|
Log-Analyse und Auswertung: Proxy-Fehlermeldung 127.0.0.1:8897Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
27.01.2015, 09:40 | #1 |
| Proxy-Fehlermeldung 127.0.0.1:8897 Hallo, ich habe den Laptop einer bekannten bekommen daa sie Probleme hatte im Internet zu surfen. Da habe ich herraus gefunden das die Proxy-Einstellungen verstell waren und zwar auf HTTP: 127.0.0.1 : 8897 Secure: 127.0.0.1 : 8897 Ausnahmen : <-loopback>;www.joosoft.com Die Einträge erscheinen nach dem Neustart wieder, Avast und Malewarebytes habe ich bereits durchlaufen lassen und die infizierten Datein entfernen lassen. Ich habe gesehen das hier jemand schon das selbe Problem hatte, ich will jedoch nichts auf eigene Faust probieren und wende mich daher an euch Hier der Link zum anderen Thema FRST Code: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01 Ran by User (administrator) on USER-PC on 27-01-2015 09:23:36 Running from C:\Users\User\Desktop Loaded Profiles: User (Available profiles: User) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Program Files (x86)\Search\WebSearch.exe (WiseCleaner.com) C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Huawei Technologies Co., Ltd.) C:\Users\User\AppData\Roaming\tele.ring Verbindungsmanager\ouc.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard) HKLM-x32\...\Run: [DataCardMonitor] => C:\Program Files (x86)\tele.ring Verbindungsmanager\DataCardMonitor.exe [253952 2013-07-03] (Huawei Technologies Co., Ltd.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-26] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Run: [HW_OPENEYE_OUC_tele.ring Verbindungsmanager] => C:\Program Files (x86)\tele.ring Verbindungsmanager\UpdateDog\ouc.exe [110592 2009-12-31] (Huawei Technologies Co., Ltd.) HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: D - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: E - E:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {29de0f77-227c-11e2-8036-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {29de0f86-227c-11e2-8036-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {2bf70504-e3b9-11e2-8d2e-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {2bf70521-e3b9-11e2-8d2e-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {34c73ff9-2c16-11e2-9a50-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {356f63b6-4016-11e1-b766-b1570f61f5d9} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {356f63c7-4016-11e1-b766-b1570f61f5d9} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {5f6fac67-3f6e-11e1-a137-85ae9d686db3} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {5f6fac7e-3f6e-11e1-a137-85ae9d686db3} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {6e38b045-773e-11e1-9b43-e38defa8a60e} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {71060446-88c3-11e2-bd69-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {b3d5e5f9-2c6b-11e1-bc7d-806e6f6e6963} - F:\Setup.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {b56a49e9-826d-11e2-a311-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {b56a49f7-826d-11e2-a311-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {c661975b-e330-11e2-9294-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {c6619775-e330-11e2-9294-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {eac35ae9-3de2-11e1-a302-90004e63fc55} - D:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {eac35af7-3de2-11e1-a302-90004e63fc55} - D:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {f660393c-40de-11e1-af44-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {f83e50fe-e95d-11e2-829c-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {facf2493-2277-11e2-bb88-90004e63fc55} - D:\Data\setup.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {facf2499-2277-11e2-bb88-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {fb2a7ec3-3411-11e4-a467-90004e63fc55} - D:\AutoRun.exe Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:8897;https=127.0.0.1:8897 ProxyEnable: [S-1-5-21-982829961-422532093-1718007052-1000] => Internet Explorer proxy is enabled. ProxyServer: [S-1-5-21-982829961-422532093-1718007052-1000] => http=127.0.0.1:8897;https=127.0.0.1:8897 HKU\S-1-5-21-982829961-422532093-1718007052-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.at/?gws_rd=ssl HKU\S-1-5-21-982829961-422532093-1718007052-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCON/1 SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {E40F8372-A296-4395-92CB-F634CAC151B8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {E40F8372-A296-4395-92CB-F634CAC151B8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> {149397D9-74D9-4EB6-B8CC-375AA2B5BD56} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10397&src=kw&q={searchTerms}&locale=de_AT&apn_ptnrs=^ABV&apn_dtid=^YYYYYY^YY^AT&apn_uid=5df9fad8-523b-49fe-b465-42f49a565823&apn_sauid=E877B625-FE41-4FF5-91DB-5C4FF038390C SearchScopes: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> {E40F8372-A296-4395-92CB-F634CAC151B8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) BHO-x32: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52272 2010-08-02] (EasyBits Software Corp.) Winsock: Catalog5 07 C:\Windows\system32\tnnslu80z.dll File Not found () Tcpip\Parameters: [DhcpNameServer] 10.64.1.224 10.64.1.225 FireFox: ======== FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\gnj2wp5w.default FF Homepage: https://www.google.at FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\2\NP_wtapp.dll () FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-03-21] FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-01-26] FF HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-26] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-26] (AVAST Software) R2 DailytoolsUpdateService; C:\Windows\SysWOW64\update1.dll [352256 2014-08-05] (Dailytools GmbH) [File not signed] R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129584 2009-02-22] (EasyBits Sofware AS) [File not signed] S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [254016 2014-10-10] (WildTangent) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () S4 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-10-16] (Hewlett-Packard Company) [File not signed] R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [File not signed] S4 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-06] () R2 Search; C:\Program Files (x86)\Search\WebSearch.exe [435696 2014-11-09] () R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580648 2012-07-17] (WiseCleaner.com) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-26] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [87912 2015-01-26] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-26] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-26] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-26] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-26] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-26] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-26] () R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) [File not signed] R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-27] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation) S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-23] (Realtek Semiconductor Corp.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) [File not signed] S3 cpuz135; \??\C:\Users\User\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X] S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X] S3 zte_ecm_enum_filter; system32\DRIVERS\zte_ecm_enum_filter.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 09:23 - 2015-01-27 09:24 - 00018436 _____ () C:\Users\User\Desktop\FRST.txt 2015-01-27 09:23 - 2015-01-27 09:23 - 02129920 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe 2015-01-27 09:23 - 2015-01-27 09:23 - 00000000 ____D () C:\FRST 2015-01-26 10:48 - 2015-01-26 10:48 - 00000000 ____D () C:\Users\User\AppData\Roaming\AVAST Software 2015-01-26 10:47 - 2015-01-26 10:47 - 00001964 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-01-26 10:47 - 2015-01-26 10:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2015-01-26 10:46 - 2015-01-27 08:11 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2015-01-26 10:46 - 2015-01-26 10:47 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2015-01-26 10:46 - 2015-01-26 10:47 - 00087912 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2015-01-26 10:46 - 2015-01-26 10:46 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2015-01-26 10:46 - 2015-01-26 10:46 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2015-01-26 10:45 - 2015-01-26 10:45 - 00000000 ____D () C:\Program Files\AVAST Software 2015-01-26 10:44 - 2015-01-26 10:45 - 00000000 ____D () C:\ProgramData\AVAST Software 2015-01-26 10:40 - 2015-01-26 10:43 - 132469808 _____ (AVAST Software) C:\Users\User\Downloads\avast_free_antivirus_setup.exe 2015-01-26 09:59 - 2015-01-27 09:06 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-26 09:58 - 2015-01-26 09:58 - 00001062 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-26 09:58 - 2015-01-26 09:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-26 09:58 - 2015-01-26 09:58 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-26 09:58 - 2015-01-26 09:58 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-01-26 09:58 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-26 09:58 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-26 09:58 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-26 09:56 - 2015-01-26 09:57 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.4.1028.exe 2015-01-24 14:18 - 2015-01-24 14:18 - 00000000 ____D () C:\Users\User\Documents\Neuer Ordner (3) 2015-01-23 06:17 - 2015-01-27 09:04 - 00000616 _____ () C:\Windows\setupact.log 2015-01-23 06:17 - 2015-01-26 12:58 - 00013996 _____ () C:\Windows\PFRO.log 2015-01-23 06:17 - 2015-01-23 06:17 - 00000000 _____ () C:\Windows\setuperr.log 2015-01-22 18:19 - 2015-01-27 09:09 - 00289755 _____ () C:\Windows\WindowsUpdate.log 2015-01-19 15:14 - 2015-01-19 15:14 - 00001003 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2015-01-19 15:14 - 2015-01-19 15:14 - 00000991 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk 2015-01-19 15:14 - 2015-01-19 15:14 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2015-01-19 15:13 - 2015-01-19 15:13 - 07718224 _____ (TeamViewer GmbH) C:\Users\User\Downloads\TeamViewer_Setup_de-ckc.exe 2015-01-14 19:09 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 19:09 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 19:09 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-14 19:09 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-01-14 19:09 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-01-14 19:09 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-01-14 19:09 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-01-14 19:09 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-01-14 19:09 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-01-14 19:09 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-14 19:09 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 19:09 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-14 19:09 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2015-01-13 16:35 - 2015-01-13 16:35 - 00000000 ____H () C:\Users\User\AppData\Local\BIT53EA.tmp 2015-01-13 16:35 - 2015-01-13 16:35 - 00000000 _____ () C:\Users\User\AppData\Local\{4B22D22B-3BA4-40E7-B6BC-98DD75627F4A} 2015-01-01 17:54 - 2015-01-01 17:54 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieBrowserModeList ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 09:23 - 2009-07-14 05:45 - 00023248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-27 09:23 - 2009-07-14 05:45 - 00023248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-27 09:18 - 2012-11-08 10:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-27 09:18 - 2012-03-05 10:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-27 09:12 - 2011-12-23 08:48 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{DB32AAC0-AE95-47E6-8D2E-C7CA58C9B8C0} 2015-01-27 09:09 - 2010-01-20 11:41 - 11334188 _____ () C:\Windows\system32\perfh007.dat 2015-01-27 09:09 - 2010-01-20 11:41 - 03584200 _____ () C:\Windows\system32\perfc007.dat 2015-01-27 09:09 - 2009-07-14 06:13 - 00006268 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-27 09:05 - 2013-03-01 11:54 - 00000000 ____D () C:\Users\User\AppData\Roaming\Wise Care 365 2015-01-27 09:04 - 2013-03-01 12:20 - 00000420 _____ () C:\Windows\Tasks\Wise Care 365.job 2015-01-27 09:04 - 2012-11-08 10:09 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-27 09:04 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-27 08:11 - 2012-11-08 10:09 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-26 10:50 - 2012-11-08 09:30 - 00001912 _____ () C:\Windows\epplauncher.mif 2015-01-26 10:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing 2015-01-22 13:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2015-01-19 17:47 - 2009-07-14 05:45 - 00374152 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-19 15:19 - 2011-12-22 08:16 - 00091216 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT 2015-01-14 20:15 - 2013-07-12 17:57 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-14 20:12 - 2011-12-23 10:36 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-01-08 09:55 - 2011-12-23 08:50 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Files in the root of some directories ======= 2011-12-22 08:15 - 2011-12-22 08:15 - 0000000 _____ () C:\Users\User\AppData\Local\AtStart.txt 2015-01-13 16:35 - 2015-01-13 16:35 - 0000000 ____H () C:\Users\User\AppData\Local\BIT53EA.tmp 2013-04-07 17:14 - 2013-05-24 17:48 - 0005632 _____ () C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2011-12-22 08:15 - 2011-12-22 08:15 - 0000000 _____ () C:\Users\User\AppData\Local\DSwitch.txt 2011-12-22 08:15 - 2011-12-22 08:15 - 0000000 _____ () C:\Users\User\AppData\Local\QSwitch.txt 2015-01-13 16:35 - 2015-01-13 16:35 - 0000000 _____ () C:\Users\User\AppData\Local\{4B22D22B-3BA4-40E7-B6BC-98DD75627F4A} 2012-12-30 10:55 - 2015-01-27 09:05 - 0000509 _____ () C:\ProgramData\HPWALog.txt 2012-03-21 15:20 - 2012-03-21 15:40 - 0003039 _____ () C:\ProgramData\hpzinstall.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log 2010-01-20 04:59 - 2010-01-20 04:59 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log 2010-01-20 04:55 - 2010-01-20 04:56 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2010-08-02 13:14 - 2010-08-02 13:14 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log 2010-01-20 04:54 - 2010-01-20 04:55 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log 2010-01-20 04:56 - 2010-01-20 04:58 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-26 13:28 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-01-2015 01 Ran by User at 2015-01-27 09:24:23 Running from C:\Users\User\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (Version: 7.2.4 - Hewlett-Packard) Hidden Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.) Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.32.18 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Reader 9.2 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.2.0 - Adobe Systems Incorporated) Adobe Shockwave Player (HKLM-x32\...\{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}) (Version: 11.5.1.601 - Adobe Systems, Inc.) ATI Catalyst Install Manager (HKLM\...\{C9083B9D-9092-FF22-DDCC-9776E69BE816}) (Version: 3.0.765.0 - ATI Technologies, Inc.) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software) Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation) Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.350.6 - Broadcom Corporation) BufferChm (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden C310 (x32 Version: 140.0.304.000 - Hewlett-Packard) Hidden ccc-core-static (x32 Version: 2010.0302.2233.40412 - Ihr Firmenname) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.24 - Piriform) Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.2216 - CyberLink Corp.) CyberLink MediaShow (HKLM-x32\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 4.1.3419 - CyberLink Corp.) CyberLink PowerDVD 8 (HKLM-x32\...\InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}) (Version: 8.0.1.1110 - CyberLink Corp.) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2201 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Destinations (x32 Version: 140.0.77.000 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard) Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden GPBaseService2 (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden HP Advisor (HKLM-x32\...\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.3.9512.3162 - Hewlett-Packard) HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.0.71 - WildTangent) HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP) HP Photosmart Prem C310 All-In-One Driver Software 14.0 Rel. 7 (HKLM\...\{4E484899-4F93-4086-88BA-56BDDF47A776}) (Version: 14.0 - HP) HP Quick Launch Buttons (HKLM-x32\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.9.1 - Hewlett-Packard) HP Setup (HKLM-x32\...\{17B4760F-334B-475D-829F-1A3E94A6A4E6}) (Version: 1.2.3560.3170 - Hewlett-Packard) HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP) HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP) HP Update (HKLM-x32\...\{74DC0593-6BC6-4001-AD5F-D810AFB68D86}) (Version: 5.002.002.002 - Hewlett-Packard) HP User Guides 0183 (HKLM-x32\...\{BC146E5F-A2B0-40DB-90E7-2833807E98DF}) (Version: 1.01.0001 - Hewlett-Packard) HP Wireless Assistant (HKLM-x32\...\{54CC7901-804D-4155-B353-21F0CC9112AB}) (Version: 3.50.9.1 - Hewlett-Packard) HPAppStudio (x32 Version: 140.0.95.000 - Hewlett-Packard) Hidden HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Java(TM) 6 Update 17 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416017FF}) (Version: 6.0.170 - Sun Microsystems, Inc.) Java(TM) 6 Update 22 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216022F0}) (Version: 6.0.220 - Oracle) Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2215 - CyberLink Corp.) LabelPrint (x32 Version: 2.5.2215 - CyberLink Corp.) Hidden LightScribe System Software (HKLM-x32\...\{10CCF16B-F1C9-4B24-9570-B4CCEE42392D}) (Version: 1.18.9.1 - LightScribe) Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: - EasyBits Software AS) Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation) Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 35.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0 (x86 de)) (Version: 35.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Network64 (Version: 140.0.215.000 - Hewlett-Packard) Hidden OpenOffice.org 3.3 (HKLM-x32\...\{4286716B-1287-48E7-9078-3DC8248DBA96}) (Version: 3.3.9567 - OpenOffice.org) Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.3415 - CyberLink Corp.) Power2Go (x32 Version: 6.0.3415 - CyberLink Corp.) Hidden PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.3420 - CyberLink Corp.) PowerDirector (x32 Version: 7.0.3420 - CyberLink Corp.) Hidden PS_AIO_07_C310_SW_Min (x32 Version: 140.0.304.000 - Hewlett-Packard) Hidden PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden QLBCASL (x32 Version: 6.40.17.2 - Hewlett-Packard) Hidden QuickTransfer (x32 Version: 140.0.98.000 - Hewlett-Packard) Hidden Realtek Ethernet Controller Driver For Windows Vista and Later (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6010 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30105 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.2214 - CyberLink Corp.) Hidden Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP) SmartWebPrinting (x32 Version: 140.0.186.000 - Hewlett-Packard) Hidden SolutionCenter (x32 Version: 140.0.214.000 - Hewlett-Packard) Hidden Speccy (HKLM\...\Speccy) (Version: 1.14 - Piriform) Status (x32 Version: 140.0.256.000 - Hewlett-Packard) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36897 - TeamViewer) tele.ring Verbindungsmanager (HKLM-x32\...\tele.ring Verbindungsmanager) (Version: 11.301.05.12.123 - Huawei Technologies Co.,Ltd) Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden WebReg (x32 Version: 140.0.212.017 - Hewlett-Packard) Hidden WildTangent Games App für HP (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.11.2 - WildTangent) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows Live Sync (HKLM-x32\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation) Wise Care 365 version 2.22 (HKLM-x32\...\{E864A1C8-EEE1-47D0-A7F8-00CC86D26D5E}_is1) (Version: 2.22 - WiseCleaner.com, Inc.) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-982829961-422532093-1718007052-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-982829961-422532093-1718007052-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-982829961-422532093-1718007052-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-982829961-422532093-1718007052-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-982829961-422532093-1718007052-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 07-12-2014 04:55:56 Windows Update 07-12-2014 19:00:11 Windows-Sicherung 10-12-2014 05:37:52 Windows Update 10-12-2014 06:01:04 Windows Update 10-12-2014 06:17:29 Windows Update 12-12-2014 19:02:24 Windows Update 15-12-2014 19:18:13 Windows-Sicherung 16-12-2014 19:50:17 Windows Update 18-12-2014 18:32:27 Windows Update 21-12-2014 19:24:15 Windows Update 22-12-2014 17:59:47 Windows-Sicherung 25-12-2014 17:12:36 Windows Update 29-12-2014 20:17:53 Windows-Sicherung 01-01-2015 08:19:57 Windows Update 05-01-2015 06:29:27 Windows Update 05-01-2015 18:36:33 Windows-Sicherung 11-01-2015 19:00:11 Windows-Sicherung 13-01-2015 05:27:26 Windows Update 14-01-2015 20:12:17 Windows Update 18-01-2015 16:48:54 Windows Update 18-01-2015 19:00:11 Windows-Sicherung 22-01-2015 05:52:14 Windows Update 25-01-2015 19:17:51 Windows Update 26-01-2015 10:00:47 Windows-Sicherung 26-01-2015 10:45:08 avast! antivirus system restore point ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {10AE75DB-1A8B-4725-9484-4F273FC4BF70} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-08] (Google Inc.) Task: {1CC9F1EE-8A58-4D17-9A5E-4C5E8FAF18F1} - \AutoKMS No Task File <==== ATTENTION Task: {2F8FFF31-7780-48A1-83C1-6C6ED5BE0AC2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-08] (Google Inc.) Task: {38D7D7B4-81CA-4204-862F-9E39D400F746} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_backup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe Task: {5363914C-6104-46F0-9DA6-DF6CFBD2BB4B} - System32\Tasks\{F6F8B99E-5DF4-4B82-8404-4DB9A0A3962D} => pcalua.exe -a "C:\Program Files (x86)\Avira\AntiVir Desktop\setup.exe" -c /REMOVE Task: {A529602A-BADE-42B2-96F3-834AEFE569EE} - System32\Tasks\Games\UpdateCheck_S-1-5-21-982829961-422532093-1718007052-1000 Task: {AA9E4DC8-66CA-4908-9D4F-A013715F94B4} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-01-26] (AVAST Software) Task: {B416E84D-7909-43DA-B267-1FD2BE8A2E45} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe Task: {BC89A92B-AEF4-4FF2-8D44-87D6CB9986C8} - System32\Tasks\Wise Care 365 => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe [2013-02-07] (WiseCleaner.com) Task: {EC5AE52E-C11E-4BDE-99CE-5F545006F60B} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2009-10-07] () Task: {FF81F6AD-5596-4FB2-AAED-0AE5EFB3E69B} - System32\Tasks\{89A41138-11E3-4A9C-AFD3-23ECA89BCA36} => pcalua.exe -a C:\Users\User\Desktop\avira_free_antivirus_de1200861.exe -d C:\Users\User\Desktop Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Wise Care 365.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe ==================== Loaded Modules (whitelisted) ============= 2011-03-14 16:27 - 2011-03-14 16:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2014-08-07 18:40 - 2014-11-09 14:43 - 00435696 _____ () C:\Program Files (x86)\Search\WebSearch.exe 2015-01-27 08:12 - 2015-01-27 08:12 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15012601\algo.dll 2015-01-26 10:46 - 2015-01-26 10:46 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2011-01-17 16:19 - 2011-12-23 10:10 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 2012-11-08 10:48 - 2015-01-27 09:18 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Users\User\Documents\Fw_ Frühling.eml:OECustomProperty AlternateDataStreams: C:\Users\User\Documents\Fw_ Kerze bitte nicht löschen!.eml:OECustomProperty AlternateDataStreams: C:\Users\User\Documents\Fw_Wunderbare Bilder.eml:OECustomProperty AlternateDataStreams: C:\Users\User\Documents\Kalender.eml:OECustomProperty AlternateDataStreams: C:\Users\User\Documents\Reservierung DI Weissenberger.eml:OECustomProperty AlternateDataStreams: C:\Users\User\Documents\Reservierung helga.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: AERTFilters => 2 MSCONFIG\Services: AMD External Events Utility => 2 MSCONFIG\Services: Com4QLBEx => 3 MSCONFIG\Services: GamesAppService => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: hpqwmiex => 3 MSCONFIG\Services: HWDeviceService64.exe => 2 MSCONFIG\Services: LightScribeService => 2 MSCONFIG\Services: LMS => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: RichVideo => 2 MSCONFIG\Services: UNS => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: Easybits Recovery => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: HPADVISOR => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW MSCONFIG\startupreg: HW_OPENEYE_OUC_tele.ring Verbindungsmanager => "C:\Program Files (x86)\tele.ring Verbindungsmanager\UpdateDog\ouc.exe" MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe MSCONFIG\startupreg: LightScribe Control Panel => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe MSCONFIG\startupreg: QlbCtrl.exe => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start MSCONFIG\startupreg: RTHDVCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s MSCONFIG\startupreg: RtkOSD => C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Java\jre6\bin\jusched.exe" MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe ========================= Accounts: ========================== Administrator (S-1-5-21-982829961-422532093-1718007052-500 - Administrator - Disabled) Gast (S-1-5-21-982829961-422532093-1718007052-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-982829961-422532093-1718007052-1002 - Limited - Enabled) User (S-1-5-21-982829961-422532093-1718007052-1000 - Administrator - Enabled) => C:\Users\User ==================== Faulty Device Manager Devices ============= Name: High Definition Audio-Controller Description: High Definition Audio-Controller Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: HDAudBus Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: ATI Mobility Radeon HD 5470 Description: ATI Mobility Radeon HD 5470 Class Guid: {4d36e968-e325-11ce-bfc1-08002be10318} Manufacturer: ATI Technologies Inc. Service: amdkmdap Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/27/2015 09:09:28 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (01/27/2015 09:09:28 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (01/27/2015 09:09:28 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (01/26/2015 06:40:29 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (01/26/2015 01:53:06 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (01/26/2015 01:04:34 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (01/26/2015 01:04:34 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (01/26/2015 01:04:34 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (01/26/2015 10:45:13 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary ekqquljw. System Error: Das System kann die angegebene Datei nicht finden. . Error: (01/26/2015 10:43:59 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. System errors: ============= Error: (01/27/2015 09:06:49 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Search" wurde nicht richtig gestartet. Error: (01/27/2015 08:11:09 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst lmhosts erreicht. Error: (01/26/2015 01:00:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/26/2015 01:00:01 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Search erreicht. Error: (01/26/2015 10:36:43 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/26/2015 10:36:43 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Search erreicht. Error: (01/26/2015 09:51:03 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/26/2015 09:51:03 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Search erreicht. Error: (01/25/2015 07:01:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/25/2015 07:01:48 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Search erreicht. Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz Percentage of memory in use: 44% Total physical RAM: 3893.86 MB Available physical RAM: 2159.55 MB Total Pagefile: 7785.9 MB Available Pagefile: 5908.01 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.57 GB) (Free:406.64 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: F2C7247F) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.6 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Danke im Vorraus |
27.01.2015, 09:42 | #2 |
/// TB-Ausbilder | Proxy-Fehlermeldung 127.0.0.1:8897 Hallo DannY_93
__________________Mein Name ist Timo und ich werde Dir bei deinem Problem behilflich sein.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist immer der sicherste Weg. Wir arbeiten hier alle freiwillig und meist auch nur in unserer Freizeit. Daher kann es bei Antworten zu Verzögerungen kommen. Solltest du innerhalb 48 Std keine Antwort von mir erhalten, dann schreib mit eine PM Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis ich oder jemand vom Team sagt, dass Du clean bist. Führe sämtliche Tools mit administrativen Rechten aus, Vista, Win7,Win8 User mit Rechtsklick "als Administrator starten". Gibt es Logs von Avast und MBAM ?
