|
Log-Analyse und Auswertung: Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
11.02.2015, 21:00 | #1 |
| Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Ausserdem die Meldung: Dein Pc wird abstürzen. Zum Beheben hier klicken! |
11.02.2015, 22:15 | #2 |
/// Malwareteam | Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Hallo BTao,
__________________mein Name ist Jonas und ich werde dir bei deiner Bereinigung helfen. Diese kann mit viel Arbeit für dich verbunden sein. Bevor wir anfangen können, lies bitte die Bereinigungsregeln und Hinweise: Regeln zum Ablauf der Bereinigung
Hinweis Wenn du alles gelesen hast, kann es losgehen. Bitte speichere alle Programme auf dem Desktop und führe sie von dort aus.
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Poste folgende Logfiles in deiner nächsten Antwort:
__________________ |
13.02.2015, 17:57 | #3 |
| Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Hallo Jonas,
__________________danke für die Hilfe. Als ich das FRST runtergeladen, konnte ich es auch gleich starten, allerdings werde ich aufgefordert eine aktuelle Version zu nutzen - siehe Screenshot. ich habe das Fenster noch offen. |
13.02.2015, 18:18 | #4 |
/// Malwareteam | Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Hi, bitte auf Ja drücken, wenn dieses Fenster kommt .
__________________ Gruß, Jonas |
13.02.2015, 18:36 | #5 |
| Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! FRST.Log FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-02-2015 Ran by Sven (administrator) on SVENS-NOTEBOOK on 13-02-2015 18:28:04 Running from C:\Users\Sven\Downloads Loaded Profiles: Sven (Available profiles: Sven) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\RMSvc.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QASvc.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe (AMD) C:\Windows\System32\atieclxx.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QAEvent.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMEvent.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QAMsg.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMTray.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QuickAccess.exe (Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe (Greenshot) C:\Program Files\Greenshot\Greenshot.exe (Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Avanquest Software) C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17499_x64__8wekyb3d8bbwe\glcnd.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Recovery Management\Notification\Notification.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Users\Sven\Downloads\Defogger.exe () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugincontainer.exe () C:\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\updater.exe () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\4\Plugin.exe () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\8\Plugin.exe () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\5\Plugin.exe () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\3\Plugin.exe () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\3\Plugin.exe (Farbar) C:\Users\Sven\Downloads\FRST64 (1).exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2890056 2013-09-06] (ELAN Microelectronics Corp.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor) HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [495616 2014-05-12] (Greenshot) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-25] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.) HKLM-x32\...\Run: [ReCycle Patch] => "E:\Sven\Musiktools\Reason\ReasonPatch(1).exe" -s HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] ( (Atheros Communications)) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466144 2014-11-27] (Sony) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\RunOnce: [Application Restart #0] => C:\Users\Sven\AppData\Local\Pokki\Engine\pokki.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-p (the data entry has 538 more characters). HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\MountPoints2: {9c949fe8-e681-11e3-8270-0c54a5328d5d} - "E:\Setup.exe" HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\MountPoints2: {e17883e0-90bf-11e3-825e-0c54a5328d5d} - "E:\Setup.exe" HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\MountPoints2: {fb0770f4-313c-11e4-8278-0c54a5328d5d} - "E:\Startme.exe" ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1764654466-1334418769-576482932-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKU\S-1-5-21-1764654466-1334418769-576482932-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=APJB SearchScopes: HKU\S-1-5-21-1764654466-1334418769-576482932-1001 -> {9EEA33CA-9F50-43C5-997E-7C9707250F33} URL = BHO-x32: Positive Finds -> {30c85a3d-1d96-4589-b63f-91fb7ef45a41} -> C:\Program Files (x86)\Positive Finds\Extensions\30c85a3d-1d96-4589-b63f-91fb7ef45a41.dll () Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () Chrome: ======= CHR HomePage: Default -> CHR Profile: C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-15] CHR Extension: (Google Drive) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-15] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-06] CHR Extension: (YouTube) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-15] CHR Extension: (Google-Suche) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-15] CHR Extension: (Avira Browserschutz) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-15] CHR Extension: (Google Wallet) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-15] CHR Extension: (Google Mail) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-15] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-20] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe [2650696 2013-07-26] (Acer Incorporated) R3 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [663592 2013-07-05] (Acer Incorporated) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101192 2013-09-06] (ELAN Microelectronics Corp.) R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [File not signed] R2 LMSvc; C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe [457768 2013-08-03] (Acer Incorporate) R3 QASvc; C:\Program Files\Packard Bell\Packard Bell Quick Access\QASvc.exe [457768 2013-08-02] (Acer Incorporate) R3 RMSvc; C:\Program Files\Packard Bell\Packard Bell Quick Access\RMSvc.exe [448040 2013-08-02] (Acer Incorporate) R2 Service Mgr PositiveFinds; C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugincontainer.exe [577272 2015-02-11] () R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software) R2 Update Mgr PositiveFinds; C:\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\updater.exe [384760 2015-02-11] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Qualcomm Atheros Communications, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [138240 2013-06-22] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-16] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-16] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated) R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2014-06-23] (TuneUp Software) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-13 18:28 - 2015-02-13 18:28 - 00014789 _____ () C:\Users\Sven\Downloads\FRST.txt 2015-02-13 18:27 - 2015-02-13 18:28 - 00000000 ____D () C:\FRST 2015-02-13 17:49 - 2015-02-13 17:49 - 02134016 _____ (Farbar) C:\Users\Sven\Downloads\FRST64 (1).exe 2015-02-11 22:01 - 2015-02-11 22:01 - 00818162 _____ () C:\Users\Sven\Downloads\Nicht bestätigt 869592.crdownload 2015-02-11 21:37 - 2015-02-11 21:37 - 02134016 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe 2015-02-11 21:36 - 2015-02-11 21:36 - 01125376 _____ (Farbar) C:\Users\Sven\Downloads\FRST (1).exe 2015-02-11 21:35 - 2015-02-11 21:35 - 01125376 _____ (Farbar) C:\Users\Sven\Downloads\FRST.exe 