|
Mülltonne: PUP.PSWTOOL.ProduktKey unter Malewarebytes gefundenWindows 7 Beiträge, die gegen unsere Regeln verstoßen haben, solche, die die Welt nicht braucht oder sonstiger Müll landet hier in der Mülltonne... |
05.10.2014, 16:07 | #1 |
| PUP.PSWTOOL.ProduktKey unter Malewarebytes gefunden Hallo, ich habe den Beitrag heute morgen schon geschrieben und Schrauber hat mir auch 1x geantwortet, aber nun ist der Beitrag verschwunden ??????? Deshalb das ganze nochmal :-) ich hoffe auf eure Hilfe und bedanke mich schon mal im voraus für euren Einsatz. Ich habe das Malewarebytes Program laufen lassen und er hat promt was in Quarantäne verschoben. Meine Frage ist, kann ich die alle problemlos löschen ohne das mein PC irgendwelche Nebenwirkungen bekommt und sind die dann auch ganz vom PC verschwunden oder muß ich noch was zusätzlich machen. Hier ist das was Maleware fand. Additional scan result of Farbar Recovery Scan Tool (x86) Version: 04-10-2014 01 Running from C:\Users\ Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.22beta (HKLM\...\7-Zip) (Version: - ) Adobe AIR (HKLM\...\Adobe AIR) (Version: 15.0.0.249 - Adobe Systems Incorporated) Adobe AIR (Version: 15.0.0.249 - Adobe Systems Incorporated) Hidden Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader XI (11.0.09) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated) Apple Application Support (HKLM\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Ashampoo Cover Studio 1.01 (HKLM\...\Ashampoo Cover Studio_is1) (Version: 1.0.1 - ashampoo GmbH & Co. KG) Ashampoo Photo Commander 11 (HKLM\...\{C92AB6F1-0F9C-8526-5DF1-0A2FD0FB33D9}_is1) (Version: 11.1.6 - Ashampoo GmbH & Co. KG) avast! Internet Security (HKLM\...\Avast) (Version: 9.0.2021 - AVAST Software) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden DHTML Editing Component (HKLM\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation) Dropbox (HKCU\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.) Fotogalerie (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Free Mp3 Wma Converter V 2.2 (HKLM\...\Free Mp3 Wma Converter_is1) (Version: 2.2.0.0 - Koyote Lab Inc.) Free MP4 Video Converter version 5.0.46.820 (HKLM\...\Free MP4 Video Converter_is1) (Version: 5.0.46.820 - DVDVideoSoft Ltd.) Garmin MapInstall (HKLM\...\{F0D44E64-51EE-4888-A1FD-F13108B75A43}) (Version: 4.0.4 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM\...\{ABA5E381-EC46-425C-86C5-5CD15BBFB4BF}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries) Google Update Helper (Version: 1.3.21.169 - Google Inc.) Hidden Haali Media Splitter (HKLM\...\HaaliMkx) (Version: - ) Java 8 Update 11 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218011FF}) (Version: 8.0.110 - Oracle Corporation) Java 8 Update 20 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218020F0}) (Version: 8.0.200 - Oracle Corporation) Java Auto Updater (Version: 2.8.20.26 - Oracle Corporation) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) MFC RunTime files (Version: 1.0.0 - Extensoft) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Movie Maker (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 32.0.3 (x86 de) (HKLM\...\Mozilla Firefox 32.0.3 (x86 de)) (Version: 32.0.3 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 32.0 - Mozilla) MPEG4E VFW - H.264/MPEG-4 AVC codec (remove only) (HKLM\...\MPEG4E) (Version: - ) MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (Version: 16.4.1108.0727 - Microsoft) Hidden MusicBee 2.4 (HKLM\...\MusicBee) (Version: 2.4 - Steven Mayall) MyFreeCodec (HKCU\...\MyFreeCodec) (Version: - ) NVIDIA 3D Vision Controller-Treiber 332.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 332.21 - NVIDIA Corporation) NVIDIA Grafiktreiber 332.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.21 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.151.1095 - NVIDIA Corporation) Hidden NVIDIA PhysX (Version: 9.13.0725 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation) NVIDIA Systemsteuerung 332.21 (Version: 332.21 - NVIDIA Corporation) Hidden OpenOffice 4.0.1 (HKLM\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) paint.net 4.0 Pre-Release (HKLM\...\{3F5F509B-E226-417C-8CD1-CAAE756C3289}) (Version: 4.0.0 - dotPDN LLC) Photo Gallery (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden QuickTime 7 (HKLM\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) SIW 2013 Home Edition (HKLM\...\{AB67580-257C-45FF-B8F4-C8C30682091A}_is1) (Version: 2013.05.14 - Topala Software Solutions) SurfMusik 3.1 (HKLM\...\SurfMusik 3.1_is1) (Version: 3.1 - Marcus Schmitt) SurfMusik 3.1a (HKLM\...\SurfMusik 3.1a_is1) (Version: 3.1a - Marcus Schmitt) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden T-Online 6.0 (HKLM\...\{B1275E23-717A-4D52-997A-1AD1E24BC7F3}) (Version: - ) TuneUp Utilities 2014 (de-DE) (Version: 14.0.1000.340 - TuneUp Software) Hidden TuneUp Utilities 2014 (HKLM\...\TuneUp Utilities) (Version: 14.0.1000.340 - TuneUp Software) TuneUp Utilities 2014 (Version: 14.0.1000.340 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2889914) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{F3F83933-75FC-4B60-84F2-3F8FA63D042E}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VLC media player 0.9.4 (HKLM\...