__________________ |
27.01.2015, 09:44 | #3 |
/// TB-Ausbilder | Proxy-Fehlermeldung 127.0.0.1:8897 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.
__________________Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter cmd: netsh winhttp reset proxy cmd: netsh winsock reset cmd: netsh int ip reset Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Starte noch einmal FRST.
__________________ |
27.01.2015, 10:05 | #4 |
| Proxy-Fehlermeldung 127.0.0.1:8897 Hier einmal die Fixlog.txt Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-01-2015 01 Ran by User at 2015-01-27 09:48:45 Run:1 Running from C:\Users\User\Desktop Loaded Profiles: User (Available profiles: User) Boot Mode: Normal ============================================== Content of fixlist: ***************** cmd: netsh winhttp reset proxy cmd: netsh winsock reset cmd: netsh int ip reset ***************** ========= netsh winhttp reset proxy ========= Aktuelle WinHTTP-Proxyeinstellungen: Direktzugriff (kein Proxyserver). ========= End of CMD: ========= ========= netsh winsock reset ========= Der Winsock-Katalog wurde zur�ckgesetzt. Sie m�ssen den Computer neu starten, um den Vorgang abzuschlie�en. ========= End of CMD: ========= ========= netsh int ip reset ========= Global wird zur�ckgesetzt, OK! Schnittstelle wird zur�ckgesetzt, OK! Starten Sie den Computer neu, um die Aktion abzuschlie�en. ========= End of CMD: ========= ==== End of Fixlog 09:48:49 ==== FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01 Ran by User (administrator) on USER-PC on 27-01-2015 10:02:32 Running from C:\Users\User\Desktop Loaded Profiles: User (Available profiles: User) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Program Files (x86)\Search\WebSearch.exe (WiseCleaner.com) C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Huawei Technologies Co., Ltd.) C:\Users\User\AppData\Roaming\tele.ring Verbindungsmanager\ouc.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard) HKLM-x32\...\Run: [DataCardMonitor] => C:\Program Files (x86)\tele.ring Verbindungsmanager\DataCardMonitor.exe [253952 2013-07-03] (Huawei Technologies Co., Ltd.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-26] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Run: [HW_OPENEYE_OUC_tele.ring Verbindungsmanager] => C:\Program Files (x86)\tele.ring Verbindungsmanager\UpdateDog\ouc.exe [110592 2009-12-31] (Huawei Technologies Co., Ltd.) HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: D - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: E - E:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {29de0f77-227c-11e2-8036-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {29de0f86-227c-11e2-8036-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {2bf70504-e3b9-11e2-8d2e-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {2bf70521-e3b9-11e2-8d2e-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {34c73ff9-2c16-11e2-9a50-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {356f63b6-4016-11e1-b766-b1570f61f5d9} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {356f63c7-4016-11e1-b766-b1570f61f5d9} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {5f6fac67-3f6e-11e1-a137-85ae9d686db3} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {5f6fac7e-3f6e-11e1-a137-85ae9d686db3} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {6e38b045-773e-11e1-9b43-e38defa8a60e} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {71060446-88c3-11e2-bd69-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {b3d5e5f9-2c6b-11e1-bc7d-806e6f6e6963} - F:\Setup.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {b56a49e9-826d-11e2-a311-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {b56a49f7-826d-11e2-a311-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {c661975b-e330-11e2-9294-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {c6619775-e330-11e2-9294-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {eac35ae9-3de2-11e1-a302-90004e63fc55} - D:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {eac35af7-3de2-11e1-a302-90004e63fc55} - D:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {f660393c-40de-11e1-af44-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {f83e50fe-e95d-11e2-829c-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {facf2493-2277-11e2-bb88-90004e63fc55} - D:\Data\setup.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {facf2499-2277-11e2-bb88-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {fb2a7ec3-3411-11e4-a467-90004e63fc55} - D:\AutoRun.exe Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:8897;https=127.0.0.1:8897 ProxyEnable: [S-1-5-21-982829961-422532093-1718007052-1000] => Internet Explorer proxy is enabled. ProxyServer: [S-1-5-21-982829961-422532093-1718007052-1000] => http=127.0.0.1:8897;https=127.0.0.1:8897 HKU\S-1-5-21-982829961-422532093-1718007052-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.at/?gws_rd=ssl HKU\S-1-5-21-982829961-422532093-1718007052-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCON/1 SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {E40F8372-A296-4395-92CB-F634CAC151B8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {E40F8372-A296-4395-92CB-F634CAC151B8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> {149397D9-74D9-4EB6-B8CC-375AA2B5BD56} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10397&src=kw&q={searchTerms}&locale=de_AT&apn_ptnrs=^ABV&apn_dtid=^YYYYYY^YY^AT&apn_uid=5df9fad8-523b-49fe-b465-42f49a565823&apn_sauid=E877B625-FE41-4FF5-91DB-5C4FF038390C SearchScopes: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> {E40F8372-A296-4395-92CB-F634CAC151B8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) BHO-x32: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52272 2010-08-02] (EasyBits Software Corp.) Winsock: Catalog5 07 C:\Windows\system32\tnnslu80z.dll File Not found () Tcpip\Parameters: [DhcpNameServer] 10.64.1.224 10.64.1.225 FireFox: ======== FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\gnj2wp5w.default FF Homepage: https://www.google.at FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\2\NP_wtapp.dll () FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-03-21] FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-01-26] FF HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-26] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-26] (AVAST Software) R2 DailytoolsUpdateService; C:\Windows\SysWOW64\update1.dll [352256 2014-08-05] (Dailytools GmbH) [File not signed] R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129584 2009-02-22] (EasyBits Sofware AS) [File not signed] S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [254016 2014-10-10] (WildTangent) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () S4 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-10-16] (Hewlett-Packard Company) [File not signed] R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [File not signed] S4 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-06] () R2 Search; C:\Program Files (x86)\Search\WebSearch.exe [435696 2014-11-09] () R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580648 2012-07-17] (WiseCleaner.com) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-26] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [87912 2015-01-26] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-26] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-26] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-26] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-26] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-26] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-26] () R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) [File not signed] R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-27] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation) S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-23] (Realtek Semiconductor Corp.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) [File not signed] S3 cpuz135; \??\C:\Users\User\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X] S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X] S3 zte_ecm_enum_filter; system32\DRIVERS\zte_ecm_enum_filter.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 09:24 - 2015-01-27 09:24 - 00030904 _____ () C:\Users\User\Desktop\Addition.txt 2015-01-27 09:23 - 2015-01-27 10:02 - 00018275 _____ () C:\Users\User\Desktop\FRST.txt 2015-01-27 09:23 - 2015-01-27 10:02 - 00000000 ____D () C:\FRST 2015-01-27 09:23 - 2015-01-27 09:23 - 02129920 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe 2015-01-26 10:48 - 2015-01-26 10:48 - 00000000 ____D () C:\Users\User\AppData\Roaming\AVAST Software 2015-01-26 10:47 - 2015-01-26 10:47 - 00001964 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-01-26 10:47 - 2015-01-26 10:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2015-01-26 10:46 - 2015-01-27 08:11 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2015-01-26 10:46 - 2015-01-26 10:47 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2015-01-26 10:46 - 2015-01-26 10:47 - 00087912 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2015-01-26 10:46 - 2015-01-26 10:46 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2015-01-26 10:46 - 2015-01-26 10:46 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2015-01-26 10:45 - 2015-01-26 10:45 - 00000000 ____D () C:\Program Files\AVAST Software 2015-01-26 10:44 - 2015-01-26 10:45 - 00000000 ____D () C:\ProgramData\AVAST Software 2015-01-26 10:40 - 2015-01-26 10:43 - 132469808 _____ (AVAST Software) C:\Users\User\Downloads\avast_free_antivirus_setup.exe 2015-01-26 09:59 - 2015-01-27 09:29 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-26 09:58 - 2015-01-26 09:58 - 00001062 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-26 09:58 - 2015-01-26 09:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-26 09:58 - 2015-01-26 09:58 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-26 09:58 - 2015-01-26 09:58 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-01-26 09:58 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-26 09:58 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-26 09:58 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-26 09:56 - 2015-01-26 09:57 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.4.1028.exe 2015-01-24 14:18 - 2015-01-24 14:18 - 00000000 ____D () C:\Users\User\Documents\Neuer Ordner (3) 2015-01-23 06:17 - 2015-01-27 09:38 - 00001413 _____ () C:\Windows\setupact.log 2015-01-23 06:17 - 2015-01-26 12:58 - 00013996 _____ () C:\Windows\PFRO.log 2015-01-23 06:17 - 2015-01-23 06:17 - 00000000 _____ () C:\Windows\setuperr.log 2015-01-22 18:19 - 2015-01-27 09:09 - 00289850 _____ () C:\Windows\WindowsUpdate.log 2015-01-19 15:14 - 2015-01-19 15:14 - 00001003 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2015-01-19 15:14 - 2015-01-19 15:14 - 00000991 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk 2015-01-19 15:14 - 2015-01-19 15:14 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2015-01-19 15:13 - 2015-01-19 15:13 - 07718224 _____ (TeamViewer GmbH) C:\Users\User\Downloads\TeamViewer_Setup_de-ckc.exe 2015-01-14 19:09 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 19:09 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 19:09 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-14 19:09 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-01-14 19:09 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-01-14 19:09 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-01-14 19:09 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-01-14 19:09 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-01-14 19:09 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-01-14 19:09 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-14 19:09 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 19:09 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-14 19:09 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2015-01-13 16:35 - 2015-01-13 16:35 - 00000000 ____H () C:\Users\User\AppData\Local\BIT53EA.tmp 2015-01-13 16:35 - 2015-01-13 16:35 - 00000000 _____ () C:\Users\User\AppData\Local\{4B22D22B-3BA4-40E7-B6BC-98DD75627F4A} 2015-01-01 17:54 - 2015-01-01 17:54 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieBrowserModeList ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 09:39 - 2010-01-20 11:41 - 11349160 _____ () C:\Windows\system32\perfh007.dat 2015-01-27 09:39 - 2010-01-20 11:41 - 03589116 _____ () C:\Windows\system32\perfc007.dat 2015-01-27 09:39 - 2009-07-14 06:13 - 00006268 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-27 09:27 - 2012-11-08 10:09 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-27 09:23 - 2009-07-14 05:45 - 00023248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-27 09:23 - 2009-07-14 05:45 - 00023248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-27 09:18 - 2012-11-08 10:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-27 09:18 - 2012-03-05 10:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-27 09:12 - 2011-12-23 08:48 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{DB32AAC0-AE95-47E6-8D2E-C7CA58C9B8C0} 2015-01-27 09:05 - 2013-03-01 11:54 - 00000000 ____D () C:\Users\User\AppData\Roaming\Wise Care 365 2015-01-27 09:04 - 2013-03-01 12:20 - 00000420 _____ () C:\Windows\Tasks\Wise Care 365.job 2015-01-27 09:04 - 2012-11-08 10:09 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-27 09:04 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-26 10:50 - 2012-11-08 09:30 - 00001912 _____ () C:\Windows\epplauncher.mif 2015-01-26 10:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing 2015-01-22 13:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2015-01-19 17:47 - 2009-07-14 05:45 - 00374152 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-19 15:19 - 2011-12-22 08:16 - 00091216 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT 2015-01-14 20:15 - 2013-07-12 17:57 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-14 20:12 - 2011-12-23 10:36 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-01-08 09:55 - 2011-12-23 08:50 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Files in the root of some directories ======= 2011-12-22 08:15 - 2011-12-22 08:15 - 0000000 _____ () C:\Users\User\AppData\Local\AtStart.txt 2015-01-13 16:35 - 2015-01-13 16:35 - 0000000 ____H () C:\Users\User\AppData\Local\BIT53EA.tmp 2013-04-07 17:14 - 2013-05-24 17:48 - 0005632 _____ () C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2011-12-22 08:15 - 2011-12-22 08:15 - 0000000 _____ () C:\Users\User\AppData\Local\DSwitch.txt 2011-12-22 08:15 - 2011-12-22 08:15 - 0000000 _____ () C:\Users\User\AppData\Local\QSwitch.txt 2015-01-13 16:35 - 2015-01-13 16:35 - 0000000 _____ () C:\Users\User\AppData\Local\{4B22D22B-3BA4-40E7-B6BC-98DD75627F4A} 2012-12-30 10:55 - 2015-01-27 09:05 - 0000509 _____ () C:\ProgramData\HPWALog.txt 2012-03-21 15:20 - 2012-03-21 15:40 - 0003039 _____ () C:\ProgramData\hpzinstall.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log 2010-01-20 04:59 - 2010-01-20 04:59 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log 2010-01-20 04:55 - 2010-01-20 04:56 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2010-08-02 13:14 - 2010-08-02 13:14 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log 2010-01-20 04:54 - 2010-01-20 04:55 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log 2010-01-20 04:56 - 2010-01-20 04:58 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-26 13:28 ==================== End Of Log ============================ Gleich mal ein riesen Lob das es echt schnell hier geht , DANKE! |
27.01.2015, 10:10 | #5 |
/// TB-Ausbilder | Proxy-Fehlermeldung 127.0.0.1:8897 Gibt es Logs von Avast und MBAM ?
