|
Plagegeister aller Art und deren Bekämpfung: db22.exe wurde von Stinger gefunden aber nicht gelöschtWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
15.01.2015, 23:39 | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ | db22.exe wurde von Stinger gefunden aber nicht gelöscht Bitte auch ne neue Addition.txt erstellen, dazu FRST starten und einen Haken setzen bei Addition.txt, dann auf Scan klicken.
__________________ Logfiles bitte immer in CODE-Tags posten |
15.01.2015, 23:56 | #17 |
| db22.exe wurde von Stinger gefunden aber nicht gelöscht FRST Additions Logfile:
__________________Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-01-2015 01 Ran by RAaM2 at 2015-01-15 23:41:51 Running from C:\Users\RAaM2\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) AC3Filter 2.6.0b (HKLM\...\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky) Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.257 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.257 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Adobe Shockwave Player 11.5 (HKLM\...\Adobe Shockwave Player) (Version: 11.5.1.601 - Adobe Systems, Inc.) Adobe® Photoshop® Album Starter Edition 3.2 (HKLM\...\Adobe® Photoshop® Album Starter Edition 3.2) (Version: 3.2.0 - Adobe: Kreativität, Marketing und Dokumentenmanagement) ALDI Foto Service (HKLM\...\ALDI Foto Service D) (Version: 4.5.9.141 - MAGIX AG) ALDI Nord Foto Manager Free (HKLM\...\ALDI Nord Foto Manager Free D) (Version: 6.0.1.491 - MAGIX AG) Aldi Nord Fotoservice (HKLM\...\Aldi Nord Fotoservice_is1) (Version: - ) ALDI Nord Online Druck Service (HKLM\...\ALDI Nord Online Druck Service D) (Version: 4.5.1.0 - MAGIX AG) Amazon MP3-Downloader 1.0.18 (HKU\S-1-5-21-837243161-1062950140-3748333167-1000\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC) Android SDK Tools (HKLM\...\Android SDK Tools) (Version: 1.16 - Google Inc.) Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASIO4ALL (HKLM\...\ASIO4ALL) (Version: - ) Audacity 2.0.3 (HKLM\...\Audacity_is1) (Version: 2.0.3 - Audacity Team) AudioCon (HKLM\...\AudioCon) (Version: 1.0 - Basement Softworks) Audiograbber 1.83 SE (HKLM\...\Audiograbber) (Version: 1.83 SE - Audiograbber) Audiograbber MP3-Plugin (HKLM\...\Audiograbber-Lame) (Version: 1.0 - AG) Avid Mbox 2 Pro Driver (x86) (HKLM\...\{DEE30D6A-B4B5-4F34-9554-312DD969F5EA}) (Version: 9.0 - Avid Technology, Inc.) BestPractice (remove only) (HKLM\...\BestPractice) (Version: - ) CamStudio (HKLM\...\CamStudio) (Version: - ) CamStudio Lossless Codec v1.4 (HKLM\...\CamStudio Lossless Codec_is1) (Version: - (c) 2003 RenderSoft Software, Modifications Copyright © 2008 Jake P.) Canon IJ Network Scan Utility (HKLM\...\Canon_IJ_Network_Scan_UTILITY) (Version: - ) Canon IJ Network Tool (HKLM\...\Canon_IJ_Network_UTILITY) (Version: - ) Canon MP Navigator EX 1.1 (HKLM\...\MP Navigator EX 1.1) (Version: - ) Canon MX850 series (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX850_series) (Version: - ) Canon MX850 series Benutzerregistrierung (HKLM\...\Canon MX850 series Benutzerregistrierung) (Version: - ) Canon My Printer (HKLM\...\CanonMyPrinter) (Version: - ) Canon Utilities Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version: - ) Canon Utilities Solution Menu (HKLM\...\CanonSolutionMenu) (Version: - ) Cartoonist 1.3 (HKLM\...\Cartoonist_is1) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.4852 - CDBurnerXP) CD-LabelPrint (HKLM\...\MediaNavigation.CDLabelPrint) (Version: - ) Cheatbook Database 2010 (HKLM\...\Cheatbook Database 2010) (Version: - ) ClipGrab 3.2.0.10 (HKLM\...\{8A1033B0-EF33-4FB5-97A1-C47A7DCDD7E6}_is1) (Version: - Philipp Schmieder Medien) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Corel MediaOne (HKLM\...\{A062A15F-9CAC-4B88-98DF-87628A0BD721}) (Version: 2.100.0000 - Corel Corporation) CorelDRAW Essential Edition 3 (HKLM\...\_{ADDBE07D-95B8-4789-9C76-187FFF9624B4}) (Version: - Corel Corporation) CorelDRAW Essential Edition 3 (Version: 3.0 - Corel Corporation) Hidden cyberJack Base Components (HKLM\...\{FC338210-F594-11D3-BA24-00001C3AB4DF}) (Version: 6.10.0 - REINER SCT) CyberLink LabelPrint (HKLM\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2024 - CyberLink Corp.) CyberLink MediaShow (HKLM\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 4.1.3121 - CyberLink Corp.) CyberLink PhotoNow (HKLM\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.6622 - CyberLink Corp.) CyberLink Power2Go (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3213 - CyberLink Corp.) CyberLink PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.2214 - CyberLink Corp.) CyberLink PowerDVD 9 (HKLM\...\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.0.2010 - CyberLink Corp.) CyberLink PowerDVD Copy (HKLM\...\{E3D04529-6EDB-11D8-A372-0050BAE317E1}) (Version: 1.0.6720 - CyberLink Corp.) CyberLink PowerProducer (HKLM\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.0.2.2129 - CyberLink Corp.) DE (Version: 3.0 - Corel Corporation) Hidden DivX Codec (HKLM\...\{7B63B2922B174135AFC0E1377DD81EC2}) (Version: 6.9.1 - DivX, Inc.) DivX Converter (HKLM\...\{B13A7C41581B411290FBC0395694E2A9}) (Version: 7.1.0 - DivX, Inc.) DivX Player (HKLM\...\{8ADFC4160D694100B5B8A22DE9DCABD9}) (Version: 7.2.0 - DivX, Inc.) DivX Plus DirectShow Filters (HKLM\...\DivX Plus DirectShow Filters) (Version: - DivX, Inc.) DivX Plus Web Player (HKLM\...\{B7050CBDB2504B34BC2A9CA0A692CC29}) (Version: 2.0.0 - DivX,Inc.) Dropbox (HKU\S-1-5-21-837243161-1062950140-3748333167-1000\...\Dropbox) (Version: 3.0.3 - Dropbox, Inc.) DVBViewer Pro (HKLM\...\DVBViewer Pro_is1) (Version: 5.2.8 - CM&V) DVD Shrink 3.2 deutsch (DeCSS-frei) (HKLM\...\DVD Shrink DE_is1) (Version: - DVD Shrink) DVDStyler v2.2 (HKLM\...\DVDStyler_is1) (Version: - ) eLicenser Control (HKLM\...\eLicenser Control) (Version: - Steinberg Media Technologies GmbH) ElsterFormular (HKLM\...\ElsterFormular) (Version: 15.1.13904 - Landesfinanzdirektion Thüringen) Eraser 6.0.7.1893 (HKLM\...\{38BA2875-D7AD-4611-ABA3-C385051ADF42}) (Version: 6.7.1893 - The Eraser Project) eReg (Version: 1.20.138.34 - Logitech, Inc.) Hidden ERUNT 1.1j (HKLM\...\ERUNT_is1) (Version: - Lars Hederer) EXIF Date Changer v2.5 (HKLM\...\{26CA1B07-BC53-4196-B9C2-A11C6F6F3E08}_is1) (Version: - Rellik Software) Firebird SQL Server - MAGIX Edition (HKLM\...\{3E6F0CAD-EE38-42A5-9EEA-AE17A55BF2D4}) (Version: 2.1.23.0 - MAGIX AG) FormatFactory 3.1.1 (HKLM\...\FormatFactory) (Version: 3.1.1 - Free Time) Free YouTube Download version 3.2.1.320 (HKLM\...\Free YouTube Download_is1) (Version: 3.2.1.320 - DVDVideoSoft Ltd.) FreeFileSync 5.11 (HKLM\...\FreeFileSync) (Version: 5.11 - Zenju) FreeRIP v3.42 (HKLM\...\{501451DE-5808-4599-B544-8BD0915B6B24}_is1) (Version: 3.42 - MGShareware) Frets On Fire (HKLM\...\Frets on Fire) (Version: 1.3.110-win32 - ) GameSpy Arcade (HKLM\...\GameSpy Arcade) (Version: - ) Genesys USB Mass Storage Device (HKLM\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: 2.5.0.0 - Genesys Logic) GeoSetter 3.4.16 (HKLM\...\GeoSetter_is1) (Version: - Friedemann Schmidt) Google Chrome (HKU\S-1-5-21-837243161-1062950140-3748333167-1000\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.) Google Drive (HKLM\...\{C60F3836-333A-4AE2-B526-CFDBA143A9BA}) (Version: 1.18.7821.2489 - Google, Inc.) Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden Google-Schnellsuchfeld (HKLM\...\Quick Search Box) (Version: 1.2.1151.245 - Google, Inc.) GPS-Track-Analyse.NET 6.0 (HKLM\...\GPS-Track-Analyse.NET 6.0_is1) (Version: - ) G-Series_ASIO32 (HKLM\...\{8791C74C-2FFD-11E0-B2E6-00269E8DC781}) (Version: 1.1.2 - ZOOM) HandBrake 0.10.0 (HKLM\...\HandBrake) (Version: 0.10.0 - ) Hardcopy (C:\Program Files\Hardcopy) (HKLM\...\Hardcopy(C__Program Files_Hardcopy)) (Version: 16.1.05 - ) Interlok driver setup x32 (HKLM\...\{25613C10-27D2-410B-942B-D922D5C3A7BE}) (Version: 5.9.0 - PACE Anti-Piracy, Inc.) IrfanView (remove only) (HKLM\...\IrfanView) (Version: - ) iriver plus 3 (remove only) (HKLM\...\iriver plus 3) (Version: - ) ITN Converter 1.82 (HKLM\...\ITN Converter_is1) (Version: 1.82 - Benichou Software) Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle) Java SE Development Kit 7 Update 17 (HKLM\...\{32A3A4F4-B792-11D6-A78A-00B0D0170170}) (Version: 1.7.0.170 - Oracle) Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden Kastor - Stream Recorder V 1.0 (HKLM\...\{CB84FEF6-C573-4328-B9A4-B29568A4E10E}_is1) (Version: 1.0.0.0 - KastorSoft) LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version: - ) LAV Filters 0.58.1 (HKLM\...\lavfilters_is1) (Version: 0.58.1 - Hendrik Leppkes) Logitech SetPoint 6.61 (HKLM\...\sp6) (Version: 6.61.15 - Logitech) Lupas Rename 2000 v4.2 (HKLM\...\Lupas Rename 2000_is1) (Version: - Ivan Anton Albarracin) Macrium Reflect - Free Edition (HKLM\...\{EB85CC54-5E9A-4D33-B319-593B82291ABC}) (Version: 4.2.2098 - Macrium) MAGIX Video deLuxe 2006 PLUS (D) (HKLM\...\MAGIX Video deLuxe 2006 PLUS D) (Version: 5.5.0.31 - MAGIX AG) MAGIX Xtreme Foto Designer 6 6.0.19.0 (D) (HKLM\...\MAGIX Xtreme Foto Designer 6 D) (Version: 6.0.19.0 - MAGIX AG) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) MEDION Fotos auf CD & DVD SE Nord (HKLM\...\MEDION Fotos auf CD & DVD SE Nord D) (Version: 8.0.3.4 - MAGIX AG) Medion Home Cinema (HKLM\...\InstallShield_{AB770FDE-8087-4C98-9A85-BD64262C104C}) (Version: 6.0.0000 - CyberLink Corp.) Medion Home Cinema (Version: 6.0.0000 - CyberLink Corp.) Hidden MergeModule_x86 (Version: 9.0.00 - Sony Corporation) Hidden Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 German Language Pack (HKLM\...\{E78BFA60-5393-4C38-82AB-E8019E464EB4}) (Version: 1.1.4322 - Microsoft) Microsoft .NET Framework 1.1 Security Update (KB953297) (HKLM\...\M953297) (Version: - ) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation) Microsoft Office Live Add-in 1.4 (HKLM\...\{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}) (Version: 2.0.3008.0 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (German) (HKLM\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-837243161-1062950140-3748333167-1000\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [DEU] (HKLM\...\{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework 2.0 Core Components (x86) ENU (HKLM\...\{FF63121D-91C6-42CC-B341-F1AA729728E7}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Sync Framework 2.0 Provider Services (x86) ENU (HKLM\...\{D3A80508-CD83-4CA3-8671-914A1BC78B61}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Microsoft Works 4 Converter (HKLM\...\{D18AF23E-AB28-4040-9396-28413B2C3B41}) (Version: 9.8.0000 - Microsoft Corporation) Microsoft Works 6-9 Converter (HKLM\...\{172423F9-522A-483A-AD65-03600CE4CA4F}) (Version: 9.7.0000 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.2.173.0 - Microsoft Corporation) MidiEditor (HKU\S-1-5-21-837243161-1062950140-3748333167-1000\...\MidiEditor) (Version: - ) MotoGP URT 3 (HKLM\...\MotoGP URT 3_is1) (Version: - THQ) Movie Converter (remove only) (HKLM\...\Movie Converter) (Version: - ) MozBackup 1.4.9 (HKLM\...\MozBackup) (Version: - Pavel Cvrcek) Mozilla Firefox 12.0 (x86 de) (HKLM\...\Mozilla Firefox 12.0 (x86 de)) (Version: 12.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 12.0 - Mozilla) Mozilla Thunderbird (3.1.11) (HKLM\...\Mozilla Thunderbird (3.1.11)) (Version: 3.1.11 (de) - Mozilla) Mp3tag v2.41 (HKLM\...