|
Log-Analyse und Auswertung: monitor.exe löschenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
02.10.2014, 14:42 | #1 |
| monitor.exe löschen Hallo, mein Antivirus-Programm versucht seit 2 Tagen monitor.exe von meinem PC zu löschen und bekommt es nicht hin. Ich denke auch durchaus, dass auf dem Computer noch mehr Malware und Viren lauern. Ich wäre deswegen auf Hilfe angewiesen. Deswegen habe ich hier nachgesehen, was es für Beiträge gibt. Ich habe mir nun nach Anweisung eines Forenbeitrags HijackThis heruntergeldaen auf test.com umbenannt und einen logfile aufstellen lassen (oder wie man das in Fachkreisen auch nennen mag...) Ich habe es etwas editiert, wie vorgegeben und setze es hier darunter, in der Hoffnung, dass mir jemand die nächsten Schritte nennt, die zu erledigen sind. Hier der Logfile: Logfile of Trend Micro HijackThis v2.0.5 Scan saved at 15:15:47, on 02.10.2014 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16575) FIREFOX: 3.6.28 (de) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\WindowsMobile\wmdSync.exe C:\Program Files\Buyond_GmbH\GloboFleet_CC_Plus\GloboFleet_CC_Plus.exe C:\Program Files\Buyond_GmbH\GloboFleet_CC\GloboFleet_CC.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\PDF24\pdf24.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe C:\Program Files\MyDrive Connect\MyDriveConnect.exe C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe C:\Program Files\Buhl finance\tax Steuersoftware 2012\taxaktuell.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\Deutsche Telekom AG\Browser 7\Browser7.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe C:\Program Files\Deutsche Telekom AG\Browser 7\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe C:\Program Files\Internet Explorer\IELowutil.exe C:\Users\XXX\Desktop\test.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://www.istartsurf.com/?type=hp&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://www.istartsurf.com/web/?type=ds&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895&q={searchTerms} R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://www.istartsurf.com/web/?type=ds&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895&q={searchTerms} R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://www.istartsurf.com/?type=hp&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://www.aldi.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll R3 - URLSearchHook: (no name) - - (no file) R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll O1 - Hosts: ::1 localhost O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll O2 - BHO: CBAbzockschutz.InitToolbarBHO - {2e250b90-0e7a-42a3-9d65-e39f9f227fa4} - mscoree.dll (file missing) O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: DVDVideoSoftTB - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll O3 - Toolbar: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll O3 - Toolbar: COMPUTERBILD-Abzockschutz - {353e2a48-6254-4bd3-88f4-3b51a0ca7870} - mscoree.dll (file missing) O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe O4 - HKLM\..\Run: [GloboFleet] "C:\Program Files\Buyond_GmbH\GloboFleet_CC_Plus\GloboFleet_CC_Plus.exe" systemBoot O4 - HKLM\..\Run: [GloboFleet CC] "C:\Program Files\Buyond_GmbH\GloboFleet_CC\GloboFleet_CC.exe" systemBoot O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe O4 - HKLM\..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [MyDriveConnect.exe] "C:\Program Files\MyDrive Connect\MyDriveConnect.exe" O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user') O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe O4 - Global Startup: t@x aktuell.lnk = C:\Program Files\Buhl finance\tax Steuersoftware 2012\taxaktuell.exe O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Stefan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-25/4 (file missing) O9 - Extra 'Tools' menuitem: eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-25/4 (file missing) O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: In Windows Live Writer in &Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: HP Intelligente Auswahl - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O9 - Extra button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - h**p://rover.ebay.com/rover/1/707-37276-17534-15/4 (file missing) (HKCU) O9 - Extra 'Tools' menuitem: eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - h**p://rover.ebay.com/rover/1/707-37276-17534-15/4 (file missing) (HKCU) O10 - Unknown file in Winsock LSP: c:\windows\system32\myosprotect.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\myosprotect.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\myosprotect.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\myosprotect.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\myosprotect.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - h**p://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - h**p://lads.myspace.com/upload/MySpaceUploader2.cab O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Avira Email Schutz (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe O23 - Service: Avira Planer (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira Echtzeit-Scanner (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Avira Browser-Schutz (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Browser 7 Maintenance Service (Browser7Maintenance) - Deutsche Telekom AG - C:\Program Files\Browser 7 Maintenance Service\maintenanceservice.exe O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe O23 - Service: MyOSProtect - MyOSCompany - C:\Program Files\PCTRunner\MyOSProtect.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe O23 - Service: Toolbar Service (TBSrv) - ClientConnect Ltd. - C:\Program Files\Tbccint\ToolbarService\ToolbarService.exe -- End of file - 15171 bytes Ich würde mich über eine schnelle Rückmeldung freuen! Viele Grüße Herr_Frosch |
02.10.2014, 14:54 | #2 |
/// the machine /// TB-Ausbilder | monitor.exe löschen hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
02.10.2014, 15:45 | #3 |
| monitor.exe löschen Hier der FRST.txt:
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-10-2014 01 Ran by XXX (administrator) on XXX-PC on 02-10-2014 16:09:41 Running from C:\Users\XXX\Desktop Loaded Profile: XXX (Available profiles: XXX) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: h**p://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (browser) C:\Program Files\Browser+ Apps+\6b793742-2e09-427a-a17a-e7ad38f0e8c2.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Buyond GmbH) C:\Program Files\Buyond_GmbH\GloboFleet_CC_Plus\GloboFleet_CC_Plus.exe (Buyond GmbH) C:\Program Files\Buyond_GmbH\GloboFleet_CC\GloboFleet_CC.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (TomTom) C:\Program Files\MyDrive Connect\MyDriveConnect.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe () C:\Program Files\Buhl finance\tax Steuersoftware 2012\taxaktuell.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Program Files\Cyberlink\Shared files\RichVideo.exe (ClientConnect Ltd.) C:\Program Files\Tbccint\ToolbarService\ToolbarService.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Deutsche Telekom AG) C:\Program Files\Deutsche Telekom AG\Browser 7\Browser7.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Deutsche Telekom AG) C:\Program Files\Deutsche Telekom AG\Browser 7\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Trend Micro Inc.) C:\Users\XXX\Desktop\test.com (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-08-29] (Advanced Micro Devices, Inc.) HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [GloboFleet] => C:\Program Files\Buyond_GmbH\GloboFleet_CC_Plus\GloboFleet_CC_Plus.exe [236288 2011-05-16] (Buyond GmbH) HKLM\...\Run: [GloboFleet CC] => C:\Program Files\Buyond_GmbH\GloboFleet_CC\GloboFleet_CC.exe [235760 2011-05-16] (Buyond GmbH) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [421736 2011-11-13] (Apple Inc.) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-01] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6695456 2008-12-02] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2008-12-02] (Realtek Semiconductor Corp.) HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) Winlogon\Notify\ScCertProp: wlnotify.dll [X] HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-06-10] (Google Inc.) HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1828136 2008-02-28] (Nero AG) HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\Run: [MyDriveConnect.exe] => C:\Program Files\MyDrive Connect\MyDriveConnect.exe [1792376 2014-08-22] (TomTom) HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\MountPoints2: {947d3ccb-55de-11de-8d68-806e6f6e6963} - I:\Autorun.exe HKU\S-1-5-18\...\Run: [Picasa Media Detector] => C:\Program Files\Picasa2\PicasaMediaDetector.exe [443968 2008-08-21] (Google Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\t@x aktuell.lnk ShortcutTarget: t@x aktuell.lnk -> C:\Program Files\Buhl finance\tax Steuersoftware 2012\taxaktuell.exe () Startup: C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe () BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://www.istartsurf.com/web/?type=ds&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://www.istartsurf.com/?type=hp&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://www.istartsurf.com/?type=hp&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895 HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = h**p://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://www.istartsurf.com/web/?type=ds&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} URLSearchHook: HKLM - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File URLSearchHook: HKLM - Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) URLSearchHook: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll (ClientConnect Ltd.) URLSearchHook: HKCU - Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll (ClientConnect Ltd.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe h**p://www.istartsurf.com/?type=sc&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895 SearchScopes: HKLM - DefaultScope {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = h**p://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = h**p://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKLM - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = h**p://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 SearchScopes: HKCU - DefaultScope {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = h**p://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = h**p://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = h**p://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKCU - {BBA6EFAC-51E4-478F-8B44-25C0E57290B4} URL = h**p://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKCU - {CF739809-1C6C-47C0-85B9-569DBB141420} URL = h**p://www.search.ask.com/web?tpid=ORJ-ST-SPE&o=APN11461&pf=V7&p2=^BE7^OSJ000^YY^DE&gct=&itbv=12.15.5.31&apn_uid=CFF0D2A0-5676-4118-BE5A-E875B8170499&apn_ptnrs=BE7&apn_dtid=^OSJ000^YY^DE&apn_dbr=Browser7.exe_0_29.0.1.5274&doi=2014-08-14&trgb=IE&q={searchTerms}&psv=&pt=tb SearchScopes: HKCU - {D6C6BCFC-6F7B-4BC8-B92E-A58EFB2D0042} URL = h**p://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKCU - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = h**p://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Winamp Toolbar Loader -> {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} -> C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) BHO: CBAbzockschutz.InitToolbarBHO -> {2e250b90-0e7a-42a3-9d65-e39f9f227fa4} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: No Name -> {7E853D72-626A-48EC-A868-BA8D5E23E045} -> No File BHO: DVDVideoSoftTB Toolbar -> {872b5b88-9db5-4310-bdd0-ac189557e5f5} -> C:\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll (ClientConnect Ltd.) BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) Toolbar: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll (ClientConnect Ltd.) Toolbar: HKLM - COMPUTERBILD-Abzockschutz - {353e2a48-6254-4bd3-88f4-3b51a0ca7870} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Winamp Toolbar - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) Toolbar: HKCU - DVDVideoSoftTB Toolbar - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll (ClientConnect Ltd.) DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} h**p://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} h**p://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} h**p://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} h**p://lads.myspace.com/upload/MySpaceUploader2.cab DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} h**p://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} h**p://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 02 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 03 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 04 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 09 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 10 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 11 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 12 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 23 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 24 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa2,version=2.0.0 -> C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF user.js: detected! => C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.) FF SearchPlugin: C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\searchplugins\icqplugin-1.xml FF SearchPlugin: C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\searchplugins\icqplugin-2.xml FF SearchPlugin: C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\searchplugins\icqplugin.xml FF SearchPlugin: C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\istartsurf.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Browser+ Apps+ - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\56560a80-995b-47cd-852a-772f3a7ea92b@gmail.com [2014-09-17] FF Extension: No Name - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\cliqz@cliqz.com [2014-09-18] FF Extension: No Name - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\engine@conduit.com-trash [2013-08-16] FF Extension: Fast Start - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\faststartff@gmail.com [2014-09-17] FF Extension: Microsoft .NET Framework Assistant - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-05-20] FF Extension: ICQ Toolbar - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2013-09-10] FF Extension: DVDVideoSoftTB - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2013-12-22] FF Extension: Free YouTube Download (Free Studio) Menu - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2011-03-12] FF Extension: Adblock Plus - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2013-12-22] FF Extension: COMPUTERBILD-Abzockschutz - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{d49175b3-3fd8-43b8-b28e-da5d47f3c398} [2013-12-22] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010-05-20] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010-09-02] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2010-10-23] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2011-01-06] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-03-31] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2011-08-09] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-10-05] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-21] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} [2013-02-15] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-06-11] FF HKLM\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\extensions\faststartff@gmail.com FF HKLM\...\Firefox\Extensions: [termtutor@termtutor.com] - C:\Program Files\Mozilla Firefox\extensions\termtutor@termtutor.com FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] FF HKCU\...\Thunderbird\Extensions: [{380AE6CB-09B9-4373-B360-D01C2462A6E7}] - C:\program files\bullguard ltd\bullguard\backup\thunderbirdbkplugin FF HKCU\...