|
Plagegeister aller Art und deren Bekämpfung: general crawlersWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
13.01.2015, 19:05 | #1 |
| general crawlers Guten Tag ich wollte gern erfragen was "general crawlers" sind , steht zwar viel bei google , aber dann auch wieder nichts , mal sind sie gefährlich und man soll was zum entfernen runterladen und kaufen , mal sind sie notwendig oder mindestens egal .???? Keine Ahnung , bei chrome hat sich was geändert und als ich von "Profil 1" zu "Cocktail" gewechselt bin , bekam ich den Hinweis das "general crawlers" geschlossen wurde . Keine Ahnung was das bedeuted . danke im voraus + m.f.g. |
13.01.2015, 19:10 | #2 |
/// the machine /// TB-Ausbilder | general crawlers hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
19.01.2015, 17:30 | #3 |
| general crawlers Hallo
__________________O.K. ich mach das mal , danke für den Tipp . m.f.g. first datei FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-01-2015 Ran by dirkdererste (administrator) on DIRKDERERSTE-PC on 19-01-2015 17:25:32 Running from C:\Users\dirkdererste\Downloads Loaded Profiles: dirkdererste (Available profiles: dirkdererste) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files\ATK Hotkey\ASLDRSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe () C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVerMedia) C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe () C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe (Microsoft Corp.) C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\ProgramData\MobileBrServ\mbbService.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE (ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe (AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Google Inc.) C:\Program Files\Google\Update\1.3.25.11\GoogleCrashHandler.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe (ASUS) C:\Windows\System32\ASUSTPE.exe (ASUS) C:\Program Files\ASUS\ASUS CopyProtect\ASPG.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe () C:\Program Files\ATK Hotkey\KBFiltr.exe (AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4853760 2008-01-07] (Realtek Semiconductor) HKLM\...\Run: [ASUSTPE] => C:\Windows\system32\ASUSTPE.exe [106496 2007-10-12] (ASUS) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguix.exe [1133584 2014-11-28] (AVG Technologies CZ, s.r.o.) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-01-06] (Google Inc.) HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19ab7c-cbab-11e3-b7e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abdb-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abe7-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe8a-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe92-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe9e-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5dd-d506-11e3-befd-c030a9561ac3} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5e9-d506-11e3-befd-b68ac94258b5} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {31011372-66a4-11e4-88f4-adb511af100e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b50-3846-11e4-b727-a594aa94d86e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b5b-3846-11e4-b727-cfe712892541} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4235e5bc-8deb-11e3-bea2-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd209-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd244-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd24e-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd256-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd262-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb3442b-1faf-11e4-94c1-9483cebc1803} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb34437-1faf-11e4-94c1-ebf9039c5468} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5061e-2d56-11e4-806c-82b39df6fe7f} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5063d-2d56-11e4-806c-ff8e48defdcd} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {5899778b-f65b-11e3-908a-fe702680487d} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {589977db-f65b-11e3-908a-d444832a8c51} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7534b009-f659-11e3-935b-983f9ae39f7f} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba568-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba588-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {84d86f73-ebcf-11e3-99f4-e91098103f7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c282-3821-11e4-ac47-8fad69652c89} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c28d-3821-11e4-ac47-98a026ee637b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {8918ebcd-f632-11e3-a4cc-aae446c3b7d9} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {98b2279a-f666-11e3-82bf-8691ac93757f} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9d60af46-6833-11e4-9ae1-81f053ff7d7b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f017-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f054-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247885d-d82f-11e3-afed-ff56e36041fd} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247889a-d82f-11e3-afed-987030581f5d} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {b4a4281b-2f93-11e4-a053-b7ed9dff2029} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {ca5b6dde-19e3-11e0-83b8-806e6f6e6963} - E:\Autorun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {d85a1d2a-462a-11e4-94c3-8888219aad9a} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {db596716-c7e8-11e3-bdee-001e101fe70e} - I:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f01bf-2e39-11e4-b425-806e6f6e6963} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f0200-2e39-11e4-b425-c3e18252350b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {faf8fc99-6d70-11e4-b1d1-f474d68c3f10} - F:\AutoRun.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-1588098070-3651612994-842810468-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=BDKTDF&PC=BDT3&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = hxxp://start.gamesagogo.iplay.com/searchresultsredirect.aspx?o=chrome&q={searchTerms} SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {47511E21-1A74-42AF-93B1-2D31D99E032B} URL = hxxp://de.wikipedia.org/wiki/Spezial:Search?search={searchTerms} SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {7B240E59-FCB8-4F40-9C17-688AC4BBDB6A} URL = hxxp://rover.ebay.com/rover/1/707-37276-23097-0/4?satitle={searchTerms} SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = hxxp://www2.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80772&lng=de BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM - Babylon Toolbar - {41B62AD3-5D43-40D1-9D43-F3539C1DB452} - No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Toolbar: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1 FireFox: ======== FF Plugin: @adobe.com/AuthorwarePlayer -> C:\WINDOWS\system32\Macromed\AUTHORWA\np32asw.dll (Macromedia, Inc.) FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_257.dll () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1588098070-3651612994-842810468-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.) FF Extension: No Name - C:\Users\dirkdererste\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com [2012-03-02] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-01-06] FF HKLM\...\Firefox\Extensions: [quick_start@gmail.com] - C:\Users\dirkdererste\AppData\Roaming\Mozilla\Firefox\Profiles\5itzr609.default\extensions\quick_start@gmail.com Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.ergebnisselive.de/" CHR Profile: C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-21] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-07] CHR Extension: (YouTube) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-21] CHR Extension: (Google-Suche) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-16] CHR Extension: (Google Wallet) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Google Mail) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-16] CHR Profile: C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-13] CHR Extension: (YouTube) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-19] CHR Extension: (Google-Suche) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-19] CHR Extension: (Value apps) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon [2014-03-20] CHR Extension: (Google Wallet) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-13] CHR Extension: (Google Mail) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-19] CHR HKLM\...\Chrome\Extension: [aacbndibbcpajfgnkdkaakeiojmmgmnk] - C:\Users\dirkdererste\AppData\Roaming\Media Finder\Extensions\mf_plugin_gc.crx [Not Found] CHR HKLM\...\Chrome\Extension: [jpihmmhdcobmllpcnpfbhnipmhamldje] - C:\Users\dirkdererste\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.crx [Not Found] CHR HKLM\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-21] CHR HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\DIRKDE~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [Not Found] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ALDITALKVerbindungsassistent_Service; C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [342984 2011-09-13] () R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () [File not signed] R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed] R2 AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [339968 2008-03-13] (AVerMedia) [File not signed] R2 AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [380928 2008-03-05] () [File not signed] R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [696848 2014-11-28] (AVG Technologies CZ, s.r.o.) R2 BingDesktopUpdate; C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-20] (Microsoft Corp.) R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] () R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed] R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2165560 2014-11-24] (AVG Technologies) R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [35640 2014-11-24] (AVG Technologies) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () S3 ASPI; C:\Windows\System32\DRIVERS\ASPI32.sys [84832 2002-07-17] (Adaptec) [File not signed] S3 AVerFx2hbtv; C:\Windows\System32\drivers\AVerFx2hbtv.sys [437888 2009-12-08] (AVerMedia TECHNOLOGIES, Inc.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( ) R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1772544 2008-05-22] () S3 tosporte; C:\Windows\System32\DRIVERS\tosporte.sys [41600 2006-10-10] (TOSHIBA Corporation) [File not signed] S3 tosrfbd; C:\Windows\System32\DRIVERS\tosrfbd.sys [113792 2006-11-30] (TOSHIBA CORPORATION) [File not signed] S3 tosrfbnp; C:\Windows\System32\Drivers\tosrfbnp.sys [36480 2006-11-20] (TOSHIBA Corporation) [File not signed] S1 Tosrfcom; C:\Windows\System32\Drivers\tosrfcom.sys [64896 2005-08-01] (TOSHIBA Corporation) [File not signed] S3 Tosrfhid; C:\Windows\System32\DRIVERS\Tosrfhid.sys [73600 2006-10-05] (TOSHIBA Corporation.) [File not signed] S3 tosrfnds; C:\Windows\System32\DRIVERS\tosrfnds.sys [18612 2005-01-06] (TOSHIBA Corporation.) [File not signed] S3 TosRfSnd; C:\Windows\System32\drivers\tosrfsnd.sys [53504 2006-11-02] (TOSHIBA Corporation) [File not signed] S3 Tosrfusb; C:\Windows\System32\DRIVERS\tosrfusb.sys [40960 2006-10-27] (TOSHIBA CORPORATION) [File not signed] R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [12320 2014-08-28] (TuneUp Software) S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 HTCAND32; System32\Drivers\ANDROIDUSB.sys [X] S3 hwusbfake; No ImagePath S3 IpInIp; No ImagePath S3 motmodem; No ImagePath S3 NwlnkFlt; No ImagePath S3 NwlnkFwd; No ImagePath S3 usbbus; system32\DRIVERS\lgusbbus.sys [X] S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X] S3 USBModem; system32\DRIVERS\lgusbmodem.sys [X] S3 VNUSB; system32\DRIVERS\VNUSB.