2015-02-11 21:23 - 2015-02-11 21:23 - 00000470 _____ () C:\Users\Sven\Downloads\defogger_disable.log 2015-02-11 21:23 - 2015-02-11 21:23 - 00000000 _____ () C:\Users\Sven\defogger_reenable 2015-02-11 21:22 - 2015-02-11 21:22 - 00050477 _____ () C:\Users\Sven\Downloads\Defogger.exe 2015-02-11 21:07 - 2015-02-11 21:07 - 00002770 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2015-02-11 20:40 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2015-02-08 18:59 - 2015-02-08 18:59 - 00000000 ____D () C:\Users\Sven\AppData\Local\Skype 2015-02-08 18:58 - 2015-02-11 20:05 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Skype 2015-02-08 18:58 - 2015-02-11 20:05 - 00000000 ____D () C:\ProgramData\Skype 2015-02-08 18:57 - 2015-02-11 21:35 - 00000000 ____D () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602 2015-02-08 18:57 - 2015-02-08 18:57 - 00000000 ____D () C:\Program Files (x86)\Positive Finds 2015-02-08 18:56 - 2015-02-08 18:56 - 00002233 _____ () C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk 2015-02-08 18:56 - 2015-02-08 18:56 - 00002225 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014.lnk 2015-02-08 18:56 - 2015-02-08 18:56 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\TuneUp Software 2015-02-08 18:56 - 2015-02-08 18:56 - 00000000 ____D () C:\Users\Sven\AppData\Local\TuneUp Software 2015-02-08 18:56 - 2014-07-16 10:24 - 00040760 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2015-02-08 18:56 - 2014-07-16 10:24 - 00029496 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2015-02-08 18:56 - 2014-07-16 10:24 - 00025400 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll 2015-02-08 18:55 - 2015-02-08 18:56 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2014 2015-02-08 18:54 - 2015-02-08 18:54 - 00001560 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk 2015-02-08 18:53 - 2015-02-08 18:58 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-02-08 18:53 - 2015-02-08 18:53 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2015-02-08 18:53 - 2015-02-08 18:53 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\RHEng 2015-02-08 18:53 - 2015-02-08 18:53 - 00000000 ____D () C:\Program Files (x86)\Free Codec Pack 2015-02-08 18:52 - 2015-02-08 18:52 - 03533008 _____ (DVDVideoSoft Ltd. ) C:\Users\Sven\Downloads\FreeYouTubeToMP3Converter.exe 2015-01-18 17:47 - 2015-01-18 17:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rob Papen Predator - Beat Version 2015-01-18 17:15 - 2015-01-18 17:15 - 00000814 _____ () C:\Users\Public\Desktop\Zynewave Podium.lnk 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\Users\Sven\Documents\Zynewave Podium Projects 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Zynewave 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zynewave 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\Program Files (x86)\Zynewave 2015-01-18 17:06 - 2015-01-18 17:06 - 00003064 _____ () C:\Windows\System32\Tasks\{9B9F2EF7-D444-4BAF-92FA-DA0DD1E9C56D} 2015-01-18 17:02 - 2015-01-18 17:02 - 00184320 _____ () C:\Users\Sven\Downloads\ReasonPatch(1).exe 2015-01-18 14:46 - 2015-01-18 17:02 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Propellerhead Software 2015-01-18 14:45 - 2015-01-18 14:45 - 00000000 ____D () C:\ProgramData\Propellerhead Software 2015-01-18 13:46 - 2015-01-18 13:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ableton 2015-01-18 13:46 - 2004-10-07 12:31 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71.dll 2015-01-18 13:46 - 2004-10-07 12:31 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2015-01-18 13:46 - 2004-10-07 12:31 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2015-01-18 13:46 - 2004-10-07 12:31 - 00212992 _____ (Propellerhead Software AB) C:\Windows\SysWOW64\ReWire.dll 2015-01-15 22:40 - 2015-01-15 22:41 - 00014014 _____ () C:\Users\Sven\Documents\MBW06-2.odt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-13 18:27 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2015-02-11 21:43 - 2014-02-01 20:41 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1764654466-1334418769-576482932-1001 2015-02-11 21:43 - 2013-11-25 11:55 - 01580030 _____ () C:\Windows\WindowsUpdate.log 2015-02-11 21:24 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-02-11 21:23 - 2014-02-01 20:34 - 00000000 ____D () C:\Users\Sven 2015-02-11 21:23 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp 2015-02-11 21:11 - 2014-08-15 11:50 - 00001148 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-10 18:53 - 2013-11-25 11:59 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-10 18:52 - 2015-01-03 13:07 - 00000000 ____D () C:\Users\Sven\OneDrive 2015-02-10 18:52 - 2014-04-06 18:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-10 18:52 - 2014-04-06 18:04 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-02-10 18:51 - 2014-08-15 11:50 - 00001144 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-08 19:16 - 2013-11-25 12:02 - 00065536 _____ () C:\Windows\system32\spu_storage.bin 2015-02-08 18:55 - 2014-04-25 18:40 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DVDVideoSoft 2015-02-08 18:54 - 2014-04-25 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-02-08 18:54 - 2014-04-25 18:42 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2015-02-08 18:36 - 2014-06-01 22:06 - 00000000 ____D () C:\Users\Sven\AppData\Local\CrashDumps 2015-02-06 18:06 - 2014-08-15 11:50 - 00004120 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-06 18:06 - 2014-08-15 11:50 - 00003884 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-04 22:17 - 2014-10-03 16:14 - 00000000 ____D () C:\Users\Sven\Documents\Texte 2015-02-03 20:31 - 2014-07-13 13:06 - 00714720 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-02-03 20:31 - 2014-07-13 13:06 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-02-02 21:43 - 2013-11-25 20:47 - 00765582 _____ () C:\Windows\system32\perfh007.dat 2015-02-02 21:43 - 2013-11-25 20:47 - 00159366 _____ () C:\Windows\system32\perfc007.dat 2015-02-02 21:43 - 2013-09-06 05:58 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-02 21:40 - 2013-08-22 15:46 - 00033234 _____ () C:\Windows\setupact.log 2015-01-29 18:14 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-28 19:44 - 2014-09-02 18:51 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-01-24 19:17 - 2013-09-06 05:51 - 01055120 _____ () C:\Windows\PFRO.log 2015-01-24 19:17 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-01-24 07:31 - 2014-12-04 20:10 - 00002054 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2015-01-24 07:31 - 2014-09-02 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony 2015-01-24 07:31 - 2013-11-25 12:21 - 00272510 _____ () C:\Windows\DPINST.LOG 2015-01-24 07:29 - 2013-11-25 12:20 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-01-18 14:46 - 2014-02-01 20:34 - 00000000 ____D () C:\Users\Sven\AppData\Local\VirtualStore 2015-01-14 23:32 - 2014-02-08 15:18 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-14 23:24 - 2014-02-08 15:18 - 113365784 ____N (Microsoft Corporation) C:\Windows\system32\MRT.exe ==================== Files in the root of some directories ======= 2013-11-25 12:24 - 2013-11-25 12:24 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some content of TEMP: ==================== C:\Users\Sven\AppData\Local\Temp\avgnt.exe C:\Users\Sven\AppData\Local\Temp\drm_dialogs.dll C:\Users\Sven\AppData\Local\Temp\drm_dyndata_7330014.dll C:\Users\Sven\AppData\Local\Temp\FreeYouTubeToMP3Converter.exe C:\Users\Sven\AppData\Local\Temp\tmp3E5B.