\VLC media player) (Version: 0.9.4 - VideoLAN Team) Winamp (HKLM\...\Winamp) (Version: 5.666 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin) Windows Live Communications Platform (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows Live Essentials (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Photo Common (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live PIMT Platform (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live SOXE (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live UX Platform (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Writer (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Windows Live Writer Resources (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden WinRAR (HKLM\...\WinRAR archiver) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1561620852-2818437426-4211308335-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1561620852-2818437426-4211308335-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1561620852-2818437426-4211308335-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1561620852-2818437426-4211308335-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ==================== Restore Points ========================= 01-10-2014 06:58:57 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {03D313D3-2E84-45D7-947D-4CBD02560BEF} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {437F9675-AB7C-4CC5-A702-A624CC506376} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21] (Adobe Systems Incorporated) Task: {529380DD-1309-4F19-AF03-325778B75D17} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1561620852-2818437426-4211308335-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe Task: {5E33E131-59DC-4988-8BF7-79FB1F80DA2F} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1561620852-2818437426-4211308335-1000 => C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe Task: {77BB507F-ED6D-40BA-BBBC-8CE1FB423347} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-07-30] (Oracle Corporation) Task: {89B71518-50A6-4AE2-BC5F-562C34C5153E} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1561620852-2818437426-4211308335-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe Task: {971E3A99-36A6-451D-B435-8906B75A796F} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {ACEBB14A-0F82-405B-B696-AA3582C07403} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1561620852-2818437426-4211308335-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe Task: {BCE62E25-CA88-4CB7-98EA-B3E221B9DCB1} - System32\Tasks\Real Player-Online-Aktualisierungsprogramm => C:\Program Files\Real\RealPlayer\Update\realsched.exe Task: {D47C7638-8AFC-4D3C-927F-BF473AD664EB} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\TuneUp Utilities 2014\OneClick.exe [2014-07-16] (TuneUp Software) Task: {D6FEC2F8-32BA-4229-87F6-6E4CDB7824EF} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1561620852-2818437426-4211308335-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe Task: {E3FABCD1-ACC3-4D19-9340-B855212FF749} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10] (Adobe Systems Incorporated) Task: {F9A4541A-30B8-49E0-B6C1-B84AB63C6A62} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-07-05] (AVAST Software) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-11-09 07:14 - 2013-12-19 20:37 - 00107296 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll 2014-07-05 16:35 - 2014-07-05 16:35 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll 2014-10-05 07:48 - 2014-10-05 07:48 - 02859008 _____ () C:\Program Files\AVAST Software\Avast\defs\14100401\algo.dll 2014-10-05 12:29 - 2014-10-05 12:29 - 02859008 _____ () C:\Program Files\AVAST Software\Avast\defs\14100500\algo.dll 2014-07-05 16:35 - 2014-07-05 16:35 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2014-07-16 10:24 - 2014-07-16 10:24 - 00585528 _____ () C:\Program Files\TuneUp Utilities 2014\avgreplibx.dll 2014-05-10 11:08 - 2014-09-27 18:01 - 03715184 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Users\\Downloads\tune up Referenz-Nr_49073605_Zahlungsi_nformationen_f_r_Produkte_von_AV_G_Ecommerce_CY_Ltd.eml:OECustomProperty AlternateDataStreams: C:\Users\\Downloads\WG_Kleine_Freunde.eml:OECustomProperty AlternateDataStreams: C:\Users\\Documents\Janitos Rechnungsformular.jpeg:3or4kl4x13tuuug3Byamue2s4b AlternateDataStreams: C:\Users\\Documents\Janitos Rechnungsformular.