|
Plagegeister aller Art und deren Bekämpfung: Ständig Skriptfehler, PC extrem langsam und viel WerbungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
12.01.2015, 15:41 | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ständig Skriptfehler, PC extrem langsam und viel Werbung Adware/Junkware/Toolbars entfernen (alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!) 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
12.01.2015, 16:54 | #17 |
| Ständig Skriptfehler, PC extrem langsam und viel Werbung ok.
__________________Code:
ATTFilter # AdwCleaner v4.107 - Bericht erstellt am 12/01/2015 um 16:36:09 # Aktualisiert 07/01/2015 von Xplode # Database : 2015-01-11.2 [Live] # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Cristian - HOMEPC # Gestartet von : C:\Users\Cristian\Downloads\AdwCleaner_4.107.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : globalUpdatem ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Software Ordner Gelöscht : C:\ProgramData\NCH Software Ordner Gelöscht : C:\ProgramData\FineDealSooft Ordner Gelöscht : C:\ProgramData\FlashCouupon Ordner Gelöscht : C:\ProgramData\RoayalCoupon Ordner Gelöscht : C:\ProgramData\SOfftiCoup Ordner Gelöscht : C:\ProgramData\TicTaCooupon Ordner Gelöscht : C:\ProgramData\288c981542a19ae2 Ordner Gelöscht : C:\Program Files\globalUpdate Ordner Gelöscht : C:\Program Files\NCH Software Ordner Gelöscht : C:\Program Files\Optimizer Pro 3.13 Ordner Gelöscht : C:\Program Files\FineDealSooft Ordner Gelöscht : C:\Program Files\FlashCouupon Ordner Gelöscht : C:\Program Files\RoayalCoupon Ordner Gelöscht : C:\Program Files\SOfftiCoup Ordner Gelöscht : C:\Program Files\TicTaCooupon Ordner Gelöscht : C:\Program Files\Super Radio Ordner Gelöscht : C:\Users\Cristian\AppData\Local\globalUpdate Ordner Gelöscht : C:\Users\Cristian\AppData\Local\Super Radio Ordner Gelöscht : C:\Users\Cristian\AppData\LocalLow\HPAppData Ordner Gelöscht : C:\Users\Cristian\AppData\LocalLow\IE-BHO Ordner Gelöscht : C:\Users\Cristian\AppData\Roaming\NCH Software Ordner Gelöscht : C:\Users\Cristian\AppData\Roaming\RHEng Ordner Gelöscht : C:\Users\Cristian\Documents\Optimizer Pro Ordner Gelöscht : C:\Users\Cristian\AppData\Roaming\Mozilla\Firefox\Profiles\e0a8z0de.default-1420726666714\Extensions\15e4983dcabc4fb695007d519f551@fc04b380cf4e4a16aeb63aa224928b.com Ordner Gelöscht : C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf Ordner Gelöscht : C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn Ordner Gelöscht : C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Datei Gelöscht : C:\Users\Cristian\Favorites\Startfenster.lnk Datei Gelöscht : C:\Users\Cristian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Startfenster.lnk Datei Gelöscht : C:\Users\Cristian\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk Datei Gelöscht : C:\Users\Cristian\Desktop\Startfenster.lnk ***** [ Tasks ] ***** Task Gelöscht : globalUpdateUpdateTaskMachineCore Task Gelöscht : globalUpdateUpdateTaskMachineUA Task Gelöscht : 7eca1cd8-2a95-4759-9c0f-ae713062040a-1 Task Gelöscht : 7eca1cd8-2a95-4759-9c0f-ae713062040a-11 Task Gelöscht : 7eca1cd8-2a95-4759-9c0f-ae713062040a-4 Task Gelöscht : 7eca1cd8-2a95-4759-9c0f-ae713062040a-5 Task Gelöscht : 7eca1cd8-2a95-4759-9c0f-ae713062040a-5_user Task Gelöscht : 7eca1cd8-2a95-4759-9c0f-ae713062040a-6 Task Gelöscht : 7eca1cd8-2a95-4759-9c0f-ae713062040a-7 ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Cristian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10 Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4 Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search\ask.com Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SoftCoup.SoftCoup Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SoftCoup.SoftCoup.9 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\. Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\..9 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Pe2bb31ae_8747_4b4b_9c34_78a5967cc4a2_.Pe2bb31ae_8747_4b4b_9c34_78a5967cc4a2_ Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Pe2bb31ae_8747_4b4b_9c34_78a5967cc4a2_.Pe2bb31ae_8747_4b4b_9c34_78a5967cc4a2_.9 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A0B10EBE-4E51-4CAE-949B-E6B9E7D68CEA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{BB975E58-E769-4E5A-BA12-B765BC559FF3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F511AFDB-726E-4458-90E7-1ECB97406544} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4de0f743-11f0-4ec3-8ccb-cd09d2f01350} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5615f24a-ccd5-499d-9dd9-842177daa963} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ab0f484e-7442-4bd1-b4a6-4f7f70835382} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{dd3ecb4a-6cd0-46d0-8cde-cd981b0f3dbe} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{e2bb31ae-8747-4b4b-9c34-78a5967cc4a2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622792277} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0AFD55C8-ADF8-4A33-A6E1-DEDB7A36AEB4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6F43FA77-C18F-4D0C-9C7E-958876FE2061} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DF948646-8BF4-450E-A059-CF8A4E0FE2BE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E96B49B0-E11F-48FC-984A-EEC29A4F57E1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655795577} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666796677} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4de0f743-11f0-4ec3-8ccb-cd09d2f01350} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5615f24a-ccd5-499d-9dd9-842177daa963} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ab0f484e-7442-4bd1-b4a6-4f7f70835382} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{dd3ecb4a-6cd0-46d0-8cde-cd981b0f3dbe} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{e2bb31ae-8747-4b4b-9c34-78a5967cc4a2} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4de0f743-11f0-4ec3-8ccb-cd09d2f01350} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5615f24a-ccd5-499d-9dd9-842177daa963} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ab0f484e-7442-4bd1-b4a6-4f7f70835382} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{dd3ecb4a-6cd0-46d0-8cde-cd981b0f3dbe} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{e2bb31ae-8747-4b4b-9c34-78a5967cc4a2} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4de0f743-11f0-4ec3-8ccb-cd09d2f01350} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5615f24a-ccd5-499d-9dd9-842177daa963} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ab0f484e-7442-4bd1-b4a6-4f7f70835382} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{dd3ecb4a-6cd0-46d0-8cde-cd981b0f3dbe} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e2bb31ae-8747-4b4b-9c34-78a5967cc4a2} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{05fc21a7-ff7d-4052-ac4e-4ba8e26cf29c} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7e97aefd-8e9a-4497-978e-46afca1ac6d4} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{835f306e-84c9-485a-be52-eefe16276291} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{C424171E-592A-415A-9EB1-DFD6D95D3530}] Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1FCEDBEB-7F31-4795-9B72-B355E1A5B444} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{99039AFC-4C2F-4AA4-93C3-96192296CA29} Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\GlobalUpdate Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Optimizer Pro Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Super Radio Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate Schlüssel Gelöscht : HKLM\SOFTWARE\hdcode Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions Schlüssel Gelöscht : HKLM\SOFTWARE\Speedchecker Limited Schlüssel Gelöscht : HKLM\SOFTWARE\Super Radio Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B114619-78B7-1CFF-55EF-74266954F883} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7540FDBD-7FDC-30AE-3778-815CB87DBE46} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Super Radio Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Super Radio Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4 ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16599 -\\ Mozilla Firefox v34.0.5 (x86 de) [e0a8z0de.default-1420726666714\prefs.js] - Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M60E790E7-6B03-4F8B-84ED-A989B26B400A&SearchSource=55&CUI=&UM=8&UP=SPE607B2D3-84A5-4D83-96F3-35FAB[...] [e0a8z0de.default-1420726666714\prefs.js] - Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M60E790E7-6B03-4F8B-84ED-A989B26B400A&SearchSource=55&CUI=&UM=8&UP=SPE607B2D3-84A5-4D83-96F3[...] [e0a8z0de.default-1420726666714\prefs.js] - Zeile gelöscht : user_pref("extensions.a15e4983dcabc4fb695007d519f551fc04b380cf4e4a16aeb63aa224928bcom67977.67977.internaldb.Resources_meta.value", "%7B%22popup.html%22%3A%7B%22id%22%3A910720%2C%22ver%22%3A1%2C%22stat[...] [e0a8z0de.default-1420726666714\prefs.js] - Zeile gelöscht : user_pref("extensions.a15e4983dcabc4fb695007d519f551fc04b380cf4e4a16aeb63aa224928bcom67977.67977.internaldb.Resources_resource_910720.value", "%22%3C%21DOCTYPE%20html%3E%5Cr%5Cn%3Chtml%3E%5Cr%5Cn%3Che[...] [e0a8z0de.default-1420726666714\prefs.js] - Zeile gelöscht : user_pref("extensions.a15e4983dcabc4fb695007d519f551fc04b380cf4e4a16aeb63aa224928bcom67977.67977.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.[...] [e0a8z0de.default-1420726666714\prefs.js] - Zeile gelöscht : user_pref("extensions.crossrider.bic", "14add6eb9ff58f0eddc71d37bf241fd0"); -\\ Google Chrome v [C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.sm.de/?q={searchTerms} [C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.trovi.com/Results.aspx?q={searchTerms}&stype=Results&Suggest=&useHistory=0&UP=SPE607B2D3-84A5-4D83-96F3-35FAB7FDD3C9&isid=M60E790E7-6B03-4F8B-84ED-A989B26B400A&UM=8&SelfSearch=1&SearchType=SearchWeb&SearchSource=55&ctid=CT3322288&octid=EB_ORIGINAL_CTID [C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.trovi.com/Results.aspx?q={searchTerms}&stype=Results&Suggest=&useHistory=0&UP=SPE607B2D3-84A5-4D83-96F3-35FAB7FDD3C9&isid=M60E790E7-6B03-4F8B-84ED-A989B26B400A&UM=8&SelfSearch=1&SearchType=SearchWeb&SearchSource=55&ctid=CT3322288&octid=EB_ORIGINAL_CTID ************************* AdwCleaner[R0].txt - [17667 octets] - [12/01/2015 15:49:24] AdwCleaner[S0].txt - [17293 octets] - [12/01/2015 16:36:09] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [17354 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.1 (12.28.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by Cristian on 12.01.2015 at 16:45:45,69 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] "C:\Users\Cristian\favorites\links\startfenster.lnk" ~~~ Folders Successfully deleted: [Folder] "C:\Users\Cristian\AppData\Roaming\getrighttogo" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12.01.2015 at 16:48:02,47 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-01-2015 01 Ran by Cristian (administrator) on HOMEPC on 12-01-2015 16:49:33 Running from C:\Users\Cristian\Downloads Loaded Profile: Cristian (Available profiles: Cristian) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVM Berlin) C:\Program Files\avmwlanstick\WLanNetService.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe () C:\Windows\System32\PSIService.exe (Secunia) C:\Program Files\Secunia\PSI\psia.exe (Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe (OsdMaestro) C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe (AVM Berlin) C:\Program Files\avmwlanstick\WLanGUI.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe () C:\Users\Cristian\Desktop\CMS\EventLogger.exe (Evoluent) C:\Program Files\Evoluent\VMouse\V4\EvoMouseExec.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe (Hewlett-Packard Company) C:\hp\KBD\kbd.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Secunia) C:\Program Files\Secunia\PSI\sua.exe (Microsoft Corporation) C:\Windows\System32\sdclt.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Farbar) C:\Users\Cristian\Downloads\FRST(1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company) HKLM\...\Run: [KBD] => C:\HP\KBD\KbdStub.EXE [65536 2006-12-08] () HKLM\...\Run: [OsdMaestro] => C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [118784 2007-02-15] (OsdMaestro) HKLM\...\Run: [HP Health Check Scheduler] => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [71176 2007-05-24] (Hewlett-Packard) HKLM\...\Run: [SunJavaUpdateReg] => C:\Windows\system32\jureg.exe [54936 2007-04-07] (Sun Microsystems, Inc.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1848648 2009-07-07] (CANON INC.) HKLM\...\Run: [itype] => C:\Program Files\Microsoft IntelliType Pro\itype.exe [1505144 2009-11-05] (Microsoft Corporation) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [AVMWlanClient] => C:\Program Files\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-09-17] (Apple Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4669440 2007-07-06] (Realtek Semiconductor) HKLM\...\RunOnce: [Launcher] => C:\Windows\SMINST\launcher.exe [44168 2007-04-03] (soft thinks) HKLM\...\Policies\Explorer: [NoCDBurning] 0 HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKLM\...\Policies\Explorer: [NoSetTaskbar] 0 HKLM\...\Policies\Explorer: [NoDeletePrinter] 0 HKLM\...\Policies\Explorer: [NoDFSTab] 0 HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0 HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0 HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKLM\...\Policies\Explorer: [NoResolveSearch] 0 HKLM\...\Policies\Explorer: [NoHardwareTab] 0 HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-19\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-19\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-19\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-19\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-19\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-20\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-20\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-20\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-20\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-20\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-18\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoStartMenuSubFolders] 0 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\EventLogger.lnk ShortcutTarget: EventLogger.lnk -> C:\Users\Cristian\Desktop\CMS\EventLogger.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Evoluent Mouse Manager.lnk ShortcutTarget: Evoluent Mouse Manager.lnk -> C:\Windows\Installer\{AD6E0AE0-DADF-480E-82AE-4CDA6035D341}\_BBBCF44DDE3DA1E118ADB6.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia) Startup: C:\Users\Cristian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 2510 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 2510 series.lnk -> C:\Program Files\HP\HP Deskjet 2510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1772254487-8582296-1865665106-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/?LinkId=69157 HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://www.google.com HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://www.google.com HKU\S-1-5-21-1772254487-8582296-1865665106-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKU\S-1-5-21-1772254487-8582296-1865665106-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {0997A1DF-9518-4A18-A389-2C0497952326} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {56FB9A98-C2C7-4C40-8187-FD09EDBBBDE9} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {63250AB7-8D89-40E1-9345-055F753AAD3B} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {6B77EBF6-3C4A-4516-B673-30A5AF0C4C74} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {99039AFC-4C2F-4AA4-93C3-96192296CA29} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation) Toolbar: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {16BC6A51-9F62-49E3-9F96-C842EF2FFE3E} hxxp://www.eytronserver.com/CAB/WebPlayer.cab DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} hxxp://o.aolcdn.com/pictures/ap/Resources/v2.14/cab/aolpPlugins.10.6.0.8.cab DPF: {29DFBD41-3B7D-4368-9021-894C5A30E054} hxxp://www.eytronserver.com/CAB/RemoteWeb.cab DPF: {54CFC975-F9FB-45EB-8D18-D2D04FBC4299} hxxp://www.eytronserver.com/CAB/RemoteWeb2.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} hxxp://www.lokalisten.de/iup/ImageUploader4.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} hxxp://upload.lokalisten.de/iup/ImageUploader6.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab DPF: {BF5453EA-7EF7-4946-8421-8F002870A5ED} hxxp://eytronserver.com/CAB2/JMNVSClientWeb.cab DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab DPF: {CF1572D7-C2DB-456A-8F56-CFAAA4C79251} hxxp://www.eytronserver.com/CAB/WEB_BACKUP2.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} hxxp://www.lokalisten.de/iup/ImageUploader4.