\Thunderbird\Extensions: [{0E810812-F4BB-4309-942A-755587587A5E}] - C:\Program Files\BullGuard Ltd\BullGuard\antispam\tbspamfilter FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe h**p://www.istartsurf.com/?type=sc&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895 Chrome: ======= CHR HomePage: Default -> h**p://www.istartsurf.com/?type=hp&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895 CHR RestoreOnStartup: Default -> "h**p://www.istartsurf.com/?type=hp&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895" CHR NewTab: Default -> "chrome-extension://aaaajpkhjdkhhnkmgfjodbkfpbmibkkk/config/skin/new-tab-page.html" CHR DefaultSearchKeyword: Default -> istartsurf CHR DefaultSearchProvider: Default -> istartsurf CHR DefaultSearchURL: Default -> h**p://www.istartsurf.com/web/?type=ds&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895&q={searchTerms} CHR DefaultSuggestURL: Default -> h**p://ss.websearch.ask.com/query?qsrc={qsrc}&li=ff&sstype=prefix&q={searchTerms} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll No File CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.290.11) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Picasa) - C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.) CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR CustomProfile: C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Ask Toolbar) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaajpkhjdkhhnkmgfjodbkfpbmibkkk [2013-08-23] CHR Extension: (YouTube) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-19] CHR Extension: (Google Search) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-19] CHR Extension: (Google Wallet) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29] CHR Extension: (Browser+ Apps+) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\okhbpnfiofnpilolnjeebnidmkopeeda [2014-09-17] CHR Extension: (Gmail) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-19] CHR HKLM\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-09-17] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [805112 2014-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [994552 2014-10-01] (Avira Operations GmbH & Co. KG) S3 Browser7Maintenance; C:\Program Files\Browser 7 Maintenance Service\maintenanceservice.exe [118584 2014-09-13] (Deutsche Telekom AG) S2 globalUpdate; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-09-17] (globalUpdate) [File not signed] S3 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-09-17] (globalUpdate) [File not signed] R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2008-10-16] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [135168 2008-03-25] (Hewlett-Packard Co.) [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.) S3 MyOSProtect; C:\Program Files\PCTRunner\MyOSProtect.exe [1317096 2014-09-01] (MyOSCompany) [File not signed] R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed] R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed] R2 RichVideo; C:\Program Files\Cyberlink\Shared files\RichVideo.exe [241734 2008-06-28] () [File not signed] R2 TBSrv; C:\Program Files\Tbccint\ToolbarService\ToolbarService.exe [350496 2014-03-26] (ClientConnect Ltd.) S3 usnjsvc; C:\Program Files\Windows Live\Messenger\usnsvc.exe [98328 2007-10-18] (Microsoft Corporation) S3 WLSetupSvc; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [266240 2007-10-25] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 ahcix86s; C:\Windows\System32\DRIVERS\ahcix86s.sys [183312 2008-10-03] (Advanced Micro Devices, Inc) R0 amdide; C:\Windows\System32\DRIVERS\amdide.sys [10632 2007-10-12] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-29] (Avira Operations GmbH & Co. KG) S3 cxbu0wdm; C:\Windows\System32\DRIVERS\cxbu0wdm.sys [115712 2010-01-25] (HID Global Corporation) S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [554496 2007-09-21] (Ralink Technology Corp.) R1 pcwatch; C:\Windows\system32\Drivers\pcwatch.sys [19840 2014-09-01] () [File not signed] <==== ATTENTION R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [154272 2008-11-11] (Realtek Semiconductor Corp.) S3 s117bus; C:\Windows\System32\DRIVERS\s117bus.sys [82984 2007-06-25] (MCCI Corporation) S3 s117mdfl; C:\Windows\System32\DRIVERS\s117mdfl.sys [14888 2007-06-25] (MCCI Corporation) S3 s117mdm; C:\Windows\System32\DRIVERS\s117mdm.sys [108456 2007-06-25] (MCCI Corporation) S3 s117mgmt; C:\Windows\System32\DRIVERS\s117mgmt.sys [100264 2007-06-25] (MCCI Corporation) S3 s117nd5; C:\Windows\System32\DRIVERS\s117nd5.sys [22952 2007-06-25] (MCCI Corporation) S3 s117obex; C:\Windows\System32\DRIVERS\s117obex.sys [98344 2007-06-25] (MCCI Corporation) S3 s117unic; C:\Windows\System32\DRIVERS\s117unic.sys [98856 2007-06-25] (MCCI Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 cleanhlp; \??\C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 Profos; \??\C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\profos.sys [X] S3 Trufos; \??\C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\trufos.sys [X] S1 ttnfd; system32\drivers\ttnfd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-02 16:09 - 2014-10-02 16:10 - 00035749 _____ () C:\Users\XXX\Desktop\FRST.txt 2014-10-02 16:09 - 2014-10-02 16:09 - 00000000 ____D () C:\FRST 2014-10-02 16:08 - 2014-10-02 16:08 - 01100288 _____ (Farbar) C:\Users\XXX\Desktop\FRST.exe 2014-10-02 15:15 - 2014-10-02 15:15 - 00015173 _____ () C:\Users\Stefan\Desktop\hijackthis.log 2014-10-02 15:11 - 2014-10-02 15:12 - 00388608 _____ (Trend Micro Inc.) C:\Users\XXX\Desktop\test.com 2014-09-28 23:43 - 2014-09-25 13:57 - 06816184 _____ (TomTom International B.V.) C:\Users\XXX\Downloads\InstallMyDriveConnect_3_3_0_1756.exe 2014-09-25 07:00 - 2014-09-09 08:24 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-09-23 15:05 - 2014-09-23 15:06 - 00000000 ____D () C:\Users\XXX\Desktop\Zeugnisse_Scan Vati 2014-09-22 19:47 - 2014-09-25 13:50 - 00006914 _____ () C:\Windows\wininit.ini 2014-09-22 17:43 - 2014-09-25 13:50 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-09-22 17:42 - 2014-09-25 13:53 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2 2014-09-22 17:40 - 2014-09-22 17:41 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\XXX\Documents\spybot_27341.exe 2014-09-22 16:48 - 2014-09-25 13:48 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\Systweak 2014-09-22 16:46 - 2014-09-22 16:46 - 03490448 _____ (tuneuppro.com ) C:\Users\XXX\Documents\setup.exe 2014-09-22 16:43 - 2014-09-22 16:43 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\Abelssoft 2014-09-22 16:43 - 2014-09-22 16:43 - 00000000 ____D () C:\Users\XXX\AppData\Local\Abelssoft 2014-09-22 16:43 - 2014-09-22 16:43 - 00000000 ____D () C:\ProgramData\XDMessagingv4 2014-09-22 16:42 - 2014-09-25 13:48 - 00000000 ____D () C:\Program Files\CHIP Updater 2014-09-22 16:42 - 2014-09-22 16:42 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\DesktopIconGoodgame 2014-09-22 16:41 - 2014-09-22 16:42 - 01101648 _____ () C:\Users\XXX\Documents\Emsisoft Anti Malware - CHIP-Installer.exe 2014-09-22 09:24 - 2014-09-22 09:24 - 00000000 ____D () C:\Program Files\Tbccint 2014-09-18 21:53 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\system32\dhRichClient3.dll 2014-09-18 21:53 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\system32\sqlite36_engine.dll 2014-09-18 21:51 - 2014-09-18 21:51 - 01101648 _____ () C:\Users\XXX\Documents\adblockplusie-1.2 - CHIP-Installer.exe 2014-09-18 21:18 - 2014-09-18 21:18 - 00000000 ____D () C:\Users\XXX\Downloads\fab14 2014-09-18 21:17 - 2014-09-18 21:17 - 00452038 _____ () C:\Users\XXX\Downloads\fab14.zip 2014-09-18 21:15 - 2014-09-18 21:16 - 01101648 _____ () C:\Users\XXX\Downloads\Firewall App Blocker FAB - CHIP-Installer.exe 2014-09-17 22:02 - 2014-09-17 22:02 - 00000000 ____D () C:\ProgramData\2308189059 2014-09-17 20:42 - 2014-09-01 20:29 - 00019840 _____ () C:\Windows\system32\Drivers\pcwatch.sys 2014-09-17 20:41 - 2014-10-02 15:04 - 00002422 _____ () C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-5_user.job 2014-09-17 20:41 - 2014-10-02 15:04 - 00002422 _____ () C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-5.job 2014-09-17 20:41 - 2014-09-01 20:28 - 00304776 _____ (MyOSCompany) C:\Windows\system32\MyOSProtect.dll 2014-09-17 20:40 - 2014-10-02 15:01 - 00003790 _____ () C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-4.job 2014-09-17 20:40 - 2014-10-02 15:01 - 00002748 _____ () C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-1.job 2014-09-17 20:40 - 2014-10-02 15:01 - 00001378 _____ () C:\Windows\Tasks\6b793742-2e09-427a-a17a-e7ad38f0e8c2.job 2014-09-17 20:40 - 2014-09-17 20:40 - 00000000 ____D () C:\Users\XXX\AppData\Local\com 2014-09-17 20:39 - 2014-10-02 15:38 - 00003446 _____ () C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-6.job 2014-09-17 20:39 - 2014-10-02 15:01 - 00004472 _____ () C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-11.job 2014-09-17 20:39 - 2014-10-02 15:01 - 00003446 _____ () C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-7.job 2014-09-17 20:38 - 2014-10-02 15:01 - 00000900 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job 2014-09-17 20:38 - 2014-10-02 14:43 - 00000904 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job 2014-09-17 20:38 - 2014-09-17 22:17 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect 2014-09-17 20:38 - 2014-09-17 20:38 - 00000000 ____D () C:\Users\XXX\AppData\Local\globalUpdate 2014-09-17 20:38 - 2014-09-17 20:38 - 00000000 ____D () C:\Program Files\globalUpdate 2014-09-17 20:37 - 2014-10-02 15:01 - 00003790 _____ () C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-3.job 2014-09-17 20:37 - 2014-09-17 20:41 - 00000000 ____D () C:\Program Files\Browser+ Apps+ 2014-09-17 20:36 - 2014-10-02 15:01 - 00000000 ____D () C:\Program Files\PCTRunner 2014-09-17 20:31 - 2014-09-17 20:31 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\OpenCandy 2014-09-17 20:28 - 2014-09-17 20:29 - 30419936 _____ (DVDVideoSoft Ltd. ) C:\Users\XXX\Downloads\FreeYouTubeToMP3Converter3.12.44.908.exe 2014-09-14 13:41 - 2014-09-14 13:41 - 00000000 ____D () C:\ProgramData\Telekom-Browser 7 2014-09-11 15:08 - 2014-08-15 16:51 - 12363264 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-09-11 15:08 - 2014-08-15 16:42 - 09739776 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-09-11 15:08 - 2014-08-15 16:42 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-09-11 15:08 - 2014-08-15 16:37 - 01137664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-09-11 15:08 - 2014-08-15 16:37 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-09-11 15:08 - 2014-08-15 16:36 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-09-11 15:08 - 2014-08-15 16:35 - 01802240 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-09-11 15:08 - 2014-08-15 16:35 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-09-11 15:08 - 2014-08-15 16:34 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-09-11 15:08 - 2014-08-15 16:34 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-09-11 15:08 - 2014-08-15 16:34 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-09-11 15:08 - 2014-08-15 16:34 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-09-11 15:08 - 2014-08-15 16:34 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-09-10 13:54 - 2014-09-26 14:25 - 00000000 ____D () C:\Users\XXX\Desktop\Sims 2014-09-10 13:54 - 2014-09-22 18:50 - 00000000 ____D () C:\Users\XXX\Desktop\Praktikum XXX 2014-09-05 15:53 - 2014-09-05 15:53 - 00000000 ____D () C:\Users\Public\Documents\EA Games 2014-09-05 15:44 - 2014-09-26 14:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES 2014-09-05 15:42 - 2014-09-05 15:42 - 00000000 ____D () C:\Users\XXX\Documents\EA Games 2014-09-05 14:15 - 2014-09-05 14:15 - 00000000 ____D () C:\Users\XXX\AppData\Local\Microsoft Corporation 2014-09-05 14:07 - 2014-09-05 14:12 - 373578968 _____ (Microsoft Corporation) C:\Users\XXX\Downloads\office2007sp3-kb2526086-fullfile-de-de.exe 2014-09-05 14:07 - 2014-09-05 14:12 - 08676128 _____ (Microsoft Corporation) C:\Users\XXX\Downloads\Windows7UpgradeAdvisorSetup.exe 2014-09-05 14:06 - 2014-09-05 14:06 - 09848595 _____ () C:\Users\XXX\Downloads\Windows6.0-KB971512-x64.msu 2014-09-05 14:05 - 2014-09-05 14:05 - 04814058 _____ () C:\Users\XXX\Downloads\Windows6.0-KB971512-x86(1).msu 2014-09-05 14:04 - 2014-09-05 14:04 - 04814058 _____ () C:\Users\XXX\Downloads\Windows6.0-KB971512-x86.msu 2014-09-05 14:01 - 2014-09-05 14:01 - 00315624 _____ (Microsoft Corporation) C:\Users\XXX\Downloads\dxwebsetup.exe 2014-09-05 14:01 - 2014-09-05 14:01 - 00000000 ____D () C:\Windows\system32\directx 2014-09-02 21:55 - 2014-09-02 21:55 - 00034244 _____ () C:\monitorsvc.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-02 16:10 - 2008-12-10 17:30 - 00000438 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job 2014-10-02 16:07 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-02 16:07 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-02 15:51 - 2010-02-06 15:33 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-02 15:48 - 2012-08-22 10:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-02 15:09 - 2009-06-10 18:54 - 01543433 _____ () C:\Windows\WindowsUpdate.log 2014-10-02 15:01 - 2010-02-06 15:33 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-02 15:01 - 2008-01-21 04:47 - 00167262 _____ () C:\Windows\PFRO.log 2014-10-02 15:01 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-02 14:57 - 2006-11-02 15:01 - 00032628 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-10-01 15:05 - 2008-12-18 13:16 - 00057323 _____ () C:\Windows\setupact.log 2014-10-01 14:09 - 2012-12-07 09:38 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-10-01 14:09 - 2012-12-07 09:38 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-09-28 23:44 - 2013-12-06 21:20 - 00000000 ____D () C:\Program Files\MyDrive Connect 2014-09-28 20:53 - 2006-11-02 12:33 - 01643318 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-26 14:20 - 2011-08-07 16:35 - 00000000 ____D () C:\Program Files\EA GAMES 2014-09-25 14:11 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\rescache 2014-09-25 07:05 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-09-24 14:48 - 2012-08-22 10:24 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-09-24 14:48 - 2012-08-22 10:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-09-23 13:27 - 2006-11-02 14:47 - 00375400 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-09-22 16:49 - 2009-06-10 19:04 - 00103912 _____ () C:\Users\XXX\AppData\Local\GDIPFONTCACHEV1.DAT 2014-09-17 22:19 - 2009-07-14 21:51 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-09-17 22:11 - 2009-06-10 19:03 - 00000953 _____ () C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-09-17 22:04 - 2011-07-27 16:26 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\DVDVideoSoft 2014-09-15 09:27 - 2013-08-31 19:11 - 00000000 ____D () C:\Users\XXX\Desktop\Ordner XXX 2014-09-15 09:06 - 2009-10-05 15:04 - 00231568 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-09-14 17:01 - 2013-12-23 13:00 - 00000000 ____D () C:\Program Files\Browser 7 Maintenance Service 2014-09-14 13:41 - 2013-12-23 13:00 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\Deutsche Telekom AG 2014-09-14 13:41 - 2013-12-23 13:00 - 00000000 ____D () C:\Program Files\Deutsche Telekom AG 2014-09-12 11:59 - 2011-06-19 09:59 - 00006836 _____ () C:\Users\XXX\AppData\Local\d3d9caps.dat 2014-09-11 18:19 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-09-11 15:07 - 2008-11-25 10:38 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-09-11 15:06 - 2013-08-16 16:30 - 00000000 ____D () C:\Windows\system32\MRT 2014-09-11 14:54 - 2006-11-02 12:24 - 98758480 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-09-05 14:32 - 2009-06-11 15:24 - 00000000 ____D () C:\Program Files\Electronic Arts 2014-09-05 14:32 - 2008-12-10 16:19 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-09-05 14:03 - 2008-12-10 17:35 - 00061284 _____ () C:\Windows\DirectX.log Some content of TEMP: ==================== C:\Users\XXX\AppData\Local\Temp\AutoRun.exe C:\Users\XXX\AppData\Local\Temp\AutoRunGUI.dll C:\Users\XXX\AppData\Local\Temp\avgnt.exe C:\Users\XXX\AppData\Local\Temp\CleanSchedule.exe C:\Users\XXX\AppData\Local\Temp\drm_dyndata_7330014.dll C:\Users\XXX\AppData\Local\Temp\drm_dyndata_7350007.dll C:\Users\XXX\AppData\Local\Temp\First15.exe C:\Users\XXX\AppData\Local\Temp\OnlineBackup.exe C:\Users\XXX\AppData\Local\Temp\VP6Install.exe C:\Users\XXX\AppData\Local\Temp\VP6VFW.dll C:\Users\XXX\AppData\Local\Temp\_is5521.exe C:\Users\XXX\AppData\Local\Temp\_is65C4.exe C:\Users\XXX\AppData\Local\Temp\_is6F9D.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-02 15:10 ==================== End Of Log ============================ --- --- --- Hier die Addition.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-10-2014 01 Ran by XXX at 2014-10-02 16:10:33 Running from C:\Users\XXX\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 32 Bit HP CIO Components Installer (Version: 1.0.0 - Hewlett-Packard) Hidden 4500_Help (Version: 1.00.0000 - Hewlett-Packard) Hidden 50 FREE MP3s +1 Free Audiobook! (HKLM\...\eMusic Promotion) (Version: 1.0.0.1 - eMusic.com Inc) Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader X (10.1.11) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.) Antivirus Pro (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.306 - Avira) Apple Application Support (HKLM\...