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} AlternateDataStreams: C:\Users\\Documents\Rechn. für. Prof. Zahnr..jpeg:3or4kl4x13tuuug3Byamue2s4b AlternateDataStreams: C:\Users\\Documents\Rechn. für. Prof. Zahnr..jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: WinampAgent => "C:\Program Files\Winamp\winampa.exe" ========================= Accounts: ========================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (09/28/2014 06:48:28 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm winamp.exe, Version 5.6.6.3516 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: ec Startzeit: 01cfdad6f8750bd2 Endzeit: 63 Anwendungspfad: C:\Program Files\Winamp\winamp.exe Berichts-ID: a0850a75-46ca-11e4-adc9-0014856d7514 Error: (09/01/2014 06:30:04 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm MediaMonkey (non-skinned).exe, Version 4.1.4.1709 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: ee8 Startzeit: 01cfc5f0ae8bea56 Endzeit: 470 Anwendungspfad: C:\Program Files\MediaMonkey\MediaMonkey (non-skinned).exe Berichts-ID: a3314e3b-31f4-11e4-a4a9-0014856d7514 Error: (09/01/2014 06:09:42 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: OneClick.exe, Version: 14.0.1000.340, Zeitstempel: 0x53c63659 Name des fehlerhaften Moduls: ntrtl60.bpl, Version: 0.0.0.0, Zeitstempel: 0x53c63614 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002c020 ID des fehlerhaften Prozesses: 0xc20 Startzeit der fehlerhaften Anwendung: 0xOneClick.exe0 Pfad der fehlerhaften Anwendung: OneClick.exe1 Pfad des fehlerhaften Moduls: OneClick.exe2 Berichtskennung: OneClick.exe3 Error: (08/26/2014 07:10:28 AM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {2cbf20a5-cec2-49f3-b385-4445878dc675} Error: (08/25/2014 06:06:30 PM) (Source: NvStreamSvc) (EventID: 1) (User: ) Description: NvStreamSvcNetworkStreamService did not shut down when asked, terminating. [1813] Error: (08/24/2014 10:37:55 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm VideoConverter.exe, Version 1.0.0.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 11b8 Startzeit: 01cfbf75ce4f5bd1 Endzeit: 325 Anwendungspfad: C:\Program Files\Free Video Converter\VideoConverter.exe Berichts-ID: e4c80660-2b69-11e4-85fc-0014856d7514 Error: (08/24/2014 10:30:40 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm VideoConverter.exe, Version 1.0.0.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 16d8 Startzeit: 01cfbf725c5cb086 Endzeit: 253 Anwendungspfad: C:\Program Files\Free Video Converter\VideoConverter.exe Berichts-ID: dc48b38f-2b68-11e4-85fc-0014856d7514 Error: (08/23/2014 07:53:13 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm apc.exe, Version 1.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: c98 Startzeit: 01cfbefa5f2dc6cf Endzeit: 149 Anwendungspfad: C:\Program Files\Ashampoo\Ashampoo Photo Commander 11\apc.exe Berichts-ID: 4a67c62d-2aee-11e4-b7d4-0014856d7514 Error: (08/23/2014 07:33:28 PM) (Source: NvStreamSvc) (EventID: 1) (User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (08/21/2014 03:47:48 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm explorer.exe, Version 6.1.7601.17567 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 3d4 Startzeit: 01cfbd462608fdca Endzeit: 59312 Anwendungspfad: C:\Windows\explorer.exe Berichts-ID: 8d010479-2939-11e4-bd78-0014856d7514 System errors: ============= Error: (10/05/2014 09:22:49 AM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80004005 Error: (10/05/2014 07:47:36 AM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80004005 Error: (10/03/2014 04:40:30 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR5 gefunden. Error: (10/03/2014 04:40:27 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk7\DR7 gefunden. Error: (10/03/2014 04:40:25 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden. Error: (10/01/2014 02:02:16 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 01.10.2014 um 13:58:05 unerwartet heruntergefahren. Error: (09/30/2014 05:47:56 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst lmhosts erreicht. Error: (09/30/2014 08:25:47 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst TuneUp.UtilitiesSvc erreicht. Error: (09/29/2014 05:39:59 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80004005 Error: (09/29/2014 05:39:37 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1070 Microsoft Office Sessions: ========================= Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-10-2014 01 Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Windows\System32\FXSSVC.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (TuneUp Software) C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesApp32.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-11-09] (Microsoft Corporation) IFEO\AcroRd32.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\adobe air application installer.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\excel.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\express.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\groove.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\infopath.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\msaccess.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\msoxmled.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\mspub.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\mstore.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\nvstlink.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\nvstview.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\offdiag.