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
27.01.2015, 10:11 | #6 |
/// TB-Ausbilder | Proxy-Fehlermeldung 127.0.0.1:8897 Mach bitte noch: Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:8897;https=127.0.0.1:8897 ProxyEnable: [S-1-5-21-982829961-422532093-1718007052-1000] => Internet Explorer proxy is enabled. ProxyServer: [S-1-5-21-982829961-422532093-1718007052-1000] => http=127.0.0.1:8897;https=127.0.0.1:8897 Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Neu Rechner unbedingt neustarten und frisches FRST Log
__________________ --> Proxy-Fehlermeldung 127.0.0.1:8897 |
27.01.2015, 10:13 | #7 |
/// TB-Ausbilder | Proxy-Fehlermeldung 127.0.0.1:8897 Jo, ich hab das Board immer offen an der Arbeit
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
27.01.2015, 10:22 | #8 |
| Proxy-Fehlermeldung 127.0.0.1:8897 Wenn du mir sagst wo die Logs von MBAM und Avast gespeichert werden Fixlog.txt Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-01-2015 01 Ran by User at 2015-01-27 10:15:05 Run:2 Running from C:\Users\User\Desktop Loaded Profiles: User (Available profiles: User) Boot Mode: Normal ============================================== Content of fixlist: ***************** ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:8897;https=127.0.0.1:8897 ProxyEnable: [S-1-5-21-982829961-422532093-1718007052-1000] => Internet Explorer proxy is enabled. ProxyServer: [S-1-5-21-982829961-422532093-1718007052-1000] => http=127.0.0.1:8897;https=127.0.0.1:8897 ***************** HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. HKU\S-1-5-21-982829961-422532093-1718007052-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\S-1-5-21-982829961-422532093-1718007052-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. ==== End of Fixlog 10:15:05 ==== Code:
ATTFilter <?xml version="1.0" encoding="UTF-16"?> -<mbam-log> -<header> <date>2015/01/26 10:23:26 +0100</date> <logfile>mbam-log-2015-01-26 (10-23-26).xml</logfile> <isadmin>yes</isadmin> </header> -<engine> <version>2.00.4.1028</version> <malware-database>v2015.01.26.04</malware-database> <rootkit-database>v2015.01.14.01</rootkit-database> <license>trial</license> <file-protection>enabled</file-protection> <web-protection>enabled</web-protection> <self-protection>disabled</self-protection> </engine> -<system> <osversion>Windows 7 Service Pack 1</osversion> <arch>x64</arch> <username>User</username> <filesys>NTFS</filesys> </system> -<summary> <type>threat</type> <result>completed</result> <objects>342010</objects> <time>685</time> <processes>0</processes> <modules>0</modules> <keys>1</keys> <values>0</values> <datas>0</datas> <folders>0</folders> <files>2</files> <sectors>0</sectors> </summary> -<options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>disabled</rootkits> <deeprootkit>disabled</deeprootkit> <heuristics>enabled</heuristics> <pup>enabled</pup> <pum>enabled</pum> </options> -<items> -<key> <path>HKU\S-1-5-21-982829961-422532093-1718007052-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic</path> <vendor>PUP.Optional.Softonic.A</vendor> <action>success</action> <hash>c13b10eb7019d2645823146c08fbe917</hash> </key> -<file> <path>C:\Windows\System32\xpt5l5ww.tsp</path> <vendor>Trojan.Mediyes</vendor> <action>delete-on-reboot</action> <hash>53a9d526f89180b62eed8193d1300cf4</hash> </file> -<file> <path>C:\Users\User\Downloads\SoftonicDownloader_fuer_avira-antivir.exe</path> <vendor>PUP.Optional.Softonic.A</vendor> <action>success</action> <hash>679525d68aff58de6ef4e3619d6443bd</hash> </file> </items> </mbam-log> Code:
ATTFilter <?xml version="1.0" encoding="UTF-16"?> -<mbam-log> -<header> <date>2015/01/26 15:42:29 +0100</date> <logfile>mbam-log-2015-01-26 (15-42-09).xml</logfile> <isadmin>yes</isadmin> </header> -<engine> <version>2.00.4.1028</version> <malware-database>v2015.01.26.06</malware-database> <rootkit-database>v2015.01.14.01</rootkit-database> <license>trial</license> <file-protection>enabled</file-protection> <web-protection>enabled</web-protection> <self-protection>disabled</self-protection> </engine> -<system> <osversion>Windows 7 Service Pack 1</osversion> <arch>x64</arch> <username>User</username> <filesys>NTFS</filesys> </system> -<summary> <type>custom</type> <result>completed</result> <objects>603974</objects> <time>6853</time> <processes>0</processes> <modules>0</modules> <keys>0</keys> <values>0</values> <datas>0</datas> <folders>0</folders> <files>0</files> <sectors>0</sectors> </summary> -<options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>enabled</rootkits> <deeprootkit>disabled</deeprootkit> <heuristics>enabled</heuristics> <pup>enabled</pup> <pum>enabled</pum> </options> <items> </items> </mbam-log> Code:
ATTFilter <?xml version="1.0" encoding="UTF-8"?> -<logs> <record subtype="Malware Protection" result="Starting" last_modified_tag="0b42d7a8-5bdc-4f02-96b5-f4c760645d13" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T09:59:56.300251+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malware Protection" result="Started" last_modified_tag="e92727e3-84ea-4c12-afd8-017f2236ec73" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T09:59:56.300251+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Starting" last_modified_tag="4ffcaf1a-2cd1-4fc0-9245-a008416c0708" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T09:59:56.331451+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Started" last_modified_tag="e6cb1f1e-1a19-447e-a1fd-c503f14d94a6" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T09:59:56.877452+01:00" LoggingEventType="2" severity="debug"/> <record last_modified_tag="0015d4dc-dff0-4535-b5bc-6530deedfd71" systemname="USER-PC" username="SYSTEM" type="Update" source="Manual" datetime="2015-01-26T09:59:58.078654+01:00" LoggingEventType="1" severity="debug" toVersion="2015.1.14.1" name="Rootkit Database" fromVersion="2014.11.18.1"/> <record last_modified_tag="46329515-b277-47a1-ae0f-abda4ef71c40" systemname="USER-PC" username="SYSTEM" type="Update" source="Manual" datetime="2015-01-26T09:59:58.094254+01:00" LoggingEventType="1" severity="debug" toVersion="2014.12.6.1" name="Remediation Database" fromVersion="2013.10.16.1"/> <record last_modified_tag="89e71558-22e5-4433-8674-5b5a754eb6a4" systemname="USER-PC" username="SYSTEM" type="Update" source="Manual" datetime="2015-01-26T10:00:11.338677+01:00" LoggingEventType="1" severity="debug" toVersion="2015.1.26.4" name="Malware Database" fromVersion="2014.11.20.6"/> <record subtype="Refresh" result="Starting" last_modified_tag="b78e1a13-5f4e-4602-af1b-57ef6c286230" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T10:00:11.401077+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Stopping" last_modified_tag="0372ae13-8614-459f-996d-ccc99cf0cb7c" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T10:00:11.401077+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Stopped" last_modified_tag="f7db1926-627d-4f31-a81d-c2a223863502" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T10:00:11.432277+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Refresh" result="Success" last_modified_tag="ef6b03e6-08cf-475a-982b-9c408fcee02e" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T10:00:16.658287+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Starting" last_modified_tag="62c2e894-dd68-4a95-aab4-84162dd9d184" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T10:00:16.673887+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Started" last_modified_tag="506c064e-b5f6-467b-8d42-eb84f24a811b" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T10:00:16.876687+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malware Protection" last_modified_tag="6ddd4e91-007e-4d87-a078-20b71a9a2526" systemname="USER-PC" username="SYSTEM" type="Detection" source="Protection" datetime="2015-01-26T10:16:32.601803+01:00" LoggingEventType="0" severity="debug" malwaretype="File" hash="5aa208f3068344f25fbc68ac37ca02fe" filename="C:\Windows\System32\xpt5l5ww.tsp" error="5" action="Quarantine Failed" vendor="Trojan.Mediyes" message="Zugriff verweigert "/> <record subtype="Malware Protection" last_modified_tag="af078b10-e5b2-45f9-ac76-ad730b19307a" systemname="USER-PC" username="SYSTEM" type="Detection" source="Protection" datetime="2015-01-26T10:17:02.932477+01:00" LoggingEventType="0" severity="debug" malwaretype="File" hash="5aa208f3068344f25fbc68ac37ca02fe" filename="C:\Windows\System32\xpt5l5ww.tsp" error="5" action="Quarantine Failed" vendor="Trojan.Mediyes" message="Zugriff verweigert "/> <record subtype="Malware Protection" last_modified_tag="0f76c231-d33d-46e4-9ea5-1d387430ed89" systemname="USER-PC" username="SYSTEM" type="Detection" source="Protection" datetime="2015-01-26T10:17:08.125739+01:00" LoggingEventType="0" severity="debug" malwaretype="File" hash="5aa208f3068344f25fbc68ac37ca02fe" filename="C:\Windows\System32\xpt5l5ww.tsp" error="5" action="Quarantine Failed" vendor="Trojan.Mediyes" message="Zugriff verweigert "/> <record subtype="Malware Protection" last_modified_tag="abc2ad6b-dc43-49ac-b741-d4e2001178b6" systemname="USER-PC" username="SYSTEM" type="Detection" source="Protection" datetime="2015-01-26T10:21:55.637831+01:00" LoggingEventType="0" severity="debug" malwaretype="File" hash="5aa208f3068344f25fbc68ac37ca02fe" filename="C:\Windows\System32\xpt5l5ww.tsp" error="5" action="Quarantine Failed" vendor="Trojan.Mediyes" message="Zugriff verweigert "/> <record last_modified_tag="03aadb2a-dba1-440e-95de-a55543eba1d3" systemname="USER-PC" username="SYSTEM" type="Scan" source="Manual" datetime="2015-01-26T10:35:03.671695+01:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="2" malwaredetections="1" duration="685" starttime="2015-01-26T10:23:26+01:00" scantype="threat"/> <record subtype="Malware Protection" result="Starting" last_modified_tag="f7dc70d6-5d09-4213-a3d8-5f6f68c9794c" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T10:36:22.854074+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malware Protection" result="Started" last_modified_tag="89fa63b0-fc9d-406f-8f33-86a329c6b974" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T10:36:22.885274+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Starting" last_modified_tag="49a49923-2f0e-40e0-b287-83a86c4d4021" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T10:36:22.900874+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Started" last_modified_tag="7ef12f2a-5ac2-4c9e-9a31-5b93de6d5c1b" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T10:38:51.995951+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malware Protection" result="Starting" last_modified_tag="c5610f6d-362e-4029-ad75-ce7f8e5eec67" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T12:59:43.480660+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malware Protection" result="Started" last_modified_tag="d412a2b1-3936-4241-bbba-7f6835528a73" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T12:59:43.530660+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Starting" last_modified_tag="e8685f4e-4126-4467-b755-c8ab3016ff57" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T12:59:43.570660+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Started" last_modified_tag="851c7b91-86cb-4624-8e2f-780b460de606" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T13:00:28.617139+01:00" LoggingEventType="2" severity="debug"/> <record last_modified_tag="72ee5ae4-7181-4cfd-93f0-841359c20097" systemname="USER-PC" username="SYSTEM" type="Update" source="Scheduler" datetime="2015-01-26T13:29:03.808951+01:00" LoggingEventType="1" severity="debug" toVersion="2015.1.26.5" name="Malware Database" fromVersion="2015.1.26.4"/> <record subtype="Refresh" result="Starting" last_modified_tag="2cdf0aed-64e4-4551-87ac-5b088115d37e" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T13:29:03.886951+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Stopping" last_modified_tag="b6c5a1f2-f611-4c50-83c2-16733552f344" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T13:29:03.902551+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Stopped" last_modified_tag="4e212f03-9267-4871-b7ff-a5c718029b0e" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T13:29:03.964952+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Refresh" result="Success" last_modified_tag="bcec41e1-70ae-496b-ad00-0929ee9f730b" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T13:29:10.267363+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Starting" last_modified_tag="14fe80c6-ef2b-4e92-81e9-e8b882afbf37" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T13:29:10.298563+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Started" last_modified_tag="3eca0a92-6494-44f2-87cf-ee8e55c43eea" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T13:29:10.969364+01:00" LoggingEventType="2" severity="debug"/> <record last_modified_tag="225b87f5-8203-4070-b832-aadb4c4cbf7a" systemname="USER-PC" username="SYSTEM" type="Update" source="Scheduler" datetime="2015-01-26T15:27:00.963026+01:00" LoggingEventType="1" severity="debug" toVersion="2015.1.26.6" name="Malware Database" fromVersion="2015.1.26.5"/> <record subtype="Refresh" result="Starting" last_modified_tag="40ca3e5a-f88b-44b8-ad19-93aa4af408a5" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T15:27:01.025426+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Stopping" last_modified_tag="ca9b7042-1dee-46fd-9629-e876f1bfd320" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T15:27:01.041026+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Stopped" last_modified_tag="b9065518-2573-452a-aa5c-e1d22c372e59" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T15:27:01.087826+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Refresh" result="Success" last_modified_tag="54380e96-8a2f-4bcb-92ff-f6b02b6a3a61" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T15:27:27.030672+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Starting" last_modified_tag="17b3351e-a7b1-4837-b9cf-0e1c0a3f5004" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T15:27:27.061872+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Started" last_modified_tag="485cff2b-4732-4202-a3f1-b0d4d91c18d4" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-26T15:27:31.570280+01:00" LoggingEventType="2" severity="debug"/> <record last_modified_tag="f4df2214-9472-40f2-9503-65cb7cac073d" systemname="USER-PC" username="SYSTEM" type="Scan" source="Manual" datetime="2015-01-26T17:36:43.774600+01:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="0" malwaredetections="0" duration="6853" starttime="2015-01-26T15:42:29+01:00" scantype="custom"/> </logs> MBAM Log 4 Code:
ATTFilter <?xml version="1.0" encoding="UTF-8"?> -<logs> <record subtype="Malware Protection" result="Starting" last_modified_tag="3dd5daaa-ad54-4b1d-a242-288f13061a40" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-27T09:05:07.274647+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malware Protection" result="Started" last_modified_tag="84919c16-7cdf-4d22-aefc-6ba5f6420011" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-27T09:05:07.274647+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Starting" last_modified_tag="0f11f66a-a03b-4398-b089-41ec8215b6c9" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-27T09:05:07.305847+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Started" last_modified_tag="3496c1ce-a014-4c68-bfb2-01dad9a048a9" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-27T09:06:50.088026+01:00" LoggingEventType="2" severity="debug"/> <record last_modified_tag="d4863eef-a261-423f-bd6c-6ce872b7c9a3" systemname="USER-PC" username="SYSTEM" type="Update" source="Scheduler" datetime="2015-01-27T09:29:02.559678+01:00" LoggingEventType="1" severity="debug" toVersion="2015.1.27.5" name="Malware Database" fromVersion="2015.1.26.6"/> <record subtype="Refresh" result="Starting" last_modified_tag="972a40ee-cf36-42d7-a53f-681cd2f027df" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-27T09:29:02.653278+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Stopping" last_modified_tag="2e524ef1-7979-4dde-872e-8c2a5883a579" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-27T09:29:02.668878+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Stopped" last_modified_tag="58bc2b40-c7d4-4be3-9470-90505614d1cd" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-27T09:29:02.700078+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Refresh" result="Success" last_modified_tag="5ff6d3db-bbc6-4bdd-84bf-ef2a4f1551b7" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-27T09:29:08.456488+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Starting" last_modified_tag="1239c337-4f29-471b-a12d-5b94665493c1" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-27T09:29:08.487688+01:00" LoggingEventType="2" severity="debug"/> <record subtype="Malicious Website Protection" result="Started" last_modified_tag="05a0a8fa-d6ea-4857-becc-1ce8b43a9196" systemname="USER-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2015-01-27T09:29:08.721689+01:00" LoggingEventType="2" severity="debug"/> </logs> |
27.01.2015, 10:32 | #9 |
/// TB-Ausbilder | Proxy-Fehlermeldung 127.0.0.1:8897 Idealerweise die Logs, aus denen eine aktuelle Löschung hervorgeht ;-) Und wie gesagt, ein neues FRST Log nach Neustart, bitte.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
27.01.2015, 10:46 | #10 |
| Proxy-Fehlermeldung 127.0.0.1:8897 Sorry mein Fehler. Hier die neue FRST Log-Datei: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01 Ran by User (administrator) on USER-PC on 27-01-2015 10:37:14 Running from C:\Users\User\Desktop Loaded Profiles: User (Available profiles: User) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (WiseCleaner.com) C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Huawei Technologies Co., Ltd.) C:\Users\User\AppData\Roaming\tele.ring Verbindungsmanager\ouc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard) HKLM-x32\...\Run: [DataCardMonitor] => C:\Program Files (x86)\tele.ring Verbindungsmanager\DataCardMonitor.exe [253952 2013-07-03] (Huawei Technologies Co., Ltd.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Run: [HW_OPENEYE_OUC_tele.ring Verbindungsmanager] => C:\Program Files (x86)\tele.ring Verbindungsmanager\UpdateDog\ouc.exe [110592 2009-12-31] (Huawei Technologies Co., Ltd.) HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: D - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: E - E:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {29de0f77-227c-11e2-8036-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {29de0f86-227c-11e2-8036-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {2bf70504-e3b9-11e2-8d2e-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {2bf70521-e3b9-11e2-8d2e-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {34c73ff9-2c16-11e2-9a50-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {356f63b6-4016-11e1-b766-b1570f61f5d9} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {356f63c7-4016-11e1-b766-b1570f61f5d9} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {5f6fac67-3f6e-11e1-a137-85ae9d686db3} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {5f6fac7e-3f6e-11e1-a137-85ae9d686db3} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {6e38b045-773e-11e1-9b43-e38defa8a60e} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {71060446-88c3-11e2-bd69-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {b3d5e5f9-2c6b-11e1-bc7d-806e6f6e6963} - F:\Setup.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {b56a49e9-826d-11e2-a311-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {b56a49f7-826d-11e2-a311-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {c661975b-e330-11e2-9294-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {c6619775-e330-11e2-9294-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {eac35ae9-3de2-11e1-a302-90004e63fc55} - D:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {eac35af7-3de2-11e1-a302-90004e63fc55} - D:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {f660393c-40de-11e1-af44-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {f83e50fe-e95d-11e2-829c-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {facf2493-2277-11e2-bb88-90004e63fc55} - D:\Data\setup.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {facf2499-2277-11e2-bb88-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {fb2a7ec3-3411-11e4-a467-90004e63fc55} - D:\AutoRun.exe Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:8897;https=127.0.0.1:8897 HKU\S-1-5-21-982829961-422532093-1718007052-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.at/?gws_rd=ssl HKU\S-1-5-21-982829961-422532093-1718007052-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCON/1 SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {E40F8372-A296-4395-92CB-F634CAC151B8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {E40F8372-A296-4395-92CB-F634CAC151B8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> {149397D9-74D9-4EB6-B8CC-375AA2B5BD56} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10397&src=kw&q={searchTerms}&locale=de_AT&apn_ptnrs=^ABV&apn_dtid=^YYYYYY^YY^AT&apn_uid=5df9fad8-523b-49fe-b465-42f49a565823&apn_sauid=E877B625-FE41-4FF5-91DB-5C4FF038390C SearchScopes: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> {E40F8372-A296-4395-92CB-F634CAC151B8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) BHO-x32: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52272 2010-08-02] (EasyBits Software Corp.) Winsock: Catalog5 07 C:\Windows\system32\tnnslu80z.dll File Not found () Tcpip\Parameters: [DhcpNameServer] 10.64.1.224 10.64.1.225 FireFox: ======== FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\gnj2wp5w.default FF Homepage: https://www.google.at FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\2\NP_wtapp.dll () FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-03-21] FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-01-26] FF HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-26] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-26] (AVAST Software) R2 DailytoolsUpdateService; C:\Windows\SysWOW64\update1.dll [352256 2014-08-05] (Dailytools GmbH) [File not signed] R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129584 2009-02-22] (EasyBits Sofware AS) [File not signed] S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [254016 2014-10-10] (WildTangent) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () S4 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-10-16] (Hewlett-Packard Company) [File not signed] R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [File not signed] S4 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-06] () S2 Search; C:\Program Files (x86)\Search\WebSearch.exe [435696 2014-11-09] () R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580648 2012-07-17] (WiseCleaner.com) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-26] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [87912 2015-01-26] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-26] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-26] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-26] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-26] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-26] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-26] () R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) [File not signed] R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-27] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation) S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-23] (Realtek Semiconductor Corp.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) [File not signed] S3 cpuz135; \??\C:\Users\User\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X] S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X] S3 zte_ecm_enum_filter; system32\DRIVERS\zte_ecm_enum_filter.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 09:24 - 2015-01-27 09:24 - 00030904 _____ () C:\Users\User\Desktop\Addition.txt 2015-01-27 09:23 - 2015-01-27 10:37 - 00018077 _____ () C:\Users\User\Desktop\FRST.txt 2015-01-27 09:23 - 2015-01-27 10:37 - 00000000 ____D () C:\FRST 2015-01-27 09:23 - 2015-01-27 09:23 - 02129920 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe 2015-01-26 10:48 - 2015-01-26 10:48 - 00000000 ____D () C:\Users\User\AppData\Roaming\AVAST Software 2015-01-26 10:47 - 2015-01-26 10:47 - 00001964 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-01-26 10:47 - 2015-01-26 10:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2015-01-26 10:46 - 2015-01-27 10:35 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2015-01-26 10:46 - 2015-01-26 10:47 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2015-01-26 10:46 - 2015-01-26 10:47 - 00087912 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2015-01-26 10:46 - 2015-01-26 10:46 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2015-01-26 10:46 - 2015-01-26 10:46 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2015-01-26 10:45 - 2015-01-26 10:45 - 00000000 ____D () C:\Program Files\AVAST Software 2015-01-26 10:44 - 2015-01-26 10:45 - 00000000 ____D () C:\ProgramData\AVAST Software 2015-01-26 10:40 - 2015-01-26 10:43 - 132469808 _____ (AVAST Software) C:\Users\User\Downloads\avast_free_antivirus_setup.exe 2015-01-26 09:59 - 2015-01-27 10:37 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-26 09:58 - 2015-01-26 09:58 - 00001062 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-26 09:58 - 2015-01-26 09:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-26 09:58 - 2015-01-26 09:58 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-26 09:58 - 2015-01-26 09:58 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-01-26 09:58 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-26 09:58 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-26 09:58 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-26 09:56 - 2015-01-26 09:57 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.4.1028.exe 2015-01-24 14:18 - 2015-01-24 14:18 - 00000000 ____D () C:\Users\User\Documents\Neuer Ordner (3) 2015-01-23 06:17 - 2015-01-27 10:34 - 00015144 _____ () C:\Windows\PFRO.log 2015-01-23 06:17 - 2015-01-27 10:34 - 00001469 _____ () C:\Windows\setupact.log 2015-01-23 06:17 - 2015-01-23 06:17 - 00000000 _____ () C:\Windows\setuperr.log 2015-01-22 18:19 - 2015-01-27 10:33 - 00290475 _____ () C:\Windows\WindowsUpdate.log 2015-01-19 15:14 - 2015-01-19 15:14 - 00001003 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2015-01-19 