|
Plagegeister aller Art und deren Bekämpfung: explorer.exe fehlermeldungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
21.11.2014, 01:09 | #1 |
| explorer.exe fehlermeldung Hallo, liebe Helfer! Ich bin mir nicht sicher was das für eine fehlermeldung ist, sie nervt und macht mir sorgen, ansonsten funktioniert eigentlich alles nachdem ich sie schliesse... Ich habe von anfang an mozilla und habe mit windows explorer eigentlich nichts zu tun. In etwa zu der zeit, seitdem die fehlermeldung erscheint habe ich ein download von: gimp durchgeführt, vielleicht habe ich auch einfach nur die falsche version? Ich habe schritt 1. und 2. eurer anweisungen bei problemen befolgt, da ich aber nicht überreagieren möchte, sende ich euch die ergebnisse und mache erst mal nicht weiter... Vielen vielen Dank schon mal, wenn mir jemand weiterhelfen kann! Erst mal die Fehlermeldung: Problemsignatur: Problemereignisname: BEX Anwendungsname: explorer.exe Anwendungsversion: 6.1.7601.17514 Anwendungszeitstempel: 4ce796f3 Fehlermodulname: bho.dll_unloaded Fehlermodulversion: 0.0.0.0 Fehlermodulzeitstempel: 542bf70b Ausnahmeoffset: 078687c0 Ausnahmecode: c0000005 Ausnahmedaten: 00000008 Betriebsystemversion: 6.1.7601.2.1.0.768.3 Gebietsschema-ID: 1031 Zusatzinformation 1: 0a9e Zusatzinformation 2: 0a9e372d3b4ad19135b953a78882e789 Zusatzinformation 3: 0a9e Zusatzinformation 4: 0a9e372d3b4ad19135b953a78882e789 Lesen Sie unsere Datenschutzbestimmungen online: hxxp://go.microsoft.com/fwlink/?linkid=104288&clcid=0x0407 Wenn die Onlinedatenschutzbestimmungen nicht verfügbar sind, lesen Sie unsere Datenschutzbestimmungen offline: C:\Windows\system32\de-DE\erofflps.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-11-2014 Ran by chiefmaster (administrator) on NEWUSER-7B3SBCM on 21-11-2014 00:23:20 Running from C:\Users\chiefmaster\Downloads Loaded Profile: chiefmaster (Available profiles: chiefmaster) Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Panda Security) C:\Program Files\Panda USB Vaccine\USBVaccine.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe () C:\Users\chiefmaster\Downloads\Defogger.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = www.afb24.com HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA72B7D3880B5CF01 HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de SearchScopes: HKU\S-1-5-21-2244492678-1565340186-2046745813-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity SearchScopes: HKU\S-1-5-21-2244492678-1565340186-2046745813-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity BHO: No Name -> {0025320D-4D37-4C73-9A5C-0C28F04068A3} -> C:\Users\chiefmaster\AppData\LocalLow\IE-BHO\bho.dll () BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default FF DefaultSearchEngine: Ixquick HTTPS - Deutsch FF SelectedSearchEngine: Ixquick HTTPS - Deutsch FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF user.js: detected! => C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\user.js FF SearchPlugin: C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\searchplugins\ixquick-https---deutsch.xml FF Extension: Foxi Security - C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\Extensions\foxi@securitii-dhfjs.com [2014-11-01] FF Extension: Adblock Plus - C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-12] Chrome: ======= ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation) R2 WHService; C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe [628736 2014-10-15] () [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 b06diag; C:\Windows\system32\drivers\bxdiagx.sys [76840 2010-12-16] (Broadcom Corporation) S3 BFN7x86; C:\Windows\system32\drivers\Xeno7x86.sys [129640 2011-01-14] (Bigfoot Networks, Inc.) S3 BFNVis32; C:\Windows\system32\drivers\XenoVx86.sys [129640 2011-01-14] (Bigfoot Networks, Inc.) S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [150568 2012-02-22] (Broadcom Corporation) S3 bxois; C:\Windows\system32\drivers\bxois.sys [431144 2010-12-10] (Broadcom Corporation) R3 e1express; C:\Windows\System32\DRIVERS\e1e6232.sys [231640 2012-03-07] (Intel Corporation) S3 e36gbus; C:\Windows\system32\drivers\e36gbus.sys [285056 2009-06-30] (MCCI Corporation) S3 e36gmgmt; C:\Windows\system32\drivers\e36gmgmt.sys [357376 2009-06-30] (MCCI Corporation) S3 e36wgps; C:\Windows\system32\drivers\e36wgps.sys [82984 2009-07-10] (Ericsson AB) S3 ecnssndis; C:\Windows\System32\Drivers\wwanuss.sys [10240 2009-09-22] (Ericsson AB) S3 ecnssndisfltr; C:\Windows\System32\Drivers\wwanussf.sys [14848 2009-09-22] (Ericsson AB) S3 FUJ02B1; C:\Windows\system32\drivers\FUJ02B1.sys [5888 2006-11-01] (FUJITSU LIMITED) S3 GzTpHid; C:\Windows\system32\drivers\GzTpHid.sys [24576 2006-11-29] (GUNZE) S3 IFCoEMP; C:\Windows\system32\drivers\ifM60x32.sys [271120 2011-03-18] (Intel(R) Corporation) S3 IFCoEVB; C:\Windows\system32\drivers\ifP60X32.sys [62224 2011-03-18] (Intel(R) Corporation) S3 ioatdma1; C:\Windows\System32\Drivers\qd16032.sys [36552 2009-11-16] (Intel Corporation) S3 ioatdma2; C:\Windows\System32\Drivers\qd26032.sys [37576 2009-11-16] (Intel Corporation) S3 MEI; C:\Windows\system32\drivers\HECI.sys [40832 2008-06-26] (Intel Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation) R1 MpKsld861a995; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{73F06144-2B27-4273-A3AE-7CD1B3DA99D0}\MpKsld861a995.sys [39464 2014-11-20] (Microsoft Corporation) S3 risdpcie; C:\Windows\system32\drivers\risdpe86.sys [47616 2009-10-28] (REDC) S3 rixdpcie; C:\Windows\system32\drivers\rixdpe86.sys [38912 2009-09-28] (REDC) S3 wisdpen; C:\Windows\system32\drivers\wisdpen.sys [30888 2008-03-27] (Wacom Technology) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-21 00:23 - 2014-11-21 00:23 - 00008931 _____ () C:\Users\chiefmaster\Downloads\FRST.txt 2014-11-21 00:23 - 2014-11-21 00:23 - 00000000 ____D () C:\FRST 2014-11-21 00:22 - 2014-11-21 00:22 - 01108992 _____ (Farbar) C:\Users\chiefmaster\Downloads\FRST.exe 2014-11-21 00:21 - 2014-11-21 00:21 - 02117632 _____ (Farbar) C:\Users\chiefmaster\Downloads\FRST64.exe 2014-11-21 00:20 - 2014-11-21 00:20 - 00000484 _____ () C:\Users\chiefmaster\Downloads\defogger_disable.log 2014-11-21 00:20 - 2014-11-21 00:20 - 00000000 _____ () C:\Users\chiefmaster\defogger_reenable 2014-11-21 00:17 - 2014-11-21 00:17 - 00050477 _____ () C:\Users\chiefmaster\Downloads\Defogger.exe 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\ProgramData\Panda Security 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\Program Files\Panda USB Vaccine 2014-11-20 23:42 - 2014-11-20 23:42 - 00848856 _____ (Panda Security ) C:\Users\chiefmaster\Downloads\USBVaccineSetup.exe 2014-11-19 23:17 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-19 23:17 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-12 13:42 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-11-12 13:42 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-11-12 13:42 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-11-12 13:42 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-11-12 13:41 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-12 13:41 - 2014-10-14 02:56 - 00136632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-12 13:41 - 2014-10-14 02:50 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-12 13:41 - 2014-10-14 02:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-11-12 13:41 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-12 13:41 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-12 13:41 - 2014-10-10 01:45 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-12 13:41 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-11-11 11:50 - 2014-11-11 11:50 - 00633240 _____ () C:\Windows\Minidump\111114-23290-01.dmp 2014-11-03 10:09 - 2014-11-03 10:09 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\Apps\2.0 2014-11-03 01:13 - 2014-11-03 01:13 - 00003839 _____ () C:\Users\chiefmaster\AppData\Local\recently-used.xbel 2014-11-01 01:37 - 2014-11-01 01:37 - 00001059 _____ () C:\Users\chiefmaster\Desktop\GIMP 2.lnk 2014-11-01 01:17 - 2014-11-03 01:13 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\gtk-2.0 2014-11-01 01:17 - 2014-11-01 01:17 - 00000000 ____D () C:\Users\chiefmaster\.thumbnails 2014-11-01 01:15 - 2014-11-03 01:13 - 00000000 ____D () C:\Users\chiefmaster\.gimp-2.8 2014-11-01 01:15 - 2014-11-01 01:15 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\gegl-0.2 2014-11-01 01:15 - 2014-11-01 01:15 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\fontconfig 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 __SHD () C:\Users\chiefmaster\AppData\Local\EmieUserList 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 __SHD () C:\Users\chiefmaster\AppData\Local\EmieSiteList 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 ____D () C:\Users\chiefmaster\AppData\Roaming\WHService 2014-11-01 01:02 - 2014-11-01 01:14 - 00001059 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk 2014-11-01 01:02 - 2014-11-01 01:03 - 00000000 ____D () C:\Users\chiefmaster\AppData\Roaming\Security Systems 2014-11-01 00:59 - 2014-11-01 01:02 - 00000000 ____D () C:\Program Files\GIMP 2 2014-11-01 00:56 - 2014-11-01 00:57 - 00370512 _____ () C:\Users\chiefmaster\Downloads\SoftonicDownloader_fuer_gimp.exe 2014-11-01 00:55 - 2014-11-01 00:55 - 00009127 _____ () C:\Users\chiefmaster\Downloads\gimp-2.8.14-setup-1.exe.torrent 2014-10-31 00:31 - 2014-10-31 00:31 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-10-30 11:28 - 2014-10-30 11:28 - 04423680 _____ () C:\Users\chiefmaster\Downloads\werkpaedagogisches_Projekt2012.pps ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-21 