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-19 17:25 - 2015-01-19 17:26 - 00024705 _____ () C:\Users\dirkdererste\Downloads\FRST.txt 2015-01-19 17:25 - 2015-01-19 17:25 - 00000000 ____D () C:\FRST 2015-01-19 17:24 - 2015-01-19 17:24 - 01118208 _____ (Farbar) C:\Users\dirkdererste\Downloads\FRST.exe 2015-01-18 09:43 - 2015-01-18 09:43 - 00002980 _____ () C:\Windows\PFRO.log 2015-01-17 18:00 - 2015-01-17 18:05 - 00000189 _____ () C:\Users\dirkdererste\Desktop\DAMEN.txt 2015-01-14 19:40 - 2015-01-14 19:40 - 05013680 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe 2015-01-14 17:28 - 2014-12-19 01:25 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 17:12 - 2014-12-06 04:14 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 17:12 - 2014-12-06 04:14 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 17:12 - 2014-12-06 04:14 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2015-01-14 17:12 - 2014-12-06 04:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2015-01-12 18:30 - 2015-01-12 18:36 - 00000022 _____ () C:\Users\dirkdererste\Downloads\Gmail.zip 2015-01-10 13:13 - 2015-01-10 13:13 - 00012602 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvv-2FbgLWtxKiUPAnNHg9Ex7XJiyYrBIUKWniOSaYy513hlfagHce8Y9q2fBnUi46j8LMJiN4Ibo0jYqNA5K4b4-2BrIkMFz4DmX-2BQqOw6O-2BALSXByyiQFSdvPgiEF8YKq1mRsmIvzrESP5BopAg0olkOxyP-2FBKvXhu1j 2015-01-10 13:13 - 2015-01-10 13:13 - 00006172 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvvsJzMbrsjw5UKW3z-2Bs2dvjRlPojiGebXy7e5eGczAbLu-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FO3NCXbmNOMaTkWVyij4LGMR 2015-01-10 13:12 - 2015-01-10 13:12 - 00014005 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvszYSjXqZ0eKiFnXjlLTe-2BMizo92Hdw-2BByllGk1G2Tgge-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FbWYBnp7TdSaoQHTs8HCgK 2015-01-10 13:12 - 2015-01-10 13:12 - 00014005 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvszYSjXqZ0eKiFnXjlLTe-2BMizo92Hdw-2BByllGk1G2Tgge-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FbWYBnp7TdSaoQHTs8 (1) 2015-01-10 13:11 - 2015-01-10 13:11 - 00006448 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvuNQjNdmO9DbIZqVdhXDmcImLLl-2FMJgwS5ROnb8F4Ar8-2B-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FO3NCXbmNOMaTkWVyij4LG 2015-01-06 20:46 - 2015-01-06 20:46 - 00001063 _____ () C:\Users\dirkdererste\Desktop\MAST.txt 2015-01-06 18:21 - 2015-01-06 18:21 - 00000864 _____ () C:\Users\dirkdererste\Desktop\DHL.txt 2015-01-02 13:14 - 2015-01-02 13:14 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\Amazon 2014-12-26 15:09 - 2014-12-26 15:16 - 00000122 _____ () C:\Users\dirkdererste\Desktop\TomTom Start 50EU Navigationsgerät 13 cm 5 Zoll Europa.txt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-19 17:25 - 2011-01-06 20:20 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-19 17:22 - 2006-11-02 13:47 - 00003616 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-19 17:22 - 2006-11-02 13:47 - 00003616 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-19 17:00 - 2014-03-24 23:00 - 01078984 _____ () C:\Windows\WindowsUpdate.log 2015-01-19 16:43 - 2011-01-06 20:20 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-19 16:42 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-18 21:50 - 2014-06-12 23:47 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-18 18:39 - 2012-07-16 10:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-18 18:36 - 2014-09-03 18:24 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\vlc 2015-01-18 18:25 - 2012-12-29 18:25 - 00000392 _____ () C:\Windows\Tasks\FreeFileViewerUpdateChecker.job 2015-01-18 02:54 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\tracing 2015-01-16 13:04 - 2006-11-02 11:33 - 01543880 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-15 22:52 - 2012-07-27 19:58 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\Canon 2015-01-15 20:45 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2015-01-15 17:53 - 2014-11-02 10:34 - 00000000 ____D () C:\Users\dirkdererste\Desktop\Neuer Ordner 2015-01-15 00:38 - 2014-06-27 14:57 - 00000000 ____D () C:\Users\dirkdererste\Documents\AVerTV 2015-01-14 19:41 - 2012-04-08 09:03 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-01-14 19:41 - 2011-05-21 12:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-01-14 18:09 - 2014-11-05 18:03 - 00000000 ____D () C:\Users\dirkdererste\Desktop\Bewerbungszeug 2015-01-14 17:28 - 2013-07-19 12:23 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-14 17:13 - 2006-11-02 11:24 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2015-01-12 23:59 - 2011-01-07 15:25 - 00000000 ___RD () C:\Users\dirkdererste\Desktop\Kram 2015-01-12 17:02 - 2013-08-17 11:28 - 00000000 ____D () C:\Users\dirkdererste\AppData\Local\Freenet 2015-01-02 14:40 - 2011-01-07 15:36 - 00000000 ___RD () C:\Users\dirkdererste\Desktop\Mein Ordner 2014-12-31 12:13 - 2011-01-06 19:02 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-12-28 11:29 - 2011-01-06 21:31 - 00000000 ____D () C:\Users\dirkdererste\AppData\Local\Adobe ==================== Files in the root of some directories ======= 2007-06-12 19:34 - 2007-06-12 19:34 - 0035822 _____ () C:\Program Files\Common Files\ASPG_icon.ico 2008-05-22 18:35 - 2008-05-22 18:35 - 0051962 _____ () C:\Program Files\Common Files\banner.jpg 2008-07-02 04:28 - 2008-07-02 04:28 - 0061440 _____ () C:\Program Files\Common Files\CPInstallAction.dll 2011-10-30 00:00 - 2011-10-30 00:00 - 0024206 _____ () C:\Users\dirkdererste\AppData\Roaming\UserTile.png 2014-09-27 14:04 - 2014-09-27 14:05 - 0010828 _____ () C:\Users\dirkdererste\AppData\Roaming\WtgInstaller.txt 2011-01-06 20:24 - 2014-08-27 22:09 - 0001356 _____ () C:\Users\dirkdererste\AppData\Local\d3d9caps.dat 2011-01-07 14:57 - 2014-12-07 14:50 - 0020480 _____ () C:\Users\dirkdererste\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-03-21 16:25 - 2014-03-21 16:25 - 1172736 _____ (AnyProtect.com) C:\Users\dirkdererste\AppData\Local\nss61AF.tmp 2011-11-21 21:46 - 2011-11-21 21:46 - 0000000 _____ () C:\Users\dirkdererste\AppData\Local\{0CE875FA-9C01-4FE6-91E4-8DD35D1352B1} ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-19 16:50 ==================== End Of Log ============================ --- --- --- --- --- --- addition dateiFRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-01-2015 Ran by dirkdererste at 2015-01-19 17:26:53 Running from C:\Users\dirkdererste\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.257 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.257 - Adobe Systems Incorporated) Adobe Reader X (10.1.13) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.13 - Adobe Systems Incorporated) Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.) AVerMedia A827 series driver 1.0.0.70 (HKLM\...\AVerMedia A827 series driver) (Version: 1.0.0.70 - AVerMedia TECHNOLOGIES, Inc.) AVerMedia MCE Encoder 3.2.1.81 (HKLM\...\AVerMedia MCE Encoder) (Version: 3.2.1.81 - AVerMedia Technologies, Inc.) AVerTV (HKLM\...\InstallShield_{E28B1E6F-E0AA-4228-AB89-DB4A0C89D426}) (Version: 6.0.12 - AVerMedia Technologies, Inc.) AVerTV (Version: 6.0.12 - AVerMedia Technologies, Inc.) Hidden AVG (HKLM\...\AvgZen) (Version: 1.0.445 - AVG Technologies) AVG PC TuneUp 2015 (de-DE) (Version: 15.0.1001.238 - AVG Technologies) Hidden AVG PC TuneUp 2015 (HKLM\...\AVG PC TuneUp) (Version: 15.0.1001.238 - AVG Technologies) AVG PC TuneUp 2015 (Version: 15.0.1001.238 - AVG Technologies) Hidden AVG Zen (Version: 1.0.445 - AVG Technologies) Hidden FMW 1 (Version: 1.0.307 - AVG Technologies) Hidden Freenet (HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Freenet) (Version: - ) Google Chrome (HKLM\...\Google Chrome) (Version: 39.0.2171.99 - Google Inc.) Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.) Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle) Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Mobile Broadband HL Service (HKLM\...\Mobile Broadband HL Service) (Version: 22.001.21.00.03 - Huawei Technologies Co.,Ltd) Mobile Partner (HKLM\...\Mobile Partner) (Version: 16.002.03.01.40 - Huawei Technologies Co.,Ltd) NAVIGON Fresh 3.5.1 (HKLM\...\NAVIGON Fresh) (Version: 3.5.1 - NAVIGON) OpenOffice 4.1.0 (HKLM\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) TuneUp Utilities 2014 (de-DE) (Version: 14.0.1000.340 - TuneUp Software) Hidden Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{30A2652A-DDF7-45e7-ACA6-3EAB26FC8A4E}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{3f04dadf-6ea4-44d1-a507-03cad176f443}\InprocServer32 -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{41662FC2-0D57-4aff-AB27-AD2E12E7C273}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{448BB771-CFE2-47C4-BCDF-1FBF378E202C}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{7B342DC4-139A-4a46-8A93-DB0827CCEE9C}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\ooofilt.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{7FA8AE11-B3E3-4D88-AABF-255526CD1CE8}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{82154420-0FBF-11d4-8313-005004526AB4}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\propertyhdl.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{D0484DE6-AAEE-468a-991F-8D4B0737B57A}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{D2D59CD1-0A6A-4D36-AE20-47817077D57C}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{E5A0B632-DFBA-4549-9346-E414DA06E6F8}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{EE5D1EA4-D445-4289-B2FC-55FC93693917}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{F616B81F-7BB8-4F22-B8A5-47428D59F8AD}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation) ==================== Restore Points ========================= 16-01-2015 12:55:14 Windows Update 19-01-2015 16:55:09 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0912621A-00EC-4657-B9C6-8CEF5AA7DE79} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {0F30378C-16D5-4D3C-9D9C-59D4EA31F027} - System32\Tasks\FreeFileViewerUpdateChecker => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe [2012-10-13] (Bitberry Software) <==== ATTENTION Task: {2004BDA4-28F1-4AE2-A2F1-8FC040BCC7B2} - System32\Tasks\Java(TM) Platform SE Auto Updater => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-09-26] (Oracle Corporation) Task: {2227E28C-1A6A-4497-A69F-6944008C63DB} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {2D94D193-F98A-4DA2-B1BD-269A1A326B6F} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe Task: {479725C9-39E6-4667-917E-51ACAFA39A71} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd) Task: {5BE27D58-1E5F-473A-9CA5-8828F1F7CCC5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.) Task: {7164F5F3-C504-40DF-9606-A00DF5D617EC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.) Task: {930061BF-B9A9-4095-84E0-0057E6798C68} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-14] (Adobe Systems Incorporated) Task: {942306DB-F2AE-4AE2-86B2-35EBAD5CEF4D} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files\ASUS\SmartLogon\sensorsrv.exe [2008-06-18] (ASUS) Task: {96F069A3-86B8-4EFE-B037-9E1C83FAF801} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {E4527CC0-ADE5-4F5B-B11A-0D5387AC057E} - System32\Tasks\Software Updater => D:\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe [2014-01-29] () <==== ATTENTION Task: {E8D3CCEC-638E-46AD-80EA-92DA2943AFA3} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\AVG\AVG PC TuneUp\OneClick.exe [2014-11-24] (AVG Technologies) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FreeFileViewerUpdateChecker.job => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-01-06 23:54 - 2007-02-06 03:13 - 00094208 _____ () C:\Program Files\ATK Hotkey\ASLDRSrv.exe 2011-01-07 00:24 - 2007-08-08 09:08 - 00094208 _____ () C:\Program Files\ATKGFNEX\GFNEXSrv.exe 2014-09-27 14:05 - 2011-09-13 09:16 - 00342984 ____N () C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe 2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-06-27 14:55 - 2008-03-05 18:13 - 00380928 ____R () C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe 2014-11-10 17:53 - 2013-07-23 04:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe 2012-12-29 20:05 - 2012-12-07 17:26 - 00167424 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe 2011-01-07 00:23 - 2008-06-10 15:13 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll 2014-11-24 12:48 - 2014-11-24 12:48 - 00604472 _____ () C:\Program Files\AVG\AVG PC TuneUp\avgreplibx.dll 2011-01-06 23:54 - 2004-05-28 03:13 - 00057344 _____ () C:\Program Files\ATK Hotkey\CMSSC.dll 2011-01-06 23:55 - 2007-01-18 04:26 - 07708672 _____ () C:\Program Files\ATKOSD2\ATKOSD2.exe 2014-09-19 19:45 - 2014-09-19 19:45 - 31842816 _____ () C:\Program Files\AVG\Framework\Common\libcef.dll 2011-01-06 23:54 - 2006-12-19 02:26 - 02420736 _____ () C:\Program Files\ATK Hotkey\ATKOSD.exe 2011-01-06 23:54 - 2007-04-17 22:39 - 00077824 _____ () C:\Program Files\ATK Hotkey\KBFiltr.exe 2014-11-24 12:49 - 2014-11-24 12:49 - 00730936 _____ () C:\Program Files\AVG\AVG PC TuneUp\tulngx.dll 2015-01-16 02:27 - 2015-01-09 01:35 - 09009480 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.99\pdf.dll 2015-01-16 02:27 - 2015-01-09 01:35 - 01677128 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.99\ffmpegsumo.dll 2015-01-16 02:27 - 2015-01-09 01:35 - 14913352 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.99\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-1588098070-3651612994-842810468-500 - Administrator - Disabled) dirkdererste (S-1-5-21-1588098070-3651612994-842810468-1000 - Administrator - Enabled) => C:\Users\dirkdererste Gast (S-1-5-21-1588098070-3651612994-842810468-501 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= Name: Microsoft-ISATAP-Adapter Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Synaptics PS/2 Port TouchPad Description: Synaptics PS/2 Port