|
Plagegeister aller Art und deren Bekämpfung: Windows 7: ungültiges Bild (Error Meldung)Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
03.02.2015, 19:46 | #1 | |
| Windows 7: ungültiges Bild (Error Meldung) Mir wurde diese Seite empfohlen, hab mich extra registriert und wie ich sehe habe ich wohl nicht allein dieses Problemchen. Also seit neuestem erscheint immer wieder folgende Fehlermeldung: Zitat:
Da bisher jedem geraten wurde einen Farbar Recovery Scan durchzuführen, habe ich mir erlaubt dies ebenfalls gleich zu machen. FRST Logfile Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015 Ran by julia (administrator) on JULIA-PC on 03-02-2015 19:27:15 Running from C:\Users\julia\Downloads Loaded Profiles: julia (Available profiles: julia) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Wacom Technology, Corp.) C:\Program Files\WTouch\WTouchService.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Corsair) C:\Program Files (x86)\Corsair SSD Toolbox\CSSDTService.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (Wacom Technology, Corp.) C:\Windows\System32\Pen_Tablet.exe (AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe (X10) C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe (Client Connect LTD) C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Client Connect LTD) C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe (Client Connect LTD) C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe (Wacom Technology, Corp.) C:\Program Files\WTouch\WTouchUser.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Wacom Technology, Corp.) C:\Windows\System32\WTablet\Pen_TabletUser.exe (Wacom Technology, Corp.) C:\Windows\System32\Pen_Tablet.exe () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\julia\Downloads\FRST64 (2).exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1814312 2009-08-14] (Synaptics Incorporated) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3838800 2014-12-13] (LogMeIn Inc.) HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1140688 2015-01-16] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-11-24] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466144 2014-11-27] (Sony) HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30873192 2014-12-11] (Skype Technologies S.A.) HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\...\MountPoints2: {d7b79e4b-1b09-11e4-a78a-0022200a07ac} - E:\Startme.exe AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [253200 2015-01-28] (Client Connect LTD) AppInit_DLLs-x32: C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC32LO~1.DLL => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [219408 2015-01-28] () Startup: C:\Users\julia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3050A J611 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3050A J611 series.lnk -> C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MFAD356A7-D765-4D26-9751-007AAC60CF2E&SearchSource=55&CUI=&UM=5&UP=SPE0DF30FF-D716-44B8-B619-581937559E07&SSPV= HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp SearchScopes: HKU\S-1-5-21-3165034952-4008388936-3891106506-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M8A738E8B-DA80-4CDC-ACA0-AE9E423A9290&SearchSource=58&CUI=&UM=8&UP=SPE0DF30FF-D716-44B8-B619-581937559E07&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-3165034952-4008388936-3891106506-1000 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M8A738E8B-DA80-4CDC-ACA0-AE9E423A9290&SearchSource=58&CUI=&UM=8&UP=SPE0DF30FF-D716-44B8-B619-581937559E07&q={searchTerms}&SSPV= BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) FireFox: ======== FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M8A738E8B-DA80-4CDC-ACA0-AE9E423A9290&SearchSource=55&CUI=&UM=8&UP=SPE0DF30FF-D716-44B8-B619-581937559E07&SSPV= CHR StartupUrls: Default -> "https://www.google.at/" CHR Profile: C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-20] CHR Extension: (Google Drive) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-20] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-07] CHR Extension: (YouTube) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-20] CHR Extension: (Google-Suche) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-20] CHR Extension: (Avira SafeSearch) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglgfnfolcgijipffhlhbbnefdcbjbml [2015-02-03] CHR Extension: (Google Wallet) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-20] CHR Extension: (Quilt) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofholagheebdhalaonjopcfcedggjooo [2014-05-30] CHR Extension: (Google Mail) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-20] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [807672 2014-11-24] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584 2014-11-24] (Avira Operations GmbH & Co. KG) R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [865744 2015-01-16] (AVG Technologies CZ, s.r.o.) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [3505936 2015-01-28] (Client Connect LTD) R2 CorsairSSDToolBox; C:\Program Files (x86)\Corsair SSD Toolbox\CSSDTService.exe [1845864 2014-02-12] (Corsair) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2014-12-02] (LogMeIn, Inc.) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2604856 2014-11-24] (AVG Technologies) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [762320 2015-01-17] (Tunngle.net GmbH) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 WTouchService; C:\Program Files\WTouch\WTouchService.exe [127784 2009-11-24] (Wacom Technology, Corp.) R2 x10nets; C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe [20480 2009-11-07] (X10) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-11-24] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-11-24] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [43064 2014-11-24] (Avira Operations GmbH & Co. KG) S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2014-08-18] (Sony Mobile Communications) S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-22] (Realtek Semiconductor Corp.) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-11-24] (TuneUp Software) R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [15896 2009-05-13] (X10 Wireless Technology, Inc.) R3 SPPD; \??\C:\Windows\system32\drivers\SPPD.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-03 19:22 - 2015-02-03 19:22 - 02131456 _____ (Farbar) C:\Users\julia\Downloads\FRST64 (2).exe 2015-02-03 18:48 - 2015-02-03 18:50 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-02-03 18:47 - 2015-02-03 18:47 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\julia\Downloads\revosetup95.exe 2015-02-03 18:43 - 2015-02-03 18:43 - 00003364 _____ () C:\Windows\System32\Tasks\AviraSpeedup 2015-02-03 18:43 - 2015-02-03 18:43 - 00001239 _____ () C:\Users\Public\Desktop\Avira System Speedup.lnk 2015-02-03 18:43 - 2015-02-03 18:43 - 00000000 ____D () C:\Users\julia\AppData\Roaming\Avira 2015-02-03 18:43 - 2015-02-03 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviraSpeedup 2015-02-03 18:42 - 2014-11-24 10:23 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-02-03 18:42 - 2014-11-24 10:23 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-02-03 18:42 - 2014-11-24 10:23 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2015-02-03 18:42 - 2014-11-24 10:23 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2015-02-03 18:39 - 2015-02-03 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-03 18:39 - 2015-02-03 18:42 - 00000000 ____D () C:\ProgramData\Avira 2015-02-03 18:39 - 2015-02-03 18:39 - 04515896 _____ (Avira Operations & Co. KG) C:\Users\julia\Downloads\avira_de_issuse_3002988189_7iomicq1hqlm0h0551hj_wd.exe 2015-02-03 18:39 - 2015-02-03 18:39 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk 2015-02-03 18:39 - 2015-02-03 18:39 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-03 18:30 - 2015-02-03 18:30 - 00025804 _____ () C:\Users\julia\Downloads\Addition.txt 2015-02-03 18:29 - 2015-02-03 19:27 - 00015234 _____ () C:\Users\julia\Downloads\FRST.txt 2015-02-03 18:29 - 2015-02-03 19:27 - 00000000 ____D () C:\FRST 2015-02-03 18:29 - 2015-02-03 18:29 - 02131456 _____ (Farbar) C:\Users\julia\Downloads\FRST64 (1).exe 2015-02-02 20:10 - 2015-02-02 20:10 - 02131456 _____ (Farbar) C:\Users\julia\Downloads\FRST64.exe 2015-02-02 18:52 - 2015-02-02 18:55 - 00002484 _____ () C:\Windows\logboot_02.02.2015.tureg.log 2015-02-02 17:50 - 2015-02-02 17:50 - 00002217 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015.lnk 2015-02-02 17:50 - 2015-02-02 17:50 - 00000000 ____D () C:\Users\julia\AppData\Roaming\AVG 2015-02-02 17:50 - 2015-02-02 17:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015 2015-02-02 17:50 - 2014-11-24 12:48 - 00040248 _____ (AVG Technologies) C:\Windows\system32\TURegOpt.exe 2015-02-02 17:50 - 2014-11-24 12:48 - 00029496 _____ (AVG Technologies) C:\Windows\system32\authuitu.dll 2015-02-02 17:50 - 2014-11-24 12:48 - 00025400 _____ (AVG Technologies) C:\Windows\SysWOW64\authuitu.dll 2015-02-02 17:49 - 2015-02-02 17:49 - 00000932 _____ () C:\Users\Public\Desktop\AVG.lnk 2015-02-02 17:49 - 2015-02-02 17:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen 2015-02-02 17:48 - 2015-02-02 17:50 - 00000000 ____D () C:\ProgramData\Avg 2015-02-02 17:48 - 2015-02-02 17:50 - 00000000 ____D () C:\Program Files (x86)\AVG 2015-02-02 17:47 - 2015-02-02 17:50 - 00000000 ____D () C:\Users\julia\AppData\Local\Avg 2015-02-02 17:47 - 2015-02-02 17:49 - 00000000 ____D () C:\Users\julia\AppData\Local\AvgSetupLog 2015-02-02 17:47 - 2015-02-02 17:47 - 16634392 _____ (AVG Technologies) C:\Users\julia\Downloads\avg_gse_stb_all_445p1_143.exe 2015-02-01 12:34 - 2014-06-16 12:13 - 00043320 _____ (TuneUp Software) C:\Windows\system32\uxt5050.tmp 2015-02-01 12:33 - 2015-02-02 17:50 - 00000000 ____D () C:\Users\julia\AppData\Local\avaxvavya 2015-02-01 12:33 - 2015-02-01 12:33 - 00003462 _____ () C:\Windows\System32\Tasks\avaxvavya 2015-02-01 12:33 - 2015-02-01 12:33 - 00000000 ____D () C:\Users\julia\AppData\Local\TuneUp Software 2015-02-01 12:32 - 2015-02-01 12:32 - 00001536 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk 2015-02-01 12:32 - 2015-02-01 12:32 - 00001245 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2015-02-01 12:32 - 2015-02-01 12:32 - 00000238 _____ () C:\Users\julia\updhelper.xml 2015-02-01 12:32 - 2015-02-01 12:32 - 00000008 _____ () C:\Users\julia\updhelper.xml.lck 2015-02-01 12:32 - 2015-02-01 12:32 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2015-02-01 12:32 - 2015-02-01 12:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-02-01 12:31 - 2015-02-01 12:32 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2015-02-01 12:31 - 2015-02-01 12:31 - 00000000 ____D () C:\Users\julia\AppData\Roaming\RHEng 2015-02-01 12:31 - 2015-02-01 12:31 - 00000000 ____D () C:\Program Files (x86)\Free Codec Pack 2015-02-01 12:30 - 2015-02-01 12:30 - 34792128 _____ (DVDVideoSoft Ltd. ) C:\Users\julia\Downloads\FreeYouTubeToMP354Converter.exe 2015-01-24 18:12 - 2015-01-24 18:12 - 00343552 _____ (Microsoft) C:\Users\julia\Downloads\BA-ReDi4u_Offline (1).exe 2015-01-24 18:08 - 2015-01-24 18:08 - 00343552 _____ (Microsoft) C:\Users\julia\Downloads\BA-ReDi4u_Offline.exe 2015-01-18 17:25 - 2015-01-18 19:26 - 00000000 ____D () C:\Users\julia\AppData\Roaming\Tunngle 2015-01-18 17:25 - 2015-01-18 19:26 - 00000000 ____D () C:\ProgramData\Tunngle 2015-01-18 17:25 - 2015-01-18 17:26 - 00000000 ____D () C:\Program Files (x86)\Tunngle 2015-01-18 17:25 - 2015-01-18 