00:20 - 2014-08-11 16:07 - 00000000 ____D () C:\Users\chiefmaster 2014-11-20 23:03 - 2014-08-04 09:51 - 01728358 _____ () C:\Windows\WindowsUpdate.log 2014-11-20 21:04 - 2010-11-20 22:01 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-20 19:50 - 2009-07-14 05:34 - 00025680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-20 19:50 - 2009-07-14 05:34 - 00025680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-20 19:43 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-20 19:43 - 2009-07-14 05:39 - 00038719 _____ () C:\Windows\setupact.log 2014-11-18 23:57 - 2014-08-12 16:02 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-11-18 23:57 - 2014-08-12 16:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-11-13 13:49 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2014-11-13 13:31 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-11-13 13:22 - 2009-07-14 05:33 - 00284480 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-13 13:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-11-13 13:04 - 2014-08-27 08:25 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-13 13:02 - 2014-08-27 08:25 - 100445232 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-11 11:50 - 2014-10-18 16:46 - 162284285 _____ () C:\Windows\MEMORY.DMP 2014-11-11 11:50 - 2014-10-18 16:46 - 00000000 ____D () C:\Windows\Minidump 2014-11-02 18:48 - 2014-08-11 17:23 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-11-01 01:11 - 2014-08-12 16:36 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\Adobe 2014-11-01 00:57 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public 2014-10-30 12:24 - 2014-08-04 09:59 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\chiefmaster\AppData\Local\Temp\Fx6_FF_IE_Setup-Stonic-German.exe C:\Users\chiefmaster\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-16 13:59 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-11-2014 Ran by chiefmaster at 2014-11-21 00:23:57 Running from C:\Users\chiefmaster\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.223 - Adobe Systems Incorporated) Adobe Reader XI (11.0.09) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated) Apple Application Support (HKLM\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{941B4CE7-3F5D-443E-A8B7-56A420D2EAFD}) (Version: 7.1.2.6 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Foxy Secure (HKLM\...\Foxy Secure) (Version: 6 - ) GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team) Intel(R) TV Wizard (HKLM\...\TVWiz) (Version: - Intel Corporation) iTunes (HKLM\...\{86D04316-F49A-4AF2-B3F1-A1E943886CE7}) (Version: 11.3.1.2 - Apple Inc.) Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 33.0.2 (x86 de) (HKLM\...\Mozilla Firefox 33.0.2 (x86 de)) (Version: 33.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) Mozilla Thunderbird 31.0 (x86 de) (HKLM\...\Mozilla Thunderbird 31.0 (x86 de)) (Version: 31.0 - Mozilla) OpenOffice 4.1.1 (HKLM\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) Panda USB Vaccine 1.0.1.4 (HKLM\...\{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1) (Version: - Panda Security) Skype™ 6.18 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.24.0 - Synaptics Incorporated) ThinkPad Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.64.00.00 - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 18-10-2014 15:57:22 Windows Update 18-10-2014 16:02:46 Installed Java 7 Update 71 23-10-2014 19:09:32 Windows Update 27-10-2014 21:42:40 Windows Update 31-10-2014 09:38:27 Windows Update 03-11-2014 21:23:22 Windows Update 05-11-2014 08:56:48 Windows Modules Installer 09-11-2014 14:30:25 Windows Update 13-11-2014 12:01:33 Windows Update 16-11-2014 12:16:48 Windows Update 19-11-2014 22:15:25 Windows Update 20-11-2014 16:49:32 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {03DB737B-EAB3-4BBB-AF08-8B6368F04EB8} - System32\Tasks\PandaUSBVaccine => C:\Program Files\Panda USB Vaccine\RunInteractiveWin.exe [2009-09-23] () (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Loaded Modules (whitelisted) ============= 2014-07-31 11:16 - 2014-07-31 11:16 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-07-31 11:16 - 2014-07-31 11:16 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-11-01 01:03 - 2014-10-15 08:10 - 00628736 _____ () C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe 2014-11-01 01:03 - 2014-11-01 01:03 - 00374272 _____ () C:\Users\chiefmaster\AppData\Roaming\WHService\sub\default.dll 2014-10-31 00:31 - 2014-10-31 00:31 - 03649648 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2014-11-21 00:17 - 2014-11-21 00:17 - 00050477 _____ () C:\Users\chiefmaster\Downloads\Defogger.exe ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-2244492678-1565340186-2046745813-500 - Administrator - Disabled) chiefmaster (S-1-5-21-2244492678-1565340186-2046745813-1000 - Administrator - Enabled) => C:\Users\chiefmaster Gast (S-1-5-21-2244492678-1565340186-2046745813-501 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/21/2014 00:08:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x078687c0 ID des fehlerhaften Prozesses: 0xd10 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (11/20/2014 08:40:04 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x06ee87c0 ID des fehlerhaften Prozesses: 0x77c Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/20/2014 08:38:30 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x06ee87c0 ID des fehlerhaften Prozesses: 0x77c Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/20/2014 07:45:05 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2014 06:22:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2014 00:47:45 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x060187c0 ID des fehlerhaften Prozesses: 0x3b0 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (11/19/2014 00:41:55 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x060787c0 ID des fehlerhaften Prozesses: 0x958 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (11/18/2014 11:55:56 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x075487c0 ID des fehlerhaften Prozesses: 0x624 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/18/2014 08:55:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2947561 Error: (11/18/2014 08:55:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2947561 System errors: ============= Error: (11/20/2014 07:43:20 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 20.11.2014 um 19:41:38 unerwartet heruntergefahren. Error: (11/20/2014 06:53:48 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Empfängerdienst erreicht. Error: (11/20/2014 06:53:47 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/20/2014 06:53:48 PM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1053ehRecvr-Service{D44CBB4F-743E-4818-8077-C47F666CA7EE} Error: (11/20/2014 06:53:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/20/2014 06:53:45 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/20/2014 06:53:45 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/20/2014 06:53:44 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/20/2014 06:53:43 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/20/2014 06:53:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Microsoft Office Sessions: ========================= Error: (11/21/2014 00:08:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.1.7601.175144ce796f3bho.dll_unloaded0.0.0.0542bf70bc0000005078687c0d1001d004f9c9741bc0C:\Windows\explorer.exebho.dll1a7c6674-710a-11e4-bbe0-001c251eafee Error: (11/20/2014 08:40:04 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.1.7601.175144ce796f3bho.dll_unloaded0.0.0.0542bf70bc000000506ee87c077c01d004f1e342dfa3C:\Windows\Explorer.EXEbho.dll05a62bd5-70ed-11e4-bbe0-001c251eafee Error: (11/20/2014 08:38:30 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.1.7601.175144ce796f3bho.dll_unloaded0.0.0.0542bf70bc000000506ee87c077c01d004f1e342dfa3C:\Windows\Explorer.EXEbho.dllcdb7826e-70ec-11e4-bbe0-001c251eafee Error: (11/20/2014 07:45:05 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2014 06:22:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2014 00:47:45 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.1.7601.175144ce796f3bho.dll_unloaded0.0.0.0542bf70bc0000005060187c03b001d003893e16dbadC:\Windows\explorer.exebho.dll75508192-7046-11e4-b831-001c251eafee Error: (11/19/2014 00:41:55 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.1.7601.175144ce796f3bho.dll_unloaded0.0.0.0542bf70bc0000005060787c095801d00382d6568c6fC:\Windows\explorer.exebho.dll7a7fab68-6f7c-11e4-b831-001c251eafee Error: (11/18/2014 11:55:56 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.1.7601.175144ce796f3bho.dll_unloaded0.0.0.0542bf70bc0000005075487c062401d00195844a0b94C:\Windows\Explorer.EXEbho.dll0d7e72af-6f76-11e4-b831-001c251eafee Error: (11/18/2014 08:55:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2947561 Error: (11/18/2014 08:55:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2947561 ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T7250 @ 2.00GHz Percentage of memory in use: 47% Total physical RAM: 2006.3 MB Available physical RAM: 1054.55 MB Total Pagefile: 4012.59 MB Available Pagefile: 2946.55 MB Total Virtual: 2047.88 MB Available Virtual: 1883.08 MB ==================== Drives ================================ Drive c: (Windows7) (Fixed) (Total:139.28 GB) (Free:107.7 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 532A7C54) Partition 1: (Active) - (Size=9.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=139.3 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Geändert von Ana Log (21.11.2014 um 01:25 Uhr) Grund: ergebnisse posten |