TouchPad Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Synaptics Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: SiS191 Ethernet Controller Description: SiS191 Ethernet Controller Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Silicon Integrated Systems Corp. Service: SiSGbeLH Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/19/2015 04:43:05 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2015 09:45:23 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2015 02:54:05 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/17/2015 09:44:08 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/16/2015 05:45:18 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/16/2015 03:50:17 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/16/2015 01:40:38 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/16/2015 00:47:11 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/15/2015 03:58:06 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/15/2015 00:51:18 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (01/19/2015 04:48:04 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (01/19/2015 04:44:21 PM) (Source: Dhcp) (EventID: 1001) (User: ) Description: Diesem Computer konnte keine Netzwerkadresse durch den DHCP-Server für die Netzwerkkarte mit der Netzwerkadresse 6223733B10C1 zugeteilt werden. Der folgende Fehler ist aufgetreten: %%258. Es wird weiterhin im Hintergrund versucht, eine Adresse vom Netzwerkadressserver (DHCP) zugeteilt zu bekommen. Error: (01/19/2015 04:43:27 PM) (Source: Dhcp) (EventID: 1002) (User: ) Description: Die IP-Adresslease 192.168.8.100 für die Netzwerkkarte mit der Netzwerkadresse 6223733B10C1 wurde durch den DHCP-Server 192.168.8.1 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet). Error: (01/19/2015 04:43:06 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Tosrfcom Error: (01/18/2015 09:45:33 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (01/18/2015 09:45:23 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Tosrfcom Error: (01/18/2015 09:44:06 AM) (Source: Dhcp) (EventID: 1002) (User: ) Description: Die IP-Adresslease 192.168.8.100 für die Netzwerkkarte mit der Netzwerkadresse CEBAC3BD9E48 wurde durch den DHCP-Server 192.168.8.1 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet). Error: (01/18/2015 03:05:03 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.191.2526.0 Aktualisierungsquelle: %NT-AUTORITÄT59 Aktualisierungsphase: 4.4.0304.00 Quellpfad: 4.4.0304.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\SYSTEM Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Error: (01/18/2015 03:01:29 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (01/18/2015 02:54:08 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Tosrfcom Microsoft Office Sessions: ========================= Error: (01/19/2015 04:43:05 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2015 09:45:23 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2015 02:54:05 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/17/2015 09:44:08 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/16/2015 05:45:18 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/16/2015 03:50:17 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/16/2015 01:40:38 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/16/2015 00:47:11 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/15/2015 03:58:06 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/15/2015 00:51:18 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2014-09-20 11:04:04.356 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-20 11:04:03.778 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-20 11:04:03.169 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-20 11:04:02.542 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-20 11:04:00.510 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-20 11:03:59.900 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-20 11:03:59.291 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-20 11:03:58.525 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-28 00:14:54.077 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\KLKBDFLT2X86\klkbdflt2.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-28 00:14:53.562 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\KLKBDFLT2X86\klkbdflt2.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Pentium(R) Dual CPU T3200 @ 2.00GHz Percentage of memory in use: 51% Total physical RAM: 3070.54 MB Available physical RAM: 1480.24 MB Total Pagefile: 6351.21 MB Available Pagefile: 4570.25 MB Total Virtual: 2047.88 MB Available Virtual: 1900.52 MB ==================== Drives ================================ Drive c: (VistaOS) (Fixed) (Total:139.73 GB) (Free:51.59 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (DATA) (Fixed) (Total:93.15 GB) (Free:65.03 GB) NTFS Drive e: (DEPECHE MODE - Alive In Berlin) (CDROM) (Total:7.72 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.9 GB) (Disk ID: 03942D70) Partition 1: (Active) - (Size=139.7 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=93.2 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
19.01.2015, 20:19 | #4 |
/// the machine /// TB-Ausbilder | general crawlers Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
26.01.2015, 18:28 | #5 |
| general crawlers Hallo und danke erstmal dafür - ich werde das mal machen , aber nicht heute . scheint ja eine ziemlich umständliche aktion zu sein . habe ich denn was auf dem rechner was nicht drauf gehört ? m.f.g. |
26.01.2015, 22:38 | #6 |
/// the machine /// TB-Ausbilder | general crawlers Jo, Adware
__________________ --> general crawlers |
31.01.2015, 12:24 | #7 |
| general crawlers Hey danke nochmal für die info , habe jetzt mal alles durchgeführt und für mich als mr.ahnungslos ist aber kein unterschied festzustellen . sollte ich diese prozedur nun öfter anwenden ? Malwarebytes Anti-Malware Malwarebytes | Free Anti-Malware & Internet Security Software Protection, 30.01.2015 22:48:08, SYSTEM, DIRKDERERSTE-PC, Protection, Malware Protection, Starting, Protection, 30.01.2015 22:48:08, SYSTEM, DIRKDERERSTE-PC, Protection, Malware Protection, Started, Protection, 30.01.2015 22:48:08, SYSTEM, DIRKDERERSTE-PC, Protection, Malicious Website Protection, Starting, Protection, 30.01.2015 22:48:12, SYSTEM, DIRKDERERSTE-PC, Protection, Malicious Website Protection, Started, Update, 30.01.2015 22:48:17, SYSTEM, DIRKDERERSTE-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1, Update, 30.01.2015 22:48:17, SYSTEM, DIRKDERERSTE-PC, Manual, Rootkit Database, 2014.11.18.1, 2015.1.14.1, Update, 30.01.2015 22:48:33, SYSTEM, DIRKDERERSTE-PC, Manual, Malware Database, 2014.11.20.6, 2015.1.30.8, Protection, 30.01.2015 22:48:33, SYSTEM, DIRKDERERSTE-PC, Protection, Refresh, Starting, Protection, 30.01.2015 22:48:33, SYSTEM, DIRKDERERSTE-PC, Protection, Malicious Website Protection, Stopping, Protection, 30.01.2015 22:48:33, SYSTEM, DIRKDERERSTE-PC, Protection, Malicious Website Protection, Stopped, Protection, 30.01.2015 22:48:41, SYSTEM, DIRKDERERSTE-PC, Protection, Refresh, Success, Protection, 30.01.2015 22:48:41, SYSTEM, DIRKDERERSTE-PC, Protection, Malicious Website Protection, Starting, Protection, 30.01.2015 22:48:42, SYSTEM, DIRKDERERSTE-PC, Protection, Malicious Website Protection, Started, (end) ---------------------------------------- # AdwCleaner v4.109 - Bericht erstellt am 30/01/2015 um 23:23:39 # Aktualisiert 24/01/2015 von Xplode # Database : 2015-01-26.1 [Live] # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : dirkdererste - DIRKDERERSTE-PC # Gestartet von : C:\Users\dirkdererste\Downloads\AdwCleaner_4.109.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Ask Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\PC Drivers HeadQuarters Ordner Gelöscht : C:\Program Files\AnyProtectEx Ordner Gelöscht : C:\Program Files\GamesBar Ordner Gelöscht : C:\Users\DIRKDE~1\AppData\Local\Temp\OCS Ordner Gelöscht : C:\Users\dirkdererste\AppData\Local\Babylon Ordner Gelöscht : C:\Users\dirkdererste\AppData\Local\Tuguu_SL Ordner Gelöscht : C:\Users\dirkdererste\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\dirkdererste\AppData\Roaming\Security System 2 Ordner Gelöscht : C:\Users\dirkdererste\AppData\Roaming\Systweak Ordner Gelöscht : C:\Users\dirkdererste\AppData\Roaming\Toolplugin Datei Gelöscht : C:\END Datei Gelöscht : C:\Windows\system32\roboot.exe ***** [ Tasks ] ***** Task Gelöscht : Software Updater ------------------------------------------------JRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.1 (12.28.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by dirkdererste on 30.01.2015 at 23:34:36,35 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6} ~~~ Files Successfully deleted: [File] C:\Windows\prefetch\DRIVERSETUP.EXE-DD5C1BF6.pf ~~~ Folders Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin" Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{01A287B1-81EF-48DF-92F9-0E4C0DFE5F89} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{03191E75-FC96-480E-BBA9-1F0014E37125} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{04081FCE-23A4-4D2C-AC17-3983BCBF5BD7} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{04B93C16-5B07-4B9F-96E5-18A79E822B00} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{05FB68B2-FADF-4184-A8F7-439B3648F860} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{06E8E259-1F28-43C1-BEE0-5CABC037E469} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{098479FC-3EC2-476C-8AA7-0A0835D4EFA8} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{0B078C03-6539-4602-B2A3-4CC5C1A85470} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{0B9C2737-4CC3-472F-9313-2D9AB1EFBB0E} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{12261B67-F504-4C1C-85BD-53F4B84F9529} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{1337A515-BFA1-4934-811A-3E19EBBF7D39} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{154B8B71-5704-424E-998B-BE686D1787B3} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{16FC69FA-486F-414A-918F-7413B6F5B6AA} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{19B47451-7F46-408F-AB64-E361A0D2B61E} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{1A447DCA-F9B3-4CDD-9E2A-E767FA8B18E1} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{1E04EE68-3030-4835-BE0F-A2344311AAE2} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{1E2EE9A3-7D38-4E28-AEC8-4490BB365FF3} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{1E915829-88BC-4A78-AEEE-1218C5A7DCB3} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{1F8D53A0-AE05-4F2D-B07A-743A12062924} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{21C04126-09D6-400E-9A42-26D4D8864679} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{22C42200-2648-429B-A77D-0C1FD0104329} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{25F3A22E-47CB-4394-B043-610F584A9754} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{26ED7610-FE03-416F-BEB7-84D6B22816C2} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{2770D1AD-2590-469B-8FC7-C926DB37B97C} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{2A17CE64-7731-4A9E-982F-54825E54EAA5} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{2CE09DFB-6589-48CD-B460-ACB4A2A4398F} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{2F238C06-75A9-49BF-8073-9DFA7365A820} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{2F68A8FA-82C7-45DA-9BF5-3D3BF4576B70} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{2F7DA4A7-1379-4217-AF55-BB95B6827338} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{30E60BAC-F497-486B-9BEC-5E91CCC3A72D} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{316C08E0-ED0E-4734-A461-F368787406D9} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{31871A65-0A52-4032-A035-CB42BC1F9838} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{339D9740-E2E7-41DA-AD97-FAE675D06212} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{3628DB2B-5B6B-420F-9225-8D4CDE1448EB} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{3E360FE0-AC4D-4669-A40D-089CEDD0BF92} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{41AB9376-6297-4DD1-9103-5301B226B1AE} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{49709AC6-8080-4823-9B6F-A27662A577E1} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{4ADCD0C3-0A07-483C-BA3C-454BD495AD8F} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{4B3289CB-6241-47CA-AF22-76A3C3F8AFAB} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{4D0EB893-DE8A-488B-9856-235E903C98FB} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{52AD7779-58CF-44BE-838A-927CBF4DC5E4} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{52BCCE54-4968-43FA-ADC4-5A3F59C01F40} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{5C629297-41DD-4564-8C7C-C4F04082B943} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{60B0E168