17:25 - 00000995 _____ () C:\Users\Public\Desktop\Tunngle.lnk 2015-01-18 17:25 - 2015-01-18 17:25 - 00000000 ____D () C:\Users\Public\Documents\Tunngle 2015-01-18 17:25 - 2015-01-18 17:25 - 00000000 ____D () C:\Users\julia\Documents\Tunngle 2015-01-18 17:25 - 2015-01-18 17:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle 2015-01-18 17:25 - 2009-09-16 07:02 - 00031232 _____ (Tunngle.net) C:\Windows\system32\Drivers\tap0901t.sys 2015-01-18 17:23 - 2015-01-18 17:23 - 04501720 _____ (Tunngle.net GmbH ) C:\Users\julia\Downloads\Tunngle_Setupv5.0.exe 2015-01-14 20:41 - 2015-01-14 20:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2015-01-14 20:41 - 2015-01-14 20:41 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi 2015-01-14 20:30 - 2015-01-23 17:27 - 00000000 ____D () C:\Users\julia\AppData\Roaming\.minecraft 2015-01-14 20:30 - 2015-01-14 20:30 - 00000000 ____D () C:\Users\julia\AppData\Roaming\java 2015-01-14 20:29 - 2015-01-30 17:23 - 00000000 ____D () C:\Program Files (x86)\Minecraft 2015-01-14 20:29 - 2015-01-14 20:29 - 02318336 _____ () C:\Users\julia\Downloads\MinecraftInstaller.msi 2015-01-14 20:29 - 2015-01-14 20:29 - 00000961 _____ () C:\Users\Public\Desktop\Minecraft.lnk 2015-01-14 20:29 - 2015-01-14 20:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft 2015-01-14 16:29 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 16:29 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 16:29 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-14 16:29 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-01-14 16:29 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-01-14 16:29 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-01-14 16:29 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-01-14 16:29 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-01-14 16:29 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-01-14 16:29 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-14 16:29 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 16:29 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-14 16:29 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2015-01-06 19:32 - 2015-01-06 19:32 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-03 19:17 - 2014-03-22 15:53 - 00000000 ____D () C:\Users\julia\AppData\Roaming\Skype 2015-02-03 19:01 - 2014-04-02 21:00 - 00000256 _____ () C:\Windows\Tasks\HP Photo Creations Messager.job 2015-02-03 18:54 - 2014-03-20 16:42 - 01954862 _____ () C:\Windows\WindowsUpdate.log 2015-02-03 18:43 - 2014-03-22 18:39 - 00000000 ____D () C:\Users\julia\AppData\Local\LogMeIn Hamachi 2015-02-03 18:43 - 2014-03-20 17:07 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-03 18:43 - 2014-03-20 16:46 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-02-03 18:43 - 2009-07-14 05:45 - 00016304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-03 18:43 - 2009-07-14 05:45 - 00016304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-03 18:42 - 2009-07-14 18:58 - 00700800 _____ () C:\Windows\system32\perfh007.dat 2015-02-03 18:42 - 2009-07-14 18:58 - 00149668 _____ () C:\Windows\system32\perfc007.dat 2015-02-03 18:42 - 2009-07-14 06:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-03 18:36 - 2014-05-04 11:06 - 00000000 ____D () C:\Users\julia\AppData\Roaming\WTablet 2015-02-03 18:36 - 2014-03-22 09:20 - 00074977 _____ () C:\Windows\setupact.log 2015-02-03 18:36 - 2014-03-22 09:19 - 00101334 _____ () C:\Windows\PFRO.log 2015-02-03 18:36 - 2014-03-20 17:07 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-03 18:36 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-02 18:55 - 2014-03-20 16:39 - 00000000 ____D () C:\Users\julia 2015-02-02 18:55 - 2009-07-14 03:34 - 72876032 _____ () C:\Windows\system32\config\SOFTWARE_tureg_old 2015-02-02 18:55 - 2009-07-14 03:34 - 17039360 _____ () C:\Windows\system32\config\SYSTEM_tureg_old 2015-02-02 18:55 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY_tureg_old 2015-02-02 18:51 - 2009-07-14 03:34 - 52953088 _____ () C:\Windows\system32\config\COMPONENTS_tureg_old 2015-02-02 18:51 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM_tureg_old 2015-02-02 18:51 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\DEFAULT_tureg_old 2015-02-02 17:55 - 2014-04-02 20:59 - 00000000 ____D () C:\Users\julia\AppData\Roaming\HpUpdate 2015-02-02 17:50 - 2014-03-20 16:39 - 00000000 ____D () C:\Users\julia\AppData\Local\VirtualStore 2015-02-01 12:33 - 2014-05-30 07:59 - 00000000 ____D () C:\Program Files (x86)\SearchProtect 2015-02-01 12:33 - 2014-03-20 19:09 - 00000000 ____D () C:\Users\julia\AppData\Roaming\TuneUp Software 2015-02-01 12:33 - 2014-03-20 19:09 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-02-01 12:33 - 2014-03-20 19:09 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2013 2015-02-01 12:32 - 2014-05-30 07:57 - 00000000 ____D () C:\Users\julia\AppData\Roaming\DVDVideoSoft 2015-01-27 18:44 - 2014-03-20 17:07 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-01-21 18:21 - 2014-08-18 20:04 - 00278270 _____ () C:\Windows\DPINST.LOG 2015-01-21 18:21 - 2014-08-18 20:03 - 00002026 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2015-01-21 18:21 - 2014-08-18 20:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony 2015-01-21 18:21 - 2014-03-20 22:55 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-01-18 19:12 - 2014-03-20 17:06 - 00086936 _____ () C:\Users\julia\AppData\Local\GDIPFONTCACHEV1.DAT 2015-01-18 17:27 - 2009-07-14 05:45 - 04895216 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-01-14 22:56 - 2014-03-20 17:34 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-14 22:53 - 2014-03-20 17:34 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-01-07 17:10 - 2014-08-18 20:06 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile 2015-01-07 12:53 - 2014-03-22 15:53 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-01-07 12:53 - 2014-03-22 15:53 - 00000000 ____D () C:\ProgramData\Skype 2015-01-06 04:36 - 2014-03-20 18:28 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Files in the root of some directories ======= 2014-05-04 13:16 - 2014-08-11 16:26 - 0000132 _____ () C:\Users\julia\AppData\Roaming\Adobe PNG Format CS5 Prefs 2014-03-20 23:10 - 2014-03-21 16:42 - 0007605 _____ () C:\Users\julia\AppData\Local\Resmon.ResmonCfg 2014-04-02 20:58 - 2014-04-02 20:58 - 0000057 _____ () C:\ProgramData\Ament.ini Some content of TEMP: ==================== C:\Users\julia\AppData\Local\Temp\avgnt.exe C:\Users\julia\AppData\Local\Temp\DseShExt-x64.dll C:\Users\julia\AppData\Local\Temp\DseShExt-x86.dll C:\Users\julia\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\julia\AppData\Local\Temp\SDShelEx-x64.dll C:\Users\julia\AppData\Local\Temp\TUUUninstallHelper.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-24 15:27 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2015 Ran by julia at 2015-02-03 18:30:10 Running from C:\Users\julia\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9120 - Adobe Systems Inc.) Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated) Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated) Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) AMD Catalyst Install Manager (HKLM\...\{37FCE154-7F59-74F0-3A35-BF503CEB230B}) (Version: 8.0.877.0 - Advanced Micro Devices, Inc.) Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) AVG (HKLM\...\AvgZen) (Version: 1.0.445 - AVG Technologies) AVG PC TuneUp 2015 (de-DE) (x32 Version: 15.0.1001.238 - AVG Technologies) Hidden AVG PC TuneUp 2015 (HKLM-x32\...\AVG PC TuneUp) (Version: 15.0.1001.238 - AVG Technologies) AVG PC TuneUp 2015 (x32 Version: 15.0.1001.238 - AVG Technologies) Hidden AVG Zen (Version: 1.0.445 - AVG Technologies) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) Corsair SSD Toolbox 1.2.0.9 (HKLM-x32\...\{70DE02E8-FBDD-4892-9B21-117DCA1DD553}_is1) (Version: 1.2.0.9 - Corsair) Dino D-Day (HKLM-x32\...\Steam App 70000) (Version: - 800 North and Digital Ranch) FMW 1 (Version: 1.0.308 - AVG Technologies) Hidden Free YouTube to MP3 Converter version 3.12.54.128 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.54.128 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.93 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (HKLM\...\{D8057953-CCF0-48B3-B61D-762C580B2A10}) (Version: 25.0.571.0 - Hewlett-Packard Co.) HP Deskjet 3050A J611 series Hilfe (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.5192 - HP Photo Creations) HP Update (HKLM-x32\...\{85DF2EED-08BC-46FB-90DA-28B0D0A8E8A8}) (Version: 5.003.000.004 - Hewlett-Packard) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.0.1006 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.5.0.1037 - Intel Corporation) iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.291 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.291 - LogMeIn, Inc.) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Minecraft (HKLM-x32\...\{63227E62-F417-497E-9060-22B3A9A52D7A}) (Version: 1.0.1.0 - Mojang) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.5 - Notepad++ Team) PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden PowerISO (HKLM-x32\...\PowerISO) (Version: 4.7 - PowerISO Computing, Inc.) Realtek Ethernet Controller Driver For Windows Vista and Later (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6010 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30105 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173F09590E16}) (Version: 1.00.0145 - REALTEK Semiconductor Corp.) Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.20.2.12 - Client Connect LTD) <==== ATTENTION Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) Sony Mobile Update Engine (HKLM-x32\...\Update Engine) (Version: 2.14.17.201412121559 - Sony Mobile Communications Inc.) Sony PC Companion 2.10.245 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.245 - Sony) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) Stifttablett (HKLM-x32\...\Pen Tablet Driver) (Version: - Wacom Technology Corp.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.0.3 - Synaptics Incorporated) Titan Quest (HKLM-x32\...\{412B69AF-C352-4F6F-A318-B92B3CB9ACC6}) (Version: 1.00.0000 - Iron Lore) TuneUp Utilities Language Pack (de-DE) (x32 Version: 13.0.3020.2 - TuneUp Software) Hidden Tunngle (HKLM-x32\...\Tunngle_is1) (Version: Tunngle - Tunngle.net GmbH) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) WebTablet IE Plugin (HKLM-x32\...\Wacom WebTabletPlugin for IE) (Version: 1.1.0.4 - Wacom Technology Corp.) WebTablet Netscape Plugin (HKLM-x32\...\Wacom WebTabletPlugin for Netscape) (Version: 1.1.0.3 - Wacom Technology Corp.) WIDCOMM Bluetooth Software (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.0.9600 - Broadcom Corporation) WinRAR 5.10 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.1 - win.rar GmbH) World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net) X10 Hardware(TM) (HKLM-x32\...\X10Hardware) (Version: - ) Xfire (remove only) (HKLM-x32\...\Xfire) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= ATTENTION: System Restore is disabled. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {10F0C431-06F7-4436-81E6-7F20600068D6} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {12E5F9FF-4189-4A56-BFDB-F7FD39EF56D7} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {1E291C7E-D115-446B-8082-D6319ABCF866} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] () Task: {24B593D9-127A-4C79-8776-B613ABC259C6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20] (Google Inc.) Task: {2DCAD893-58A5-486F-9494-340AEFBC8A3E} - System32\Tasks\{440C718E-1154-4FEE-9C8F-2EB5BABF3F48} => pcalua.exe -a "C:\Users\julia\Downloads\dxwebsetup0411 (1).exe" -d C:\Users\julia\Downloads Task: {4524602A-3F9B-4CAF-AB14-6BB576C972F2} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {6BF95FB0-67DD-46B2-AB18-EA381E5850D4} - System32\Tasks\AdobeAAMUpdater-1.0-julia-PC-julia => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated) Task: {9015B820-B6C2-4C23-B8B6-1A529B3715BC} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {ACB94E8D-4124-47D7-B76C-52F7FA79A733} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20] (Google Inc.) Task: {C7415573-9E48-4F96-9E80-2AEC182B5A20} - System32\Tasks\avaxvavya => C:\Users\julia\AppData\Local\avaxvavya\avaxvavya.exe [2015-01-28] () Task: {D0271C63-D1CE-4D68-A8E9-434DB72DCC94} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2011-03-24] (Hewlett-Packard) Task: {EF00AFF2-4D13-4D5B-8689-6B28FC658EA9} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe ==================== Loaded Modules (whitelisted) ============= 2014-11-24 12:48 - 2014-11-24 12:48 - 00713528 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\avgrepliba.dll 2014-11-24 12:49 - 2014-11-24 12:49 - 00856888 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\tulnga.dll 2014-08-18 20:03 - 2014-06-23 08:07 - 00113376 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe 2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-03-20 22:55 - 2009-10-02 13:18 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2014-08-18 20:03 - 2012-04-30 10:57 - 00039936 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll 2014-08-18 20:03 - 2014-12-04 14:18 - 00241152 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll 2011-07-07 14:54 - 2011-07-07 14:54 - 00233984 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll 2014-08-18 20:03 - 2013-05-20 11:58 - 00620718 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll 2014-08-18 20:03 - 2010-01-11 15:44 - 00053248 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\VObject.dll 2014-11-21 12:31 - 2014-11-21 12:31 - 00663040 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PhoneUpdate.dll 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2015-02-02 17:48 - 2015-02-02 17:48 - 31842816 _____ () C:\Program Files (x86)\AVG\Framework\Common\libcef.dll 2015-01-27 18:44 - 2015-01-25 07:08 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\libglesv2.dll 2015-01-27 18:44 - 2015-01-25 07:08 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\libegl.dll 2015-01-27 18:44 - 2015-01-25 07:08 - 09170760 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\pdf.dll 2015-01-27 18:44 - 2015-01-25 07:08 - 14913864 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-3165034952-4008388936-3891106506-500 - Administrator - Disabled) Gast (S-1-5-21-3165034952-4008388936-3891106506-501 - Limited - Disabled) julia (S-1-5-21-3165034952-4008388936-3891106506-1000 - Administrator - Enabled) => C:\Users\julia ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/01/2015 00:33:05 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: julia-PC) Description: Die Anwendung oder der Dienst "Windows-Explorer" konnte nicht heruntergefahren werden. Error: (01/31/2015 05:08:05 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: TuneUpSystemStatusCheck.exe, Version: 13.0.3020.2, Zeitstempel: 0x510679cd Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b96f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0003bc24 ID des fehlerhaften Prozesses: 0x944 Startzeit der fehlerhaften Anwendung: 0xTuneUpSystemStatusCheck.exe0 Pfad der fehlerhaften Anwendung: TuneUpSystemStatusCheck.exe1 Pfad des fehlerhaften Moduls: TuneUpSystemStatusCheck.exe2 Berichtskennung: TuneUpSystemStatusCheck.exe3 Error: (01/31/2015 11:15:38 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (01/30/2015 04:37:09 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (01/28/2015 03:17:56 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (01/27/2015 07:30:34 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (01/25/2015 00:28:57 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (01/24/2015 03:27:51 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (01/23/2015 04:06:27 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (01/19/2015 01:34:35 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. System errors: ============= Error: (02/02/2015 11:05:53 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (02/02/2015 06:55:41 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "JULIA-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.5 registriert werden. Der Computer mit IP-Adresse 192.168.1.2 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (02/02/2015 06:55:40 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "JULIA-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.5 registriert werden. Der Computer mit IP-Adresse 192.168.1.2 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (02/02/2015 06:55:40 PM) (Source: Server) (EventID: 2505) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{E9CFE29A-9453-4C33-A5EB-AEC7D29A58E8} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error: (02/02/2015 06:55:21 PM) (Source: volmgr) (EventID: 46) (User: ) Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen. Error: (02/02/2015 05:40:51 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "JULIA-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.4 registriert werden. Der Computer mit IP-Adresse 192.168.1.2 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (02/02/2015 05:40:51 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "JULIA-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.4 registriert werden. Der Computer mit IP-Adresse 192.168.1.2 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (02/02/2015 05:40:51 PM) (Source: Server) (EventID: 2505) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{E9CFE29A-9453-4C33-A5EB-AEC7D29A58E8} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error: (02/01/2015 00:34:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "TuneUp Designerweiterung" wurde aufgrund folgenden Fehlers nicht gestartet: %%1083 Error: (02/01/2015 00:34:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "TuneUp Designerweiterung" wurde aufgrund folgenden Fehlers nicht gestartet: %%1083 Microsoft Office Sessions: ========================= Error: (02/01/2015 00:33:05 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: julia-PC) Description: 1C:\Windows\explorer.exeWindows-Explorer0411734400 Error: (01/31/2015 05:08:05 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: TuneUpSystemStatusCheck.exe13.0.3020.2510679cdole32.dll6.1.7601.175144ce7b96fc00000050003bc2494401d03d7014759b32C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpSystemStatusCheck.exeC:\Windows\syswow64\ole32.dll568939bb-a963-11e4-a7c2-0022200a07ac Error: (01/31/2015 11:15:38 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (01/30/2015 04:37:09 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (01/28/2015 03:17:56 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (01/27/2015 07:30:34 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (01/25/2015 00:28:57 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (01/24/2015 03:27:51 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (01/23/2015 04:06:27 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (01/19/2015 01:34:35 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5 CPU M 430 @ 2.27GHz Percentage of memory in use: 44% Total physical RAM: 4084.56 MB Available physical RAM: 2286.32 MB Total Pagefile: 8167.31 MB Available Pagefile: 5947.46 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:223.47 GB) (Free:124.7 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 088A8900) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=223.5 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
03.02.2015, 19:48 | #2 |
/// the machine /// TB-Ausbilder | Windows 7: ungültiges Bild (Error Meldung) hi,
__________________Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Scan mit Combofix
__________________ |
03.02.2015, 20:18 | #3 |
| Windows 7: ungültiges Bild (Error Meldung) Danke schon mal, die Meldungen haben endlich aufgehört =3
__________________Wie angefordert: Code:
ATTFilter ComboFix 15-02-02.01 - julia 03.02.2015 20:05:39.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.43.1031.18.4085.1878 [GMT 1:00] ausgeführt von:: c:\users\julia\Downloads\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\julia\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll c:\users\julia\AppData\Roaming\WTouch c:\users\julia\AppData\Roaming\WTouch\WTouch.xml c:\windows\logboot_02.02.2015.tureg.log c:\windows\msdownld.tmp . . ((((((((((((((((((((((( Dateien erstellt von 2015-01-03 bis 2015-02-03 )))))))))))))))))))))))))))))) . . 2015-02-03 17:48 . 2015-02-03 18:56 -------- d-----w- c:\program files (x86)\VS Revo Group 2015-02-03 17:43 . 2015-02-03 17:43 -------- d-----w- c:\users\julia\AppData\Roaming\Avira 2015-02-03 17:42 . 2014-11-24 09:23 43064 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2015-02-03 17:42 . 2014-11-24 09:23 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2015-02-03 17:42 . 2014-11-24 09:23 131608 ----a-w- c:\windows\system32\drivers\avipbb.sys 2015-02-03 17:42 . 2014-11-24 09:23 119272 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2015-02-03 17:39 . 2015-02-03 17:42 -------- d-----w- c:\programdata\Avira 2015-02-03 17:39 . 2015-02-03 17:39 -------- d-----w- c:\programdata\Package Cache 2015-02-03 17:29 . 2015-02-03 18:30 -------- d-----w- C:\FRST 2015-02-03 17:25 . 2014-12-02 10:26 11870360 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B94C7858-0248-4849-8C89-6057EC56B55E}\mpengine.dll 2015-02-02 16:50 . 2014-11-24 11:48 40248 ----a-w- c:\windows\system32\TURegOpt.exe 2015-02-02 16:50 . 2014-11-24 11:48 29496 ----a-w- c:\windows\system32\authuitu.dll 2015-02-02 16:50 . 2014-11-24 11:48 25400 ----a-w- c:\windows\SysWow64\authuitu.dll 2015-02-02 16:50 . 2015-02-02 16:50 -------- d-----w- c:\users\julia\AppData\Roaming\AVG 2015-02-02 16:48 . 2015-02-02 16:50 -------- d-----w- c:\programdata\Avg 2015-02-02 16:48 . 2015-02-02 16:50 -------- d-----w- c:\program files (x86)\AVG 2015-02-02 16:47 . 2015-02-02 16:50 -------- d-----w- c:\users\julia\AppData\Local\Avg 2015-02-01 11:34 . 2014-06-16 11:13 43320 ----a-w- c:\windows\system32\uxt5050.tmp 2015-02-01 11:33 . 2015-02-01 11:33 -------- d-----w- c:\users\julia\AppData\Local\TuneUp Software 2015-02-01 11:32 . 2015-02-01 11:32 -------- d-sh--w- c:\programdata\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2015-02-01 11:31 . 2015-02-01 11:31 -------- d-----w- c:\program files (x86)\Free Codec Pack 2015-02-01 11:31 . 2015-02-01 11:32 -------- d-----w- c:\program files (x86)\DVDVideoSoft 2015-02-01 11:31 . 2015-02-01 11:31 -------- d-----w- c:\program files (x86)\Common Files\DVDVideoSoft 2015-02-01 11:31 . 2015-02-01 11:31 -------- d-----w- c:\users\julia\AppData\Roaming\RHEng 2015-01-18 16:25 . 2015-01-18 18:26 -------- d-----w- c:\users\julia\AppData\Roaming\Tunngle 2015-01-18 16:25 . 2015-01-18 18:26 -------- d-----w- c:\programdata\Tunngle 2015-01-18 16:25 . 2009-09-16 06:02 31232 ----a-w- c:\windows\system32\drivers\tap0901t.sys 2015-01-18 16:25 . 2015-01-18 16:26 -------- d-----w- c:\program files (x86)\Tunngle 2015-01-14 19:41 . 2015-01-14 19:41 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi 2015-01-14 19:30 . 