\{A83279FD-CA4B-4206-9535-90974DE76654}) (Version: 2.1.5 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{8153ED9A-C94A-426E-9880-5E6775C08B62}) (Version: 4.0.0.97 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ArcSoft ShowBiz (HKLM\...\{9D41D2EF-2D33-4CFD-8A3E-C7E6FCC3303B}) (Version: - ArcSoft) ATI Catalyst Install Manager (HKLM\...\{E73E0ECF-080F-8E71-C413-0961332D47A0}) (Version: 3.0.704.0 - ATI Technologies, Inc.) Avanquest update (HKLM\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.19 - Avanquest Software) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) BPD_HPSU (Version: 1.00.0000 - Hewlett-Packard) Hidden bpd_scan (Version: 3.00.0000 - Hewlett-Packard) Hidden BPDSoftware (Version: 50.0.165.000 - Hewlett-Packard) Hidden BPDSoftware_Ini (Version: 1.00.0000 - Hewlett-Packard) Hidden Brother MFL-Pro Suite (HKLM\...\{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}) (Version: 1.00 - Brother Industries, Ltd.) Browser 7 der Telekom 31.0.20 (x86 de) (HKLM\...\Browser 7 der Telekom 31.0.20 (x86 de)) (Version: 31.0.20 - Deutsche Telekom AG) Browser 7 Maintenance Service (HKLM\...\Browser7MaintenanceService) (Version: 29.0.40 - Deutsche Telekom AG) BufferChm (Version: 100.0.170.000 - Hewlett-Packard) Hidden Catalyst Control Center Core Implementation (Version: 2008.1201.1504.27008 - ATI) Hidden Catalyst Control Center Graphics Full Existing (Version: 2008.1201.1504.27008 - ATI) Hidden Catalyst Control Center Graphics Full New (Version: 2008.1201.1504.27008 - ATI) Hidden Catalyst Control Center Graphics Light (Version: 2008.1201.1504.27008 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (Version: 2008.1201.1504.27008 - ATI) Hidden Catalyst Control Center InstallProxy (Version: 2008.1201.1504.27008 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization German (Version: 2008.1201.1504.27008 - ATI) Hidden CCC Help English (Version: 2008.1201.1503.27008 - ATI) Hidden CCC Help German (Version: 2008.1201.1503.27008 - ATI) Hidden ccc-core-static (Version: 2008.1201.1504.27008 - Ihr Firmenname) Hidden ccc-utility (Version: 2008.1201.1504.27008 - ATI) Hidden Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) COMPUTERBILD-Abzockschutz (HKLM\...\{09D29DA8-F155-4AEA-A110-FA5F10895D88}) (Version: 1.0.36 - J3S) CorelDRAW Essential Edition 3 (HKLM\...\_{ADDBE07D-95B8-4789-9C76-187FFF9624B4}) (Version: - Corel Corporation) CorelDRAW Essential Edition 3 (Version: 3.0 - Corel Corporation) Hidden CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden CyberLink MediaShow (HKLM\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 4.1.2318 - CyberLink Corp.) CyberLink MediaShow (Version: 4.1.2318 - CyberLink Corp.) Hidden CyberLink PhotoNow (HKLM\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.5615 - CyberLink Corp.) CyberLink PhotoNow (Version: 1.1.5615 - CyberLink Corp.) Hidden CyberLink PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2209b - CyberLink Corp.) CyberLink PowerDirector (Version: 7.0.2209b - CyberLink Corp.) Hidden CyberLink PowerDVD 8 (HKLM\...\InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}) (Version: 8.0.2217 - CyberLink Corp.) CyberLink PowerDVD 8 (Version: 8.0.2217 - CyberLink Corp.) Hidden CyberLink PowerProducer (HKLM\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.1111 - CyberLink Corp.) CyberLink PowerProducer (Version: 5.1111 - CyberLink Corp.) Hidden DE (Version: 3.0 - Corel Corporation) Hidden Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{650DE870-ECA3-4E63-8D77-778512BE5D4C}) (Version: - Microsoft) Destination Component (Version: 100.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (Version: 110.0.180.000 - Hewlett-Packard) Hidden DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden DHTML Editing Component (HKLM\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation) Die Sims 2 (HKLM\...\{6E7DD182-9FC6-4651-0095-2E666CC6AF35}) (Version: - ) Die Sims 2: Nightlife (HKLM\...\{F7529650-B9DB-481B-0089-A2AC3C2821C1}) (Version: - ) Die Sims 2: Open For Business (HKLM\...\{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}) (Version: - ) Die Sims 2: Wilde Campus-Jahre (HKLM\...\{01521746-02A6-4A72-00BD-A285DF6B80C6}) (Version: - ) Die Sims™ 2 Freizeit-Spaß (HKLM\...\{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}) (Version: - Electronic Arts) Die Sims™ 2 Gute Reise (HKLM\...\{F248ADFA-64E0-4b03-8A83-059078BED6A0}) (Version: - Electronic Arts) Die Sims™ 2 Haustiere (HKLM\...\{4817189D-1785-4627-A33C-39FD90919300}) (Version: - ) Die Sims™ 2 Vier Jahreszeiten (HKLM\...\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}) (Version: - ) DocMgr (Version: 100.0.201.000 - Hewlett-Packard) Hidden DocProc (Version: 11.0.0.0 - Hewlett-Packard) Hidden DocProcQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden DVDVideoSoftTB Toolbar (HKLM\...\DVDVideoSoftTB Toolbar) (Version: 6.9.0.16 - DVDVideoSoftTB) EA Download Manager (HKLM\...\EADM) (Version: 5.1.0.4 - Electronic Arts, Inc.) eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden Fax (Version: 120.0.194.000 - Hewlett-Packard) Hidden Free Audio CD Burner version 1.4.7 (HKLM\...\Free Audio CD Burner_is1) (Version: - DVDVideoSoft Limited.) GloboFleet CC (HKLM\...\{624550CB-52A5-4FE2-AAD0-6CAF49619A9D}) (Version: 3.4.3 - Buyond GmbH) GloboFleet CC Plus (HKLM\...\{95FEFF62-C9C4-4726-BDF2-85AC9C192391}) (Version: 2.6.2 - Buyond GmbH) Google Chrome (HKLM\...\Google Chrome) (Version: 37.0.2062.120 - Google Inc.) Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden GPBaseService (Version: 100.0.187.000 - Hewlett-Packard) Hidden HP Customer Participation Program 10.0 (HKLM\...\HPExtendedCapabilities) (Version: 10.0 - HP) HP Document Manager 1.0 (HKLM\...\HP Document Manager) (Version: 1.0 - HP) HP Imaging Device Functions 10.0 (HKLM\...\HP Imaging Device Functions) (Version: 10.0 - HP) HP Officejet J4500 Series (HKLM\...\{CD0773D5-C18E-495c-B39B-21A96415EDD5}) (Version: 1.0 - HP) HP Photosmart Essential 2.5 (HKLM\...\HP Photosmart Essential) (Version: 2.5 - HP) HP Photosmart Essential 2.5 (Version: 1.02.0000 - Hewlett-Packard) Hidden HP Smart Web Printing (HKLM\...\HP Smart Web Printing) (Version: 3.5 - HP) HP Solution Center 10.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 10.0 - HP) HP Update (HKLM\...\{818ABC3C-635C-4651-8183-D0E9640B7DD1}) (Version: 5.002.000.013 - Hewlett-Packard) HPProductAssistant (Version: 100.0.170.000 - Hewlett-Packard) Hidden HPSSupply (Version: 100.0.170.000 - Hewlett-Packard) Hidden iTunes (HKLM\...\{3127F76D-5335-4AC7-BD1E-2F5247A23C24}) (Version: 10.5.1.42 - Apple Inc.) J4500 (Version: 50.0.165.000 - Ihr Firmenname) Hidden Java 7 Update 67 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.670 - Oracle) Java Auto Updater (Version: 2.1.67.1 - Oracle, Inc.) Hidden Java(TM) 6 Update 39 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216035FF}) (Version: 6.0.390 - Oracle) MarketResearch (Version: 100.0.170.000 - Hewlett-Packard) Hidden McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 1.1 German Language Pack (HKLM\...\{E78BFA60-5393-4C38-82AB-E8019E464EB4}) (Version: 1.1.4322 - Microsoft) Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - ) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Age of Empires (HKLM\...\Age of Empires) (Version: - ) Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint Viewer 2007 (German) (HKLM\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [DEU] (HKLM\...\{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual J# .NET Redistributable Package 1.1 (HKLM\...\{1A655D51-1423-48A3-B748-8F5A0BE294C8}) (Version: 1.1.4322 - Microsoft) Microsoft Visual J# 2.0 Redistributable Package (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package) (Version: - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package (Version: 2.0.50727 - Microsoft Corporation) Hidden Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mozilla Firefox (3.6.28) (HKLM\...\Mozilla Firefox (3.6.28)) (Version: 3.6.28 (de) - Mozilla) MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyDriveConnect 3.3.0.1756 (HKLM\...\MyDriveConnect) (Version: 3.3.0.1756 - TomTom) Need for Speed (HKLM\...\Need for Speed High Stakes) (Version: - ) Nero 8 Essentials (HKLM\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031}) (Version: 8.3.124 - Nero AG) neroxml (Version: 1.0.0 - Nero AG) Hidden OCR Software by I.R.I.S. 10.0 (HKLM\...\HPOCR) (Version: 10.0 - HP) OpenOffice.org 3.2 (HKLM\...\{192A107E-C6B9-41B9-BDBF-38E3AA226054}) (Version: 3.2.9483 - OpenOffice.org) PaperPort Image Printer (HKLM\...\{332CC6BF-E6C7-48EE-BA3D-435E576AD67F}) (Version: 1.00.0000 - Nuance Communications, Inc.) PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Picasa 2 (HKLM\...\Picasa2) (Version: 2.0 - Google, Inc.) ProductContext (Version: 50.0.165.000 - Hewlett-Packard) Hidden PSSWCORE (Version: 2.02.0000 - Hewlett-Packard) Hidden QuickTime (HKLM\...\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.) Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5749 - Realtek Semiconductor Corp.) Scan (Version: 10.1.0.0 - Hewlett-Packard) Hidden ScanSoft PaperPort 11 (HKLM\...\{B6C89654-A6A2-477C-873B-724EC1C56407}) (Version: 11.1.0000 - Nuance Communications, Inc.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (Version: - Microsoft) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 10.0 - HP) Skins (Version: 2008.1201.1504.27008 - ATI) Hidden SmartWebPrintingOC (Version: 100.0.189.000 - Hewlett-Packard) Hidden SolutionCenter (Version: 100.0.175.000 - Hewlett-Packard) Hidden Sony Ericsson PC Suite 3.208.00 (HKLM\...\{2FFE93F0-BB72-4E52-8761-354D1AAA9387}) (Version: 3.208.00 - Sony Ericsson) Spelling Dictionaries Support For Adobe Reader 9 (HKLM\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated) Status (Version: 110.0.180.000 - Hewlett-Packard) Hidden swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden t@x 2011 (HKLM\...\{B0414A3B-3AE3-47B8-8FC0-2129781FF425}) (Version: 18.00.6928 - Buhl Data Service GmbH) t@x 2012 (HKLM\...\{0E806605-5B82-4A4F-BC31-AA4FADA03C42}) (Version: 19.00.7303 - Buhl Data Service GmbH) Tacho+Personal (Version: 1.26.0 - SoftProject AG CH-9000 St.Gallen) Hidden TachoPlusFreeDriver (HKLM\...\TachoPlusFreeDriver) (Version: 1.26.0 - SoftProject) T-Online 6.0 (HKLM\...\{B1275E23-717A-4D52-997A-1AD1E24BC7F3}) (Version: - ) T-Online WLAN-Access Finder (HKLM\...\{295C31E5-3F91-498E-9623-DA24D2FA2B6A}) (Version: - ) Toolbox (Version: 100.0.170.000 - Hewlett-Packard) Hidden TrayApp (Version: 110.0.180.000 - Hewlett-Packard) Hidden Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Excel 2010 (KB2889836) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9179FC17-97A8-4D98-9E09-05720AF5D44E}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0D672F7-883E-4279-8E75-D97A5445AB46}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B9B89E01-5B6B-4F73-BC34-B2C0D8ACB4CD}) (Version: - Microsoft) Update Manager (Version: 4.60 - Corel Corporation) Hidden USB Video/Audio Device Driver (HKLM\...\{3717C4F2-7412-4793-9BB8-D73D2817B3D6}) (Version: 1.00.0000 - Ihr Firmenname) VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden VideoToolkit01 (Version: 100.0.128.000 - Hewlett-Packard) Hidden Visual Studio C++ 10.0 Runtime (HKLM\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.) Web Protect for Windows (HKLM\...\wp-dcollect-tgu) (Version: 10.0.0 - PC Publishing) <==== ATTENTION WebReg (Version: 100.0.170.000 - Hewlett-Packard) Hidden Winamp (HKLM\...\Winamp) (Version: 5.56 - Nullsoft, Inc) Winamp Toolbar (HKLM\...\Winamp Toolbar) (Version: - ) <==== ATTENTION Windows Live Anmelde-Assistent (HKLM\...\{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}) (Version: 5.000.818.6 - Microsoft Corporation) Windows Live Fotogalerie (HKLM\...\{A1D08B90-AE1A-4885-AC29-731496FD397E}) (Version: 12.0.1347.0718 - Microsoft Corporation) Windows Live installer (HKLM\...\{7A7B0BF3-2F00-4F03-8A9B-6ABCC07B90C6}) (Version: 12.0.1471.1025 - Microsoft Corporation) Windows Live Mail (HKLM\...\{82F2B38B-1426-443D-874C-AC25675E7BEB}) (Version: 12.0.1606.1023 - Microsoft Corporation) Windows Live Messenger (HKLM\...\{2B091530-69AA-442E-AB09-39ED06B58220}) (Version: 8.5.1302.1018 - Microsoft Corporation) Windows Live Writer (HKLM\...\{B8D42C3A-3CFF-4A8A-A7DA-4F44474D12C5}) (Version: 12.0.1370.0325 - Microsoft Corporation) Yahoo! Detect (HKLM\...\YTdetect) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-4257748576-2051970891-1811884360-1000_Classes\CLSID\{46C4F788-2570-4CEA-B7E7-4CC39A33192D}\InprocServer32 -> C:\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll (ClientConnect Ltd.) CustomCLSID: HKU\S-1-5-21-4257748576-2051970891-1811884360-1000_Classes\CLSID\{66E8DCC7-97D2-4A89-8E08-D0610FF0878C}\InprocServer32 -> C:\Users\XXX\AppData\Local\Conduit\Community Alerts\Alert.dll No File CustomCLSID: HKU\S-1-5-21-4257748576-2051970891-1811884360-1000_Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\InprocServer32 -> C:\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll (ClientConnect Ltd.) ==================== Restore Points ========================= 10-09-2014 19:01:29 Geplanter Prüfpunkt 11-09-2014 12:44:28 Windows Update 14-09-2014 17:08:14 Geplanter Prüfpunkt 16-09-2014 11:58:37 Windows Update 17-09-2014 20:14:05 Removed Shopping App by Ask 17-09-2014 20:15:19 Removed Ask Toolbar 18-09-2014 17:21:06 Geplanter Prüfpunkt 18-09-2014 19:53:20 Installed Adblock Plus for IE (32-bit) 20-09-2014 12:53:05 Geplanter Prüfpunkt 21-09-2014 13:00:59 Removed Adblock Plus für IE (32-Bit) 22-09-2014 07:38:56 Windows 7 Upgrade Advisor wird entfernt 22-09-2014 07:40:39 TuneUp Utilities wird entfernt 22-09-2014 07:41:57 TuneUp Utilities Language Pack (de-DE) wird entfernt 23-09-2014 11:45:27 Windows Update 23-09-2014 12:04:20 Tuneup Pro Di, Sep 23, 14 14:04 25-09-2014 04:56:54 Windows Update 25-09-2014 17:15:22 Geplanter Prüfpunkt 26-09-2014 14:19:58 Geplanter Prüfpunkt 27-09-2014 19:36:03 Geplanter Prüfpunkt 28-09-2014 17:59:18 Geplanter Prüfpunkt 29-09-2014 16:10:52 Geplanter Prüfpunkt 30-09-2014 07:26:20 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0E95454C-7E3D-4EBF-ACDB-1D936082D97D} - System32\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-6 => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-6.exe Task: {126A4CBD-602D-4424-B754-F18FBAA9E56F} - System32\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-5 => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-5.exe [2014-09-17] (browser) Task: {19BF2478-EB1D-4E6E-AEA6-7FDCA4A8EF63} - System32\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-11 => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-11.exe Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {25189201-B35A-4673-928C-4A35EC5D5F69} - System32\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-3 => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-3.exe Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {412E772F-5CFD-4625-BD3E-5AA368790780} - System32\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-1 => C:\Program Files\Browser+ Apps+\Browser+ Apps+-codedownloader.exe Task: {4295E4CA-159C-4DEB-9961-F02A1AA95918} - System32\Tasks\6b793742-2e09-427a-a17a-e7ad38f0e8c2 => C:\Program Files\Browser+ Apps+\6b793742-2e09-427a-a17a-e7ad38f0e8c2.exe [2014-09-17] (browser) Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {559893F7-7A56-46DE-93B6-5604099D8942} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files\CHIP Updater\CHIPUpdater.exe Task: {6766781B-DAFE-4962-82A1-E4CDA837577F} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files\TuneUp Utilities 2010\OneClick.exe Task: {70B42FC1-0526-40C9-946E-5EBA0D8F4934} - System32\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-5_user => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-5.exe [2014-09-17] (browser) Task: {7D595D52-E19C-4300-9997-8D18F43621D0} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2014-09-17] (globalUpdate) <==== ATTENTION Task: {8AC2C82D-2D06-4666-BBA4-D1A578A417FB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-06] (Google Inc.) Task: {9A76530C-8970-4AD9-964D-92B8B058BFD2} - System32\Tasks\LaunchApp => C:\Program Files\MyPC Backup\MyPC Backup.exe <==== ATTENTION Task: {A6976519-2AEA-4AB0-B136-8B21CA0D3DA2} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: {C2D62B5D-7F5B-4765-A835-3B49479B37C3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-06] (Google Inc.) Task: {C35DAD7A-09EB-4F9C-8E3E-C03ACD444E50} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {D14E86FC-3296-4D3A-A90C-3AD41E0545C8} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-24] (Adobe Systems Incorporated) Task: {E3E8F077-CFF6-4A33-B0A7-3F1B081F4D00} - System32\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-4 => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-4.exe Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {F8B5CD07-A670-4853-B0A4-D88EF41B5CD7} - System32\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-7 => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-7.exe Task: {FAABACB8-9300-456D-A738-E2AA0EE48BD0} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2014-09-17] (globalUpdate) <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-1.job => C:\Program Files\Browser+ Apps+\Browser+ Apps+-codedownloader.exe Task: C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-11.job => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-11.exe Task: C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-3.job => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-3.exe Task: C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-4.job => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-4.exe Task: C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-5.job => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-5.exe Task: C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-5_user.job => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-5.exe Task: C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-6.job => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-6.exe Task: C:\Windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-7.job => C:\Program Files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-7.exe Task: C:\Windows\Tasks\6b793742-2e09-427a-a17a-e7ad38f0e8c2.job => C:\Program Files\Browser+ Apps+\6b793742-2e09-427a-a17a-e7ad38f0e8c2.