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-11 21:14 ==================== End Of Log ============================ + Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-02-2015 Ran by Sven at 2015-02-13 18:30:17 Running from C:\Users\Sven\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Acer Docs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.01.3006 - Acer Incorporated) Acer Media (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.02.3104.3 - Acer Incorporated) Acer Photo (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 2.02.3104.6 - Acer Incorporated) Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 2.02.3104 - Acer Incorporated) Acer Remote Files (HKLM\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 1.00.3007 - Acer Incorporated) Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden AMD Catalyst Install Manager (HKLM\...\{113AEB14-AF33-098B-55A1-6D64D9D5323F}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) Ankh (HKLM-x32\...\Ankh) (Version: - ) Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Avira (HKLM-x32\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG) Avira (x32 Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Buzzdock (HKLM-x32\...\{cfd32d46-7d3f-483f-bace-7172aec5592d}) (Version: - Alactro LLC) <==== ATTENTION calibre (HKLM-x32\...\{BED35097-6053-4E51-B9EC-A779CCCDEE72}) (Version: 2.15.0 - Kovid Goyal) Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3126.57 - CyberLink Corp.) eBay Worldwide (HKLM-x32\...\{91589413-6675-4C27-8AFC-EFB9103B90A5}) (Version: 2.4.0105 - OEM) ETDWare PS/2-X64 11.6.27.201_WHQL (HKLM\...\Elantech) (Version: 11.6.27.201 - ELAN Microelectronic Corp.) Free M4a to MP3 Converter 8.1 (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com) Free YouTube to MP3 Converter version 3.12.54.128 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.54.128 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.111 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden Greenshot 1.1.9.13 (HKLM\...\Greenshot_is1) (Version: 1.1.9.13 - Greenshot) Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.8100 - Packard Bell) iTunes (HKLM\...\{77DE5105-D05E-448C-96CB-7FA381903753}) (Version: 11.3.1.2 - Apple Inc.) Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.8100 - Packard Bell) Luxor Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\...\{551AC8F2-FEA2-4B45-ACF7-C98681233CC9}) (Version: 12.5.01200 - Nero AG) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.8 - Notepad++ Team) OEM Application Profile (HKLM-x32\...\{276FD4A2-030F-8A24-7DFE-9B1384131BCD}) (Version: 1.00.0000 - Ihr Firmenname) Office Addin (HKLM-x32\...\{6D2BBE1D-E600-4695-BA37-0B0E605542CC}) (Version: 2.02.2009 - Acer) Office Addin 2003 (HKLM-x32\...\{1FCC073B-CC01-4443-AD20-E559F66E6E83}) (Version: 2.02.2009 - Acer) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Packard Bell Games (HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\Pokki_c3e2005ede46d0c9848c79a4f19e87561ed8d0aa) (Version: 1.1.9.43466 - Pokki) Packard Bell Launch Manager (HKLM\...\{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}) (Version: 8.00.8101 - Packard Bell) Packard Bell Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8100 - Packard Bell) Packard Bell Quick Access (HKLM\...\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.00.3000 - Packard Bell) Packard Bell Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8100 - Packard Bell) Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden Pokki Start Menu (HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\Pokki_Start_Menu) (Version: 0.269.3.181 - ) Positive Finds (HKLM-x32\...\Positive Finds) (Version: 2.0.5517.17175 - Positive Finds) Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.305 - Qualcomm Atheros Communications) Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.07 - Qualcomm Atheros) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.28145 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7027 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Rob Papen Predator Beat V1.0.0 (HKLM-x32\...\Predator - Beat Version_is1) (Version: - RPCX) Sam and Max - Season One 1.0 (HKLM-x32\...\Sam and Max - Season One) (Version: 1.0 - JoWooD Productions) Scratches: Director's Cut (HKLM-x32\...\Steam App 46460) (Version: - Nucleosys) ScummVM 1.7.0 (HKLM-x32\...\ScummVM_is1) (Version: - The ScummVM Team) Sony PC Companion 2.10.245 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.245 - Sony) Spotify (HKLM-x32\...\Spotify) (Version: 0.9.1.57.ge7405149 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.32 - WildTangent) Hidden Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.340 - TuneUp Software) TuneUp Utilities 2014 (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden Uninstall Lilly Looking Through (HKLM-x32\...\{CEA8642A-A183-4626-B0CC-ABD263112A39}_is1) (Version: 1.1 - Geeta Games, LLC) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) VoiceOver Kit (HKLM-x32\...\{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}) (Version: 1.42.128.0 - Apple Inc.) WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent) WildTangent Games App (x32 Version: 4.0.10.20 - WildTangent) Hidden Zynewave Podium Beat 1.72 (HKLM-x32\...\{08010FDC-EA6E-4934-BC17-1E4CF8782E67}) (Version: 1.72 - Zynewave) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 28-01-2015 20:00:25 Windows Update 08-02-2015 08:31:22 Windows Update 11-02-2015 20:03:34 Removed Skype™ 7.1 ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {2F6BFA1C-C3B6-4B39-BB26-D4EB2A484562} - System32\Tasks\Quick Access => C:\Program Files\Packard Bell\Packard Bell Quick Access\QALauncher.exe [2013-08-02] (Acer Incorporate) Task: {3B1442F3-B516-4E7C-9A5D-F116CB047F44} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-01-14] (Microsoft Corporation) Task: {3CDA38F4-8E52-4270-ACE4-CD6B7F4E5B43} - System32\Tasks\Launch Manager => C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMLauncher.exe [2013-08-03] (Acer Incorporate) Task: {403F3D0C-C140-40CC-BCEF-1DDF66E7E58B} - System32\Tasks\{9B9F2EF7-D444-4BAF-92FA-DA0DD1E9C56D} => pcalua.exe -a "D:\Install Reason.exe" -d D:\ Task: {489ADBCF-D8C4-431D-9B15-DB0656CF521C} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2014-07-16] (TuneUp Software) Task: {5D8B9DFA-AE5C-4619-873D-FFCA1A869A06} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Packard Bell\Packard Bell Recovery Management\Notification\Notification.exe [2013-07-10] (Acer Incorporated) Task: {605F9326-39E9-4EF6-8408-7B7B075B4675} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\acpanel_win.exe [2013-07-26] (Acer Incorporated) Task: {A261F22C-70BE-4A4C-950D-D193567A5285} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Packard Bell\Live Updater\liveupdater_agent.exe [2013-01-22] () Task: {D40547CB-B1F8-4498-B5AB-73547BD4711B} - System32\Tasks\Power Management => C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [2013-07-05] (Acer Incorporated) Task: {D9E6A394-2895-4B5F-929F-1E2A014AA268} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-15] (Google Inc.) Task: {DA4783A4-96BF-40BA-9004-2B6B0519E4AC} - System32\Tasks\ALU => C:\Program Files (x86)\Packard Bell\Live Updater\updater.exe [2013-07-08] () Task: {F339E6A9-93EF-40C4-8134-D5029EBCB641} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-15] (Google Inc.