: Kann ich mich irgenwie erkenntlich zeigen? War schließlich eine langwierige Sache, insbesondere für Dich! Viele Grüße |
26.10.2014, 00:10 | #29 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Meldung RunDLL Program Files (x86)\HomeTab\TBUpdater.dll Du hattest wie fast jeder hier auch Werbung (Adware/Junkware/PUPs) auf deinem Rechner. Was PUPs sind erklärt Emsisoft hier recht gut => A Typical Day at Emsisoft?s Headquarters: The PUP Encounter | Emsisoft Blog Danke, dass du uns unterstützen möchtest, nähere Infos findest du dazu hier => Spende - Trojaner-Board - Spendenkonto - Trojaner-Board Dann wären wir durch! Falls du noch Lob oder Kritik loswerden möchtest => Lob, Kritik und Wünsche - Trojaner-Board Die Programme, die hier zum Einsatz kamen, können alle deinstalliert werden. Es empfiehlt sich Malwarebytes Anti-Malware zu behalten und damit wöchentlich nach Malware zu scannen. Helfen kann dir dabei delfix: Die Reihenfolge ist hier entscheidend.
Bitte abschließend noch die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden. Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern. Microsoftupdate Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren. Windows Vista/7: Start, Systemsteuerung, Windows-Update PDF-Reader aktualisieren Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast) Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader. Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers: Prüfen => Adobe - Flash Player Downloadlinks findest du hier => Browsers and Plugins - FilePony.de Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind. Java-Update Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________ Logfiles bitte immer in CODE-Tags posten |