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Cristian\AppData\Roaming\Mozilla\Firefox\Profiles\e0a8z0de.default-1420726666714 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @innoplus.de/ino3DViewer -> C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll No File FF Plugin: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1772254487-8582296-1865665106-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-1772254487-8582296-1865665106-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-22] FF HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR HomePage: Default -> 76AE0F9BBB54349ABD7027A926874B88C59A5D426C2250D17C46099C70EDFD39 CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M60E790E7-6B03-4F8B-84ED-A989B26B400A&SearchSource=55&CUI=&UM=8&UP=SPE607B2D3-84A5-4D83-96F3-35FAB7FDD3C9&SSPV=" CHR Profile: C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-07] CHR Extension: (YouTube) - C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-07] CHR Extension: (Google-Suche) - C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-07] CHR Extension: (Google Wallet) - C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-15] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AVM WLAN Connection Service; C:\Program Files\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed] S2 c8ea8cd3; c:\Program Files\UpgradeStance\UpgradeStance.dll [2089984 2015-01-12] () [File not signed] R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [61440 2007-05-24] (Hewlett-Packard) [File not signed] R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed] S3 IDriverT; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed] R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed] R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1227800 2013-04-18] (Secunia) R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [659992 2013-04-18] (Secunia) S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2010-10-01] (AVM Berlin) [File not signed] R3 AVMWAN; C:\Windows\System32\DRIVERS\avmwan.sys [29968 2001-11-08] (AVM Berlin) [File not signed] R3 EvoMouseDriverFilterHidUsb; C:\Windows\System32\DRIVERS\EvoMouseDriverFilterHidUsb.sys [22712 2010-06-23] (Evoluent) R3 EvoMouseDriverMini; C:\Windows\System32\drivers\EvoMouseDriverMini.sys [20024 2010-06-23] () R3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [926080 2010-10-01] (AVM GmbH) S3 fxusbase; C:\Windows\System32\DRIVERS\fxusbase.sys [488656 2001-11-08] (AVM Berlin) [File not signed] S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [30464 2013-07-09] () S3 LFXACT; C:\Windows\System32\Drivers\LFXACT.sys [20672 2007-01-09] (OEM) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-04-18] (Secunia) R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2008-01-22] (Acronis) S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-01] (America Online, Inc.) S3 WlanUIG; C:\Windows\System32\DRIVERS\2862w.sys [346944 2004-04-06] (SMC Networks, Inc.) [File not signed] S3 XMLDIUSB; C:\Windows\System32\Drivers\XMLDIUSB.sys [31879 2007-01-09] (OEM) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] U0 SR; No ImagePath U2 srservice; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-12 16:49 - 2015-01-12 16:49 - 01115648 _____ (Farbar) C:\Users\Cristian\Downloads\FRST(1).exe 2015-01-12 16:48 - 2015-01-12 16:48 - 00000805 _____ () C:\Users\Cristian\Desktop\JRT.txt 2015-01-12 16:44 - 2015-01-12 16:44 - 01707939 _____ (Thisisu) C:\Users\Cristian\Downloads\JRT.exe 2015-01-12 15:49 - 2015-01-12 16:36 - 00000000 ____D () C:\AdwCleaner 2015-01-12 15:48 - 2015-01-12 15:49 - 02191360 _____ () C:\Users\Cristian\Downloads\AdwCleaner_4.107.exe 2015-01-12 15:34 - 2015-01-12 15:34 - 00022740 _____ () C:\ComboFix.txt 2015-01-12 15:09 - 2015-01-12 15:35 - 00000000 ____D () C:\ComboFix 2015-01-12 15:09 - 2015-01-12 15:34 - 00000000 ____D () C:\Qoobox 2015-01-12 15:09 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-01-12 15:09 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-01-12 15:09 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2015-01-12 15:08 - 2015-01-12 15:33 - 00000000 ____D () C:\Windows\erdnt 2015-01-12 15:08 - 2015-01-12 15:08 - 05609736 ____R (Swearware) C:\Users\Cristian\Downloads\ComboFix.exe 2015-01-12 14:21 - 2015-01-12 14:22 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-01-12 14:12 - 2015-01-12 14:12 - 00583256 _____ () C:\Users\Cristian\Downloads\Installation.exe 2015-01-12 13:33 - 2015-01-12 15:25 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2015-01-12 12:45 - 2015-01-12 12:45 - 16448208 _____ (Malwarebytes Corp.) C:\Users\Cristian\Downloads\mbar-1.08.2.1001(1).exe 2015-01-12 12:38 - 2015-01-12 14:37 - 00000000 ____D () C:\Users\Cristian\Desktop\mbar 2015-01-12 12:37 - 2015-01-12 12:37 - 16448208 _____ (Malwarebytes Corp.) C:\Users\Cristian\Downloads\mbar-1.08.2.1001.exe 2015-01-12 12:27 - 2015-01-12 12:27 - 00000159 _____ () C:\Users\Cristian\Desktop\Malwareprotokoll.txt 2015-01-12 12:06 - 2015-01-12 12:08 - 00048718 _____ () C:\Users\Cristian\Downloads\Addition.txt 2015-01-12 12:04 - 2015-01-12 16:49 - 00026266 _____ () C:\Users\Cristian\Downloads\FRST.txt 2015-01-12 12:04 - 2015-01-12 16:49 - 00000000 ____D () C:\FRST 2015-01-12 12:04 - 2015-01-12 12:04 - 01115648 _____ (Farbar) C:\Users\Cristian\Downloads\FRST.exe 2015-01-12 11:37 - 2015-01-12 11:37 - 00000000 ____D () C:\Program Files\UpgradeStance 2015-01-12 10:59 - 2015-01-12 11:07 - 00000000 ____D () C:\Users\Cristian\Desktop\Alle privaten Fotos 2015-01-05 22:32 - 2015-01-05 22:32 - 00000000 ____D () C:\ProgramData\dfhndngfkikbamohhepblbjlemgbjooa 2014-12-22 10:09 - 2014-12-22 10:09 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CdCoverCreator 2014-12-22 10:09 - 2014-12-22 10:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CdCoverCreator 2014-12-22 10:08 - 2015-01-12 11:26 - 00000000 ____D () C:\Program Files\CHIP Updater 2014-12-22 10:08 - 2014-12-22 10:09 - 00000000 ____D () C:\Users\Cristian\AppData\Local\Abelssoft 2014-12-22 10:08 - 2014-12-22 10:08 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\Abelssoft 2014-12-22 10:08 - 2014-12-22 10:08 - 00000000 ____D () C:\ProgramData\XDMessagingv4 2014-12-22 10:07 - 2014-12-22 10:07 - 01174352 _____ () C:\Users\Cristian\Downloads\CdCoverCreator - CHIP-Installer.exe 2014-12-17 15:25 - 2015-01-12 11:36 - 00000000 ____D () C:\ProgramData\Freemake 2014-12-17 15:25 - 2014-12-17 15:33 - 00000000 ____D () C:\Users\Cristian\Documents\Freemake 2014-12-17 14:53 - 2015-01-12 15:21 - 00000000 ____D () C:\Program Files\ef0ef932-01b1-473d-a940-2c3a15fc9957 2014-12-17 14:48 - 2014-12-17 14:48 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\TuneUp Software 2014-12-17 14:48 - 2014-12-17 14:48 - 00000000 ____D () C:\Users\Cristian\AppData\Local\TuneUp Software 2014-12-17 14:47 - 2014-12-18 11:02 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-12-17 14:47 - 2014-12-17 14:47 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-12-17 14:45 - 2015-01-12 10:15 - 00018872 _____ () C:\Windows\system32\Drivers\SPPD.sys 2014-12-17 14:18 - 2014-12-17 14:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo 2014-12-17 14:18 - 2014-12-17 14:31 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-12-17 14:18 - 2014-12-17 14:18 - 00000000 ____D () C:\Users\Cristian\AppData\Local\Ashampoo Movie Studio 2013 ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-12 16:39 - 2007-11-20 21:26 - 00000000 ____D () C:\Windows\SMINST 2015-01-12 16:38 - 2011-06-27 06:03 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-12 16:38 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-12 16:38 - 2006-11-02 13:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-12 16:38 - 2006-11-02 13:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-12 16:37 - 2012-05-30 20:08 - 00090796 _____ () C:\Windows\PFRO.log 2015-01-12 16:37 - 2012-05-28 10:17 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-01-12 16:37 - 2006-11-02 14:01 - 00032560 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-12 16:36 - 2013-07-04 20:41 - 00001101 _____ () C:\Users\Cristian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2015-01-12 16:36 - 2007-11-29 14:41 - 01710286 _____ () C:\Windows\WindowsUpdate.log 2015-01-12 15:34 - 2006-11-02 12:18 - 00000000 __RHD () C:\Users\Default 2015-01-12 15:34 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public 2015-01-12 15:28 - 2006-11-02 11:23 - 00000215 _____ () C:\Windows\system.ini 2015-01-12 15:24 - 2006-11-02 11:22 - 66584576 _____ () C:\Windows\system32\config\SYSTEM.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 65011712 _____ () C:\Windows\system32\config\SOFTWARE.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 55574528 _____ () C:\Windows\system32\config\COMPON~1.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\DEFAULT.bak 2015-01-12 15:21 - 2010-10-31 16:30 - 00000000 ____D () C:\Program Files\7-Zip 2015-01-12 14:16 - 2014-05-19 07:57 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-12 14:15 - 2014-05-19 07:56 - 00079576 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-12 14:09 - 2008-01-15 10:27 - 00111960 _____ () C:\Users\Cristian\AppData\Local\GDIPFONTCACHEV1.DAT 2015-01-12 14:08 - 2007-11-20 20:52 - 00000000 ____D () C:\Windows\system32\RTCOM 2015-01-12 14:06 - 2006-11-02 13:47 - 00410136 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-12 11:50 - 2007-11-20 20:56 - 00000000 ____D () C:\Program Files\Roxio 2015-01-12 11:50 - 2007-11-20 20:55 - 00000000 ____D () C:\Program Files\Common Files\Roxio Shared 2015-01-12 11:40 - 2007-11-20 20:52 - 00319456 _____ (Microsoft Corporation) C:\Windows\DIFxAPI.dll 2015-01-12 11:40 - 2007-11-20 20:52 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2015-01-12 11:38 - 2009-03-19 14:57 - 00000000 ____D () C:\Program Files\Sigel 2015-01-12 11:34 - 2011-08-20 20:06 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\DVDVideoSoft 2015-01-12 11:34 - 2011-08-20 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-01-12 11:30 - 2010-12-23 19:36 - 00000000 ____D () C:\Program Files\Canon 2015-01-12 11:29 - 2010-12-23 19:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities 2015-01-12 11:27 - 2014-09-22 08:21 - 00000000 ____D () C:\Program Files\dm 2015-01-12 11:26 - 2008-01-15 10:21 - 00000000 ____D () C:\Users\Cristian 2015-01-12 11:23 - 2014-09-21 17:01 - 00000000 ____D () C:\ProgramData\tmp 2015-01-12 11:06 - 2013-11-27 09:19 - 00000000 ____D () C:\Users\Cristian\Desktop\Reichwein 2015-01-12 11:05 - 2013-11-27 09:30 - 00000000 ____D () C:\Users\Cristian\Desktop\Scheidl 2015-01-12 11:03 - 2013-11-27 09:27 - 00000000 ____D () C:\Users\Cristian\Desktop\ZurbackstubnFotos 2015-01-06 04:36 - 2009-10-04 17:50 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-12-19 15:38 - 2008-01-22 13:33 - 00027136 _____ () C:\Users\Cristian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-12-18 13:04 - 2012-07-26 12:38 - 00005806 _____ () C:\Windows\setupact.log 2014-12-17 15:11 - 2010-10-26 12:03 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\vlc 2014-12-17 14:50 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Sidebar 2014-12-17 14:27 - 2009-06-06 17:49 - 00000000 ____D () C:\Users\Cristian\Documents\DVDVideoSoft Some content of TEMP: ==================== C:\Users\Cristian\AppData\Local\temp\Quarantine.exe C:\Users\Cristian\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-12 16:45 ==================== End Of Log ============================ |
12.01.2015, 19:03 | #18 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ständig Skriptfehler, PC extrem langsam und viel Werbung Zukünftig bitte beachten:
__________________Zitat:
Bitte alle Tools direkt auf den Desktop downloaden bzw. dorthin verschieben und vom Desktop starten, da unsere Anleitungen daraufhin ausgelegt sind. Zudem lassen sich dann am Ende der Bereinigung alle verwendeten Tools sehr einfach entfernen. Alle Tools bis zum Ende der Bereinigung auf dem Desktop lassen, evtl. benötigen wir manche öfter. Bitte auch ne neue Addition.txt erstellen, dazu FRST starten und einen Haken setzen bei Addition.txt, dann auf Scan klicken.
__________________ |
13.01.2015, 11:09 | #19 |
| Ständig Skriptfehler, PC extrem langsam und viel Werbung Hallo, ich habe sie gefunden unter Downloads und auf den Desktop geschoben. (ging automatisch unter Downloads) Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-01-2015 01 Ran by Cristian at 2015-01-13 11:07:25 Running from C:\Users\Cristian\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 32 Bit HP CIO Components Installer (Version: 1.0.0 - Hewlett-Packard) Hidden 3D-Viewer-innoplus (HKLM\...\{B96DB037-DBEA-4186-9081-9CBD537F82E8}) (Version: 13.01.07 - INNOVA-engineering GmbH) 4500_Help (Version: 1.00.0000 - Hewlett-Packard) Hidden 6300 (Version: 82.0.242.000 - Hewlett-Packard) Hidden 6300_Help (Version: 82.0.242.000 - Hewlett-Packard) Hidden 6300Trb (Version: 82.0.242.000 - Hewlett-Packard) Hidden 7-Zip 4.65 (HKLM\...\7-Zip) (Version: - ) ActiveCheck component for HP Active Support Library (Version: 3.0.0.2 - Hewlett-Packard) Hidden Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.8.0.1430 - Adobe Systems Incorporated) Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader X (10.1.13) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.13 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM\...\{0099B484-C24C-4D5F-8167-B0F6DF196E72}) (Version: 12.0.3.133 - Adobe Systems, Inc) Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.) AIO_CDB_ProductContext (Version: 82.0.242.000 - Hewlett-Packard) Hidden AIO_CDB_Software (Version: 82.0.242.000 - Hewlett-Packard) Hidden AIO_Scan (Version: 82.0.173.000 - Hewlett-Packard) Hidden Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{0592EF96-69D8-4E4B-9CC9-88F58EA86F01}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) AVM FRITZ!WLAN (HKLM\...\AVMWLANCLI) (Version: - AVM Berlin) BPD_HPSU (Version: 1.00.0000 - Hewlett-Packard) Hidden bpd_scan (Version: 3.00.0000 - Hewlett-Packard) Hidden BPDSoftware (Version: 50.0.165.000 - Hewlett-Packard) Hidden BPDSoftware_Ini (Version: 1.00.0000 - Hewlett-Packard) Hidden BufferChm (Version: 100.0.170.000 - Hewlett-Packard) Hidden Canon iP3600 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP3600_series) (Version: - ) Canon Utilities Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version: - ) Canon Utilities My Printer (HKLM\...\CanonMyPrinter) (Version: - ) Copy (Version: 82.0.188.000 - Hewlett-Packard) Hidden CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden Destination Component (Version: 100.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (Version: 100.0.190.000 - Hewlett-Packard) Hidden DHTML Editing Component (HKLM\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation) DocMgr (Version: 100.0.201.000 - Hewlett-Packard) Hidden DocProc (Version: 10.0.0.0 - Hewlett-Packard) Hidden Evoluent Mouse Manager (HKLM\...\{AD6E0AE0-DADF-480E-82AE-4CDA6035D341}) (Version: 4.0.0 - Evoluent) Fax (Version: 100.0.187.000 - Hewlett-Packard) Hidden Google Chrome (HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Google Chrome) (Version: 39.0.2171.65 - Google Inc.) Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden GPBaseService (Version: 100.0.187.000 - Hewlett-Packard) Hidden GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden HP Customer Experience Enhancements (HKLM\...\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}) (Version: 5.2.0.2296 - Hewlett-Packard) HP Customer Participation Program 10.0 (HKLM\...\HPExtendedCapabilities) (Version: 10.0 - HP) HP Deskjet 2510 series - Grundlegende Software für das Gerät (HKLM\...\{A3B40F90-312F-497B-A631-D0C7D37D7C59}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) HP Deskjet 2510 series Hilfe (HKLM\...\{07B48D2C-E60D-41E6-B546-11D128F633EC}) (Version: 27.0.0 - Hewlett Packard) HP Deskjet 2510 series Setup Guide (HKLM\...\{216C7F38-4BBC-4E9A-8392-C9FA21B54386}) (Version: 27.0.0 - Hewlett Packard) HP Document Manager 1.0 (HKLM\...\HP Document Manager) (Version: 1.0 - HP) HP Easy Setup - Frontend (HKLM\...\{40F7AED3-0C7D-4582-99F6-484A515C73F2}) (Version: 5.2.0.2304 - Hewlett-Packard) HP Imaging Device Functions 10.0 (HKLM\...\HP Imaging Device Functions) (Version: 10.0 - HP) HP Officejet J4500 Series (HKLM\...\{CD0773D5-C18E-495c-B39B-21A96415EDD5}) (Version: 1.0 - HP) HP On-Screen Cap/Num/Scroll Lock Indicator (HKLM\...\OsdMaestro) (Version: - Hewlett-Packard) HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.7702 - HP) HP Photosmart Essential 2.01 (HKLM\...\HP Photosmart Essential) (Version: 2.01 - HP) HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (HKLM\...\{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}) (Version: 8.0 - HP) HP Smart Web Printing (HKLM\...\HP Smart Web Printing) (Version: 3.5 - HP) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Update (HKLM\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) HPAsset component for HP Active Support Library (Version: 3.0.2.2 - Hewlett-Packard) Hidden HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden iCloud (HKLM\...\{5DDB3393-E08B-447E-925F-6C00B95D0FE7}) (Version: 2.1.1.3 - Apple Inc.) iTunes (HKLM\...\{DF9C119C-7F26-45B9-93D4-7C372CBBBA11}) (Version: 11.1.0.126 - Apple Inc.) J4500 (Version: 50.0.165.000 - Ihr Firmenname) Hidden Java 7 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle) JPEG2000 Dual Codec Software (HKLM\...\{EFECCA45-A5FA-4656-B0D8-89089A1BE0AA}) (Version: 1.0 - ) LightScribe 1.8.15.1 (Version: 1.8.15.1 - Ihr Firmenname) Hidden Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) MarketResearch (Version: 100.0.170.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - ) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft IntelliType Pro 7.1 (HKLM\...\{11E94FDB-C895-45F1-B756-1C9B8C36C8F1}) (Version: 7.10.344.0 - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007-Testversion (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE) (Version: - Microsoft Corporation) Microsoft Works (HKLM\...\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}) (Version: 08.05.0822 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mozilla Firefox 34.0.5 (x86 de) (HKLM\...\Mozilla Firefox 34.0.5 (x86 de)) (Version: 34.0.5 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSVCSetup (Version: 1.00.0000 - HP) Hidden MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) Optimierte Multimedia-Tastatur-Lösung (HKLM\...\KBD) (Version: - Hewlett-Packard) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.) Picasa Packages (HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Picasa Packages) (Version: - ) <==== ATTENTION ProductContext (Version: 50.0.165.000 - Hewlett-Packard) Hidden PSSWCORE (Version: 2.01.0000 - Hewlett-Packard) Hidden Python 2.5 (HKLM\...\{0A2C5854-557E-48C8-835A-3B9F074BDCAA}) (Version: 2.5.150 - Martin v. Löwis) QuickTime (HKLM\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - ) Roxio Creator Copy (HKLM\...\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.4.0 - Roxio) Roxio Creator Data (HKLM\...\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.4.0 - Roxio) Roxio Creator EasyArchive (HKLM\...\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}) (Version: 3.4.0 - Roxio) Roxio Creator Tools (HKLM\...\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.4.0 - Roxio) Scan (Version: 10.1.0.0 - Hewlett-Packard) Hidden Secunia PSI (3.0.0.7009) (HKLM\...\Secunia PSI) (Version: 3.0.0.7009 - Secunia) Shockwave (HKLM\...\Shockwave) (Version: - ) SmartWebPrintingOC (Version: 100.0.189.000 - Hewlett-Packard) Hidden Snap.Do Engine (HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\{3511a307-7c4a-43da-9555-f5c8b8032b3b}) (Version: 1.28.1.10797 - ReSoft Ltd.) <==== ATTENTION SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden Status (Version: 100.0.175.000 - Hewlett-Packard) Hidden Studie zur Verbesserung von HP Deskjet 2510 series Produkten (HKLM\...\{CDE2DEBC-B8AD-41A2-AE45-A8CE9A41EF8F}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Toolbox (Version: 100.0.170.000 - Hewlett-Packard) Hidden Toolbox (Version: 82.0.173.000 - Hewlett-Packard) Hidden TrayApp (Version: 100.0.170.000 - Hewlett-Packard) Hidden UnloadSupport (Version: 1.00.0000 - Hewlett-Packard) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) UpgradeStance (HKLM\...