2015-01-14 19:30 -------- d-----w- c:\users\julia\AppData\Roaming\java 2015-01-14 19:30 . 2015-01-23 16:27 -------- d-----w- c:\users\julia\AppData\Roaming\.minecraft 2015-01-14 19:29 . 2015-01-30 16:23 -------- d-----w- c:\program files (x86)\Minecraft . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-01-14 21:53 . 2014-03-20 16:34 113365784 ----a-w- c:\windows\system32\MRT.exe 2015-01-06 03:36 . 2014-03-20 17:28 298120 ------w- c:\windows\system32\MpSigStub.exe 2014-12-13 05:09 . 2014-12-18 17:02 144384 ----a-w- c:\windows\system32\ieUnatt.exe 2014-12-13 03:33 . 2014-12-18 17:02 115712 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-11-27 01:43 . 2014-12-10 15:09 389296 ----a-w- c:\windows\system32\iedkcs32.dll 2014-11-22 03:13 . 2014-12-10 15:09 25059840 ----a-w- c:\windows\system32\mshtml.dll 2014-11-22 03:06 . 2014-12-10 15:10 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-11-22 03:06 . 2014-12-10 15:09 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-11-22 02:50 . 2014-12-10 15:09 66560 ----a-w- c:\windows\system32\iesetup.dll 2014-11-22 02:50 . 2014-12-10 15:09 580096 ----a-w- c:\windows\system32\vbscript.dll 2014-11-22 02:49 . 2014-12-10 15:10 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-11-22 02:49 . 2014-12-10 15:09 2885120 ----a-w- c:\windows\system32\iertutil.dll 2014-11-22 02:48 . 2014-12-10 15:09 88064 ----a-w- c:\windows\system32\MshtmlDac.dll 2014-11-22 02:41 . 2014-12-10 15:09 54784 ----a-w- c:\windows\system32\jsproxy.dll 2014-11-22 02:40 . 2014-12-10 15:10 34304 ----a-w- c:\windows\system32\iernonce.dll 2014-11-22 02:37 . 2014-12-10 15:09 633856 ----a-w- c:\windows\system32\ieui.dll 2014-11-22 02:35 . 2014-12-10 15:10 114688 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-11-22 02:34 . 2014-12-10 15:09 814080 ----a-w- c:\windows\system32\jscript9diag.dll 2014-11-22 02:34 . 2014-12-10 15:09 6039552 ----a-w- c:\windows\system32\jscript9.dll 2014-11-22 02:26 . 2014-12-10 15:09 968704 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-11-22 02:22 . 2014-12-10 15:09 490496 ----a-w- c:\windows\system32\dxtmsft.dll 2014-11-22 02:20 . 2014-12-10 15:09 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-11-22 02:14 . 2014-12-10 15:10 77824 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2014-11-22 02:09 . 2014-12-10 15:09 199680 ----a-w- c:\windows\system32\msrating.dll 2014-11-22 02:08 . 2014-12-10 15:09 92160 ----a-w- c:\windows\system32\mshtmled.dll 2014-11-22 02:07 . 2014-12-10 15:09 501248 ----a-w- c:\windows\SysWow64\vbscript.dll 2014-11-22 02:07 . 2014-12-10 15:09 62464 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-11-22 02:06 . 2014-12-10 15:10 47616 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2014-11-22 02:05 . 2014-12-10 15:09 64000 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2014-11-22 02:05 . 2014-12-10 15:09 316928 ----a-w- c:\windows\system32\dxtrans.dll 2014-11-22 01:54 . 2014-12-10 15:09 620032 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2014-11-22 01:49 . 2014-12-10 15:10 718848 ----a-w- c:\windows\system32\ie4uinit.exe 2014-11-22 01:49 . 2014-12-10 15:09 800768 ----a-w- c:\windows\system32\msfeeds.dll 2014-11-22 01:47 . 2014-12-10 15:09 1359360 ----a-w- c:\windows\system32\mshtmlmedia.dll 2014-11-22 01:46 . 2014-12-10 15:09 2125312 ----a-w- c:\windows\system32\inetcpl.cpl 2014-11-22 01:43 . 2014-12-10 15:09 14412800 ----a-w- c:\windows\system32\ieframe.dll 2014-11-22 01:40 . 2014-12-10 15:10 60416 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2014-11-22 01:29 . 2014-12-10 15:09 4299264 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-11-22 01:28 . 2014-12-10 15:09 2358272 ----a-w- c:\windows\system32\wininet.dll 2014-11-22 01:22 . 2014-12-10 15:09 2052096 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-11-22 01:21 . 2014-12-10 15:09 1155072 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2014-11-22 01:15 . 2014-12-10 15:09 1548288 ----a-w- c:\windows\system32\urlmon.dll 2014-11-22 01:03 . 2014-12-10 15:09 800768 ----a-w- c:\windows\system32\ieapfltr.dll 2014-11-22 01:00 . 2014-12-10 15:09 1888256 ----a-w- c:\windows\SysWow64\wininet.dll 2014-11-19 03:31 . 2014-11-19 03:31 1217192 ----a-w- c:\windows\SysWow64\FM20.DLL 2014-11-11 03:09 . 2014-12-10 15:10 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2014-11-11 03:08 . 2014-11-19 15:15 241152 ----a-w- c:\windows\system32\pku2u.dll 2014-11-11 03:08 . 2014-11-19 15:15 728064 ----a-w- c:\windows\system32\kerberos.dll 2014-11-11 02:44 . 2014-12-10 15:10 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2014-11-11 02:44 . 2014-11-19 15:15 186880 ----a-w- c:\windows\SysWow64\pku2u.dll 2014-11-11 02:44 . 2014-11-19 15:15 550912 ----a-w- c:\windows\SysWow64\kerberos.dll 2014-11-11 01:46 . 2014-12-10 15:10 119296 ----a-w- c:\windows\system32\drivers\tdx.sys 2014-11-08 03:16 . 2014-12-10 15:09 2048 ----a-w- c:\windows\system32\tzres.dll 2014-11-08 02:45 . 2014-12-10 15:09 2048 ----a-w- c:\windows\SysWow64\tzres.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "Sony PC Companion"="c:\program files (x86)\Sony\Sony PC Companion\PCCompanion.exe" [2014-11-27 466144] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-12-11 30873192] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-12-13 3838800] "AvgUi"="c:\program files (x86)\AVG\Framework\Common\avguix.exe" [2015-01-16 1140688] "Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2015-01-19 126712] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-11-24 702768] . c:\users\julia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Tintenwarnungen überwachen - HP Deskjet 3050A J611 series.lnk - c:\windows\system32\RunDll32.exe "c:\program files\HP\HP Deskjet 3050A J611 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN19D484NW05PJ;CONNECTION=USB;MONITOR=1; [2009-7-14 45568] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun "AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices "SwitchBoard"=c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe "AMD AVT"=Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "c:\program files (x86)\AMD AVT\bin\kdbsync.exe" aml "IAStorIcon"=c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" "HP Software Update"=c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x] R3 ggflt;SOMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x] R3 ggsomc;SOMC USB Flash Driver;c:\windows\system32\DRIVERS\ggsomc.sys;c:\windows\SYSNATIVE\DRIVERS\ggsomc.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe;c:\program files (x86)\Tunngle\TnglCtrl.exe [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AntiVirMailService;Avira Email-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x] S2 avgsvc;AVG Service;c:\program files (x86)\AVG\Framework\Common\avgsvca.exe;c:\program files (x86)\AVG\Framework\Common\avgsvca.exe [x] S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x] S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x] S2 CorsairSSDToolBox;Corsair SSD Toolbox;c:\program files (x86)\Corsair SSD Toolbox\CSSDTService.exe;c:\program files (x86)\Corsair SSD Toolbox\CSSDTService.exe [x] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x] S2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] S2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe;c:\windows\SYSNATIVE\Pen_Tablet.exe [x] S2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service;c:\program files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe;c:\program files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [x] S2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe;c:\program files\WTouch\WTouchService.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192se.sys [x] S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [x] S3 X10Hid;X10 Hid Device;c:\windows\system32\Drivers\x10hid.sys;c:\windows\SYSNATIVE\Drivers\x10hid.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2015-01-27 17:43 1086280 ----a-w- c:\program files (x86)\Google\Chrome\Application\40.0.2214.93\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2015-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20 16:07] . 2015-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20 16:07] . 2015-02-03 c:\windows\Tasks\HP Photo Creations Messager.job - c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11] . . --------- X64 Entries ----------- . . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MFAD356A7-D765-4D26-9751-007AAC60CF2E&SearchSource=55&CUI=&UM=5&UP=SPE0DF30FF-D716-44B8-B619-581937559E07&SSPV= mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKLM-Run-<NO NAME> - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\progra~2\COMMON~1\X10\Common\x10nets.exe c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe c:\program files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe c:\program files (x86)\Avira\AviraSpeedup\avira_system_speedup_internetsecuritysuite.exe . ************************************************************************** . Zeit der Fertigstellung: 2015-02-03 20:12:41 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2015-02-03 19:12 . Vor Suchlauf: 11 Verzeichnis(se), 133.636.886.528 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 133.880.360.960 Bytes frei . - - End Of File - - 3935CC444AE89CA1538E764EEA8A7A52 |
04.02.2015, 18:42 | #4 |
/// the machine /// TB-Ausbilder | Windows 7: ungültiges Bild (Error Meldung) Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.02.2015, 17:18 | #5 |
| Windows 7: ungültiges Bild (Error Meldung) Okay, hier bitte: 1. Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Protection, 06.02.2015 16:37:14, SYSTEM, JULIA-PC, Protection, Malware Protection, Starting, Protection, 06.02.2015 16:37:14, SYSTEM, JULIA-PC, Protection, Malware Protection, Started, Protection, 06.02.2015 16:37:14, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Starting, Update, 06.02.2015 16:37:14, SYSTEM, JULIA-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1, Update, 06.02.2015 16:37:14, SYSTEM, JULIA-PC, Manual, Rootkit Database, 2014.11.18.1, 2015.2.3.1, Protection, 06.02.2015 16:37:14, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Started, Update, 06.02.2015 16:37:20, SYSTEM, JULIA-PC, Manual, Malware Database, 2014.11.20.6, 2015.2.6.4, Protection, 06.02.2015 16:37:20, SYSTEM, JULIA-PC, Protection, Refresh, Starting, Protection, 06.02.2015 16:37:20, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Stopping, Protection, 06.02.2015 16:37:20, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Stopped, Protection, 06.02.2015 16:37:26, SYSTEM, JULIA-PC, Protection, Refresh, Success, Protection, 06.02.2015 16:37:26, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Starting, Protection, 06.02.2015 16:37:26, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Started, Update, 06.02.2015 16:39:26, SYSTEM, JULIA-PC, Scheduler, Malware Database, 2015.2.6.4, 2015.2.6.5, Protection, 06.02.2015 16:39:26, SYSTEM, JULIA-PC, Protection, Refresh, Starting, Protection, 06.02.2015 16:39:26, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Stopping, Protection, 06.02.2015 16:39:26, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Stopped, Protection, 06.02.2015 16:39:33, SYSTEM, JULIA-PC, Protection, Refresh, Success, Protection, 06.02.2015 16:39:33, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Starting, Protection, 06.02.2015 16:39:33, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Started, Scan, 06.02.2015 16:47:11, SYSTEM, JULIA-PC, Manual, Start: % 1 "% 2", Dauer: % 1 min 8 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, 9-Malwareerkennung, Protection, 06.02.2015 16:48:13, SYSTEM, JULIA-PC, Protection, Malware Protection, Starting, Protection, 06.02.2015 16:48:13, SYSTEM, JULIA-PC, Protection, Malware Protection, Started, Protection, 06.02.2015 16:48:13, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Starting, Protection, 06.02.2015 16:49:55, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Started, (end) Code:
ATTFilter # AdwCleaner v4.110 - Bericht erstellt 06/02/2015 um 16:57:32 # Aktualisiert 05/02/2015 von Xplode # Datenbank : 2015-02-05.2 [Server] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64) # Benutzername : julia - JULIA-PC # Gestarted von : C:\Users\julia\Downloads\AdwCleaner_4.110.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\julia\AppData\Roaming\RHEng ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17496 -\\ Google Chrome v40.0.2214.111 ************************* AdwCleaner[R0].txt - [1308 Bytes] - [06/02/2015 16:55:03] AdwCleaner[S0].txt - [1230 Bytes] - [06/02/2015 16:57:32] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1289 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.2 (02.02.2015:1) OS: Windows 7 Home Premium x64 Ran by julia on 06.02.2015 at 17:03:48,18 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 06.02.2015 at 17:08:01,41 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-02-2015 Ran by julia (administrator) on JULIA-PC on 06-02-2015 17:11:16 Running from C:\Users\julia\Downloads Loaded Profiles: julia (Available profiles: julia) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Wacom Technology, Corp.) C:\Program Files\WTouch\WTouchService.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Corsair) C:\Program Files (x86)\Corsair SSD Toolbox\CSSDTService.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Wacom Technology, Corp.) C:\Windows\System32\Pen_Tablet.exe (AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe (X10) C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe (Wacom Technology, Corp.) C:\Program Files\WTouch\WTouchUser.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup_internetsecuritysuite.exe (Thisisu) C:\Users\julia\Downloads\JRT.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\julia\Downloads\FRST64 (3).exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\reader_sl.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1814312 2009-08-14] (Synaptics Incorporated) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3838800 2014-12-13] (LogMeIn Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-11-24] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1140688 2015-01-16] (AVG Technologies CZ, s.r.o.) HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466144 2014-11-27] (Sony) HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30873192 2014-12-11] (Skype Technologies S.A.) Startup: C:\Users\julia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3050A J611 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3050A J611 series.lnk -> C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M8A738E8B-DA80-4CDC-ACA0-AE9E423A9290&SearchSource=55&CUI=&UM=8&UP=SPE0DF30FF-D716-44B8-B619-581937559E07&SSPV= CHR StartupUrls: Default -> "https://www.google.at/" CHR Profile: C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-20] CHR Extension: (Google Drive) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-20] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-07] CHR Extension: (YouTube) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-20] CHR Extension: (Google-Suche) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-20] CHR Extension: (Avira SafeSearch) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglgfnfolcgijipffhlhbbnefdcbjbml [2015-02-03] CHR Extension: (Google Wallet) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-20] CHR Extension: (Quilt) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofholagheebdhalaonjopcfcedggjooo [2014-05-30] CHR Extension: (Google Mail) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-20] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [807672 2014-11-24] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584 2014-11-24] (Avira Operations GmbH & Co. KG) R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [865744 2015-01-16] (AVG Technologies CZ, s.r.o.) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) R2 CorsairSSDToolBox; C:\Program Files (x86)\Corsair SSD Toolbox\CSSDTService.exe [1845864 2014-02-12] (Corsair) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2014-12-02] (LogMeIn, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2604344 2015-01-30] (AVG Technologies) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [762320 2015-01-17] (Tunngle.net GmbH) R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [44856 2015-01-30] (AVG Technologies) R2 UxTuneUp; C:\Windows\SysWOW64\uxtuneup.dll [36664 2015-01-30] (AVG Technologies) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 WTouchService; C:\Program Files\WTouch\WTouchService.exe [127784 2009-11-24] (Wacom Technology, Corp.) R2 x10nets; C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe [20480 2009-11-07] (X10) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-11-24] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-11-24] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [43064 2014-11-24] (Avira Operations GmbH & Co. KG) S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2014-08-18] (Sony Mobile Communications) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-06] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation) S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-22] (Realtek Semiconductor Corp.) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-11-24] (TuneUp Software) R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [15896 2009-05-13] (X10 Wireless Technology, Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-06 17:10 - 2015-02-06 17:11 - 02131968 _____ (Farbar) C:\Users\julia\Downloads\FRST64 (3).exe 2015-02-06 17:08 - 2015-02-06 17:08 - 00000625 _____ () C:\Users\julia\Desktop\JRT.txt 2015-02-06 17:03 - 2015-02-06 17:03 - 01388274 _____ (Thisisu) C:\Users\julia\Downloads\JRT.exe 2015-02-06 16:54 - 2015-02-06 16:57 - 00000000 ____D () C:\AdwCleaner 2015-02-06 16:54 - 2015-02-06 16:54 - 02112512 _____ () C:\Users\julia\Downloads\AdwCleaner_4.110.exe 2015-02-06 16:53 - 2015-02-06 16:53 - 00002612 _____ () C:\Users\julia\Desktop\mbam.txt 2015-02-06 16:37 - 2015-02-06 17:01 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-02-06 16:36 - 2015-02-06 16:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-02-06 16:36 - 2015-02-06 16:36 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-02-06 16:36 - 2015-02-06 16:36 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-02-06 16:36 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-02-06 16:36 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-02-06 16:36 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-02-06 16:35 - 2015-02-06 16:35 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\julia\Downloads\mbam-setup-2.0.4.1028.exe 2015-02-06 16:34 - 2015-01-30 17:22 - 00044856 _____ (AVG Technologies) C:\Windows\system32\uxtuneup.dll 2015-02-06 16:34 - 2015-01-30 17:22 - 00036664 _____ (AVG Technologies) C:\Windows\SysWOW64\uxtuneup.dll 2015-02-05 20:08 - 2015-02-05 20:08 - 00002762 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2015-02-04 16:30 - 2015-02-04 16:30 - 00000000 _____ () C:\Windows\setuperr.log 2015-02-04 14:22 - 2015-02-04 14:22 - 00002217 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015.lnk 2015-02-04 14:22 - 2015-02-04 14:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015 2015-02-04 14:22 - 2015-01-30 17:23 - 00041784 _____ (AVG Technologies) C:\Windows\system32\TURegOpt.exe 2015-02-04 14:22 - 2015-01-30 17:22 - 00030520 _____ (AVG Technologies) C:\Windows\system32\authuitu.dll 2015-02-04 14:22 - 2015-01-30 17:22 - 00025912 _____ (AVG Technologies) C:\Windows\SysWOW64\authuitu.dll 2015-02-04 14:21 - 2015-02-04 14:21 - 00000932 _____ () C:\Users\Public\Desktop\AVG.lnk 2015-02-04 14:21 - 2015-02-04 14:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen 2015-02-04 14:20 - 2015-02-04 14:20 - 16634392 _____ (AVG Technologies) C:\Users\julia\Downloads\avg_gse_stb_all_445p1_105.exe 2015-02-03 20:12 - 2015-02-03 20:12 - 00019801 _____ () C:\ComboFix.txt 2015-02-03 20:10 - 2015-02-04 13:57 - 00000000 ____D () C:\Users\julia\AppData\Roaming\WTouch 2015-02-03 20:10 - 2015-02-03 20:10 - 00000000 ____D () C:\Users\julia\AppData\Local\AviraSpeedup 2015-02-03 20:04 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-02-03 20:04 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-02-03 20:04 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-02-03 20:04 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-02-03 20:04 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-02-03 20:04 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2015-02-03 20:04 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2015-02-03 20:04 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2015-02-03 20:00 - 2015-02-03 20:12 - 00000000 ____D () C:\Qoobox 2015-02-03 20:00 - 2015-02-03 20:11 - 00000000 ____D () C:\Windows\erdnt 2015-02-03 19:59 - 2015-02-03 19:59 - 05611380 ____R (Swearware) C:\Users\julia\Downloads\ComboFix.exe 2015-02-03 19:56 - 2015-02-03 19:56 - 00001268 _____ () C:\Users\julia\Desktop\Revo Uninstaller.lnk 2015-02-03 19:55 - 2015-02-03 19:55 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\julia\Downloads\revosetup95 (1).exe 2015-02-03 19:22 - 2015-02-03 19:22 - 02131456 _____ (Farbar) C:\Users\julia\Downloads\FRST64 (2).exe 2015-02-03 18:48 - 2015-02-03 19:56 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-02-03 18:47 - 2015-02-03 18:47 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\julia\Downloads\revosetup95.exe 2015-02-03 18:43 - 2015-02-03 18:43 - 00003364 _____ () C:\Windows\System32\Tasks\AviraSpeedup 2015-02-03 18:43 - 2015-02-03 18:43 - 00001239 _____ () C:\Users\Public\Desktop\Avira System Speedup.lnk 2015-02-03 18:43 - 2015-02-03 18:43 - 00000000 ____D () C:\Users\julia\AppData\Roaming\Avira 2015-02-03 18:43 - 2015-02-03 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviraSpeedup 2015-02-03 18:42 - 2014-11-24 10:23 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-02-03 18:42 - 2014-11-24 10:23 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-02-03 18:42 - 2014-11-24 10:23 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2015-02-03 18:42 - 2014-11-24 10:23 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2015-02-03 18:39 - 2015-02-03 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-03 18:39 - 2015-02-03 18:42 - 00000000 ____D () C:\ProgramData\Avira 2015-02-03 18:39 - 2015-02-03 18:39 - 04515896 _____ (Avira Operations & Co. KG) C:\Users\julia\Downloads\avira_de_issuse_3002988189_7iomicq1hqlm0h0551hj_wd.exe 2015-02-03 18:39 - 2015-02-03 18:39 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk 2015-02-03 18:39 - 2015-02-03 18:39 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-03 18:30 - 2015-02-03 18:30 - 00025804 _____ () C:\Users\julia\Downloads\Addition.txt 2015-02-03 18:29 - 2015-02-06 17:11 - 00015121 _____ () C:\Users\julia\Downloads\FRST.txt 2015-02-03 18:29 - 2015-02-06 17:11 - 00000000 ____D () C:\FRST 2015-02-03 18:29 - 2015-02-03 18:29 - 02131456 _____ (Farbar) C:\Users\julia\Downloads\FRST64 (1).exe 2015-02-02 20:10 - 