15:14 - 2015-01-19 15:14 - 00000991 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk 2015-01-19 15:14 - 2015-01-19 15:14 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2015-01-19 15:13 - 2015-01-19 15:13 - 07718224 _____ (TeamViewer GmbH) C:\Users\User\Downloads\TeamViewer_Setup_de-ckc.exe 2015-01-14 19:09 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 19:09 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 19:09 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-14 19:09 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-01-14 19:09 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-01-14 19:09 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-01-14 19:09 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-01-14 19:09 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-01-14 19:09 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-01-14 19:09 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-14 19:09 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 19:09 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-14 19:09 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2015-01-13 16:35 - 2015-01-13 16:35 - 00000000 ____H () C:\Users\User\AppData\Local\BIT53EA.tmp 2015-01-13 16:35 - 2015-01-13 16:35 - 00000000 _____ () C:\Users\User\AppData\Local\{4B22D22B-3BA4-40E7-B6BC-98DD75627F4A} 2015-01-01 17:54 - 2015-01-01 17:54 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieBrowserModeList ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 10:36 - 2013-03-01 11:54 - 00000000 ____D () C:\Users\User\AppData\Roaming\Wise Care 365 2015-01-27 10:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing 2015-01-27 10:34 - 2013-03-01 12:20 - 00000420 _____ () C:\Windows\Tasks\Wise Care 365.job 2015-01-27 10:34 - 2012-11-08 10:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-27 10:34 - 2012-11-08 10:09 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-27 10:34 - 2012-03-05 10:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-27 10:34 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-27 10:34 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-27 10:27 - 2012-11-08 10:09 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-27 10:03 - 2010-01-20 11:41 - 11364132 _____ () C:\Windows\system32\perfh007.dat 2015-01-27 10:03 - 2010-01-20 11:41 - 03594032 _____ () C:\Windows\system32\perfc007.dat 2015-01-27 10:03 - 2009-07-14 06:13 - 00006268 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-27 09:23 - 2009-07-14 05:45 - 00023248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-27 09:23 - 2009-07-14 05:45 - 00023248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-27 09:12 - 2011-12-23 08:48 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{DB32AAC0-AE95-47E6-8D2E-C7CA58C9B8C0} 2015-01-26 10:50 - 2012-11-08 09:30 - 00001912 _____ () C:\Windows\epplauncher.mif 2015-01-22 13:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2015-01-19 17:47 - 2009-07-14 05:45 - 00374152 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-19 15:19 - 2011-12-22 08:16 - 00091216 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT 2015-01-14 20:15 - 2013-07-12 17:57 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-14 20:12 - 2011-12-23 10:36 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-01-08 09:55 - 2011-12-23 08:50 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Files in the root of some directories ======= 2011-12-22 08:15 - 2011-12-22 08:15 - 0000000 _____ () C:\Users\User\AppData\Local\AtStart.txt 2015-01-13 16:35 - 2015-01-13 16:35 - 0000000 ____H () C:\Users\User\AppData\Local\BIT53EA.tmp 2013-04-07 17:14 - 2013-05-24 17:48 - 0005632 _____ () C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2011-12-22 08:15 - 2011-12-22 08:15 - 0000000 _____ () C:\Users\User\AppData\Local\DSwitch.txt 2011-12-22 08:15 - 2011-12-22 08:15 - 0000000 _____ () C:\Users\User\AppData\Local\QSwitch.txt 2015-01-13 16:35 - 2015-01-13 16:35 - 0000000 _____ () C:\Users\User\AppData\Local\{4B22D22B-3BA4-40E7-B6BC-98DD75627F4A} 2012-12-30 10:55 - 2015-01-27 10:35 - 0000509 _____ () C:\ProgramData\HPWALog.txt 2012-03-21 15:20 - 2012-03-21 15:40 - 0003039 _____ () C:\ProgramData\hpzinstall.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log 2010-01-20 04:59 - 2010-01-20 04:59 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log 2010-01-20 04:55 - 2010-01-20 04:56 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2010-08-02 13:14 - 2010-08-02 13:14 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log 2010-01-20 04:54 - 2010-01-20 04:55 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log 2010-01-20 04:56 - 2010-01-20 04:58 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-26 13:28 ==================== End Of Log ============================ --- --- --- Das habe ich noch in einer Log Datei von Avast gefunden: Code:
ATTFilter 26.01.2015 10:47:17 Schreibzugriff auf die Datei \Device\HarddiskVolume2\ProgramData\AVAST Software\Avast\lscache.dat verweigert. [PID 4] 26.01.2015 12:59:12 Schreibzugriff auf die Datei \Device\HarddiskVolume2\ProgramData\AVAST Software\Avast\lscache.dat verweigert. [PID 4] 26.01.2015 13:32:28 Schreibzugriff auf die Datei \Device\HarddiskVolume2\ProgramData\AVAST Software\Avast verweigert. [C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE] 26.01.2015 13:32:28 Schreibzugriff auf die Datei \Device\HarddiskVolume2\ProgramData\AVAST Software\Avast\log verweigert. [C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE] 27.01.2015 09:04:34 Schreibzugriff auf die Datei \Device\HarddiskVolume2\ProgramData\AVAST Software\Avast\lscache.dat verweigert. [PID 4] |
27.01.2015, 10:50 | #11 |
/// TB-Ausbilder | Proxy-Fehlermeldung 127.0.0.1:8897Hinweis: Registry Cleaner Ich sehe, dass du sogenannte Registry Cleaner installiert hast. In deinem Fall CCleaner, Wise Care 365. Wir raten von der Verwendung jeglicher Art von Registry Cleaner ab. Der Grund ist ganz einfach: Die Registry ist das Hirn des Systems. Funktioniert das Hirn nicht, funktioniert der Rest nicht mehr wirklich. Man sollte nicht unnötigerweise an der Registry rumbasteln. Schon ein kleiner Fehler kann gravierende Folgen haben und auch Programme machen manchmal Fehler. Zerstörst du die Registry, zerstörst du Windows. Zudem ist der Nutzen zur Performancesteigerung umstritten und meist kaum im wahrnehmbaren Bereich. Ich würde dir empfehlen, Registry Cleaner nicht weiterhin zu verwenden und über Start --> Systemsteuerung --> Software (bei Windows XP)zu deinstallieren. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter CloseProcesses: Winsock: Catalog5 07 C:\Windows\system32\tnnslu80z.dll File Not found () ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:8897;https=127.0.0.1:8897 emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Und bitte neue FRST Logs. Haken setzen bei addition.txt dann auf Scan klicken
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
27.01.2015, 11:46 | #12 |
| Proxy-Fehlermeldung 127.0.0.1:8897 So hier erstmal die Fixlog.txt Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-01-2015 01 Ran by User at 2015-01-27 11:09:51 Run:3 Running from C:\Users\User\Desktop Loaded Profiles: User (Available profiles: User) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: Winsock: Catalog5 07 C:\Windows\system32\tnnslu80z.dll File Not found () ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:8897;https=127.0.0.1:8897 emptytemp: ***************** Processes closed successfully. Winsock: Catalog entry 000000000007 => Deleted successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. EmptyTemp: => Removed 450.9 MB temporary data. The system needed a reboot. ==== End of Fixlog 11:10:23 ==== Hier von ADwcleaner: Code:
ATTFilter # AdwCleaner v4.109 - Bericht erstellt am 27/01/2015 um 11:22:16 # Aktualisiert 24/01/2015 von Xplode # Database : 2015-01-26.1 [Live] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : User - USER-PC # Gestartet von : C:\Users\User\Desktop\adwcleaner_4.109.exe # Option : Löschen ***** [ Dienste ] ***** Dienst Gelöscht : DailytoolsUpdateService [#] Dienst Gelöscht : Search ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Ask Ordner Gelöscht : C:\Program Files (x86)\Search Ordner Gelöscht : C:\Users\User\AppData\Roaming\iWin Datei Gelöscht : C:\Windows\SysWOW64\update1.dll ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\microsoft\windows nt\currentversion\svchost [DailytoolsInstallerService] Wert Gelöscht : HKLM\SOFTWARE\microsoft\windows nt\currentversion\svchost [DailytoolsUpdateService] Wert Gelöscht : HKLM\SOFTWARE\microsoft\windows nt\currentversion\svchost [Update-Service-Installer-Service] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{149397D9-74D9-4EB6-B8CC-375AA2B5BD56} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Joosoft.com Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>;www.joosoft.com ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17496 -\\ Mozilla Firefox v35.0.1 (x86 de) [h3u3xxu9.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.defaultengine", "Ask.com"); [h3u3xxu9.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.defaultenginename", "Ask.com"); [h3u3xxu9.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.order.1", "Ask.com"); [h3u3xxu9.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.selectedEngine", "Ask.com"); [h3u3xxu9.default\prefs.js] - Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", ""); [h3u3xxu9.default\prefs.js] - Zeile gelöscht : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ORJ&o=100000027&locale=de_US&apn_uid=09120C01-59A6-4D66-B001-5C42489B063F&apn_ptnrs=U3&apn_sauid=DA6203A7-3500-488F-8700[...] ************************* AdwCleaner[R0].txt - [2607 octets] - [27/01/2015 11:19:33] AdwCleaner[S0].txt - [2460 octets] - [27/01/2015 11:22:16] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2520 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.1 (12.28.2014:1) OS: Windows 7 Home Premium x64 Ran by User on 27.01.2015 at 11:26:56,52 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\gnj2wp5w.default\minidumps [60 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 27.01.2015 at 11:31:04,47 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01 Ran by User (administrator) on USER-PC on 27-01-2015 11:32:08 Running from C:\Users\User\Desktop Loaded Profiles: User (Available profiles: User) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Huawei Technologies Co., Ltd.) C:\Users\User\AppData\Roaming\tele.ring Verbindungsmanager\ouc.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard) HKLM-x32\...\Run: [DataCardMonitor] => C:\Program Files (x86)\tele.ring Verbindungsmanager\DataCardMonitor.exe [253952 2013-07-03] (Huawei Technologies Co., Ltd.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Run: [HW_OPENEYE_OUC_tele.ring Verbindungsmanager] => C:\Program Files (x86)\tele.ring Verbindungsmanager\UpdateDog\ouc.exe [110592 2009-12-31] (Huawei Technologies Co., Ltd.) HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: D - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: E - E:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {29de0f77-227c-11e2-8036-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {29de0f86-227c-11e2-8036-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {2bf70504-e3b9-11e2-8d2e-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {2bf70521-e3b9-11e2-8d2e-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {34c73ff9-2c16-11e2-9a50-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {356f63b6-4016-11e1-b766-b1570f61f5d9} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {356f63c7-4016-11e1-b766-b1570f61f5d9} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {5f6fac67-3f6e-11e1-a137-85ae9d686db3} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {5f6fac7e-3f6e-11e1-a137-85ae9d686db3} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {6e38b045-773e-11e1-9b43-e38defa8a60e} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {71060446-88c3-11e2-bd69-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {b3d5e5f9-2c6b-11e1-bc7d-806e6f6e6963} - F:\Setup.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {b56a49e9-826d-11e2-a311-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {b56a49f7-826d-11e2-a311-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {c661975b-e330-11e2-9294-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {c6619775-e330-11e2-9294-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {eac35ae9-3de2-11e1-a302-90004e63fc55} - D:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {eac35af7-3de2-11e1-a302-90004e63fc55} - D:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {f660393c-40de-11e1-af44-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {f83e50fe-e95d-11e2-829c-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {facf2493-2277-11e2-bb88-90004e63fc55} - D:\Data\setup.