\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{c8ea8cd3}) (Version: - Software Publisher) <==== ATTENTION VideoToolkit01 (Version: 90.0.146.000 - Hewlett-Packard) Hidden VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN) WebReg (Version: 100.0.170.000 - Hewlett-Packard) Hidden Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00BB2763-6A77-11D0-A535-00C04FD7D062}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00EEBF57-477D-4084-9921-7AB3C2C9459D}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.135\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{03C036F1-A186-11D0-824A-00AA005B4383}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.99\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0AF10CEC-2ECD-4B92-9581-34F6AE0637F3}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0B91A74B-AD7C-4A9D-B563-29EEF9167172}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0C15D503-D017-47CE-9016-7B3F978721CC}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.5\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{1D2680C9-0E2A-469D-B787-065558BC7D43}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{218D2740-5A50-42A8-AB9F-62FF1B168782}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.69\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{23170F69-40C1-278A-1000-000100020000}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{320F0FDB-BE0A-4648-9D18-4A2C3448C007}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.79\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.23.9\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{35786D3C-B075-49B9-88DD-029876E11C01}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Chrome\Application\39.0.2171.65\delegate_execute.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{603D3800-BD81-11D0-A3A5-00C04FD706EC}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.145\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{6311429E-2F1A-4777-880F-C7289FD10169}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.123\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{640167B4-59B0-47A6-B335-A6B3C0695AEA}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.153\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{77F419AA-771A-45FF-AC66-7567FA3243D3}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServer32 -> C:\Windows\system32\urlmon.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{807C1E6C-1D00-453F-B920-B61BB7CDD997}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{82C588E7-E54B-408C-9F8C-6AF9ADF6F1E9}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{88C6C381-2E85-11D0-94DE-444553540000}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.24.15\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.149\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.22.3\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.165\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{AB968F1E-E20B-403A-9EB8-72EB0EB6797E}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{AE054212-3535-4430-83ED-D501AA6680E6}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{B155BDF8-02F0-451E-9A26-AE317CFD7779}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{B8967F85-58AE-4F46-9FB2-5D7904798F4B}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{BD84B380-8CA2-1069-AB1D-08000948F534}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.115\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{EB06378B-ABB6-4B3C-9B40-D488DD8A6E93}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.22.5\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{EDB5F444-CB8D-445A-A523-EC5AB6EA33C7}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{F3364BA0-65B9-11CE-A9BA-00AA004AE837}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.111\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.24.7\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{FE841493-835C-4FA3-B6CC-B4B2D4719848}\InprocServer32 -> No File Path ==================== Restore Points ========================= 26-12-2014 00:00:09 Geplanter Prüfpunkt 26-12-2014 15:45:27 Windows Update 28-12-2014 00:00:06 Geplanter Prüfpunkt 29-12-2014 00:00:07 Geplanter Prüfpunkt 30-12-2014 00:00:06 Geplanter Prüfpunkt 30-12-2014 19:32:59 Windows Update 01-01-2015 00:00:06 Geplanter Prüfpunkt 02-01-2015 00:00:06 Geplanter Prüfpunkt 03-01-2015 00:00:10 Geplanter Prüfpunkt 04-01-2015 00:00:07 Geplanter Prüfpunkt 05-01-2015 00:00:05 Geplanter Prüfpunkt 06-01-2015 00:00:06 Geplanter Prüfpunkt 06-01-2015 08:34:39 Windows Update 07-01-2015 00:00:12 Geplanter Prüfpunkt 07-01-2015 02:47:18 Windows Defender Checkpoint 08-01-2015 00:00:09 Geplanter Prüfpunkt 12-01-2015 10:35:10 Windows Update 12-01-2015 11:28:33 Removed Bonjour 12-01-2015 11:32:20 Entfernt dakota.ag 12-01-2015 11:36:33 Removed Lexware Info Service. 12-01-2015 11:41:03 Removed RTC Client API v1.2 12-01-2015 11:42:39 Removed Roxio MyDVD Basic v9 12-01-2015 11:52:04 TuneUp Utilities 2014 wird entfernt 12-01-2015 11:53:12 TuneUp Utilities 2014 (de-DE) wird entfernt 12-01-2015 14:00:19 Malwarebytes Anti-Rootkit Restore Point ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 11:23 - 2015-01-12 15:28 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {146CC7F1-4B47-4F95-A5B8-2EC0C2D6EE07} - System32\Tasks\Microsoft_Hardware_Launch_IType_exe => C:\Program Files\Microsoft IntelliType Pro\IType.exe [2009-11-05] (Microsoft Corporation) Task: {205AE3E8-DB28-4703-A3B3-F0DA74E7EBBF} - System32\Tasks\RecoveryCD => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-05-17] () Task: {2C0B4CE0-7836-4049-A6B5-D9E791DD6B06} - System32\Tasks\HP Health Check => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2007-05-24] (Hewlett-Packard) Task: {621536AC-9241-4203-B4F4-002AB26F46CF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1772254487-8582296-1865665106-1000UA => C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-19] (Google Inc.) Task: {6F52023A-8583-4A2F-8897-8D0DDA752944} - \Plus-HD-2.3-updater No Task File <==== ATTENTION Task: {71B70DA7-B205-4D15-AF69-8603BF16CBA0} - \EPUpdater No Task File <==== ATTENTION Task: {7715F03D-398E-4875-B39D-12C8D5AEE73F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-21] (Adobe Systems Incorporated) Task: {7B7A5420-7034-43BA-A57B-FC1A6FF8AB58} - \Plus-HD-2.3-enabler No Task File <==== ATTENTION Task: {81F91B00-251E-4352-A217-3ECBB3585831} - \7eca1cd8-2a95-4759-9c0f-ae713062040a-2 No Task File <==== ATTENTION Task: {85BDE8BD-0C9C-4672-B693-EE931B666872} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-04] (Google Inc.) Task: {89A435BF-CCA2-4D6D-BDE0-7695142B981D} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files\CHIP Updater\CHIPUpdater.exe Task: {8ED6C316-C98E-43E4-A29F-5CB447DD9375} - System32\Tasks\{A5B8BB3E-DCB6-4F73-A1E6-D7B14E616081} => pcalua.exe -a "C:\Program Files\Webroot\WRSA.exe" -c -uninstall Task: {98DD3500-6AF6-483F-937F-F076B631E27A} - System32\Tasks\JavaUpdateAdministrator => C:\Windows\system32\jusched.exe Task: {A2E415A9-3608-4E3E-A566-BB1F440BD94B} - \Plus-HD-2.3-codedownloader No Task File <==== ATTENTION Task: {A3056F46-39FA-464C-8CE5-76CA9BB28BFF} - \Plus-HD-2.3-chromeinstaller No Task File <==== ATTENTION Task: {B046B8D3-B880-44CE-B7D2-351DCA2AD8B5} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1772254487-8582296-1865665106-1000Core => C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-19] (Google Inc.) Task: {B148C776-5662-4CC8-86BF-936CFB3E2F20} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Cristian => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation) Task: {B4FD720C-38A7-4279-9DD2-A9EF3679C1A8} - System32\Tasks\HPCustParticipation HP Deskjet 2510 series => C:\Program Files\HP\HP Deskjet 2510 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.) Task: {BCE50F3A-5158-4353-ACA6-2739922780E4} - System32\Tasks\JavaUpdateCristian => C:\Windows\system32\jusched.exe Task: {D5E75031-DD6F-4FDF-9EEC-4C5553072652} - System32\Tasks\JavaUpdateAdmin => C:\Windows\system32\jusched.exe Task: {F918DF09-76C1-4BA6-A67F-A5A0E4FCB875} - \Plus-HD-2.3-firefoxinstaller No Task File <==== ATTENTION Task: {FC26B1A7-902B-49E8-A903-BAAC992A7E3D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-04] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1772254487-8582296-1865665106-1000Core.job => C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1772254487-8582296-1865665106-1000UA.job => C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2008-08-28 10:09 - 2007-07-30 05:19 - 00040960 _____ () C:\Windows\System32\LFXPJL2K.DLL 2011-09-27 06:23 - 2011-09-27 06:23 - 00087912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2011-09-27 06:22 - 2011-09-27 06:22 - 01242472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2007-06-05 12:20 - 2007-06-05 12:20 - 00177704 _____ () C:\Windows\system32\PSIService.exe 2013-11-20 08:28 - 2007-12-27 21:33 - 00540672 _____ () C:\Users\Cristian\Desktop\cms\EventLogger.exe 2013-11-20 08:28 - 2007-11-28 09:33 - 00102400 _____ () C:\Users\Cristian\Desktop\cms\RemoteSocket.dll 2013-11-20 08:28 - 2007-12-27 21:31 - 00163840 _____ () C:\Users\Cristian\Desktop\cms\eventlogger.dll 2013-11-20 08:28 - 2007-01-17 15:14 - 00386464 _____ () C:\Users\Cristian\Desktop\cms\sqlite.dll 2015-01-12 14:21 - 2015-01-12 14:22 - 03758192 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-21-1772254487-8582296-1865665106-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION! ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Cristian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk => C:\Windows\pss\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" ========================= Accounts: ========================== Administrator (S-1-5-21-1772254487-8582296-1865665106-500 - Administrator - Disabled) ASPNET (S-1-5-21-1772254487-8582296-1865665106-1002 - Limited - Enabled) Cristian (S-1-5-21-1772254487-8582296-1865665106-1000 - Administrator - Enabled) => C:\Users\Cristian Gast (S-1-5-21-1772254487-8582296-1865665106-501 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Error: (01/13/2015 08:47:47 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793} Microsoft Office Sessions: ========================= Error: (06/29/2013 08:01:20 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 522231 seconds with 4980 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2015-01-13 11:07:18.948 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 11:07:18.090 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 11:07:17.264 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 11:07:16.406 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 11:06:52.241 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\hitmanpro37.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 11:06:51.492 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\hitmanpro37.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 11:06:50.712 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\hitmanpro37.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 11:06:49.605 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\hitmanpro37.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-12 16:50:23.541 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-12 16:50:22.752 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: AMD Athlon(tm) 64 Processor 4000+ Percentage of memory in use: 49% Total physical RAM: 1917.82 MB Available physical RAM: 967.32 MB Total Pagefile: 4082.09 MB Available Pagefile: 2869.58 MB Total Virtual: 2047.88 MB Available Virtual: 1905.69 MB ==================== Drives ================================ Drive c: (HP) (Fixed) (Total:141.75 GB) (Free:36.64 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (FACTORY_IMAGE) (Fixed) (Total:7.3 GB) (Free:0.67 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 149.1 GB) (Disk ID: 1549F232) Partition 1: (Active) - (Size=141.8 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=7.3 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
13.01.2015, 11:20 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ständig Skriptfehler, PC extrem langsam und viel Werbung //edit Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
__________________ Logfiles bitte immer in CODE-Tags posten |
13.01.2015, 13:44 | #21 |
| Ständig Skriptfehler, PC extrem langsam und viel Werbung Erledigt. Ich weiss zwar nicht was Du da alles erkennst, merke aber langsam Besserung... der Pc ist etwas schneller... lg |
13.01.2015, 14:15 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ständig Skriptfehler, PC extrem langsam und viel Werbung Neue FRST Logs bitte
__________________ Logfiles bitte immer in CODE-Tags posten |
13.01.2015, 14:19 | #23 |
| Ständig Skriptfehler, PC extrem langsam und viel WerbungFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-01-2015 01 Ran by Cristian (administrator) on HOMEPC on 13-01-2015 14:16:09 Running from C:\Users\Cristian\Desktop Loaded Profile: Cristian (Available profiles: Cristian) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVM Berlin) C:\Program Files\avmwlanstick\WLanNetService.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe () C:\Windows\System32\PSIService.exe (Secunia) C:\Program Files\Secunia\PSI\psia.exe (Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe (OsdMaestro) C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe (AVM Berlin) C:\Program Files\avmwlanstick\WLanGUI.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe () C:\Users\Cristian\Desktop\CMS\EventLogger.exe (Evoluent) C:\Program Files\Evoluent\VMouse\V4\EvoMouseExec.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe (Hewlett-Packard Company) C:\hp\KBD\kbd.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Secunia) C:\Program Files\Secunia\PSI\sua.exe (Microsoft Corporation) C:\Windows\System32\sdclt.exe (Google Inc.) C:\Users\Cristian\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Cristian\AppData\Local\Google\Chrome\Application\chrome.exe () C:\Users\Cristian\AppData\Roaming\0F0W0T1V0D0L0M\Picasa Packages\uninstaller.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company) HKLM\...\Run: [KBD] => C:\HP\KBD\KbdStub.EXE [65536 2006-12-08] () HKLM\...\Run: [OsdMaestro] => C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [118784 2007-02-15] (OsdMaestro) HKLM\...\Run: [HP Health Check Scheduler] => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [71176 2007-05-24] (Hewlett-Packard) HKLM\...\Run: [SunJavaUpdateReg] => C:\Windows\system32\jureg.exe [54936 2007-04-07] (Sun Microsystems, Inc.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1848648 2009-07-07] (CANON INC.) HKLM\...\Run: [itype] => C:\Program Files\Microsoft IntelliType Pro\itype.exe [1505144 2009-11-05] (Microsoft Corporation) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [AVMWlanClient] => C:\Program Files\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-09-17] (Apple Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4669440 2007-07-06] (Realtek Semiconductor) HKLM\...\RunOnce: [Launcher] => C:\Windows\SMINST\launcher.exe [44168 2007-04-03] (soft thinks) HKLM\...\Policies\Explorer: [NoCDBurning] 0 HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKLM\...\Policies\Explorer: [NoSetTaskbar] 0 HKLM\...\Policies\Explorer: [NoDeletePrinter] 0 HKLM\...\Policies\Explorer: [NoDFSTab] 0 HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0 HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0 HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKLM\...\Policies\Explorer: [NoResolveSearch] 0 HKLM\...\Policies\Explorer: [NoHardwareTab] 0 HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-19\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-19\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-19\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-19\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-19\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-20\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-20\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-20\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-20\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-20\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\RunOnce: [Adobe Speed Launcher] => !Dƒ HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-18\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoStartMenuSubFolders] 0 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\EventLogger.lnk ShortcutTarget: EventLogger.lnk -> C:\Users\Cristian\Desktop\CMS\EventLogger.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Evoluent Mouse Manager.lnk ShortcutTarget: Evoluent Mouse Manager.lnk -> C:\Windows\Installer\{AD6E0AE0-DADF-480E-82AE-4CDA6035D341}\_BBBCF44DDE3DA1E118ADB6.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia) Startup: C:\Users\Cristian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 2510 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 2510 series.lnk -> C:\Program Files\HP\HP Deskjet 2510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1772254487-8582296-1865665106-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/?LinkId=69157 HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://www.google.com HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://www.google.com HKU\S-1-5-21-1772254487-8582296-1865665106-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKU\S-1-5-21-1772254487-8582296-1865665106-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> DefaultScope {0997A1DF-9518-4A18-A389-2C0497952326} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {0997A1DF-9518-4A18-A389-2C0497952326} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {56FB9A98-C2C7-4C40-8187-FD09EDBBBDE9} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {63250AB7-8D89-40E1-9345-055F753AAD3B} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {6B77EBF6-3C4A-4516-B673-30A5AF0C4C74} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {99039AFC-4C2F-4AA4-93C3-96192296CA29} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation) Toolbar: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {16BC6A51-9F62-49E3-9F96-C842EF2FFE3E} hxxp://www.eytronserver.com/CAB/WebPlayer.cab DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} hxxp://o.aolcdn.com/pictures/ap/Resources/v2.14/cab/aolpPlugins.10.6.0.8.cab DPF: {29DFBD41-3B7D-4368-9021-894C5A30E054} hxxp://www.eytronserver.com/CAB/RemoteWeb.cab DPF: {54CFC975-F9FB-45EB-8D18-D2D04FBC4299} hxxp://www.eytronserver.com/CAB/RemoteWeb2.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} hxxp://www.lokalisten.de/iup/ImageUploader4.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} hxxp://upload.lokalisten.de/iup/ImageUploader6.