-BD5C-407D-874E-266493D843EF} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{617A780B-4BEE-4E20-8DBE-589270F57BBB} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{65217493-C958-47FC-A19C-67AF53D1B4CB} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{676CC973-B8DE-4A39-B31A-D6A41C4EFEAF} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{67B9690D-CF31-430A-A1F7-B2CF39B20A3D} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{6A67D21D-A943-4AF4-9EEC-BDF550FE9574} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{6B55CF83-A6CB-40C8-9915-CE40A2BA3969} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{6C5D25EB-1910-4924-AAE7-0FD49A5B1DB6} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{6C674FD5-C129-4FDC-9B61-D9E14B9F9652} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{72B05727-4FB8-467F-8FC5-1F94C4900CE1} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{73147042-00CD-4B3E-959A-B95BE8BE93C3} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{73698C02-9A20-4AFB-ABA3-E01DA5949F81} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{77BD3833-FB57-49B8-A32E-638166A333EB} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{7AF635C5-97EA-4FEF-8FED-E0D9A4BAABE8} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{7BE22156-CA58-47D4-B38D-64BA209BECA8} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{7D3AEA8D-AA93-42E6-AE3D-CD7BCDD185C9} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{85D87357-D550-4E24-B74A-ADB2F88362AB} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{880D30D0-75E1-4E21-9C8A-BAFA05027FB6} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{8EDED6F0-B914-4628-9C73-F967EC88CD1F} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{8FB9E7CD-1E20-4A37-9986-EB1DFB8AECEB} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{9237A495-6E8D-44C3-B9B5-6FE399FB72AD} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{936198E1-C708-4D12-8716-D27629103C2B} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{9A931F4A-9929-46CA-B131-B91415BCF8B3} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{9BD92546-27A1-4A2F-9EB1-36517D1A5486} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{9F959141-2DE9-4B2C-8CE1-6B48581754F7} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{A0B08665-8162-40A4-AF01-C37ACBC1AB1C} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{A57AF6E7-518C-46AD-81DB-2F9F7D8AAFDC} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{A5AFB053-BC1C-43E4-B7A4-6550EB534BFF} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{A627AAE2-2DD6-4B45-964A-0DB43F3062BE} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{A70111A7-3B41-4546-A96A-44C5DCB6DF73} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{A88903AB-3840-4AEA-AC8E-1316B8B5C258} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{AB232FD8-6567-4226-902D-5B5864A268FA} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{B11233FC-CC80-4E0B-A789-1482002A4419} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{B9538D8E-F44C-4405-954F-70444B95CE31} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{BE2DE09F-9AA7-491C-B18C-FCA07848F75C} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{BF1C8246-BD10-4495-A3AB-41FD5F0F0284} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{C6870E8C-36AE-42D7-A927-38E91AC920DF} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{CC90E0D2-ED01-4D61-9335-61EF75D99180} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{CD2303BD-D2DA-445C-BD33-1FD1B9E8EC96} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{CFC345DA-4616-49CA-A184-583B9DDCF450} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{D0C97D88-10E7-43AF-9167-5895249DDCF3} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{D3C233DB-5B7C-4FC5-84B2-D734EB616499} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{DD809FBD-C7BC-48A1-8BBB-C37899077A25} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{E15485D4-9BD8-4374-A903-366BC97A6F39} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{E27C459C-8A57-4008-A949-F33FD125696C} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{E28C7A92-A90C-4CDC-8A00-2F48F6166ADF} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{ED58AA0B-1F60-469A-A559-E761942EE4E8} Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{FBFB72F6-8D2E-4E37-9E99-B5E965D5FE3C} ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 30.01.2015 at 23:39:35,09 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ---------------------------------------------------------------- FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-01-2015 01 Ran by dirkdererste (administrator) on DIRKDERERSTE-PC on 30-01-2015 23:41:46 Running from C:\Users\dirkdererste\Downloads Loaded Profiles: dirkdererste (Available profiles: dirkdererste) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files\ATK Hotkey\ASLDRSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe (Google Inc.) C:\Program Files\Google\Update\1.3.25.11\GoogleCrashHandler.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe () C:\Program Files\Wireless Console 2\wcourier.exe () C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe (ASUS) C:\Program Files\ASUS\ASUS CopyProtect\ASPG.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVerMedia) C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe () C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe () C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe (Microsoft Corp.) C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe (Malwarebytes Corporation) C:\ Malwarebytes Anti-Malware \mbamscheduler.exe () C:\Program Files\ATK Hotkey\KBFiltr.exe (Malwarebytes Corporation) C:\ Malwarebytes Anti-Malware \mbamservice.exe () C:\ProgramData\MobileBrServ\mbbService.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE (AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Malwarebytes Corporation) C:\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (ASUS) C:\Windows\System32\ASUSTPE.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 10.0\Reader\reader_sl.exe (Farbar) C:\Users\dirkdererste\Downloads\FRST (1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4853760 2008-01-07] (Realtek Semiconductor) HKLM\...\Run: [ASUSTPE] => C:\Windows\system32\ASUSTPE.exe [106496 2007-10-12] (ASUS) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguix.exe [1140688 2015-01-16] (AVG Technologies CZ, s.r.o.) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-01-06] (Google Inc.) HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19ab7c-cbab-11e3-b7e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abdb-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abe7-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe8a-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe92-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe9e-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5dd-d506-11e3-befd-c030a9561ac3} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5e9-d506-11e3-befd-b68ac94258b5} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {31011372-66a4-11e4-88f4-adb511af100e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b50-3846-11e4-b727-a594aa94d86e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b5b-3846-11e4-b727-cfe712892541} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4235e5bc-8deb-11e3-bea2-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd209-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd244-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd24e-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd256-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd262-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb3442b-1faf-11e4-94c1-9483cebc1803} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb34437-1faf-11e4-94c1-ebf9039c5468} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5061e-2d56-11e4-806c-82b39df6fe7f} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5063d-2d56-11e4-806c-ff8e48defdcd} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {5899778b-f65b-11e3-908a-fe702680487d} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {589977db-f65b-11e3-908a-d444832a8c51} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7534b009-f659-11e3-935b-983f9ae39f7f} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba568-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba588-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {84d86f73-ebcf-11e3-99f4-e91098103f7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c282-3821-11e4-ac47-8fad69652c89} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c28d-3821-11e4-ac47-98a026ee637b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {8918ebcd-f632-11e3-a4cc-aae446c3b7d9} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {98b2279a-f666-11e3-82bf-8691ac93757f} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9d60af46-6833-11e4-9ae1-81f053ff7d7b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f017-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f054-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247885d-d82f-11e3-afed-ff56e36041fd} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247889a-d82f-11e3-afed-987030581f5d} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {b4a4281b-2f93-11e4-a053-b7ed9dff2029} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {ca5b6dde-19e3-11e0-83b8-806e6f6e6963} - E:\Autorun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {d85a1d2a-462a-11e4-94c3-8888219aad9a} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {db596716-c7e8-11e3-bdee-001e101fe70e} - I:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f01bf-2e39-11e4-b425-806e6f6e6963} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f0200-2e39-11e4-b425-c3e18252350b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {faf8fc99-6d70-11e4-b1d1-f474d68c3f10} - F:\AutoRun.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-1588098070-3651612994-842810468-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = hxxp://start.gamesagogo.iplay.com/searchresultsredirect.aspx?o=chrome&q={searchTerms} SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {47511E21-1A74-42AF-93B1-2D31D99E032B} URL = hxxp://de.wikipedia.org/wiki/Spezial:Search?search={searchTerms} SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {7B240E59-FCB8-4F40-9C17-688AC4BBDB6A} URL = hxxp://rover.ebay.com/rover/1/707-37276-23097-0/4?satitle={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Babylon Toolbar - {41B62AD3-5D43-40D1-9D43-F3539C1DB452} - No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1 FireFox: ======== FF Plugin: @adobe.com/AuthorwarePlayer -> C:\WINDOWS\system32\Macromed\AUTHORWA\np32asw.dll (Macromedia, Inc.) FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1588098070-3651612994-842810468-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-01-06] Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.ergebnisselive.de/" CHR Profile: C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-21] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-07] CHR Extension: (YouTube) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-21] CHR Extension: (Google-Suche) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-16] CHR Extension: (Google Wallet) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Google Mail) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-16] CHR Profile: C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-13] CHR Extension: (YouTube) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-19] CHR Extension: (Google-Suche) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-19] CHR Extension: (Value apps) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon [2014-03-20] CHR Extension: (Google Wallet) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-13] CHR Extension: (Google Mail) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-19] CHR HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\DIRKDE~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [Not Found] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ALDITALKVerbindungsassistent_Service; C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [342984 2011-09-13] () R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () [File not signed] R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed] R2 AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [339968 2008-03-13] (AVerMedia) [File not signed] R2 AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [380928 2008-03-05] () [File not signed] R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [703952 2015-01-16] (AVG Technologies CZ, s.r.o.) R2 BingDesktopUpdate; C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-20] (Microsoft Corp.) R2 MBAMScheduler; C:\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] () R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed] R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2165560 2014-11-24] (AVG Technologies) R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [35640 2014-11-24] (AVG Technologies) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () S3 ASPI; C:\Windows\System32\DRIVERS\ASPI32.sys [84832 2002-07-17] (Adaptec) [File not signed] S3 AVerFx2hbtv; C:\Windows\System32\drivers\AVerFx2hbtv.sys [437888 2009-12-08] (AVerMedia TECHNOLOGIES, Inc.