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {facf2499-2277-11e2-bb88-90004e63fc55} - D:\AutoRun.exe HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\MountPoints2: {fb2a7ec3-3411-11e4-a467-90004e63fc55} - D:\AutoRun.exe Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:8897;https=127.0.0.1:8897 HKU\S-1-5-21-982829961-422532093-1718007052-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.at/?gws_rd=ssl HKU\S-1-5-21-982829961-422532093-1718007052-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCON/1 SearchScopes: HKLM -> {E40F8372-A296-4395-92CB-F634CAC151B8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> {E40F8372-A296-4395-92CB-F634CAC151B8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> {E40F8372-A296-4395-92CB-F634CAC151B8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKU\S-1-5-21-982829961-422532093-1718007052-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52272 2010-08-02] (EasyBits Software Corp.) Tcpip\Parameters: [DhcpNameServer] 10.64.1.224 10.64.1.225 FireFox: ======== FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\gnj2wp5w.default FF Homepage: https://www.google.at FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\2\NP_wtapp.dll () FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-03-21] FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-01-26] FF HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-26] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-26] (AVAST Software) R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129584 2009-02-22] (EasyBits Sofware AS) [File not signed] S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [254016 2014-10-10] (WildTangent) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () S4 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-10-16] (Hewlett-Packard Company) [File not signed] S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [File not signed] S4 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-06] () R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-26] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [87912 2015-01-26] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-26] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-26] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-26] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-26] (AVAST Software) S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-26] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-26] () R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) [File not signed] S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation) S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-23] (Realtek Semiconductor Corp.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) [File not signed] S3 cpuz135; \??\C:\Users\User\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X] S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X] S3 zte_ecm_enum_filter; system32\DRIVERS\zte_ecm_enum_filter.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 11:32 - 2015-01-27 11:32 - 00016619 _____ () C:\Users\User\Desktop\FRST.txt 2015-01-27 11:31 - 2015-01-27 11:31 - 00001937 _____ () C:\Users\User\Desktop\JRT.txt 2015-01-27 11:26 - 2015-01-27 11:26 - 00000000 ____D () C:\Windows\ERUNT 2015-01-27 11:19 - 2015-01-27 11:22 - 00000000 ____D () C:\AdwCleaner 2015-01-27 11:18 - 2015-01-27 11:19 - 01707939 _____ (Thisisu) C:\Users\User\Desktop\JRT641.exe 2015-01-27 11:17 - 2015-01-27 11:17 - 02194432 _____ () C:\Users\User\Desktop\adwcleaner_4.109.exe 2015-01-27 09:23 - 2015-01-27 11:32 - 00000000 ____D () C:\FRST 2015-01-27 09:23 - 2015-01-27 09:23 - 02129920 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe 2015-01-26 10:48 - 2015-01-26 10:48 - 00000000 ____D () C:\Users\User\AppData\Roaming\AVAST Software 2015-01-26 10:47 - 2015-01-26 10:47 - 00001964 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-01-26 10:47 - 2015-01-26 10:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2015-01-26 10:46 - 2015-01-27 11:25 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2015-01-26 10:46 - 2015-01-26 10:47 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2015-01-26 10:46 - 2015-01-26 10:47 - 00087912 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2015-01-26 10:46 - 2015-01-26 10:46 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2015-01-26 10:46 - 2015-01-26 10:46 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2015-01-26 10:46 - 2015-01-26 10:46 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2015-01-26 10:45 - 2015-01-26 10:45 - 00000000 ____D () C:\Program Files\AVAST Software 2015-01-26 10:44 - 2015-01-26 10:45 - 00000000 ____D () C:\ProgramData\AVAST Software 2015-01-26 10:40 - 2015-01-26 10:43 - 132469808 _____ (AVAST Software) C:\Users\User\Downloads\avast_free_antivirus_setup.exe 2015-01-26 09:59 - 2015-01-27 11:24 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-26 09:58 - 2015-01-26 09:58 - 00001062 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-26 09:58 - 2015-01-26 09:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-26 09:58 - 2015-01-26 09:58 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-26 09:58 - 2015-01-26 09:58 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-01-26 09:58 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-26 09:58 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-26 09:58 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-26 09:56 - 2015-01-26 09:57 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.4.1028.exe 2015-01-24 14:18 - 2015-01-24 14:18 - 00000000 ____D () C:\Users\User\Documents\Neuer Ordner (3) 2015-01-23 06:17 - 2015-01-27 11:23 - 00001581 _____ () C:\Windows\setupact.log 2015-01-23 06:17 - 2015-01-27 11:22 - 00016262 _____ () C:\Windows\PFRO.log 2015-01-23 06:17 - 2015-01-23 06:17 - 00000000 _____ () C:\Windows\setuperr.log 2015-01-22 18:19 - 2015-01-27 11:27 - 00319641 _____ () C:\Windows\WindowsUpdate.log 2015-01-19 15:14 - 2015-01-19 15:14 - 00001003 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2015-01-19 15:14 - 2015-01-19 15:14 - 00000991 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk 2015-01-19 15:14 - 2015-01-19 15:14 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2015-01-19 15:13 - 2015-01-19 15:13 - 07718224 _____ (TeamViewer GmbH) C:\Users\User\Downloads\TeamViewer_Setup_de-ckc.exe 2015-01-14 19:09 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 19:09 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 19:09 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-14 19:09 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-01-14 19:09 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-01-14 19:09 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-01-14 19:09 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-01-14 19:09 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-01-14 19:09 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-01-14 19:09 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-14 19:09 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 19:09 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-14 19:09 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2015-01-13 16:35 - 2015-01-13 16:35 - 00000000 ____H () C:\Users\User\AppData\Local\BIT53EA.tmp 2015-01-13 16:35 - 2015-01-13 16:35 - 00000000 _____ () C:\Users\User\AppData\Local\{4B22D22B-3BA4-40E7-B6BC-98DD75627F4A} 2015-01-01 17:54 - 2015-01-01 17:54 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieBrowserModeList ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 11:30 - 2010-01-20 11:41 - 11424020 _____ () C:\Windows\system32\perfh007.dat 2015-01-27 11:30 - 2010-01-20 11:41 - 03613696 _____ () C:\Windows\system32\perfc007.dat 2015-01-27 11:30 - 2009-07-14 06:13 - 00006268 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-27 11:30 - 2009-07-14 05:45 - 00023248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-27 11:30 - 2009-07-14 05:45 - 00023248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-27 11:27 - 2012-11-08 10:09 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-27 11:23 - 2013-03-01 12:20 - 00000420 _____ () C:\Windows\Tasks\Wise Care 365.job 2015-01-27 11:23 - 2012-11-08 10:09 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-27 11:23 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-27 11:12 - 2012-11-08 10:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-27 10:54 - 2012-03-05 10:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-27 10:40 - 2011-12-23 08:48 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{DB32AAC0-AE95-47E6-8D2E-C7CA58C9B8C0} 2015-01-27 10:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing 2015-01-27 10:34 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-26 10:50 - 2012-11-08 09:30 - 00001912 _____ () C:\Windows\epplauncher.mif 2015-01-22 13:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2015-01-19 17:47 - 2009-07-14 05:45 - 00374152 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-19 15:19 - 2011-12-22 08:16 - 00091216 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT 2015-01-14 20:15 - 2013-07-12 17:57 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-14 20:12 - 2011-12-23 10:36 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-01-08 09:55 - 2011-12-23 08:50 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Files in the root of some directories ======= 2011-12-22 08:15 - 2011-12-22 08:15 - 0000000 _____ () C:\Users\User\AppData\Local\AtStart.txt 2015-01-13 16:35 - 2015-01-13 16:35 - 0000000 ____H () C:\Users\User\AppData\Local\BIT53EA.tmp 2013-04-07 17:14 - 2013-05-24 17:48 - 0005632 _____ () C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2011-12-22 08:15 - 2011-12-22 08:15 - 0000000 _____ () C:\Users\User\AppData\Local\DSwitch.txt 2011-12-22 08:15 - 2011-12-22 08:15 - 0000000 _____ () C:\Users\User\AppData\Local\QSwitch.txt 2015-01-13 16:35 - 2015-01-13 16:35 - 0000000 _____ () C:\Users\User\AppData\Local\{4B22D22B-3BA4-40E7-B6BC-98DD75627F4A} 2012-12-30 10:55 - 2015-01-27 11:23 - 0000509 _____ () C:\ProgramData\HPWALog.txt 2012-03-21 15:20 - 2012-03-21 15:40 - 0003039 _____ () C:\ProgramData\hpzinstall.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log 2010-01-20 04:59 - 2010-01-20 04:59 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log 2010-01-20 04:55 - 2010-01-20 04:56 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2010-08-02 13:14 - 2010-08-02 13:14 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log 2010-01-20 04:54 - 2010-01-20 04:55 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log 2010-01-20 04:56 - 2010-01-20 04:58 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log 2010-08-02 13:15 - 2010-08-02 13:15 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log Some content of TEMP: ==================== C:\Users\User\AppData\Local\Temp\Quarantine.exe C:\Users\User\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-26 13:28 ==================== End Of Log ============================ --- --- --- --- --- --- Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-01-2015 01 Ran by User at 2015-01-27 11:32:53 Running from C:\Users\User\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (Version: 7.2.4 - Hewlett-Packard) Hidden Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.) Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.32.18 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Reader 9.2 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.2.0 - Adobe Systems Incorporated) Adobe Shockwave Player (HKLM-x32\...\{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}) (Version: 11.5.1.601 - Adobe Systems, Inc.) ATI Catalyst Install Manager (HKLM\...\{C9083B9D-9092-FF22-DDCC-9776E69BE816}) (Version: 3.0.765.0 - ATI Technologies, Inc.) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software) Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation) Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.350.6 - Broadcom Corporation) BufferChm (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden C310 (x32 Version: 140.0.304.000 - Hewlett-Packard) Hidden ccc-core-static (x32 Version: 2010.0302.2233.40412 - Ihr Firmenname) Hidden Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.2216 - CyberLink Corp.) CyberLink MediaShow (HKLM-x32\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 4.1.3419 - CyberLink Corp.) CyberLink PowerDVD 8 (HKLM-x32\...\InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}) (Version: 8.0.1.1110 - CyberLink Corp.) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2201 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Destinations (x32 Version: 140.0.77.000 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard) Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden GPBaseService2 (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden HP Advisor (HKLM-x32\...\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.3.9512.3162 - Hewlett-Packard) HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.0.71 - WildTangent) HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP) HP Photosmart Prem C310 All-In-One Driver Software 14.0 Rel. 7 (HKLM\...\{4E484899-4F93-4086-88BA-56BDDF47A776}) (Version: 14.0 - HP) HP Quick Launch Buttons (HKLM-x32\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.9.1 - Hewlett-Packard) HP Setup (HKLM-x32\...\{17B4760F-334B-475D-829F-1A3E94A6A4E6}) (Version: 1.2.3560.3170 - Hewlett-Packard) HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP) HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP) HP Update (HKLM-x32\...\{74DC0593-6BC6-4001-AD5F-D810AFB68D86}) (Version: 5.002.002.002 - Hewlett-Packard) HP User Guides 0183 (HKLM-x32\...