21.11.2014, 06:43 | #2 |
/// the machine /// TB-Ausbilder | explorer.exe fehlermeldung hi,
__________________Scan mit Combofix
__________________ |
21.11.2014, 14:16 | #3 |
| explorer.exe fehlermeldungCode:
ATTFilter ComboFix 14-11-18.01 - chiefmaster 21.11.2014 13:53:23.1.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.2006.1238 [GMT 1:00] ausgeführt von:: c:\users\chiefmaster\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} SP: Microsoft Security Essentials *Disabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2014-10-21 bis 2014-11-21 )))))))))))))))))))))))))))))) . . 2014-11-21 12:58 . 2014-11-21 12:58 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-11-21 12:43 . 2014-09-17 08:45 908840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D8B0CC88-2F65-43D3-84C5-7C73AF685EE1}\gapaengine.dll 2014-11-21 12:42 . 2014-11-02 04:17 8941456 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1B98DD8D-E34E-4EE1-92BC-6767DD9E76A1}\mpengine.dll 2014-11-20 23:23 . 2014-11-20 23:24 -------- d-----w- C:\FRST 2014-11-20 22:44 . 2014-11-20 22:44 -------- d-----w- c:\programdata\Panda Security 2014-11-20 22:44 . 2014-11-20 22:44 -------- d-----w- c:\program files\Panda USB Vaccine 2014-11-19 22:17 . 2014-11-11 02:44 186880 ----a-w- c:\windows\system32\pku2u.dll 2014-11-19 22:17 . 2014-11-11 02:44 550912 ----a-w- c:\windows\system32\kerberos.dll 2014-11-19 22:17 . 2014-11-02 04:17 8941456 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2014-11-12 12:42 . 2014-10-18 01:33 571904 ----a-w- c:\windows\system32\oleaut32.dll 2014-11-12 12:42 . 2014-08-12 01:36 701440 ----a-w- c:\windows\system32\IMJP10K.DLL 2014-11-12 12:42 . 2014-08-21 06:26 1237504 ----a-w- c:\windows\system32\msxml3.dll 2014-11-12 12:42 . 2014-08-21 06:23 2048 ----a-w- c:\windows\system32\msxml3r.dll 2014-11-12 12:42 . 2014-10-03 01:44 442880 ----a-w- c:\windows\system32\AUDIOKSE.dll 2014-11-12 12:42 . 2014-10-03 01:44 275968 ----a-w- c:\windows\system32\EncDump.dll 2014-11-12 12:42 . 2014-10-03 01:44 475136 ----a-w- c:\windows\system32\audiosrv.dll 2014-11-12 12:42 . 2014-10-03 01:44 374784 ----a-w- c:\windows\system32\AudioEng.dll 2014-11-12 12:42 . 2014-10-03 01:44 195584 ----a-w- c:\windows\system32\AudioSes.dll 2014-11-03 09:09 . 2014-11-03 09:09 -------- d-----w- c:\users\chiefmaster\AppData\Local\Apps 2014-11-01 00:17 . 2014-11-03 00:13 -------- d-----w- c:\users\chiefmaster\AppData\Local\gtk-2.0 2014-11-01 00:17 . 2014-11-01 00:17 -------- d-----w- c:\users\chiefmaster\.thumbnails 2014-11-01 00:15 . 2014-11-01 00:15 -------- d-----w- c:\users\chiefmaster\AppData\Local\fontconfig 2014-11-01 00:15 . 2014-11-03 00:13 -------- d-----w- c:\users\chiefmaster\.gimp-2.8 2014-11-01 00:15 . 2014-11-01 00:15 -------- d-----w- c:\users\chiefmaster\AppData\Local\gegl-0.2 2014-11-01 00:03 . 2014-11-01 00:03 -------- d-----w- c:\users\chiefmaster\AppData\Roaming\WHService 2014-11-01 00:03 . 2014-11-01 00:03 -------- d-sh--w- c:\users\chiefmaster\AppData\Local\EmieUserList 2014-11-01 00:03 . 2014-11-01 00:03 -------- d-sh--w- c:\users\chiefmaster\AppData\Local\EmieSiteList 2014-11-01 00:02 . 2014-11-01 00:03 -------- d-----w- c:\users\chiefmaster\AppData\Roaming\Security Systems 2014-10-31 23:59 . 2014-11-01 00:02 -------- d-----w- c:\program files\GIMP 2 2014-10-31 23:59 . 2014-10-31 23:59 -------- d-----w- c:\users\chiefmaster\AppData\Local\Programs . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-11-20 16:53 . 2014-09-06 00:25 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2014-11-19 22:07 . 2014-09-08 15:49 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2014-11-19 22:07 . 2014-09-08 15:49 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2014-11-18 22:57 . 2014-08-12 15:02 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2014-11-18 22:57 . 2014-08-12 15:02 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2014-11-16 13:09 . 2014-09-06 00:25 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2014-11-16 13:08 . 2014-09-06 00:25 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2014-11-04 19:42 . 2014-09-08 15:49 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2014-10-30 11:24 . 2014-08-04 08:59 229000 ------w- c:\windows\system32\MpSigStub.exe 2014-10-18 16:03 . 2014-10-18 16:03 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2014-09-17 08:45 . 2014-08-28 15:15 908840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2014-09-04 05:04 . 2014-10-15 10:26 372736 ----a-w- c:\windows\system32\rastls.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{0025320D-4D37-4C73-9A5C-0C28F04068A3}] 2014-10-01 14:47 2237952 ----a-w- c:\users\chiefmaster\AppData\LocalLow\IE-BHO\bho.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2014-08-01 152392] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-08-22 974432] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2014-09-26 271744] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2014-04-03 315008] R2 WHService;WHService;c:\users\chiefmaster\AppData\Roaming\WHService\wh.exe [2014-10-15 628736] R3 b06diag;Broadcom NetXtreme II Diag Driver;c:\windows\system32\drivers\bxdiagx.sys [2010-12-16 76840] R3 BFN7x86;Bigfoot Networks Killer Gaming Service;c:\windows\system32\drivers\Xeno7x86.sys [2011-01-14 129640] R3 BFNVis32;Bigfoot Networks Killer Gaming Service;c:\windows\system32\drivers\XenoVx86.sys [2011-01-14 129640] R3 bxfcoe;bxfcoe;c:\windows\system32\drivers\bxfcoe.sys [2012-02-22 150568] R3 bxois;bxois;c:\windows\system32\drivers\bxois.sys [2010-12-10 431144] R3 e36gbus;F3607gw Mobile Broadband Device driver (Win7);c:\windows\system32\drivers\e36gbus.sys [2009-06-30 285056] R3 e36gmgmt;F3607gw Mobile Broadband Device Management Drivers (Win7);c:\windows\system32\drivers\e36gmgmt.sys [2009-06-30 357376] R3 e36wgps;Mobile Broadband GPS Port;c:\windows\system32\drivers\e36wgps.sys [2009-07-10 82984] R3 ecnssndis;Service for enabling selective suspend to NDIS device;c:\windows\System32\Drivers\wwanuss.sys [2009-09-22 10240] R3 ecnssndisfltr;SSNDIS filter service;c:\windows\System32\Drivers\wwanussf.sys [2009-09-22 14848] R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\drivers\FUJ02E3.sys [2006-11-01 5632] R3 GzTpHid;Touch Panel Filter Driver;c:\windows\system32\drivers\GzTpHid.sys [2006-11-29 24576] R3 IFCoEMP;IFCoEMP;c:\windows\system32\drivers\ifM60x32.sys [2011-03-18 271120] R3 IFCoEVB;IFCoEVB;c:\windows\system32\drivers\ifP60X32.sys [2011-03-18 62224] R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd16032.sys [2009-11-16 36552] R3 ioatdma2;Intel(R) QuickData Technology device ver.2;c:\windows\System32\Drivers\qd26032.sys [2009-11-16 37576] R3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\drivers\HECI.sys [2008-06-26 40832] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 95920] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2014-08-22 288120] R3 rimspci;rimspci;c:\windows\system32\drivers\rimspe86.sys [2009-10-26 48640] R3 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [2009-10-28 47616] R3 rixdpcie;rixdpcie;c:\windows\system32\drivers\rixdpe86.sys [2009-09-28 38912] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] R3 wisdpen;Wacom Penabled MiniDriver;c:\windows\system32\drivers\wisdpen.sys [2008-03-27 30888] S3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504] . . . ------- Zusätzlicher Suchlauf ------- . uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\ FF - prefs.js: browser.search.selectedEngine - Ixquick HTTPS - Deutsch FF - user.js: extensions.blocklist.enabled - false FF - user.js: app.update.auto - false FF - user.js: security.mixed_content.block_active_content - false FF - user.js: security.mixed_content.block_display_content - false FF - user.js: app.update.staging.enabled - true FF - user.js: app.update.interval - 31536000 FF - user.js: app.update.idletime - 31536000 FF - user.js: browser.search.update - false FF - user.js: browser.search.update.interval - 31536000 FF - user.js: app.update.channel - default FF - user.js: extensions.getAddons.cache.enabled - false FF - user.js: app.update.download.backgroundInterval - 31536000 FF - user.js: browser.safebrowsing.appRepURL - . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files\Synaptics\SynTP\SynTPEnh.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-11-21 14:00:31 ComboFix-quarantined-files.txt 2014-11-21 13:00 . Vor Suchlauf: 7 Verzeichnis(se), 115.547.021.312 Bytes frei Nach Suchlauf: 9 Verzeichnis(se), 115.262.787.584 Bytes frei . - - End Of File - - 29E0442557A318A66655456CF770093E A36C5E4F47E84449FF07ED3517B43A31 Muß ich den Windows-Defender einschalten? Der will nämlich nicht, ich glaub ich hatte ihn aber vorher auch nicht aktiv... Vielen Dank, viele Grüße! |
22.11.2014, 12:06 | #4 |
/// the machine /// TB-Ausbilder | explorer.exe fehlermeldung Nö Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.11.2014, 13:14 | #5 |
| explorer.exe fehlermeldung hui, das ist ja ganz schön viel, ich dachte nicht daß es schon so schlimm ist, da alles einwandfrei funktioniert. Was hat mein rechner denn? Und muß ich mir Sorgen machen, daß ich seitdem schon mein bankkonto angeschaut habe? Also, ich mach mich dann gleich mal an die arbeit: nen drucker wär schön um diese wege besser befolgen zu können... Ehm, und meine Schutzsoftware ist das Antivirenprogramm? Lieben Dank und Gruß |
23.11.2014, 08:01 | #6 |
/// the machine /// TB-Ausbilder | explorer.exe fehlermeldung Schutzsoftware ist das Antivirenprogramm, genau. Mit den Tools entfernen wir nur bissl ADware.