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab DPF: {BF5453EA-7EF7-4946-8421-8F002870A5ED} hxxp://eytronserver.com/CAB2/JMNVSClientWeb.cab DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab DPF: {CF1572D7-C2DB-456A-8F56-CFAAA4C79251} hxxp://www.eytronserver.com/CAB/WEB_BACKUP2.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} hxxp://www.lokalisten.de/iup/ImageUploader4.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Cristian\AppData\Roaming\Mozilla\Firefox\Profiles\e0a8z0de.default-1420726666714 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @innoplus.de/ino3DViewer -> C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll No File FF Plugin: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1772254487-8582296-1865665106-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-1772254487-8582296-1865665106-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-22] FF HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR Profile: C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-07] CHR Extension: (YouTube) - C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-07] CHR Extension: (Google-Suche) - C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-07] CHR Extension: (Google Wallet) - C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-15] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AVM WLAN Connection Service; C:\Program Files\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed] R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [61440 2007-05-24] (Hewlett-Packard) [File not signed] R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed] S3 IDriverT; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed] R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed] R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1227800 2013-04-18] (Secunia) R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [659992 2013-04-18] (Secunia) S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2010-10-01] (AVM Berlin) [File not signed] R3 AVMWAN; C:\Windows\System32\DRIVERS\avmwan.sys [29968 2001-11-08] (AVM Berlin) [File not signed] R3 EvoMouseDriverFilterHidUsb; C:\Windows\System32\DRIVERS\EvoMouseDriverFilterHidUsb.sys [22712 2010-06-23] (Evoluent) R3 EvoMouseDriverMini; C:\Windows\System32\drivers\EvoMouseDriverMini.sys [20024 2010-06-23] () R3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [926080 2010-10-01] (AVM GmbH) S3 fxusbase; C:\Windows\System32\DRIVERS\fxusbase.sys [488656 2001-11-08] (AVM Berlin) [File not signed] S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [30464 2013-07-09] () S3 LFXACT; C:\Windows\System32\Drivers\LFXACT.sys [20672 2007-01-09] (OEM) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-04-18] (Secunia) R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2008-01-22] (Acronis) S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-01] (America Online, Inc.) S3 WlanUIG; C:\Windows\System32\DRIVERS\2862w.sys [346944 2004-04-06] (SMC Networks, Inc.) [File not signed] S3 XMLDIUSB; C:\Windows\System32\Drivers\XMLDIUSB.sys [31879 2007-01-09] (OEM) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] U0 SR; No ImagePath U2 srservice; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-13 13:05 - 2015-01-13 13:05 - 00000661 _____ () C:\Users\Cristian\Desktop\Revo Uninstaller.lnk 2015-01-13 13:04 - 2015-01-13 13:04 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Cristian\Desktop\revosetup95.exe 2015-01-13 11:07 - 2015-01-13 11:07 - 00039225 _____ () C:\Users\Cristian\Desktop\Addition.txt 2015-01-13 11:06 - 2015-01-13 14:16 - 00026281 _____ () C:\Users\Cristian\Desktop\FRST.txt 2015-01-13 11:04 - 2015-01-13 11:04 - 00000551 _____ () C:\Users\Cristian\Desktop\ComboFix - Verknüpfung.lnk 2015-01-13 11:04 - 2015-01-13 11:04 - 00000551 _____ () C:\Users\Cristian\Desktop\ComboFix - Verknüpfung (2).lnk 2015-01-12 16:49 - 2015-01-12 16:49 - 01115648 _____ (Farbar) C:\Users\Cristian\Desktop\FRST(1).exe 2015-01-12 16:48 - 2015-01-12 16:48 - 00000805 _____ () C:\Users\Cristian\Desktop\JRT.txt 2015-01-12 16:44 - 2015-01-12 16:44 - 01707939 _____ (Thisisu) C:\Users\Cristian\Downloads\JRT.exe 2015-01-12 15:49 - 2015-01-12 16:36 - 00000000 ____D () C:\AdwCleaner 2015-01-12 15:48 - 2015-01-12 15:49 - 02191360 _____ () C:\Users\Cristian\Desktop\AdwCleaner_4.107.exe 2015-01-12 15:34 - 2015-01-12 15:34 - 00022740 _____ () C:\ComboFix.txt 2015-01-12 15:09 - 2015-01-12 15:35 - 00000000 ____D () C:\ComboFix 2015-01-12 15:09 - 2015-01-12 15:34 - 00000000 ____D () C:\Qoobox 2015-01-12 15:09 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-01-12 15:09 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-01-12 15:09 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2015-01-12 15:08 - 2015-01-12 15:33 - 00000000 ____D () C:\Windows\erdnt 2015-01-12 15:08 - 2015-01-12 15:08 - 05609736 ____R (Swearware) C:\Users\Cristian\Downloads\ComboFix.exe 2015-01-12 14:21 - 2015-01-12 14:22 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-01-12 14:12 - 2015-01-12 14:12 - 00583256 _____ () C:\Users\Cristian\Downloads\Installation.exe 2015-01-12 13:33 - 2015-01-12 15:25 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2015-01-12 12:45 - 2015-01-12 12:45 - 16448208 _____ (Malwarebytes Corp.) C:\Users\Cristian\Downloads\mbar-1.08.2.1001(1).exe 2015-01-12 12:38 - 2015-01-12 14:37 - 00000000 ____D () C:\Users\Cristian\Desktop\mbar 2015-01-12 12:37 - 2015-01-12 12:37 - 16448208 _____ (Malwarebytes Corp.) C:\Users\Cristian\Downloads\mbar-1.08.2.1001.exe 2015-01-12 12:27 - 2015-01-12 12:27 - 00000159 _____ () C:\Users\Cristian\Desktop\Malwareprotokoll.txt 2015-01-12 12:06 - 2015-01-12 12:08 - 00048718 _____ () C:\Users\Cristian\Downloads\Addition.txt 2015-01-12 12:04 - 2015-01-13 14:16 - 00000000 ____D () C:\FRST 2015-01-12 12:04 - 2015-01-12 16:50 - 00036775 _____ () C:\Users\Cristian\Downloads\FRST.txt 2015-01-12 12:04 - 2015-01-12 12:04 - 01115648 _____ (Farbar) C:\Users\Cristian\Desktop\FRST.exe 2015-01-12 10:59 - 2015-01-12 11:07 - 00000000 ____D () C:\Users\Cristian\Desktop\Alle privaten Fotos 2015-01-05 22:32 - 2015-01-05 22:32 - 00000000 ____D () C:\ProgramData\dfhndngfkikbamohhepblbjlemgbjooa 2014-12-22 10:09 - 2014-12-22 10:09 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CdCoverCreator 2014-12-22 10:09 - 2014-12-22 10:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CdCoverCreator 2014-12-22 10:08 - 2015-01-12 11:26 - 00000000 ____D () C:\Program Files\CHIP Updater 2014-12-22 10:08 - 2014-12-22 10:09 - 00000000 ____D () C:\Users\Cristian\AppData\Local\Abelssoft 2014-12-22 10:08 - 2014-12-22 10:08 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\Abelssoft 2014-12-22 10:08 - 2014-12-22 10:08 - 00000000 ____D () C:\ProgramData\XDMessagingv4 2014-12-22 10:07 - 2014-12-22 10:07 - 01174352 _____ () C:\Users\Cristian\Downloads\CdCoverCreator - CHIP-Installer.exe 2014-12-17 15:25 - 2015-01-12 11:36 - 00000000 ____D () C:\ProgramData\Freemake 2014-12-17 15:25 - 2014-12-17 15:33 - 00000000 ____D () C:\Users\Cristian\Documents\Freemake 2014-12-17 14:53 - 2015-01-12 15:21 - 00000000 ____D () C:\Program Files\ef0ef932-01b1-473d-a940-2c3a15fc9957 2014-12-17 14:48 - 2014-12-17 14:48 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\TuneUp Software 2014-12-17 14:48 - 2014-12-17 14:48 - 00000000 ____D () C:\Users\Cristian\AppData\Local\TuneUp Software 2014-12-17 14:47 - 2014-12-18 11:02 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-12-17 14:47 - 2014-12-17 14:47 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-12-17 14:45 - 2015-01-12 10:15 - 00018872 _____ () C:\Windows\system32\Drivers\SPPD.sys 2014-12-17 14:18 - 2014-12-17 14:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo 2014-12-17 14:18 - 2014-12-17 14:31 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-12-17 14:18 - 2014-12-17 14:18 - 00000000 ____D () C:\Users\Cristian\AppData\Local\Ashampoo Movie Studio 2013 ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-13 13:41 - 2007-11-29 14:41 - 01732199 _____ () C:\Windows\WindowsUpdate.log 2015-01-13 12:38 - 2006-11-02 13:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-13 12:38 - 2006-11-02 13:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-13 01:50 - 2011-06-27 06:03 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-12 16:39 - 2007-11-20 21:26 - 00000000 ____D () C:\Windows\SMINST 2015-01-12 16:38 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-12 16:37 - 2012-05-30 20:08 - 00090796 _____ () C:\Windows\PFRO.log 2015-01-12 16:37 - 2012-05-28 10:17 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-01-12 16:37 - 2006-11-02 14:01 - 00032560 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-12 16:36 - 2013-07-04 20:41 - 00001101 _____ () C:\Users\Cristian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2015-01-12 15:34 - 2006-11-02 12:18 - 00000000 __RHD () C:\Users\Default 2015-01-12 15:34 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public 2015-01-12 15:28 - 2006-11-02 11:23 - 00000215 _____ () C:\Windows\system.ini 2015-01-12 15:24 - 2006-11-02 11:22 - 66584576 _____ () C:\Windows\system32\config\SYSTEM.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 65011712 _____ () C:\Windows\system32\config\SOFTWARE.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 55574528 _____ () C:\Windows\system32\config\COMPON~1.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\DEFAULT.bak 2015-01-12 15:21 - 2010-10-31 16:30 - 00000000 ____D () C:\Program Files\7-Zip 2015-01-12 14:16 - 2014-05-19 07:57 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-12 14:15 - 2014-05-19 07:56 - 00079576 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-12 14:09 - 2008-01-15 10:27 - 00111960 _____ () C:\Users\Cristian\AppData\Local\GDIPFONTCACHEV1.DAT 2015-01-12 14:08 - 2007-11-20 20:52 - 00000000 ____D () C:\Windows\system32\RTCOM 2015-01-12 14:06 - 2006-11-02 13:47 - 00410136 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-12 11:50 - 2007-11-20 20:56 - 00000000 ____D () C:\Program Files\Roxio 2015-01-12 11:50 - 2007-11-20 20:55 - 00000000 ____D () C:\Program Files\Common Files\Roxio Shared 2015-01-12 11:40 - 2007-11-20 20:52 - 00319456 _____ (Microsoft Corporation) C:\Windows\DIFxAPI.dll 2015-01-12 11:40 - 2007-11-20 20:52 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2015-01-12 11:38 - 2009-03-19 14:57 - 00000000 ____D () C:\Program Files\Sigel 2015-01-12 11:34 - 2011-08-20 20:06 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\DVDVideoSoft 2015-01-12 11:34 - 2011-08-20 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-01-12 11:30 - 2010-12-23 19:36 - 00000000 ____D () C:\Program Files\Canon 2015-01-12 11:29 - 2010-12-23 19:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities 2015-01-12 11:27 - 2014-09-22 08:21 - 00000000 ____D () C:\Program Files\dm 2015-01-12 11:26 - 2008-01-15 10:21 - 00000000 ____D () C:\Users\Cristian 2015-01-12 11:23 - 2014-09-21 17:01 - 00000000 ____D () C:\ProgramData\tmp 2015-01-12 11:06 - 2013-11-27 09:19 - 00000000 ____D () C:\Users\Cristian\Desktop\Reichwein 2015-01-12 11:05 - 2013-11-27 09:30 - 00000000 ____D () C:\Users\Cristian\Desktop\Scheidl 2015-01-12 11:03 - 2013-11-27 09:27 - 00000000 ____D () C:\Users\Cristian\Desktop\ZurbackstubnFotos 2015-01-06 04:36 - 2009-10-04 17:50 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-12-19 15:38 - 2008-01-22 13:33 - 00027136 _____ () C:\Users\Cristian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-12-18 13:04 - 2012-07-26 12:38 - 00005806 _____ () C:\Windows\setupact.log 2014-12-17 15:11 - 2010-10-26 12:03 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\vlc 2014-12-17 14:50 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Sidebar 2014-12-17 14:27 - 2009-06-06 17:49 - 00000000 ____D () C:\Users\Cristian\Documents\DVDVideoSoft Some content of TEMP: ==================== C:\Users\Cristian\AppData\Local\temp\Quarantine.exe C:\Users\Cristian\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-13 04:47 ==================== End Of Log ======================== Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-01-2015 01 Ran by Cristian at 2015-01-13 14:17:02 Running from C:\Users\Cristian\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 32 Bit HP CIO Components Installer (Version: 1.0.0 - Hewlett-Packard) Hidden 3D-Viewer-innoplus (HKLM\...\{B96DB037-DBEA-4186-9081-9CBD537F82E8}) (Version: 13.01.07 - INNOVA-engineering GmbH) 4500_Help (Version: 1.00.0000 - Hewlett-Packard) Hidden 6300 (Version: 82.0.242.000 - Hewlett-Packard) Hidden 6300_Help (Version: 82.0.242.000 - Hewlett-Packard) Hidden 6300Trb (Version: 82.0.242.000 - Hewlett-Packard) Hidden 7-Zip 4.65 (HKLM\...\7-Zip) (Version: - ) ActiveCheck component for HP Active Support Library (Version: 3.0.0.2 - Hewlett-Packard) Hidden Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.8.0.1430 - Adobe Systems Incorporated) Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader X (10.1.13) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.13 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM\...\{0099B484-C24C-4D5F-8167-B0F6DF196E72}) (Version: 12.0.3.133 - Adobe Systems, Inc) Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.) AIO_CDB_ProductContext (Version: 82.0.242.000 - Hewlett-Packard) Hidden AIO_CDB_Software (Version: 82.0.242.000 - Hewlett-Packard) Hidden AIO_Scan (Version: 82.0.173.000 - Hewlett-Packard) Hidden Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{0592EF96-69D8-4E4B-9CC9-88F58EA86F01}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) AVM FRITZ!WLAN (HKLM\...\AVMWLANCLI) (Version: - AVM Berlin) BPD_HPSU (Version: 1.00.0000 - Hewlett-Packard) Hidden bpd_scan (Version: 3.00.0000 - Hewlett-Packard) Hidden BPDSoftware (Version: 50.0.165.000 - Hewlett-Packard) Hidden BPDSoftware_Ini (Version: 1.00.0000 - Hewlett-Packard) Hidden BufferChm (Version: 100.0.170.000 - Hewlett-Packard) Hidden Canon iP3600 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP3600_series) (Version: - ) Canon Utilities Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version: - ) Canon Utilities My Printer (HKLM\...\CanonMyPrinter) (Version: - ) Copy (Version: 82.0.188.000 - Hewlett-Packard) Hidden CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden Destination Component (Version: 100.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (Version: 100.0.190.000 - Hewlett-Packard) Hidden DHTML Editing Component (HKLM\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation) DocMgr (Version: 100.0.201.000 - Hewlett-Packard) Hidden DocProc (Version: 10.0.0.0 - Hewlett-Packard) Hidden Evoluent Mouse Manager (HKLM\...\{AD6E0AE0-DADF-480E-82AE-4CDA6035D341}) (Version: 4.0.0 - Evoluent) Fax (Version: 100.0.187.000 - Hewlett-Packard) Hidden Google Chrome (HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Google Chrome) (Version: 39.0.2171.65 - Google Inc.) Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden GPBaseService (Version: 100.0.187.000 - Hewlett-Packard) Hidden GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden HP Customer Experience Enhancements (HKLM\...\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}) (Version: 5.2.0.2296 - Hewlett-Packard) HP Customer Participation Program 10.0 (HKLM\...\HPExtendedCapabilities) (Version: 10.0 - HP) HP Deskjet 2510 series - Grundlegende Software für das Gerät (HKLM\...\{A3B40F90-312F-497B-A631-D0C7D37D7C59}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) HP Deskjet 2510 series Hilfe (HKLM\...\{07B48D2C-E60D-41E6-B546-11D128F633EC}) (Version: 27.0.0 - Hewlett Packard) HP Deskjet 2510 series Setup Guide (HKLM\...\{216C7F38-4BBC-4E9A-8392-C9FA21B54386}) (Version: 27.0.0 - Hewlett Packard) HP Document Manager 1.0 (HKLM\...\HP Document Manager) (Version: 1.0 - HP) HP Easy Setup - Frontend (HKLM\...\{40F7AED3-0C7D-4582-99F6-484A515C73F2}) (Version: 5.2.0.2304 - Hewlett-Packard) HP Imaging Device Functions 10.0 (HKLM\...\HP Imaging Device Functions) (Version: 10.0 - HP) HP Officejet J4500 Series (HKLM\...\{CD0773D5-C18E-495c-B39B-21A96415EDD5}) (Version: 1.0 - HP) HP On-Screen Cap/Num/Scroll Lock Indicator (HKLM\...\OsdMaestro) (Version: - Hewlett-Packard) HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.7702 - HP) HP Photosmart Essential 2.01 (HKLM\...\HP Photosmart Essential) (Version: 2.01 - HP) HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (HKLM\...\{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}) (Version: 8.0 - HP) HP Smart Web Printing (HKLM\...\HP Smart Web Printing) (Version: 3.5 - HP) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Update (HKLM\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) HPAsset component for HP Active Support Library (Version: 3.0.2.2 - Hewlett-Packard) Hidden HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden iCloud (HKLM\...\{5DDB3393-E08B-447E-925F-6C00B95D0FE7}) (Version: 2.1.1.3 - Apple Inc.) iTunes (HKLM\...\{DF9C119C-7F26-45B9-93D4-7C372CBBBA11}) (Version: 11.1.0.126 - Apple Inc.) J4500 (Version: 50.0.165.000 - Ihr Firmenname) Hidden Java 7 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle) JPEG2000 Dual Codec Software (HKLM\...\{EFECCA45-A5FA-4656-B0D8-89089A1BE0AA}) (Version: 1.0 - ) LightScribe 1.8.15.1 (Version: 1.8.15.1 - Ihr Firmenname) Hidden Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) MarketResearch (Version: 100.0.170.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - ) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft IntelliType Pro 7.1 (HKLM\...\{11E94FDB-C895-45F1-B756-1C9B8C36C8F1}) (Version: 7.10.344.0 - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007-Testversion (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE) (Version: - Microsoft Corporation) Microsoft Works (HKLM\...\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}) (Version: 08.05.0822 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mozilla Firefox 34.0.5 (x86 de) (HKLM\...\Mozilla Firefox 34.0.5 (x86 de)) (Version: 34.0.5 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSVCSetup (Version: 1.00.0000 - HP) Hidden MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) Optimierte Multimedia-Tastatur-Lösung (HKLM\...\KBD) (Version: - Hewlett-Packard) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.) ProductContext (Version: 50.0.165.000 - Hewlett-Packard) Hidden PSSWCORE (Version: 2.01.0000 - Hewlett-Packard) Hidden Python 2.5 (HKLM\...\{0A2C5854-557E-48C8-835A-3B9F074BDCAA}) (Version: 2.5.150 - Martin v. Löwis) QuickTime (HKLM\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - ) Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Roxio Creator Copy (HKLM\...