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( ) R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-01-30] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1772544 2008-05-22] () S3 tosporte; C:\Windows\System32\DRIVERS\tosporte.sys [41600 2006-10-10] (TOSHIBA Corporation) [File not signed] S3 tosrfbd; C:\Windows\System32\DRIVERS\tosrfbd.sys [113792 2006-11-30] (TOSHIBA CORPORATION) [File not signed] S3 tosrfbnp; C:\Windows\System32\Drivers\tosrfbnp.sys [36480 2006-11-20] (TOSHIBA Corporation) [File not signed] S1 Tosrfcom; C:\Windows\System32\Drivers\tosrfcom.sys [64896 2005-08-01] (TOSHIBA Corporation) [File not signed] S3 Tosrfhid; C:\Windows\System32\DRIVERS\Tosrfhid.sys [73600 2006-10-05] (TOSHIBA Corporation.) [File not signed] S3 tosrfnds; C:\Windows\System32\DRIVERS\tosrfnds.sys [18612 2005-01-06] (TOSHIBA Corporation.) [File not signed] S3 TosRfSnd; C:\Windows\System32\drivers\tosrfsnd.sys [53504 2006-11-02] (TOSHIBA Corporation) [File not signed] S3 Tosrfusb; C:\Windows\System32\DRIVERS\tosrfusb.sys [40960 2006-10-27] (TOSHIBA CORPORATION) [File not signed] R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [12320 2014-08-28] (TuneUp Software) S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 HTCAND32; System32\Drivers\ANDROIDUSB.sys [X] S3 hwusbfake; No ImagePath S3 IpInIp; No ImagePath S3 motmodem; No ImagePath S3 NwlnkFlt; No ImagePath S3 NwlnkFwd; No ImagePath S3 usbbus; system32\DRIVERS\lgusbbus.sys [X] S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X] S3 USBModem; system32\DRIVERS\lgusbmodem.sys [X] S3 VNUSB; system32\DRIVERS\VNUSB.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-30 23:41 - 2015-01-30 23:41 - 01121792 _____ (Farbar) C:\Users\dirkdererste\Downloads\FRST (1).exe 2015-01-30 23:39 - 2015-01-30 23:39 - 00011221 _____ () C:\Users\dirkdererste\Desktop\JRT.txt 2015-01-30 23:34 - 2015-01-30 23:34 - 00000000 ____D () C:\Windows\ERUNT 2015-01-30 23:32 - 2015-01-30 23:32 - 01707939 _____ (Thisisu) C:\Users\dirkdererste\Downloads\JRT.exe 2015-01-30 23:31 - 2015-01-30 23:31 - 00011039 _____ () C:\Users\dirkdererste\Desktop\AdwCleaner[S0].txt 2015-01-30 23:17 - 2015-01-30 23:23 - 00000000 ____D () C:\AdwCleaner 2015-01-30 23:16 - 2015-01-30 23:16 - 02194432 _____ () C:\Users\dirkdererste\Downloads\AdwCleaner_4.109.exe 2015-01-30 23:14 - 2015-01-30 23:14 - 00001444 _____ () C:\Users\dirkdererste\Desktop\antimalware.txt 2015-01-30 22:48 - 2015-01-30 23:30 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-30 22:47 - 2015-01-30 22:47 - 00000660 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-30 22:47 - 2015-01-30 22:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-30 22:47 - 2015-01-30 22:47 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-30 22:47 - 2015-01-30 22:47 - 00000000 ____D () C:\ Malwarebytes Anti-Malware 2015-01-30 22:47 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-30 22:47 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-30 22:47 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-30 22:44 - 2015-01-30 22:44 - 00000551 _____ () C:\Users\dirkdererste\Desktop\ddd.txt 2015-01-30 22:41 - 2015-01-30 22:42 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\dirkdererste\Downloads\mbam-setup-2.0.4.1028.exe 2015-01-27 19:05 - 2015-01-27 19:03 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2015-01-27 19:05 - 2015-01-27 19:03 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2015-01-27 19:05 - 2015-01-27 19:03 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2015-01-21 18:11 - 2015-01-30 23:28 - 00012758 _____ () C:\Windows\PFRO.log 2015-01-20 19:53 - 2015-01-20 19:55 - 00000000 ___RD () C:\Users\dirkdererste\Desktop\Write 2015-01-20 19:45 - 2015-01-20 19:45 - 00000000 ____D () C:\Users\Public\Documents\sun 2015-01-20 19:44 - 2015-01-20 19:44 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\LibreOffice 2015-01-20 19:42 - 2015-01-20 19:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.2 2015-01-20 19:36 - 2015-01-20 19:42 - 00000000 ____D () C:\Program Files\LibreOffice 4 2015-01-20 19:31 - 2015-01-20 19:31 - 00000000 ____D () C:\Users\dirkdererste\Desktop\LernZeugs 2015-01-20 13:43 - 2015-01-20 13:52 - 220569600 _____ () C:\Users\dirkdererste\LibreOffice_4.2.8_Win_x86.msi 2015-01-19 17:26 - 2015-01-19 17:27 - 00027860 _____ () C:\Users\dirkdererste\Downloads\Addition.txt 2015-01-19 17:25 - 2015-01-30 23:41 - 00024162 _____ () C:\Users\dirkdererste\Downloads\FRST.txt 2015-01-19 17:25 - 2015-01-30 23:41 - 00000000 ____D () C:\FRST 2015-01-19 17:24 - 2015-01-19 17:24 - 01118208 _____ (Farbar) C:\Users\dirkdererste\Downloads\FRST.exe 2015-01-14 17:28 - 2014-12-19 01:25 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 17:12 - 2014-12-06 04:14 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 17:12 - 2014-12-06 04:14 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 17:12 - 2014-12-06 04:14 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2015-01-14 17:12 - 2014-12-06 04:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2015-01-12 18:30 - 2015-01-12 18:36 - 00000022 _____ () C:\Users\dirkdererste\Downloads\Gmail.zip 2015-01-10 13:13 - 2015-01-10 13:13 - 00012602 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvv-2FbgLWtxKiUPAnNHg9Ex7XJiyYrBIUKWniOSaYy513hlfagHce8Y9q2fBnUi46j8LMJiN4Ibo0jYqNA5K4b4-2BrIkMFz4DmX-2BQqOw6O-2BALSXByyiQFSdvPgiEF8YKq1mRsmIvzrESP5BopAg0olkOxyP-2FBKvXhu1j 2015-01-10 13:13 - 2015-01-10 13:13 - 00006172 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvvsJzMbrsjw5UKW3z-2Bs2dvjRlPojiGebXy7e5eGczAbLu-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FO3NCXbmNOMaTkWVyij4LGMR 2015-01-10 13:12 - 2015-01-10 13:12 - 00014005 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvszYSjXqZ0eKiFnXjlLTe-2BMizo92Hdw-2BByllGk1G2Tgge-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FbWYBnp7TdSaoQHTs8HCgK 2015-01-10 13:12 - 2015-01-10 13:12 - 00014005 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvszYSjXqZ0eKiFnXjlLTe-2BMizo92Hdw-2BByllGk1G2Tgge-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FbWYBnp7TdSaoQHTs8 (1) 2015-01-10 13:11 - 2015-01-10 13:11 - 00006448 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvuNQjNdmO9DbIZqVdhXDmcImLLl-2FMJgwS5ROnb8F4Ar8-2B-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FO3NCXbmNOMaTkWVyij4LG 2015-01-06 20:46 - 2015-01-06 20:46 - 00001063 _____ () C:\Users\dirkdererste\Desktop\MAST.txt 2015-01-02 13:14 - 2015-01-02 13:14 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\Amazon ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-30 23:39 - 2012-07-16 10:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-30 23:33 - 2014-03-24 23:00 - 01526593 _____ () C:\Windows\WindowsUpdate.log 2015-01-30 23:28 - 2011-01-06 20:20 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-30 23:28 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-30 23:28 - 2006-11-02 13:47 - 00003616 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-30 23:28 - 2006-11-02 13:47 - 00003616 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-30 23:26 - 2012-05-06 11:55 - 00000000 ____D () C:\Windows\de 2015-01-30 23:25 - 2014-06-12 23:47 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-30 23:25 - 2011-01-06 20:20 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-30 18:28 - 2012-12-29 18:25 - 00000392 _____ () C:\Windows\Tasks\FreeFileViewerUpdateChecker.job 2015-01-30 15:53 - 2006-11-02 11:33 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-30 00:21 - 2014-06-27 14:57 - 00000000 ____D () C:\Users\dirkdererste\Documents\AVerTV 2015-01-29 18:32 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\tracing 2015-01-27 19:06 - 2013-10-21 16:27 - 00000000 ____D () C:\ProgramData\Oracle 2015-01-27 19:05 - 2011-01-10 00:43 - 00000000 ____D () C:\Program Files\Java 2015-01-27 19:04 - 2014-11-04 16:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-01-27 19:03 - 2014-11-04 16:35 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2015-01-25 12:50 - 2012-04-08 09:03 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-01-25 12:50 - 2011-05-21 12:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-01-24 17:16 - 2014-09-03 18:24 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\vlc 2015-01-21 18:11 - 2014-09-14 00:30 - 00299008 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-20 20:53 - 2014-09-14 09:32 - 00065328 _____ () C:\Users\dirkdererste\AppData\Local\GDIPFONTCACHEV1.DAT 2015-01-20 19:32 - 2011-01-06 16:43 - 00000000 ____D () C:\Users\dirkdererste 2015-01-15 22:52 - 2012-07-27 19:58 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\Canon 2015-01-15 20:45 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2015-01-15 17:53 - 2014-11-02 10:34 - 00000000 ____D () C:\Users\dirkdererste\Desktop\Neuer Ordner 2015-01-14 17:28 - 2013-07-19 12:23 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-14 17:13 - 2006-11-02 11:24 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2015-01-12 23:59 - 2011-01-07 15:25 - 00000000 ___RD () C:\Users\dirkdererste\Desktop\Kram 2015-01-12 17:02 - 2013-08-17 11:28 - 00000000 ____D () C:\Users\dirkdererste\AppData\Local\Freenet 2015-01-02 14:40 - 2011-01-07 15:36 - 00000000 ___RD () C:\Users\dirkdererste\Desktop\Mein Ordner 2014-12-31 12:13 - 2011-01-06 19:02 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Files in the root of some directories ======= 2007-06-12 19:34 - 2007-06-12 19:34 - 0035822 _____ () C:\Program Files\Common Files\ASPG_icon.ico 2008-05-22 18:35 - 2008-05-22 18:35 - 0051962 _____ () C:\Program Files\Common Files\banner.jpg 2008-07-02 04:28 - 2008-07-02 04:28 - 0061440 _____ () C:\Program Files\Common Files\CPInstallAction.dll 2011-10-30 00:00 - 2011-10-30 00:00 - 0024206 _____ () C:\Users\dirkdererste\AppData\Roaming\UserTile.png 2014-09-27 14:04 - 2014-09-27 14:05 - 0010828 _____ () C:\Users\dirkdererste\AppData\Roaming\WtgInstaller.txt 2011-01-06 20:24 - 2014-08-27 22:09 - 0001356 _____ () C:\Users\dirkdererste\AppData\Local\d3d9caps.dat 2011-01-07 14:57 - 2014-12-07 14:50 - 0020480 _____ () C:\Users\dirkdererste\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-03-21 16:25 - 2014-03-21 16:25 - 1172736 _____ (AnyProtect.com) C:\Users\dirkdererste\AppData\Local\nss61AF.tmp 2011-11-21 21:46 - 2011-11-21 21:46 - 0000000 _____ () C:\Users\dirkdererste\AppData\Local\{0CE875FA-9C01-4FE6-91E4-8DD35D1352B1} Some content of TEMP: ==================== C:\Users\dirkdererste\AppData\Local\Temp\avguirn_082101543405.exe C:\Users\dirkdererste\AppData\Local\Temp\jre-8u31-windows-au.exe C:\Users\dirkdererste\AppData\Local\Temp\Quarantine.exe C:\Users\dirkdererste\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-30 23:37 ==================== End Of Log ============================ |
31.01.2015, 16:01 | #8 |
/// the machine /// TB-Ausbilder | general crawlersESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.02.2015, 17:07 | #9 |
| general crawlers Hey danke für den tipp , werde ich mal machen , aber kann es sein das die ganze scannerei eine wechselwirkung mit meinem tune up utilities hat ? ich denke mal ja , weil seit samstag geht das nicht mehr , es stürzt bei jedem scan einfach ab . |
03.02.2015, 21:07 | #10 |
/// the machine /// TB-Ausbilder | general crawlers Nö, wir haben bis jetzt nur ADware entfernt. Aber falls Du vor hast aus deinem Rechner nen Toaster zu bauen kannste Tune Up weiter benutzen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.02.2015, 12:02 | #11 |
| general crawlers `n toaster habe ich ja schon , meinste man braucht das nicht ? ich finds praktisch weil man immer was bereinigen kann und so , habe aber auch schon öfter gehört dass das was für dummies ist , aber bin ich ja auch . von daher . schaden richtet es ja wohl nicht an . m.f.g. |
07.02.2015, 15:52 | #12 | |
/// the machine /// TB-Ausbilder | general crawlersZitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.02.2015, 18:26 | #13 |