2015-02-02 20:10 - 02131456 _____ (Farbar) C:\Users\julia\Downloads\FRST64.exe 2015-02-02 17:50 - 2015-02-02 17:50 - 00000000 ____D () C:\Users\julia\AppData\Roaming\AVG 2015-02-02 17:48 - 2015-02-04 14:21 - 00000000 ____D () C:\ProgramData\Avg 2015-02-02 17:48 - 2015-02-04 14:21 - 00000000 ____D () C:\Program Files (x86)\AVG 2015-02-02 17:47 - 2015-02-04 14:21 - 00000000 ____D () C:\Users\julia\AppData\Local\AvgSetupLog 2015-02-02 17:47 - 2015-02-02 17:50 - 00000000 ____D () C:\Users\julia\AppData\Local\Avg 2015-02-02 17:47 - 2015-02-02 17:47 - 16634392 _____ (AVG Technologies) C:\Users\julia\Downloads\avg_gse_stb_all_445p1_143.exe 2015-02-01 12:34 - 2014-06-16 12:13 - 00043320 _____ (TuneUp Software) C:\Windows\system32\uxt5050.tmp 2015-02-01 12:33 - 2015-02-01 12:33 - 00000000 ____D () C:\Users\julia\AppData\Local\TuneUp Software 2015-02-01 12:32 - 2015-02-01 12:32 - 00001536 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk 2015-02-01 12:32 - 2015-02-01 12:32 - 00001245 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2015-02-01 12:32 - 2015-02-01 12:32 - 00000238 _____ () C:\Users\julia\updhelper.xml 2015-02-01 12:32 - 2015-02-01 12:32 - 00000008 _____ () C:\Users\julia\updhelper.xml.lck 2015-02-01 12:32 - 2015-02-01 12:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-02-01 12:31 - 2015-02-01 12:32 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2015-02-01 12:31 - 2015-02-01 12:31 - 00000000 ____D () C:\Program Files (x86)\Free Codec Pack 2015-02-01 12:30 - 2015-02-01 12:30 - 34792128 _____ (DVDVideoSoft Ltd. ) C:\Users\julia\Downloads\FreeYouTubeToMP354Converter.exe 2015-01-24 18:12 - 2015-01-24 18:12 - 00343552 _____ (Microsoft) C:\Users\julia\Downloads\BA-ReDi4u_Offline (1).exe 2015-01-24 18:08 - 2015-01-24 18:08 - 00343552 _____ (Microsoft) C:\Users\julia\Downloads\BA-ReDi4u_Offline.exe 2015-01-18 17:25 - 2015-01-18 19:26 - 00000000 ____D () C:\Users\julia\AppData\Roaming\Tunngle 2015-01-18 17:25 - 2015-01-18 19:26 - 00000000 ____D () C:\ProgramData\Tunngle 2015-01-18 17:25 - 2015-01-18 17:26 - 00000000 ____D () C:\Program Files (x86)\Tunngle 2015-01-18 17:25 - 2015-01-18 17:25 - 00000995 _____ () C:\Users\Public\Desktop\Tunngle.lnk 2015-01-18 17:25 - 2015-01-18 17:25 - 00000000 ____D () C:\Users\Public\Documents\Tunngle 2015-01-18 17:25 - 2015-01-18 17:25 - 00000000 ____D () C:\Users\julia\Documents\Tunngle 2015-01-18 17:25 - 2015-01-18 17:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle 2015-01-18 17:25 - 2009-09-16 07:02 - 00031232 _____ (Tunngle.net) C:\Windows\system32\Drivers\tap0901t.sys 2015-01-18 17:23 - 2015-01-18 17:23 - 04501720 _____ (Tunngle.net GmbH ) C:\Users\julia\Downloads\Tunngle_Setupv5.0.exe 2015-01-14 20:41 - 2015-01-14 20:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2015-01-14 20:41 - 2015-01-14 20:41 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi 2015-01-14 20:30 - 2015-01-23 17:27 - 00000000 ____D () C:\Users\julia\AppData\Roaming\.minecraft 2015-01-14 20:30 - 2015-01-14 20:30 - 00000000 ____D () C:\Users\julia\AppData\Roaming\java 2015-01-14 20:29 - 2015-01-30 17:23 - 00000000 ____D () C:\Program Files (x86)\Minecraft 2015-01-14 20:29 - 2015-01-14 20:29 - 02318336 _____ () C:\Users\julia\Downloads\MinecraftInstaller.msi 2015-01-14 20:29 - 2015-01-14 20:29 - 00000961 _____ () C:\Users\Public\Desktop\Minecraft.lnk 2015-01-14 20:29 - 2015-01-14 20:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft 2015-01-14 16:29 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 16:29 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 16:29 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-14 16:29 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-01-14 16:29 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-01-14 16:29 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-01-14 16:29 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-01-14 16:29 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-01-14 16:29 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-01-14 16:29 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-14 16:29 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 16:29 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-14 16:29 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-06 17:08 - 2009-07-14 05:45 - 00016304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-06 17:08 - 2009-07-14 05:45 - 00016304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-06 17:03 - 2009-07-14 18:58 - 00700800 _____ () C:\Windows\system32\perfh007.dat 2015-02-06 17:03 - 2009-07-14 18:58 - 00149668 _____ () C:\Windows\system32\perfc007.dat 2015-02-06 17:03 - 2009-07-14 06:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-06 17:02 - 2014-03-22 15:53 - 00000000 ____D () C:\Users\julia\AppData\Roaming\Skype 2015-02-06 17:01 - 2014-04-02 21:00 - 00000256 _____ () C:\Windows\Tasks\HP Photo Creations Messager.job 2015-02-06 17:01 - 2014-03-22 18:39 - 00000000 ____D () C:\Users\julia\AppData\Local\LogMeIn Hamachi 2015-02-06 16:59 - 2014-03-20 17:07 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-06 16:58 - 2014-03-22 09:20 - 00075929 _____ () C:\Windows\setupact.log 2015-02-06 16:58 - 2014-03-22 09:19 - 00133092 _____ () C:\Windows\PFRO.log 2015-02-06 16:58 - 2014-03-20 16:42 - 01122246 _____ () C:\Windows\WindowsUpdate.log 2015-02-06 16:58 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-06 16:48 - 2014-03-20 17:07 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-06 16:47 - 2014-03-20 17:07 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-02-06 16:47 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2015-02-06 15:57 - 2014-05-04 11:06 - 00000000 ____D () C:\Users\julia\AppData\Roaming\WTablet 2015-02-04 14:48 - 2014-10-25 19:04 - 00000000 ____D () C:\Windows\Minidump 2015-02-04 14:48 - 2014-07-17 17:35 - 00000000 ____D () C:\Program Files (x86)\Steam 2015-02-04 14:48 - 2014-04-02 20:59 - 00000000 ____D () C:\Users\julia\AppData\Roaming\HpUpdate 2015-02-04 14:48 - 2014-03-21 16:01 - 00000000 ____D () C:\Users\julia\Documents\Youcam 2015-02-04 14:48 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sysprep 2015-02-03 20:12 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2015-02-03 20:10 - 2014-03-20 17:06 - 00087336 _____ () C:\Users\julia\AppData\Local\GDIPFONTCACHEV1.DAT 2015-02-03 20:10 - 2009-07-14 05:45 - 04903592 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-02-03 20:10 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2015-02-03 18:43 - 2014-03-20 16:46 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-02-02 18:55 - 2014-03-20 16:39 - 00000000 ____D () C:\Users\julia 2015-02-02 18:55 - 2009-07-14 03:34 - 72876032 _____ () C:\Windows\system32\config\SOFTWARE_tureg_old 2015-02-02 18:55 - 2009-07-14 03:34 - 17039360 _____ () C:\Windows\system32\config\SYSTEM_tureg_old 2015-02-02 18:55 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY_tureg_old 2015-02-02 18:51 - 2009-07-14 03:34 - 52953088 _____ () C:\Windows\system32\config\COMPONENTS_tureg_old 2015-02-02 18:51 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM_tureg_old 2015-02-02 18:51 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\DEFAULT_tureg_old 2015-02-02 17:50 - 2014-03-20 16:39 - 00000000 ____D () C:\Users\julia\AppData\Local\VirtualStore 2015-02-01 12:33 - 2014-03-20 19:09 - 00000000 ____D () C:\Users\julia\AppData\Roaming\TuneUp Software 2015-02-01 12:33 - 2014-03-20 19:09 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-02-01 12:33 - 2014-03-20 19:09 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2013 2015-02-01 12:32 - 2014-05-30 07:57 - 00000000 ____D () C:\Users\julia\AppData\Roaming\DVDVideoSoft 2015-01-21 18:21 - 2014-08-18 20:04 - 00278270 _____ () C:\Windows\DPINST.LOG 2015-01-21 18:21 - 2014-08-18 20:03 - 00002026 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2015-01-21 18:21 - 2014-08-18 20:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony 2015-01-21 18:21 - 2014-03-20 22:55 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-01-14 22:56 - 2014-03-20 17:34 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-14 22:53 - 2014-03-20 17:34 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-01-07 17:10 - 2014-08-18 20:06 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile 2015-01-07 12:53 - 2014-03-22 15:53 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-01-07 12:53 - 2014-03-22 15:53 - 00000000 ____D () C:\ProgramData\Skype ==================== Files in the root of some directories ======= 2014-05-04 13:16 - 2014-08-11 16:26 - 0000132 _____ () C:\Users\julia\AppData\Roaming\Adobe PNG Format CS5 Prefs 2014-03-20 23:10 - 2014-03-21 16:42 - 0007605 _____ () C:\Users\julia\AppData\Local\Resmon.ResmonCfg 2014-04-02 20:58 - 2014-04-02 20:58 - 0000057 _____ () C:\ProgramData\Ament.ini Some content of TEMP: ==================== C:\Users\julia\AppData\Local\Temp\avgnt.exe C:\Users\julia\AppData\Local\Temp\DseShExt-x64.dll C:\Users\julia\AppData\Local\Temp\DseShExt-x86.dll C:\Users\julia\AppData\Local\Temp\Quarantine.exe C:\Users\julia\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\julia\AppData\Local\Temp\SDShelEx-x64.dll C:\Users\julia\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-05 19:01 ==================== End Of Log ============================ --- --- --- |
07.02.2015, 11:33 | #6 |
/// the machine /// TB-Ausbilder | Windows 7: ungültiges Bild (Error Meldung)ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Windows 7: ungültiges Bild (Error Meldung) |
07.02.2015, 19:22 | #7 |
| Windows 7: ungültiges Bild (Error Meldung)Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=c221687b49a8bb428fbe0a8d62536f53 # engine=22356 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-02-07 06:03:20 # local_time=2015-02-07 07:03:20 (+0100, Mitteleuropäische Zeit) # country="Austria" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 347878 174962050 0 0 # scanned=180001 # found=10 # cleaned=0 # scan_time=3532 sh=43F36CBCD2BE0AB181A17FFD9806DEEA94D6D27A ft=1 fh=53c5f979c7bf21cf vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\julia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CMG2MAVY\Setup[1].exe" sh=ED3463A7DB95D4B0A40B18FF7D4C3A198AFE9C87 ft=1 fh=b73262d5706d13f5 vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\julia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RU0EBF1E\Stub[1].exe" sh=0CB43200BA49B352AAD0BF5899A1B24763FA1119 ft=1 fh=75e8bdb400cebfdb vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\julia\Downloads\FreeYouTubeToMp3Converter.exe" sh=3837DCC6FC0D2C7D2CD6765EE18175468E314815 ft=1 fh=404bf2cda126427a vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\julia\Downloads\FreeYouTubeToMP3Converter31126(1).exe" sh=3837DCC6FC0D2C7D2CD6765EE18175468E314815 ft=1 fh=404bf2cda126427a vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\julia\Downloads\FreeYouTubeToMP3Converter31126.exe" sh=E8CD33623287C08C7CC3662A042E45522654BB30 ft=1 fh=7cd3b160b0dbd4bd vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\julia\Downloads\FreeYouTubeToMP3Converter37.exe" sh=20BA51F96F4EA5423FC90E17F635791D97DA4D44 ft=1 fh=c8ec0d8ad2660144 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\julia\Downloads\FreeYouTubeToMp3Converter3820.exe" sh=7D71FB7993C688DBF65C7F0E58DBA53DDF79F54A ft=1 fh=cb519e2c8557bf3c vn="Variante von Win32/Downloader.JooSoft.