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2014-07-16 10:24 - 2014-07-16 10:24 - 00699704 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll 2013-09-07 01:48 - 2013-09-07 01:48 - 00011264 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll 2013-09-07 01:45 - 2013-09-07 01:45 - 00086016 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Map\MAP.dll 2013-09-07 01:52 - 2013-09-07 01:52 - 00012928 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe 2014-09-02 20:33 - 2014-06-23 08:07 - 00113376 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe 2015-02-11 21:22 - 2015-02-11 21:22 - 00050477 _____ () C:\Users\Sven\Downloads\Defogger.exe 2015-02-08 15:32 - 2015-02-11 12:33 - 00577272 _____ () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugincontainer.exe 2015-02-08 15:32 - 2015-02-11 12:33 - 00384760 _____ () C:\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\updater.exe 2015-02-11 08:08 - 2015-02-11 08:08 - 00400120 _____ () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\4\plugin.exe 2015-02-11 00:32 - 2015-02-11 00:32 - 00508152 _____ () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\8\plugin.exe 2015-02-11 08:09 - 2015-02-11 08:09 - 00518904 _____ () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\5\plugin.exe 2015-02-11 08:16 - 2015-02-11 08:16 - 00701176 _____ () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\3\plugin.exe 2014-07-31 11:16 - 2014-07-31 11:16 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-07-31 11:16 - 2014-07-31 11:16 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-09-02 20:33 - 2012-04-30 10:57 - 00039936 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll 2014-09-02 20:33 - 2014-12-04 14:18 - 00241152 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll 2011-07-07 13:54 - 2011-07-07 13:54 - 00233984 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll 2014-09-02 20:33 - 2013-05-20 11:58 - 00620718 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll 2014-09-02 20:33 - 2010-01-11 15:44 - 00053248 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\VObject.dll 2013-11-25 12:48 - 2013-07-30 18:11 - 00088648 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext.dll 2015-02-06 18:12 - 2015-02-04 10:02 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\libglesv2.dll 2015-02-06 18:12 - 2015-02-04 10:02 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\libegl.dll 2015-02-06 18:12 - 2015-02-04 10:02 - 14965064 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\PepperFlash\pepflashplayer.dll 2015-02-06 18:12 - 2015-02-04 10:02 - 09170760 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\pdf.dll 2015-02-11 20:35 - 2015-02-11 21:36 - 00246008 _____ () C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\3\b158039e-9294-4496-98f7-2cb127f3ad36.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Users\Sven\OneDrive:ms-properties ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\PackardBell01.jpg DNS Servers: 192.168.178.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== Accounts: ============================= Administrator (S-1-5-21-1764654466-1334418769-576482932-500 - Administrator - Disabled) Gast (S-1-5-21-1764654466-1334418769-576482932-501 - Limited - Disabled) Sven (S-1-5-21-1764654466-1334418769-576482932-1001 - Administrator - Enabled) => C:\Users\Sven ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/13/2015 05:43:12 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1594 Error: (02/13/2015 05:43:12 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1594 Error: (02/11/2015 10:04:40 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (02/11/2015 09:57:06 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "asmv2:clrClassInvocation1". Fehler in Manifest- oder Richtliniendatei "asmv2:clrClassInvocation2" in Zeile asmv2:clrClassInvocation3. Das asmv2:clrClassInvocation-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird. Error: (02/11/2015 09:57:06 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "asmv2:clrClassInvocation1". Fehler in Manifest- oder Richtliniendatei "asmv2:clrClassInvocation2" in Zeile asmv2:clrClassInvocation3. Das asmv2:clrClassInvocation-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird. Error: (02/11/2015 09:57:06 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "asmv2:clrClassInvocation1". Fehler in Manifest- oder Richtliniendatei "asmv2:clrClassInvocation2" in Zeile asmv2:clrClassInvocation3. Das asmv2:clrClassInvocation-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird. Error: (02/08/2015 07:16:40 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15312 Error: (02/08/2015 07:16:40 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15312 Error: (02/08/2015 07:16:40 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (02/08/2015 07:16:25 PM) (Source: Avira Service Host) (EventID: 0) (User: ) Description: Fehler beim Verarbeiten von Sitzungsänderung. System.ComponentModel.Win32Exception (0x80004005): Key (Users\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall) could not be opened Error: 87, Hive: Users, Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall bei Avira.OE.WinCore.Utility.RegistryValueWatcher.CheckResultAndThrowWin32Exception(Int32 result, String message) bei Avira.OE.WinCore.Utility.RegistryValueWatcher.OpenRegKey() bei Avira.OE.WinCore.Utility.RegistryValueWatcher.Start() bei Avira.OE.ServiceHost.AppInfoRepositoryFactory.CreateRegistryAppInfoRepository(RegistryHive registryHive, String registryPath, RegistryView registryView) bei Avira.OE.ServiceHost.DesktopApplications.UpdateUserAppInfoRepository(String userSid) bei Avira.OE.ServiceHost.DesktopApplications.UpdateOnNewUserSid(String userSid) bei Avira.OE.ServiceHost.DesktopApplications.OnSessionChange(Int32 sessionId, SessionChangeReason reason) bei Avira.OE.ServiceHost.ServiceHost.OnSessionChange(SessionChangeDescription changeDescription) bei S... System errors: ============= Error: (02/11/2015 08:06:29 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 70. Der Windows-SChannel-Fehlerstatus lautet: 105. Error: (02/08/2015 00:04:38 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 70. Der Windows-SChannel-Fehlerstatus lautet: 105. Error: (01/29/2015 06:14:39 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 28.01.2015 um 21:03:38 unerwartet heruntergefahren. Error: (01/28/2015 07:29:26 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WSearch erreicht. Error: (01/25/2015 10:17:51 AM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (01/24/2015 06:11:08 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80240055 fehlgeschlagen: Sicherheitsupdate für Internet Explorer Flash Player für Windows 8.1 für x64-Systeme (KB3033408) Error: (01/18/2015 05:10:01 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (01/18/2015 05:09:58 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (01/18/2015 05:09:55 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (01/18/2015 05:09:52 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Microsoft Office Sessions: ========================= Error: (02/13/2015 05:43:12 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1594 Error: (02/13/2015 05:43:12 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1594 Error: (02/11/2015 10:04:40 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (02/11/2015 09:57:06 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: asmv2:clrClassInvocationurn:schemas-microsoft-com:asm.v1^entryPointC:\Program Files (x86)\Acer\Office Addin 2003\ExcelAddIn2003.dll.ManifestC:\Program Files (x86)\Acer\Office Addin 2003\ExcelAddIn2003.dll.Manifest4 Error: (02/11/2015 09:57:06 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: asmv2:clrClassInvocationurn:schemas-microsoft-com:asm.v1^entryPointC:\Program Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.ManifestC:\Program Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.Manifest4 Error: (02/11/2015 09:57:06 PM) (Source: SideBySide) (EventID: 72) (User: ) Description: asmv2:clrClassInvocationurn:schemas-microsoft-com:asm.v1^entryPointC:\Program Files (x86)\Acer\Office Addin 2003\WordAddIn2003.dll.ManifestC:\Program Files (x86)\Acer\Office Addin 2003\WordAddIn2003.dll.Manifest4 Error: (02/08/2015 07:16:40 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15312 Error: (02/08/2015 07:16:40 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15312 Error: (02/08/2015 07:16:40 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (02/08/2015 07:16:25 PM) (Source: Avira Service Host) (EventID: 0) (User: ) Description: Fehler beim Verarbeiten