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job => C:\Windows\system32\msfeedssync.exe ==================== Loaded Modules (whitelisted) ============= 2008-12-01 22:46 - 2008-12-01 22:46 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll 2011-06-24 22:56 - 2011-06-24 22:56 - 00087328 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2011-06-24 22:56 - 2011-06-24 22:56 - 01241888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-08-22 10:38 - 2014-08-22 10:38 - 00026488 _____ () C:\Program Files\MyDrive Connect\DeviceDetection.dll 2014-08-22 10:38 - 2014-08-22 10:38 - 00087416 _____ () C:\Program Files\MyDrive Connect\TomTomSupporterBase.dll 2014-08-22 10:38 - 2014-08-22 10:38 - 00398712 _____ () C:\Program Files\MyDrive Connect\TomTomSupporterProxy.dll 2013-05-16 17:16 - 2013-01-24 11:10 - 00537680 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\taxaktuell.exe 2013-05-16 17:14 - 2013-01-24 11:10 - 07965776 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\wgui12.dll 2013-05-16 17:14 - 2013-01-24 11:10 - 00028672 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\rsdcom47.dll 2013-05-16 17:14 - 2011-11-04 13:47 - 02356736 ____N () C:\Program Files\Buhl finance\tax Steuersoftware 2012\QtCorers47.dll 2013-05-16 17:14 - 2011-11-04 13:47 - 08934400 ____N () C:\Program Files\Buhl finance\tax Steuersoftware 2012\QtGuirs47.dll 2013-05-16 17:14 - 2011-11-04 13:47 - 00990208 ____N () C:\Program Files\Buhl finance\tax Steuersoftware 2012\QtNetworkrs47.dll 2013-05-16 17:14 - 2011-11-04 13:47 - 00358400 ____N () C:\Program Files\Buhl finance\tax Steuersoftware 2012\QtXmlrs47.dll 2013-05-16 17:14 - 2012-01-25 11:01 - 00720896 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\QtSqlrs47.dll 2013-05-16 17:14 - 2011-11-04 13:47 - 01340416 ____N () C:\Program Files\Buhl finance\tax Steuersoftware 2012\QtScriptrs47.dll 2013-05-16 17:14 - 2011-11-04 13:47 - 02395648 ____N () C:\Program Files\Buhl finance\tax Steuersoftware 2012\Qt3Supportrs47.dll 2013-05-16 17:14 - 2011-11-04 13:47 - 11163648 ____N () C:\Program Files\Buhl finance\tax Steuersoftware 2012\QtWebKitrs47.dll 2013-05-16 17:14 - 2011-11-04 13:47 - 00271872 ____N () C:\Program Files\Buhl finance\tax Steuersoftware 2012\phononrs47.dll 2013-05-16 17:14 - 2011-11-04 13:47 - 00108544 ____N () C:\Program Files\Buhl finance\tax Steuersoftware 2012\QtTestrs47.dll 2013-05-16 17:14 - 2013-01-24 11:10 - 00275536 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\rscorewinapi47.dll 2013-05-16 17:14 - 2013-01-24 11:10 - 00320080 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\rsguiwinapi47.dll 2013-05-16 17:14 - 2013-01-24 11:11 - 02993744 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\wcore12.dll 2013-05-16 17:14 - 2013-01-24 11:10 - 00136272 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\rsodbc47.dll 2013-05-16 17:14 - 2012-11-26 19:46 - 00866816 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\QtCLuceners47.dll 2013-05-16 17:14 - 2013-01-24 11:10 - 02045008 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\wfvie12.dll 2013-05-16 17:14 - 2011-11-04 13:47 - 00281088 ____N () C:\Program Files\Buhl finance\tax Steuersoftware 2012\QtSvgrs47.dll 2013-05-16 17:14 - 2013-01-24 11:10 - 01552464 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\wsteu12.dll 2013-05-16 17:14 - 2013-01-24 11:10 - 01654864 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\wreli12.dll 2013-05-16 17:14 - 2013-01-24 11:10 - 04545616 _____ () C:\Program Files\Buhl finance\tax Steuersoftware 2012\wauff12.dll 2008-12-18 11:40 - 2008-06-28 09:00 - 00241734 _____ () C:\Program Files\Cyberlink\Shared files\RichVideo.exe 2009-10-20 21:02 - 2010-04-06 20:10 - 00970752 _____ () C:\Program Files\OpenOffice.org 3\program\libxml2.dll 2014-09-13 16:18 - 2014-09-13 16:18 - 03575096 _____ () C:\Program Files\Deutsche Telekom AG\Browser 7\mozjs.dll 2008-12-10 15:53 - 2008-12-10 15:53 - 00014848 _____ () C:\Windows\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll 2014-09-10 16:48 - 2014-09-10 16:48 - 16825520 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Users\XXX\Downloads\FW_Urlaub (1).eml:OECustomProperty AlternateDataStreams: C:\Users\XXX\Downloads\FW_Urlaub.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup MSCONFIG\startupreg: BrMfcWnd => C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN MSCONFIG\startupreg: ControlCenter3 => C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun MSCONFIG\startupreg: EA Core => "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent MSCONFIG\startupreg: Google Desktop Search => "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup MSCONFIG\startupreg: Google EULA Launcher => C:\Program Files\Google\Google EULA\GoogleEULALauncher.exe GE MSCONFIG\startupreg: HP Software Update => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: hpqSRMon => C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe MSCONFIG\startupreg: IndexSearch => "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" MSCONFIG\startupreg: PaperPort PTD => "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" MSCONFIG\startupreg: PPort11reminder => "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe MSCONFIG\startupreg: Skytel => C:\Program Files\Realtek\Audio\HDA\Skytel.exe MSCONFIG\startupreg: Sony Ericsson PC Suite => "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon MSCONFIG\startupreg: SSBkgdUpdate => "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot MSCONFIG\startupreg: swg => "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" MSCONFIG\startupreg: WinampAgent => "C:\Program Files\Winamp\winampa.exe" ========================= Accounts: ========================== Administrator (S-1-5-21-4257748576-2051970891-1811884360-500 - Administrator - Disabled) ASPNET (S-1-5-21-4257748576-2051970891-1811884360-1002 - Limited - Enabled) Gast (S-1-5-21-4257748576-2051970891-1811884360-501 - Limited - Disabled) XXX (S-1-5-21-4257748576-2051970891-1811884360-1000 - Administrator - Enabled) => C:\Users\XXX ==================== Faulty Device Manager Devices ============= Name: Microsoft-ISATAP-Adapter #5 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver ==================== Event log errors: ========================= Application errors: ================== Error: (10/02/2014 02:57:21 PM) (Source: EventSystem) (EventID: 4621) (User: ) Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (10/02/2014 02:56:28 PM) (Source: VSS) (EventID: 12289) (User: ) Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy53,0xc0000000,0x00000003,...)". hr = 0x80070005. Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:56:27 PM) (Source: VSS) (EventID: 12289) (User: ) Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy53,0xc0000000,0x00000003,...)". hr = 0x80070005. Error: (10/02/2014 02:55:35 PM) (Source: VSS) (EventID: 12289) (User: ) Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy53,0xc0000000,0x00000003,...)". hr = 0x80070005. Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:55:11 PM) (Source: VSS) (EventID: 12289) (User: ) Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy52,0xc0000000,0x00000003,...)". hr = 0x80070005. Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:54:54 PM) (Source: VSS) (EventID: 12289) (User: ) Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy51,0xc0000000,0x00000003,...)". hr = 0x80070005. Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:54:32 PM) (Source: VSS) (EventID: 12289) (User: ) Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy50,0xc0000000,0x00000003,...)". hr = 0x80070005. Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:53:51 PM) (Source: VSS) (EventID: 12289) (User: ) Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy49,0xc0000000,0x00000003,...)". hr = 0x80070005. Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:53:00 PM) (Source: VSS) (EventID: 12289) (User: ) Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy47,0xc0000000,0x00000003,...)". hr = 0x80070005. Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:52:59 PM) (Source: VSS) (EventID: 12289) (User: ) Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy47,0xc0000000,0x00000003,...)". hr = 0x80070005. System errors: ============= Error: (10/02/2014 03:03:48 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: ttnfd Error: (10/02/2014 03:03:48 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: HP CUE DeviceDiscovery Service Error: (10/02/2014 03:01:53 PM) (Source: SCardSvr) (EventID: 602) (User: ) Description: Das System kann den angegebenen Pfad nicht finden. Error: (10/02/2014 03:01:53 PM) (Source: SCardSvr) (EventID: 602) (User: ) Description: Das System kann den angegebenen Pfad nicht finden. Error: (10/02/2014 02:57:09 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (10/02/2014 02:39:33 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: 30000Eventlog Error: (10/02/2014 02:25:16 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: ttnfd Error: (10/02/2014 02:25:15 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: HP CUE DeviceDiscovery Service Error: (10/02/2014 02:24:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Protect Monitor%%1053 Error: (10/02/2014 02:24:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Protect Monitor Microsoft Office Sessions: ========================= Error: (10/02/2014 02:57:21 PM) (Source: EventSystem) (EventID: 4621) (User: ) Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (10/02/2014 02:56:28 PM) (Source: VSS) (EventID: 12289) (User: ) Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy53,0xc0000000,0x00000003,...)0x80070005 Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:56:27 PM) (Source: VSS) (EventID: 12289) (User: ) Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy53,0xc0000000,0x00000003,...)0x80070005 Error: (10/02/2014 02:55:35 PM) (Source: VSS) (EventID: 12289) (User: ) Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy53,0xc0000000,0x00000003,...)0x80070005 Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:55:11 PM) (Source: VSS) (EventID: 12289) (User: ) Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy52,0xc0000000,0x00000003,...)0x80070005 Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:54:54 PM) (Source: VSS) (EventID: 12289) (User: ) Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy51,0xc0000000,0x00000003,...)0x80070005 Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:54:32 PM) (Source: VSS) (EventID: 12289) (User: ) Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy50,0xc0000000,0x00000003,...)0x80070005 Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:53:51 PM) (Source: VSS) (EventID: 12289) (User: ) Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy49,0xc0000000,0x00000003,...)0x80070005 Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:53:00 PM) (Source: VSS) (EventID: 12289) (User: ) Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy47,0xc0000000,0x00000003,...)0x80070005 Vorgang: EndPrepareSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (10/02/2014 02:52:59 PM) (Source: VSS) (EventID: 12289) (User: ) Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy47,0xc0000000,0x00000003,...)0x80070005 ==================== Memory info =========================== Processor: AMD Athlon(tm) 7750 Dual-Core Processor Percentage of memory in use: 52% Total physical RAM: 3325.39 MB Available physical RAM: 1579.15 MB Total Pagefile: 6883.27 MB Available Pagefile: 4784.48 MB Total Virtual: 2047.88 MB Available Virtual: 1879.2 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:576.16 GB) (Free:408.68 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:20 GB) (Free:9.86 GB) FAT32 Drive i: (Sims2EP7) (CDROM) (Total:0.95 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596.2 GB) (Disk ID: 95D4DE53) Partition 1: (Active) - (Size=576.2 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
03.10.2014, 11:23 | #4 |
/// the machine /// TB-Ausbilder | monitor.exe löschen Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.10.2014, 12:42 | #5 |
| monitor.exe löschen Also habe jetzt versucht alle so zu machen, wie du es gesagt hast. Vielen Dank erstmal bis hierher! Mir ist aufgefallen, dass beim deinstallieren, sich ein neuer internetbrowser auf dem Desktop gesetzt hat namens "the Internet". Hier erstmal der Logfile vom Combofix: Code:
ATTFilter ComboFix 14-10-02.01 - XXX 03.10.2014 13:07:26.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3325.1971 [GMT 2:00] ausgeführt von:: c:\users\XXX\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\XXX\4.0 c:\windows\IsUn0407.exe . . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_globalUpdate . . ((((((((((((((((((((((( Dateien erstellt von 2014-09-03 bis 2014-10-03 )))))))))))))))))))))))))))))) . . 2014-10-03 11:19 . 2014-10-03 11:19 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-10-03 10:53 . 2014-10-03 10:53 -------- d-----w- c:\program files\VS Revo Group 2014-10-03 10:13 . 2014-09-09 01:24 8806800 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{1758DEFA-2A3B-456A-8107-BE6A009429E7}\mpengine.dll ERROR(0x00000005) 2014-10-02 14:09 . 2014-10-02 14:12 -------- d-----w- C:\FRST 2014-09-25 05:00 . 2014-09-09 06:24 2048 ----a-w- c:\windows\system32\tzres.dll 2014-09-22 15:42 . 2014-09-25 11:53 -------- d-----w- c:\program files\Spybot - Search & Destroy 2 2014-09-22 14:48 . 2014-09-25 11:48 -------- d-----w- c:\users\XXX\AppData\Roaming\Systweak 2014-09-22 14:43 . 2014-09-22 14:43 -------- d-----w- c:\users\XXX\AppData\Roaming\Abelssoft 2014-09-22 14:43 . 2014-09-22 14:43 -------- d-----w- c:\users\XXX\AppData\Local\Abelssoft 2014-09-22 14:42 . 2014-09-25 11:48 -------- d-----w- c:\program files\CHIP Updater 2014-09-22 14:42 . 2014-09-22 14:42 -------- d-----w- c:\users\XXX\AppData\Roaming\DesktopIconGoodgame 2014-09-22 07:24 . 2014-09-22 07:24 -------- d-----w- c:\program files\Tbccint 2014-09-18 19:53 . 2011-03-25 18:42 338432 ----a-w- c:\windows\system32\sqlite36_engine.dll 2014-09-18 19:53 . 2011-05-13 10:16 493056 ----a-w- c:\windows\system32\dhRichClient3.dll 2014-09-17 18:42 . 2014-09-01 18:29 19840 ----a-w- c:\windows\system32\drivers\pcwatch.sys 2014-09-17 18:41 . 2014-09-01 18:28 304776 ----a-w- c:\windows\system32\MyOSProtect.dll 2014-09-17 18:40 . 2014-09-17 18:40 -------- d-----w- c:\users\XXX\AppData\Local\com 2014-09-17 18:38 . 2014-09-17 18:38 -------- d-----w- c:\program files\globalUpdate 2014-09-17 18:38 . 2014-09-17 18:38 -------- d-----w- c:\users\XXX\AppData\Local\globalUpdate 2014-09-17 18:37 . 2014-09-17 18:41 -------- d-----w- c:\program files\Browser+ Apps+ 2014-09-17 18:36 . 2014-10-02 13:01 -------- d-----w- c:\program files\PCTRunner 2014-09-17 18:31 . 2014-09-17 18:31 -------- d-----w- c:\users\XXX\AppData\Roaming\OpenCandy 2014-09-05 12:15 . 2014-09-05 12:15 -------- d-----w- c:\users\XXX\AppData\Local\Microsoft Corporation . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-10-01 12:09 . 2012-12-07 07:38 98160 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2014-10-01 12:09 . 