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\julia\Downloads\pbsetup.exe" sh=BC27FA0154EBA2A700571E391247A47D7A11823A ft=1 fh=5f8499be83172a25 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\julia\Downloads\xfire_installer_45547.exe" sh=6994FC133F3D99F1B1257370C9BC01BD54AF5D30 ft=1 fh=d1eb868415c0b931 vn="Variante von Win32/Toolbar.Conduit.AI evtl. unerwünschte Anwendung" ac=I fn="C:\Users\julia\Downloads\zaSetup_92_058_000_de.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.95 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` AVG PC TuneUp 2015 AVG PC TuneUp 2015 (de-DE) AVG PC TuneUp 2015 TuneUp Utilities Language Pack (de-DE) Java 64-bit 8 Update 31 Adobe Reader XI Google Chrome (40.0.2214.111) Google Chrome (40.0.2214.94) ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-02-2015 Ran by julia (administrator) on JULIA-PC on 07-02-2015 19:19:30 Running from C:\Users\julia\Downloads Loaded Profiles: julia (Available profiles: julia) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Wacom Technology, Corp.) C:\Program Files\WTouch\WTouchService.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Corsair) C:\Program Files (x86)\Corsair SSD Toolbox\CSSDTService.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Wacom Technology, Corp.) C:\Windows\System32\Pen_Tablet.exe (AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe (X10) C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe (Wacom Technology, Corp.) C:\Program Files\WTouch\WTouchUser.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe (Wacom Technology, Corp.) C:\Windows\System32\WTablet\Pen_TabletUser.exe (Wacom Technology, Corp.) C:\Windows\System32\Pen_Tablet.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup_internetsecuritysuite.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Farbar) C:\Users\julia\Downloads\FRST64 (4).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1814312 2009-08-14] (Synaptics Incorporated) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-01-27] (Apple Inc.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3838800 2014-12-13] (LogMeIn Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-11-24] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1140688 2015-01-16] (AVG Technologies CZ, s.r.o.) HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466144 2014-11-27] (Sony) HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30873192 2014-12-11] (Skype Technologies S.A.) Startup: C:\Users\julia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3050A J611 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3050A J611 series.lnk -> C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M8A738E8B-DA80-4CDC-ACA0-AE9E423A9290&SearchSource=55&CUI=&UM=8&UP=SPE0DF30FF-D716-44B8-B619-581937559E07&SSPV= CHR StartupUrls: Default -> "https://www.google.at/" CHR Profile: C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-20] CHR Extension: (Google Drive) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-20] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-07] CHR Extension: (YouTube) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-20] CHR Extension: (Google-Suche) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-20] CHR Extension: (Avira SafeSearch) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglgfnfolcgijipffhlhbbnefdcbjbml [2015-02-03] CHR Extension: (Google Wallet) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-20] CHR Extension: (Quilt) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofholagheebdhalaonjopcfcedggjooo [2014-05-30] CHR Extension: (Google Mail) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-20] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [807672 2014-11-24] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584 2014-11-24] (Avira Operations GmbH & Co. KG) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.) R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [865744 2015-01-16] (AVG Technologies CZ, s.r.o.) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) R2 CorsairSSDToolBox; C:\Program Files (x86)\Corsair SSD Toolbox\CSSDTService.exe [1845864 2014-02-12] (Corsair) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2014-12-02] (LogMeIn, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2604344 2015-01-30] (AVG Technologies) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [762320 2015-01-17] (Tunngle.net GmbH) R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [44856 2015-01-30] (AVG Technologies) R2 UxTuneUp; C:\Windows\SysWOW64\uxtuneup.dll [36664 2015-01-30] (AVG Technologies) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 WTouchService; C:\Program Files\WTouch\WTouchService.exe [127784 2009-11-24] (Wacom Technology, Corp.) R2 x10nets; C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe [20480 2009-11-07] (X10) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-11-24] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-11-24] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [43064 2014-11-24] (Avira Operations GmbH & Co. KG) S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2014-08-18] (Sony Mobile Communications) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-07] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation) S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-22] (Realtek Semiconductor Corp.) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-11-24] (TuneUp Software) R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [15896 2009-05-13] (X10 Wireless Technology, Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-07 19:19 - 2015-02-07 19:19 - 02132992 _____ (Farbar) C:\Users\julia\Downloads\FRST64 (4).exe 2015-02-07 19:15 - 2015-02-07 19:15 - 00852573 _____ () C:\Users\julia\Downloads\SecurityCheck.exe 2015-02-07 18:01 - 2015-02-07 18:01 - 02347384 _____ (ESET) C:\Users\julia\Downloads\esetsmartinstaller_deu.exe 2015-02-07 09:35 - 2015-02-07 09:35 - 00001753 _____ () C:\Users\Public\Desktop\iTunes.lnk 2015-02-07 09:35 - 2015-02-07 09:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-02-07 09:35 - 2015-02-07 09:35 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-02-07 09:35 - 2015-02-07 09:35 - 00000000 ____D () C:\Program Files\iTunes 2015-02-07 09:35 - 2015-02-07 09:35 - 00000000 ____D () C:\Program Files\iPod 2015-02-07 09:35 - 2015-02-07 09:35 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-02-06 17:10 - 2015-02-06 17:11 - 02131968 _____ (Farbar) C:\Users\julia\Downloads\FRST64 (3).exe 2015-02-06 17:03 - 2015-02-06 17:03 - 01388274 _____ (Thisisu) C:\Users\julia\Downloads\JRT.exe 2015-02-06 16:54 - 2015-02-06 16:57 - 00000000 ____D () C:\AdwCleaner 2015-02-06 16:54 - 2015-02-06 16:54 - 02112512 _____ () C:\Users\julia\Downloads\AdwCleaner_4.110.exe 2015-02-06 16:37 - 2015-02-07 17:53 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-02-06 16:36 - 2015-02-06 16:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-02-06 16:36 - 2015-02-06 16:36 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-02-06 16:36 - 2015-02-06 16:36 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-02-06 16:36 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-02-06 16:36 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-02-06 16:36 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-02-06 16:35 - 2015-02-06 16:35 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\julia\Downloads\mbam-setup-2.0.4.1028.exe 2015-02-06 16:34 - 2015-01-30 17:22 - 00044856 _____ (AVG Technologies) C:\Windows\system32\uxtuneup.dll 2015-02-06 16:34 - 2015-01-30 17:22 - 00036664 _____ (AVG Technologies) C:\Windows\SysWOW64\uxtuneup.dll 2015-02-05 20:08 - 2015-02-05 20:08 - 00002762 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2015-02-04 16:30 - 2015-02-04 16:30 - 00000000 _____ () C:\Windows\setuperr.log 2015-02-04 14:22 - 2015-02-04 14:22 - 00002217 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015.lnk 2015-02-04 14:22 - 2015-02-04 14:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015 2015-02-04 14:22 - 2015-01-30 17:23 - 00041784 _____ (AVG Technologies) C:\Windows\system32\TURegOpt.exe 2015-02-04 14:22 - 2015-01-30 17:22 - 00030520 _____ (AVG Technologies) C:\Windows\system32\authuitu.dll 2015-02-04 14:22 - 2015-01-30 17:22 - 00025912 _____ (AVG Technologies) C:\Windows\SysWOW64\authuitu.dll 2015-02-04 14:21 - 2015-02-04 14:21 - 00000932 _____ () C:\Users\Public\Desktop\AVG.lnk 2015-02-04 14:21 - 2015-02-04 14:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen 2015-02-04 14:20 - 2015-02-04 14:20 - 16634392 _____ (AVG Technologies) C:\Users\julia\Downloads\avg_gse_stb_all_445p1_105.exe 2015-02-03 20:12 - 2015-02-03 20:12 - 00019801 _____ () C:\ComboFix.txt 2015-02-03 20:10 - 2015-02-04 13:57 - 00000000 ____D () C:\Users\julia\AppData\Roaming\WTouch 2015-02-03 20:10 - 2015-02-03 20:10 - 00000000 ____D () C:\Users\julia\AppData\Local\AviraSpeedup 2015-02-03 20:04 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-02-03 20:04 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-02-03 20:04 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-02-03 20:04 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-02-03 20:04 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-02-03 20:04 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2015-02-03 20:04 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2015-02-03 20:04 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2015-02-03 20:00 - 2015-02-03 20:12 - 00000000 ____D () C:\Qoobox 2015-02-03 20:00 - 2015-02-03 20:11 - 00000000 ____D () C:\Windows\erdnt 2015-02-03 19:59 - 2015-02-03 19:59 - 05611380 ____R (Swearware) C:\Users\julia\Downloads\ComboFix.exe 2015-02-03 19:56 - 2015-02-03 19:56 - 00001268 _____ () C:\Users\julia\Desktop\Revo Uninstaller.lnk 2015-02-03 19:55 - 2015-02-03 19:55 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\julia\Downloads\revosetup95 (1).exe 2015-02-03 19:22 - 2015-02-03 19:22 - 02131456 _____ (Farbar) C:\Users\julia\Downloads\FRST64 (2).exe 2015-02-03 18:48 - 2015-02-03 19:56 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-02-03 18:47 - 2015-02-03 18:47 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\julia\Downloads\revosetup95.exe 2015-02-03 18:43 - 2015-02-03 18:43 - 00003364 _____ () C:\Windows\System32\Tasks\AviraSpeedup 2015-02-03 18:43 - 2015-02-03 18:43 - 00001239 _____ () C:\Users\Public\Desktop\Avira System Speedup.lnk 2015-02-03 18:43 - 2015-02-03 18:43 - 00000000 ____D () C:\Users\julia\AppData\Roaming\Avira 2015-02-03 18:43 - 2015-02-03 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviraSpeedup 2015-02-03 18:42 - 2014-11-24 10:23 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-02-03 18:42 - 2014-11-24 10:23 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-02-03 18:42 - 2014-11-24 10:23 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2015-02-03 18:42 - 2014-11-24 10:23 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2015-02-03 18:39 - 2015-02-03 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-03 18:39 - 2015-02-03 18:42 - 00000000 ____D () C:\ProgramData\Avira 2015-02-03 18:39 - 2015-02-03 18:39 - 04515896 _____ (Avira Operations & Co. KG) C:\Users\julia\Downloads\avira_de_issuse_3002988189_7iomicq1hqlm0h0551hj_wd.exe 2015-02-03 18:39 - 2015-02-03 18:39 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk 2015-02-03 18:39 - 2015-02-03 18:39 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-03 18:30 - 2015-02-03 18:30 - 00025804 _____ () C:\Users\julia\Downloads\Addition.txt 2015-02-03 18:29 - 2015-02-07 19:19 - 00015801 _____ () C:\Users\julia\Downloads\FRST.txt 2015-02-03 18:29 - 2015-02-07 19:19 - 00000000 ____D () C:\FRST 