\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.4.0 - Roxio) Roxio Creator Data (HKLM\...\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.4.0 - Roxio) Roxio Creator EasyArchive (HKLM\...\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}) (Version: 3.4.0 - Roxio) Roxio Creator Tools (HKLM\...\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.4.0 - Roxio) Scan (Version: 10.1.0.0 - Hewlett-Packard) Hidden Secunia PSI (3.0.0.7009) (HKLM\...\Secunia PSI) (Version: 3.0.0.7009 - Secunia) Shockwave (HKLM\...\Shockwave) (Version: - ) SmartWebPrintingOC (Version: 100.0.189.000 - Hewlett-Packard) Hidden SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden Status (Version: 100.0.175.000 - Hewlett-Packard) Hidden Studie zur Verbesserung von HP Deskjet 2510 series Produkten (HKLM\...\{CDE2DEBC-B8AD-41A2-AE45-A8CE9A41EF8F}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Toolbox (Version: 100.0.170.000 - Hewlett-Packard) Hidden Toolbox (Version: 82.0.173.000 - Hewlett-Packard) Hidden TrayApp (Version: 100.0.170.000 - Hewlett-Packard) Hidden UnloadSupport (Version: 1.00.0000 - Hewlett-Packard) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VideoToolkit01 (Version: 90.0.146.000 - Hewlett-Packard) Hidden VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN) WebReg (Version: 100.0.170.000 - Hewlett-Packard) Hidden Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00BB2763-6A77-11D0-A535-00C04FD7D062}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00EEBF57-477D-4084-9921-7AB3C2C9459D}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.135\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{03C036F1-A186-11D0-824A-00AA005B4383}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.99\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0AF10CEC-2ECD-4B92-9581-34F6AE0637F3}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0B91A74B-AD7C-4A9D-B563-29EEF9167172}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0C15D503-D017-47CE-9016-7B3F978721CC}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.5\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{1D2680C9-0E2A-469D-B787-065558BC7D43}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{218D2740-5A50-42A8-AB9F-62FF1B168782}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.69\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{23170F69-40C1-278A-1000-000100020000}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{320F0FDB-BE0A-4648-9D18-4A2C3448C007}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.79\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.23.9\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{35786D3C-B075-49B9-88DD-029876E11C01}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Chrome\Application\39.0.2171.65\delegate_execute.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{603D3800-BD81-11D0-A3A5-00C04FD706EC}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.145\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{6311429E-2F1A-4777-880F-C7289FD10169}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.123\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{640167B4-59B0-47A6-B335-A6B3C0695AEA}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.153\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{77F419AA-771A-45FF-AC66-7567FA3243D3}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServer32 -> C:\Windows\system32\urlmon.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{807C1E6C-1D00-453F-B920-B61BB7CDD997}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{82C588E7-E54B-408C-9F8C-6AF9ADF6F1E9}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{88C6C381-2E85-11D0-94DE-444553540000}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.24.15\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.149\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.22.3\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.165\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{AB968F1E-E20B-403A-9EB8-72EB0EB6797E}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{AE054212-3535-4430-83ED-D501AA6680E6}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{B155BDF8-02F0-451E-9A26-AE317CFD7779}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{B8967F85-58AE-4F46-9FB2-5D7904798F4B}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{BD84B380-8CA2-1069-AB1D-08000948F534}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.115\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{EB06378B-ABB6-4B3C-9B40-D488DD8A6E93}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.22.5\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{EDB5F444-CB8D-445A-A523-EC5AB6EA33C7}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{F3364BA0-65B9-11CE-A9BA-00AA004AE837}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.111\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.24.7\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{FE841493-835C-4FA3-B6CC-B4B2D4719848}\InprocServer32 -> No File Path ==================== Restore Points ========================= 30-12-2014 00:00:06 Geplanter Prüfpunkt 30-12-2014 19:32:59 Windows Update 01-01-2015 00:00:06 Geplanter Prüfpunkt 02-01-2015 00:00:06 Geplanter Prüfpunkt 03-01-2015 00:00:10 Geplanter Prüfpunkt 04-01-2015 00:00:07 Geplanter Prüfpunkt 05-01-2015 00:00:05 Geplanter Prüfpunkt 06-01-2015 00:00:06 Geplanter Prüfpunkt 06-01-2015 08:34:39 Windows Update 07-01-2015 00:00:12 Geplanter Prüfpunkt 07-01-2015 02:47:18 Windows Defender Checkpoint 08-01-2015 00:00:09 Geplanter Prüfpunkt 12-01-2015 10:35:10 Windows Update 12-01-2015 11:28:33 Removed Bonjour 12-01-2015 11:32:20 Entfernt dakota.ag 12-01-2015 11:36:33 Removed Lexware Info Service. 12-01-2015 11:41:03 Removed RTC Client API v1.2 12-01-2015 11:42:39 Removed Roxio MyDVD Basic v9 12-01-2015 11:52:04 TuneUp Utilities 2014 wird entfernt 12-01-2015 11:53:12 TuneUp Utilities 2014 (de-DE) wird entfernt 12-01-2015 14:00:19 Malwarebytes Anti-Rootkit Restore Point 13-01-2015 13:06:34 Revo Uninstaller's restore point - Picasa Packages 13-01-2015 13:31:26 Revo Uninstaller's restore point - Picasa Packages 13-01-2015 13:34:51 Revo Uninstaller's restore point - Snap.Do 13-01-2015 13:35:11 Removed Snap.Do 13-01-2015 13:37:37 Revo Uninstaller's restore point - Snap.Do Engine 13-01-2015 13:39:35 Revo Uninstaller's restore point - UpgradeStance ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 11:23 - 2015-01-12 15:28 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {146CC7F1-4B47-4F95-A5B8-2EC0C2D6EE07} - System32\Tasks\Microsoft_Hardware_Launch_IType_exe => C:\Program Files\Microsoft IntelliType Pro\IType.exe [2009-11-05] (Microsoft Corporation) Task: {205AE3E8-DB28-4703-A3B3-F0DA74E7EBBF} - System32\Tasks\RecoveryCD => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-05-17] () Task: {2C0B4CE0-7836-4049-A6B5-D9E791DD6B06} - System32\Tasks\HP Health Check => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2007-05-24] (Hewlett-Packard) Task: {621536AC-9241-4203-B4F4-002AB26F46CF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1772254487-8582296-1865665106-1000UA => C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-19] (Google Inc.) Task: {6F52023A-8583-4A2F-8897-8D0DDA752944} - \Plus-HD-2.3-updater No Task File <==== ATTENTION Task: {71B70DA7-B205-4D15-AF69-8603BF16CBA0} - \EPUpdater No Task File <==== ATTENTION Task: {7715F03D-398E-4875-B39D-12C8D5AEE73F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-21] (Adobe Systems Incorporated) Task: {7B7A5420-7034-43BA-A57B-FC1A6FF8AB58} - \Plus-HD-2.3-enabler No Task File <==== ATTENTION Task: {81F91B00-251E-4352-A217-3ECBB3585831} - \7eca1cd8-2a95-4759-9c0f-ae713062040a-2 No Task File <==== ATTENTION Task: {85BDE8BD-0C9C-4672-B693-EE931B666872} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-04] (Google Inc.) Task: {89A435BF-CCA2-4D6D-BDE0-7695142B981D} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files\CHIP Updater\CHIPUpdater.exe Task: {8ED6C316-C98E-43E4-A29F-5CB447DD9375} - System32\Tasks\{A5B8BB3E-DCB6-4F73-A1E6-D7B14E616081} => pcalua.exe -a "C:\Program Files\Webroot\WRSA.exe" -c -uninstall Task: {98DD3500-6AF6-483F-937F-F076B631E27A} - System32\Tasks\JavaUpdateAdministrator => C:\Windows\system32\jusched.exe Task: {A2E415A9-3608-4E3E-A566-BB1F440BD94B} - \Plus-HD-2.3-codedownloader No Task File <==== ATTENTION Task: {A3056F46-39FA-464C-8CE5-76CA9BB28BFF} - \Plus-HD-2.3-chromeinstaller No Task File <==== ATTENTION Task: {B046B8D3-B880-44CE-B7D2-351DCA2AD8B5} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1772254487-8582296-1865665106-1000Core => C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-19] (Google Inc.) Task: {B148C776-5662-4CC8-86BF-936CFB3E2F20} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Cristian => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation) Task: {B4FD720C-38A7-4279-9DD2-A9EF3679C1A8} - System32\Tasks\HPCustParticipation HP Deskjet 2510 series => C:\Program Files\HP\HP Deskjet 2510 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.) Task: {BCE50F3A-5158-4353-ACA6-2739922780E4} - System32\Tasks\JavaUpdateCristian => C:\Windows\system32\jusched.exe Task: {D5E75031-DD6F-4FDF-9EEC-4C5553072652} - System32\Tasks\JavaUpdateAdmin => C:\Windows\system32\jusched.exe Task: {F918DF09-76C1-4BA6-A67F-A5A0E4FCB875} - \Plus-HD-2.3-firefoxinstaller No Task File <==== ATTENTION Task: {FC26B1A7-902B-49E8-A903-BAAC992A7E3D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-04] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1772254487-8582296-1865665106-1000Core.job => C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1772254487-8582296-1865665106-1000UA.job => C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2008-08-28 10:09 - 2007-07-30 05:19 - 00040960 _____ () C:\Windows\System32\LFXPJL2K.DLL 2011-09-27 06:23 - 2011-09-27 06:23 - 00087912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2011-09-27 06:22 - 2011-09-27 06:22 - 01242472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2007-06-05 12:20 - 2007-06-05 12:20 - 00177704 _____ () C:\Windows\system32\PSIService.exe 2013-11-20 08:28 - 2007-12-27 21:33 - 00540672 _____ () C:\Users\Cristian\Desktop\cms\EventLogger.exe 2013-11-20 08:28 - 2007-11-28 09:33 - 00102400 _____ () C:\Users\Cristian\Desktop\cms\RemoteSocket.dll 2013-11-20 08:28 - 2007-12-27 21:31 - 00163840 _____ () C:\Users\Cristian\Desktop\cms\eventlogger.dll 2013-11-20 08:28 - 2007-01-17 15:14 - 00386464 _____ () C:\Users\Cristian\Desktop\cms\sqlite.dll 2014-11-19 05:56 - 2014-11-14 22:15 - 09009480 _____ () C:\Users\Cristian\AppData\Local\Google\Chrome\Application\39.0.2171.65\pdf.dll 2014-11-19 05:56 - 2014-11-14 22:15 - 01677128 _____ () C:\Users\Cristian\AppData\Local\Google\Chrome\Application\39.0.2171.65\ffmpegsumo.dll 2013-07-03 10:53 - 2013-01-30 13:45 - 01114624 _____ () C:\Users\Cristian\AppData\Roaming\0F0W0T1V0D0L0M\Picasa Packages\uninstaller.exe ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-21-1772254487-8582296-1865665106-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION! ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Cristian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk => C:\Windows\pss\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" ========================= Accounts: ========================== Administrator (S-1-5-21-1772254487-8582296-1865665106-500 - Administrator - Disabled) ASPNET (S-1-5-21-1772254487-8582296-1865665106-1002 - Limited - Enabled) Cristian (S-1-5-21-1772254487-8582296-1865665106-1000 - Administrator - Enabled) => C:\Users\Cristian Gast (S-1-5-21-1772254487-8582296-1865665106-501 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/13/2015 01:39:35 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {166dd7df-f552-4c01-bc0d-04b580900594} Error: (01/13/2015 01:37:37 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {166dd7df-f552-4c01-bc0d-04b580900594} Error: (01/13/2015 01:34:50 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {166dd7df-f552-4c01-bc0d-04b580900594} Error: (01/13/2015 01:31:26 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {166dd7df-f552-4c01-bc0d-04b580900594} Error: (01/13/2015 01:06:30 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {166dd7df-f552-4c01-bc0d-04b580900594} System errors: ============= Error: (01/13/2015 08:47:47 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793} Microsoft Office Sessions: ========================= Error: (06/29/2013 08:01:20 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 522231 seconds with 4980 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2015-01-13 14:16:55.077 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 14:16:54.313 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 14:16:53.533 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 14:16:52.753 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 14:16:24.969 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\hitmanpro37.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 14:16:24.189 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\hitmanpro37.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 14:16:23.409 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\hitmanpro37.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 14:16:22.629 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\hitmanpro37.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 11:07:18.948 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 11:07:18.090 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: AMD Athlon(tm) 64 Processor 4000+ Percentage of memory in use: 48% Total physical RAM: 1917.82 MB Available physical RAM: 988.93 MB Total Pagefile: 4082.09 MB Available Pagefile: 2780.67 MB Total Virtual: 2047.88 MB Available Virtual: 1905.38 MB ==================== Drives ================================ Drive c: (HP) (Fixed) (Total:141.75 GB) (Free:37.71 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (FACTORY_IMAGE) (Fixed) (Total:7.3 GB) (Free:0.67 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 149.1 GB) (Disk ID: 1549F232) Partition 1: (Active) - (Size=141.8 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=7.3 GB) - (Type=07 NTFS) ==================== End Of Log ============================ übrigens, beim letzten Male wo mir hier jemand geholfen hatte, hat genau dieses Picasa (Photoalbum, was ich runtergeladen hatte) Probleme gemacht, also war das wohl noch nicht ganz weg.... |
13.01.2015, 15:02 | #24 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ständig Skriptfehler, PC extrem langsam und viel Werbung Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKU\S-1-5-21-1772254487-8582296-1865665106-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = C:\Users\Cristian\AppData\Roaming\0F0W0T1V0D0L0M C:\Program Files\ef0ef932-01b1-473d-a940-2c3a15fc9957 C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} Task: {6F52023A-8583-4A2F-8897-8D0DDA752944} - \Plus-HD-2.3-updater No Task File <==== ATTENTION Task: {71B70DA7-B205-4D15-AF69-8603BF16CBA0} - \EPUpdater No Task File <==== ATTENTION Task: {7B7A5420-7034-43BA-A57B-FC1A6FF8AB58} - \Plus-HD-2.3-enabler No Task File <==== ATTENTION Task: {81F91B00-251E-4352-A217-3ECBB3585831} - \7eca1cd8-2a95-4759-9c0f-ae713062040a-2 No Task File <==== ATTENTION Task: {A2E415A9-3608-4E3E-A566-BB1F440BD94B} - \Plus-HD-2.3-codedownloader No Task File <==== ATTENTION Task: {A3056F46-39FA-464C-8CE5-76CA9BB28BFF} - \Plus-HD-2.3-chromeinstaller No Task File <==== ATTENTION Task: {F918DF09-76C1-4BA6-A67F-A5A0E4FCB875} - \Plus-HD-2.3-firefoxinstaller No Task File <==== ATTENTION HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-21-1772254487-8582296-1865665106-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION! CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00BB2763-6A77-11D0-A535-00C04FD7D062}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00EEBF57-477D-4084-9921-7AB3C2C9459D}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{03C036F1-A186-11D0-824A-00AA005B4383}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0AF10CEC-2ECD-4B92-9581-34F6AE0637F3}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0B91A74B-AD7C-4A9D-B563-29EEF9167172}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0C15D503-D017-47CE-9016-7B3F978721CC}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{1D2680C9-0E2A-469D-B787-065558BC7D43}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{23170F69-40C1-278A-1000-000100020000}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{35786D3C-B075-49B9-88DD-029876E11C01}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{603D3800-BD81-11D0-A3A5-00C04FD706EC}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{6311429E-2F1A-4777-880F-C7289FD10169}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{640167B4-59B0-47A6-B335-A6B3C0695AEA}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{77F419AA-771A-45FF-AC66-7567FA3243D3}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{807C1E6C-1D00-453F-B920-B61BB7CDD997}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{82C588E7-E54B-408C-9F8C-6AF9ADF6F1E9}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{88C6C381-2E85-11D0-94DE-444553540000}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{AB968F1E-E20B-403A-9EB8-72EB0EB6797E}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{AE054212-3535-4430-83ED-D501AA6680E6}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{B155BDF8-02F0-451E-9A26-AE317CFD7779}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{B8967F85-58AE-4F46-9FB2-5D7904798F4B}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{BD84B380-8CA2-1069-AB1D-08000948F534}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{EDB5F444-CB8D-445A-A523-EC5AB6EA33C7}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{F3364BA0-65B9-11CE-A9BA-00AA004AE837}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{FE841493-835C-4FA3-B6CC-B4B2D4719848}\InprocServer32 -> No File Path EmptyTemp: Hosts: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
13.01.2015, 15:30 | #25 |