von Sitzungsänderung. System.ComponentModel.Win32Exception (0x80004005): Key (Users\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall) could not be opened Error: 87, Hive: Users, Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall bei Avira.OE.WinCore.Utility.RegistryValueWatcher.CheckResultAndThrowWin32Exception(Int32 result, String message) bei Avira.OE.WinCore.Utility.RegistryValueWatcher.OpenRegKey() bei Avira.OE.WinCore.Utility.RegistryValueWatcher.Start() bei Avira.OE.ServiceHost.AppInfoRepositoryFactory.CreateRegistryAppInfoRepository(RegistryHive registryHive, String registryPath, RegistryView registryView) bei Avira.OE.ServiceHost.DesktopApplications.UpdateUserAppInfoRepository(String userSid) bei Avira.OE.ServiceHost.DesktopApplications.UpdateOnNewUserSid(String userSid) bei Avira.OE.ServiceHost.DesktopApplications.OnSessionChange(Int32 sessionId, SessionChangeReason reason) bei Avira.OE.ServiceHost.ServiceHost.OnSessionChange(SessionChangeDescription changeDescription) bei S... ==================== Memory info =========================== Processor: AMD E2-3800 APU with Radeon(TM) HD Graphics Percentage of memory in use: 65% Total physical RAM: 3529.26 MB Available physical RAM: 1218.16 MB Total Pagefile: 4361.26 MB Available Pagefile: 1162.69 MB Total Virtual: 131072 MB Available Virtual: 131071.8 MB ==================== Drives ================================ Drive c: (Packard Bell) (Fixed) (Total:913.7 GB) (Free:867.58 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 0A41A91F) Partition: GPT Partition Type. ==================== End Of Log ============================ |
13.02.2015, 18:44 | #6 |
/// Malwareteam | Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Alles klar, dann gehts so weiter: Schritt 1 Bitte deinstalliere folgende Programme:
Windows XP: Start -> Systemsteuerung -> Kategorieansicht auswählen (falls nicht voreingestellt) -> Softwareund wähle die angegeben Programme aus. Drücke Entfernen (Windows XP) oder Deinstallieren (Windows Vista/7/8). Schritt 2 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 4 Starte noch einmal FRST.
Poste folgende Logfiles in deiner nächsten Antwort:
__________________ --> Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! |
14.02.2015, 21:56 | #7 |
| Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! AdwCleaner.txt Code:
ATTFilter # AdwCleaner v4.110 - Bericht erstellt 13/02/2015 um 19:20:36 # Aktualisiert 05/02/2015 von Xplode # Datenbank : 2015-02-13.1 [Server] # Betriebssystem : Windows 8.1 (x64) # Benutzername : Sven - SVENS-NOTEBOOK # Gestarted von : C:\Users\Sven\Downloads\AdwCleaner_4.110.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\DownloadManager Ordner Gelöscht : C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602 Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\RHEng Datei Gelöscht : C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage Datei Gelöscht : C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal Datei Gelöscht : C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage Datei Gelöscht : C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{30C85A3D-1D96-4589-B63F-91FB7EF45A41} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{50F60937-910A-4C05-8E36-FE4E299191CF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{63C63464-1423-4FDB-BA5D-6F75F491C63E} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30C85A3D-1D96-4589-B63F-91FB7EF45A41} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{50F60937-910A-4C05-8E36-FE4E299191CF} Schlüssel Gelöscht : HKLM\SOFTWARE\PositiveFinds Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17416 -\\ Google Chrome v40.0.2214.111 [C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} ************************* AdwCleaner[R0].txt - [2347 Bytes] - [13/02/2015 19:16:28] AdwCleaner[S0].txt - [2265 Bytes] - [13/02/2015 19:20:36] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2324 Bytes] ########## Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 13.02.2015 Suchlauf-Zeit: 19:33:30 Logdatei: mbam.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2015.02.13.05 Rootkit Datenbank: v2015.02.03.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Sven Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 333002 Verstrichene Zeit: 29 Min, 26 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 0 (Keine schädliche Elemente erkannt) Registrierungswerte: 0 (Keine schädliche Elemente erkannt) Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 0 (Keine schädliche Elemente erkannt) Dateien: 3 PUP.Adware.Agent, C:\Users\Sven\AppData\Local\Temp\PositiveFinds\Setup.exe, In Quarantäne, [06f38f8e7218df57b6147c8ab14f9c64], PUP.Optional.MindSpark.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_internetspeedtracker.dl.tb.ask.com_0.localstorage, In Quarantäne, [f4058697bfcbaf87b9672f933ec5ed13], PUP.Optional.MindSpark.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_internetspeedtracker.dl.tb.ask.com_0.localstorage-journal, In Quarantäne, [21d8ae6ff6947fb72000655d4cb7ea16], Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-02-2015 Ran by Sven (administrator) on SVENS-NOTEBOOK on 14-02-2015 21:47:57 Running from C:\Users\Sven\Downloads Loaded Profiles: Sven (Available profiles: Sven) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMEvent.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QASvc.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\RMSvc.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QAEvent.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QAMsg.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMTray.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QuickAccess.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Greenshot) C:\Program Files\Greenshot\Greenshot.exe (Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Recovery Management\Notification\Notification.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_fa2b7d3b9b36c7b4\TiWorker.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2890056 2013-09-06] (ELAN Microelectronics Corp.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor) HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [495616 2014-05-12] (Greenshot) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-25] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.) HKLM-x32\...\Run: [ReCycle Patch] => "E:\Sven\Musiktools\Reason\ReasonPatch(1).exe" -s HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] ( (Atheros Communications)) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466144 2014-11-27] (Sony) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\RunOnce: [Application Restart #0] => C:\Users\Sven\AppData\Local\Pokki\Engine\pokki.