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\ois.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\onenote.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\outlook.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\powerpnt.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\uninst.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" IFEO\winword.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe" ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/ SearchScopes: HKCU - DefaultScope {C6CBAD42-930C-4027-99A8-E54866EFB65F} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=e0efec4f0000000000000014856d7514&r=359 SearchScopes: HKCU - {C6CBAD42-930C-4027-99A8-E54866EFB65F} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=e0efec4f0000000000000014856d7514&r=359 BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Free Download Manager -> {CC59E0F9-7E43-44FA-9FAA-8377850BF205} -> No File Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default FF DefaultSearchEngine: Startpage HTTPS - Deutsch FF SelectedSearchEngine: Startpage HTTPS - Deutsch FF Homepage: www. FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @nullsoft.com/winampDetector;version=1 -> C:\Program Files\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll No File FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll No File FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF user.js: detected! => C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\user.js FF SearchPlugin: C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\searchplugins\google-maps.xml FF SearchPlugin: C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\searchplugins\startpage-https---deutsch.xml FF SearchPlugin: C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\searchplugins\startpage-ssl.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Wörterbuch Deutsch (de-DE), Hunspell-unterstützt - C:\Users\Koegel\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\Extensions\de_DE@dicts.j3e.de [2014-09-18] FF Extension: YouTube Unblocker - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\Extensions\youtubeunblocker@unblocker.yt [2014-04-05] FF Extension: Garmin Communicator - C:\Users\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-08-10] FF Extension: WOT - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26] FF Extension: Click to Play per-element - C:\Users\Koegel\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\Extensions\ClickToPlayPerElement@uaSad.addons.mozilla.org.xpi [2013-11-18] FF Extension: Ghostery - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\Extensions\firefox@ghostery.com.xpi [2014-04-27] FF Extension: Flagfox - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-08-27] FF Extension: ImTranslator - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2014-04-05] FF Extension: Adblock Plus - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-11-08] FF Extension: BetterPrivacy - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2014-08-27] FF Extension: QuickJava - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\Extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi [2014-05-12] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-11-26] FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKCU\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\9jmiqo3h.default\extensions\cliqz@cliqz.com Chrome: ======= CHR RestoreOnStartup: Default -> "hxxp://www.google.com/" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefi xUrl}{googleageClassification}sugkey={google:suggestAPIKeyParameter} CHR CustomProfile: C:\Users\\AppData\Local\Google\Chrome\User Data\default CHR Extension: (Docs) - C:\Users\\AppData\Local\Google\Chrome\User Data\default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-21] CHR Extension: (Google Drive) - C:\Users\\AppData\Local\Google\Chrome\User Data\default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-21] CHR Extension: (YouTube) - C:\Users\\AppData\Local\Google\Chrome\User Data\default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-21] CHR Extension: (Google-Suche) - C:\Users\\AppData\Local\Google\Chrome\User Data\default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-21] CHR Extension: (RealDownloader) - C:\Users\\AppData\Local\Google\Chrome\User Data\default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-12-21] CHR Extension: (Google Wallet) - C:\Users\\AppData\Local\Google\Chrome\User Data\default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-21] CHR Extension: (Google Mail) - C:\Users\\AppData\Local\Google\Chrome\User Data\default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-21] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-05] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-05] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [106488 2014-07-05] (AVAST Software) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe [1781048 2014-07-16] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-07-05] () R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [26136 2014-07-05] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-07-05] (AVAST Software) R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [270752 2014-07-05] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-07-05] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-07-05] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-07-05] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [414520 2014-07-05] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [71944 2014-07-05] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-07-05] () S3 k750bus; C:\Windows\System32\DRIVERS\k750bus.sys [55216 2005-02-11] (MCCI) R3 SrvHsfPCI; C:\Windows\System32\DRIVERS\VSTBS23.SYS [266752 2009-07-14] (Conexant Systems, Inc.) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesDriver32.sys [12320 2013-09-18] (TuneUp Software) S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-05 13:14 - 2014-10-05 13:15 - 00014423 _____ () C:\Users\Downloads\FRST.txt 2014-10-05 13:14 - 2014-10-05 13:14 - 00000000 ____D () C:\FRST 2014-10-05 13:12 - 2014-10-05 13:13 - 01100800 _____ (Farbar) C:\Users\\Downloads\FRST.exe 2014-10-05 10:15 - 2014-10-05 10:15 - 00011011 _____ () C:\Malewarebytes.txt 2014-10-05 08:26 - 2014-10-05 08:26 - 00001024 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-05 08:26 - 2014-10-05 08:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-05 08:25 - 2014-10-05 08:25 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-10-05 08:21 - 2014-10-05 08:22 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\\Downloads\mbam-setup-2.0.2.1012.exe 2014-10-04 19:57 - 2014-10-04 19:57 - 00014816 _____ () C:\Users\\Documents\Strom sparen am pc.odt 2014-10-04 16:47 - 2014-10-04 16:47 - 00115288 _____ () C:\Users\\AppData\Local\GDIPFONTCACHEV1.DAT 2014-10-04 09:10 - 2014-10-05 12:27 - 00007018 _____ () C:\Windows\PFRO.log 2014-10-04 09:10 - 2014-10-05 12:27 - 00000280 _____ () C:\Windows\setupact.log 2014-10-04 09:10 - 2014-10-04 09:10 - 00436552 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-04 09:10 - 2014-10-04 09:10 - 00000000 _____ () C:\Windows\setuperr.log 2014-10-01 08:58 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-09-28 13:28 - 2014-09-28 13:28 - 00000000 ____D () C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CdCoverCreator 2014-09-28 13:27 - 2014-09-28 13:27 - 02831657 _____ () C:\Users\\Downloads\CdCoverCreator-Setup-2.5.3_CB-DL-Manager [1].exe 2014-09-28 13:25 - 2014-09-28 13:25 - 00816064 _____ ( ) C:\Users\\Downloads\CdCoverCreator-Setup-2.5.3_CB-DL-Manager.exe 2014-09-28 07:49 - 2014-09-28 07:58 - 00185719 _____ () C:\Users\\Desktop\Test Cover.cedprj 2014-09-27 22:00 - 2014-09-27 22:00 - 00000000 ____D () C:\Users\\AppData\Roaming\Ashampoo Cover Studio 2014-09-27 21:59 - 2014-09-27 21:59 - 00001152 _____ () C:\Users\Public\Desktop\Ashampoo Cover Studio.lnk 2014-09-27 21:47 - 2014-09-27 21:47 - 17091736 _____ (ashampoo GmbH & Co. KG ) C:\Users\\Downloads\ashampoo_cover_studio_101_5870.exe 2014-09-27 20:07 - 2014-09-27 20:08 - 00000000 ____D () C:\Users\Koegel\Documents\für R 2014-09-24 16:59 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-09-21 10:59 - 2014-09-21 11:00 - 01508995 _____ () C:\Users\\Downloads\LAME3.99.5.zip 2014-09-21 10:03 - 2014-10-03 17:09 - 00000000 ____D () C:\Users\\AppData\Roaming\MusicBee 2014-09-21 10:01 - 2014-09-21 10:02 - 00000000 ____D () C:\Program Files\MusicBee 2014-09-21 10:01 - 2014-09-21 10:01 - 00000000 ____D () C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MusicBee 2014-09-21 10:00 - 2014-09-21 10:00 - 15526961 _____ () C:\Users\\Downloads\MusicBeeSetup_2_4_CB-DL-Manager [1].exe 2014-09-21 09:58 - 2014-09-21 09:58 - 00816064 _____ ( ) C:\Users\\Downloads\MusicBeeSetup_2_4_CB-DL-Manager.exe 2014-09-14 19:06 - 2014-09-21 10:02 - 00000929 _____ () C:\Users\Desktop\MusicBee.lnk 2014-09-14 19:05 - 2014-09-14 19:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicBee 2014-09-13 08:47 - 2014-09-13 08:47 - 00011863 _____ () C:\Users\\Documents\Einstellungen von Firefox und Apps.odt 2014-09-11 13:48 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-09-11 13:48 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-09-11 13:48 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-09-11 13:48 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-09-11 13:48 - 2014-08-18 23:57 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-09-11 13:48 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-09-11 13:48 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-09-11 13:48 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-09-11 13:48 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-09-11 13:48 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-09-11 13:48 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-09-11 13:48 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-09-11 13:48 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-09-11 13:48 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-09-11 13:48 - 2014-08-18 23:36 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-09-11 13:48 