| Ständig Skriptfehler, PC extrem langsam und viel Werbung Der Pc hat sich automatisch runtergefahren und wieder hoch, hoffe das soll so sein? Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 12-01-2015 01 Ran by Cristian at 2015-01-13 15:22:37 Run:1 Running from C:\Users\Cristian\Desktop Loaded Profile: Cristian (Available profiles: Cristian) Boot Mode: Normal ============================================== Content of fixlist: ***************** CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKU\S-1-5-21-1772254487-8582296-1865665106-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = C:\Users\Cristian\AppData\Roaming\0F0W0T1V0D0L0M C:\Program Files\ef0ef932-01b1-473d-a940-2c3a15fc9957 C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} Task: {6F52023A-8583-4A2F-8897-8D0DDA752944} - \Plus-HD-2.3-updater No Task File <==== ATTENTION Task: {71B70DA7-B205-4D15-AF69-8603BF16CBA0} - \EPUpdater No Task File <==== ATTENTION Task: {7B7A5420-7034-43BA-A57B-FC1A6FF8AB58} - \Plus-HD-2.3-enabler No Task File <==== ATTENTION Task: {81F91B00-251E-4352-A217-3ECBB3585831} - \7eca1cd8-2a95-4759-9c0f-ae713062040a-2 No Task File <==== ATTENTION Task: {A2E415A9-3608-4E3E-A566-BB1F440BD94B} - \Plus-HD-2.3-codedownloader No Task File <==== ATTENTION Task: {A3056F46-39FA-464C-8CE5-76CA9BB28BFF} - \Plus-HD-2.3-chromeinstaller No Task File <==== ATTENTION Task: {F918DF09-76C1-4BA6-A67F-A5A0E4FCB875} - \Plus-HD-2.3-firefoxinstaller No Task File <==== ATTENTION HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-21-1772254487-8582296-1865665106-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION! CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00BB2763-6A77-11D0-A535-00C04FD7D062}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00EEBF57-477D-4084-9921-7AB3C2C9459D}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{03C036F1-A186-11D0-824A-00AA005B4383}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0AF10CEC-2ECD-4B92-9581-34F6AE0637F3}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0B91A74B-AD7C-4A9D-B563-29EEF9167172}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0C15D503-D017-47CE-9016-7B3F978721CC}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{1D2680C9-0E2A-469D-B787-065558BC7D43}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{23170F69-40C1-278A-1000-000100020000}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{35786D3C-B075-49B9-88DD-029876E11C01}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{603D3800-BD81-11D0-A3A5-00C04FD706EC}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{6311429E-2F1A-4777-880F-C7289FD10169}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{640167B4-59B0-47A6-B335-A6B3C0695AEA}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{77F419AA-771A-45FF-AC66-7567FA3243D3}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{807C1E6C-1D00-453F-B920-B61BB7CDD997}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{82C588E7-E54B-408C-9F8C-6AF9ADF6F1E9}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{88C6C381-2E85-11D0-94DE-444553540000}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{AB968F1E-E20B-403A-9EB8-72EB0EB6797E}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{AE054212-3535-4430-83ED-D501AA6680E6}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{B155BDF8-02F0-451E-9A26-AE317CFD7779}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{B8967F85-58AE-4F46-9FB2-5D7904798F4B}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{BD84B380-8CA2-1069-AB1D-08000948F534}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{EDB5F444-CB8D-445A-A523-EC5AB6EA33C7}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{F3364BA0-65B9-11CE-A9BA-00AA004AE837}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{FE841493-835C-4FA3-B6CC-B4B2D4719848}\InprocServer32 -> No File Path EmptyTemp: Hosts: ***************** "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => Key deleted successfully. HKCR\CLSID\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => Key not found. HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. C:\Users\Cristian\AppData\Roaming\0F0W0T1V0D0L0M => Moved successfully. C:\Program Files\ef0ef932-01b1-473d-a940-2c3a15fc9957 => Moved successfully. C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6F52023A-8583-4A2F-8897-8D0DDA752944}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F52023A-8583-4A2F-8897-8D0DDA752944}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-2.3-updater => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{71B70DA7-B205-4D15-AF69-8603BF16CBA0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71B70DA7-B205-4D15-AF69-8603BF16CBA0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7B7A5420-7034-43BA-A57B-FC1A6FF8AB58}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B7A5420-7034-43BA-A57B-FC1A6FF8AB58}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-2.3-enabler => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{81F91B00-251E-4352-A217-3ECBB3585831}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81F91B00-251E-4352-A217-3ECBB3585831}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7eca1cd8-2a95-4759-9c0f-ae713062040a-2" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A2E415A9-3608-4E3E-A566-BB1F440BD94B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A2E415A9-3608-4E3E-A566-BB1F440BD94B}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-2.3-codedownloader => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A3056F46-39FA-464C-8CE5-76CA9BB28BFF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A3056F46-39FA-464C-8CE5-76CA9BB28BFF}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-2.3-chromeinstaller => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F918DF09-76C1-4BA6-A67F-A5A0E4FCB875}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F918DF09-76C1-4BA6-A67F-A5A0E4FCB875}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-2.3-firefoxinstaller => Key not found. "HKU\.DEFAULT\Software\Classes\exefile" => Key deleted successfully. "HKU\.DEFAULT\Software\Classes\.exe" => Key deleted successfully. HKU\.DEFAULT\Software\Classes\exefile => Key not found. "HKU\S-1-5-19\Software\Classes\exefile" => Key deleted successfully. "HKU\S-1-5-19\Software\Classes\.exe" => Key deleted successfully. HKU\S-1-5-19\Software\Classes\exefile => Key not found. "HKU\S-1-5-20\Software\Classes\exefile" => Key deleted successfully. "HKU\S-1-5-20\Software\Classes\.exe" => Key deleted successfully. HKU\S-1-5-20\Software\Classes\exefile => Key not found. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000\Software\Classes\exefile" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00BB2763-6A77-11D0-A535-00C04FD7D062}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{00EEBF57-477D-4084-9921-7AB3C2C9459D}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{03C036F1-A186-11D0-824A-00AA005B4383}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0AF10CEC-2ECD-4B92-9581-34F6AE0637F3}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0B91A74B-AD7C-4A9D-B563-29EEF9167172}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0C15D503-D017-47CE-9016-7B3F978721CC}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{1D2680C9-0E2A-469D-B787-065558BC7D43}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{23170F69-40C1-278A-1000-000100020000}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{35786D3C-B075-49B9-88DD-029876E11C01}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{603D3800-BD81-11D0-A3A5-00C04FD706EC}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{6311429E-2F1A-4777-880F-C7289FD10169}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{640167B4-59B0-47A6-B335-A6B3C0695AEA}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{77F419AA-771A-45FF-AC66-7567FA3243D3}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{807C1E6C-1D00-453F-B920-B61BB7CDD997}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{82C588E7-E54B-408C-9F8C-6AF9ADF6F1E9}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{88C6C381-2E85-11D0-94DE-444553540000}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{AB968F1E-E20B-403A-9EB8-72EB0EB6797E}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{AE054212-3535-4430-83ED-D501AA6680E6}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{B155BDF8-02F0-451E-9A26-AE317CFD7779}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{B8967F85-58AE-4F46-9FB2-5D7904798F4B}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{BD84B380-8CA2-1069-AB1D-08000948F534}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{EDB5F444-CB8D-445A-A523-EC5AB6EA33C7}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{F3364BA0-65B9-11CE-A9BA-00AA004AE837}" => Key deleted successfully. "HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{FE841493-835C-4FA3-B6CC-B4B2D4719848}" => Key deleted successfully. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. EmptyTemp: => Removed 1.5 GB temporary data. The system needed a reboot. ==== End of Fixlog 15:23:16 ==== |
13.01.2015, 16:26 | #26 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ständig Skriptfehler, PC extrem langsam und viel Werbung Und nochmal zwecks Kontrolle neue FRST Logs bitte
__________________ Logfiles bitte immer in CODE-Tags posten |
13.01.2015, 16:45 | #27 |
| Ständig Skriptfehler, PC extrem langsam und viel WerbungFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-01-2015 01 Ran by Cristian (administrator) on HOMEPC on 13-01-2015 16:42:09 Running from C:\Users\Cristian\Desktop Loaded Profile: Cristian (Available profiles: Cristian) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVM Berlin) C:\Program Files\avmwlanstick\WLanNetService.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe () C:\Windows\System32\PSIService.exe (Secunia) C:\Program Files\Secunia\PSI\psia.exe (Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe (OsdMaestro) C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe (AVM Berlin) C:\Program Files\avmwlanstick\WLanGUI.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe () C:\Users\Cristian\Desktop\CMS\EventLogger.exe (Evoluent) C:\Program Files\Evoluent\VMouse\V4\EvoMouseExec.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\schtasks.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe (Hewlett-Packard Company) C:\hp\KBD\kbd.exe (Secunia) C:\Program Files\Secunia\PSI\sua.exe (Microsoft Corporation) C:\Windows\System32\sdclt.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company) HKLM\...\Run: [KBD] => C:\HP\KBD\KbdStub.EXE [65536 2006-12-08] () HKLM\...\Run: [OsdMaestro] => C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [118784 2007-02-15] (OsdMaestro) HKLM\...\Run: [HP Health Check Scheduler] => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [71176 2007-05-24] (Hewlett-Packard) HKLM\...\Run: [SunJavaUpdateReg] => C:\Windows\system32\jureg.exe [54936 2007-04-07] (Sun Microsystems, Inc.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1848648 2009-07-07] (CANON INC.) HKLM\...\Run: [itype] => C:\Program Files\Microsoft IntelliType Pro\itype.exe [1505144 2009-11-05] (Microsoft Corporation) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [AVMWlanClient] => C:\Program Files\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-09-17] (Apple Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4669440 2007-07-06] (Realtek Semiconductor) HKLM\...\RunOnce: [Launcher] => C:\Windows\SMINST\launcher.exe [44168 2007-04-03] (soft thinks) HKLM\...\Policies\Explorer: [NoCDBurning] 0 HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKLM\...\Policies\Explorer: [NoSetTaskbar] 0 HKLM\...\Policies\Explorer: [NoDeletePrinter] 0 HKLM\...\Policies\Explorer: [NoDFSTab] 0 HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0 HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0 HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKLM\...\Policies\Explorer: [NoResolveSearch] 0 HKLM\...\Policies\Explorer: [NoHardwareTab] 0 HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-19\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-19\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-19\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-19\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-19\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-20\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-20\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-20\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-20\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-20\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\RunOnce: [Adobe Speed Launcher] => !’U HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-18\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-18\...\Policies\Explorer: [NoStartMenuSubFolders] 0 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\EventLogger.lnk ShortcutTarget: EventLogger.lnk -> C:\Users\Cristian\Desktop\CMS\EventLogger.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Evoluent Mouse Manager.lnk ShortcutTarget: Evoluent Mouse Manager.lnk -> C:\Windows\Installer\{AD6E0AE0-DADF-480E-82AE-4CDA6035D341}\_BBBCF44DDE3DA1E118ADB6.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia) Startup: C:\Users\Cristian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 2510 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 2510 series.lnk -> C:\Program Files\HP\HP Deskjet 2510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/?LinkId=69157 HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://www.google.com HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://www.google.com HKU\S-1-5-21-1772254487-8582296-1865665106-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKU\S-1-5-21-1772254487-8582296-1865665106-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> DefaultScope {0997A1DF-9518-4A18-A389-2C0497952326} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {0997A1DF-9518-4A18-A389-2C0497952326} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {56FB9A98-C2C7-4C40-8187-FD09EDBBBDE9} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {63250AB7-8D89-40E1-9345-055F753AAD3B} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {6B77EBF6-3C4A-4516-B673-30A5AF0C4C74} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> {99039AFC-4C2F-4AA4-93C3-96192296CA29} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation) Toolbar: HKU\S-1-5-21-1772254487-8582296-1865665106-1000 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {16BC6A51-9F62-49E3-9F96-C842EF2FFE3E} hxxp://www.eytronserver.com/CAB/WebPlayer.cab DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} hxxp://o.aolcdn.com/pictures/ap/Resources/v2.14/cab/aolpPlugins.10.6.0.8.cab DPF: {29DFBD41-3B7D-4368-9021-894C5A30E054} hxxp://www.eytronserver.com/CAB/RemoteWeb.cab DPF: {54CFC975-F9FB-45EB-8D18-D2D04FBC4299} hxxp://www.eytronserver.com/CAB/RemoteWeb2.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} hxxp://www.lokalisten.de/iup/ImageUploader4.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} hxxp://upload.lokalisten.de/iup/ImageUploader6.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab DPF: {BF5453EA-7EF7-4946-8421-8F002870A5ED} hxxp://eytronserver.com/CAB2/JMNVSClientWeb.cab DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab DPF: {CF1572D7-C2DB-456A-8F56-CFAAA4C79251} hxxp://www.eytronserver.com/CAB/WEB_BACKUP2.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} hxxp://www.lokalisten.de/iup/ImageUploader4.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Cristian\AppData\Roaming\Mozilla\Firefox\Profiles\e0a8z0de.default-1420726666714 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @innoplus.de/ino3DViewer -> C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll No File FF Plugin: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1772254487-8582296-1865665106-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-1772254487-8582296-1865665106-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-22] FF HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR Profile: C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-07] CHR Extension: (YouTube) - C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-07] CHR Extension: (Google-Suche) - C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-07] CHR Extension: (Google Wallet) - C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-15] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AVM WLAN Connection Service; C:\Program Files\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed] R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [61440 2007-05-24] (Hewlett-Packard) [File not signed] R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed] S3 IDriverT; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed] R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed] R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1227800 2013-04-18] (Secunia) R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [659992 2013-04-18] (Secunia) S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2010-10-01] (AVM Berlin) [File not signed] R3 AVMWAN; C:\Windows\System32\DRIVERS\avmwan.sys [29968 2001-11-08] (AVM Berlin) [File not signed] R3 EvoMouseDriverFilterHidUsb; C:\Windows\System32\DRIVERS\EvoMouseDriverFilterHidUsb.sys [22712 2010-06-23] (Evoluent) R3 EvoMouseDriverMini; C:\Windows\System32\drivers\EvoMouseDriverMini.sys [20024 2010-06-23] () R3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [926080 2010-10-01] (AVM GmbH) S3 fxusbase; C:\Windows\System32\DRIVERS\fxusbase.sys [488656 2001-11-08] (AVM Berlin) [File not signed] S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [30464 2013-07-09] () S3 LFXACT; C:\Windows\System32\Drivers\LFXACT.sys [20672 2007-01-09] (OEM) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-04-18] (Secunia) R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2008-01-22] (Acronis) S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-01] (America Online, Inc.) S3 WlanUIG; C:\Windows\System32\DRIVERS\2862w.sys [346944 2004-04-06] (SMC Networks, Inc.) [File not signed] S3 XMLDIUSB; C:\Windows\System32\Drivers\XMLDIUSB.sys [31879 2007-01-09] (OEM) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] U0 SR; No ImagePath U2 srservice; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-13 13:05 - 2015-01-13 13:05 - 00000661 _____ () C:\Users\Cristian\Desktop\Revo Uninstaller.lnk 2015-01-13 13:04 - 2015-01-13 13:04 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Cristian\Desktop\revosetup95.exe 2015-01-13 11:07 - 2015-01-13 14:17 - 00042203 _____ () C:\Users\Cristian\Desktop\Addition.txt 2015-01-13 11:06 - 2015-01-13 16:42 - 00025658 _____ () C:\Users\Cristian\Desktop\FRST.txt 2015-01-13 11:04 - 2015-01-13 11:04 - 00000551 _____ () C:\Users\Cristian\Desktop\ComboFix - Verknüpfung.lnk 2015-01-13 11:04 - 2015-01-13 11:04 - 00000551 _____ () C:\Users\Cristian\Desktop\ComboFix - Verknüpfung (2).lnk 2015-01-12 16:49 - 2015-01-12 16:49 - 01115648 _____ (Farbar) C:\Users\Cristian\Desktop\FRST(1).exe 2015-01-12 16:48 - 2015-01-12 16:48 - 00000805 _____ () C:\Users\Cristian\Desktop\JRT.txt 2015-01-12 16:44 - 2015-01-12 16:44 - 01707939 _____ (Thisisu) C:\Users\Cristian\Downloads\JRT.exe 2015-01-12 15:49 - 2015-01-12 16:36 - 00000000 ____D () C:\AdwCleaner 2015-01-12 15:48 - 2015-01-12 15:49 - 02191360 _____ () C:\Users\Cristian\Desktop\AdwCleaner_4.107.exe 2015-01-12 15:34 - 2015-01-12 15:34 - 00022740 _____ () C:\ComboFix.txt 2015-01-12 15:09 - 2015-01-12 15:35 - 00000000 ____D () C:\ComboFix 2015-01-12 15:09 - 2015-01-12 15:34 - 00000000 ____D () C:\Qoobox 2015-01-12 15:09 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-01-12 15:09 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-01-12 15:09 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2015-01-12 15:09 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2015-01-12 15:08 - 2015-01-12 15:33 - 00000000 ____D () C:\Windows\erdnt 2015-01-12 15:08 - 2015-01-12 15:08 - 05609736 ____R (Swearware) C:\Users\Cristian\Downloads\ComboFix.exe 2015-01-12 14:21 - 2015-01-12 14:22 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-01-12 14:12 - 2015-01-12 14:12 - 00583256 _____ () C:\Users\Cristian\Downloads\Installation.exe 2015-01-12 13:33 - 2015-01-12 15:25 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2015-01-12 12:45 - 2015-01-12 12:45 - 16448208 _____ (Malwarebytes Corp.) C:\Users\Cristian\Downloads\mbar-1.08.2.1001(1).exe 2015-01-12 12:38 - 2015-01-12 14:37 - 00000000 ____D () C:\Users\Cristian\Desktop\mbar 2015-01-12 12:37 - 2015-01-12 12:37 - 16448208 _____ (Malwarebytes Corp.) C:\Users\Cristian\Downloads\mbar-1.08.2.1001.exe 2015-01-12 12:27 - 2015-01-12 12:27 - 00000159 _____ () C:\Users\Cristian\Desktop\Malwareprotokoll.txt 2015-01-12 12:06 - 2015-01-12 12:08 - 00048718 _____ () C:\Users\Cristian\Downloads\Addition.txt 2015-01-12 12:04 - 2015-01-13 16:42 - 00000000 ____D () C:\FRST 2015-01-12 12:04 - 2015-01-12 16:50 - 00036775 _____ () C:\Users\Cristian\Downloads\FRST.txt 2015-01-12 12:04 - 2015-01-12 12:04 - 01115648 _____ (Farbar) C:\Users\Cristian\Desktop\FRST.exe 2015-01-12 10:59 - 2015-01-12 11:07 - 00000000 ____D () C:\Users\Cristian\Desktop\Alle privaten Fotos 2015-01-05 22:32 - 2015-01-05 22:32 - 00000000 ____D () C:\ProgramData\dfhndngfkikbamohhepblbjlemgbjooa 2014-12-22 10:09 - 2014-12-22 10:09 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CdCoverCreator 2014-12-22 10:09 - 2014-12-22 10:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CdCoverCreator 2014-12-22 10:08 - 2015-01-12 11:26 - 00000000 ____D () C:\Program Files\CHIP Updater 2014-12-22 10:08 - 2014-12-22 10:09 - 00000000 ____D () C:\Users\Cristian\AppData\Local\Abelssoft 2014-12-22 10:08 - 2014-12-22 10:08 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\Abelssoft 2014-12-22 10:08 - 2014-12-22 10:08 - 00000000 ____D () C:\ProgramData\XDMessagingv4 2014-12-22 10:07 - 2014-12-22 10:07 - 01174352 _____ () C:\Users\Cristian\Downloads\CdCoverCreator - CHIP-Installer.exe 2014-12-17 15:25 - 2015-01-12 11:36 - 00000000 ____D () C:\ProgramData\Freemake 2014-12-17 15:25 - 2014-12-17 15:33 - 00000000 ____D () C:\Users\Cristian\Documents\Freemake 2014-12-17 14:48 - 2014-12-17 14:48 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\TuneUp Software 2014-12-17 14:48 - 2014-12-17 14:48 - 00000000 ____D () C:\Users\Cristian\AppData\Local\TuneUp Software 2014-12-17 14:47 - 2014-12-18 11:02 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-12-17 14:45 - 2015-01-12 10:15 - 00018872 _____ () C:\Windows\system32\Drivers\SPPD.sys 2014-12-17 14:18 - 2014-12-17 14:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo 2014-12-17 14:18 - 2014-12-17 14:31 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-12-17 14:18 - 2014-12-17 14:18 - 00000000 ____D () C:\Users\Cristian\AppData\Local\Ashampoo Movie Studio 2013 ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-13 15:40 - 2011-06-27 06:03 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-13 15:32 - 2007-11-29 14:41 - 01738546 _____ () C:\Windows\WindowsUpdate.log 2015-01-13 15:26 - 2007-11-20 21:26 - 00000000 ____D () C:\Windows\SMINST 2015-01-13 15:25 - 2012-05-30 20:08 - 00092278 _____ () C:\Windows\PFRO.log 2015-01-13 15:25 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-13 15:25 - 2006-11-02 13:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-13 15:25 - 2006-11-02 13:47 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-13 15:23 - 2006-11-02 14:01 - 00032560 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-12 16:37 - 2012-05-28 10:17 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-01-12 16:36 - 2013-07-04 20:41 - 00001101 _____ () C:\Users\Cristian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2015-01-12 15:34 - 2006-11-02 12:18 - 00000000 __RHD () C:\Users\Default 2015-01-12 15:34 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public 2015-01-12 15:28 - 2006-11-02 11:23 - 00000215 _____ () C:\Windows\system.ini 2015-01-12 15:24 - 2006-11-02 11:22 - 66584576 _____ () C:\Windows\system32\config\SYSTEM.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 65011712 _____ () C:\Windows\system32\config\SOFTWARE.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 55574528 _____ () C:\Windows\system32\config\COMPON~1.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2015-01-12 15:24 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\DEFAULT.bak 2015-01-12 15:21 - 2010-10-31 16:30 - 00000000 ____D () C:\Program Files\7-Zip 2015-01-12 14:16 - 2014-05-19 07:57 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-12 14:15 - 2014-05-19 07:56 - 00079576 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-12 14:09 - 2008-01-15 10:27 - 00111960 _____ () C:\Users\Cristian\AppData\Local\GDIPFONTCACHEV1.DAT 2015-01-12 14:08 - 2007-11-20 20:52 - 00000000 ____D () C:\Windows\system32\RTCOM 2015-01-12 14:06 - 2006-11-02 13:47 - 00410136 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-12 11:50 - 2007-11-20 20:56 - 00000000 ____D () C:\Program Files\Roxio 2015-01-12 11:50 - 2007-11-20 20:55 - 00000000 ____D () C:\Program Files\Common Files\Roxio Shared 2015-01-12 11:40 - 2007-11-20 20:52 - 00319456 _____ (Microsoft Corporation) C:\Windows\DIFxAPI.dll 2015-01-12 11:40 - 2007-11-20 20:52 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2015-01-12 11:38 - 2009-03-19 14:57 - 00000000 ____D () C:\Program Files\Sigel 2015-01-12 11:34 - 2011-08-20 20:06 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\DVDVideoSoft 2015-01-12 11:34 - 2011-08-20 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-01-12 11:30 - 2010-12-23 19:36 - 00000000 ____D () C:\Program Files\Canon 2015-01-12 11:29 - 2010-12-23 19:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities 2015-01-12 11:27 - 2014-09-22 08:21 - 00000000 ____D () C:\Program Files\dm 2015-01-12 11:26 - 2008-01-15 10:21 - 00000000 ____D () C:\Users\Cristian 2015-01-12 11:23 - 2014-09-21 17:01 - 00000000 ____D () C:\ProgramData\tmp 2015-01-12 11:06 - 2013-11-27 09:19 - 00000000 ____D () C:\Users\Cristian\Desktop\Reichwein 2015-01-12 11:05 - 2013-11-27 09:30 - 00000000 ____D () C:\Users\Cristian\Desktop\Scheidl 2015-01-12 11:03 - 2013-11-27 09:27 - 00000000 ____D () C:\Users\Cristian\Desktop\ZurbackstubnFotos 2015-01-06 04:36 - 2009-10-04 17:50 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-12-19 15:38 - 2008-01-22 13:33 - 00027136 _____ () C:\Users\Cristian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-12-18 13:04 - 2012-07-26 12:38 - 00005806 _____ () C:\Windows\setupact.log 2014-12-17 15:11 - 2010-10-26 12:03 - 00000000 ____D () C:\Users\Cristian\AppData\Roaming\vlc 2014-12-17 14:50 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Sidebar 2014-12-17 14:27 - 2009-06-06 17:49 - 00000000 ____D () C:\Users\Cristian\Documents\DVDVideoSoft ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-13 15:32 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-01-2015 01 Ran by Cristian at 2015-01-13 16:42:56 Running from C:\Users\Cristian\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 32 Bit HP CIO Components Installer (Version: 1.0.0 - Hewlett-Packard) Hidden 3D-Viewer-innoplus (HKLM\...\{B96DB037-DBEA-4186-9081-9CBD537F82E8}) (Version: 13.01.07 - INNOVA-engineering GmbH) 4500_Help (Version: 1.00.0000 - Hewlett-Packard) Hidden 6300 (Version: 82.0.242.000 - Hewlett-Packard) Hidden 6300_Help (Version: 82.0.242.000 - Hewlett-Packard) Hidden 6300Trb (Version: 82.0.242.000 - Hewlett-Packard) Hidden 7-Zip 4.65 (HKLM\...\7-Zip) (Version: - ) ActiveCheck component for HP Active Support Library (Version: 3.0.0.2 - Hewlett-Packard) Hidden Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.8.0.1430 - Adobe Systems Incorporated) Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader X (10.1.13) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.13 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM\...\{0099B484-C24C-4D5F-8167-B0F6DF196E72}) (Version: 12.0.3.133 - Adobe Systems, Inc) Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.) AIO_CDB_ProductContext (Version: 82.0.242.000 - Hewlett-Packard) Hidden AIO_CDB_Software (Version: 82.0.242.000 - Hewlett-Packard) Hidden AIO_Scan (Version: 82.0.173.000 - Hewlett-Packard) Hidden Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{0592EF96-69D8-4E4B-9CC9-88F58EA86F01}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) AVM FRITZ!WLAN (HKLM\...\AVMWLANCLI) (Version: - AVM Berlin) BPD_HPSU (Version: 1.00.0000 - Hewlett-Packard) Hidden bpd_scan (Version: 3.00.0000 - Hewlett-Packard) Hidden BPDSoftware (Version: 50.0.165.000 - Hewlett-Packard) Hidden BPDSoftware_Ini (Version: 1.00.0000 - Hewlett-Packard) Hidden BufferChm (Version: 100.0.170.000 - Hewlett-Packard) Hidden Canon iP3600 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP3600_series) (Version: - ) Canon Utilities Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version: - ) Canon Utilities My Printer (HKLM\...\CanonMyPrinter) (Version: - ) Copy (Version: 82.0.188.000 - Hewlett-Packard) Hidden CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden Destination Component (Version: 100.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (Version: 100.0.190.000 - Hewlett-Packard) Hidden DHTML Editing Component (HKLM\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation) DocMgr (Version: 100.0.201.000 - Hewlett-Packard) Hidden DocProc (Version: 10.0.0.0 - Hewlett-Packard) Hidden Evoluent Mouse Manager (HKLM\...\{AD6E0AE0-DADF-480E-82AE-4CDA6035D341}) (Version: 4.0.0 - Evoluent) Fax (Version: 100.0.187.000 - Hewlett-Packard) Hidden Google Chrome (HKU\S-1-5-21-1772254487-8582296-1865665106-1000\...\Google Chrome) (Version: 39.0.2171.65 - Google Inc.) Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden GPBaseService (Version: 100.0.187.000 - Hewlett-Packard) Hidden GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden HP Customer Experience Enhancements (HKLM\...\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}) (Version: 5.2.0.2296 - Hewlett-Packard) HP Customer Participation Program 10.0 (HKLM\...\HPExtendedCapabilities) (Version: 10.0 - HP) HP Deskjet 2510 series - Grundlegende Software für das Gerät (HKLM\...\{A3B40F90-312F-497B-A631-D0C7D37D7C59}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) HP Deskjet 2510 series Hilfe (HKLM\...\{07B48D2C-E60D-41E6-B546-11D128F633EC}) (Version: 27.0.0 - Hewlett Packard) HP Deskjet 2510 series Setup Guide (HKLM\...\{216C7F38-4BBC-4E9A-8392-C9FA21B54386}) (Version: 27.0.0 - Hewlett Packard) HP Document Manager 1.0 (HKLM\...\HP Document Manager) (Version: 1.0 - HP) HP Easy Setup - Frontend (HKLM\...\{40F7AED3-0C7D-4582-99F6-484A515C73F2}) (Version: 5.2.0.2304 - Hewlett-Packard) HP Imaging Device Functions 10.0 (HKLM\...\HP Imaging Device Functions) (Version: 10.0 - HP) HP Officejet J4500 Series (HKLM\...\{CD0773D5-C18E-495c-B39B-21A96415EDD5}) (Version: 1.0 - HP) HP On-Screen Cap/Num/Scroll Lock Indicator (HKLM\...\OsdMaestro) (Version: - Hewlett-Packard) HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.7702 - HP) HP Photosmart Essential 2.01 (HKLM\...\HP Photosmart Essential) (Version: 2.01 - HP) HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (HKLM\...\{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}) (Version: 8.0 - HP) HP Smart Web Printing (HKLM\...\HP Smart Web Printing) (Version: 3.5 - HP) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Update (HKLM\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) HPAsset component for HP Active Support Library (Version: 3.0.2.2 - Hewlett-Packard) Hidden HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden iCloud (HKLM\...\{5DDB3393-E08B-447E-925F-6C00B95D0FE7}) (Version: 2.1.1.3 - Apple Inc.) iTunes (HKLM\...\{DF9C119C-7F26-45B9-93D4-7C372CBBBA11}) (Version: 11.1.0.126 - Apple Inc.) J4500 (Version: 50.0.165.000 - Ihr Firmenname) Hidden Java 7 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle) JPEG2000 Dual Codec Software (HKLM\...\{EFECCA45-A5FA-4656-B0D8-89089A1BE0AA}) (Version: 1.0 - ) LightScribe 1.8.15.1 (Version: 1.8.15.1 - Ihr Firmenname) Hidden Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) MarketResearch (Version: 100.0.170.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - ) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft IntelliType Pro 7.1 (HKLM\...\{11E94FDB-C895-45F1-B756-1C9B8C36C8F1}) (Version: 7.10.344.0 - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007-Testversion (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE) (Version: - Microsoft Corporation) Microsoft Works (HKLM\...\{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}) (Version: 08.05.0822 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mozilla Firefox 34.0.5 (x86 de) (HKLM\...\Mozilla Firefox 34.0.5 (x86 de)) (Version: 34.0.5 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSVCSetup (Version: 1.00.0000 - HP) Hidden MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) Optimierte Multimedia-Tastatur-Lösung (HKLM\...\KBD) (Version: - Hewlett-Packard) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.) ProductContext (Version: 50.0.165.000 - Hewlett-Packard) Hidden PSSWCORE (Version: 2.01.0000 - Hewlett-Packard) Hidden Python 2.5 (HKLM\...\{0A2C5854-557E-48C8-835A-3B9F074BDCAA}) (Version: 2.5.150 - Martin v. Löwis) QuickTime (HKLM\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - ) Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Roxio Creator Copy (HKLM\...\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.4.0 - Roxio) Roxio Creator Data (HKLM\...\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.4.0 - Roxio) Roxio Creator EasyArchive (HKLM\...\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}) (Version: 3.4.0 - Roxio) Roxio Creator Tools (HKLM\...\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.4.0 - Roxio) Scan (Version: 10.1.0.0 - Hewlett-Packard) Hidden Secunia PSI (3.0.0.7009) (HKLM\...\Secunia PSI) (Version: 3.0.0.7009 - Secunia) Shockwave (HKLM\...\Shockwave) (Version: - ) SmartWebPrintingOC (Version: 100.0.189.000 - Hewlett-Packard) Hidden SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden Status (Version: 100.0.175.000 - Hewlett-Packard) Hidden Studie zur Verbesserung von HP Deskjet 2510 series Produkten (HKLM\...\{CDE2DEBC-B8AD-41A2-AE45-A8CE9A41EF8F}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Toolbox (Version: 100.0.170.000 - Hewlett-Packard) Hidden Toolbox (Version: 82.0.173.000 - Hewlett-Packard) Hidden TrayApp (Version: 100.0.170.000 - Hewlett-Packard) Hidden UnloadSupport (Version: 1.00.0000 - Hewlett-Packard) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VideoToolkit01 (Version: 90.0.146.000 - Hewlett-Packard) Hidden VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN) WebReg (Version: 100.0.170.000 - Hewlett-Packard) Hidden Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.135\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.99\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.5\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{218D2740-5A50-42A8-AB9F-62FF1B168782}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.69\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{320F0FDB-BE0A-4648-9D18-4A2C3448C007}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.79\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.23.9\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Chrome\Application\39.0.2171.65\delegate_execute.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.145\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.123\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.153\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServer32 -> C:\Windows\system32\urlmon.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.24.15\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.149\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.22.3\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.165\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.115\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{EB06378B-ABB6-4B3C-9B40-D488DD8A6E93}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.22.5\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.21.111\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1772254487-8582296-1865665106-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Cristian\AppData\Local\Google\Update\1.3.24.7\psuser.dll No File ==================== Restore Points ========================= 30-12-2014 00:00:06 Geplanter Prüfpunkt 30-12-2014 19:32:59 Windows Update 01-01-2015 00:00:06 Geplanter Prüfpunkt 02-01-2015 00:00:06 Geplanter Prüfpunkt 03-01-2015 00:00:10 Geplanter Prüfpunkt 04-01-2015 00:00:07 Geplanter Prüfpunkt 05-01-2015 00:00:05 Geplanter Prüfpunkt 06-01-2015 00:00:06 Geplanter Prüfpunkt 06-01-2015 08:34:39 Windows Update 07-01-2015 00:00:12 Geplanter Prüfpunkt 07-01-2015 02:47:18 Windows Defender Checkpoint 08-01-2015 00:00:09 Geplanter Prüfpunkt 12-01-2015 10:35:10 Windows Update 12-01-2015 11:28:33 Removed Bonjour 12-01-2015 11:32:20 Entfernt dakota.ag 12-01-2015 11:36:33 Removed Lexware Info Service. 