__________________ --> explorer.exe fehlermeldung |
24.11.2014, 11:42 | #7 |
| explorer.exe fehlermeldung Richtig vermutet, rest folgt: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 24.11.2014 Suchlauf-Zeit: 09:54:10 Logdatei: mbam.txt Administrator: Ja Version: 2.00.3.1025 Malware Datenbank: v2014.11.24.04 Rootkit Datenbank: v2014.11.22.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: chiefmaster Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 317774 Verstrichene Zeit: 16 Min, 12 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert FRST Logfile: FRST Logfile: Code:
ATTFilter # AdwCleaner v4.102 - Bericht erstellt am 24/11/2014 um 11:09:46 # Aktualisiert 23/11/2014 von Xplode # Database : 2014-11-23.7 [Live] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : chiefmaster - NEWUSER-7B3SBCM # Gestartet von : C:\Users\chiefmaster\Downloads\AdwCleaner_4.102.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\chiefmaster\AppData\Roaming\Security Systems Datei Gelöscht : C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\invalidprefs.js Datei Gelöscht : C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\user.js ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Softonic ***** [ Browser ] ***** -\\ Internet Explorer v0.0.0.0 -\\ Mozilla Firefox v33.0.2 (x86 de) [7sn1yoe3.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.defaultenginename", "Ixquick hxxpS - Deutsch"); [7sn1yoe3.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.selectedEngine", "Ixquick hxxpS - Deutsch"); ************************* AdwCleaner[R0].txt - [1353 octets] - [24/11/2014 10:24:41] AdwCleaner[S0].txt - [1292 octets] - [24/11/2014 11:09:46] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1352 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.3.9 (11.15.2014:2) OS: Windows 7 Home Premium x86 Ran by chiefmaster on 24.11.2014 at 11:17:54,65 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\chiefmaster\AppData\Roaming\mozilla\firefox\profiles\7sn1yoe3.default\minidumps [9 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 24.11.2014 at 11:20:21,97 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-11-2014 Ran by chiefmaster (administrator) on NEWUSER-7B3SBCM on 24-11-2014 11:32:54 Running from C:\Users\chiefmaster\Downloads Loaded Profile: chiefmaster (Available profiles: chiefmaster) Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe () C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Panda Security) C:\Program Files\Panda USB Vaccine\USBVaccine.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA72B7D3880B5CF01 HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKU\S-1-5-21-2244492678-1565340186-2046745813-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity SearchScopes: HKU\S-1-5-21-2244492678-1565340186-2046745813-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity BHO: No Name -> {0025320D-4D37-4C73-9A5C-0C28F04068A3} -> C:\Users\chiefmaster\AppData\LocalLow\IE-BHO\bho.dll () BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default FF DefaultSearchEngine: Amazon.de FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\searchplugins\ixquick-https---deutsch.xml FF Extension: Foxi Security - C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\Extensions\foxi@securitii-dhfjs.com [2014-11-01] FF Extension: Adblock Plus - C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-12] Chrome: ======= ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation) R2 WHService; C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe [628736 2014-10-15] () [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 b06diag; C:\Windows\system32\drivers\bxdiagx.sys [76840 2010-12-16] (Broadcom Corporation) S3 BFN7x86; C:\Windows\system32\drivers\Xeno7x86.sys [129640 2011-01-14] (Bigfoot Networks, Inc.) S3 BFNVis32; C:\Windows\system32\drivers\XenoVx86.sys [129640 2011-01-14] (Bigfoot Networks, Inc.) S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [150568 2012-02-22] (Broadcom Corporation) S3 bxois; C:\Windows\system32\drivers\bxois.sys [431144 2010-12-10] (Broadcom Corporation) R3 e1express; C:\Windows\System32\DRIVERS\e1e6232.sys [231640 2012-03-07] (Intel Corporation) S3 e36gbus; C:\Windows\system32\drivers\e36gbus.sys [285056 2009-06-30] (MCCI Corporation) S3 e36gmgmt; C:\Windows\system32\drivers\e36gmgmt.sys [357376 2009-06-30] (MCCI Corporation) S3 e36wgps; C:\Windows\system32\drivers\e36wgps.sys [82984 2009-07-10] (Ericsson AB) S3 ecnssndis; C:\Windows\System32\Drivers\wwanuss.sys [10240 2009-09-22] (Ericsson AB) S3 ecnssndisfltr; C:\Windows\System32\Drivers\wwanussf.sys [14848 2009-09-22] (Ericsson AB) S3 FUJ02B1; C:\Windows\system32\drivers\FUJ02B1.sys [5888 2006-11-01] (FUJITSU LIMITED) S3 GzTpHid; C:\Windows\system32\drivers\GzTpHid.sys [24576 2006-11-29] (GUNZE) S3 IFCoEMP; C:\Windows\system32\drivers\ifM60x32.sys [271120 2011-03-18] (Intel(R) Corporation) S3 IFCoEVB; C:\Windows\system32\drivers\ifP60X32.sys [62224 2011-03-18] (Intel(R) Corporation) S3 ioatdma1; C:\Windows\System32\Drivers\qd16032.sys [36552 2009-11-16] (Intel Corporation) S3 ioatdma2; C:\Windows\System32\Drivers\qd26032.sys [37576 2009-11-16] (Intel Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2014-11-24] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation) S3 MEI; C:\Windows\system32\drivers\HECI.sys [40832 2008-06-26] (Intel Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation) S3 risdpcie; C:\Windows\system32\drivers\risdpe86.sys [47616 2009-10-28] (REDC) S3 rixdpcie; C:\Windows\system32\drivers\rixdpe86.sys [38912 2009-09-28] (REDC) S3 wisdpen; C:\Windows\system32\drivers\wisdpen.sys [30888 2008-03-27] (Wacom Technology) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\CHIEFM~1\AppData\Local\Temp\catchme.sys [X] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-24 11:32 - 2014-11-24 11:32 - 00000000 ____D () C:\Users\chiefmaster\Downloads\FRST-OlderVersion 2014-11-24 11:20 - 2014-11-24 11:20 - 00000768 _____ () C:\Users\chiefmaster\Desktop\JRT.txt 2014-11-24 11:17 - 2014-11-24 11:17 - 00000000 ____D () C:\Windows\ERUNT 2014-11-24 10:24 - 2014-11-24 11:09 - 00000000 ____D () C:\AdwCleaner 2014-11-24 10:23 - 2014-11-24 10:23 - 02148864 _____ () C:\Users\chiefmaster\Downloads\AdwCleaner_4.102.exe 2014-11-24 10:17 - 2014-11-24 10:17 - 00001484 _____ () C:\Users\chiefmaster\Desktop\mbam.txt 2014-11-24 09:53 - 2014-11-24 11:12 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-11-24 09:52 - 2014-11-24 09:52 - 00001072 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-11-24 09:52 - 2014-11-24 09:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-11-24 09:52 - 2014-11-24 09:52 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-11-24 09:52 - 2014-11-24 09:52 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-11-24 09:52 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-11-24 09:52 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-11-24 09:52 - 2014-10-01 11:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-11-24 09:47 - 2014-11-24 09:47 - 01707532 _____ (Thisisu) C:\Users\chiefmaster\Downloads\JRT.exe 2014-11-24 09:45 - 2014-11-24 09:46 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\chiefmaster\Downloads\mbam-setup-2.0.3.1025.exe 2014-11-21 14:08 - 2014-11-21 14:08 - 00011311 _____ () C:\Users\chiefmaster\Desktop\ComboFix.txt 2014-11-21 14:00 - 2014-11-21 14:00 - 00011311 _____ () C:\ComboFix.txt 2014-11-21 13:51 - 2014-11-21 14:00 - 00000000 ____D () C:\Qoobox 2014-11-21 13:51 - 2014-11-21 13:59 - 00000000 ____D () C:\Windows\erdnt 2014-11-21 13:51 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-11-21 13:51 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-11-21 13:51 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-11-21 13:42 - 2014-11-21 13:42 - 05598306 ____R (Swearware) C:\Users\chiefmaster\Downloads\ComboFix.exe 2014-11-21 00:23 - 2014-11-24 11:32 - 00009648 _____ () C:\Users\chiefmaster\Downloads\FRST.txt 2014-11-21 00:23 - 2014-11-24 11:32 - 00000000 ____D () C:\FRST 2014-11-21 00:23 - 2014-11-21 00:24 - 00016093 _____ () C:\Users\chiefmaster\Downloads\Addition.txt 2014-11-21 00:22 - 2014-11-24 11:32 - 01110016 _____ (Farbar) C:\Users\chiefmaster\Downloads\FRST.exe 2014-11-21 00:20 - 2014-11-21 00:20 - 00000484 _____ () C:\Users\chiefmaster\Downloads\defogger_disable.log 2014-11-21 00:20 - 2014-11-21 00:20 - 00000000 _____ () C:\Users\chiefmaster\defogger_reenable 2014-11-21 00:17 - 2014-11-21 00:17 - 00050477 _____ () C:\Users\chiefmaster\Downloads\Defogger.exe 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\ProgramData\Panda Security 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\Program Files\Panda USB Vaccine 2014-11-20 23:42 - 2014-11-20 23:42 - 00848856 _____ (Panda Security ) C:\Users\chiefmaster\Downloads\USBVaccineSetup.exe 2014-11-19 23:17 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-19 23:17 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-12 13:42 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-11-12 13:42 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-11-12 13:42 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-11-12 13:42 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-11-12 13:41 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-12 13:41 - 2014-10-14 02:56 - 00136632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-12 13:41 - 2014-10-14 02:50 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-12 13:41 - 2014-10-14 02:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-11-12 13:41 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-12 13:41 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-12 13:41 - 2014-10-10 01:45 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-12 13:41 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-11-11 11:50 - 2014-11-11 11:50 - 00633240 _____ () C:\Windows\Minidump\111114-23290-01.dmp 2014-11-03 10:09 - 2014-11-03 10:09 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\Apps\2.0 2014-11-03 01:13 - 2014-11-03 01:13 - 00003839 _____ () C:\Users\chiefmaster\AppData\Local\recently-used.xbel 2014-11-01 01:37 - 2014-11-01 01:37 - 00001059 _____ () C:\Users\chiefmaster\Desktop\GIMP 2.lnk 2014-11-01 01:17 - 2014-11-03 01:13 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\gtk-2.0 2014-11-01 01:17 - 2014-11-01 01:17 - 00000000 ____D () C:\Users\chiefmaster\.thumbnails 2014-11-01 01:15 - 2014-11-23 02:36 - 00000000 ____D () C:\Users\chiefmaster\.gimp-2.8 2014-11-01 01:15 - 2014-11-01 01:15 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\gegl-0.2 2014-11-01 01:15 - 2014-11-01 01:15 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\fontconfig 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 __SHD () C:\Users\chiefmaster\AppData\Local\EmieUserList 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 __SHD () C:\Users\chiefmaster\AppData\Local\EmieSiteList 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 ____D () C:\Users\chiefmaster\AppData\Roaming\WHService 2014-11-01 01:02 - 2014-11-01 01:14 - 00001059 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk 2014-11-01 00:59 - 2014-11-01 01:02 - 00000000 ____D () C:\Program Files\GIMP 2 2014-11-01 00:55 - 2014-11-01 00:55 - 00009127 _____ () C:\Users\chiefmaster\Downloads\gimp-2.8.14-setup-1.exe.torrent 2014-10-31 00:31 - 2014-10-31 00:31 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-10-30 11:28 - 2014-10-30 11:28 - 04423680 _____ () C:\Users\chiefmaster\Downloads\werkpaedagogisches_Projekt2012.pps ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-24 11:19 - 2009-07-14 05:34 - 00025680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-24 