\Mp3tag) (Version: v2.41 - Florian Heidenreich) MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2721691) (HKLM\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB973685) (HKLM\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation) MyFreeCodec (HKU\S-1-5-21-837243161-1062950140-3748333167-1000\...\MyFreeCodec) (Version: - ) Nitro Reader 3 (HKLM\...\{5027D37B-3677-4F16-9501-A42288EBDB31}) (Version: 3.5.2.10 - Nitro) No23 Recorder (HKLM\...\{22B0E143-2B0B-435B-9F56-136A3D16065F}) (Version: 2.1.0.3 - No23) Node.js (HKLM\...\{2D41A012-35EE-4724-AE8E-E592EDD9F89D}) (Version: 0.10.13 - Joyent, Inc. and other Node contributors) Notepad++ (HKLM\...\Notepad++) (Version: - ) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.9 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.18.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.18.0 - NVIDIA Corporation) NVIDIA PhysX (HKLM\...\{B83FC356-B7C0-441F-8A4D-D71E088E7974}) (Version: 9.09.0428 - NVIDIA Corporation) OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0 - Microsoft Corporation) Hidden OpenOffice 4.1.0 (HKLM\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) Paragon Partition Manager™ 12 Free (HKLM\...\{47E5588F-C3A0-11DE-9857-005056C00008}) (Version: 90.00.0003 - Paragon Software) Password Safe (HKLM\...\Password Safe) (Version: - ) PC Connectivity Solution (HKLM\...\{4CE6B3C4-D8E2-4A5D-BEF5-5B69AF843B0C}) (Version: 9.45.0.0 - Nokia) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.8 - Google, Inc.) Pinnacle VideoSpin (HKLM\...\{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}) (Version: 2.0.0.669 - Pinnacle Systems) PlayMemories Home (HKLM\...\{93AA5B49-0994-4EF6-80F3-868C9CEA88ED}) (Version: 4.0.00.09031 - Sony Corporation) PlayReady PC Runtime x86 (HKLM\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation) PMB_ModeEditor (Version: 9.0.00 - Sony Corporation) Hidden PMB_ServiceUploader (Version: 9.0.00 - Sony Corporation) Hidden Power Tab Editor 1.7 (HKLM\...\{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}) (Version: 1.7.0 - Power Tab Software) Presto! PageManager 7.15.20 (HKLM\...\{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}) (Version: 7.15.20 - NewSoft Technology Corporation) Project64 1.6 (HKLM\...\{9559F7CA-5E34-4237-A2D9-D856464AD727}) (Version: 1.6 - Project64) PS3 Media Server (HKLM\...\PS3 Media Server) (Version: - ) QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.) RecordPad Sound Recorder (HKLM\...\Recordpad) (Version: - NCH Software) Remote Control USB Driver (HKLM\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - ) Richard Burns Rally (HKLM\...\{92C7D009-A464-4948-A980-7A3E28CB2F49}) (Version: 1.00.000 - ) Rubik's Games (HKLM\...\Rubik's Games) (Version: - ) Samsung AllShare (HKLM\...\InstallShield_{DF47ACA3-7C78-4C08-8007-AC682563C9F1}) (Version: 2.1.0.12031_10 - Samsung Electronics Co., Ltd.) Samsung AllShare (Version: 2.1.0.12031_10 - Samsung Electronics Co., Ltd.) Hidden Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.0.1.11053_99 - Samsung Electronics Co., Ltd.) Samsung Kies (Version: 2.0.1.11053_99 - Samsung Electronics Co., Ltd.) Hidden Samsung Story Album Viewer (HKLM\...\InstallShield_{698BBAD8-B116-495D-B879-0F07A533E57F}) (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.) Samsung Story Album Viewer (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.) ScanSoft OmniPage SE 4 (HKLM\...\{66B4C110-8BEB-49B5-824E-C70AEEB20ECD}) (Version: 15.2.0020 - Nuance Communications, Inc.) Secret Maryo Chronicles (HKLM\...\secretmaryo) (Version: 1.9 - Florian Richter) Secret Maryo Chronicles Music Pack (HKLM\...\secretmaryo_music) (Version: 4.1 - Florian Richter) Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) SOHLib for PlayMemories Home (Version: 1.0.3.02170 - Sony Corporation) Hidden Spelling Dictionaries Support For Adobe Reader 9 (HKLM\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated) Spotify (HKU\S-1-5-21-837243161-1062950140-3748333167-1000\...\Spotify) (Version: 0.9.14.13.gba5645ad - Spotify AB) StarMoney (Version: 2.0 - StarFinanz) Hidden StarMoney (Version: 3.0.2.50 - StarFinanz) Hidden StarMoney (Version: 4.0.2.34 - StarFinanz) Hidden StarMoney 8.0 S-Edition (HKLM\...\{87F3F20B-5CF8-40DA-B044-4E714E203006}) (Version: 8.0 - Star Finanz GmbH) StarMoney 9.0 S-Edition (HKLM\...\{95686B93-9738-4F0A-BB2A-212B6943F057}) (Version: 9.0 - Star Finanz GmbH) StationRipper 2.93B (HKU\S-1-5-21-837243161-1062950140-3748333167-1000\...\StationRipper) (Version: 2.93B - Ratajik Software) Steinberg HALionOne (HKLM\...\{E70E7159-93B1-470D-9FBD-D8E9EF34B538}) (Version: 1.1.0.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne GM Drum Set (HKLM\...\{AC997F93-0757-4ED4-A701-F40C2D654D09}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne GM Set (HKLM\...\{F057965A-D974-4C64-ADB1-4381CD4B8956}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) Steinberg Sequel 2 Trial Content (HKLM\...\{DF584D4A-2619-41BE-9515-AAB18439D393}) (Version: 2.0.0.351 - Steinberg Media Technologies GmbH) Steinberg Sequel LE 2 (HKLM\...\{7146D087-B853-4E00-BB52-883DCE99F155}) (Version: 2.0.5 - Steinberg Media Technologies GmbH) SUPER © Version 2010.bld.37 (Jan 2, 2010) (HKLM\...\SUPER ©) (Version: Version 2010.bld.37 (Jan 2, 2010) - eRightSoft) Switch Sound File Converter (HKLM\...\Switch) (Version: - NCH Software) SyncToy 2.1 (x86) (HKLM\...\{A066194B-DC8F-449A-8E0F-B57BDD3A2072}) (Version: 2.1.0 - Microsoft) Telegram Desktop version 0.7.6 (HKU\S-1-5-21-837243161-1062950140-3748333167-1000\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 0.7.6 - Telegram Messenger LLP) The Nomad Soul (HKLM\...\The Nomad Soul) (Version: - ) Tinypic 3.18 (HKLM\...\{E3723A04-A894-4036-A78E-282E18F43C0A}_is1) (Version: Tinypic 3.18 - E. Fiedler) Titanium Studio (HKLM\...\Titanium Studio) (Version: 3.1.1 - Appcelerator, Inc.) Tracktion (HKLM\...\Tracktion4) (Version: - ) Update Manager (Version: 4.60 - Corel Corporation) Hidden URL Snooper v2.27.01 (HKLM\...\URLSnooper 2_is1) (Version: - DonationCoder.com) VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0 - DivX, Inc) Hidden VideoPad Video Editor (HKLM\...\VideoPad) (Version: - NCH Software) VirtualDub Filter Pack 1.1 (HKLM\...\VirtualDub Filter Pack_is1) (Version: - Infognition Co. Ltd.) VLC media player 1.0.3 (HKLM\...\VLC media player) (Version: 1.0.3 - VideoLAN Team) VSDC Free Video Editor Version 2.1.9.211 (HKLM\...\VSDC Free Video Editor_is1) (Version: 2.1.9.211 - Flash-Integro LLC) WavePad Sound Editor (HKLM\...\WavePad) (Version: - NCH Software) WD Quick View (HKLM\...\{C58994CF-D15D-41E3-A03B-587B39EAA903}) (Version: 2.4.6.3 - Western Digital Technologies, Inc.) WD SmartWare (HKLM\...\{752EC2DC-0313-435A-BF9A-9B02927C049A}) (Version: 2.4.6.3 - Western Digital Technologies, Inc.) WD SmartWare Installer (HKLM\...\{1891b882-48f7-442d-98d0-c1ce533f25bd}) (Version: 2.4.6.3 - Western Digital Technologies, Inc.) Win7codecs (HKLM\...\{8C0CAA7A-3272-4991-A808-2C7559DE3409}) (Version: 2.1.9 - Shark007) Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live ID-Anmelde-Assistent (HKLM\...\{10A44844-4465-456E-8C97-80BDD4F68845}) (Version: 6.500.3146.0 - Microsoft Corporation) Windows Live Sync (HKLM\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation) Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) Windows Mobile-Gerätecenter (HKLM\...\{904CCF62-818D-4675-BC76-D37EB399F917}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) (HKLM\...\504244733D18C8F63FF584AEB290E3904E791693) (Version: 08/22/2008 7.0.0.0 - Nokia) WinPcap 4.1.1 (HKLM\...\WinPcapInst) (Version: 4.1.0.1753 - CACE Technologies) X10 Hardware(TM) (HKLM\...\X10Hardware) (Version: - ) XAMPP (HKLM\...\xampp) (Version: 1.8.2-2 - BitNami) XMedia Recode 2.1.4.8 (HKLM\...\XMedia Recode) (Version: 2.1.4.8 - Sebastian Dörfler) Zebra 3 (HKLM\...\{10D41532-9935-460A-8AC4-64E9614CB04E}) (Version: 1.0.0 - Klett Verlag GmbH) ZOOM Edit&Share for Windows (HKLM\...\{E99B8E1C-262D-49E6-9A84-D2AC486B2648}) (Version: 5.00.0000 - ZOOM Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\RAaM2\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{0BE35200-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{0BE35201-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{0BE35202-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> No File Path CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\RAaM2\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\RAaM2\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{3f04dadf-6ea4-44d1-a507-03cad176f443}\InprocServer32 -> C:\Users\RAaM2\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\RAaM2\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\RAaM2\AppData\Local\Google\Chrome\Application\39.0.2171.95\delegate_execute.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{6d05bf60-3eaf-4a97-87c5-10cce505435b}\localserver32 -> C:\Users\RAaM2\AppData\Local\Temp\{9c0ba3c1-2b67-45eb-bf69-bed9658d28d2}\IDriver.NonElevated.exe No (the data entry has 4 more characters). CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}\localserver32 -> C:\Users\RAaM2\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\RAaM2\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}\localserver32 -> C:\Users\RAaM2\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\RAaM2\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\RAaM2\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\RAaM2\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\RAaM2\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\RAaM2\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611}\InprocServer32 -> C:\Program Files\Macrium\Reflect\RShellExt.dll (Paramount Software UK Ltd) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\RAaM2\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\RAaM2\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\RAaM2\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\SkyDriveShell.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\RAaM2\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\FileSyncApi.