12-01-2015 11:41:03 Removed RTC Client API v1.2 12-01-2015 11:42:39 Removed Roxio MyDVD Basic v9 12-01-2015 11:52:04 TuneUp Utilities 2014 wird entfernt 12-01-2015 11:53:12 TuneUp Utilities 2014 (de-DE) wird entfernt 12-01-2015 14:00:19 Malwarebytes Anti-Rootkit Restore Point 13-01-2015 13:06:34 Revo Uninstaller's restore point - Picasa Packages 13-01-2015 13:31:26 Revo Uninstaller's restore point - Picasa Packages 13-01-2015 13:34:51 Revo Uninstaller's restore point - Snap.Do 13-01-2015 13:35:11 Removed Snap.Do 13-01-2015 13:37:37 Revo Uninstaller's restore point - Snap.Do Engine 13-01-2015 13:39:35 Revo Uninstaller's restore point - UpgradeStance ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 11:23 - 2015-01-13 15:22 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {146CC7F1-4B47-4F95-A5B8-2EC0C2D6EE07} - System32\Tasks\Microsoft_Hardware_Launch_IType_exe => C:\Program Files\Microsoft IntelliType Pro\IType.exe [2009-11-05] (Microsoft Corporation) Task: {205AE3E8-DB28-4703-A3B3-F0DA74E7EBBF} - System32\Tasks\RecoveryCD => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-05-17] () Task: {2C0B4CE0-7836-4049-A6B5-D9E791DD6B06} - System32\Tasks\HP Health Check => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2007-05-24] (Hewlett-Packard) Task: {621536AC-9241-4203-B4F4-002AB26F46CF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1772254487-8582296-1865665106-1000UA => C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-19] (Google Inc.) Task: {7715F03D-398E-4875-B39D-12C8D5AEE73F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-21] (Adobe Systems Incorporated) Task: {85BDE8BD-0C9C-4672-B693-EE931B666872} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-04] (Google Inc.) Task: {89A435BF-CCA2-4D6D-BDE0-7695142B981D} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files\CHIP Updater\CHIPUpdater.exe Task: {8ED6C316-C98E-43E4-A29F-5CB447DD9375} - System32\Tasks\{A5B8BB3E-DCB6-4F73-A1E6-D7B14E616081} => pcalua.exe -a "C:\Program Files\Webroot\WRSA.exe" -c -uninstall Task: {98DD3500-6AF6-483F-937F-F076B631E27A} - System32\Tasks\JavaUpdateAdministrator => C:\Windows\system32\jusched.exe Task: {B046B8D3-B880-44CE-B7D2-351DCA2AD8B5} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1772254487-8582296-1865665106-1000Core => C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-19] (Google Inc.) Task: {B148C776-5662-4CC8-86BF-936CFB3E2F20} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Cristian => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation) Task: {B4FD720C-38A7-4279-9DD2-A9EF3679C1A8} - System32\Tasks\HPCustParticipation HP Deskjet 2510 series => C:\Program Files\HP\HP Deskjet 2510 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.) Task: {BCE50F3A-5158-4353-ACA6-2739922780E4} - System32\Tasks\JavaUpdateCristian => C:\Windows\system32\jusched.exe Task: {D5E75031-DD6F-4FDF-9EEC-4C5553072652} - System32\Tasks\JavaUpdateAdmin => C:\Windows\system32\jusched.exe Task: {FC26B1A7-902B-49E8-A903-BAAC992A7E3D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-04] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1772254487-8582296-1865665106-1000Core.job => C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1772254487-8582296-1865665106-1000UA.job => C:\Users\Cristian\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2008-08-28 10:09 - 2007-07-30 05:19 - 00040960 _____ () C:\Windows\System32\LFXPJL2K.DLL 2011-09-27 06:23 - 2011-09-27 06:23 - 00087912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2011-09-27 06:22 - 2011-09-27 06:22 - 01242472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2007-06-05 12:20 - 2007-06-05 12:20 - 00177704 _____ () C:\Windows\system32\PSIService.exe 2013-11-20 08:28 - 2007-12-27 21:33 - 00540672 _____ () C:\Users\Cristian\Desktop\cms\EventLogger.exe 2013-11-20 08:28 - 2007-11-28 09:33 - 00102400 _____ () C:\Users\Cristian\Desktop\cms\RemoteSocket.dll 2013-11-20 08:28 - 2007-12-27 21:31 - 00163840 _____ () C:\Users\Cristian\Desktop\cms\eventlogger.dll 2013-11-20 08:28 - 2007-01-17 15:14 - 00386464 _____ () C:\Users\Cristian\Desktop\cms\sqlite.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Cristian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk => C:\Windows\pss\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" ========================= Accounts: ========================== Administrator (S-1-5-21-1772254487-8582296-1865665106-500 - Administrator - Disabled) ASPNET (S-1-5-21-1772254487-8582296-1865665106-1002 - Limited - Enabled) Cristian (S-1-5-21-1772254487-8582296-1865665106-1000 - Administrator - Enabled) => C:\Users\Cristian Gast (S-1-5-21-1772254487-8582296-1865665106-501 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/13/2015 01:39:35 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {166dd7df-f552-4c01-bc0d-04b580900594} Error: (01/13/2015 01:37:37 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {166dd7df-f552-4c01-bc0d-04b580900594} Error: (01/13/2015 01:34:50 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {166dd7df-f552-4c01-bc0d-04b580900594} Error: (01/13/2015 01:31:26 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {166dd7df-f552-4c01-bc0d-04b580900594} Error: (01/13/2015 01:06:30 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {166dd7df-f552-4c01-bc0d-04b580900594} System errors: ============= Error: (01/13/2015 03:26:48 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: i8042prt Error: (01/13/2015 03:26:48 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: HP CUE DeviceDiscovery Service Error: (01/13/2015 03:26:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (01/13/2015 03:25:14 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 412) (User: NT-AUTORITÄT) Description: 2147942402 Error: (01/13/2015 08:47:47 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793} Microsoft Office Sessions: ========================= Error: (06/29/2013 08:01:20 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 522231 seconds with 4980 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2015-01-13 16:42:48.432 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 16:42:47.293 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 16:42:46.544 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 16:42:45.796 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 16:42:21.881 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\hitmanpro37.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 16:42:21.132 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\hitmanpro37.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 16:42:20.383 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\hitmanpro37.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 16:42:19.619 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\hitmanpro37.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 14:16:55.077 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-13 14:16:54.313 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: AMD Athlon(tm) 64 Processor 4000+ Percentage of memory in use: 51% Total physical RAM: 1917.82 MB Available physical RAM: 937.24 MB Total Pagefile: 4082.09 MB Available Pagefile: 3085.14 MB Total Virtual: 2047.88 MB Available Virtual: 1909.61 MB ==================== Drives ================================ Drive c: (HP) (Fixed) (Total:141.75 GB) (Free:39.07 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (FACTORY_IMAGE) (Fixed) (Total:7.3 GB) (Free:0.77 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 149.1 GB) (Disk ID: 1549F232) Partition 1: (Active) - (Size=141.8 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=7.3 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
13.01.2015, 16:58 | #28 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ständig Skriptfehler, PC extrem langsam und viel Werbung Okay, dann Kontrollscans mit MBAM und ESET bitte: Downloade Dir bitte Malwarebytes Anti-Malware
ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
14.01.2015, 08:25 | #29 |
| Ständig Skriptfehler, PC extrem langsam und viel Werbung Guten Morgen, Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 13.01.2015 Suchlauf-Zeit: 17:48:18 Logdatei: mbam.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2015.01.13.13 Rootkit Datenbank: v2015.01.07.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows Vista Service Pack 2 CPU: x86 Dateisystem: NTFS Benutzer: Cristian Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 334298 Verstrichene Zeit: 13 Min, 31 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 0 (Keine schädliche Elemente erkannt) Registrierungswerte: 0 (Keine schädliche Elemente erkannt) Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 4 PUP.Optional.CrossRider.A, C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0, Keine Aktion durch Benutzer, [e70ac92dc0c9dc5a7dd7aa931be8a060], PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect, Keine Aktion durch Benutzer, [1ed345b1aadfbc7af1c8163461a2fa06], PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect\SearchProtect, Keine Aktion durch Benutzer, [1ed345b1aadfbc7af1c8163461a2fa06], PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect\SearchProtect\rep, Keine Aktion durch Benutzer, [1ed345b1aadfbc7af1c8163461a2fa06], Dateien: 10 PUP.Optional.ClickYes, C:\Users\Cristian\Downloads\Installation.exe, Keine Aktion durch Benutzer, [50a1e70f1b6e9d99506a7791bb477a86], PUP.Optional.InstallCore, C:\Users\Cristian\Downloads\ZipOpenerSetup.exe, Keine Aktion durch Benutzer, [b63bdd191c6d76c0b53eb877b150bd43], PUP.Optional.SmartBar, C:\Windows\Installer\7d378c.msi, Keine Aktion durch Benutzer, [cb268b6b761368ce72119a9447b98e72], PUP.Optional.SmartBar.A, C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_amfclgbdpgndipgoegfpkkgobahigbcl_0.localstorage, Keine Aktion durch Benutzer, [e70a91655039fb3ba4d7046e966de020], PUP.Optional.CrossRider.A, C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0.localstorage, Keine Aktion durch Benutzer, [628f9e584e3bba7cbbc0bce622e1fa06], PUP.Optional.CrossRider.A, C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0\3, Keine Aktion durch Benutzer, [e70ac92dc0c9dc5a7dd7aa931be8a060], PUP.Optional.CrossRider.A, C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0\4, Keine Aktion durch Benutzer, [e70ac92dc0c9dc5a7dd7aa931be8a060], PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, Keine Aktion durch Benutzer, [1ed345b1aadfbc7af1c8163461a2fa06], PUP.Optional.Trovi.A, C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M60E790E7-6B03-4F8B-84ED-A989B26B400A&SearchSource=55&CUI=&UM=8&UP=SPE607B2D3-84A5-4D83-96F3-35FAB7FDD3C9&SSPV=" ],), Keine Aktion durch Benutzer,[fef36a8c79100e28e56e438a42c38a76] PUP.Optional.Trovi.A, C:\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M60E790E7-6B03-4F8B-84ED-A989B26B400A&SearchSource=55&CUI=&UM=8&UP=SPE607B2D3-84A5-4D83-96F3-35FAB7FDD3C9&SSPV=",), Keine Aktion durch Benutzer,[737e6a8c6c1d9d995afa8944ed18c43c] Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=19c8eb468f12f64aa3335a55cd224469 # engine=21947 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-01-13 06:20:03 # local_time=2015-01-13 07:20:03 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode_1='' # compatibility_mode=5892 16776574 100 100 26263 258705931 0 0 # scanned=187653 # found=36 # cleaned=35 # scan_time=3921 sh=3F3FE6FA3876FAFC6387C29C55AEBD4D34F9043A ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Users\All Users\dfhndngfkikbamohhepblbjlemgbjooa\WL.js" sh=D76C173756A50E3FC56F42FB50D33FACDC9A4AB7 ft=1 fh=2a02195397d30d3a vn="Variante von Win32/Adware.SpeedingUpMyPC.C Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Optimizer Pro 3.13\OptProSmartScan.exe.vir" sh=7B23412A65A3F1005E9C48949885CD831E1C0647 ft=1 fh=985e28a05a3d1725 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Super Radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-11.exe.vir" sh=E1AAF9171928E13CD479688F46DD4A82D47329B1 ft=1 fh=0d5456a8feb54bf0 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Super Radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-4.exe.vir" sh=E411F313C879C9B69FA12E377C2FD8AD2E51DC54 ft=1 fh=6ebfde842dee39d4 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Super Radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-5.exe.vir" sh=F085FE77EA6E4870C48057B08E850785BEC5CA74 ft=1 fh=274efd6ec63b652c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Super Radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-6.exe.vir" sh=257669513A7A183D6FF078945FF9E76B9E56B226 ft=1 fh=c26e22a0dc80cb1b vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Super Radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-7.exe.vir" sh=95D4DBA255DF108A1988D3D1DD45E0FCFE627481 ft=1 fh=79094dba718c7c3a vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Super Radio\Super Radio-bg.exe.vir" sh=EA333C25E7A0CE769126776C05A12D3CF006F3AD ft=1 fh=330ab6924b1b6359 vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Super Radio\Super Radio-bho.dll.vir" sh=8087BB78E386EC6164D83BDD0063C363FC1B7698 ft=1 fh=f2d1ab3f17e38ab7 vn="Variante von Win32/Toolbar.CrossRider.BD evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Super Radio\Super Radio-buttonutil.dll.vir" sh=3FC075B4F38798E1D16682E41171A9AFB2D7A172 ft=1 fh=26694d3acaec8475 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Super Radio\Super Radio-buttonutil.exe.vir" sh=257669513A7A183D6FF078945FF9E76B9E56B226 ft=1 fh=c26e22a0dc80cb1b vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Super Radio\Super Radio-codedownloader.exe.vir" sh=7FAAC1751D7478685BD5ABEF23D2941447CC1BE0 ft=1 fh=0a1672fce62ca1a3 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Super Radio\Uninstall.exe.vir" sh=BFA8F875E89FD85CAFCFC70EB4B736B03C63E307 ft=1 fh=4473aa22b04f63ec vn="Win32/Packed.VMDetector.I evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Super Radio\utils.exe.vir" sh=193536221FB836117EF926D5E1E724B7A908EB38 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Cristian\AppData\Roaming\Mozilla\Firefox\Profiles\e0a8z0de.default-1420726666714\Extensions\15e4983dcabc4fb695007d519f551@fc04b380cf4e4a16aeb63aa224928b.com\extensionData\plugins\91.js.vir" sh=437DF08286CCE6D058869584295BCE4F4BAE6FC4 ft=1 fh=f59901ea312e0f83 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Cristian\AppData\Roaming\RHEng\0F1C6C356C6F4811838C90CAFAC0F264\setup1215.exe.vir" sh=C0472A56A5253FE19A559E4FE25EB4F6CF80A7ED ft=1 fh=82bc8c84d2499bd9 vn="Win32/Packed.ScrambleWrapper.O evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Cristian\AppData\Roaming\RHEng\1C190B6E33494E26ADB3C0D9C25ADB93\setup1215.exe.vir" sh=BEBBC2D67A8E2F0F852A6D6AC3C85BED73948F0C ft=1 fh=83bf463bc66b253f vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Cristian\AppData\Roaming\RHEng\4B653E60358341B08AEADEAA3CB0968F\445f2.exe.vir" sh=BEBBC2D67A8E2F0F852A6D6AC3C85BED73948F0C ft=1 fh=83bf463bc66b253f vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Cristian\AppData\Roaming\RHEng\AAA54DAA98AF4FC68298EE79FDEB3E17\445f2.exe.vir" sh=9F82BB5DC8D4EC6B8B2BB47CB6C329B8AF1C14CE ft=1 fh=c92ed1f3ca58c043 vn="Win32/InstallCore.AZ evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\FRST\Quarantine\C\Users\Cristian\AppData\Roaming\0F0W0T1V0D0L0M\Picasa Packages\uninstaller.exe" sh=3F3FE6FA3876FAFC6387C29C55AEBD4D34F9043A ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\ProgramData\dfhndngfkikbamohhepblbjlemgbjooa\WL.js" sh=4ED99C07223447C8C7C517FC9B5F0BC54A90D533 ft=1 fh=7ba5bd2a7b6e7323 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Qoobox\Quarantine\C\Program Files\7-Zip\1e3f9a5c-2dae-4817-b2fe-d4774c972006.dll.vir" sh=4ED99C07223447C8C7C517FC9B5F0BC54A90D533 ft=1 fh=7ba5bd2a7b6e7323 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Qoobox\Quarantine\C\Program Files\ef0ef932-01b1-473d-a940-2c3a15fc9957\9ece8453-29b7-4520-a60c-8718595e480e.dll.vir" sh=4ED99C07223447C8C7C517FC9B5F0BC54A90D533 ft=1 fh=7ba5bd2a7b6e7323 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Qoobox\Quarantine\C\Program Files\Super Radio\bac1d71e-543f-453f-901e-cdaeba4a0822.dll.vir" sh=B582D2DFEE30BCBC1776749124012AC56D487E83 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Qoobox\Quarantine\C\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhbfcdbhbobookobjhdnkgcgoiajlebn\243\lsdb.js.vir" sh=4B1697DE7F85A66C6A919E0404E71CD799983508 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Qoobox\Quarantine\C\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhbfcdbhbobookobjhdnkgcgoiajlebn\243\wmDAiQ.js.vir" sh=B582D2DFEE30BCBC1776749124012AC56D487E83 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Qoobox\Quarantine\C\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnecgiinnfijdlbjooeehnjbmdlgihod\128\lsdb.js.vir" sh=98DC41C9613924239A72DDBA40246FBC13356CB1 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Qoobox\Quarantine\C\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnecgiinnfijdlbjooeehnjbmdlgihod\128\PX.js.vir" sh=C9EF128ACA8B2A0D2C7903529C0EE9155954A45B ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Qoobox\Quarantine\C\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nilidoodajjnlapacccmliohagelpanf\183\CBxCCf5jcu.js.vir" sh=9201C0EA63A7D48DEA4E34C18F4799105AD1DF9B ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Qoobox\Quarantine\C\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\phbooabomhiefkllgocicphjpcaijdgi\219\DRcf4zb.js.vir" sh=B582D2DFEE30BCBC1776749124012AC56D487E83 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Qoobox\Quarantine\C\Users\Cristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\phbooabomhiefkllgocicphjpcaijdgi\219\lsdb.js.vir" sh=AF133206993877EEE55A97851B5CE932E19D576F ft=1 fh=0f02b5c30d03482b vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Cristian\Downloads\ashampoo_slideshow_studio_2012_1.0.2_12124.exe" sh=78712370CB8E4B52A74EDF124460A14B1A03C7FA ft=1 fh=8b0631dfc0ad3ae8 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Cristian\Downloads\CdCoverCreator - CHIP-Installer.exe" sh=E8CD33623287C08C7CC3662A042E45522654BB30 ft=1 fh=7cd3b160b0dbd4bd vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Cristian\Downloads\FreeYouTubeToMP3Converter.exe" sh=53B864054C53E89A824BECA877CAD04334666B8A ft=1 fh=df59eec964703436 vn="Win32/OutBrowse.BS evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Cristian\Downloads\Installation.exe" sh=006E1349E7DAF06FF8C0A278840DF9BB69795764 ft=1 fh=c65b23137b9a957f vn="Win32/InstallCore.BN evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Cristian\Downloads\ZipOpenerSetup.exe" |
14.01.2015, 09:11 | #30 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ständig Skriptfehler, PC extrem langsam und viel Werbung Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\All Users\dfhndngfkikbamohhepblbjlemgbjooa C:\ProgramData\dfhndngfkikbamohhepblbjlemgbjooa EmptyTemp: Hosts: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Ständig Skriptfehler, PC extrem langsam und viel Werbung |
ahnung, anderes, daten, dvd, erstellung, explorer, externe, fehler, hallo zusammen, kaufen, klicke, kostenlose, langsam, neuer, nimmer, pc extrem langsam, platte, programme, schei, sichern, sicherung, wenig ahnung, werbung, würde, zusammen, öffnen |