2015-02-03 18:29 - 2015-02-03 18:29 - 02131456 _____ (Farbar) C:\Users\julia\Downloads\FRST64 (1).exe 2015-02-02 20:10 - 2015-02-02 20:10 - 02131456 _____ (Farbar) C:\Users\julia\Downloads\FRST64.exe 2015-02-02 17:50 - 2015-02-02 17:50 - 00000000 ____D () C:\Users\julia\AppData\Roaming\AVG 2015-02-02 17:48 - 2015-02-04 14:21 - 00000000 ____D () C:\ProgramData\Avg 2015-02-02 17:48 - 2015-02-04 14:21 - 00000000 ____D () C:\Program Files (x86)\AVG 2015-02-02 17:47 - 2015-02-04 14:21 - 00000000 ____D () C:\Users\julia\AppData\Local\AvgSetupLog 2015-02-02 17:47 - 2015-02-02 17:50 - 00000000 ____D () C:\Users\julia\AppData\Local\Avg 2015-02-02 17:47 - 2015-02-02 17:47 - 16634392 _____ (AVG Technologies) C:\Users\julia\Downloads\avg_gse_stb_all_445p1_143.exe 2015-02-01 12:34 - 2014-06-16 12:13 - 00043320 _____ (TuneUp Software) C:\Windows\system32\uxt5050.tmp 2015-02-01 12:33 - 2015-02-01 12:33 - 00000000 ____D () C:\Users\julia\AppData\Local\TuneUp Software 2015-02-01 12:32 - 2015-02-01 12:32 - 00001536 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk 2015-02-01 12:32 - 2015-02-01 12:32 - 00001245 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2015-02-01 12:32 - 2015-02-01 12:32 - 00000238 _____ () C:\Users\julia\updhelper.xml 2015-02-01 12:32 - 2015-02-01 12:32 - 00000008 _____ () C:\Users\julia\updhelper.xml.lck 2015-02-01 12:32 - 2015-02-01 12:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-02-01 12:31 - 2015-02-01 12:32 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2015-02-01 12:31 - 2015-02-01 12:31 - 00000000 ____D () C:\Program Files (x86)\Free Codec Pack 2015-02-01 12:30 - 2015-02-01 12:30 - 34792128 _____ (DVDVideoSoft Ltd. ) C:\Users\julia\Downloads\FreeYouTubeToMP354Converter.exe 2015-01-24 18:12 - 2015-01-24 18:12 - 00343552 _____ (Microsoft) C:\Users\julia\Downloads\BA-ReDi4u_Offline (1).exe 2015-01-24 18:08 - 2015-01-24 18:08 - 00343552 _____ (Microsoft) C:\Users\julia\Downloads\BA-ReDi4u_Offline.exe 2015-01-18 17:25 - 2015-01-18 19:26 - 00000000 ____D () C:\Users\julia\AppData\Roaming\Tunngle 2015-01-18 17:25 - 2015-01-18 19:26 - 00000000 ____D () C:\ProgramData\Tunngle 2015-01-18 17:25 - 2015-01-18 17:26 - 00000000 ____D () C:\Program Files (x86)\Tunngle 2015-01-18 17:25 - 2015-01-18 17:25 - 00000995 _____ () C:\Users\Public\Desktop\Tunngle.lnk 2015-01-18 17:25 - 2015-01-18 17:25 - 00000000 ____D () C:\Users\Public\Documents\Tunngle 2015-01-18 17:25 - 2015-01-18 17:25 - 00000000 ____D () C:\Users\julia\Documents\Tunngle 2015-01-18 17:25 - 2015-01-18 17:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle 2015-01-18 17:25 - 2009-09-16 07:02 - 00031232 _____ (Tunngle.net) C:\Windows\system32\Drivers\tap0901t.sys 2015-01-18 17:23 - 2015-01-18 17:23 - 04501720 _____ (Tunngle.net GmbH ) C:\Users\julia\Downloads\Tunngle_Setupv5.0.exe 2015-01-14 20:41 - 2015-01-14 20:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2015-01-14 20:41 - 2015-01-14 20:41 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi 2015-01-14 20:30 - 2015-01-23 17:27 - 00000000 ____D () C:\Users\julia\AppData\Roaming\.minecraft 2015-01-14 20:30 - 2015-01-14 20:30 - 00000000 ____D () C:\Users\julia\AppData\Roaming\java 2015-01-14 20:29 - 2015-01-30 17:23 - 00000000 ____D () C:\Program Files (x86)\Minecraft 2015-01-14 20:29 - 2015-01-14 20:29 - 02318336 _____ () C:\Users\julia\Downloads\MinecraftInstaller.msi 2015-01-14 20:29 - 2015-01-14 20:29 - 00000961 _____ () C:\Users\Public\Desktop\Minecraft.lnk 2015-01-14 20:29 - 2015-01-14 20:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft 2015-01-14 16:29 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 16:29 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 16:29 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-14 16:29 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-01-14 16:29 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-01-14 16:29 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-01-14 16:29 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-01-14 16:29 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-01-14 16:29 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-01-14 16:29 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-14 16:29 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 16:29 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-14 16:29 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-07 19:19 - 2014-03-22 15:53 - 00000000 ____D () C:\Users\julia\AppData\Roaming\Skype 2015-02-07 19:14 - 2014-03-22 18:39 - 00000000 ____D () C:\Users\julia\AppData\Local\LogMeIn Hamachi 2015-02-07 19:12 - 2014-03-20 16:42 - 01194794 _____ () C:\Windows\WindowsUpdate.log 2015-02-07 19:01 - 2014-04-02 21:00 - 00000256 _____ () C:\Windows\Tasks\HP Photo Creations Messager.job 2015-02-07 18:49 - 2014-03-20 17:07 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-07 17:26 - 2009-07-14 05:45 - 00016304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-07 17:26 - 2009-07-14 05:45 - 00016304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-07 17:25 - 2009-07-14 18:58 - 00700800 _____ () C:\Windows\system32\perfh007.dat 2015-02-07 17:25 - 2009-07-14 18:58 - 00149668 _____ () C:\Windows\system32\perfc007.dat 2015-02-07 17:25 - 2009-07-14 06:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-07 17:19 - 2014-03-22 09:20 - 00076601 _____ () C:\Windows\setupact.log 2015-02-07 17:18 - 2014-05-04 11:06 - 00000000 ____D () C:\Users\julia\AppData\Roaming\WTablet 2015-02-07 17:18 - 2014-03-20 17:07 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-07 17:18 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-07 09:44 - 2014-03-20 17:07 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-07 09:44 - 2014-03-20 17:07 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-07 09:35 - 2014-03-22 17:25 - 00000000 ____D () C:\Program Files\Common Files\Apple 2015-02-06 16:58 - 2014-03-22 09:19 - 00133092 _____ () C:\Windows\PFRO.log 2015-02-06 16:47 - 2014-03-20 17:07 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-02-06 16:47 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2015-02-04 14:48 - 2014-10-25 19:04 - 00000000 ____D () C:\Windows\Minidump 2015-02-04 14:48 - 2014-07-17 17:35 - 00000000 ____D () C:\Program Files (x86)\Steam 2015-02-04 14:48 - 2014-04-02 20:59 - 00000000 ____D () C:\Users\julia\AppData\Roaming\HpUpdate 2015-02-04 14:48 - 2014-03-21 16:01 - 00000000 ____D () C:\Users\julia\Documents\Youcam 2015-02-04 14:48 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sysprep 2015-02-03 20:12 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2015-02-03 20:10 - 2014-03-20 17:06 - 00087336 _____ () C:\Users\julia\AppData\Local\GDIPFONTCACHEV1.DAT 2015-02-03 20:10 - 2009-07-14 05:45 - 04903592 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-02-03 20:10 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2015-02-03 18:43 - 2014-03-20 16:46 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-02-02 18:55 - 2014-03-20 16:39 - 00000000 ____D () C:\Users\julia 2015-02-02 18:55 - 2009-07-14 03:34 - 72876032 _____ () C:\Windows\system32\config\SOFTWARE_tureg_old 2015-02-02 18:55 - 2009-07-14 03:34 - 17039360 _____ () C:\Windows\system32\config\SYSTEM_tureg_old 2015-02-02 18:55 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY_tureg_old 2015-02-02 18:51 - 2009-07-14 03:34 - 52953088 _____ () C:\Windows\system32\config\COMPONENTS_tureg_old 2015-02-02 18:51 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM_tureg_old 2015-02-02 18:51 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\DEFAULT_tureg_old 2015-02-02 17:50 - 2014-03-20 16:39 - 00000000 ____D () C:\Users\julia\AppData\Local\VirtualStore 2015-02-01 12:33 - 2014-03-20 19:09 - 00000000 ____D () C:\Users\julia\AppData\Roaming\TuneUp Software 2015-02-01 12:33 - 2014-03-20 19:09 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-02-01 12:33 - 2014-03-20 19:09 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2013 2015-02-01 12:32 - 2014-05-30 07:57 - 00000000 ____D () C:\Users\julia\AppData\Roaming\DVDVideoSoft 2015-01-21 18:21 - 2014-08-18 20:04 - 00278270 _____ () C:\Windows\DPINST.LOG 2015-01-21 18:21 - 2014-08-18 20:03 - 00002026 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2015-01-21 18:21 - 2014-08-18 20:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony 2015-01-21 18:21 - 2014-03-20 22:55 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-01-14 22:56 - 2014-03-20 17:34 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-14 22:53 - 2014-03-20 17:34 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe ==================== Files in the root of some directories ======= 2014-05-04 13:16 - 2014-08-11 16:26 - 0000132 _____ () C:\Users\julia\AppData\Roaming\Adobe PNG Format CS5 Prefs 2014-03-20 23:10 - 2014-03-21 16:42 - 0007605 _____ () C:\Users\julia\AppData\Local\Resmon.ResmonCfg 2014-04-02 20:58 - 2014-04-02 20:58 - 0000057 _____ () C:\ProgramData\Ament.ini Some content of TEMP: ==================== C:\Users\julia\AppData\Local\Temp\avgnt.exe C:\Users\julia\AppData\Local\Temp\DseShExt-x64.dll C:\Users\julia\AppData\Local\Temp\DseShExt-x86.dll C:\Users\julia\AppData\Local\Temp\Quarantine.exe C:\Users\julia\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\julia\AppData\Local\Temp\SDShelEx-x64.dll C:\Users\julia\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-05 19:01 ==================== End Of Log ============================ --- --- --- So gemacht. Ne, also weitere Probleme hab ich bisher nicht und da bin ich auch froh drüber! Aber falls wieder was sein sollte, weiß ich ja mittlerweile, wo ich mich melden muss ;D |
08.02.2015, 11:24 | #8 |
/// the machine /// TB-Ausbilder | Windows 7: ungültiges Bild (Error Meldung) Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\julia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CMG2MAVY\Setup[1].exe C:\Users\julia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RU0EBF1E\Stub[1].exe C:\Users\julia\Downloads\FreeYouTubeToMp3Converter.exe C:\Users\julia\Downloads\FreeYouTubeToMP3Converter31126(1).exe C:\Users\julia\Downloads\FreeYouTubeToMP3Converter31126.exe C:\Users\julia\Downloads\FreeYouTubeToMP3Converter37.exe C:\Users\julia\Downloads\FreeYouTubeToMp3Converter3820.exe C:\Users\julia\Downloads\pbsetup.exe C:\Users\julia\Downloads\xfire_installer_45547.exe C:\Users\julia\Downloads\zaSetup_92_058_000_de.exe Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.02.2015, 16:34 | #9 |
| Windows 7: ungültiges Bild (Error Meldung) Also ich hab das gemacht, allerdings hab ich kein Fixlog.txt. gefunden. Was genau soll ich jetzt machen? Ich hoffe mal, das ist kein schlechtes Omen. |
09.02.2015, 18:19 | #10 |
/// the machine /// TB-Ausbilder | Windows 7: ungültiges Bild (Error Meldung) Das Fixlog liegt am gleichen Ort wie FRST, aber auch nit so schlimm
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.02.2015, 16:52 | #11 |
| Windows 7: ungültiges Bild (Error Meldung) Okay. Brauchst du das jetzt trotzdem? Weil ich finde es wirklich nirgends ='D |
11.02.2015, 07:05 | #12 |
/// the machine /// TB-Ausbilder | Windows 7: ungültiges Bild (Error Meldung) Nee passt schon
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7: ungültiges Bild (Error Meldung) |
adware, antivir, antivirus, avira, bonjour, browser, computer, desktop, device driver, dvdvideosoft ltd., error, google, home, homepage, mozilla, mp3, netzwerk, programm, realtek, registry, rundll, scan, security, server, svchost.exe, vc32loader.dll, vc32lo~1.dll, vista, windows |