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-837243161-1062950140-3748333167-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) ==================== Restore Points ========================= 26-12-2014 18:10:44 Windows Update 28-12-2014 19:00:41 Windows-Sicherung 30-12-2014 12:18:15 Windows Update 13-01-2015 17:07:25 Windows Update 13-01-2015 17:14:08 Windows-Sicherung 13-01-2015 20:06:34 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 14-01-2015 11:57:22 Wiederherstellungsvorgang 14-01-2015 13:26:05 Windows Update 14-01-2015 13:29:36 Windows-Sicherung 14-01-2015 15:26:58 Wiederherstellungsvorgang 14-01-2015 15:40:05 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 14-01-2015 16:44:49 Windows Update 14-01-2015 17:20:19 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 14-01-2015 17:53:11 Windows Update 14-01-2015 18:01:36 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 14-01-2015 18:34:05 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 14-01-2015 20:25:54 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-01-2015 22:16:10 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 15-01-2015 22:24:03 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {019D783D-DB94-4694-B95A-BDC4512EAD3B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {03DAB6B5-8876-4594-A1A3-48EEE2B72CF3} - System32\Tasks\{ADCA8631-7C7D-4BB1-BD6A-164C482A8C2B} => C:\Program Files\DVD Shrink DE\DVD Shrink 3.2 DE (DeCSS-frei).exe [2005-05-31] (DVD Shrink) Task: {0467EEA8-3E2C-4216-B86E-797865254649} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-837243161-1062950140-3748333167-1000UA => C:\Users\RAaM2\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-18] (Google Inc.) Task: {04C64550-C726-4A0B-85F1-00D87A127BAC} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft) Task: {07A1C535-F579-4666-A22E-0AAD82E45B0D} - System32\Tasks\{33F2EBAD-215B-4165-8A6A-E311315E2C8D} => C:\Program Files\Project64 1.6\Project64.exe [2005-04-01] () Task: {097CD8A5-14ED-4891-BCEC-936474E43335} - System32\Tasks\{97A1201B-8983-47AD-9B48-6F1630FB36DC} => C:\Program Files\DVD Shrink DE\DVD Shrink 3.2 DE (DeCSS-frei).exe [2005-05-31] (DVD Shrink) Task: {1556A58E-27BD-47BB-88C7-0DF0AA864353} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd) Task: {15AF40CE-95C4-4B93-A65D-F693613E0605} - System32\Tasks\{CE22A2A8-0EDF-45EC-A86A-5120707C24D9} => C:\MAGIX\Video_deLuxe_2006_PLUS\VideodeLuxe.exe [2006-06-14] (MAGIX AG) Task: {175AD2BA-364C-49A0-883A-5D26738413DA} - System32\Tasks\{F1EBC007-5A7A-46C0-83AA-F4F8C719F628} => C:\Program Files\office97\Office\Office10\OUTLOOK.EXE Task: {187E44F8-A384-4553-B51D-33EAC93F1950} - System32\Tasks\{6EC45BB9-22D7-4307-98CD-33C3AE83AE15} => C:\MAGIX\Video_deLuxe_2006_PLUS\VideodeLuxe.exe [2006-06-14] (MAGIX AG) Task: {1AA0B8E1-901D-45B4-B043-50AB3411D839} - System32\Tasks\{AE8B22B8-ABA7-4079-B91E-C7ED7847D89B} => pcalua.exe -a "C:\Users\RAaM2\Downloads\Neuer Download\vcredist_x86.exe" -d "C:\Users\RAaM2\Downloads\Neuer Download" Task: {1E151774-5459-4D5D-8B65-13D881C1FC83} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {2E046C9E-EFAD-452B-97B0-34D9486ABCE8} - System32\Tasks\{E7D5220E-AF6F-4269-BDEA-1586F80731D2} => C:\Program Files\DVD Shrink DE\DVD Shrink 3.2 DE (DeCSS-frei).exe [2005-05-31] (DVD Shrink) Task: {32E625A5-7C31-44F5-8599-87949871C1D2} - System32\Tasks\{C980546F-B754-4536-AD88-3731BDCAA6D1} => C:\Program Files\office97\Office\Office10\OUTLOOK.EXE Task: {34521D69-C0E7-49D2-8056-38CB7CD8BE6E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-14] (Adobe Systems Incorporated) Task: {35A4D229-81D6-490B-B9DD-E7BAF650673A} - System32\Tasks\{9BFF994D-B78E-4038-B3CA-D7AB95F96736} => Chrome.exe hxxp://ui.skype.com/ui/0/4.2.0.187/de/go/help.faq.installer?LastError=1603 Task: {37598CF9-FB9B-4F03-AA33-9164DC30D05E} - System32\Tasks\{A24F35DC-E365-454A-B462-6A76DB3220BC} => C:\Program Files\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.) Task: {3FD986E6-786E-4B80-9EA4-074D462E6DF1} - System32\Tasks\{99D2A16C-528E-4968-8891-2DC280C2B5BC} => C:\Program Files\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.) Task: {4385C8C7-112D-4969-9000-D52CA516F06D} - System32\Tasks\{54BF46E5-AEB3-4152-BC93-F4DDFC988C94} => C:\Program Files\Kinstone Video Power\VideoPower.exe Task: {4A58290C-3401-4598-99F9-05EFF9B3FC20} - System32\Tasks\{BA994F75-EE10-45A6-8553-3BB35005A26F} => pcalua.exe -a "C:\Users\RAaM2\Downloads\Magix Xtrme Foto Designer 6\free_xtremefotodesigner6_de.exe" -d "C:\Users\RAaM2\Downloads\Magix Xtrme Foto Designer 6" Task: {4AAB949C-B0C1-46EE-A131-62A8C3BEA1A3} - System32\Tasks\neoKiKA 02.09.2014 23-41-00 => C:\Program Files\DVBViewer\dvbviewer.exe [2013-10-09] (CM&V Hackbart) Task: {4B5154FA-3870-4F54-9B7B-D4054574062D} - System32\Tasks\{5F683722-6637-4ECF-B189-11AF0C95138A} => pcalua.exe -a "C:\Users\RAaM2\Downloads\StarMoney 7.0\smoney_m_4_0_25050180_3_.exe" -d "C:\Users\RAaM2\Downloads\StarMoney 7.0" Task: {4DA7CC83-870B-49BE-9B98-0ED3A9A3B257} - System32\Tasks\{6788DE74-C5C7-4AA8-AD3C-AD68FAC5AD27} => C:\Program Files\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.) Task: {54D26981-1528-4631-B95F-CDCD31764F4A} - System32\Tasks\neoKiKA 02.09.2014 22-41-00 => C:\Program Files\DVBViewer\dvbviewer.exe [2013-10-09] (CM&V Hackbart) Task: {57D6827E-A5AB-44D6-8B9C-03042011383E} - System32\Tasks\{041D8794-2E36-435B-8E2E-5723D6A2DBB8} => C:\Program Files\Project64 1.6\Project64.exe [2005-04-01] () Task: {5BFD0C98-B9EF-49C4-A329-9F952787F9CB} - System32\Tasks\SyncToy\SyncToy Test => C:\Program Files\SyncToy 2.1\SyncToyCmd.exe [2009-10-19] (Microsoft Corporation) Task: {6DA33AFC-42FA-41E5-8DFE-30AA03E8C299} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION Task: {75F9A913-FAE3-4C34-B9B8-F7B4AB7AA64E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-837243161-1062950140-3748333167-1000Core => C:\Users\RAaM2\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-18] (Google Inc.) Task: {7877CFB3-9498-40F4-83CF-DA5CAD0528A8} - System32\Tasks\{EFF213B3-EFC7-47B4-B601-24D8FF28F00C} => C:\Program Files\Kinstone Video Power\VideoPower.exe Task: {835B8281-6E3E-44F8-A07B-613ECB0A8E53} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-25] (Google Inc.) Task: {8ED58C42-D9CD-4C33-BA7A-354CB0B2DB08} - System32\Tasks\{75A926E6-8113-4921-976A-BA57A07FFA25} => C:\Program Files\TuneUp Utilities 2007\OneClickMaintenance.exe Task: {8EDC792A-6BB3-44AB-AE2F-616658AD9D1F} - System32\Tasks\{33207D11-6CE4-494C-A47B-D989A462B709} => C:\Program Files\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.) Task: {92509917-9DEC-4764-B7F8-C7C1D32E3BB7} - System32\Tasks\{741A89C9-5041-425D-A583-EC9B38579736} => C:\Program Files\office97\Office\Office10\OUTLOOK.EXE Task: {92D0E115-AF42-442B-A268-0B1EC0A68487} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-25] (Google Inc.) Task: {996E3306-9718-45AF-B5B8-E42D3B8106DC} - System32\Tasks\{5328E27C-3F6A-4508-9A24-7F7477C46DE7} => C:\Program Files\SyncToy 2.1\SyncToy.exe [2009-10-19] (Microsoft Corporation) Task: {9BA85ADF-9BB2-4C05-8F40-CD897CDAA8B4} - System32\Tasks\{59F6DCC7-D1CF-40F0-BD16-F97835F30AEB} => C:\Program Files\office97\Office\Office10\OUTLOOK.EXE Task: {9F3A75F0-9FFD-4B51-B36A-83C6810E4758} - System32\Tasks\{0566F81D-3AD9-4543-9C17-E5C225CBF1FF} => C:\Program Files\office97\Office\Office10\OUTLOOK.EXE Task: {A54CB527-CF9C-4059-9B3F-CC11300A4705} - System32\Tasks\Sony Corporation\Sony Home Network Library\SOHLib SOHDms => C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDms.exe [2014-01-16] (Sony Corporation) Task: {A68ADDAA-87AA-40B9-B236-0B707121213D} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {A9805966-B3BC-4B6F-A9BC-E99D79201376} - System32\Tasks\{EC238D77-640F-4045-8362-6FD551440A5B} => O:\Downloads\Software\Nokia\NokiaSoftwareUpdaterSetup_de.exe Task: {AC2C2030-1C22-4FFE-8E31-2F1CDD3890D7} - System32\Tasks\{57A35445-BA05-4EEF-A389-4C1CC734F489} => C:\Program Files\Alwil Software\Avast4\ashAvast.exe Task: {AF9D9552-9493-498F-B489-53EB58A6EE01} - System32\Tasks\{AACF9AE8-780F-4124-9A52-F9E47B706F84} => pcalua.exe -a C:\Users\RAaM2\Downloads\HBCI-Leser_cyberjack\bc_6_8_0.exe -d C:\Users\RAaM2\Downloads\HBCI-Leser_cyberjack Task: {B2D26877-DEF1-486E-9368-E1578292154D} - System32\Tasks\{4018C64E-26FC-479D-A92B-0A80940EEB1F} => pcalua.exe -a O:\Downloads\Software\iriver\MovieConverterSetup.exe -d O:\Downloads\Software\iriver Task: {B6E3A24A-5456-4B92-87E2-5DE2EA1C529D} - System32\Tasks\{AC2E26C2-BFCB-4AAD-A36A-3F0137954D59} => C:\Program Files\DVD Shrink DE\DVD Shrink 3.2 DE (DeCSS-frei).exe [2005-05-31] (DVD Shrink) Task: {C2DE5B4B-F3C1-4E66-B228-488A6F398519} - System32\Tasks\{691515F1-649F-4A3F-A132-5988A568222A} => C:\Program Files\office97\Office\Office10\OUTLOOK.EXE Task: {C3EC964F-C3CC-4E5D-B5CB-3A2326A41A5C} - System32\Tasks\1-Klick-Wartung => C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe Task: {C7ECD6AF-0789-4956-BC0C-84711A3A6241} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {C822C4B9-2629-4EC7-8D75-3463090333AD} - System32\Tasks\{4F76398C-9EB8-48A7-B9D3-2AC976C72615} => C:\Program Files\iriver\iriver plus 3\iLauncher.exe [2009-03-25] (Reigncom Limited) Task: {C958D7E3-4B1D-4FA8-B34C-C4872FE0F67D} - System32\Tasks\{B5B8C8AE-DED2-4EA4-96E5-64DD37D8FC1E} => C:\Program Files\office97\Office\Office10\OUTLOOK.EXE Task: {D17BE0A0-47C0-4074-A3F9-ED4149F80852} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION Task: {D85665FD-A042-4791-AD37-D40F2A292258} - System32\Tasks\{41AAA134-0CD8-489C-8FAD-75C2DF6A8A87} => C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe [2009-02-05] (Pinnacle Systems) Task: {DAA37B1B-3FC2-4E26-8FE3-915D5E187923} - System32\Tasks\{D07541E5-CD90-43E9-A676-3456030083D3} => C:\Users\RAaM2\Downloads\Neuer Download\vcredist_x86.exe Task: {DFD19D02-FD8C-41D5-B56A-71A55BE5EFF2} - System32\Tasks\{C9F9A88E-9DF0-4D4D-AAAE-884EADEC290D} => C:\Program Files\iriver\Movie Converter\iLauncher.exe [2007-10-11] (Reigncom Limited) Task: {DFDFFB4D-6929-4BF5-B02A-F72267FA6572} - System32\Tasks\{42A95E58-CA2F-4FE3-9F1F-F696943BEAC4} => C:\Program Files\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.) Task: {E16F5EE7-2D2D-4EFB-82FF-A54D5D3DF571} - System32\Tasks\{08E84115-1BCA-40AF-AE31-E2B23B5A72A2} => C:\Program Files\office97\Office\Office10\OUTLOOK.EXE Task: {E97EAEAD-BA11-464D-90FF-F7B014016CEC} - System32\Tasks\{E1E276D7-7DB0-447F-B15A-0A54F5A79D20} => C:\Program Files\Project64 1.6\Project64.exe [2005-04-01] () Task: {EA203C2F-33C7-4CF4-A0EC-57394D5BC250} - System32\Tasks\{9361C8AD-E054-44DF-AAE7-897CA7F07BB1} => pcalua.exe -a "E:\USB Driver for Windows OS\setup.exe" -d "E:\USB Driver for Windows OS" Task: {ED0BA1AE-8B58-478D-BE60-6A5E95451760} - System32\Tasks\{941B1359-8C05-43A3-9733-9E216AC5D07A} => pcalua.exe -a O:\Downloads\Software\iriver\iplus3.exe -d O:\Downloads\Software\iriver Task: {EE3E4D51-DA29-45CC-AD8F-A348B89E2624} - System32\Tasks\{3AE65294-911B-4F40-8D43-6AEBC4EE35C5} => C:\Program Files\DVD Shrink DE\DVD Shrink 3.2 DE (DeCSS-frei).exe [2005-05-31] (DVD Shrink) Task: {F44060CD-0D2A-4968-BEFE-8AFCD8F41569} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {F75B9CF0-8A4B-4483-9CE9-0F0AAF6B37FA} - System32\Tasks\{9A23B699-1021-47D6-987B-003EDE61EEB6} => C:\Program Files\Alwil Software\Avast4\ashAvast.exe Task: {F76E6AE9-0F61-4AB8-8BCD-C686F1D49974} - System32\Tasks\{731991E4-B052-47DB-973F-1F68907C9C66} => pcalua.exe -a C:\Windows\system32\dgfw.cpl -c Digidesign Mbox 2 Pro Task: {FCDEC0C2-CAB2-467B-BD16-2DFC79CF0FB9} - System32\Tasks\{7B768B8E-0F06-46DC-936A-8E5FFD10042D} => C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\Photoshop Album Starter Edition.exe [2007-03-16] (Adobe Systems Incorporated) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\1-Klick-Wartung.job => C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-837243161-1062950140-3748333167-1000Core.job => C:\Users\RAaM2\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-837243161-1062950140-3748333167-1000UA.job => C:\Users\RAaM2\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\neoKiKA 02.09.2014 22-41-00.job => C:\Program Files\DVBViewer\dvbviewer.exe Task: C:\Windows\Tasks\neoKiKA 02.09.2014 23-41-00.job => C:\Program Files\DVBViewer\dvbviewer.exe ==================== Loaded Modules (whitelisted) ============= 1996-12-14 00:00 - 1996-12-14 00:00 - 00022016 _____ () C:\Windows\system32\docobj.dll 2009-12-05 00:24 - 2005-03-28 10:13 - 00077824 _____ () C:\Windows\System32\csdlocalmon.dll 2009-12-01 20:12 - 2007-05-31 07:38 - 00167936 ____N () C:\Windows\system32\SerialXP.dll 2007-06-05 12:20 - 2007-06-05 12:20 - 00177704 _____ () C:\Windows\system32\PSIService.exe 2009-11-12 13:50 - 2009-11-12 13:50 - 00220128 _____ () C:\Program Files\Macrium\Reflect\ReflectService.exe 2009-10-23 10:17 - 2009-07-27 14:49 - 00244904 ____N () C:\Program Files\CyberLink\Shared files\RichVideo.exe 2013-02-06 14:52 - 2011-01-13 11:44 - 00232800 _____ () C:\Program Files\StarMoney 8.0 S-Edition\ouservice\PATCHW32.dll 2014-08-06 22:39 - 2011-01-13 11:44 - 00232800 _____ () C:\Program Files\StarMoney 9.0 S-Edition\ouservice\PATCHW32.dll 2009-11-29 21:26 - 2006-09-20 08:35 - 00020480 _____ () C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe 2010-09-05 17:12 - 2007-06-18 04:40 - 00200704 ____R () C:\Windows\System32\UMonit.exe 2010-09-05 17:12 - 2007-05-09 07:34 - 00176128 ____R () C:\Windows\System32\ustor.dll 2009-11-29 21:26 - 2006-10-30 16:59 - 00024576 _____ () C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe 2012-06-08 16:11 - 2012-06-08 16:11 - 01989632 _____ () C:\Program Files\ZOOM\Edit_Share\bin\ZOOM Edit&Share startup.exe 2014-09-25 13:07 - 2014-09-25 13:07 - 00081056 _____ () C:\Users\RAaM2\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\LoggingPlatform.DLL 2014-09-25 13:07 - 2014-09-25 13:07 - 00081056 _____ () C:\Users\RAaM2\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\LoggingPlatform.dll 2015-01-01 15:24 - 2015-01-01 15:24 - 00186368 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Commonc65c5a95#\36165d484fa2857575583d9a4cc61840\Kies.Common.DeviceServiceLib.Interface.ni.dll 2015-01-01 15:25 - 2015-01-01 15:25 - 14993920 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\afc3f45376148ce6a1ee84da499d7edb\Kies.Theme.ni.dll 2015-01-01 15:24 - 2015-01-01 15:24 - 01865728 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\ff954a7b95f33b6498d154499e393055\Kies.UI.ni.dll 2015-01-01 15:24 - 2015-01-01 15:24 - 00081920 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\5157234c4b83b2a920dcc02362260903\Kies.MVVM.ni.dll 2014-10-15 17:54 - 2014-10-15 17:54 - 00236032 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\6815ff93472d008087880a6462931188\ASF_cSharpAPI.ni.dll 2014-10-22 01:22 - 2014-10-22 01:22 - 00750080 _____ () C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2015-01-15 22:50 - 2015-01-15 22:50 - 00043008 _____ () c:\users\raam2\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpawoxya.dll 2014-10-22 01:22 - 2014-10-22 01:22 - 00047616 _____ () C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\libEGL.dll 2014-10-22 01:22 - 2014-10-22 01:22 - 00863744 _____ () C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll 2014-10-22 01:22 - 2014-10-22 01:22 - 00200704 _____ () C:\Users\RAaM2\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll 2015-01-15 22:50 - 2015-01-15 22:50 - 00098816 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32api.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00110080 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\pywintypes27.dll 2015-01-15 22:50 - 2015-01-15 22:50 - 00364544 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\pythoncom27.dll 2015-01-15 22:50 - 2015-01-15 22:50 - 00045568 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\_socket.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 01160704 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\_ssl.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00320512 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32com.shell.shell.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00713216 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\_hashlib.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 01175040 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\wx._core_.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00805888 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\wx._gdi_.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00811008 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\wx._windows_.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 01062400 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\wx._controls_.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00735232 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\wx._misc_.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00128512 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\_elementtree.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00127488 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\pyexpat.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00557056 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\pysqlite2._sqlite.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00087552 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\_ctypes.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00119808 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32file.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00108544 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32security.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00007168 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\hashobjs_ext.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00167936 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32gui.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00018432 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32event.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00038912 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32inet.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00011264 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32crypt.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00070656 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\wx._html2.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00027136 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\_multiprocessing.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00035840 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32process.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00686080 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\unicodedata.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00122368 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\wx._wizard.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00024064 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32pipe.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00025600 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32pdh.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00525640 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\windows._lib_cacheinvalidation.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00010240 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\select.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00017408 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32profile.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00022528 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\win32ts.pyd 2015-01-15 22:50 - 2015-01-15 22:50 - 00078336 _____ () C:\Users\RAaM2\AppData\Local\Temp\_MEI14882\wx._animate.pyd 2014-12-12 23:18 - 2014-12-06 02:50 - 01077064 _____ () C:\Users\RAaM2\AppData\Local\Google\Chrome\Application\39.0.2171.95\libglesv2.dll 2014-12-12 23:18 - 2014-12-06 02:50 - 00211272 _____ () C:\Users\RAaM2\AppData\Local\Google\Chrome\Application\39.0.2171.95\libegl.dll 2014-12-12 23:18 - 2014-12-06 02:50 - 09009480 _____ () C:\Users\RAaM2\AppData\Local\Google\Chrome\Application\39.0.2171.95\pdf.dll 2014-12-12 23:18 - 2014-12-06 02:50 - 01677128 _____ () C:\Users\RAaM2\AppData\Local\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll 2013-10-09 19:17 - 2013-04-12 18:23 - 00612664 _____ () C:\Program Files\DVBViewer\sqlite3.dll 2013-10-08 14:40 - 2013-04-05 20:26 - 02106368 _____ () C:\Program Files\AC3Filter\ac3filter.ax 2013-10-08 14:40 - 2013-04-05 20:27 - 01021440 _____ () C:\Program Files\AC3Filter\ac3filter_intl.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^RAaM2^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Produktregistrierung.lnk => C:\Windows\pss\Logitech . Produktregistrierung.lnk.Startup MSCONFIG\startupreg: Adobe Photo Downloader => "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" MSCONFIG\startupreg: AllShareAgent => C:\Program Files\Samsung\AllShare\AllShareAgent.exe MSCONFIG\startupreg: AmazonMP3DownloaderHelper => C:\Users\RAaM2\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe MSCONFIG\startupreg: CanonSolutionMenu => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon MSCONFIG\startupreg: CLMLServer => "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: Eraser => "C:\PROGRA~1\Eraser\Eraser.exe" --atRestart MSCONFIG\startupreg: KiesPDLR => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe MSCONFIG\startupreg: KiesPreload => C:\Program Files\Samsung\Kies\Kies.exe /preload MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: OpwareSE4 => "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" MSCONFIG\startupreg: PC Suite Tray => "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe ========================= Accounts: ========================== Administrator (S-1-5-21-837243161-1062950140-3748333167-500 - Administrator - Disabled) ASPNET (S-1-5-21-837243161-1062950140-3748333167-1002 - Limited - Enabled) Christa (S-1-5-21-837243161-1062950140-3748333167-1007 - Administrator - Enabled) => C:\Users\Christa Gast (S-1-5-21-837243161-1062950140-3748333167-501 - Limited - Enabled) => C:\Users\Gast HomeGroupUser$ (S-1-5-21-837243161-1062950140-3748333167-1005 - Limited - Enabled) RAaM2 (S-1-5-21-837243161-1062950140-3748333167-1000 - Administrator - Enabled) => C:\Users\RAaM2 Sarah (S-1-5-21-837243161-1062950140-3748333167-1006 - Administrator - Enabled) => C:\Users\Sarah ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Error: (01/15/2015 11:21:27 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Quad CPU Q8300 @ 2.50GHz Percentage of memory in use: 67% Total physical RAM: 3071.3 MB Available physical RAM: 987.04 MB Total Pagefile: 7165.59 MB Available Pagefile: 4558.15 MB Total Virtual: 2047.88 MB Available Virtual: 1918.75 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:910.41 GB) (Free:755.32 GB) NTFS Drive d: (Recover) (Fixed) (Total:20 GB) (Free:10.34 GB) NTFS Drive e: (MyBook) (Fixed) (Total:2794.49 GB) (Free:2218.81 GB) NTFS Drive p: (Expansion) (Fixed) (Total:465.76 GB) (Free:439.39 GB) NTFS Drive q: (maxi n.u) (Fixed) (Total:465.76 GB) (Free:0 GB) NTFS Drive z: (Public) (Network) (Total:2779.26 GB) (Free:2024.87 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 9E009E00) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=910.4 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=20 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=1 GB) - (Type=12) ======================================================== Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: BA7E796E) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) Attempted reading MBR returned 0 bytes. Could not read MBR for disk 2. ======================================================== Disk: 6 (Size: 465.8 GB) (Disk ID: E5A677E1) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Frage: Kann ich auf dem Laptop meiner Frau genau den gleichen Ablauf fahren, um den von möglicher Malware zu befreien? Oder muss je nach Inhalt der Logfiles eine abweichende Entscheidung getroffen werden? |
16.01.2015, 02:12 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | db22.exe wurde von Stinger gefunden aber nicht gelöscht Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.