| general crawlers so , auch erledigt ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=bd5a45e1632b9648924ab16d72318762 # engine=22353 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2015-02-07 05:01:02 # local_time=2015-02-07 06:01:02 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode_1='' # compatibility_mode=5892 16776574 100 100 22542911 260861190 0 0 # scanned=223934 # found=15 # cleaned=15 # scan_time=19728 sh=68F39FDC5C97B7D3B93A4B793E3E9DAF1ED75344 ft=1 fh=c71c0011ed98cc6f vn="Variante von Win32/Toolbar.Babylon.F evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\dirkdererste\AppData\Local\Babylon\Setup\BExternal.dll.vir" sh=D128CBAF3DEF02BD11A92A43C36D540E47BF06E0 ft=1 fh=6abf192eb2d8af09 vn="Variante von Win32/Toolbar.Babylon.E evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\dirkdererste\AppData\Local\Babylon\Setup\IECookieLow.dll.vir" sh=C88D76106C34D093167BD69B433CFF15F24CFE68 ft=1 fh=c9f8a6e51b4e4ea2 vn="Variante von Win32/Toolbar.Babylon.E evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\dirkdererste\AppData\Local\Babylon\Setup\Setup.exe.vir" sh=1D9AE65A97C417A8083FB38EFDB8022EAE3A9698 ft=1 fh=8dd7dc1cf3445b5c vn="Variante von Win32/Adware.Synatix.A Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\dirkdererste\AppData\Roaming\Security System 2\uninstaller.exe.vir" sh=6FA33E5768F1E40A7CAA358C9A03356D7002119A ft=1 fh=35739b1b5e17d626 vn="Variante von Win32/Systweak.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Windows\system32\roboot.exe.vir" sh=348832D64C253FE6E7E770656518076BB4E3C61F ft=1 fh=4a025439f848ffb5 vn="Win32/AnyProtect.D evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\AppData\Local\nss61AF.tmp" sh=62D0AD7E219D16AB54D31417D58D40D550B4C1D9 ft=0 fh=0000000000000000 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\111127120115106.rsc" sh=8E3FB0901E5AFC704B4609902ED0DFBAD4F93092 ft=0 fh=0000000000000000 vn="HTML/Iframe.B.Gen Virus (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\AppData\Roaming\AVG\Rescue\Track Eraser\111227230414798.rsc" sh=FDCBC8D81CF255A328EE31C244613B1B5C56DC43 ft=1 fh=cfb484d79a6c1c3a vn="Variante von Win32/Toolbar.Visicom.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\AppData\Roaming\VisicomToolBar\gamesagogo_en_w3i_toolbar_3.2.0.36.exe" sh=1F53DE2B098AF90931AE36750AB4B0D779A7C2CB ft=1 fh=3b09867ae1cba431 vn="Win32/OpenCandy potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\Downloads\FreeAVIVideoConverter_CB-DL-Manager [1].exe" sh=3132CEDD6066AEFD82FC7CEB210193DD5CBA2678 ft=1 fh=26d53975373e166e vn="Variante von Win32/InstallCore.PK evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\Downloads\FreeAVIVideoConverter_CB-DL-Manager.exe" sh=8B1451E9C3E7A5028CC7BF5A7D3E8B5B1C69EFAF ft=1 fh=72d46938dae5e617 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\Downloads\VLC media player 32 Bit - CHIP-Installer (1).exe" sh=DB189999FB75EE11E3CBD4FCF30550FCA92514A7 ft=1 fh=4c37e42dc2a8448f vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\Downloads\VLC media player 32 Bit - CHIP-Installer.exe" sh=F711D2AA2F4CC4C6DA8C668A566152517DA39F1B ft=0 fh=0000000000000000 vn="Variante von Win32/Systweak.L evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\Downloads\wz180gev-32.msi" sh=A981E3D6F03D3BD57D1472F33A4093A01533F8A8 ft=1 fh=7aaf7b3d0491af48 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\Downloads\wzmp_8.exe" ------------------------------------------------------------------------------------- Results of screen317's Security Check version 0.99.95 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` AVG PC TuneUp 2015 AVG PC TuneUp 2015 (de-DE) AVG PC TuneUp 2015 TuneUp Utilities 2014 (de-DE) Java 8 Update 31 Java version 32-bit out of Date! Java 64-bit 8 Update 31 Adobe Flash Player 16.0.0.305 Adobe Reader 10.1.13 Adobe Reader out of Date! Google Chrome (40.0.2214.111) Google Chrome (40.0.2214.94) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` --------------------------------------------------------------------------------- FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 07-02-2015 Ran by dirkdererste (administrator) on DIRKDERERSTE-PC on 07-02-2015 18:18:41 Running from C:\Users\dirkdererste\Downloads Loaded Profiles: dirkdererste (Available profiles: dirkdererste) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files\ATK Hotkey\ASLDRSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe () C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVerMedia) C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe () C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe (Microsoft Corp.) C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\ProgramData\MobileBrServ\mbbService.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE (AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe (ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (ASUS) C:\Program Files\ASUS\ASUS CopyProtect\ASPG.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Windows\System32\ASUSTPE.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe () C:\Program Files\ATK Hotkey\KBFiltr.exe (AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Farbar) C:\Users\dirkdererste\Downloads\FRST (2).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4853760 2008-01-07] (Realtek Semiconductor) HKLM\...\Run: [ASUSTPE] => C:\Windows\system32\ASUSTPE.exe [106496 2007-10-12] (ASUS) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguix.exe [1140688 2015-01-16] (AVG Technologies CZ, s.r.o.) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-01-06] (Google Inc.) HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19ab7c-cbab-11e3-b7e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abdb-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abe7-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe8a-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe92-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe9e-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5dd-d506-11e3-befd-c030a9561ac3} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5e9-d506-11e3-befd-b68ac94258b5} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {31011372-66a4-11e4-88f4-adb511af100e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b50-3846-11e4-b727-a594aa94d86e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b5b-3846-11e4-b727-cfe712892541} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4235e5bc-8deb-11e3-bea2-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd209-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd244-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd24e-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd256-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd262-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb3442b-1faf-11e4-94c1-9483cebc1803} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb34437-1faf-11e4-94c1-ebf9039c5468} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5061e-2d56-11e4-806c-82b39df6fe7f} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5063d-2d56-11e4-806c-ff8e48defdcd} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {5899778b-f65b-11e3-908a-fe702680487d} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {589977db-f65b-11e3-908a-d444832a8c51} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7534b009-f659-11e3-935b-983f9ae39f7f} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba568-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba588-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {84d86f73-ebcf-11e3-99f4-e91098103f7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c282-3821-11e4-ac47-8fad69652c89} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c28d-3821-11e4-ac47-98a026ee637b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {8918ebcd-f632-11e3-a4cc-aae446c3b7d9} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {98b2279a-f666-11e3-82bf-8691ac93757f} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9d60af46-6833-11e4-9ae1-81f053ff7d7b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f017-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f054-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247885d-d82f-11e3-afed-ff56e36041fd} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247889a-d82f-11e3-afed-987030581f5d} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {b4a4281b-2f93-11e4-a053-b7ed9dff2029} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {ca5b6dde-19e3-11e0-83b8-806e6f6e6963} - E:\Autorun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {d85a1d2a-462a-11e4-94c3-8888219aad9a} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {db596716-c7e8-11e3-bdee-001e101fe70e} - I:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f01bf-2e39-11e4-b425-806e6f6e6963} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f0200-2e39-11e4-b425-c3e18252350b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {faf8fc99-6d70-11e4-b1d1-f474d68c3f10} - F:\AutoRun.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-1588098070-3651612994-842810468-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = hxxp://start.gamesagogo.iplay.com/searchresultsredirect.aspx?o=chrome&q={searchTerms} SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {47511E21-1A74-42AF-93B1-2D31D99E032B} URL = hxxp://de.wikipedia.org/wiki/Spezial:Search?search={searchTerms} SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {7B240E59-FCB8-4F40-9C17-688AC4BBDB6A} URL = hxxp://rover.ebay.com/rover/1/707-37276-23097-0/4?satitle={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Babylon Toolbar - {41B62AD3-5D43-40D1-9D43-F3539C1DB452} - No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1 FireFox: ======== FF Plugin: @adobe.com/AuthorwarePlayer -> C:\WINDOWS\system32\Macromed\AUTHORWA\np32asw.dll (Macromedia, Inc.) FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1588098070-3651612994-842810468-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-01-06] Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.ergebnisselive.de/" CHR Profile: C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-21] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-07] CHR Extension: (YouTube) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-21] CHR Extension: (Google-Suche) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-16] CHR Extension: (Internet Speed Tracker) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\jinlofiojphnmpllecgejammnjcmeipf [2015-02-07] CHR Extension: (Google Wallet) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Google Mail) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-16] CHR Profile: C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-13] CHR Extension: (YouTube) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-19] CHR Extension: (Google-Suche) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-19] CHR Extension: (Value apps) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon [2014-03-20] CHR Extension: (Google Wallet) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-13] CHR Extension: (Google Mail) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-19] CHR HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\DIRKDE~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [Not Found] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ALDITALKVerbindungsassistent_Service; C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [342984 2011-09-13] () R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () [File not signed] R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed] R2 AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [339968 2008-03-13] (AVerMedia) [File not signed] R2 AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [380928 2008-03-05] () [File not signed] R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [703952 2015-01-16] (AVG Technologies CZ, s.r.o.) R2 BingDesktopUpdate; C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-20] (Microsoft Corp.) R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] () R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed] R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2161976 2015-01-30] (AVG Technologies) R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [36664 2015-01-30] (AVG Technologies) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () S3 ASPI; C:\Windows\System32\DRIVERS\ASPI32.sys [84832 2002-07-17] (Adaptec) [File not signed] S3 AVerFx2hbtv; C:\Windows\System32\drivers\AVerFx2hbtv.sys [437888 2009-12-08] (AVerMedia TECHNOLOGIES, Inc.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( ) R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1772544 2008-05-22] () S3 tosporte; C:\Windows\System32\DRIVERS\tosporte.sys [41600 2006-10-10] (TOSHIBA Corporation) [File not signed] S3 tosrfbd; C:\Windows\System32\DRIVERS\tosrfbd.sys [113792 2006-11-30] (TOSHIBA CORPORATION) [File not signed] S3 tosrfbnp; C:\Windows\System32\Drivers\tosrfbnp.sys [36480 2006-11-20] (TOSHIBA Corporation) [File not signed] S1 Tosrfcom; C:\Windows\System32\Drivers\tosrfcom.sys [64896 2005-08-01] (TOSHIBA Corporation) [File not signed] S3 Tosrfhid; C:\Windows\System32\DRIVERS\Tosrfhid.sys [73600 2006-10-05] (TOSHIBA Corporation.) [File not signed] S3 tosrfnds; C:\Windows\System32\DRIVERS\tosrfnds.sys [18612 2005-01-06] (TOSHIBA Corporation.) [File not signed] S3 TosRfSnd; C:\Windows\System32\drivers\tosrfsnd.sys [53504 2006-11-02] (TOSHIBA Corporation) [File not signed] S3 Tosrfusb; C:\Windows\System32\DRIVERS\tosrfusb.sys [40960 2006-10-27] (TOSHIBA CORPORATION) [File not signed] R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [12320 2014-08-28] (TuneUp Software) S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 HTCAND32; System32\Drivers\ANDROIDUSB.sys [X] S3 hwusbfake; No ImagePath S3 IpInIp; No ImagePath S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] S3 motmodem; No ImagePath S3 NwlnkFlt; No ImagePath S3 NwlnkFwd; No ImagePath S3 usbbus; system32\DRIVERS\lgusbbus.sys [X] S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X] S3 USBModem; system32\DRIVERS\lgusbmodem.sys [X] S3 VNUSB; system32\DRIVERS\VNUSB.