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-p (the data entry has 538 more characters). HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\MountPoints2: {9c949fe8-e681-11e3-8270-0c54a5328d5d} - "E:\Setup.exe" HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\MountPoints2: {e17883e0-90bf-11e3-825e-0c54a5328d5d} - "E:\Setup.exe" HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\MountPoints2: {fb0770f4-313c-11e4-8278-0c54a5328d5d} - "E:\Startme.exe" ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1764654466-1334418769-576482932-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKU\S-1-5-21-1764654466-1334418769-576482932-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=APJB SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1764654466-1334418769-576482932-1001 -> {9EEA33CA-9F50-43C5-997E-7C9707250F33} URL = Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () Chrome: ======= CHR HomePage: Default -> CHR Profile: C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-15] CHR Extension: (Google Drive) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-15] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-06] CHR Extension: (YouTube) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-15] CHR Extension: (Google-Suche) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-15] CHR Extension: (Avira Browserschutz) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-15] CHR Extension: (Google Wallet) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-15] CHR Extension: (Google Mail) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-15] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-20] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe [2650696 2013-07-26] (Acer Incorporated) R3 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [663592 2013-07-05] (Acer Incorporated) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101192 2013-09-06] (ELAN Microelectronics Corp.) R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [File not signed] R2 LMSvc; C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe [457768 2013-08-03] (Acer Incorporate) R3 QASvc; C:\Program Files\Packard Bell\Packard Bell Quick Access\QASvc.exe [457768 2013-08-02] (Acer Incorporate) R3 RMSvc; C:\Program Files\Packard Bell\Packard Bell Quick Access\RMSvc.exe [448040 2013-08-02] (Acer Incorporate) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Qualcomm Atheros Communications, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [138240 2013-06-22] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-16] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-16] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-14] (Malwarebytes Corporation) R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2014-06-23] (TuneUp Software) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-14 21:47 - 2015-02-14 21:47 - 00000000 ____D () C:\Users\Sven\Downloads\FRST-OlderVersion 2015-02-14 21:46 - 2015-02-14 21:46 - 00001707 _____ () C:\Users\Sven\Desktop\mbam.txt 2015-02-13 19:32 - 2015-02-13 19:32 - 00001126 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-02-13 19:30 - 2015-02-13 19:31 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.4.1028.exe 2015-02-13 19:16 - 2015-02-13 19:27 - 00000000 ____D () C:\AdwCleaner 2015-02-13 19:14 - 2015-02-13 19:14 - 02112512 _____ () C:\Users\Sven\Downloads\AdwCleaner_4.110.exe 2015-02-13 18:30 - 2015-02-13 18:41 - 00027703 _____ () C:\Users\Sven\Downloads\Addition.txt 2015-02-13 18:28 - 2015-02-14 21:47 - 00013999 _____ () C:\Users\Sven\Downloads\FRST.txt 2015-02-13 18:27 - 2015-02-14 21:48 - 00000000 ____D () C:\FRST 2015-02-11 21:37 - 2015-02-14 21:47 - 02134528 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe 2015-02-11 21:23 - 2015-02-11 21:23 - 00000470 _____ () C:\Users\Sven\Downloads\defogger_disable.log 2015-02-11 21:23 - 2015-02-11 21:23 - 00000000 _____ () C:\Users\Sven\defogger_reenable 2015-02-11 21:22 - 2015-02-11 21:22 - 00050477 _____ () C:\Users\Sven\Downloads\Defogger.exe 2015-02-11 21:07 - 2015-02-11 21:07 - 00002770 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2015-02-11 20:41 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2015-02-11 20:41 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2015-02-11 20:41 - 2014-12-09 00:12 - 00391526 _____ () C:\Windows\system32\ApnDatabase.xml 2015-02-11 20:40 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2015-02-11 20:16 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll 2015-02-11 20:16 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll 2015-02-11 20:15 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-02-11 20:15 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-02-11 20:15 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2015-02-11 20:15 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2015-02-11 20:15 - 2015-01-13 23:11 - 01762840 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-02-11 20:15 - 2015-01-13 23:04 - 01489072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-02-11 20:15 - 2015-01-10 10:10 - 07472960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-02-11 20:15 - 2015-01-10 10:10 - 01733440 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-02-11 20:15 - 2015-01-10 09:28 - 01498360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-02-11 20:15 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-02-11 20:15 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-02-11 20:15 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-02-11 20:15 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-02-11 20:15 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-02-11 20:15 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-02-11 20:15 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-02-11 20:15 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-02-11 20:15 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-02-11 20:15 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-02-11 20:15 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-02-11 20:15 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-02-11 20:15 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-02-11 20:14 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-02-11 20:14 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-02-11 20:14 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-02-11 20:14 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-02-11 20:14 - 2015-01-12 03:34 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-02-11 20:14 - 2015-01-12 03:32 - 06041088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-02-11 20:14 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-02-11 20:14 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-02-11 20:14 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-02-11 20:14 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-02-11 20:14 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-02-11 20:14 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-02-11 20:14 - 2015-01-12 02:58 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2015-02-11 20:14 - 2015-01-12 02:55 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-02-11 20:14 - 2015-01-12 02:51 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-02-11 20:14 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-02-11 20:14 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-02-11 20:14 - 2015-01-12 02:48 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-02-11 20:14 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-02-11 20:14 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-02-11 20:14 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-02-11 20:14 - 2015-01-12 02:34 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2015-02-11 20:14 - 2015-01-12 02:30 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2015-02-11 20:14 - 2015-01-12 02:29 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-02-11 20:14 - 2015-01-12 02:27 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2015-02-11 20:14 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-02-11 20:14 - 2015-01-12 02:25 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-02-11 20:14 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-02-11 20:14 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-02-11 20:14 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-02-11 20:14 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-02-11 20:14 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-02-11 20:14 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-02-11 20:14 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-02-11 20:14 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-02-11 20:14 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-02-11 20:14 - 2015-01-10 08:00 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-02-11 20:14 - 2015-01-10 07:38 - 