2012-12-07 07:38 136216 ----a-w- c:\windows\system32\drivers\avipbb.sys 2014-09-24 12:48 . 2012-08-22 08:24 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2014-09-24 12:48 . 2012-08-22 08:24 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2014-09-15 07:06 . 2009-10-05 13:04 231568 ------w- c:\windows\system32\MpSigStub.exe 2014-09-09 01:24 . 2008-11-24 09:42 8806800 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll ERROR(0x00000005) 2014-09-02 19:55 . 2014-09-02 19:55 34244 ----a-w- C:\monitorsvc.exe 2014-08-23 01:03 . 2014-08-29 06:48 297984 ----a-w- c:\windows\system32\gdi32.dll 2014-08-22 23:26 . 2014-08-29 06:48 2054656 ----a-w- c:\windows\system32\win32k.sys 2014-07-25 10:55 . 2014-08-14 03:00 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2014-07-25 00:35 . 2014-07-25 00:35 875688 ----a-w- c:\windows\system32\msvcr120_clr0400.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll" [2014-03-26 424224] . [HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] . [HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] 2014-03-26 14:19 424224 ----a-w- c:\users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll" [2014-03-26 424224] . [HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"= "c:\users\XXX\AppData\LocalLow\DVDVideoSoftTB\prxtbDVD2.dll" [2014-03-26 424224] . [HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-10 39408] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136] "MyDriveConnect.exe"="c:\program files\MyDrive Connect\MyDriveConnect.exe" [2014-08-22 1792376] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440] "ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424] "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552] "GloboFleet"="c:\program files\Buyond_GmbH\GloboFleet_CC_Plus\GloboFleet_CC_Plus.exe" [2011-05-16 236288] "GloboFleet CC"="c:\program files\Buyond_GmbH\GloboFleet_CC\GloboFleet_CC.exe" [2011-05-16 235760] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-11-12 421736] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2014-10-01 703736] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2008-12-02 6695456] "Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2008-12-02 1833504] "PDFPrint"="c:\program files\PDF24\pdf24.exe" [2014-02-06 189480] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2014-07-25 256896] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968] . c:\users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.150\SSScheduler.exe [2014-4-9 279456] t@x aktuell.lnk - c:\program files\Buhl finance\tax Steuersoftware 2012\taxaktuell.exe [2013-5-16 537680] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup backupExtension=.CommonStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd] 2007-03-12 12:51 663552 ------w- c:\program files\Brother\Brmfcmon\BrMfcWnd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3] 2007-01-26 13:58 65536 ------w- c:\program files\Brother\ControlCenter3\BrCtrCen.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core] 2009-09-03 21:17 3342336 ----a-w- c:\program files\Electronic Arts\EADM\Core.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google EULA Launcher] 2008-10-14 09:57 20480 ----a-w- c:\program files\Google\Google EULA\GoogleEULALauncher.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2007-10-14 19:17 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon] 2007-08-22 15:31 80896 ----a-w- c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch] 2007-01-29 19:10 46632 ----a-w- c:\program files\ScanSoft\PaperPort\IndexSearch.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD] 2007-01-29 19:12 30248 ----a-w- c:\program files\ScanSoft\PaperPort\pptd40nt.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPort11reminder] 2007-02-01 11:46 255528 ----a-w- c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] 2008-12-02 16:04 6695456 ----a-w- c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel] 2008-12-02 16:05 1833504 ----a-w- c:\program files\Realtek\Audio\HDA\SkyTel.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] 2008-02-20 14:19 360448 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate] 2006-10-25 07:03 210472 ----a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] 2009-06-10 17:03 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] 2009-07-01 16:37 37888 ----a-w- c:\program files\Winamp\winampa.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-09-14 15:51 1096520 ----a-w- c:\program files\Google\Chrome\Application\37.0.2062.120\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-10-03 c:\windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-5.job - c:\program files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-5.exe [2014-09-17 18:41] . 2014-10-03 c:\windows\Tasks\1a878cad-63df-4953-8a63-7f65ee067291-5_user.job - c:\program files\Browser+ Apps+\1a878cad-63df-4953-8a63-7f65ee067291-5.exe [2014-09-17 18:41] . 2014-10-03 c:\windows\Tasks\6b793742-2e09-427a-a17a-e7ad38f0e8c2.job - c:\program files\Browser+ Apps+\6b793742-2e09-427a-a17a-e7ad38f0e8c2.exe [2014-09-17 18:40] . 2014-10-03 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-22 12:48] . 2014-10-03 c:\windows\Tasks\globalUpdateUpdateTaskMachineCore.job - c:\program files\globalUpdate\Update\GoogleUpdate.exe [2014-09-17 18:37] . 2014-10-02 c:\windows\Tasks\globalUpdateUpdateTaskMachineUA.job - c:\program files\globalUpdate\Update\GoogleUpdate.exe [2014-09-17 18:37] . 2014-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 13:33] . 2014-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 13:33] . 2014-10-03 c:\windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job - c:\windows\system32\msfeedssync.exe [2014-09-11 14:34] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.istartsurf.com/?type=hp&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895 uDefault_Search_URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895&q={searchTerms} mStart Page = about:blank uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s IE: An OneNote s&enden - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105 IE: Free YouTube to MP3 Converter - c:\users\XXX\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000 IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - h**p://rover.ebay.com/rover/1/707-37276-17534-25/4 LSP: c:\windows\system32\MyOSProtect.dll LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\ user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);user_pref('extensions.blocklist.enabled', false);user_pref('security.mixed_content.block_active_content', false); . - - - - Entfernte verwaiste Registrierungseinträge - - - - . SafeBoot-CleanHlp SafeBoot-CleanHlp.sys SafeBoot-WudfPf SafeBoot-WudfRd MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe AddRemove-Free Audio CD Burner_is1 - c:\program files\DVDVideoSoft\Free Audio CD Burner\unins000.exe AddRemove-Need for Speed High Stakes - c:\windows\ISUN0407.EXE AddRemove-_{ADDBE07D-95B8-4789-9C76-187FFF9624B4} - c:\program files\Corel\CorelDRAW Essential Edition 3\Programs\MSILauncher {ADDBE07D-95B8-4789-9C76-187FFF9624B4} . . . ************************************************************************** Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-4257748576-2051970891-1811884360-1000\Software\AppDataLow\Software\Conduit\Community Alerts\Settings\Locales\e*n**jÞ-½[A] @Allowed: (Read) (RestrictedCode) @SACL=(02 0001) "LP_LastUpdateTime"="0" "LP_LastCheckTime"=dword:541fcea9 . [HKEY_USERS\S-1-5-21-4257748576-2051970891-1811884360-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:c6,e9,08,e3,d2,06,6e,6f,a6,87,ba,4c,44,90,77,2f,b5,9a,b0,59,4c,1e,dd, 41,2c,d9,b6,1c,23,56,44,fb,0c,0e,2b,20,63,03,c1,aa,ad,88,b5,28,33,7d,02,c9,\ "??"=hex:37,f6,bf,c5,43,08,2b,dc,2b,06,51,4f,65,de,75,20 . [HKEY_USERS\S-1-5-21-4257748576-2051970891-1811884360-1000\Software\SecuROM\License information*] "datasecu"=hex:c1,8d,73,40,bf,28,6e,b2,9b,25,22,70,7e,ab,f1,52,f7,32,f7,7b,5f, 22,b5,0a,c0,00,f7,b3,13,17,fb,78,7f,96,4a,74,8e,14,5d,b3,d0,cc,03,b1,49,1c,\ "rkeysecu"=hex:8d,30,af,30,22,99,3f,5f,38,b4,18,8f,b1,6a,d5,03 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\program files\Avira\AntiVir Desktop\sched.exe c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe c:\windows\system32\IoctlSvc.exe c:\program files\Cyberlink\Shared files\RichVideo.exe c:\program files\Tbccint\ToolbarService\ToolbarService.exe c:\windows\System32\WUDFHost.exe c:\program files\Avira\AntiVir Desktop\avshadow.exe c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE c:\windows\system32\conime.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\program files\iPod\bin\iPodService.exe c:\program files\OpenOffice.org 3\program\soffice.exe c:\windows\ehome\ehmsas.exe c:\program files\Common Files\Nero\Lib\NMIndexingService.exe c:\program files\OpenOffice.org 3\program\soffice.bin c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe c:\windows\servicing\TrustedInstaller.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-10-03 13:33:52 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-10-03 11:33 . Vor Suchlauf: 6 Verzeichnis(se), 436.967.469.056 Bytes frei Nach Suchlauf: 11 Verzeichnis(se), 436.034.682.880 Bytes frei . - - End Of File - - 1E6A28302368AB678206ADE8BA341159 671B81004FDD1588FA9ED1331C9CECA9 |
04.10.2014, 13:44 | #6 |
/// the machine /// TB-Ausbilder | monitor.exe löschen Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> monitor.exe löschen |
05.10.2014, 00:01 | #7 |
| monitor.exe löschen Hier ist der MBAMtext: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Update, 04.10.2014 23:29:32, SYSTEM, XXX-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.9.19.1, Update, 04.10.2014 23:29:38, SYSTEM, XXX-PC, Manual, Malware Database, 2014.3.4.9, 2014.10.4.11, Update, 04.10.2014 23:31:51, SYSTEM, XXX-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.9.19.1, Update, 04.10.2014 23:31:57, SYSTEM, XXX-PC, Manual, Malware Database, 2014.3.4.9, 2014.10.4.11, (end) Code:
ATTFilter # AdwCleaner v3.311 - Bericht erstellt am 05/10/2014 um 00:30:46 # Aktualisiert 30/09/2014 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : XXX - XXX-PC # Gestartet von : C:\Users\XXX\Desktop\AdwCleaner_3.311.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : globalUpdatem [#] Dienst Gelöscht : MyOSProtect [#] Dienst Gelöscht : pcwatch Dienst Gelöscht : TBSrv ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\2308189059 Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar Ordner Gelöscht : C:\ProgramData\WindowsMangerProtect Ordner Gelöscht : C:\Program Files\Conduit Ordner Gelöscht : C:\Program Files\DVDVideoSoftTB Ordner Gelöscht : C:\Program Files\globalUpdate Ordner Gelöscht : C:\Program Files\ICQ6Toolbar [!] Ordner Gelöscht : C:\Program Files\PCTRunner Ordner Gelöscht : C:\Program Files\Tbccint Ordner Gelöscht : C:\Users\XXX\AppData\Local\globalUpdate Ordner Gelöscht : C:\Users\XXX\AppData\Local\PackageAware Ordner Gelöscht : C:\Users\XXX\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\XXX\AppData\LocalLow\DVDVideoSoftTB Ordner Gelöscht : C:\Users\XXX\AppData\LocalLow\PriceGong Ordner Gelöscht : C:\Users\XXX\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\XXX\AppData\Roaming\OpenCandy Ordner Gelöscht : C:\Users\XXX\AppData\Roaming\Systweak Ordner Gelöscht : C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\ConduitCommon Ordner Gelöscht : C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\ICQToolbarData Ordner Gelöscht : C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\CT2269050 Ordner Gelöscht : C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07} Ordner Gelöscht : C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} Ordner Gelöscht : C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C} Ordner Gelöscht : C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\faststartff@gmail.com Ordner Gelöscht : C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaajpkhjdkhhnkmgfjodbkfpbmibkkk Datei Gelöscht : C:\monitorsvc.exe Datei Gelöscht : C:\Windows\system32\drivers\pcwatch.sys Datei Gelöscht : C:\Windows\system32\MyOSProtect.dll Datei Gelöscht : C:\Program Files\Mozilla Firefox\.autoreg Datei Gelöscht : C:\Program Files\Mozilla Firefox\Components\AskSearch.js Datei Gelöscht : C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\searchplugins\icqplugin.xml Datei Gelöscht : C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\searchplugins\icqplugin-1.xml Datei Gelöscht : C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\searchplugins\icqplugin-2.xml Datei Gelöscht : C:\Program Files\Mozilla Firefox\searchplugins\istartsurf.xml Datei Gelöscht : C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\user.js Datei Gelöscht : C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx ***** [ Tasks ] ***** Task Gelöscht : globalUpdateUpdateTaskMachineCore Task Gelöscht : globalUpdateUpdateTaskMachineUA Task Gelöscht : LaunchApp Task Gelöscht : 1a878cad-63df-4953-8a63-7f65ee067291-5 Task Gelöscht : 1a878cad-63df-4953-8a63-7f65ee067291-5_user Task Gelöscht : 6b793742-2e09-427a-a17a-e7ad38f0e8c2 ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com] Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma Schlüssel Gelöscht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Conduit.Engine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10 Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4 Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2269050 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{46C4F788-2570-4CEA-B7E7-4CC39A33192D} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{46C4F788-2570-4CEA-B7E7-4CC39A33192D} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2A09E62-E40C-4DF6-AC9A-560036D9F66D} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E4B39EB-81A0-4598-B4BB-97833E844A09} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\DVDVideoSoftTB Schlüssel Gelöscht : HKCU\Software\GlobalUpdate Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\SupHpUISoft Schlüssel Gelöscht : HKCU\Software\Tbccint_HKLM Schlüssel Gelöscht : HKCU\Software\Tune Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit Schlüssel Gelöscht : HKLM\SOFTWARE\DVDVideoSoftTB Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate Schlüssel Gelöscht : HKLM\SOFTWARE\ICQ\ICQToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions Schlüssel Gelöscht : HKLM\SOFTWARE\istartsurfSoftware Schlüssel Gelöscht : HKLM\SOFTWARE\supWindowsMangerProtect Schlüssel Gelöscht : HKLM\SOFTWARE\systweak Schlüssel Gelöscht : HKLM\SOFTWARE\Tune Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Winamp Toolbar Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16575 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] -\\ Mozilla Firefox v3.6.28 (de) -\\ Google Chrome v37.0.2062.120 [ Datei : C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Homepage] : hxxp://www.istartsurf.com/?type=hp&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895 Gelöscht [Extension] : aaaajpkhjdkhhnkmgfjodbkfpbmibkkk ************************* AdwCleaner[R0].txt - [16527 octets] - [05/10/2014 00:21:25] AdwCleaner[S0].txt - [14718 octets] - [05/10/2014 00:30:46] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14779 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.2.8 (10.04.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by XXX on 05.10.2014 at 0:45:39,36 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BBA6EFAC-51E4-478F-8B44-25C0E57290B4} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D6C6BCFC-6F7B-4BC8-B92E-A58EFB2D0042} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" Successfully deleted: [Folder] "C:\Program Files\browser+ apps+" ~~~ FireFox Successfully deleted: [Folder] C:\Users\XXX\AppData\Roaming\mozilla\firefox\profiles\gh5sdnyo.default\extensions\engine@conduit.com-trash Emptied folder: C:\Users\XXX\AppData\Roaming\mozilla\firefox\profiles\gh5sdnyo.default\minidumps [1 files] ~~~ Chrome Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy] Successfully deleted: [Folder] C:\Users\XXX\appdata\local\Google\Chrome\User Data\Default\Extensions\aaaajpkhjdkhhnkmgfjodbkfpbmibkkk ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 05.10.2014 at 0:50:26,83 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-10-2014 01 Ran by XXX (administrator) on XXX-PC on 05-10-2014 00:55:00 Running from C:\Users\XXX\Desktop Loaded Profile: XXX (Available profiles: XXX) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Program Files\Cyberlink\Shared files\RichVideo.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Buyond GmbH) C:\Program Files\Buyond_GmbH\GloboFleet_CC_Plus\GloboFleet_CC_Plus.exe (Buyond GmbH) C:\Program Files\Buyond_GmbH\GloboFleet_CC\GloboFleet_CC.