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-07 18:18 - 2015-02-07 18:18 - 01124352 _____ (Farbar) C:\Users\dirkdererste\Downloads\FRST (2).exe 2015-02-07 18:17 - 2015-02-07 18:17 - 00001080 _____ () C:\Users\dirkdererste\Desktop\checkup.txt 2015-02-07 18:08 - 2015-02-07 18:08 - 00852573 _____ () C:\Users\dirkdererste\Downloads\SecurityCheck.exe 2015-02-07 18:03 - 2015-02-07 18:04 - 00004530 _____ () C:\Users\dirkdererste\Desktop\ESET.txt 2015-02-07 12:20 - 2015-02-07 12:20 - 02347384 _____ (ESET) C:\Users\dirkdererste\Downloads\esetsmartinstaller_deu.exe 2015-02-06 00:11 - 2015-02-06 00:11 - 00003660 _____ () C:\Windows\PFRO.log 2015-02-05 19:41 - 2015-01-30 17:22 - 00036664 _____ (AVG Technologies) C:\Windows\system32\uxtuneup.dll 2015-02-05 19:41 - 2015-01-30 17:22 - 00025912 _____ (AVG Technologies) C:\Windows\system32\authuitu.dll 2015-02-01 00:05 - 2015-02-01 00:06 - 16634392 _____ (AVG Technologies) C:\Users\dirkdererste\Downloads\avg_gse_stb_all_445p1_105.exe 2015-02-01 00:01 - 2015-02-01 00:01 - 04579240 _____ (AVG Technologies) C:\Users\dirkdererste\Downloads\avg_isct_stb_all_2015_5315_evol1.exe 2015-02-01 00:01 - 2015-02-01 00:01 - 00000000 ____D () C:\Users\dirkdererste\AppData\Local\Avg2015 2015-01-30 23:41 - 2015-01-30 23:41 - 01121792 _____ (Farbar) C:\Users\dirkdererste\Downloads\FRST (1).exe 2015-01-30 23:34 - 2015-01-30 23:34 - 00000000 ____D () C:\Windows\ERUNT 2015-01-30 23:32 - 2015-01-30 23:32 - 01707939 _____ (Thisisu) C:\Users\dirkdererste\Downloads\JRT.exe 2015-01-30 23:17 - 2015-01-30 23:23 - 00000000 ____D () C:\AdwCleaner 2015-01-30 23:16 - 2015-01-30 23:16 - 02194432 _____ () C:\Users\dirkdererste\Downloads\AdwCleaner_4.109.exe 2015-01-30 22:47 - 2015-01-30 22:47 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-30 22:41 - 2015-01-30 22:42 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\dirkdererste\Downloads\mbam-setup-2.0.4.1028.exe 2015-01-27 19:05 - 2015-01-27 19:03 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2015-01-27 19:05 - 2015-01-27 19:03 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2015-01-27 19:05 - 2015-01-27 19:03 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2015-01-20 19:45 - 2015-01-20 19:45 - 00000000 ____D () C:\Users\Public\Documents\sun 2015-01-20 19:44 - 2015-01-20 19:44 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\LibreOffice 2015-01-20 19:31 - 2015-02-04 18:53 - 00000000 ____D () C:\Users\dirkdererste\Desktop\LernZeugs 2015-01-20 13:43 - 2015-01-20 13:52 - 220569600 _____ () C:\Users\dirkdererste\LibreOffice_4.2.8_Win_x86.msi 2015-01-19 17:26 - 2015-01-19 17:27 - 00027860 _____ () C:\Users\dirkdererste\Downloads\Addition.txt 2015-01-19 17:25 - 2015-02-07 18:18 - 00023713 _____ () C:\Users\dirkdererste\Downloads\FRST.txt 2015-01-19 17:25 - 2015-02-07 18:18 - 00000000 ____D () C:\FRST 2015-01-19 17:24 - 2015-01-19 17:24 - 01118208 _____ (Farbar) C:\Users\dirkdererste\Downloads\FRST.exe 2015-01-14 17:28 - 2014-12-19 01:25 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 17:12 - 2014-12-06 04:14 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 17:12 - 2014-12-06 04:14 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 17:12 - 2014-12-06 04:14 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2015-01-14 17:12 - 2014-12-06 04:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2015-01-12 18:30 - 2015-01-12 18:36 - 00000022 _____ () C:\Users\dirkdererste\Downloads\Gmail.zip 2015-01-10 13:13 - 2015-01-10 13:13 - 00012602 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvv-2FbgLWtxKiUPAnNHg9Ex7XJiyYrBIUKWniOSaYy513hlfagHce8Y9q2fBnUi46j8LMJiN4Ibo0jYqNA5K4b4-2BrIkMFz4DmX-2BQqOw6O-2BALSXByyiQFSdvPgiEF8YKq1mRsmIvzrESP5BopAg0olkOxyP-2FBKvXhu1j 2015-01-10 13:13 - 2015-01-10 13:13 - 00006172 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvvsJzMbrsjw5UKW3z-2Bs2dvjRlPojiGebXy7e5eGczAbLu-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FO3NCXbmNOMaTkWVyij4LGMR 2015-01-10 13:12 - 2015-01-10 13:12 - 00014005 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvszYSjXqZ0eKiFnXjlLTe-2BMizo92Hdw-2BByllGk1G2Tgge-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FbWYBnp7TdSaoQHTs8HCgK 2015-01-10 13:12 - 2015-01-10 13:12 - 00014005 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvszYSjXqZ0eKiFnXjlLTe-2BMizo92Hdw-2BByllGk1G2Tgge-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FbWYBnp7TdSaoQHTs8 (1) 2015-01-10 13:11 - 2015-01-10 13:11 - 00006448 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvuNQjNdmO9DbIZqVdhXDmcImLLl-2FMJgwS5ROnb8F4Ar8-2B-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FO3NCXbmNOMaTkWVyij4LG ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-07 18:17 - 2006-11-02 11:33 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-07 17:57 - 2012-12-29 18:23 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\VisicomToolBar 2015-02-07 17:41 - 2011-01-06 20:20 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-07 17:39 - 2012-07-16 10:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-02-07 17:11 - 2006-11-02 13:47 - 00003616 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-07 17:11 - 2006-11-02 13:47 - 00003616 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-07 16:41 - 2011-01-06 20:20 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-07 15:45 - 2014-09-03 18:24 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\vlc 2015-02-07 09:31 - 2014-03-24 23:00 - 01943143 _____ () C:\Windows\WindowsUpdate.log 2015-02-07 09:11 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-06 22:43 - 2014-06-12 23:47 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-02-06 18:25 - 2012-12-29 18:25 - 00000392 _____ () C:\Windows\Tasks\FreeFileViewerUpdateChecker.job 2015-02-05 23:36 - 2014-06-27 14:57 - 00000000 ____D () C:\Users\dirkdererste\Documents\AVerTV 2015-02-05 19:39 - 2012-04-08 09:03 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-02-05 19:39 - 2011-05-21 12:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-02-04 23:50 - 2011-01-06 16:43 - 00000000 ____D () C:\Users\dirkdererste 2015-02-01 10:11 - 2014-09-14 00:30 - 00259816 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-02-01 00:14 - 2014-09-14 09:32 - 00057120 _____ () C:\Users\dirkdererste\AppData\Local\GDIPFONTCACHEV1.DAT 2015-02-01 00:09 - 2014-09-19 19:44 - 00000000 ____D () C:\Users\dirkdererste\AppData\Local\AvgSetupLog 2015-02-01 00:04 - 2011-11-15 19:32 - 00000000 ____D () C:\ProgramData\MFAData 2015-01-31 20:54 - 2014-11-02 10:34 - 00000000 ____D () C:\Users\dirkdererste\Desktop\Neuer Ordner 2015-01-30 23:26 - 2012-05-06 11:55 - 00000000 ____D () C:\Windows\de 2015-01-30 17:23 - 2014-09-19 19:58 - 00037176 _____ (AVG Technologies) C:\Windows\system32\TURegOpt.exe 2015-01-29 18:32 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\tracing 2015-01-27 19:06 - 2013-10-21 16:27 - 00000000 ____D () C:\ProgramData\Oracle 2015-01-27 19:05 - 2011-01-10 00:43 - 00000000 ____D () C:\Program Files\Java 2015-01-27 19:04 - 2014-11-04 16:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-01-27 19:03 - 2014-11-04 16:35 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2015-01-15 22:52 - 2012-07-27 19:58 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\Canon 2015-01-15 20:45 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2015-01-14 17:28 - 2013-07-19 12:23 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-14 17:13 - 2006-11-02 11:24 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2015-01-12 23:59 - 2011-01-07 15:25 - 00000000 ___RD () C:\Users\dirkdererste\Desktop\Kram ==================== Files in the root of some directories ======= 2007-06-12 19:34 - 2007-06-12 19:34 - 0035822 _____ () C:\Program Files\Common Files\ASPG_icon.ico 2008-05-22 18:35 - 2008-05-22 18:35 - 0051962 _____ () C:\Program Files\Common Files\banner.jpg 2008-07-02 04:28 - 2008-07-02 04:28 - 0061440 _____ () C:\Program Files\Common Files\CPInstallAction.dll 2011-10-30 00:00 - 2011-10-30 00:00 - 0024206 _____ () C:\Users\dirkdererste\AppData\Roaming\UserTile.png 2014-09-27 14:04 - 2014-09-27 14:05 - 0010828 _____ () C:\Users\dirkdererste\AppData\Roaming\WtgInstaller.txt 2011-01-06 20:24 - 2014-08-27 22:09 - 0001356 _____ () C:\Users\dirkdererste\AppData\Local\d3d9caps.dat 2011-11-21 21:46 - 2011-11-21 21:46 - 0000000 _____ () C:\Users\dirkdererste\AppData\Local\{0CE875FA-9C01-4FE6-91E4-8DD35D1352B1} Some content of TEMP: ==================== C:\Users\dirkdererste\AppData\Local\Temp\avguirn_082101543405.exe C:\Users\dirkdererste\AppData\Local\Temp\jre-8u31-windows-au.exe C:\Users\dirkdererste\AppData\Local\Temp\Quarantine.exe C:\Users\dirkdererste\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-07 09:18 ==================== End Of Log ============================ |
08.02.2015, 11:16 | #14 |
/// the machine /// TB-Ausbilder | general crawlers Adobe updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19ab7c-cbab-11e3-b7e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abdb-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abe7-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe8a-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe92-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe9e-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5dd-d506-11e3-befd-c030a9561ac3} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5e9-d506-11e3-befd-b68ac94258b5} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {31011372-66a4-11e4-88f4-adb511af100e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b50-3846-11e4-b727-a594aa94d86e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b5b-3846-11e4-b727-cfe712892541} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4235e5bc-8deb-11e3-bea2-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd209-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd244-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd24e-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd256-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd262-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb3442b-1faf-11e4-94c1-9483cebc1803} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb34437-1faf-11e4-94c1-ebf9039c5468} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5061e-2d56-11e4-806c-82b39df6fe7f} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5063d-2d56-11e4-806c-ff8e48defdcd} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {5899778b-f65b-11e3-908a-fe702680487d} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {589977db-f65b-11e3-908a-d444832a8c51} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7534b009-f659-11e3-935b-983f9ae39f7f} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba568-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba588-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {84d86f73-ebcf-11e3-99f4-e91098103f7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c282-3821-11e4-ac47-8fad69652c89} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c28d-3821-11e4-ac47-98a026ee637b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {8918ebcd-f632-11e3-a4cc-aae446c3b7d9} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {98b2279a-f666-11e3-82bf-8691ac93757f} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9d60af46-6833-11e4-9ae1-81f053ff7d7b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f017-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f054-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247885d-d82f-11e3-afed-ff56e36041fd} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247889a-d82f-11e3-afed-987030581f5d} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {b4a4281b-2f93-11e4-a053-b7ed9dff2029} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {ca5b6dde-19e3-11e0-83b8-806e6f6e6963} - E:\Autorun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {d85a1d2a-462a-11e4-94c3-8888219aad9a} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {db596716-c7e8-11e3-bdee-001e101fe70e} - I:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f01bf-2e39-11e4-b425-806e6f6e6963} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f0200-2e39-11e4-b425-c3e18252350b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {faf8fc99-6d70-11e4-b1d1-f474d68c3f10} - F:\AutoRun.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.02.2015, 19:24 | #15 |