__________________Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Task: {D17BE0A0-47C0-4074-A3F9-ED4149F80852} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION Task: {6DA33AFC-42FA-41E5-8DFE-30AA03E8C299} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION C:\ProgramData\W4Gisl.dat C:\Users\Gast\AppData\Local\Temp\{7815BC09-5CB0-49E5-B205-E2E29FD09BC9}-21.0.1180.60_chrome_installer.exe C:\Users\RAaM2\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpawoxya.dll C:\Users\RAaM2\AppData\Local\Temp\Quarantine.exe C:\Users\RAaM2\AppData\Local\Temp\repair4.exe C:\Users\RAaM2\AppData\Local\Temp\sqlite3.dll EmptyTemp: Hosts: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ |
16.01.2015, 11:17 | #19 |
| db22.exe wurde von Stinger gefunden aber nicht gelöscht Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 15-01-2015 01 Ran by RAaM2 at 2015-01-16 11:04:13 Run:1 Running from C:\Users\RAaM2\Desktop Loaded Profiles: RAaM2 (Available profiles: RAaM2 & Sarah & Christa & Gast) Boot Mode: Normal ============================================== Content of fixlist: ***************** SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Task: {D17BE0A0-47C0-4074-A3F9-ED4149F80852} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION Task: {6DA33AFC-42FA-41E5-8DFE-30AA03E8C299} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION C:\ProgramData\W4Gisl.dat C:\Users\Gast\AppData\Local\Temp\{7815BC09-5CB0-49E5-B205-E2E29FD09BC9}-21.0.1180.60_chrome_installer.exe C:\Users\RAaM2\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpawoxya.dll C:\Users\RAaM2\AppData\Local\Temp\Quarantine.exe C:\Users\RAaM2\AppData\Local\Temp\repair4.exe C:\Users\RAaM2\AppData\Local\Temp\sqlite3.dll EmptyTemp: Hosts: ***************** HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}" => Key deleted successfully. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D17BE0A0-47C0-4074-A3F9-ED4149F80852}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D17BE0A0-47C0-4074-A3F9-ED4149F80852}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{6DA33AFC-42FA-41E5-8DFE-30AA03E8C299}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DA33AFC-42FA-41E5-8DFE-30AA03E8C299}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate 2" => Key deleted successfully. C:\ProgramData\W4Gisl.dat => Moved successfully. C:\Users\Gast\AppData\Local\Temp\{7815BC09-5CB0-49E5-B205-E2E29FD09BC9}-21.0.1180.60_chrome_installer.exe => Moved successfully. "C:\Users\RAaM2\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpawoxya.dll" => File/Directory not found. C:\Users\RAaM2\AppData\Local\Temp\Quarantine.exe => Moved successfully. C:\Users\RAaM2\AppData\Local\Temp\repair4.exe => Moved successfully. C:\Users\RAaM2\AppData\Local\Temp\sqlite3.dll => Moved successfully. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. EmptyTemp: => Removed 629.3 MB temporary data. The system needed a reboot. ==== End of Fixlog 11:05:17 ==== Guten Morgen Consinus :-)) |
16.01.2015, 11:33 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | db22.exe wurde von Stinger gefunden aber nicht gelöscht Okay, dann Kontrollscans mit MBAM und ESET bitte: Downloade Dir bitte Malwarebytes Anti-Malware
ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
16.01.2015, 12:38 | #21 |
| db22.exe wurde von Stinger gefunden aber nicht gelöscht Malwarebytes Anti-Malware Malwarebytes | Free Anti-Malware & Internet Security Software Suchlauf Datum: 16.01.2015 Suchlauf-Zeit: 11:58:14 Logdatei: mbam.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2015.01.16.04 Rootkit Datenbank: v2015.01.14.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: RAaM2 Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 471770 Verstrichene Zeit: 23 Min, 52 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 7 PUP.Optional.CompatibilityVerifier.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Verifies and fixes application compatibility issues, In Quarantäne, [24f06f89e9a0ea4cd9161d5235ce0ef2], PUP.Optional.Babylon.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, In Quarantäne, [24f083758efb4de99b1ec90220e416ea], PUP.Optional.BProtector.A, HKU\S-1-5-21-837243161-1062950140-3748333167-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, In Quarantäne, [4fc5f40491f8dd590fed07c632d28d73], PUP.Optional.DataMngr.A, HKU\S-1-5-21-837243161-1062950140-3748333167-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, In Quarantäne, [e232e117a7e2ff37991d448612f207f9], PUP.Optional.DataMngr.A, HKU\S-1-5-21-837243161-1062950140-3748333167-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, In Quarantäne, [2de7a94f563363d36a4b23a7020204fc], PUP.Optional.BProtector.A, HKU\S-1-5-21-837243161-1062950140-3748333167-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, In Quarantäne, [3cd805f35336b18530cc9d30ad57b848], PUP.Optional.BProtector.A, HKU\S-1-5-21-837243161-1062950140-3748333167-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, In Quarantäne, [ff15f800b7d285b148b4814cca3a28d8], Registrierungswerte: 3 PUP.BProtector, HKU\S-1-5-21-837243161-1062950140-3748333167-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, In Quarantäne, [8c882ace7e0b94a25a5dfdcd74906898], PUP.BProtector, HKU\S-1-5-21-837243161-1062950140-3748333167-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, In Quarantäne, [2be925d343465adc7e39d2f8ca3a23dd], PUP.BProtector, HKU\S-1-5-21-837243161-1062950140-3748333167-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, In Quarantäne, [8e8656a2f495fb3bebcc5f6b4bb99769], Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 3 PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\locales, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.AdPeak.A, C:\Temp, In Quarantäne, [e82c6c8ce3a61026de14b1e501021de3], Dateien: 28 PUP.Optional.AdPeak.A, C:\Temp\t.msi, In Quarantäne, [c94bfdfb57327fb79e35283dfd0808f8], PUP.Optional.Softonic.A, C:\Users\RAaM2\Downloads\SoftonicDownloader_fuer_asio4all.exe, In Quarantäne, [031175834c3dc76f98dc0d351de405fb], PUP.Optional.Softonic.A, C:\Users\RAaM2\Downloads\SoftonicDownloader_fuer_free-video-editor (1).exe, In Quarantäne, [ed278f69f09961d58be9c67cee13c13f], PUP.Optional.Softonic.A, C:\Users\RAaM2\Downloads\SoftonicDownloader_fuer_free-video-editor.exe, In Quarantäne, [a4704bad5d2cdf579ed67cc602ff40c0], PUP.Optional.Softonic.A, C:\Users\RAaM2\Downloads\SoftonicDownloader_fuer_paragon-partition-manager-12.exe, In Quarantäne, [71a3b54396f323139cd84ff3946d58a8], PUP.Optional.Softonic, C:\Users\RAaM2\Downloads\SoftonicDownloader_fuer_power-tab-editor.exe, In Quarantäne, [ce460cecdcad78be58bea483e0218d73], PUP.Optional.OpenCandy, C:\Users\RAaM2\Downloads\FreeFileSync_5.11_setup.exe, In Quarantäne, [9084a7511e6b89ad353f1da039cca35d], PUP.Optional.OpenCandy, C:\Users\RAaM2\Downloads\FreeFileSync_5.6_setup.exe, In Quarantäne, [bf5535c3e9a0a69080f4d5e8dc2948b8], PUP.Funmoods, C:\Users\RAaM2\Downloads\agsetup183se.exe, In Quarantäne, [47cd7c7c206938fec2325db3e818629e], PUP.Optional.LiveSoftAction.A, C:\Users\RAaM2\Downloads\MEDION LIFE X15002 MD 30238 user guide provided through pdfretriever.com.exe, In Quarantäne, [30e4995fd5b40a2c11bc370648b927d9], PUP.Optional.LiveSoftAction, C:\Users\RAaM2\Downloads\CANON PIXMA MX850 user guide provided through pdfretriever.com.exe, In Quarantäne, [8490fbfdb8d1b38351064c7a60a5bd43], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\cef.pak, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\cef_100_percent.pak, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\cef_200_percent.pak, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\debug.log, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\icudtl.dat, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\libEGL.dll, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\libGLESv2.dll, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.CompatibilityVerifier.A, C:\Users\Default\AppData\Roaming\Compatibility Verifier\vcredist_x86.exe, In Quarantäne, [f51f47b1e1a8b97dffeecba4be4516ea], PUP.Optional.AdPeak.A, C:\Temp\lsp2.log, In Quarantäne, [e82c6c8ce3a61026de14b1e501021de3], PUP.Optional.AdPeak.A, C:\Temp\InstallFilter32.msi, In Quarantäne, [e82c6c8ce3a61026de14b1e501021de3], PUP.Optional.AdPeak.A, C:\Temp\output.txt, In Quarantäne, [e82c6c8ce3a61026de14b1e501021de3], PUP.Optional.AdPeak.A, C:\Temp\t.txt, In Quarantäne, [e82c6c8ce3a61026de14b1e501021de3], Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) |
16.01.2015, 13:10 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | db22.exe wurde von Stinger gefunden aber nicht gelöschtLesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ Logfiles bitte immer in CODE-Tags posten |
16.01.2015, 13:50 | #23 |
| db22.exe wurde von Stinger gefunden aber nicht gelöscht Hatte ich wohl so gemacht. ESET Online Scanner läuft. Wird aber lange dauern. Wie gesagt, der ESET Scan läuft sehr lange. Habe dafür die Windows Firewall ausgeschaltet und die Microsoft Security Essentials deaktiviert. Habe bedenken, dass ich mir in dieser Zeit wieder was einfange. Das wird noch einige Stunden laufen. Muss ich das Risiko so lange eingehen? |
17.01.2015, 16:27 | #24 |
/// Winkelfunktion /// TB-Süch-Tiger™ | db22.exe wurde von Stinger gefunden aber nicht gelöscht Hast die die letzten beiden Male nicht gemacht. Also keine CODE-Tags. Ohne die wird es sehr unübersichtlich. Windows-Firewall kannste anlassen. MSE sollte aber deaktiviert sein.