00359424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-02-11 20:13 - 2015-01-10 09:22 - 04175872 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-02-08 18:59 - 2015-02-08 18:59 - 00000000 ____D () C:\Users\Sven\AppData\Local\Skype 2015-02-08 18:58 - 2015-02-11 20:05 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Skype 2015-02-08 18:58 - 2015-02-11 20:05 - 00000000 ____D () C:\ProgramData\Skype 2015-02-08 18:56 - 2015-02-08 18:56 - 00002233 _____ () C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk 2015-02-08 18:56 - 2015-02-08 18:56 - 00002225 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014.lnk 2015-02-08 18:56 - 2015-02-08 18:56 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\TuneUp Software 2015-02-08 18:56 - 2015-02-08 18:56 - 00000000 ____D () C:\Users\Sven\AppData\Local\TuneUp Software 2015-02-08 18:56 - 2014-07-16 10:24 - 00040760 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2015-02-08 18:56 - 2014-07-16 10:24 - 00029496 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2015-02-08 18:56 - 2014-07-16 10:24 - 00025400 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll 2015-02-08 18:55 - 2015-02-08 18:56 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2014 2015-02-08 18:54 - 2015-02-08 18:54 - 00001560 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk 2015-02-08 18:53 - 2015-02-08 18:58 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-02-08 18:53 - 2015-02-08 18:53 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2015-02-08 18:53 - 2015-02-08 18:53 - 00000000 ____D () C:\Program Files (x86)\Free Codec Pack 2015-02-08 18:52 - 2015-02-08 18:52 - 03533008 _____ (DVDVideoSoft Ltd. ) C:\Users\Sven\Downloads\FreeYouTubeToMP3Converter.exe 2015-01-18 17:47 - 2015-01-18 17:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rob Papen Predator - Beat Version 2015-01-18 17:15 - 2015-01-18 17:15 - 00000814 _____ () C:\Users\Public\Desktop\Zynewave Podium.lnk 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\Users\Sven\Documents\Zynewave Podium Projects 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Zynewave 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zynewave 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\Program Files (x86)\Zynewave 2015-01-18 17:06 - 2015-01-18 17:06 - 00003064 _____ () C:\Windows\System32\Tasks\{9B9F2EF7-D444-4BAF-92FA-DA0DD1E9C56D} 2015-01-18 17:02 - 2015-01-18 17:02 - 00184320 _____ () C:\Users\Sven\Downloads\ReasonPatch(1).exe 2015-01-18 14:46 - 2015-01-18 17:02 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Propellerhead Software 2015-01-18 14:45 - 2015-01-18 14:45 - 00000000 ____D () C:\ProgramData\Propellerhead Software 2015-01-18 13:46 - 2015-01-18 13:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ableton 2015-01-18 13:46 - 2004-10-07 12:31 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71.dll 2015-01-18 13:46 - 2004-10-07 12:31 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2015-01-18 13:46 - 2004-10-07 12:31 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2015-01-18 13:46 - 2004-10-07 12:31 - 00212992 _____ (Propellerhead Software AB) C:\Windows\SysWOW64\ReWire.dll 2015-01-15 22:40 - 2015-01-15 22:41 - 00014014 _____ () C:\Users\Sven\Documents\MBW06-2.odt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-14 21:41 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp 2015-02-14 21:40 - 2014-09-12 19:07 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-02-14 21:38 - 2015-01-03 13:07 - 00000000 ___RD () C:\Users\Sven\OneDrive 2015-02-14 21:35 - 2014-08-15 11:50 - 00001144 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-14 21:35 - 2013-08-22 15:46 - 00033466 _____ () C:\Windows\setupact.log 2015-02-14 21:35 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-14 21:34 - 2013-11-25 11:55 - 01755062 _____ () C:\Windows\WindowsUpdate.log 2015-02-14 21:34 - 2013-09-06 05:51 - 01059394 _____ () C:\Windows\PFRO.log 2015-02-14 21:34 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-02-14 21:33 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Performance 2015-02-14 21:29 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2015-02-13 23:06 - 2013-11-25 12:02 - 00065536 _____ () C:\Windows\system32\spu_storage.bin 2015-02-13 19:32 - 2014-09-12 19:07 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-02-13 19:31 - 2013-11-25 20:47 - 00765582 _____ () C:\Windows\system32\perfh007.dat 2015-02-13 19:31 - 2013-11-25 20:47 - 00159366 _____ () C:\Windows\system32\perfc007.dat 2015-02-13 19:31 - 2013-09-06 05:58 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-13 19:25 - 2013-08-22 15:44 - 00362760 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-02-13 19:11 - 2014-08-15 11:50 - 00001148 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-11 21:43 - 2014-02-01 20:41 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1764654466-1334418769-576482932-1001 2015-02-11 21:24 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-02-11 21:23 - 2014-02-01 20:34 - 00000000 ____D () C:\Users\Sven 2015-02-10 18:53 - 2013-11-25 11:59 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-10 18:52 - 2014-04-06 18:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-10 18:52 - 2014-04-06 18:04 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-02-08 18:55 - 2014-04-25 18:40 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DVDVideoSoft 2015-02-08 18:54 - 2014-04-25 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-02-08 18:54 - 2014-04-25 18:42 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2015-02-08 18:36 - 2014-06-01 22:06 - 00000000 ____D () C:\Users\Sven\AppData\Local\CrashDumps 2015-02-06 18:06 - 2014-08-15 11:50 - 00004120 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-06 18:06 - 2014-08-15 11:50 - 00003884 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-04 22:17 - 2014-10-03 16:14 - 00000000 ____D () C:\Users\Sven\Documents\Texte 2015-02-03 20:31 - 2014-07-13 13:06 - 00714720 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-02-03 20:31 - 2014-07-13 13:06 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-01-28 19:44 - 2014-09-02 18:51 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-01-24 07:31 - 2014-12-04 20:10 - 00002054 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2015-01-24 07:31 - 2014-09-02 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony 2015-01-24 07:31 - 2013-11-25 12:21 - 00272510 _____ () C:\Windows\DPINST.LOG 2015-01-24 07:29 - 2013-11-25 12:20 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-01-18 14:46 - 2014-02-01 20:34 - 00000000 ____D () C:\Users\Sven\AppData\Local\VirtualStore ==================== Files in the root of some directories ======= 2013-11-25 12:24 - 2013-11-25 12:24 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some content of TEMP: ==================== C:\Users\Sven\AppData\Local\Temp\avgnt.exe C:\Users\Sven\AppData\Local\Temp\drm_dialogs.dll C:\Users\Sven\AppData\Local\Temp\drm_dyndata_7330014.dll C:\Users\Sven\AppData\Local\Temp\FreeYouTubeToMP3Converter.exe C:\Users\Sven\AppData\Local\Temp\Quarantine.exe C:\Users\Sven\AppData\Local\Temp\sqlite3.dll C:\Users\Sven\AppData\Local\Temp\tmp3E5B.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-11 21:14 ==================== End Of Log ============================ |
15.02.2015, 11:10 | #8 |
/// Malwareteam | Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Ok, dann gehts so weiter: Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\RunOnce: [Application Restart #0] => C:\Users\Sven\AppData\Local\Pokki\Engine\pokki.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-p (the data entry has 538 more characters). C:\Users\Sven\AppData\Local\Pokki HKU\S-1-5-21-1764654466-1334418769-576482932-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 ESET Online Scanner
Schritt 3 Starte noch einmal FRST.