\{BC146E5F-A2B0-40DB-90E7-2833807E98DF}) (Version: 1.01.0001 - Hewlett-Packard) HP Wireless Assistant (HKLM-x32\...\{54CC7901-804D-4155-B353-21F0CC9112AB}) (Version: 3.50.9.1 - Hewlett-Packard) HPAppStudio (x32 Version: 140.0.95.000 - Hewlett-Packard) Hidden HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Java(TM) 6 Update 17 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416017FF}) (Version: 6.0.170 - Sun Microsystems, Inc.) Java(TM) 6 Update 22 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216022F0}) (Version: 6.0.220 - Oracle) Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2215 - CyberLink Corp.) LabelPrint (x32 Version: 2.5.2215 - CyberLink Corp.) Hidden LightScribe System Software (HKLM-x32\...\{10CCF16B-F1C9-4B24-9570-B4CCEE42392D}) (Version: 1.18.9.1 - LightScribe) Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: - EasyBits Software AS) Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-982829961-422532093-1718007052-1000\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation) Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Network64 (Version: 140.0.215.000 - Hewlett-Packard) Hidden OpenOffice.org 3.3 (HKLM-x32\...\{4286716B-1287-48E7-9078-3DC8248DBA96}) (Version: 3.3.9567 - OpenOffice.org) Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.3415 - CyberLink Corp.) Power2Go (x32 Version: 6.0.3415 - CyberLink Corp.) Hidden PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.3420 - CyberLink Corp.) PowerDirector (x32 Version: 7.0.3420 - CyberLink Corp.) Hidden PS_AIO_07_C310_SW_Min (x32 Version: 140.0.304.000 - Hewlett-Packard) Hidden PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden QLBCASL (x32 Version: 6.40.17.2 - Hewlett-Packard) Hidden QuickTransfer (x32 Version: 140.0.98.000 - Hewlett-Packard) Hidden Realtek Ethernet Controller Driver For Windows Vista and Later (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6010 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30105 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.2214 - CyberLink Corp.) Hidden Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP) SmartWebPrinting (x32 Version: 140.0.186.000 - Hewlett-Packard) Hidden SolutionCenter (x32 Version: 140.0.214.000 - Hewlett-Packard) Hidden Speccy (HKLM\...\Speccy) (Version: 1.14 - Piriform) Status (x32 Version: 140.0.256.000 - Hewlett-Packard) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36897 - TeamViewer) tele.ring Verbindungsmanager (HKLM-x32\...\tele.ring Verbindungsmanager) (Version: 11.301.05.12.123 - Huawei Technologies Co.,Ltd) Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden WebReg (x32 Version: 140.0.212.017 - Hewlett-Packard) Hidden WildTangent Games App für HP (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.11.2 - WildTangent) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows Live Sync (HKLM-x32\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-982829961-422532093-1718007052-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-982829961-422532093-1718007052-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-982829961-422532093-1718007052-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-982829961-422532093-1718007052-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-982829961-422532093-1718007052-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 07-12-2014 04:55:56 Windows Update 07-12-2014 19:00:11 Windows-Sicherung 10-12-2014 05:37:52 Windows Update 10-12-2014 06:01:04 Windows Update 10-12-2014 06:17:29 Windows Update 12-12-2014 19:02:24 Windows Update 15-12-2014 19:18:13 Windows-Sicherung 16-12-2014 19:50:17 Windows Update 18-12-2014 18:32:27 Windows Update 21-12-2014 19:24:15 Windows Update 22-12-2014 17:59:47 Windows-Sicherung 25-12-2014 17:12:36 Windows Update 29-12-2014 20:17:53 Windows-Sicherung 01-01-2015 08:19:57 Windows Update 05-01-2015 06:29:27 Windows Update 05-01-2015 18:36:33 Windows-Sicherung 11-01-2015 19:00:11 Windows-Sicherung 13-01-2015 05:27:26 Windows Update 14-01-2015 20:12:17 Windows Update 18-01-2015 16:48:54 Windows Update 18-01-2015 19:00:11 Windows-Sicherung 22-01-2015 05:52:14 Windows Update 25-01-2015 19:17:51 Windows Update 26-01-2015 10:00:47 Windows-Sicherung 26-01-2015 10:45:08 avast! antivirus system restore point ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {10AE75DB-1A8B-4725-9484-4F273FC4BF70} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-08] (Google Inc.) Task: {1CC9F1EE-8A58-4D17-9A5E-4C5E8FAF18F1} - \AutoKMS No Task File <==== ATTENTION Task: {2F8FFF31-7780-48A1-83C1-6C6ED5BE0AC2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-08] (Google Inc.) Task: {38D7D7B4-81CA-4204-862F-9E39D400F746} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_backup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe Task: {5363914C-6104-46F0-9DA6-DF6CFBD2BB4B} - System32\Tasks\{F6F8B99E-5DF4-4B82-8404-4DB9A0A3962D} => pcalua.exe -a "C:\Program Files (x86)\Avira\AntiVir Desktop\setup.exe" -c /REMOVE Task: {A529602A-BADE-42B2-96F3-834AEFE569EE} - System32\Tasks\Games\UpdateCheck_S-1-5-21-982829961-422532093-1718007052-1000 Task: {AA9E4DC8-66CA-4908-9D4F-A013715F94B4} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-01-26] (AVAST Software) Task: {B416E84D-7909-43DA-B267-1FD2BE8A2E45} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe Task: {BC89A92B-AEF4-4FF2-8D44-87D6CB9986C8} - System32\Tasks\Wise Care 365 => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe Task: {EC5AE52E-C11E-4BDE-99CE-5F545006F60B} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2009-10-07] () Task: {FF81F6AD-5596-4FB2-AAED-0AE5EFB3E69B} - System32\Tasks\{89A41138-11E3-4A9C-AFD3-23ECA89BCA36} => pcalua.exe -a C:\Users\User\Desktop\avira_free_antivirus_de1200861.exe -d C:\Users\User\Desktop Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Wise Care 365.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe ==================== Loaded Modules (whitelisted) ============= 2011-03-14 16:27 - 2011-03-14 16:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2015-01-27 10:36 - 2015-01-27 10:36 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15012700\algo.dll 2011-01-17 16:19 - 2011-12-23 10:10 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 2015-01-26 10:46 - 2015-01-26 10:46 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Users\User\Documents\Fw_ Frühling.eml:OECustomProperty AlternateDataStreams: C:\Users\User\Documents\Fw_ Kerze bitte nicht löschen!.eml:OECustomProperty AlternateDataStreams: C:\Users\User\Documents\Fw_Wunderbare Bilder.eml:OECustomProperty AlternateDataStreams: C:\Users\User\Documents\Kalender.eml:OECustomProperty AlternateDataStreams: C:\Users\User\Documents\Reservierung DI Weissenberger.eml:OECustomProperty AlternateDataStreams: C:\Users\User\Documents\Reservierung helga.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: AERTFilters => 2 MSCONFIG\Services: AMD External Events Utility => 2 MSCONFIG\Services: Com4QLBEx => 3 MSCONFIG\Services: GamesAppService => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: hpqwmiex => 3 MSCONFIG\Services: HWDeviceService64.exe => 2 MSCONFIG\Services: LightScribeService => 2 MSCONFIG\Services: LMS => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: RichVideo => 2 MSCONFIG\Services: UNS => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: Easybits Recovery => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: HPADVISOR => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW MSCONFIG\startupreg: HW_OPENEYE_OUC_tele.ring Verbindungsmanager => "C:\Program Files (x86)\tele.ring Verbindungsmanager\UpdateDog\ouc.exe" MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe MSCONFIG\startupreg: LightScribe Control Panel => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe MSCONFIG\startupreg: QlbCtrl.exe => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start MSCONFIG\startupreg: RTHDVCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s MSCONFIG\startupreg: RtkOSD => C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Java\jre6\bin\jusched.exe" MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe ========================= Accounts: ========================== Administrator (S-1-5-21-982829961-422532093-1718007052-500 - Administrator - Disabled) Gast (S-1-5-21-982829961-422532093-1718007052-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-982829961-422532093-1718007052-1002 - Limited - Enabled) User (S-1-5-21-982829961-422532093-1718007052-1000 - Administrator - Enabled) => C:\Users\User ==================== Faulty Device Manager Devices ============= Name: High Definition Audio-Controller Description: High Definition Audio-Controller Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: HDAudBus Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: ATI Mobility Radeon HD 5470 Description: ATI Mobility Radeon HD 5470 Class Guid: {4d36e968-e325-11ce-bfc1-08002be10318} Manufacturer: ATI Technologies Inc. Service: amdkmdap Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz Percentage of memory in use: 34% Total physical RAM: 3893.86 MB Available physical RAM: 2555.74 MB Total Pagefile: 7785.9 MB Available Pagefile: 6383.46 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.57 GB) (Free:407.11 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (MULTIBOOT) (Removable) (Total:7.19 GB) (Free:2.33 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: F2C7247F) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.6 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 7.2 GB) (Disk ID: 88B88326) Partition 1: (Active) - (Size=7.2 GB) - (Type=0C) ==================== End Of Log ============================ Wie du auf Arbeit |
27.01.2015, 11:46 | #13 |
/// TB-Ausbilder | Proxy-Fehlermeldung 127.0.0.1:8897 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter cmd: type %windir%\System32\Tasks\Games\UpdateCheck_S-1-5-21-982829961-422532093-1718007052-1000 Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
27.01.2015, 11:50 | #14 |
| Proxy-Fehlermeldung 127.0.0.1:8897 Hier noch schnell das Foxlog.txt Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-01-2015 01 Ran by User at 2015-01-27 11:49:13 Run:4 Running from C:\Users\User\Desktop Loaded Profiles: User (Available profiles: User) Boot Mode: Normal ============================================== Content of fixlist: ***************** cmd: type %windir%\System32\Tasks\Games\UpdateCheck_S-1-5-21-982829961-422532093-1718007052-1000 ***************** ========= type %windir%\System32\Tasks\Games\UpdateCheck_S-1-5-21-982829961-422532093-1718007052-1000 ========= <?xml version="1.0" encoding="UTF-16"?> <Task version="1.3" xmlns="hxxp://schemas.microsoft.com/windows/2004/02/mit/task"> <RegistrationInfo> <Source>Microsoft Corporation</Source> <Author>Microsoft Corporation</Author> <Description>F�hrt eine �berpr�fung auf Updates f�r die derzeit installierten Spiele aus.</Description> <URI>\Games\UpdateCheck_S-1-5-21-982829961-422532093-1718007052-1000</URI> <SecurityDescriptor>D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;S-1-5-21-982829961-422532093-1718007052-1000)</SecurityDescriptor> </RegistrationInfo> <Triggers> <CalendarTrigger> <StartBoundary>2008-01-01T02:00:00</StartBoundary> <Enabled>true</Enabled> <RandomDelay>PT2H</RandomDelay> <ScheduleByDay> <DaysInterval>1</DaysInterval> </ScheduleByDay> </CalendarTrigger> <LogonTrigger> <Enabled>true</Enabled> <UserId>User</UserId> <Delay>PT15M</Delay> </LogonTrigger> </Triggers> <Principals> <Principal id="Author"> <UserId>S-1-5-21-982829961-422532093-1718007052-1000</UserId> <RunLevel>LeastPrivilege</RunLevel> <LogonType>InteractiveToken</LogonType> </Principal> </Principals> <Settings> <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy> <DisallowStartIfOnBatteries>true</DisallowStartIfOnBatteries> <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries> <AllowHardTerminate>true</AllowHardTerminate> <StartWhenAvailable>false</StartWhenAvailable> <RunOnlyIfNetworkAvailable>true</RunOnlyIfNetworkAvailable> <IdleSettings> <Duration>PT10M</Duration> <WaitTimeout>PT1H</WaitTimeout> <StopOnIdleEnd>true</StopOnIdleEnd> <RestartOnIdle>false</RestartOnIdle> </IdleSettings> <AllowStartOnDemand>true</AllowStartOnDemand> <Enabled>true</Enabled> <Hidden>true</Hidden> <RunOnlyIfIdle>true</RunOnlyIfIdle> <DisallowStartOnRemoteAppSession>false</DisallowStartOnRemoteAppSession> <UseUnifiedSchedulingEngine>true</UseUnifiedSchedulingEngine> <WakeToRun>false</WakeToRun> <ExecutionTimeLimit>PT72H</ExecutionTimeLimit> <Priority>7</Priority> </Settings> <Actions Context="Author"> <ComHandler> <ClassId>{CA22F5B1-E06F-4A2B-94FC-21E87FE53781}</ClassId> </ComHandler> </Actions> </Task> ========= End of CMD: ========= ==== End of Fixlog 11:49:13 ==== |
27.01.2015, 12:04 | #15 | |
/// TB-Ausbilder | Proxy-Fehlermeldung 127.0.0.1:8897 Achtung: 2 Dateien ! Bitte lasse die Datei aus der Code-Box bei Virustotal überprüfen.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
Themen zu Proxy-Fehlermeldung 127.0.0.1:8897 |
adware, antivirus, autokms, avira, bingbar, browser, defender, device driver, entfernen, excel, fehler, firefox, flash player, home, homepage, internet, mozilla, onedrive, performance, prozess, realtek, registry, scan, security, services.exe, software, system, vista, windows |