__________________ Logfiles bitte immer in CODE-Tags posten |
17.01.2015, 19:43 | #25 |
| db22.exe wurde von Stinger gefunden aber nicht gelöschtCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=c763fd6978fbdf44999371e464532565 # engine=21998 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-01-16 11:54:21 # local_time=2015-01-16 12:54:21 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Microsoft Security Essentials' # compatibility_mode=5895 16777213 100 100 11042745 62718977 0 0 # scanned=4533 # found=17 # cleaned=0 # scan_time=154 sh=321FFA63BC10C82EBF9D52BBC8DFAD1635A7D88D ft=1 fh=6345b32e772ed437 vn="Win32/AdWare.Adpeak.F Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\002\yewimmxqbs32.exe.vir" sh=CF6185A9EDFBA0217C9D36D25CA9F6ADCC9F6BC8 ft=1 fh=f90d49fcbe154eac vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir" sh=2B51D22D9C35776114CDBE261D8A916BB59C570B ft=1 fh=47ec4f3960fc4f8f vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\NCH Software\VideoPad\uninst.exe.vir" sh=6516305E7DD80E81AE0603FBCE24C10A8C4F7635 ft=1 fh=bdd20bf360fc4f8f vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\NCH Software\VideoPad\videopad.exe.vir" sh=E27B3D7DC6E1D8EE5C398238C6E2059A385B0656 ft=1 fh=0a752b4a288ad097 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\NCH Software\VideoPad\video_pad_setup_v2.41.exe.vir" sh=91FD0C68DC46843917C8FEA976D8DDF7B941D897 ft=1 fh=fe05ab993baef410 vn="Win32/Toolbar.Babylon.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\BabMaint.exe.vir" sh=3CB374AC1A0ED39C2A98701908F2722472A3F853 ft=1 fh=06738372f8f49ab8 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\BabSolution\Shared\BabMaint.exe.vir" sh=7664F6A327E5201011200E703489577A0971AB77 ft=1 fh=c71c0011451c6a93 vn="Variante von Win32/Toolbar.Babylon.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\BabSolution\Shared\BUSolution.dll.vir" sh=977B60DEF45F24048D040ECDCAA65BB332C6B449 ft=1 fh=164dad5fc31d40af vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe.vir" sh=2C8981A59216CCB644BE5FBC92DBB7F8F0188F99 ft=1 fh=6aad921543298e71 vn="Variante von Win32/AdSuproot.A Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe.vir" sh=D95DA6EB1B41CE144BC78AA7EF8FDBA782692156 ft=1 fh=038f0e9c2aa6fcd9 vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll.vir" sh=6FAC18F40A0B9D8591E636CB3B40208DE00A527D ft=1 fh=f4fb7f62c46286d7 vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll.vir" sh=2E6E4C2FDF55F1E6CB989861ABC276BF28DE1F0C ft=1 fh=ab455342bbbbf6b6 vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\libEGL.dll.vir" sh=A759EFBF880BDF0268F7ACA91E5C7CFA184EC6BA ft=1 fh=8b9d0fa7f7d4506b vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\libGLESv2.dll.vir" sh=560236056E7C0D6603562B7296CBA8EDA6B081D5 ft=1 fh=27394455615c306e vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll.vir" sh=531FF0A9D22D63AC4B01A2603B1C9DEC717D9B99 ft=1 fh=2d1fb7038f001cc8 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Windows Net Data\uninstaller.exe.vir" sh=1D30BA70A9357EB25F9BD0277EAD24972C93F5EA ft=1 fh=06aa925a752c149d vn="Variante von Win32/Foxferi.A Trojaner" ac=I fn="C:\EULE SHARE A\vlc-0.9.9-win32.exe" ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=c763fd6978fbdf44999371e464532565 # engine=21998 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-01-17 01:25:14 # local_time=2015-01-17 02:25:14 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Microsoft Security Essentials' # compatibility_mode=5895 16777213 100 100 11134598 62810830 0 0 # scanned=632987 # found=116 # cleaned=0 # scan_time=4785 sh=321FFA63BC10C82EBF9D52BBC8DFAD1635A7D88D ft=1 fh=6345b32e772ed437 vn="Win32/AdWare.Adpeak.F Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\002\yewimmxqbs32.exe.vir" sh=CF6185A9EDFBA0217C9D36D25CA9F6ADCC9F6BC8 ft=1 fh=f90d49fcbe154eac vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir" sh=2B51D22D9C35776114CDBE261D8A916BB59C570B ft=1 fh=47ec4f3960fc4f8f vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\NCH Software\VideoPad\uninst.exe.vir" sh=6516305E7DD80E81AE0603FBCE24C10A8C4F7635 ft=1 fh=bdd20bf360fc4f8f vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\NCH Software\VideoPad\videopad.exe.vir" sh=E27B3D7DC6E1D8EE5C398238C6E2059A385B0656 ft=1 fh=0a752b4a288ad097 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\NCH Software\VideoPad\video_pad_setup_v2.41.exe.vir" sh=91FD0C68DC46843917C8FEA976D8DDF7B941D897 ft=1 fh=fe05ab993baef410 vn="Win32/Toolbar.Babylon.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\BabMaint.exe.vir" sh=3CB374AC1A0ED39C2A98701908F2722472A3F853 ft=1 fh=06738372f8f49ab8 vn="Variante von Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\BabSolution\Shared\BabMaint.exe.vir" sh=7664F6A327E5201011200E703489577A0971AB77 ft=1 fh=c71c0011451c6a93 vn="Variante von Win32/Toolbar.Babylon.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\BabSolution\Shared\BUSolution.dll.vir" sh=977B60DEF45F24048D040ECDCAA65BB332C6B449 ft=1 fh=164dad5fc31d40af vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe.vir" sh=2C8981A59216CCB644BE5FBC92DBB7F8F0188F99 ft=1 fh=6aad921543298e71 vn="Variante von Win32/AdSuproot.A Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe.vir" sh=D95DA6EB1B41CE144BC78AA7EF8FDBA782692156 ft=1 fh=038f0e9c2aa6fcd9 vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll.vir" sh=6FAC18F40A0B9D8591E636CB3B40208DE00A527D ft=1 fh=f4fb7f62c46286d7 vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll.vir" sh=2E6E4C2FDF55F1E6CB989861ABC276BF28DE1F0C ft=1 fh=ab455342bbbbf6b6 vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\libEGL.dll.vir" sh=A759EFBF880BDF0268F7ACA91E5C7CFA184EC6BA ft=1 fh=8b9d0fa7f7d4506b vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\libGLESv2.dll.vir" sh=560236056E7C0D6603562B7296CBA8EDA6B081D5 ft=1 fh=27394455615c306e vn="Variante von Win32/AdSuproot Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll.vir" sh=531FF0A9D22D63AC4B01A2603B1C9DEC717D9B99 ft=1 fh=2d1fb7038f001cc8 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RAaM2\AppData\Roaming\Windows Net Data\uninstaller.exe.vir" sh=1D30BA70A9357EB25F9BD0277EAD24972C93F5EA ft=1 fh=06aa925a752c149d vn="Variante von Win32/Foxferi.A Trojaner" ac=I fn="C:\EULE SHARE A\vlc-0.9.9-win32.exe" sh=2B63A81AA85F4EF22C32580E794BF4E4E53C4D5E ft=1 fh=ce6678054b617312 vn="Win32/Packed.Autoit.C.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\Win7codecs\Tools\Settings32.exe" sh=DEE59B90BEF30820D5C5203603DB37B96EC89FD6 ft=0 fh=0000000000000000 vn="Win32/Packed.Autoit.C.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\ProgramData\Win7codecs\{6B010B4A-EBD4-491C-A6A9-BC1063E2A432}\Win7codecs.msi" sh=2B63A81AA85F4EF22C32580E794BF4E4E53C4D5E ft=1 fh=ce6678054b617312 vn="Win32/Packed.Autoit.C.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Programme\Win7codecs\Tools\Settings32.exe" sh=DEE59B90BEF30820D5C5203603DB37B96EC89FD6 ft=0 fh=0000000000000000 vn="Win32/Packed.Autoit.C.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\All Users\Win7codecs\{6B010B4A-EBD4-491C-A6A9-BC1063E2A432}\Win7codecs.msi" sh=19876B0C21073CE7AC4725124851FC36B7EA7301 ft=1 fh=31b372839de59c7b vn="Variante von Win32/CNETInstaller.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\cbsidlm-cbsi188-BestPractice-ORG-10794555.exe" sh=828C42D06CD16A36ECFEED14229067EE58FFB924 ft=1 fh=7c172d145bbff8b9 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\DVBViewer_setup_demo_uni.exe" sh=F686AF85780FCC5D0D5183D27BE5D58F7D710652 ft=0 fh=0000000000000000 vn="Win32/DownWare.W evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\FFSetup-270.zip" sh=E83BBBDAD06E7769E5EDD7C28B56CC3E1983D944 ft=1 fh=514b0e163f8f3e70 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\FFSetup3.1.1.0.exe" sh=FDE3D7E13260CD75D7523F0B02BC06C16419C026 ft=1 fh=3918cb108fedf547 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\FFSetup3.3.1.0.exe" sh=F7C72C5EC5334C58465B8A4257978531B19C4098 ft=1 fh=0ab1d01b6bb0271d vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\FreeYouTubeDownload_3.2.1.320.exe" sh=F59DF4C2504512C6869FE12D9C2EC95C1A56EA16 ft=1 fh=06b9b33add6bc5ca vn="Win32/Toolbar.SearchSuite.Y evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\iMeshV12.exe" sh=148C61BCE25F187347100AFB9FD6123C3E3B92B3 ft=1 fh=eaa9c73ebe349a59 vn="Win32/DownWare.W evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\VDFilterPack.exe" sh=E0D69AA8A393FD98AC9899EF3A143C90DF1503F1 ft=1 fh=47978917b33c8b08 vn="NSIS/StartPage.CC Trojaner" ac=I fn="C:\Users\RAaM2\Downloads\vlc-2.1.2-win32.exe" sh=FEFD340D0F20B6E66CAF762AE77336C562377BD3 ft=1 fh=854f4a4a933b781f vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\VSDC Free Video Editor - CHIP-Installer.exe" sh=B112DA09697AB4852B99DFF33DC51CE135FAA03C ft=1 fh=5b10c6967d3c268c vn="Win32/DownWare.W evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\MediaSoftware\DVDStyler-2.2-win32.exe" sh=A3C802263642F915147595097E88E1B0447CA421 ft=1 fh=f8b6a28d464f1e55 vn="Win32/SoftonicDownloader.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\MediaSoftware\SoftonicDownloader_fuer_videopad-video-editor.exe" sh=E27B3D7DC6E1D8EE5C398238C6E2059A385B0656 ft=1 fh=0a752b4a288ad097 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\MediaSoftware\video_pad_setup.exe" sh=CA1E1F6DFDD79529165583E676B397924F688939 ft=1 fh=d20ecb07122ce0d5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\AdwCleaner - CHIP-Installer.exe" sh=DCDFA1E9A0B3EFBB5F4C1DF25889C00D30CD30D8 ft=1 fh=78eeb4e84da1a50d vn="Variante von Win32/DownloadGuide.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\ag_setup183se.exe" sh=D86D2FC37B1FED635CAF6F25254D7A575466ED1E ft=1 fh=7614c1446a9b863f vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\FFSetup3.3.4.0.exe" sh=E79CE0DA43C79F2A4E48A4F4A02905DE783FBD16 ft=1 fh=a9eb553813c219ce vn="NSIS/StartPage.CC Trojaner" ac=I fn="C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\vlc-2.1.4-win64.exe" sh=DEE59B90BEF30820D5C5203603DB37B96EC89FD6 ft=0 fh=0000000000000000 vn="Win32/Packed.Autoit.C.