11:19 - 2009-07-14 05:34 - 00025680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-24 11:16 - 2010-11-20 22:01 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-24 11:15 - 2014-08-04 09:51 - 02026887 _____ () C:\Windows\WindowsUpdate.log 2014-11-24 11:11 - 2010-11-20 22:48 - 00009258 _____ () C:\Windows\PFRO.log 2014-11-24 11:11 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-24 11:11 - 2009-07-14 05:39 - 00038887 _____ () C:\Windows\setupact.log 2014-11-24 10:11 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\tracing 2014-11-21 14:00 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default 2014-11-21 14:00 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public 2014-11-21 13:58 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini 2014-11-21 00:20 - 2014-08-11 16:07 - 00000000 ____D () C:\Users\chiefmaster 2014-11-18 23:57 - 2014-08-12 16:02 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-11-18 23:57 - 2014-08-12 16:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-11-13 13:49 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2014-11-13 13:31 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-11-13 13:22 - 2009-07-14 05:33 - 00284480 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-13 13:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-11-13 13:04 - 2014-08-27 08:25 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-13 13:02 - 2014-08-27 08:25 - 100445232 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-11 11:50 - 2014-10-18 16:46 - 162284285 _____ () C:\Windows\MEMORY.DMP 2014-11-11 11:50 - 2014-10-18 16:46 - 00000000 ____D () C:\Windows\Minidump 2014-11-02 18:48 - 2014-08-11 17:23 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-11-01 01:11 - 2014-08-12 16:36 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\Adobe 2014-10-30 12:24 - 2014-08-04 09:59 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\chiefmaster\AppData\Local\Temp\Quarantine.exe C:\Users\chiefmaster\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-16 13:59 ==================== End Of Log ============================ --- --- --- Geändert von Ana Log (24.11.2014 um 11:39 Uhr) Grund: weiter |
25.11.2014, 09:29 | #8 |
/// the machine /// TB-Ausbilder | explorer.exe fehlermeldungESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
26.11.2014, 10:22 | #9 |
| explorer.exe fehlermeldungCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=39ae0670b926c44583c039bfd36afad3 # engine=21269 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-11-26 09:15:53 # local_time=2014-11-26 10:15:53 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Microsoft Security Essentials' # compatibility_mode=5895 16777213 100 100 6516106 111174557 0 0 # scanned=94700 # found=0 # cleaned=0 # scan_time=1410 Code:
ATTFilter Results of screen317's Security Check version 0.99.90 Windows 7 Service Pack 1 x86 (UAC is enabled) ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 71 Adobe Flash Player 15.0.0.239 Adobe Reader XI Mozilla Firefox (33.0.2) Mozilla Thunderbird (31.0.) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-11-2014 Ran by chiefmaster (administrator) on NEWUSER-7B3SBCM on 26-11-2014 10:34:27 Running from C:\Users\chiefmaster\Downloads Loaded Profile: chiefmaster (Available profiles: chiefmaster) Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe () C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe (Panda Security) C:\Program Files\Panda USB Vaccine\USBVaccine.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe () C:\Users\chiefmaster\Desktop\SecurityCheck.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA72B7D3880B5CF01 HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKU\S-1-5-21-2244492678-1565340186-2046745813-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity SearchScopes: HKU\S-1-5-21-2244492678-1565340186-2046745813-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity BHO: No Name -> {0025320D-4D37-4C73-9A5C-0C28F04068A3} -> C:\Users\chiefmaster\AppData\LocalLow\IE-BHO\bho.dll () BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default FF DefaultSearchEngine: Ixquick HTTPS - Deutsch FF SelectedSearchEngine: Ixquick HTTPS - Deutsch FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_239.dll () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\searchplugins\ixquick-https---deutsch.xml FF Extension: Foxi Security - C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\Extensions\foxi@securitii-dhfjs.com [2014-11-01] FF Extension: Adblock Plus - C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-12] Chrome: ======= ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation) R2 WHService; C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe [628736 2014-10-15] () [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 b06diag; C:\Windows\system32\drivers\bxdiagx.sys [76840 2010-12-16] (Broadcom Corporation) S3 BFN7x86; C:\Windows\system32\drivers\Xeno7x86.sys [129640 2011-01-14] (Bigfoot Networks, Inc.) S3 BFNVis32; C:\Windows\system32\drivers\XenoVx86.sys [129640 2011-01-14] (Bigfoot Networks, Inc.) S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [150568 2012-02-22] (Broadcom Corporation) S3 bxois; C:\Windows\system32\drivers\bxois.sys [431144 2010-12-10] (Broadcom Corporation) R3 e1express; C:\Windows\System32\DRIVERS\e1e6232.sys [231640 2012-03-07] (Intel Corporation) S3 e36gbus; C:\Windows\system32\drivers\e36gbus.sys [285056 2009-06-30] (MCCI Corporation) S3 e36gmgmt; C:\Windows\system32\drivers\e36gmgmt.sys [357376 2009-06-30] (MCCI Corporation) S3 e36wgps; C:\Windows\system32\drivers\e36wgps.sys [82984 2009-07-10] (Ericsson AB) S3 ecnssndis; C:\Windows\System32\Drivers\wwanuss.sys [10240 2009-09-22] (Ericsson AB) S3 ecnssndisfltr; C:\Windows\System32\Drivers\wwanussf.sys [14848 2009-09-22] (Ericsson AB) S3 FUJ02B1; C:\Windows\system32\drivers\FUJ02B1.sys [5888 2006-11-01] (FUJITSU LIMITED) S3 GzTpHid; C:\Windows\system32\drivers\GzTpHid.sys [24576 2006-11-29] (GUNZE) S3 IFCoEMP; C:\Windows\system32\drivers\ifM60x32.sys [271120 2011-03-18] (Intel(R) Corporation) S3 IFCoEVB; C:\Windows\system32\drivers\ifP60X32.sys [62224 2011-03-18] (Intel(R) Corporation) S3 ioatdma1; C:\Windows\System32\Drivers\qd16032.sys [36552 2009-11-16] (Intel Corporation) S3 ioatdma2; C:\Windows\System32\Drivers\qd26032.sys [37576 2009-11-16] (Intel Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2014-11-26] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation) S3 MEI; C:\Windows\system32\drivers\HECI.sys [40832 2008-06-26] (Intel Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation) S3 risdpcie; C:\Windows\system32\drivers\risdpe86.sys [47616 2009-10-28] (REDC) S3 rixdpcie; C:\Windows\system32\drivers\rixdpe86.sys [38912 2009-09-28] (REDC) S3 wisdpen; C:\Windows\system32\drivers\wisdpen.sys [30888 2008-03-27] (Wacom Technology) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\CHIEFM~1\AppData\Local\Temp\catchme.sys [X] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-26 09:45 - 2014-11-26 09:45 - 02347384 _____ (ESET) C:\Users\chiefmaster\Downloads\esetsmartinstaller_deu.exe 2014-11-26 09:45 - 2014-11-26 09:45 - 00854414 _____ () C:\Users\chiefmaster\Desktop\SecurityCheck.exe 2014-11-24 11:36 - 2014-11-24 11:36 - 00021499 _____ () C:\Users\chiefmaster\Desktop\FRST.txt 2014-11-24 11:32 - 2014-11-24 11:32 - 00000000 ____D () C:\Users\chiefmaster\Downloads\FRST-OlderVersion 2014-11-24 11:20 - 2014-11-24 11:20 - 00000768 _____ () C:\Users\chiefmaster\Desktop\JRT.txt 2014-11-24 11:17 - 2014-11-24 11:17 - 00000000 ____D () C:\Windows\ERUNT 2014-11-24 10:24 - 2014-11-24 11:09 - 00000000 ____D () C:\AdwCleaner 2014-11-24 10:23 - 2014-11-24 10:23 - 02148864 _____ () C:\Users\chiefmaster\Downloads\AdwCleaner_4.102.exe 2014-11-24 10:17 - 2014-11-24 10:17 - 00001484 _____ () C:\Users\chiefmaster\Desktop\mbam.txt 2014-11-24 09:53 - 2014-11-26 10:26 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-11-24 09:52 - 2014-11-24 09:52 - 00001072 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-11-24 09:52 - 2014-11-24 09:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-11-24 09:52 - 2014-11-24 09:52 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-11-24 09:52 - 2014-11-24 09:52 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-11-24 09:52 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-11-24 09:52 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-11-24 09:52 - 2014-10-01 11:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-11-24 09:47 - 2014-11-24 09:47 - 01707532 _____ (Thisisu) C:\Users\chiefmaster\Downloads\JRT.exe 2014-11-24 09:45 - 2014-11-24 09:46 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\chiefmaster\Downloads\mbam-setup-2.0.3.1025.exe 2014-11-21 14:08 - 2014-11-21 14:08 - 00011311 _____ () C:\Users\chiefmaster\Desktop\ComboFix.txt 2014-11-21 14:00 - 2014-11-21 14:00 - 00011311 _____ () C:\ComboFix.txt 2014-11-21 13:51 - 2014-11-21 14:00 - 00000000 ____D () C:\Qoobox 2014-11-21 13:51 - 2014-11-21 13:59 - 00000000 ____D () C:\Windows\erdnt 2014-11-21 13:51 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-11-21 13:51 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-11-21 13:51 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-11-21 13:42 - 2014-11-21 13:42 - 05598306 ____R (Swearware) C:\Users\chiefmaster\Downloads\ComboFix.exe 2014-11-21 00:23 - 2014-11-26 10:34 - 00009763 _____ () C:\Users\chiefmaster\Downloads\FRST.txt 2014-11-21 00:23 - 2014-11-26 10:34 - 00000000 ____D () C:\FRST 2014-11-21 00:23 - 2014-11-21 00:24 - 00016093 _____ () C:\Users\chiefmaster\Downloads\Addition.txt 2014-11-21 00:22 - 2014-11-24 11:32 - 01110016 _____ (Farbar) C:\Users\chiefmaster\Downloads\FRST.exe 2014-11-21 00:20 - 2014-11-21 00:20 - 00000484 _____ () C:\Users\chiefmaster\Downloads\defogger_disable.log 2014-11-21 00:20 - 2014-11-21 00:20 - 00000000 _____ () C:\Users\chiefmaster\defogger_reenable 2014-11-21 00:17 - 2014-11-21 00:17 - 00050477 _____ () C:\Users\chiefmaster\Downloads\Defogger.exe 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\ProgramData\Panda Security 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\Program Files\Panda USB Vaccine 2014-11-20 23:42 - 2014-11-20 23:42 - 00848856 _____ (Panda Security ) C:\Users\chiefmaster\Downloads\USBVaccineSetup.exe 2014-11-19 23:17 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-19 23:17 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-12 13:42 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-11-12 13:42 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-11-12 13:42 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-11-12 13:42 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-11-12 13:41 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-12 13:41 - 2014-10-14 02:56 - 00136632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-12 13:41 - 2014-10-14 02:50 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-12 13:41 - 2014-10-14 02:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-11-12 13:41 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-12 13:41 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-12 13:41 - 2014-10-10 01:45 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-12 13:41 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-11-11 11:50 - 2014-11-11 11:50 - 00633240 _____ () C:\Windows\Minidump\111114-23290-01.dmp 2014-11-03 10:09 - 2014-11-03 10:09 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\Apps\2.0 2014-11-03 01:13 - 2014-11-03 01:13 - 00003839 _____ () C:\Users\chiefmaster\AppData\Local\recently-used.xbel 