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (TomTom) C:\Program Files\MyDrive Connect\MyDriveConnect.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe () C:\Program Files\Buhl finance\tax Steuersoftware 2012\taxaktuell.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-08-29] (Advanced Micro Devices, Inc.) HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [GloboFleet] => C:\Program Files\Buyond_GmbH\GloboFleet_CC_Plus\GloboFleet_CC_Plus.exe [236288 2011-05-16] (Buyond GmbH) HKLM\...\Run: [GloboFleet CC] => C:\Program Files\Buyond_GmbH\GloboFleet_CC\GloboFleet_CC.exe [235760 2011-05-16] (Buyond GmbH) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [421736 2011-11-13] (Apple Inc.) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-01] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6695456 2008-12-02] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2008-12-02] (Realtek Semiconductor Corp.) HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) Winlogon\Notify\ScCertProp: wlnotify.dll [X] HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-06-10] (Google Inc.) HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1828136 2008-02-28] (Nero AG) HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\Run: [MyDriveConnect.exe] => C:\Program Files\MyDrive Connect\MyDriveConnect.exe [1792376 2014-08-22] (TomTom) HKU\S-1-5-18\...\Run: [Picasa Media Detector] => C:\Program Files\Picasa2\PicasaMediaDetector.exe [443968 2008-08-21] (Google Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\t@x aktuell.lnk ShortcutTarget: t@x aktuell.lnk -> C:\Program Files\Buhl finance\tax Steuersoftware 2012\taxaktuell.exe () Startup: C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe () BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: CBAbzockschutz.InitToolbarBHO -> {2e250b90-0e7a-42a3-9d65-e39f9f227fa4} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: No Name -> {7E853D72-626A-48EC-A868-BA8D5E23E045} -> No File BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - COMPUTERBILD-Abzockschutz - {353e2a48-6254-4bd3-88f4-3b51a0ca7870} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} hxxp://lads.myspace.com/upload/MySpaceUploader2.cab DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 02 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 03 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 04 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 09 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 10 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 11 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 12 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 23 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 24 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa2,version=2.0.0 -> C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.) FF SearchPlugin: C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Browser+ Apps+ - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\56560a80-995b-47cd-852a-772f3a7ea92b@gmail.com [2014-09-17] FF Extension: No Name - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\cliqz@cliqz.com [2014-09-18] FF Extension: Microsoft .NET Framework Assistant - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-05-20] FF Extension: Adblock Plus - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2013-12-22] FF Extension: COMPUTERBILD-Abzockschutz - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{d49175b3-3fd8-43b8-b28e-da5d47f3c398} [2013-12-22] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010-05-20] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010-09-02] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2010-10-23] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2011-01-06] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-03-31] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2011-08-09] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-10-05] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-21] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} [2013-02-15] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-06-11] FF HKLM\...\Firefox\Extensions: [termtutor@termtutor.com] - C:\Program Files\Mozilla Firefox\extensions\termtutor@termtutor.com FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] FF HKCU\...\Thunderbird\Extensions: [{380AE6CB-09B9-4373-B360-D01C2462A6E7}] - C:\program files\bullguard ltd\bullguard\backup\thunderbirdbkplugin FF HKCU\...\Thunderbird\Extensions: [{0E810812-F4BB-4309-942A-755587587A5E}] - C:\Program Files\BullGuard Ltd\BullGuard\antispam\tbspamfilter FF Extension: No Name - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\extensions\faststartff@gmail.com [Not Found] FF Extension: No Name - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [Not Found] Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com/ CHR RestoreOnStartup: Default -> "hxxp://www.istartsurf.com/?type=hp&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895" CHR NewTab: Default -> "chrome-extension://aaaajpkhjdkhhnkmgfjodbkfpbmibkkk/config/skin/new-tab-page.html" CHR DefaultSearchKeyword: Default -> istartsurf CHR DefaultSearchProvider: Default -> istartsurf CHR DefaultSearchURL: Default -> h**p://www.istartsurf.com/web/?type=ds&ts=1410978976&from=tugs&uid=395049983_1052451_CE8AA895&q={searchTerms} CHR DefaultSuggestURL: Default -> h**p://ss.websearch.ask.com/query?qsrc={qsrc}&li=ff&sstype=prefix&q={searchTerms} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll No File CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.290.11) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Picasa) - C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.) CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR CustomProfile: C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (YouTube) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-19] CHR Extension: (Google Search) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-19] CHR Extension: (Google Wallet) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29] CHR Extension: (Browser+ Apps+) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\okhbpnfiofnpilolnjeebnidmkopeeda [2014-09-17] CHR Extension: (Gmail) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-19] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [805112 2014-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [994552 2014-10-01] (Avira Operations GmbH & Co. KG) S3 Browser7Maintenance; C:\Program Files\Browser 7 Maintenance Service\maintenanceservice.exe [118584 2014-09-13] (Deutsche Telekom AG) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2008-10-16] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [135168 2008-03-25] (Hewlett-Packard Co.) [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.) S3 MyOSProtect; C:\Program Files\PCTRunner\MyOSProtect.exe [1317096 2014-09-01] (MyOSCompany) [File not signed] R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed] R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed] R2 RichVideo; C:\Program Files\Cyberlink\Shared files\RichVideo.exe [241734 2008-06-28] () [File not signed] S3 usnjsvc; C:\Program Files\Windows Live\Messenger\usnsvc.exe [98328 2007-10-18] (Microsoft Corporation) S3 WLSetupSvc; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [266240 2007-10-25] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 ahcix86s; C:\Windows\System32\DRIVERS\ahcix86s.sys [183312 2008-10-03] (Advanced Micro Devices, Inc) R0 amdide; C:\Windows\System32\DRIVERS\amdide.sys [10632 2007-10-12] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-29] (Avira Operations GmbH & Co. KG) S3 cxbu0wdm; C:\Windows\System32\DRIVERS\cxbu0wdm.sys [115712 2010-01-25] (HID Global Corporation) S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [554496 2007-09-21] (Ralink Technology Corp.) R1 pcwatch; C:\Windows\system32\Drivers\pcwatch.sys [19840 2014-09-01] () [File not signed] <==== ATTENTION R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [154272 2008-11-11] (Realtek Semiconductor Corp.) S3 s117bus; C:\Windows\System32\DRIVERS\s117bus.sys [82984 2007-06-25] (MCCI Corporation) S3 s117mdfl; C:\Windows\System32\DRIVERS\s117mdfl.sys [14888 2007-06-25] (MCCI Corporation) S3 s117mdm; C:\Windows\System32\DRIVERS\s117mdm.sys [108456 2007-06-25] (MCCI Corporation) S3 s117mgmt; C:\Windows\System32\DRIVERS\s117mgmt.sys [100264 2007-06-25] (MCCI Corporation) S3 s117nd5; C:\Windows\System32\DRIVERS\s117nd5.sys [22952 2007-06-25] (MCCI Corporation) S3 s117obex; C:\Windows\System32\DRIVERS\s117obex.sys [98344 2007-06-25] (MCCI Corporation) S3 s117unic; C:\Windows\System32\DRIVERS\s117unic.sys [98856 2007-06-25] (MCCI Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cleanhlp; \??\C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 Profos; \??\C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\profos.sys [X] S3 Trufos; \??\C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\trufos.sys [X] S1 ttnfd; system32\drivers\ttnfd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-05 00:54 - 2014-10-05 00:54 - 00000000 ____D () C:\Users\XXX\Desktop\FRST-OlderVersion 2014-10-05 00:50 - 2014-10-05 00:50 - 00001582 _____ () C:\Users\XXX\Desktop\JRT.txt 2014-10-05 00:45 - 2014-10-05 00:45 - 00000000 ____D () C:\Windows\ERUNT 2014-10-05 00:43 - 2014-10-05 00:43 - 01694116 _____ (Thisisu) C:\Users\XXX\Desktop\JRT.exe 2014-10-05 00:21 - 2014-10-05 00:32 - 00000000 ____D () C:\AdwCleaner 2014-10-05 00:20 - 2014-10-05 00:20 - 01375089 _____ () C:\Users\XXX\Desktop\AdwCleaner_3.311.exe 2014-10-05 00:16 - 2014-10-05 00:16 - 00000468 _____ () C:\Users\XXX\Desktop\MBAM.txt 2014-10-04 23:29 - 2014-10-05 00:15 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-04 23:28 - 2014-10-04 23:31 - 00000863 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-04 23:28 - 2014-10-04 23:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-04 23:27 - 2014-10-04 23:31 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-10-04 23:27 - 2014-10-04 23:27 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-04 23:27 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-10-04 23:27 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-10-04 23:27 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-10-04 23:26 - 2014-10-04 23:26 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\XXX\Desktop\mbam-setup-2.0.2.1012.exe 2014-10-03 13:33 - 2014-10-03 13:33 - 00018853 _____ () C:\ComboFix.txt 2014-10-03 13:03 - 2014-10-03 13:33 - 00000000 ____D () C:\Qoobox 2014-10-03 13:03 - 2014-10-03 13:31 - 00000000 ____D () C:\Windows\erdnt 2014-10-03 13:03 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-10-03 13:03 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-10-03 13:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-10-03 13:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-10-03 13:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-10-03 13:03 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-10-03 13:03 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-10-03 13:03 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-10-03 13:01 - 2014-10-03 13:01 - 05582981 ____R (Swearware) C:\Users\XXX\Desktop\ComboFix.exe 2014-10-03 12:53 - 2014-10-03 12:53 - 00001061 _____ () C:\Users\XXX\Desktop\Revo Uninstaller.lnk 2014-10-03 12:53 - 2014-10-03 12:53 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-10-03 12:52 - 2014-10-03 12:52 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\XXX\Desktop\revosetup95.exe 2014-10-02 16:10 - 2014-10-02 16:12 - 00050951 _____ () C:\Users\XXX\Desktop\Addition.txt 2014-10-02 16:09 - 2014-10-05 00:55 - 00027509 _____ () C:\Users\XXX\Desktop\FRST.txt 2014-10-02 16:09 - 2014-10-05 00:55 - 00000000 ____D () C:\FRST 2014-10-02 16:08 - 2014-10-05 00:54 - 01100800 _____ (Farbar) C:\Users\XXX\Desktop\FRST.exe 2014-10-02 15:15 - 2014-10-02 15:15 - 00015173 _____ () C:\Users\XXX\Desktop\hijackthis.log 2014-10-02 15:11 - 2014-10-02 15:12 - 00388608 _____ (Trend Micro Inc.) C:\Users\XXX\Desktop\test.com 2014-09-28 23:43 - 2014-09-25 13:57 - 06816184 _____ (TomTom International B.V.) C:\Users\XXX\Downloads\InstallMyDriveConnect_3_3_0_1756.exe 2014-09-25 07:00 - 2014-09-09 08:24 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-09-23 15:05 - 2014-09-23 15:06 - 00000000 ____D () C:\Users\XXX\Desktop\Zeugnisse_Scan Vati 2014-09-22 19:47 - 2014-09-25 13:50 - 00006914 _____ () C:\Windows\wininit.ini 2014-09-22 17:43 - 2014-09-25 13:50 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-09-22 17:42 - 2014-09-25 13:53 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2 2014-09-22 17:40 - 2014-09-22 17:41 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\XXX\Documents\spybot_27341.exe 2014-09-22 16:46 - 2014-09-22 16:46 - 03490448 _____ (tuneuppro.com ) C:\Users\XXX\Documents\setup.exe 2014-09-22 16:43 - 2014-09-22 16:43 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\Abelssoft 2014-09-22 16:43 - 2014-09-22 16:43 - 00000000 ____D () C:\Users\XXX\AppData\Local\Abelssoft 2014-09-22 16:43 - 2014-09-22 16:43 - 00000000 ____D () C:\ProgramData\XDMessagingv4 2014-09-22 16:42 - 2014-09-25 13:48 - 00000000 ____D () C:\Program Files\CHIP Updater 2014-09-22 16:42 - 2014-09-22 16:42 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\DesktopIconGoodgame 2014-09-22 16:41 - 2014-09-22 16:42 - 01101648 _____ () C:\Users\XXX\Documents\Emsisoft Anti Malware - CHIP-Installer.exe 2014-09-18 21:53 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\system32\dhRichClient3.dll 2014-09-18 21:53 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\system32\sqlite36_engine.dll 2014-09-18 21:51 - 2014-09-18 21:51 - 01101648 _____ () C:\Users\XXX\Documents\adblockplusie-1.2 - CHIP-Installer.exe 2014-09-18 21:18 - 2014-09-18 21:18 - 00000000 ____D () C:\Users\XXX\Downloads\fab14 2014-09-18 21:17 - 2014-09-18 21:17 - 00452038 _____ () C:\Users\XXX\Downloads\fab14.zip 2014-09-18 21:15 - 2014-09-18 21:16 - 01101648 _____ () C:\Users\XXX\Downloads\Firewall App Blocker FAB - CHIP-Installer.exe 2014-09-17 20:42 - 2014-09-01 20:29 - 00019840 _____ () C:\Windows\system32\Drivers\pcwatch.sys 2014-09-17 20:41 - 2014-09-01 20:28 - 00304776 _____ (MyOSCompany) C:\Windows\system32\MyOSProtect.dll 2014-09-17 20:40 - 2014-09-17 20:40 - 00000000 ____D () C:\Users\XXX\AppData\Local\com 2014-09-17 20:36 - 2014-10-02 15:01 - 00000000 ____D () C:\Program Files\PCTRunner 2014-09-17 20:28 - 2014-09-17 20:29 - 30419936 _____ (DVDVideoSoft Ltd. ) C:\Users\XXX\Downloads\FreeYouTubeToMP3Converter3.12.44.908.exe 2014-09-14 13:41 - 2014-09-14 13:41 - 00000000 ____D () C:\ProgramData\Telekom-Browser 7 2014-09-11 15:08 - 2014-08-15 16:51 - 12363264 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-09-11 15:08 - 2014-08-15 16:42 - 09739776 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-09-11 15:08 - 2014-08-15 16:42 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-09-11 15:08 - 2014-08-15 16:37 - 01137664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-09-11 15:08 - 2014-08-15 16:37 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-09-11 15:08 - 2014-08-15 16:36 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-09-11 15:08 - 2014-08-15 16:35 - 01802240 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-09-11 15:08 - 2014-08-15 16:35 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-09-11 15:08 - 2014-08-15 16:35 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-09-11 15:08 - 2014-08-15 16:34 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-09-11 15:08 - 2014-08-15 16:34 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-09-11 15:08 - 2014-08-15 16:34 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-09-11 15:08 - 2014-08-15 16:34 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-09-11 15:08 - 2014-08-15 16:34 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-09-10 13:54 - 2014-09-26 14:25 - 00000000 ____D () C:\Users\XXX\Desktop\Sims 2014-09-10 13:54 - 2014-09-22 18:50 - 00000000 ____D () C:\Users\XXX\Desktop\Praktikum XXX 2014-09-05 15:53 - 2014-09-05 15:53 - 00000000 ____D () C:\Users\Public\Documents\EA Games 2014-09-05 15:44 - 2014-09-26 14:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES 2014-09-05 15:42 - 2014-09-05 15:42 - 00000000 ____D () C:\Users\XXX\Documents\EA Games 2014-09-05 14:15 - 2014-09-05 14:15 - 00000000 ____D () C:\Users\XXX\AppData\Local\Microsoft Corporation 2014-09-05 14:07 - 2014-09-05 14:12 - 373578968 _____ (Microsoft Corporation) C:\Users\XXX\Downloads\office2007sp3-kb2526086-fullfile-de-de.exe 2014-09-05 14:07 - 2014-09-05 14:12 - 08676128 _____ (Microsoft Corporation) C:\Users\XXX\Downloads\Windows7UpgradeAdvisorSetup.exe 2014-09-05 14:06 - 2014-09-05 14:06 - 09848595 _____ () C:\Users\XXX\Downloads\Windows6.0-KB971512-x64.msu 2014-09-05 14:05 - 2014-09-05 14:05 - 04814058 _____ () C:\Users\XXX\Downloads\Windows6.0-KB971512-x86(1).msu 2014-09-05 14:04 - 2014-09-05 14:04 - 04814058 _____ () C:\Users\XXX\Downloads\Windows6.0-KB971512-x86.msu 2014-09-05 14:01 - 2014-09-05 14:01 - 00315624 _____ (Microsoft Corporation) C:\Users\XXX\Downloads\dxwebsetup.exe 2014-09-05 14:01 - 2014-09-05 14:01 - 00000000 ____D () C:\Windows\system32\directx ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-05 00:55 - 2008-12-10 17:30 - 00000438 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job 2014-10-05 00:51 - 2010-02-06 15:33 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-05 00:48 - 2012-08-22 10:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-05 00:34 - 2010-02-06 15:33 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-05 00:34 - 2008-01-21 04:47 - 00171620 _____ () C:\Windows\PFRO.log 2014-10-05 00:34 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-05 00:34 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-05 00:34 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-05 00:32 - 2009-06-10 18:54 - 01599003 _____ () C:\Windows\WindowsUpdate.log 2014-10-05 00:32 - 2006-11-02 15:01 - 00032628 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-10-05 00:31 - 2009-07-14 21:51 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-10-05 00:30 - 2009-06-11 22:37 - 00000000 ____D () C:\ProgramData\ICQ 2014-10-03 13:33 - 2006-11-02 13:18 - 00000000 __RHD () C:\Users\Default 2014-10-03 13:33 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public 2014-10-03 13:25 - 2006-11-02 12:23 - 00000215 _____ () C:\Windows\system.ini 2014-10-03 13:18 - 2009-06-10 19:03 - 00000000 ____D () C:\Users\XXX 2014-10-01 15:05 - 2008-12-18 13:16 - 00057323 _____ () C:\Windows\setupact.log 2014-10-01 14:09 - 2012-12-07 09:38 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-10-01 14:09 - 2012-12-07 09:38 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-09-28 23:44 - 2013-12-06 21:20 - 00000000 ____D () C:\Program Files\MyDrive Connect 2014-09-28 20:53 - 2006-11-02 12:33 - 01643318 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-26 14:20 - 2011-08-07 16:35 - 00000000 ____D () C:\Program Files\EA GAMES 2014-09-25 14:11 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\rescache 2014-09-25 07:05 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-09-24 14:48 - 2012-08-22 10:24 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-09-24 14:48 - 2012-08-22 10:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-09-23 13:27 - 2006-11-02 14:47 - 00375400 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-09-22 16:49 - 2009-06-10 19:04 - 00103912 _____ () C:\Users\XXX\AppData\Local\GDIPFONTCACHEV1.DAT 2014-09-17 22:11 - 2009-06-10 19:03 - 00000953 _____ () C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-09-17 22:04 - 2011-07-27 16:26 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\DVDVideoSoft 2014-09-15 09:27 - 2013-08-31 19:11 - 00000000 ____D () C:\Users\XXX\Desktop\Ordner XXX 2014-09-15 09:06 - 2009-10-05 15:04 - 00231568 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-09-14 17:01 - 2013-12-23 13:00 - 00000000 ____D () C:\Program Files\Browser 7 Maintenance Service 2014-09-14 13:41 - 2013-12-23 13:00 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\Deutsche Telekom AG 2014-09-14 13:41 - 2013-12-23 13:00 - 00000000 ____D () C:\Program Files\Deutsche Telekom AG 2014-09-12 11:59 - 2011-06-19 09:59 - 00006836 _____ () C:\Users\XXX\AppData\Local\d3d9caps.dat 2014-09-11 18:19 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-09-11 15:07 - 2008-11-25 10:38 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-09-11 15:06 - 2013-08-16 16:30 - 00000000 ____D () C:\Windows\system32\MRT 2014-09-11 14:54 - 2006-11-02 12:24 - 98758480 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-09-05 14:32 - 2009-06-11 15:24 - 00000000 ____D () C:\Program Files\Electronic Arts 2014-09-05 14:32 - 2008-12-10 16:19 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-09-05 14:03 - 2008-12-10 17:35 - 00061284 _____ () C:\Windows\DirectX.log Some content of TEMP: ==================== C:\Users\XXX\AppData\Local\Temp\avgnt.exe C:\Users\XXX\AppData\Local\Temp\drm_dyndata_7350007.dll C:\Users\XXX\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-05 00:42 ==================== End Of Log ============================ --- --- --- --- --- --- Wieder einmal bis hierher einen recht herzlichen Dank! |
05.10.2014, 14:58 | #8 |
/// the machine /// TB-Ausbilder | monitor.exe löschen Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Winsock: Catalog9 24 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 01 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 02 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 03 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 04 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) C:\Windows\system32\MyOSProtect.dll cmd: netsh winsock reset CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.10.2014, 13:57 | #9 |
| monitor.exe löschen Hallo, vielen Dank für die stets schnelle Hilfe! Leider hatte ich die letzten Tage keine Möglichkeit weiter den Anweisungen zu folgen. Jetzt geht es aber wieder weiter. Hier der Fixlog.txt: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 06-10-2014 01 Ran by XXX at 2014-10-09 14:27:38 Run:1 Running from C:\Users\XXX\Desktop Loaded Profile: XXX (Available profiles: XXX) Boot Mode: Normal ============================================== Content of fixlist: ***************** Winsock: Catalog9 24 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 01 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 02 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 03 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 04 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) C:\Windows\system32\MyOSProtect.dll cmd: netsh winsock reset CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Emptytemp: ***************** "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000024" => Error deleting key. The key could be protected. "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" => Error deleting key. The key could be protected. "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" => Error deleting key. The key could be protected. "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" => Error deleting key. The key could be protected. "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" => Error deleting key. The key could be protected. Could not move "C:\Windows\system32\MyOSProtect.dll" => Scheduled to move on reboot. ========= netsh winsock reset ========= Zugriff verweigert ========= End of CMD: ========= "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. EmptyTemp: => Removed 998.9 MB temporary data. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-10-09 14:49:22)<= "C:\Windows\system32\MyOSProtect.dll" => File could not move. ==== End of Fixlog ==== |
09.10.2014, 20:12 | #10 |
/// the machine /// TB-Ausbilder | monitor.exe löschen Ok ich warte dann auf den Rest.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.10.2014, 20:26 | #11 |
| monitor.exe löschen Hallo, Entschuldige das wird bis zum Wochenende warten müssen. Der PC ist der bei meinen Eltern und ich bin erstmal wieder zum Studium weggefahren... Und der heutige Kurzbesuch hat da leider nicht ausgereicht um das Programms durchlaufen zu lassen... Ich schreibe sobald die restlichen Schritte getan sind. Danke dir bis hierher! |
10.10.2014, 17:35 | #12 |
/// the machine /// TB-Ausbilder | monitor.exe löschen ok
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.10.2014, 20:06 | #13 |
| monitor.exe löschen So, es kann zumindest mit dem Logfile für ESET weitergehen: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=ee876869d0ec304ebc66a9be3c7643de # engine=20517 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-10-09 05:43:35 # local_time=2014-10-09 07:43:35 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode_1='' # compatibility_mode=5892 16776574 100 100 545392 250409343 0 0 # scanned=229752 # found=23 # cleaned=0 # scan_time=16775 sh=C5E60CCD154DB4E5978E33285DB016171C80ED79 ft=1 fh=58635ab0e5696ad2 vn="Win32/AdWare.Loadshop.A Anwendung" ac=I fn="C:\monitorsvc.exe" sh=97BCCD25561F44E9B13F05F6EEF083C9CE9BA529 ft=1 fh=641f1fb3d2e699c4 vn="Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Conduit\Community Alerts\Alert0.dll.vir" sh=E5AD99CE7C7362CA566156033ECB0F04F9437CA7 ft=1 fh=f45d83e01e1c8734 vn="Win32/Toolbar.Conduit.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\DVDVideoSoftTB\DVDVideoSoftTBToolbarHelper1.exe.vir" sh=A1280B1F085B8284DC157EC359BD1ADA091CFE7E ft=1 fh=d8aa3384d1249a40 vn="Variante von Win32/Toolbar.Conduit.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\DVDVideoSoftTB\ldrtbDVD0.dll.vir" sh=A2D929A9864513C0E8ED84AAD622EF6ADCC9B950 ft=1 fh=22c06217fc444ec5 vn="Win32/Toolbar.Conduit.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\DVDVideoSoftTB\prxtbDVD0.dll.vir" sh=92E84D2216A7763D580E42FA2493CCF67D0D0560 ft=1 fh=e8efc42494afd9f6 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\DVDVideoSoftTB\tbDVD0.dll.vir" sh=57CD8DEAF43DF3A2F4703E5219A69935B119D0DB ft=1 fh=311781f1ea21501f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\DVDVideoSoftTB\tbDVDV.dll.vir" sh=FDF4ADB3654AC8E84A67513864636A36359C2B31 ft=1 fh=ef83010defedbcf7 vn="Variante von Win32/Conduit.SearchProtect.N evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Tbccint\ToolbarService\ToolbarService.exe.vir" sh=37FDC039C02562267559D42D94DDB64B692FD091 ft=1 fh=7aeecd1bb81f6a22 vn="Variante von Win64/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\hk64tbDVD2.dll.vir" sh=A6D053127826CDA8DD8FCDBB4E81F63000910624 ft=1 fh=e8f05c501331b563 vn="Variante von Win32/Toolbar.Conduit.X evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\hktbDVD2.dll.vir" sh=A1280B1F085B8284DC157EC359BD1ADA091CFE7E ft=1 fh=d8aa3384d1249a40 vn="Variante von Win32/Toolbar.Conduit.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\ldrtbDVD0.dll.vir" sh=92E84D2216A7763D580E42FA2493CCF67D0D0560 ft=1 fh=e8efc42494afd9f6 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\tbDVD0.dll.vir" sh=594E0844207ADD0DBD163E1AFB7696BAA25CB961 ft=1 fh=b78030dcfe359240 vn="Variante von Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\tbDVD1.dll.vir" sh=7148AC44C7FE0CB8D30A12ACB28171AE1F609C20 ft=1 fh=779162af1796b620 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\tbDVD2.dll.vir" sh=57CD8DEAF43DF3A2F4703E5219A69935B119D0DB ft=1 fh=311781f1ea21501f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\tbDVDV.dll.vir" sh=ABF759CA3BFB16DE62197DD7C417AC5039A43AE0 ft=1 fh=1801af74030ebca1 vn="Variante von Win32/PriceGong.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\XXX\AppData\LocalLow\DVDVideoSoftTB\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3\bin\PriceGongIE.dll.vir" sh=4ED25B3CC890F0610C90A0AFC23958E9735BBADA ft=1 fh=5adcb2e47924708b vn="Variante von Win32/Conduit.SearchProtect.N evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\Plugins\npConduitFirefoxPlugin.dll.vir" sh=6BBC79D174DEA35228600E7C9AF0ABFBF91CF403 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\okhbpnfiofnpilolnjeebnidmkopeeda\1.26.29_0\extensionData\plugins\91.js" sh=9DF4EA0B9CB1D953184D380A961FC03F07F8A8FF ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX\AppData\Roaming\Deutsche Telekom AG\Browser7\Profiles\tnwlyutu.default\extensions\56560a80-995b-47cd-852a-772f3a7ea92b@gmail.com\extensionData\plugins\91.js" sh=6BBC79D174DEA35228600E7C9AF0ABFBF91CF403 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\extensions\56560a80-995b-47cd-852a-772f3a7ea92b@gmail.com\extensionData\plugins\91.js" sh=0CEB95BDE6A27C4F750FF850102A03030529723E ft=1 fh=c61c8f1ba39a5b2a vn="Win32/Systweak.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX\Documents\setup.exe" sh=4C2E3F12AC48D1FA3988EF1052706354E7EDF335 ft=1 fh=150c0ce4dffdd413 vn="Variante von Win32/Toolbar.Conduit.AI evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX\Downloads\FreeYouTubeToMP3Converter.exe" sh=FC36E37C5AF2A351DCD003127821BE33E48D56CF ft=1 fh=cc013aa1066e7274 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX\Downloads\FreeYouTubeToMP3Converter34.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.87 Windows Vista Service Pack 2 x86 Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Java(TM) 6 Update 39 Java 7 Update 67 Adobe Flash Player 15.0.0.152 Adobe Reader 9 Adobe Reader out of Date! Adobe Reader 10.1.11 Adobe Reader out of Date! Mozilla Firefox (3.6.28) Firefox out of Date! Google Chrome 37.0.2062.103 Google Chrome 37.0.2062.120 ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-10-2014 Ran by XXX (administrator) on XXX-PC on 12-10-2014 21:01:12 Running from C:\Users\XXX\Desktop Loaded Profile: XXX (Available profiles: XXX) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe () C:\Program Files\Cyberlink\Shared files\RichVideo.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Buyond GmbH) C:\Program Files\Buyond_GmbH\GloboFleet_CC_Plus\GloboFleet_CC_Plus.exe (Buyond GmbH) C:\Program Files\Buyond_GmbH\GloboFleet_CC\GloboFleet_CC.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe (Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (TomTom) C:\Program Files\MyDrive Connect\MyDriveConnect.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Program Files\Buhl finance\tax Steuersoftware 2012\taxaktuell.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Deutsche Telekom AG) C:\Program Files\Deutsche Telekom AG\Browser 7\Browser7.exe (Deutsche Telekom AG) C:\Program Files\Deutsche Telekom AG\Browser 7\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-08-29] (Advanced Micro Devices, Inc.) HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [GloboFleet] => C:\Program Files\Buyond_GmbH\GloboFleet_CC_Plus\GloboFleet_CC_Plus.exe [236288 2011-05-16] (Buyond GmbH) HKLM\...\Run: [GloboFleet CC] => C:\Program Files\Buyond_GmbH\GloboFleet_CC\GloboFleet_CC.exe [235760 2011-05-16] (Buyond GmbH) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [421736 2011-11-13] (Apple Inc.) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-01] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6695456 2008-12-02] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2008-12-02] (Realtek Semiconductor Corp.) HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) Winlogon\Notify\ScCertProp: wlnotify.dll [X] HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-06-10] (Google Inc.) HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1828136 2008-02-28] (Nero AG) HKU\S-1-5-21-4257748576-2051970891-1811884360-1000\...\Run: [MyDriveConnect.exe] => C:\Program Files\MyDrive Connect\MyDriveConnect.exe [1792376 2014-08-22] (TomTom) HKU\S-1-5-18\...\Run: [Picasa Media Detector] => C:\Program Files\Picasa2\PicasaMediaDetector.exe [443968 2008-08-21] (Google Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\t@x aktuell.lnk ShortcutTarget: t@x aktuell.lnk -> C:\Program Files\Buhl finance\tax Steuersoftware 2012\taxaktuell.exe () Startup: C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe () BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} BHO: CBAbzockschutz.InitToolbarBHO -> {2e250b90-0e7a-42a3-9d65-e39f9f227fa4} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: No Name -> {7E853D72-626A-48EC-A868-BA8D5E23E045} -> No File BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - COMPUTERBILD-Abzockschutz - {353e2a48-6254-4bd3-88f4-3b51a0ca7870} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} h**p://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} h**p://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} h**p://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} h**p://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} h**p://lads.myspace.com/upload/MySpaceUploader2.cab DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} h**p://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} h**p://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 02 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 03 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 04 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 09 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 10 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 11 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 12 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 23 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 24 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa2,version=2.0.0 -> C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.) FF SearchPlugin: C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Browser+ Apps+ - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\56560a80-995b-47cd-852a-772f3a7ea92b@gmail.com [2014-09-17] FF Extension: No Name - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\cliqz@cliqz.com [2014-09-18] FF Extension: Microsoft .NET Framework Assistant - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-05-20] FF Extension: Adblock Plus - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2013-12-22] FF Extension: COMPUTERBILD-Abzockschutz - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\Extensions\{d49175b3-3fd8-43b8-b28e-da5d47f3c398} [2013-12-22] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010-05-20] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010-09-02] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2010-10-23] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2011-01-06] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-03-31] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2011-08-09] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-10-05] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-21] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} [2013-02-15] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-06-11] FF HKLM\...