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\ad1211.msi" sh=7DAE12039594E04E6D41DC84C7FCC015CD263800 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-03-26 010446\Backup Files 2014-03-26 010446\Backup files 1.zip" sh=84E3E45F4AFA01876F5ECB20AAF274783247C016 ft=0 fh=0000000000000000 vn="Win32/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-03-26 010446\Backup Files 2014-03-26 010446\Backup files 2.zip" sh=10215BFE67D5E6F91916934265301E5308139E18 ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-03-26 010446\Backup Files 2014-03-26 010446\Backup files 5.zip" sh=FDA8448F8C4535A3A2F3B03D9926FFE154E0F30A ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-04-27 130947\Backup Files 2014-04-27 130947\Backup files 1.zip" sh=647B0A3D745A312848728D17103494F880EA3456 ft=0 fh=0000000000000000 vn="Win32/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-04-27 130947\Backup Files 2014-04-27 130947\Backup files 3.zip" sh=83428518B6D4FB678DA3AA7DB214E67D8C16DC75 ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-04-27 130947\Backup Files 2014-04-27 190010\Backup files 5.zip" sh=D0137896A1D87C76EA1EA3EC1DBD6794BA9A0D4A ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadGuide.A evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-05-21 205848\Backup Files 2014-05-21 205848\Backup files 1.zip" sh=07FC8985C2E325AC5150F1AD153F81BCC72181E2 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-06-09 222442\Backup Files 2014-06-09 222442\Backup files 1.zip" sh=42C366AEC316C1BC0CD0CC3CCFB068503FDAC0E9 ft=0 fh=0000000000000000 vn="Win32/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-06-09 222442\Backup Files 2014-06-09 222442\Backup files 3.zip" sh=C739BAE635C584FD19053FE78D5E18F6FDB79E25 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-06-09 222442\Backup Files 2014-06-18 195430\Backup files 1.zip" sh=99A020A9D16BA511A4DB8F7EF3DD6FDD9AFBA388 ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-06-09 222442\Backup Files 2014-06-18 195430\Backup files 2.zip" sh=BB67805A10ED1E3C0F221F9A2A3D0B7D768E83D4 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-08-03 190006\Backup Files 2014-08-03 190006\Backup files 1.zip" sh=42113FE7E23024A559255A0C083EC90F2138AC22 ft=0 fh=0000000000000000 vn="Win32/AnyProtect.D evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-08-03 190006\Backup Files 2014-08-03 190006\Backup files 3.zip" sh=5CE4F39ABB854A5F1ECE479B7C5C1FAFB962DA26 ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\BackUp Lenovo\RAA-LENOVO\Backup Set 2014-08-03 190006\Backup Files 2014-08-13 181917\Backup files 3.zip" sh=AA536EF6940E1F86E75A2A3C9F32F4684775864D ft=1 fh=5710fe768813d120 vn="Variante von Win32/Toolbar.Funmoods.D evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\agsetup183se.exe" sh=7A285950FE1D0BBD0B4AF71B3DF5B743C43BCE1E ft=1 fh=2752c089397c1a82 vn="Variante von Win32/GetNow.C evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\CANON PIXMA MX850 user guide provided through pdfretriever.com.exe" sh=19876B0C21073CE7AC4725124851FC36B7EA7301 ft=1 fh=31b372839de59c7b vn="Variante von Win32/CNETInstaller.B evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\cbsidlm-cbsi188-BestPractice-ORG-10794555.exe" sh=828C42D06CD16A36ECFEED14229067EE58FFB924 ft=1 fh=7c172d145bbff8b9 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\DVBViewer_setup_demo_uni.exe" sh=F686AF85780FCC5D0D5183D27BE5D58F7D710652 ft=0 fh=0000000000000000 vn="Win32/DownWare.W evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\FFSetup-270.zip" sh=E83BBBDAD06E7769E5EDD7C28B56CC3E1983D944 ft=1 fh=514b0e163f8f3e70 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\FFSetup3.1.1.0.exe" sh=FDE3D7E13260CD75D7523F0B02BC06C16419C026 ft=1 fh=3918cb108fedf547 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\FFSetup3.3.1.0.exe" sh=F7C72C5EC5334C58465B8A4257978531B19C4098 ft=1 fh=0ab1d01b6bb0271d vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\FreeYouTubeDownload_3.2.1.320.exe" sh=F59DF4C2504512C6869FE12D9C2EC95C1A56EA16 ft=1 fh=06b9b33add6bc5ca vn="Win32/Toolbar.SearchSuite.Y evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\iMeshV12.exe" sh=D788F820CD808A6FB5BC70F001812646B9F24754 ft=1 fh=bd80a08b7692f12f vn="Variante von Win32/GetNow.B evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\MEDION LIFE X15002 MD 30238 user guide provided through pdfretriever.com.exe" sh=F3BB9FE93D7848C6205F2037754E2AD9A0F1A79D ft=1 fh=67f446f21fccd307 vn="Variante von Win32/SoftonicDownloader.F evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\SoftonicDownloader_fuer_asio4all.exe" sh=B76EF32BFCC760E2897AF387565CE754369FEDEB ft=1 fh=49ff6bcdbef51897 vn="Win32/SoftonicDownloader.D evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\SoftonicDownloader_fuer_free-video-editor.exe" sh=0F76C2F92FFF4F3C233EBE791E9E42356788D8EB ft=1 fh=f22517ab9956d4aa vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\SoftonicDownloader_fuer_paragon-partition-manager-12.exe" sh=E1604D0E902939AC36647DC2F1E59D7D8C49FE23 ft=1 fh=32c6b051e23c60af vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\SoftonicDownloader_fuer_power-tab-editor.exe" sh=148C61BCE25F187347100AFB9FD6123C3E3B92B3 ft=1 fh=eaa9c73ebe349a59 vn="Win32/DownWare.W evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\VDFilterPack.exe" sh=E0D69AA8A393FD98AC9899EF3A143C90DF1503F1 ft=1 fh=47978917b33c8b08 vn="NSIS/StartPage.CC Trojaner" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\vlc-2.1.2-win32.exe" sh=B112DA09697AB4852B99DFF33DC51CE135FAA03C ft=1 fh=5b10c6967d3c268c vn="Win32/DownWare.W evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\MediaSoftware\DVDStyler-2.2-win32.exe" sh=A3C802263642F915147595097E88E1B0447CA421 ft=1 fh=f8b6a28d464f1e55 vn="Win32/SoftonicDownloader.D evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\MediaSoftware\SoftonicDownloader_fuer_videopad-video-editor.exe" sh=E27B3D7DC6E1D8EE5C398238C6E2059A385B0656 ft=1 fh=0a752b4a288ad097 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\MediaSoftware\video_pad_setup.exe" sh=CA1E1F6DFDD79529165583E676B397924F688939 ft=1 fh=d20ecb07122ce0d5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\_BackUp Downloads Lenovo\AdwCleaner - CHIP-Installer.exe" sh=DCDFA1E9A0B3EFBB5F4C1DF25889C00D30CD30D8 ft=1 fh=78eeb4e84da1a50d vn="Variante von Win32/DownloadGuide.A evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\_BackUp Downloads Lenovo\ag_setup183se.exe" sh=D86D2FC37B1FED635CAF6F25254D7A575466ED1E ft=1 fh=7614c1446a9b863f vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\_BackUp Downloads Lenovo\FFSetup3.3.4.0.exe" sh=E79CE0DA43C79F2A4E48A4F4A02905DE783FBD16 ft=1 fh=a9eb553813c219ce vn="NSIS/StartPage.CC Trojaner" ac=I fn="E:\Backup von MyBookLive\MyBookLive Public\Shared Downloads\_BackUp Downloads Lenovo\vlc-2.1.4-win64.exe" sh=D24E61D3397326811FD8B5CFEB800652E4F57713 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Babylon.P evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-01-06 134532\Backup files 21.zip" sh=101C6718F4E9E14BBF0953500EBA83778586F2E7 ft=0 fh=0000000000000000 vn="Win32/DownWare.W evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-01-06 134532\Backup files 213.zip" sh=D35DCE119BBFCD1B71EFCACB586B026B4AD653B1 ft=0 fh=0000000000000000 vn="Win32/FileScout.A evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-01-06 134532\Backup files 22.zip" sh=7DD8F3D49017ECACB0D754E6E2F0834228DB5069 ft=0 fh=0000000000000000 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-01-06 134532\Backup files 27.zip" sh=A2CC1B3770ABAAFA343F9A45850C8F19F6E7DD44 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Funmoods.D evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-01-06 134532\Backup files 30.zip" sh=CF893B58F9925ED460ACB97031F8413DE0215DAD ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-01-06 134532\Backup files 31.zip" sh=A22B99B99A08F9AFFFB18FA09A3F31D8E4302F61 ft=0 fh=0000000000000000 vn="Variante von Win32/SoftonicDownloader.F evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-01-06 134532\Backup files 32.zip" sh=368AF56062F3C9CA655E7B2C4D534B1E6395A0F8 ft=0 fh=0000000000000000 vn="Win32/DownWare.W evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-01-06 134532\Backup files 33.zip" sh=E58782D7F0840F877C2B3031F0451176732188A5 ft=0 fh=0000000000000000 vn="Win32/DownWare.W evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-01-06 134532\Backup files 38.zip" sh=C940F1E58858B39FFD7CCE2478E291A151438C2A ft=0 fh=0000000000000000 vn="Win32/Packed.Autoit.C.Gen evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-01-06 134532\Backup files 4.zip" sh=2D907567CA5DE36346D42C0D9E1457A5F128D69D ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-01-06 134532\Backup files 67.zip" sh=7B0BD9A49E0E5CDBFEBF12ABC0C1288746AA9551 ft=0 fh=0000000000000000 vn="NSIS/StartPage.CC Trojaner" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-02-09 190001\Backup files 2.zip" sh=76E961C314A6AFDA975ADB011E1A394E46FDA3C7 ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-02-09 190001\Backup files 5.zip" sh=06B9B1AFC68D07E51769E390F2B6A04B4A9FEB0E ft=0 fh=0000000000000000 vn="Variante von Win32/GetNow.B evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-03-10 102308\Backup files 2.zip" sh=2E1D21E26528D483DE885A169CDE9EDEF1E34B93 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadGuide.A evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-04-13 190002\Backup files 1.zip" sh=9F740056BC43E7FF06A3E72029FE353622F9492E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-04-13 190002\Backup files 10.zip" sh=AFBF8D4E2D118FF9197C54993C15D5347361F84B ft=0 fh=0000000000000000 vn="NSIS/StartPage.CC Trojaner" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-04-13 190002\Backup files 2.zip" sh=A15E646FB44710E6F735F03AF813233954AEF333 ft=0 fh=0000000000000000 vn="Variante von Win32/CNETInstaller.B evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-05 211824\Backup files 1.zip" sh=EDC2E4DEEC841C783659563BAF5FD0BD6311C129 ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-05 211824\Backup files 109.zip" sh=303298A8A36121BEA4967A183C5A34CE0ABB4C50 ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-05 211824\Backup files 110.zip" sh=3450D32969420E58B5504E660D0456C887485157 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-05 211824\Backup files 15.zip" sh=184DA795E166218B19CDB7BA403D0FB2EA4D3394 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Funmoods.D evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-05 211824\Backup files 