2014-11-01 01:37 - 2014-11-01 01:37 - 00001059 _____ () C:\Users\chiefmaster\Desktop\GIMP 2.lnk 2014-11-01 01:17 - 2014-11-03 01:13 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\gtk-2.0 2014-11-01 01:17 - 2014-11-01 01:17 - 00000000 ____D () C:\Users\chiefmaster\.thumbnails 2014-11-01 01:15 - 2014-11-23 02:36 - 00000000 ____D () C:\Users\chiefmaster\.gimp-2.8 2014-11-01 01:15 - 2014-11-01 01:15 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\gegl-0.2 2014-11-01 01:15 - 2014-11-01 01:15 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\fontconfig 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 __SHD () C:\Users\chiefmaster\AppData\Local\EmieUserList 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 __SHD () C:\Users\chiefmaster\AppData\Local\EmieSiteList 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 ____D () C:\Users\chiefmaster\AppData\Roaming\WHService 2014-11-01 01:02 - 2014-11-01 01:14 - 00001059 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk 2014-11-01 00:59 - 2014-11-01 01:02 - 00000000 ____D () C:\Program Files\GIMP 2 2014-11-01 00:55 - 2014-11-01 00:55 - 00009127 _____ () C:\Users\chiefmaster\Downloads\gimp-2.8.14-setup-1.exe.torrent 2014-10-31 00:31 - 2014-10-31 00:31 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-10-30 11:28 - 2014-10-30 11:28 - 04423680 _____ () C:\Users\chiefmaster\Downloads\werkpaedagogisches_Projekt2012.pps ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-26 10:32 - 2009-07-14 05:34 - 00025680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-26 10:32 - 2009-07-14 05:34 - 00025680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-26 10:30 - 2010-11-20 22:01 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-26 10:29 - 2014-08-04 09:51 - 01086871 _____ () C:\Windows\WindowsUpdate.log 2014-11-26 10:25 - 2010-11-20 22:48 - 00009878 _____ () C:\Windows\PFRO.log 2014-11-26 10:25 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-26 10:25 - 2009-07-14 05:39 - 00038943 _____ () C:\Windows\setupact.log 2014-11-26 00:42 - 2014-08-12 16:02 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-11-26 00:42 - 2014-08-12 16:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-11-24 10:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\tracing 2014-11-21 14:00 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default 2014-11-21 14:00 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public 2014-11-21 13:58 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini 2014-11-21 00:20 - 2014-08-11 16:07 - 00000000 ____D () C:\Users\chiefmaster 2014-11-13 13:49 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2014-11-13 13:31 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-11-13 13:22 - 2009-07-14 05:33 - 00284480 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-13 13:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-11-13 13:04 - 2014-08-27 08:25 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-13 13:02 - 2014-08-27 08:25 - 100445232 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-11 11:50 - 2014-10-18 16:46 - 162284285 _____ () C:\Windows\MEMORY.DMP 2014-11-11 11:50 - 2014-10-18 16:46 - 00000000 ____D () C:\Windows\Minidump 2014-11-02 18:48 - 2014-08-11 17:23 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-11-01 01:11 - 2014-08-12 16:36 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\Adobe 2014-10-30 12:24 - 2014-08-04 09:59 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\chiefmaster\AppData\Local\Temp\Quarantine.exe C:\Users\chiefmaster\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-16 13:59 ==================== End Of Log ============================ Hallo schrauber, leider erschien die fehlermeldung weiterhin... Liebe Grüße Anna Geändert von Ana Log (26.11.2014 um 10:40 Uhr) |
27.11.2014, 08:09 | #10 |
/// the machine /// TB-Ausbilder | explorer.exe fehlermeldung Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION BHO: No Name -> {0025320D-4D37-4C73-9A5C-0C28F04068A3} -> C:\Users\chiefmaster\AppData\LocalLow\IE-BHO\bho.dll () C:\Users\chiefmaster\AppData\LocalLow\IE-BHO\bho.dll Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.11.2014, 12:58 | #11 |
| explorer.exe fehlermeldungCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-11-2014 01 Ran by chiefmaster at 2014-11-27 11:08:10 Run:1 Running from C:\Users\chiefmaster\Desktop Loaded Profiles: chiefmaster & (Available profiles: chiefmaster) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION BHO: No Name -> {0025320D-4D37-4C73-9A5C-0C28F04068A3} -> C:\Users\chiefmaster\AppData\LocalLow\IE-BHO\bho.dll () C:\Users\chiefmaster\AppData\LocalLow\IE-BHO\bho.dll Emptytemp: ***************** "HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0025320D-4D37-4C73-9A5C-0C28F04068A3}" => Key deleted successfully. "HKCR\CLSID\{0025320D-4D37-4C73-9A5C-0C28F04068A3}" => Key deleted successfully. C:\Users\chiefmaster\AppData\LocalLow\IE-BHO\bho.dll => Moved successfully. EmptyTemp: => Removed 70.6 MB temporary data. The system needed a reboot. ==== End of Fixlog ==== Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=39ae0670b926c44583c039bfd36afad3 # engine=21290 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-11-27 11:23:32 # local_time=2014-11-27 12:23:32 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Microsoft Security Essentials' # compatibility_mode=5895 16777213 100 100 6610165 111268616 0 0 # scanned=104286 # found=0 # cleaned=0 # scan_time=1544 Code:
ATTFilter Results of screen317's Security Check version 0.99.90 Windows 7 Service Pack 1 x86 (UAC is enabled) ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 71 Adobe Flash Player 15.0.0.239 Adobe Reader XI Mozilla Firefox (33.0.2) Mozilla Thunderbird (31.0.) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-11-2014 01 Ran by chiefmaster (administrator) on NEWUSER-7B3SBCM on 27-11-2014 12:45:28 Running from C:\Users\chiefmaster\Desktop Loaded Profile: chiefmaster (Available profiles: chiefmaster) Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe (Panda Security) C:\Program Files\Panda USB Vaccine\USBVaccine.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2379504 2013-04-24] (Synaptics Incorporated) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA72B7D3880B5CF01 HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de SearchScopes: HKU\S-1-5-21-2244492678-1565340186-2046745813-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity SearchScopes: HKU\S-1-5-21-2244492678-1565340186-2046745813-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default FF DefaultSearchEngine: Ixquick HTTPS - Deutsch FF SelectedSearchEngine: Ixquick HTTPS - Deutsch FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_239.dll () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\searchplugins\ixquick-https---deutsch.xml FF Extension: Foxi Security - C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\Extensions\foxi@securitii-dhfjs.com [2014-11-01] FF Extension: Adblock Plus - C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-12] Chrome: ======= ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation) R2 WHService; C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe [628736 2014-10-15] () [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 b06diag; C:\Windows\system32\drivers\bxdiagx.sys [76840 2010-12-16] (Broadcom Corporation) S3 BFN7x86; C:\Windows\system32\drivers\Xeno7x86.sys [129640 2011-01-14] (Bigfoot Networks, Inc.) S3 BFNVis32; C:\Windows\system32\drivers\XenoVx86.sys [129640 2011-01-14] (Bigfoot Networks, Inc.) S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [150568 2012-02-22] (Broadcom Corporation) S3 bxois; C:\Windows\system32\drivers\bxois.sys [431144 2010-12-10] (Broadcom Corporation) R3 e1express; C:\Windows\System32\DRIVERS\e1e6232.sys [231640 2012-03-07] (Intel Corporation) S3 e36gbus; C:\Windows\system32\drivers\e36gbus.sys [285056 2009-06-30] (MCCI Corporation) S3 e36gmgmt; C:\Windows\system32\drivers\e36gmgmt.sys [357376 2009-06-30] (MCCI Corporation) S3 e36wgps; C:\Windows\system32\drivers\e36wgps.sys [82984 2009-07-10] (Ericsson AB) S3 ecnssndis; C:\Windows\System32\Drivers\wwanuss.sys [10240 2009-09-22] (Ericsson AB) S3 ecnssndisfltr; C:\Windows\System32\Drivers\wwanussf.sys [14848 2009-09-22] (Ericsson AB) S3 FUJ02B1; C:\Windows\system32\drivers\FUJ02B1.sys [5888 2006-11-01] (FUJITSU LIMITED) S3 GzTpHid; C:\Windows\system32\drivers\GzTpHid.sys [24576 2006-11-29] (GUNZE) S3 IFCoEMP; C:\Windows\system32\drivers\ifM60x32.sys [271120 2011-03-18] (Intel(R) Corporation) S3 IFCoEVB; C:\Windows\system32\drivers\ifP60X32.sys [62224 2011-03-18] (Intel(R) Corporation) S3 ioatdma1; C:\Windows\System32\Drivers\qd16032.sys [36552 2009-11-16] (Intel Corporation) S3 ioatdma2; C:\Windows\System32\Drivers\qd26032.sys [37576 2009-11-16] (Intel Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2014-11-27] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation) S3 MEI; C:\Windows\system32\drivers\HECI.sys [40832 2008-06-26] (Intel Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation) S3 risdpcie; C:\Windows\system32\drivers\risdpe86.sys [47616 2009-10-28] (REDC) S3 rixdpcie; C:\Windows\system32\drivers\rixdpe86.sys [38912 2009-09-28] (REDC) S3 wisdpen; C:\Windows\system32\drivers\wisdpen.sys [30888 2008-03-27] (Wacom Technology) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\CHIEFM~1\AppData\Local\Temp\catchme.sys [X] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-27 11:08 - 2014-11-27 11:08 - 00000000 ____D () C:\Users\chiefmaster\Desktop\FRST-OlderVersion 2014-11-26 23:09 - 2014-11-26 23:09 - 00013911 _____ () C:\Users\chiefmaster\Desktop\exe26.11.14.odt 2014-11-26 22:39 - 2014-11-26 22:39 - 00000000 ____D () C:\Program Files\Microsoft.NET 2014-11-26 22:31 - 2014-11-26 22:31 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2014-11-26 22:31 - 2014-11-26 22:31 - 00000000 ____D () C:\Program Files\Synaptics 2014-11-26 22:30 - 2014-11-26 22:30 - 00000000 ____D () C:\Program Files\AuthenTec 2014-11-26 22:21 - 2012-08-23 15:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-11-26 22:21 - 2012-08-23 15:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2014-11-26 22:21 - 2012-08-23 14:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-11-26 22:21 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2014-11-26 22:21 - 2012-08-23 11:08 - 02739712 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-11-26 22:20 - 2013-10-02 01:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-11-26 22:20 - 2013-10-02 01:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-11-26 22:20 - 2013-10-02 01:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-11-26 22:20 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-11-26 22:20 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-11-26 22:20 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-11-26 22:20 - 2013-10-02 00:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-11-26 22:20 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-11-26 22:20 - 2013-10-02 00:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-11-26 22:20 - 2013-10-01 23:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-11-26 22:20 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-11-26 22:20 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-11-26 22:06 - 2014-11-26 22:07 - 00000000 ____D () C:\d03fdc9d11b6c69571 2014-11-26 22:05 - 2014-11-26 22:05 - 00000000 ____D () C:\Windows\system32\x64 2014-11-26 22:05 - 2009-08-06 17:15 - 01002008 _____ (Intel Corporation) C:\Windows\system32\igxpun.exe 2014-11-26 22:04 - 2014-11-26 22:04 - 00000000 ____D () C:\Program