| general crawlers hallo also eine Fixlog.txt erstellt das nicht , es erstellt eine FRST.txt und eine Addition.txt Datei . hallo , nochmal jetzt ging`s doch Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 08-02-2015 Ran by dirkdererste at 2015-02-09 19:03:58 Run:1 Running from C:\Users\dirkdererste\Desktop Loaded Profiles: dirkdererste (Available profiles: dirkdererste) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19ab7c-cbab-11e3-b7e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abdb-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abe7-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe8a-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe92-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe9e-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5dd-d506-11e3-befd-c030a9561ac3} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5e9-d506-11e3-befd-b68ac94258b5} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {31011372-66a4-11e4-88f4-adb511af100e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b50-3846-11e4-b727-a594aa94d86e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b5b-3846-11e4-b727-cfe712892541} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4235e5bc-8deb-11e3-bea2-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd209-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd244-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd24e-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd256-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd262-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb3442b-1faf-11e4-94c1-9483cebc1803} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb34437-1faf-11e4-94c1-ebf9039c5468} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5061e-2d56-11e4-806c-82b39df6fe7f} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5063d-2d56-11e4-806c-ff8e48defdcd} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {5899778b-f65b-11e3-908a-fe702680487d} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {589977db-f65b-11e3-908a-d444832a8c51} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7534b009-f659-11e3-935b-983f9ae39f7f} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba568-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba588-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {84d86f73-ebcf-11e3-99f4-e91098103f7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c282-3821-11e4-ac47-8fad69652c89} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c28d-3821-11e4-ac47-98a026ee637b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {8918ebcd-f632-11e3-a4cc-aae446c3b7d9} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {98b2279a-f666-11e3-82bf-8691ac93757f} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9d60af46-6833-11e4-9ae1-81f053ff7d7b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f017-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f054-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247885d-d82f-11e3-afed-ff56e36041fd} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247889a-d82f-11e3-afed-987030581f5d} - F:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {b4a4281b-2f93-11e4-a053-b7ed9dff2029} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {ca5b6dde-19e3-11e0-83b8-806e6f6e6963} - E:\Autorun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {d85a1d2a-462a-11e4-94c3-8888219aad9a} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {db596716-c7e8-11e3-bdee-001e101fe70e} - I:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f01bf-2e39-11e4-b425-806e6f6e6963} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f0200-2e39-11e4-b425-c3e18252350b} - F:\AutoRun.exe HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {faf8fc99-6d70-11e4-b1d1-f474d68c3f10} - F:\AutoRun.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION Emptytemp: ***************** "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e19ab7c-cbab-11e3-b7e1-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{0e19ab7c-cbab-11e3-b7e1-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e19abdb-cbab-11e3-b7e1-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{0e19abdb-cbab-11e3-b7e1-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e19abe7-cbab-11e3-b7e1-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{0e19abe7-cbab-11e3-b7e1-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{18a9fe8a-c7c1-11e3-bd56-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{18a9fe8a-c7c1-11e3-bd56-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{18a9fe92-c7c1-11e3-bd56-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{18a9fe92-c7c1-11e3-bd56-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{18a9fe9e-c7c1-11e3-bd56-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{18a9fe9e-c7c1-11e3-bd56-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2505d5dd-d506-11e3-befd-c030a9561ac3}" => Key deleted successfully. HKCR\CLSID\{2505d5dd-d506-11e3-befd-c030a9561ac3} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2505d5e9-d506-11e3-befd-b68ac94258b5}" => Key deleted successfully. HKCR\CLSID\{2505d5e9-d506-11e3-befd-b68ac94258b5} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{31011372-66a4-11e4-88f4-adb511af100e}" => Key deleted successfully. HKCR\CLSID\{31011372-66a4-11e4-88f4-adb511af100e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{41a94b50-3846-11e4-b727-a594aa94d86e}" => Key deleted successfully. HKCR\CLSID\{41a94b50-3846-11e4-b727-a594aa94d86e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{41a94b5b-3846-11e4-b727-cfe712892541}" => Key deleted successfully. HKCR\CLSID\{41a94b5b-3846-11e4-b727-cfe712892541} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4235e5bc-8deb-11e3-bea2-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{4235e5bc-8deb-11e3-bea2-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{437dd209-cc5b-11e3-bf9d-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{437dd209-cc5b-11e3-bf9d-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{437dd244-cc5b-11e3-bf9d-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{437dd244-cc5b-11e3-bf9d-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{437dd24e-cc5b-11e3-bf9d-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{437dd24e-cc5b-11e3-bf9d-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{437dd256-cc5b-11e3-bf9d-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{437dd256-cc5b-11e3-bf9d-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{437dd262-cc5b-11e3-bf9d-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{437dd262-cc5b-11e3-bf9d-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4fb3442b-1faf-11e4-94c1-9483cebc1803}" => Key deleted successfully. HKCR\CLSID\{4fb3442b-1faf-11e4-94c1-9483cebc1803} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4fb34437-1faf-11e4-94c1-ebf9039c5468}" => Key deleted successfully. HKCR\CLSID\{4fb34437-1faf-11e4-94c1-ebf9039c5468} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{53a5061e-2d56-11e4-806c-82b39df6fe7f}" => Key deleted successfully. HKCR\CLSID\{53a5061e-2d56-11e4-806c-82b39df6fe7f} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{53a5063d-2d56-11e4-806c-ff8e48defdcd}" => Key deleted successfully. HKCR\CLSID\{53a5063d-2d56-11e4-806c-ff8e48defdcd} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5899778b-f65b-11e3-908a-fe702680487d}" => Key deleted successfully. HKCR\CLSID\{5899778b-f65b-11e3-908a-fe702680487d} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{589977db-f65b-11e3-908a-d444832a8c51}" => Key deleted successfully. HKCR\CLSID\{589977db-f65b-11e3-908a-d444832a8c51} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7534b009-f659-11e3-935b-983f9ae39f7f}" => Key deleted successfully. HKCR\CLSID\{7534b009-f659-11e3-935b-983f9ae39f7f} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7f8ba568-c57e-11e3-9624-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{7f8ba568-c57e-11e3-9624-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7f8ba588-c57e-11e3-9624-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{7f8ba588-c57e-11e3-9624-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{84d86f73-ebcf-11e3-99f4-e91098103f7e}" => Key deleted successfully. HKCR\CLSID\{84d86f73-ebcf-11e3-99f4-e91098103f7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{85d3c282-3821-11e4-ac47-8fad69652c89}" => Key deleted successfully. HKCR\CLSID\{85d3c282-3821-11e4-ac47-8fad69652c89} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{85d3c28d-3821-11e4-ac47-98a026ee637b}" => Key deleted successfully. HKCR\CLSID\{85d3c28d-3821-11e4-ac47-98a026ee637b} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8918ebcd-f632-11e3-a4cc-aae446c3b7d9}" => Key deleted successfully. HKCR\CLSID\{8918ebcd-f632-11e3-a4cc-aae446c3b7d9} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{98b2279a-f666-11e3-82bf-8691ac93757f}" => Key deleted successfully. HKCR\CLSID\{98b2279a-f666-11e3-82bf-8691ac93757f} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9d60af46-6833-11e4-9ae1-81f053ff7d7b}" => Key deleted successfully. HKCR\CLSID\{9d60af46-6833-11e4-9ae1-81f053ff7d7b} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e75f017-cc80-11e3-86e1-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{9e75f017-cc80-11e3-86e1-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e75f054-cc80-11e3-86e1-00235462ea7e}" => Key deleted successfully. HKCR\CLSID\{9e75f054-cc80-11e3-86e1-00235462ea7e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a247885d-d82f-11e3-afed-ff56e36041fd}" => Key deleted successfully. HKCR\CLSID\{a247885d-d82f-11e3-afed-ff56e36041fd} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a247889a-d82f-11e3-afed-987030581f5d}" => Key deleted successfully. HKCR\CLSID\{a247889a-d82f-11e3-afed-987030581f5d} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b4a4281b-2f93-11e4-a053-b7ed9dff2029}" => Key deleted successfully. HKCR\CLSID\{b4a4281b-2f93-11e4-a053-b7ed9dff2029} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ca5b6dde-19e3-11e0-83b8-806e6f6e6963}" => Key deleted successfully. HKCR\CLSID\{ca5b6dde-19e3-11e0-83b8-806e6f6e6963} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d85a1d2a-462a-11e4-94c3-8888219aad9a}" => Key deleted successfully. HKCR\CLSID\{d85a1d2a-462a-11e4-94c3-8888219aad9a} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{db596716-c7e8-11e3-bdee-001e101fe70e}" => Key deleted successfully. HKCR\CLSID\{db596716-c7e8-11e3-bdee-001e101fe70e} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f08f01bf-2e39-11e4-b425-806e6f6e6963}" => Key deleted successfully. HKCR\CLSID\{f08f01bf-2e39-11e4-b425-806e6f6e6963} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f08f0200-2e39-11e4-b425-c3e18252350b}" => Key deleted successfully. HKCR\CLSID\{f08f0200-2e39-11e4-b425-c3e18252350b} => Key not found. "HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{faf8fc99-6d70-11e4-b1d1-f474d68c3f10}" => Key deleted successfully. HKCR\CLSID\{faf8fc99-6d70-11e4-b1d1-f474d68c3f10} => Key not found. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. EmptyTemp: => Removed 230.4 MB temporary data. The system needed a reboot. ==== End of Fixlog 19:04:10 ==== hat gleich neugestartet . was mir aufgefallen ist , meine googlestarobefläche sieht anders aus , das hatte ich mal was runtergeladen , weil es sich als googlechromedownload ausgab , was dann irgendwie alles verändert hat und sich ewig nicht mehr wegmachen lies , ich glaube dass das jetzt ganz weg ist .habe aber vergessen wie der scheiß geheissen hat . das hatte jedenfalls jeden browser übernommen . jetzt scheint das ganz weg zu sein . und das tuneup dachte ich ist ganz gut , weil mei laptop immer so laut ist , dachte ich ich kann dadurch was verbessern , ist aber nicht so . aber das mir das was kaputt macht habe ich jetzt auch noch nicht gemerkt , und ich nehme das schon seit 4 jahren oder so . was du jetzt mit defogger meinst weiß ich aber nicht , soll ich das jetzt nachdem alles fertig ist runterladen und durchlaufen lassen ? was ist wenn ich das was ich runtergeladen habe einfach behalte und es ab und zu alles so durchlaufen lasse wie jetzt die tage ? stört doch nicht oder ? ansonsten danke für die hilfe . wenn ich mal etwas abzwiegen kann spende ich mal was . arbeite z.zt. nicht , da ist das etwas schwierig . wenn du das löschst was du löschen willst , bleibt ja die konversation hier erhalte , so das ich jederzeit mal was nachlesen kann , oder ? ansonsten nochmal danke . m.f.g. |
Themen zu general crawlers |
ahnung, chrome, entferne, entfernen, gefährlich, general, general crawlers, geschlossen, geändert, google, guten, hinweis, kaufen, mindestens, nichts, notwendig, profil, runterladen |