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-09-11 13:48 - 2014-08-18 23:30 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-09-11 13:48 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-09-11 13:48 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-09-11 13:48 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-09-11 13:48 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-09-11 13:48 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-09-11 13:48 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-09-11 13:48 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-09-11 13:48 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-09-11 13:48 - 2014-08-18 23:08 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-09-11 13:48 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-09-11 13:48 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-09-11 13:48 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-09-11 13:48 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-09-11 13:47 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-09-11 13:24 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-09-11 13:24 - 2014-07-07 03:40 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-09-11 13:24 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-09-11 13:24 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-09-11 13:21 - 2014-09-05 03:52 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-09-11 13:21 - 2014-09-05 03:47 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-09-07 18:32 - 2014-09-07 18:32 - 01101648 _____ () C:\Users\Downloads\Firefox - CHIP-Installer.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-05 13:06 - 2013-11-07 19:06 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-05 13:03 - 2009-07-14 06:34 - 00020800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-05 13:03 - 2009-07-14 06:34 - 00020800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-05 12:32 - 2013-11-07 11:33 - 02004287 _____ () C:\Windows\WindowsUpdate.log 2014-10-05 12:27 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-05 09:31 - 2014-06-12 20:08 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-05 09:20 - 2014-06-12 15:56 - 00000000 ____D () C:\Users\\AppData\Roaming\systweak 2014-10-03 16:41 - 2014-08-26 07:10 - 00000000 ____D () C:\Users\\AppData\Local\Windows Live 2014-09-28 06:17 - 2013-11-07 18:43 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-09-27 21:59 - 2014-02-19 13:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo 2014-09-27 21:59 - 2014-02-19 13:43 - 00000000 ____D () C:\Program Files\Ashampoo 2014-09-27 20:09 - 2013-12-22 19:32 - 00023040 _____ () C:\Users\\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-09-27 18:01 - 2014-05-10 11:08 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-09-27 10:33 - 2014-07-09 11:57 - 00000000 ____D () C:\Users\[CODE][/CODE\AppData\Roaming\MediaMonkey 2014-09-26 13:19 - 2013-11-07 11:42 - 01618600 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-24 17:01 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-09-22 21:16 - 2013-12-14 14:08 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-09-15 09:06 - 2009-10-14 04:21 - 00231568 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-09-13 18:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-09-12 15:51 - 2014-07-22 08:40 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR 2014-09-11 18:24 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-09-11 13:51 - 2013-11-07 11:47 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-09-11 13:47 - 2013-11-08 21:08 - 00000000 ____D () C:\Windows\system32\MRT 2014-09-11 13:40 - 2009-10-14 04:21 - 98758480 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-09-11 13:39 - 2014-05-06 07:05 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-09-10 19:08 - 2013-11-07 19:05 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-09-10 19:08 - 2013-11-07 19:05 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-09-07 21:57 - 2013-11-07 18:43 - 00001081 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-09-30 14:19 ==================== End Of Log ============================ muss auch noch dazu sagen, das mein PC ganz normal läuft und ich nur mal so das Malewarebytes habe laufen lassen. Vielleicht liegt`s am Adblock Plus das nichts schlimmeres passierte,oder sind das "Zecken" die mich nur auf andere Webseiten lenken wollten? Danke für eure Bemühungen |
05.10.2014, 16:27 | #2 |
/// the machine /// TB-Ausbilder | PUP.PSWTOOL.ProduktKey unter Malewarebytes gefunden dein Beitrag ist nicht verschwunden, vielleicht ist er auf Seite 2. Ich habe dein Thema noch in Arbeit.
__________________http://www.trojaner-board.de/159391-...roduktkey.html
__________________ |
Themen zu PUP.PSWTOOL.ProduktKey unter Malewarebytes gefunden |
antivirus, browser, converter, desktop, dvdvideosoft ltd., email, error, excel, failed, firefox, flash player, frage, free download, helper, home, homepage, internet, koyote, mp3, rundll, scan, security, server, software, svchost.exe, usb, windows, wma |