Files\CONEXANT 2014-11-26 22:03 - 2014-06-27 02:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-11-26 22:02 - 2014-11-26 22:02 - 00000000 ____D () C:\Program Files\Analog Devices 2014-11-26 21:58 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-11-26 21:58 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-11-26 21:58 - 2013-08-28 01:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2014-11-26 21:58 - 2012-10-03 17:42 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2014-11-26 21:58 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2014-11-26 21:58 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2014-11-26 21:58 - 2012-10-03 17:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2014-11-26 21:58 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2014-11-26 21:58 - 2012-10-03 17:40 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2014-11-26 21:58 - 2012-10-03 16:21 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2014-11-26 21:58 - 2011-05-04 05:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2014-11-26 21:58 - 2011-05-04 05:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2014-11-26 21:58 - 2011-05-04 05:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2014-11-26 21:58 - 2011-05-04 05:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2014-11-26 21:58 - 2011-05-04 05:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2014-11-26 21:58 - 2011-05-04 05:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2014-11-26 21:58 - 2011-05-04 05:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2014-11-26 21:58 - 2011-05-04 05:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2014-11-26 21:58 - 2011-05-04 05:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2014-11-26 21:57 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-11-26 21:57 - 2014-09-25 02:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-11-26 21:57 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-11-26 21:57 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-11-26 21:57 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-11-26 21:57 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-11-26 21:57 - 2014-07-09 02:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-11-26 21:57 - 2014-07-08 23:30 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-11-26 21:57 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-11-26 21:57 - 2014-06-24 03:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-11-26 21:57 - 2014-02-04 03:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-11-26 21:57 - 2014-02-04 03:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-11-26 21:57 - 2014-02-04 03:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-11-26 21:57 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-11-26 21:57 - 2014-02-04 03:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-11-26 21:57 - 2014-01-28 03:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-11-26 21:57 - 2014-01-24 03:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-11-26 21:57 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-11-26 21:57 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2014-11-26 21:57 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2014-11-26 21:57 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2014-11-26 21:57 - 2013-08-05 02:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2014-11-26 21:57 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2014-11-26 21:57 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2014-11-26 21:57 - 2013-07-04 10:48 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2014-11-26 21:57 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2014-11-26 21:57 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2014-11-26 21:57 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2014-11-26 21:57 - 2011-06-16 05:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll 2014-11-26 21:57 - 2011-03-11 06:39 - 00143744 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys 2014-11-26 21:57 - 2011-03-11 06:39 - 00117120 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys 2014-11-26 21:57 - 2011-03-11 06:38 - 00332160 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys 2014-11-26 21:57 - 2011-03-11 06:38 - 00080256 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys 2014-11-26 21:57 - 2011-03-11 06:38 - 00022400 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys 2014-11-26 21:57 - 2011-03-11 06:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll 2014-11-26 21:57 - 2011-03-11 06:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe 2014-11-26 21:57 - 2011-03-11 05:01 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2014-11-26 21:57 - 2011-02-25 06:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2014-11-26 21:57 - 2011-02-18 06:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe 2014-11-26 21:56 - 2014-09-09 22:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-11-26 21:52 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-11-26 21:52 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-11-26 21:52 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-11-26 21:52 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-11-26 21:52 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-11-26 21:52 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-11-26 21:52 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-11-26 21:52 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-11-26 21:52 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-11-26 09:45 - 2014-11-26 09:45 - 02347384 _____ (ESET) C:\Users\chiefmaster\Desktop\esetsmartinstaller_deu.exe 2014-11-26 09:45 - 2014-11-26 09:45 - 00854414 _____ () C:\Users\chiefmaster\Desktop\SecurityCheck.exe 2014-11-24 11:36 - 2014-11-27 12:45 - 00010133 _____ () C:\Users\chiefmaster\Desktop\FRST.txt 2014-11-24 11:32 - 2014-11-24 11:32 - 00000000 ____D () C:\Users\chiefmaster\Downloads\FRST-OlderVersion 2014-11-24 11:20 - 2014-11-24 11:20 - 00000768 _____ () C:\Users\chiefmaster\Desktop\JRT.txt 2014-11-24 11:17 - 2014-11-24 11:17 - 00000000 ____D () C:\Windows\ERUNT 2014-11-24 10:24 - 2014-11-24 11:09 - 00000000 ____D () C:\AdwCleaner 2014-11-24 10:23 - 2014-11-24 10:23 - 02148864 _____ () C:\Users\chiefmaster\Downloads\AdwCleaner_4.102.exe 2014-11-24 10:17 - 2014-11-24 10:17 - 00001484 _____ () C:\Users\chiefmaster\Desktop\mbam.txt 2014-11-24 09:53 - 2014-11-27 11:10 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-11-24 09:52 - 2014-11-24 09:52 - 00001072 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-11-24 09:52 - 2014-11-24 09:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-11-24 09:52 - 2014-11-24 09:52 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-11-24 09:52 - 2014-11-24 09:52 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-11-24 09:52 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-11-24 09:52 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-11-24 09:52 - 2014-10-01 11:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-11-24 09:47 - 2014-11-24 09:47 - 01707532 _____ (Thisisu) C:\Users\chiefmaster\Downloads\JRT.exe 2014-11-24 09:45 - 2014-11-24 09:46 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\chiefmaster\Downloads\mbam-setup-2.0.3.1025.exe 2014-11-21 14:08 - 2014-11-21 14:08 - 00011311 _____ () C:\Users\chiefmaster\Desktop\ComboFix.txt 2014-11-21 14:00 - 2014-11-21 14:00 - 00011311 _____ () C:\ComboFix.txt 2014-11-21 13:51 - 2014-11-21 14:00 - 00000000 ____D () C:\Qoobox 2014-11-21 13:51 - 2014-11-21 13:59 - 00000000 ____D () C:\Windows\erdnt 2014-11-21 13:51 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-11-21 13:51 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-11-21 13:51 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-11-21 13:51 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-11-21 13:42 - 2014-11-21 13:42 - 05598306 ____R (Swearware) C:\Users\chiefmaster\Downloads\ComboFix.exe 2014-11-21 00:23 - 2014-11-27 12:45 - 00000000 ____D () C:\FRST 2014-11-21 00:23 - 2014-11-26 10:35 - 00021932 _____ () C:\Users\chiefmaster\Downloads\FRST.txt 2014-11-21 00:23 - 2014-11-21 00:24 - 00016093 _____ () C:\Users\chiefmaster\Downloads\Addition.txt 2014-11-21 00:22 - 2014-11-27 11:08 - 01109504 _____ (Farbar) C:\Users\chiefmaster\Desktop\FRST.exe 2014-11-21 00:20 - 2014-11-21 00:20 - 00000484 _____ () C:\Users\chiefmaster\Downloads\defogger_disable.log 2014-11-21 00:20 - 2014-11-21 00:20 - 00000000 _____ () C:\Users\chiefmaster\defogger_reenable 2014-11-21 00:17 - 2014-11-21 00:17 - 00050477 _____ () C:\Users\chiefmaster\Downloads\Defogger.exe 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\ProgramData\Panda Security 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\Program Files\Panda USB Vaccine 2014-11-20 23:42 - 2014-11-20 23:42 - 00848856 _____ (Panda Security ) C:\Users\chiefmaster\Downloads\USBVaccineSetup.exe 2014-11-19 23:17 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-19 23:17 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-14 05:36 - 2014-11-14 05:36 - 00074992 _____ (Lenovo.) C:\Windows\system32\ibmpmsvc.exe 2014-11-14 05:36 - 2014-11-14 05:36 - 00072432 _____ (Lenovo.) C:\Windows\system32\ibmpmctl.exe 2014-11-14 05:36 - 2014-11-14 05:36 - 00048208 _____ (Lenovo.) C:\Windows\system32\Drivers\ibmpmdrv.sys 2014-11-14 05:36 - 2014-11-14 05:36 - 00036592 _____ (Lenovo.) C:\Windows\system32\tpinspm.dll 2014-11-12 13:42 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-11-12 13:42 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-11-12 13:42 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-11-12 13:42 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-11-12 13:41 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-12 13:41 - 2014-10-14 02:56 - 00136632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-12 13:41 - 2014-10-14 02:50 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-12 13:41 - 2014-10-14 02:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-11-12 13:41 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-12 13:41 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-12 13:41 - 2014-10-10 01:45 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-12 13:41 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-11-11 11:50 - 2014-11-11 11:50 - 00633240 _____ () C:\Windows\Minidump\111114-23290-01.dmp 2014-11-03 10:09 - 2014-11-03 10:09 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\Apps\2.0 2014-11-03 01:13 - 2014-11-03 01:13 - 00003839 _____ () C:\Users\chiefmaster\AppData\Local\recently-used.xbel 2014-11-01 01:37 - 2014-11-01 01:37 - 00001059 _____ () C:\Users\chiefmaster\Desktop\GIMP 2.lnk 2014-11-01 01:17 - 2014-11-03 01:13 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\gtk-2.0 2014-11-01 01:17 - 2014-11-01 01:17 - 00000000 ____D () C:\Users\chiefmaster\.thumbnails 2014-11-01 01:15 - 2014-11-23 02:36 - 00000000 ____D () C:\Users\chiefmaster\.gimp-2.8 2014-11-01 01:15 - 2014-11-01 01:15 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\gegl-0.2 2014-11-01 01:15 - 2014-11-01 01:15 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\fontconfig 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 __SHD () C:\Users\chiefmaster\AppData\Local\EmieUserList 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 __SHD () C:\Users\chiefmaster\AppData\Local\EmieSiteList 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 ____D () C:\Users\chiefmaster\AppData\Roaming\WHService 2014-11-01 01:02 - 2014-11-01 01:14 - 00001059 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk 2014-11-01 