46.zip" sh=837378B3CC7CFB2047F89E000DA353AC264CB786 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-05 211824\Backup files 47.zip" sh=BF1EC78FDD8D605EEF9FF8B078816AD0B30814C5 ft=0 fh=0000000000000000 vn="Variante von Win32/SoftonicDownloader.F evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-05 211824\Backup files 48.zip" sh=44B72EB0206649FA96752D88154BFE5F054F06A0 ft=0 fh=0000000000000000 vn="NSIS/StartPage.CC Trojaner" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-05 211824\Backup files 49.zip" sh=BBA2DCABA048A88CCC9747B1B4A0980E0C66F2C2 ft=0 fh=0000000000000000 vn="Win32/DownWare.W evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-05 211824\Backup files 50.zip" sh=4CB4A1C9D56F9B379902011CE27F8B958104AE9B ft=0 fh=0000000000000000 vn="NSIS/StartPage.CC Trojaner" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-05 211824\Backup files 51.zip" sh=94A353BD89890C262F1A5253DEB1A446E85B26FD ft=0 fh=0000000000000000 vn="Win32/DownWare.W evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-05 211824\Backup files 92.zip" sh=58C02CE6F13D8AEDE7A8C7F53EE1270CC929D2FC ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-05 211824\Backup files 96.zip" sh=D26E8D874CB654339B23ED816BFA88B17FF74CC3 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-11 190011\Backup files 106.zip" sh=0C09568A159D7E9A86B45F286CA1426360E6C47D ft=0 fh=0000000000000000 vn="Win32/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-11 190011\Backup files 107.zip" sh=45AC07EA2179793C822B8A772F9E3DF7A230A224 ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-11 190011\Backup files 110.zip" sh=D315454F1667173240AD648557AE16EC017A0787 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-11 190011\Backup files 117.zip" sh=5489EC57F820126DC5B25585794AD195D2DBB81C ft=0 fh=0000000000000000 vn="Win32/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-11 190011\Backup files 119.zip" sh=3DB031094B65628DF706DB24BE226F581CA84515 ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-11 190011\Backup files 125.zip" sh=5A67F1D545EA3F2FCE544F9C092852E7631E8104 ft=0 fh=0000000000000000 vn="Win32/DownWare.W evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-11 190011\Backup files 167.zip" sh=CEE58752607605C03EE1AC75F4EA20BCDC905046 ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-05-11 190011\Backup files 23.zip" sh=B52936F5FFAE5B86958025EF4C849E48F28AAF25 ft=0 fh=0000000000000000 vn="Variante von Win32/GetNow.C evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-06-29 190005\Backup files 1.zip" sh=6B303FA66C259EF4C3515784311F60F5732B4ED6 ft=0 fh=0000000000000000 vn="Win32/AdWare.Adpeak.F Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-06-29 190005\Backup files 6.zip" sh=00A3768F04C3461140348C620BA6198C622E47C8 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="Q:\RAINER-PC\Backup Set 2014-01-06 134532\Backup Files 2014-06-29 190005\Backup files 9.zip" |
17.01.2015, 20:44 | #26 |
/// Winkelfunktion /// TB-Süch-Tiger™ | db22.exe wurde von Stinger gefunden aber nicht gelöscht Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\EULE SHARE A\vlc-0.9.9-win32.exe C:\Program Files\Win7codecs C:\Users\All Users\Win7codecs C:\Users\RAaM2\Downloads\cbsidlm-cbsi188-BestPractice-ORG-10794555.exe C:\Users\RAaM2\Downloads\DVBViewer_setup_demo_uni.exe C:\Users\RAaM2\Downloads\FFSetup-270.zip C:\Users\RAaM2\Downloads\FFSetup3.1.1.0.exe C:\Users\RAaM2\Downloads\FFSetup3.3.1.0.exe C:\Users\RAaM2\Downloads\FreeYouTubeDownload_3.2.1.320.exe C:\Users\RAaM2\Downloads\iMeshV12.exe C:\Users\RAaM2\Downloads\VDFilterPack.exe C:\Users\RAaM2\Downloads\vlc-2.1.2-win32.exe C:\Users\RAaM2\Downloads\VSDC Free Video Editor - CHIP-Installer.exe C:\Users\RAaM2\Downloads\MediaSoftware\DVDStyler-2.2-win32.exe C:\Users\RAaM2\Downloads\MediaSoftware\SoftonicDownloader_fuer_videopad-video-editor.exe C:\Users\RAaM2\Downloads\MediaSoftware\video_pad_setup.exe C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\AdwCleaner - CHIP-Installer.exe C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\ag_setup183se.exe C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\FFSetup3.3.4.0.exe C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\vlc-2.1.4-win64.exe C:\Windows\Installer\ad1211.msi EmptyTemp: Hosts: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
17.01.2015, 21:40 | #27 |
| db22.exe wurde von Stinger gefunden aber nicht gelöschtCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 17-01-2015 01 Ran by RAaM2 at 2015-01-17 21:29:53 Run:2 Running from C:\Users\RAaM2\Desktop Loaded Profiles: RAaM2 (Available profiles: RAaM2 & Sarah & Christa & Gast) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\EULE SHARE A\vlc-0.9.9-win32.exe C:\Program Files\Win7codecs C:\Users\All Users\Win7codecs C:\Users\RAaM2\Downloads\cbsidlm-cbsi188-BestPractice-ORG-10794555.exe C:\Users\RAaM2\Downloads\DVBViewer_setup_demo_uni.exe C:\Users\RAaM2\Downloads\FFSetup-270.zip C:\Users\RAaM2\Downloads\FFSetup3.1.1.0.exe C:\Users\RAaM2\Downloads\FFSetup3.3.1.0.exe C:\Users\RAaM2\Downloads\FreeYouTubeDownload_3.2.1.320.exe C:\Users\RAaM2\Downloads\iMeshV12.exe C:\Users\RAaM2\Downloads\VDFilterPack.exe C:\Users\RAaM2\Downloads\vlc-2.1.2-win32.exe C:\Users\RAaM2\Downloads\VSDC Free Video Editor - CHIP-Installer.exe C:\Users\RAaM2\Downloads\MediaSoftware\DVDStyler-2.2-win32.exe C:\Users\RAaM2\Downloads\MediaSoftware\SoftonicDownloader_fuer_videopad-video-editor.exe C:\Users\RAaM2\Downloads\MediaSoftware\video_pad_setup.exe C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\AdwCleaner - CHIP-Installer.exe C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\ag_setup183se.exe C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\FFSetup3.3.4.0.exe C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\vlc-2.1.4-win64.exe C:\Windows\Installer\ad1211.msi EmptyTemp: Hosts: ***************** C:\EULE SHARE A\vlc-0.9.9-win32.exe => Moved successfully. C:\Program Files\Win7codecs => Moved successfully. C:\Users\All Users\Win7codecs => Moved successfully. C:\Users\RAaM2\Downloads\cbsidlm-cbsi188-BestPractice-ORG-10794555.exe => Moved successfully. C:\Users\RAaM2\Downloads\DVBViewer_setup_demo_uni.exe => Moved successfully. C:\Users\RAaM2\Downloads\FFSetup-270.zip => Moved successfully. C:\Users\RAaM2\Downloads\FFSetup3.1.1.0.exe => Moved successfully. C:\Users\RAaM2\Downloads\FFSetup3.3.1.0.exe => Moved successfully. C:\Users\RAaM2\Downloads\FreeYouTubeDownload_3.2.1.320.exe => Moved successfully. C:\Users\RAaM2\Downloads\iMeshV12.exe => Moved successfully. C:\Users\RAaM2\Downloads\VDFilterPack.exe => Moved successfully. C:\Users\RAaM2\Downloads\vlc-2.1.2-win32.exe => Moved successfully. C:\Users\RAaM2\Downloads\VSDC Free Video Editor - CHIP-Installer.exe => Moved successfully. C:\Users\RAaM2\Downloads\MediaSoftware\DVDStyler-2.2-win32.exe => Moved successfully. C:\Users\RAaM2\Downloads\MediaSoftware\SoftonicDownloader_fuer_videopad-video-editor.exe => Moved successfully. C:\Users\RAaM2\Downloads\MediaSoftware\video_pad_setup.exe => Moved successfully. C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\AdwCleaner - CHIP-Installer.exe => Moved successfully. C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\ag_setup183se.exe => Moved successfully. C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\FFSetup3.3.4.0.exe => Moved successfully. C:\Users\RAaM2\Downloads\_BackUp Downloads Lenovo\vlc-2.1.4-win64.exe => Moved successfully. C:\Windows\Installer\ad1211.msi => Moved successfully. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. EmptyTemp: => Removed 350.4 MB temporary data. The system needed a reboot. ==== End of Fixlog 21:30:09 ==== |
17.01.2015, 22:19 | #28 |
/// Winkelfunktion /// TB-Süch-Tiger™ | db22.exe wurde von Stinger gefunden aber nicht gelöscht Sieht soweit ok aus Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) empfehle ich die Erweiterung Ghostery, diese verhindert weitgehend Usertracking bzw. das Anzeigen von Werbebannern. Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie ) Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird. Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________ Logfiles bitte immer in CODE-Tags posten |
18.01.2015, 11:34 | #29 |
| db22.exe wurde von Stinger gefunden aber nicht gelöscht Hallo Cosinus, zunächst mal vielen Dank für deine professionelle Unterstützung. Alleine hätte ich das nie geschafft. An der einen oder anderen Stelle hätte ich mir zu den Programmläufen oder meinen Log-Posts noch ein bissl Hintergrund-Info gewünscht. Nur ein oder zwei Sätze. Ich habe aber auch Verständnis dafür, dass sowas das Prozedere noch mehr in die Länge ziehen könnte. Ich denke auf meinem Pc ist jetzt wieder alles ok. Ich werde mir deine Tipps mal genauer ansehen und das eine und/oder andere berücksichtigen. Nochmal vielen Dank und Grüße ronark |
18.01.2015, 14:56 | #30 |
/// Winkelfunktion /// TB-Süch-Tiger™ | db22.exe wurde von Stinger gefunden aber nicht gelöscht Dann wären wir durch! Falls du noch Lob oder Kritik loswerden möchtest => Lob, Kritik und Wünsche - Trojaner-Board Die Programme, die hier zum Einsatz kamen, können alle deinstalliert werden. Es empfiehlt sich Malwarebytes Anti-Malware zu behalten und damit wöchentlich nach Malware zu scannen. Helfen kann dir dabei delfix: Die Reihenfolge ist hier entscheidend.
Bitte abschließend noch die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden. Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern. Microsoftupdate Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren. Windows Vista/7: Start, Systemsteuerung, Windows-Update PDF-Reader aktualisieren Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast) Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader. Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers: Prüfen => Adobe - Flash Player Downloadlinks findest du hier => Browsers and Plugins - FilePony.de Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind. Java-Update Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu db22.exe wurde von Stinger gefunden aber nicht gelöscht |
abgespielt, anwendung, c:\windows, c:\windows\temp, datei, db22.exe, einfach, gefunde, gelöscht, hintergrund, lautsprecher, löschen, mcaffee, musik, neu, rechner, richtig, schlau, stinger, temp, thread, troja, trojaner, vermute, windows, windows\temp |