\Firefox\Extensions: [termtutor@termtutor.com] - C:\Program Files\Mozilla Firefox\extensions\termtutor@termtutor.com FF HKCU\...\Thunderbird\Extensions: [{380AE6CB-09B9-4373-B360-D01C2462A6E7}] - C:\program files\bullguard ltd\bullguard\backup\thunderbirdbkplugin FF HKCU\...\Thunderbird\Extensions: [{0E810812-F4BB-4309-942A-755587587A5E}] - C:\Program Files\BullGuard Ltd\BullGuard\antispam\tbspamfilter FF Extension: No Name - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\extensions\faststartff@gmail.com [Not Found] FF Extension: No Name - C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gh5sdnyo.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [Not Found] Chrome: ======= CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll No File CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.290.11) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Picasa) - C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.) CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Profile: C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (YouTube) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-19] CHR Extension: (Google Search) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-19] CHR Extension: (Google Wallet) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29] CHR Extension: (Browser+ Apps+) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\okhbpnfiofnpilolnjeebnidmkopeeda [2014-09-17] CHR Extension: (Gmail) - C:\Users\XXX\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-19] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [805112 2014-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [994552 2014-10-01] (Avira Operations GmbH & Co. KG) S3 Browser7Maintenance; C:\Program Files\Browser 7 Maintenance Service\maintenanceservice.exe [118584 2014-09-13] (Deutsche Telekom AG) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2008-10-16] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [135168 2008-03-25] (Hewlett-Packard Co.) [File not signed] S3 MyOSProtect; C:\Program Files\PCTRunner\MyOSProtect.exe [1317096 2014-09-01] (MyOSCompany) [File not signed] R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed] R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed] R2 RichVideo; C:\Program Files\Cyberlink\Shared files\RichVideo.exe [241734 2008-06-28] () [File not signed] S3 usnjsvc; C:\Program Files\Windows Live\Messenger\usnsvc.exe [98328 2007-10-18] (Microsoft Corporation) S3 WLSetupSvc; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [266240 2007-10-25] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 ahcix86s; C:\Windows\System32\DRIVERS\ahcix86s.sys [183312 2008-10-03] (Advanced Micro Devices, Inc) R0 amdide; C:\Windows\System32\DRIVERS\amdide.sys [10632 2007-10-12] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-29] (Avira Operations GmbH & Co. KG) S3 cxbu0wdm; C:\Windows\System32\DRIVERS\cxbu0wdm.sys [115712 2010-01-25] (HID Global Corporation) S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [554496 2007-09-21] (Ralink Technology Corp.) R1 pcwatch; C:\Windows\system32\Drivers\pcwatch.sys [19840 2014-09-01] () [File not signed] <==== ATTENTION R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [154272 2008-11-11] (Realtek Semiconductor Corp.) S3 s117bus; C:\Windows\System32\DRIVERS\s117bus.sys [82984 2007-06-25] (MCCI Corporation) S3 s117mdfl; C:\Windows\System32\DRIVERS\s117mdfl.sys [14888 2007-06-25] (MCCI Corporation) S3 s117mdm; C:\Windows\System32\DRIVERS\s117mdm.sys [108456 2007-06-25] (MCCI Corporation) S3 s117mgmt; C:\Windows\System32\DRIVERS\s117mgmt.sys [100264 2007-06-25] (MCCI Corporation) S3 s117nd5; C:\Windows\System32\DRIVERS\s117nd5.sys [22952 2007-06-25] (MCCI Corporation) S3 s117obex; C:\Windows\System32\DRIVERS\s117obex.sys [98344 2007-06-25] (MCCI Corporation) S3 s117unic; C:\Windows\System32\DRIVERS\s117unic.sys [98856 2007-06-25] (MCCI Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cleanhlp; \??\C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 Profos; \??\C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\profos.sys [X] S3 Trufos; \??\C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\trufos.sys [X] S1 ttnfd; system32\drivers\ttnfd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-12 20:51 - 2014-10-12 20:51 - 00854417 _____ () C:\Users\XXX\Desktop\SecurityCheck.exe 2014-10-09 14:58 - 2014-10-09 14:58 - 02347384 _____ (ESET) C:\Users\XXX\Desktop\esetsmartinstaller_deu.exe 2014-10-09 14:53 - 2014-10-09 14:53 - 00000000 ____D () C:\Users\XXX\AppData\Local\PackageAware 2014-10-05 00:54 - 2014-10-12 21:01 - 00000000 ____D () C:\Users\XXX\Desktop\FRST-OlderVersion 2014-10-05 00:50 - 2014-10-05 00:50 - 00001582 _____ () C:\Users\XXX\Desktop\JRT.txt 2014-10-05 00:45 - 2014-10-05 00:45 - 00000000 ____D () C:\Windows\ERUNT 2014-10-05 00:43 - 2014-10-05 00:43 - 01694116 _____ (Thisisu) C:\Users\XXX\Desktop\JRT.exe 2014-10-05 00:21 - 2014-10-05 00:32 - 00000000 ____D () C:\AdwCleaner 2014-10-05 00:20 - 2014-10-05 00:20 - 01375089 _____ () C:\Users\XXX\Desktop\AdwCleaner_3.311.exe 2014-10-05 00:16 - 2014-10-05 00:16 - 00000468 _____ () C:\Users\XXX\Desktop\MBAM.txt 2014-10-04 23:29 - 2014-10-05 00:15 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-04 23:28 - 2014-10-04 23:31 - 00000863 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-04 23:28 - 2014-10-04 23:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-04 23:27 - 2014-10-04 23:31 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-10-04 23:27 - 2014-10-04 23:27 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-04 23:27 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-10-04 23:27 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-10-04 23:27 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-10-04 23:26 - 2014-10-04 23:26 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\XXX\Desktop\mbam-setup-2.0.2.1012.exe 2014-10-03 13:33 - 2014-10-03 13:33 - 00018853 _____ () C:\ComboFix.txt 2014-10-03 13:03 - 2014-10-03 13:33 - 00000000 ____D () C:\Qoobox 2014-10-03 13:03 - 2014-10-03 13:31 - 00000000 ____D () C:\Windows\erdnt 2014-10-03 13:03 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-10-03 13:03 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-10-03 13:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-10-03 13:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-10-03 13:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-10-03 13:03 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-10-03 13:03 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-10-03 13:03 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-10-03 13:01 - 2014-10-03 13:01 - 05582981 ____R (Swearware) C:\Users\XXX\Desktop\ComboFix.exe 2014-10-03 12:53 - 2014-10-03 12:53 - 00001061 _____ () C:\Users\XXX\Desktop\Revo Uninstaller.lnk 2014-10-03 12:53 - 2014-10-03 12:53 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-10-03 12:52 - 2014-10-03 12:52 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\XXX\Desktop\revosetup95.exe 2014-10-02 16:10 - 2014-10-02 16:12 - 00050951 _____ () C:\Users\XXX\Desktop\Addition.txt 2014-10-02 16:09 - 2014-10-12 21:01 - 00026331 _____ () C:\Users\XXX\Desktop\FRST.txt 2014-10-02 16:09 - 2014-10-12 21:01 - 00000000 ____D () C:\FRST 2014-10-02 16:08 - 2014-10-12 21:01 - 01101824 _____ (Farbar) C:\Users\XXX\Desktop\FRST.exe 2014-10-02 15:15 - 2014-10-02 15:15 - 00015173 _____ () C:\Users\XXX\Desktop\hijackthis.log 2014-10-02 15:11 - 2014-10-02 15:12 - 00388608 _____ (Trend Micro Inc.) C:\Users\XXX\Desktop\test.com 2014-09-28 23:43 - 2014-09-25 13:57 - 06816184 _____ (TomTom International B.V.) C:\Users\XXX\Downloads\InstallMyDriveConnect_3_3_0_1756.exe 2014-09-25 07:00 - 2014-09-09 08:24 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-09-23 15:05 - 2014-09-23 15:06 - 00000000 ____D () C:\Users\XXX\Desktop\Zeugnisse_Scan Vati 2014-09-22 19:47 - 2014-09-25 13:50 - 00006914 _____ () C:\Windows\wininit.ini 2014-09-22 17:43 - 2014-09-25 13:50 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-09-22 17:42 - 2014-09-25 13:53 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2 2014-09-22 17:40 - 2014-09-22 17:41 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\XXX\Documents\spybot_27341.exe 2014-09-22 16:46 - 2014-09-22 16:46 - 03490448 _____ (tuneuppro.com ) C:\Users\XXX\Documents\setup.exe 2014-09-22 16:43 - 2014-09-22 16:43 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\Abelssoft 2014-09-22 16:43 - 2014-09-22 16:43 - 00000000 ____D () C:\Users\XXX\AppData\Local\Abelssoft 2014-09-22 16:43 - 2014-09-22 16:43 - 00000000 ____D () C:\ProgramData\XDMessagingv4 2014-09-22 16:42 - 2014-09-25 13:48 - 00000000 ____D () C:\Program Files\CHIP Updater 2014-09-22 16:42 - 2014-09-22 16:42 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\DesktopIconGoodgame 2014-09-22 16:41 - 2014-09-22 16:42 - 01101648 _____ () C:\Users\XXX\Documents\Emsisoft Anti Malware - CHIP-Installer.exe 2014-09-18 21:53 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\system32\dhRichClient3.dll 2014-09-18 21:53 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\system32\sqlite36_engine.dll 2014-09-18 21:51 - 2014-09-18 21:51 - 01101648 _____ () C:\Users\XXX\Documents\adblockplusie-1.2 - CHIP-Installer.exe 2014-09-18 21:18 - 2014-09-18 21:18 - 00000000 ____D () C:\Users\XXX\Downloads\fab14 2014-09-18 21:17 - 2014-09-18 21:17 - 00452038 _____ () C:\Users\XXX\Downloads\fab14.zip 2014-09-18 21:15 - 2014-09-18 21:16 - 01101648 _____ () C:\Users\XXX\Downloads\Firewall App Blocker FAB - CHIP-Installer.exe 2014-09-17 20:42 - 2014-09-01 20:29 - 00019840 _____ () C:\Windows\system32\Drivers\pcwatch.sys 2014-09-17 20:41 - 2014-09-01 20:28 - 00304776 _____ (MyOSCompany) C:\Windows\system32\MyOSProtect.dll 2014-09-17 20:40 - 2014-09-17 20:40 - 00000000 ____D () C:\Users\XXX\AppData\Local\com 2014-09-17 20:36 - 2014-10-02 15:01 - 00000000 ____D () C:\Program Files\PCTRunner 2014-09-17 20:28 - 2014-09-17 20:29 - 30419936 _____ (DVDVideoSoft Ltd. ) C:\Users\XXX\Downloads\FreeYouTubeToMP3Converter3.12.44.908.exe 2014-09-14 13:41 - 2014-09-14 13:41 - 00000000 ____D () C:\ProgramData\Telekom-Browser 7 ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-12 21:00 - 2008-12-10 17:30 - 00000438 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job 2014-10-12 20:51 - 2010-02-06 15:33 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-12 20:49 - 2009-06-10 18:54 - 01682957 _____ () C:\Windows\WindowsUpdate.log 2014-10-12 20:48 - 2012-08-22 10:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-12 20:30 - 2010-02-06 15:33 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-12 20:30 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-12 20:30 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-12 20:30 - 2006-11-02 14:47 - 00003744 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-12 20:28 - 2008-01-21 04:47 - 01070042 _____ () C:\Windows\PFRO.log 2014-10-09 21:05 - 2006-11-02 15:01 - 00032628 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-10-09 16:49 - 2006-11-02 12:33 - 01643318 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-10-09 15:02 - 2008-12-18 13:16 - 00058119 _____ () C:\Windows\setupact.log 2014-10-09 14:53 - 2011-06-16 14:17 - 00000000 ____D () C:\Program Files\TachoPlusFreeDriver 2014-10-05 00:31 - 2009-07-14 21:51 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-10-05 00:30 - 2009-06-11 22:37 - 00000000 ____D () C:\ProgramData\ICQ 2014-10-03 13:33 - 2006-11-02 13:18 - 00000000 __RHD () C:\Users\Default 2014-10-03 13:33 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public 2014-10-03 13:25 - 2006-11-02 12:23 - 00000215 _____ () C:\Windows\system.ini 2014-10-03 13:18 - 2009-06-10 19:03 - 00000000 ____D () C:\Users\XXX 2014-10-01 14:09 - 2012-12-07 09:38 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-10-01 14:09 - 2012-12-07 09:38 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-09-28 23:44 - 2013-12-06 21:20 - 00000000 ____D () C:\Program Files\MyDrive Connect 2014-09-26 14:25 - 2014-09-10 13:54 - 00000000 ____D () C:\Users\XXX\Desktop\Sims 2014-09-26 14:23 - 2014-09-05 15:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES 2014-09-26 14:20 - 2011-08-07 16:35 - 00000000 ____D () C:\Program Files\EA GAMES 2014-09-25 14:11 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\rescache 2014-09-25 07:05 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-09-24 14:48 - 2012-08-22 10:24 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-09-24 14:48 - 2012-08-22 10:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-09-23 13:27 - 2006-11-02 14:47 - 00375400 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-09-22 18:50 - 2014-09-10 13:54 - 00000000 ____D () C:\Users\XXX\Desktop\Praktikum XXX 2014-09-22 16:49 - 2009-06-10 19:04 - 00103912 _____ () C:\Users\XXX\AppData\Local\GDIPFONTCACHEV1.DAT 2014-09-17 22:11 - 2009-06-10 19:03 - 00000953 _____ () C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-09-17 22:04 - 2011-07-27 16:26 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\DVDVideoSoft 2014-09-15 09:27 - 2013-08-31 19:11 - 00000000 ____D () C:\Users\XXX\Desktop\Ordner XXX 2014-09-15 09:06 - 2009-10-05 15:04 - 00231568 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-09-14 17:01 - 2013-12-23 13:00 - 00000000 ____D () C:\Program Files\Browser 7 Maintenance Service 2014-09-14 13:41 - 2013-12-23 13:00 - 00000000 ____D () C:\Users\XXX\AppData\Roaming\Deutsche Telekom AG 2014-09-14 13:41 - 2013-12-23 13:00 - 00000000 ____D () C:\Program Files\Deutsche Telekom AG 2014-09-12 11:59 - 2011-06-19 09:59 - 00006836 _____ () C:\Users\XXX\AppData\Local\d3d9caps.dat Some content of TEMP: ==================== C:\Users\XXX\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-12 20:40 ==================== End Of Log ============================ --- --- --- |
13.10.2014, 14:46 | #14 |
/// the machine /// TB-Ausbilder | monitor.exe löschen Adobe und Firefox updaten. Revo Uninstaller - Download - Filepony damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.google.com/chrome/answer/3296214?hl=de Genau so mit dem Telekom Browser verfahren, diesen aber nicht mehr installieren. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Winsock: Catalog9 24 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) cmd: netsh winsock reset Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.10.2014, 11:18 | #15 |
| monitor.exe löschen Hallo schrauber, danke schon mal bis hierher. Ich bilde mir ein, der Computer läuft schon wieder schneller. Entschuldige bitte, dass es wieder so lange dauerte. Ich habe jetzt Chrome neu installiert über den Link den du mir gesendet hast und nicht zurückgesetzt, da ich das nicht in den Einstellungen gefunden habe, wie es im Link stand. Der Rest ist auch so erledigt. Hier der fixlog.txt: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 18-10-2014 01 Ran by XXX at 2014-10-19 12:11:15 Run:2 Running from C:\Users\XXX\Desktop Loaded Profile: XXX (Available profiles: XXX) Boot Mode: Normal ============================================== Content of fixlist: ***************** Winsock: Catalog9 24 C:\Windows\system32\MyOSProtect.dll [304776] (MyOSCompany) cmd: netsh winsock reset ***************** "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000024" => Error deleting key. The key could be protected. ========= netsh winsock reset ========= Zugriff verweigert ========= End of CMD: ========= ==== End of Fixlog ==== |