00:59 - 2014-11-01 01:02 - 00000000 ____D () C:\Program Files\GIMP 2 2014-11-01 00:55 - 2014-11-01 00:55 - 00009127 _____ () C:\Users\chiefmaster\Downloads\gimp-2.8.14-setup-1.exe.torrent 2014-10-31 00:31 - 2014-10-31 00:31 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-10-30 11:28 - 2014-10-30 11:28 - 04423680 _____ () C:\Users\chiefmaster\Downloads\werkpaedagogisches_Projekt2012.pps ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-27 11:17 - 2010-11-20 22:01 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-27 11:17 - 2009-07-14 05:34 - 00025680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-27 11:17 - 2009-07-14 05:34 - 00025680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-27 11:14 - 2014-08-04 09:51 - 01878429 _____ () C:\Windows\WindowsUpdate.log 2014-11-27 11:10 - 2010-11-20 22:48 - 00010218 _____ () C:\Windows\PFRO.log 2014-11-27 11:10 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-27 11:10 - 2009-07-14 05:39 - 00042782 _____ () C:\Windows\setupact.log 2014-11-26 22:54 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-11-26 22:30 - 2009-07-14 05:52 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns 2014-11-26 22:25 - 2009-07-14 03:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-11-26 22:24 - 2009-07-14 05:33 - 00286688 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-26 22:23 - 2011-04-12 02:29 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE 2014-11-26 22:23 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-11-26 22:12 - 2014-08-11 16:11 - 00064024 _____ () C:\Users\chiefmaster\AppData\Local\GDIPFONTCACHEV1.DAT 2014-11-26 00:42 - 2014-08-12 16:02 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-11-26 00:42 - 2014-08-12 16:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-11-24 10:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\tracing 2014-11-21 14:00 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default 2014-11-21 14:00 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public 2014-11-21 13:58 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini 2014-11-21 00:20 - 2014-08-11 16:07 - 00000000 ____D () C:\Users\chiefmaster 2014-11-13 13:49 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2014-11-13 13:04 - 2014-08-27 08:25 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-13 13:02 - 2014-08-27 08:25 - 100445232 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-11 11:50 - 2014-10-18 16:46 - 162284285 _____ () C:\Windows\MEMORY.DMP 2014-11-11 11:50 - 2014-10-18 16:46 - 00000000 ____D () C:\Windows\Minidump 2014-11-02 18:48 - 2014-08-11 17:23 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-11-01 01:11 - 2014-08-12 16:36 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\Adobe 2014-10-30 12:24 - 2014-08-04 09:59 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-16 13:59 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 26-11-2014 01 Ran by chiefmaster at 2014-11-27 12:46:25 Running from C:\Users\chiefmaster\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated) Adobe Reader XI (11.0.09) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated) Apple Application Support (HKLM\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{941B4CE7-3F5D-443E-A8B7-56A420D2EAFD}) (Version: 7.1.2.6 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Foxy Secure (HKLM\...\Foxy Secure) (Version: 6 - ) <==== ATTENTION GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1867 - Intel Corporation) Intel(R) TV Wizard (HKLM\...\TVWiz) (Version: - Intel Corporation) iTunes (HKLM\...\{86D04316-F49A-4AF2-B3F1-A1E943886CE7}) (Version: 11.3.1.2 - Apple Inc.) Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle) Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.09.03 - ) Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 33.0.2 (x86 de) (HKLM\...\Mozilla Firefox 33.0.2 (x86 de)) (Version: 33.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) Mozilla Thunderbird 31.0 (x86 de) (HKLM\...\Mozilla Thunderbird 31.0 (x86 de)) (Version: 31.0 - Mozilla) OpenOffice 4.1.1 (HKLM\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) Panda USB Vaccine 1.0.1.4 (HKLM\...\{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1) (Version: - Panda Security) Skype™ 6.18 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.) ThinkPad Modem (HKLM\...\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10140588) (Version: 7.62.00 - ) ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.19.7 - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 03-11-2014 21:23:22 Windows Update 05-11-2014 08:56:48 Windows Modules Installer 09-11-2014 14:30:25 Windows Update 13-11-2014 12:01:33 Windows Update 16-11-2014 12:16:48 Windows Update 19-11-2014 22:15:25 Windows Update 20-11-2014 16:49:32 Windows Update 24-11-2014 08:52:00 Windows Update 26-11-2014 20:58:56 Windows Update 26-11-2014 21:19:05 Windows Update 26-11-2014 21:29:47 Windows Update 26-11-2014 21:36:32 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {03DB737B-EAB3-4BBB-AF08-8B6368F04EB8} - System32\Tasks\PandaUSBVaccine => C:\Program Files\Panda USB Vaccine\RunInteractiveWin.exe [2009-09-23] () (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Loaded Modules (whitelisted) ============= 2014-07-31 11:16 - 2014-07-31 11:16 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-07-31 11:16 - 2014-07-31 11:16 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-11-01 01:03 - 2014-10-15 08:10 - 00628736 _____ () C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe 2014-11-01 01:03 - 2014-11-01 01:03 - 00374272 _____ () C:\Users\chiefmaster\AppData\Roaming\WHService\sub\default.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-2244492678-1565340186-2046745813-500 - Administrator - Disabled) chiefmaster (S-1-5-21-2244492678-1565340186-2046745813-1000 - Administrator - Enabled) => C:\Users\chiefmaster Gast (S-1-5-21-2244492678-1565340186-2046745813-501 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/27/2014 11:12:04 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/26/2014 11:45:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x051e87c0 ID des fehlerhaften Prozesses: 0x31c Startzeit der fehlerhaften Anwendung: 0xExplorer.exe0 Pfad der fehlerhaften Anwendung: Explorer.exe1 Pfad des fehlerhaften Moduls: Explorer.exe2 Berichtskennung: Explorer.exe3 Error: (11/26/2014 11:05:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x05f787c0 ID des fehlerhaften Prozesses: 0x610 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/26/2014 11:05:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x05f787c0 ID des fehlerhaften Prozesses: 0x610 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/26/2014 11:00:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/26/2014 10:34:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/26/2014 10:25:55 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/26/2014 10:14:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x069787c0 ID des fehlerhaften Prozesses: 0xe68 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/26/2014 10:13:57 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x069787c0 ID des fehlerhaften Prozesses: 0xe68 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/26/2014 10:12:18 PM) (Source: Windows Search Service) (EventID: 1019) (User: ) Description: Die Liste der eingeschlossenen und ausgeschlossenen Adressen konnte vvon Windows Search nicht verarbeitet werden. Fehler: <30, 0x80040d07, "iehistory://{S-1-5-21-2244492678-1565340186-2046745813-1000}/">. System errors: ============= Error: (11/27/2014 11:07:55 AM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort1 gefunden. Error: (11/27/2014 11:04:15 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Empfängerdienst erreicht. Error: (11/27/2014 11:04:15 AM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1053ehRecvr-Service{D44CBB4F-743E-4818-8077-C47F666CA7EE} Error: (11/27/2014 11:04:14 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/27/2014 11:04:03 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/27/2014 11:04:03 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/27/2014 11:04:02 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/27/2014 11:04:02 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/27/2014 11:03:59 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/27/2014 11:03:54 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Microsoft Office Sessions: ========================= Error: (11/27/2014 11:12:04 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/26/2014 11:45:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.exe6.1.7601.175674d6727a7bho.dll_unloaded0.0.0.0542bf70bc0000005051e87c031c01d009c517c95340C:\Windows\Explorer.exebho.dlle37fed4c-75bd-11e4-b253-001c251eafee Error: (11/26/2014 11:05:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.1.7601.175674d6727a7bho.dll_unloaded0.0.0.0542bf70bc000000505f787c061001d009c4338370f1C:\Windows\Explorer.EXEbho.dll53c2424f-75b8-11e4-b253-001c251eafee Error: (11/26/2014 11:05:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.1.7601.175674d6727a7bho.dll_unloaded0.0.0.0542bf70bc000000505f787c061001d009c4338370f1C:\Windows\Explorer.EXEbho.dll444613bf-75b8-11e4-b253-001c251eafee Error: (11/26/2014 11:00:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/26/2014 10:34:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/26/2014 10:25:55 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/26/2014 10:14:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.1.7601.175674d6727a7bho.dll_unloaded0.0.0.0542bf70bc0000005069787c0e6801d009bd8827899eC:\Windows\Explorer.EXEbho.dll237e7460-75b1-11e4-8379-001c251eafee Error: (11/26/2014 10:13:57 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.1.7601.175674d6727a7bho.dll_unloaded0.0.0.0542bf70bc0000005069787c0e6801d009bd8827899eC:\Windows\Explorer.EXEbho.dll21d6bf6f-75b1-11e4-8379-001c251eafee Error: (11/26/2014 10:12:18 PM) (Source: Windows Search Service) (EventID: 1019) (User: ) Description: 300x80040d07iehistory://{S-1-5-21-2244492678-1565340186-2046745813-1000}/ ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T7250 @ 2.00GHz Percentage of memory in use: 42% Total physical RAM: 2006.3 MB Available physical RAM: 1156.63 MB Total Pagefile: 4012.59 MB Available Pagefile: 2965.43 MB Total Virtual: 2047.88 MB Available Virtual: 1917.58 MB ==================== Drives ================================ Drive c: (Windows7) (Fixed) (Total:139.28 GB) (Free:105.95 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 532A7C54) Partition 1: (Active) - (Size=9.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=139.3 GB) - (Type=07 NTFS) ==================== End Of Log ============================ So bis jetzt gabs ruhe!!! Vielen vielen Dank! Bin ich die Meldung nun los? Und soll ich gimp entfernen? |
28.11.2014, 08:42 | #12 |
/// the machine /// TB-Ausbilder | explorer.exe fehlermeldung Gimp kannste drauf lassen. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.11.2014, 11:40 | #13 |
| explorer.exe fehlermeldung Hier die kurze Rückmeldung, sieht gefühlt so sauber aus wie nie!!! Alles Gute, Anna |
29.11.2014, 09:27 | #14 |
/// the machine /// TB-Ausbilder | explorer.exe fehlermeldung Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu explorer.exe fehlermeldung |
c:\windows, device driver, download, durchgeführt, ergebnisse, erscheint, explorer.exe, fehlercode 0x5, fehlercode 0xc0000005, fehlercode windows, fehlermeldung, formation, funktioniert, panda usb vaccine, probleme, pup.optional.softonic, pup.optional.softonic.a, system32, verfügbar, weiterhelfen, windows, windows explorer |