Noch irgendwelche Probleme mit dem Rechner? Poste folgende Logfiles in deiner nächsten Antwort:
__________________ Gruß, Jonas |
15.02.2015, 15:27 | #9 |
| Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Hi, also momentan noch alles beim alten. Fast jeder Klick, öffnet bei mir ungewünschte Fenster. Hier die Logs. Fixlog.txt Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-02-2015 Ran by Sven at 2015-02-15 11:43:36 Run:1 Running from C:\Users\Sven\Downloads Loaded Profiles: Sven (Available profiles: Sven) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\RunOnce: [Application Restart #0] => C:\Users\Sven\AppData\Local\Pokki\Engine\pokki.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-p (the data entry has 538 more characters). C:\Users\Sven\AppData\Local\Pokki HKU\S-1-5-21-1764654466-1334418769-576482932-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ***************** HKU\S-1-5-21-1764654466-1334418769-576482932-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Application Restart #0 => value deleted successfully. "C:\Users\Sven\AppData\Local\Pokki" => File/Directory not found. "HKU\S-1-5-21-1764654466-1334418769-576482932-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk" => Key deleted successfully. ==== End of Fixlog 11:43:36 ==== Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=3d86a8f53041ec48b86e052de5772f9b # engine=22479 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-02-15 01:57:22 # local_time=2015-02-15 02:57:22 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 65692 30690978 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 7246384 29844816 0 0 # scanned=213946 # found=4 # cleaned=0 # scan_time=10842 sh=C21AAC7F201EC119D5B879EAB16525D76E75FA61 ft=1 fh=4c07350428b83a2f vn="Variante von Win32/BrowseFox.AF evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugincontainer.exe.vir" sh=9DF97B417C53958902D1876867B1B5233E107868 ft=1 fh=b6fea5969f17fc17 vn="Win32/Somoto.E evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Sven\Downloads\m4a-to-mp3-81converter.exe" sh=72A25E9732F5FEFEBB83E08E8AA653B75B00995E ft=1 fh=7dcb11e9b84159a1 vn="Variante von Win32/InstallCore.QW evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012_CB-DL-Manager.exe" sh=DD0841A3C2E510BD8ED2067F8AB9053EE9094871 ft=1 fh=cc69a5621e9cb0fb vn="Win32/OutBrowse.BU evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Sven\Downloads\Nicht bestätigt 263958.crdownload" FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-02-2015 Ran by Sven (administrator) on SVENS-NOTEBOOK on 15-02-2015 15:19:51 Running from C:\Users\Sven\Downloads Loaded Profiles: Sven (Available profiles: Sven) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMEvent.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QASvc.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\RMSvc.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QAEvent.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QAMsg.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMTray.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QuickAccess.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Greenshot) C:\Program Files\Greenshot\Greenshot.exe (Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Recovery Management\Notification\Notification.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\swriter.exe (Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.exe (Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.bin (Microsoft Corporation) C:\Windows\splwow64.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2890056 2013-09-06] (ELAN Microelectronics Corp.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor) HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [495616 2014-05-12] (Greenshot) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-25] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.) HKLM-x32\...\Run: [ReCycle Patch] => "E:\Sven\Musiktools\Reason\ReasonPatch(1).exe" -s HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] ( (Atheros Communications)) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466144 2014-11-27] (Sony) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\MountPoints2: {9c949fe8-e681-11e3-8270-0c54a5328d5d} - "E:\Setup.exe" HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\MountPoints2: {e17883e0-90bf-11e3-825e-0c54a5328d5d} - "E:\Setup.exe" HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\MountPoints2: {fb0770f4-313c-11e4-8278-0c54a5328d5d} - "E:\Startme.exe" ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKU\S-1-5-21-1764654466-1334418769-576482932-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=APJB SearchScopes: HKU\S-1-5-21-1764654466-1334418769-576482932-1001 -> {9EEA33CA-9F50-43C5-997E-7C9707250F33} URL = Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () Chrome: ======= CHR HomePage: Default -> CHR Profile: C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-15] CHR Extension: (Google Drive) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-15] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-06] CHR Extension: (YouTube) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-15] CHR Extension: (Google-Suche) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-15] CHR Extension: (Google Wallet) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-15] CHR Extension: (Google Mail) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-15] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-20] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe [2650696 2013-07-26] (Acer Incorporated) R3 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [663592 2013-07-05] (Acer Incorporated) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101192 2013-09-06] (ELAN Microelectronics Corp.) R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [File not signed] R2 LMSvc; C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe [457768 2013-08-03] (Acer Incorporate) R3 QASvc; C:\Program Files\Packard Bell\Packard Bell Quick Access\QASvc.exe [457768 2013-08-02] (Acer Incorporate) R3 RMSvc; C:\Program Files\Packard Bell\Packard Bell Quick Access\RMSvc.exe [448040 2013-08-02] (Acer Incorporate) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Qualcomm Atheros Communications, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [138240 2013-06-22] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-16] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-16] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-14] (Malwarebytes Corporation) R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2014-06-23] (TuneUp Software) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-15 11:48 - 2015-02-15 11:48 - 02347384 _____ (ESET) C:\Users\Sven\Downloads\esetsmartinstaller_deu.exe 2015-02-15 11:48 - 2015-02-15 11:48 - 00000000 ____D () C:\Program Files (x86)\ESET 2015-02-15 11:44 - 2015-02-15 11:44 - 00613304 _____ () C:\Users\Sven\Downloads\Nicht bestätigt 263958.crdownload 2015-02-14 21:47 - 2015-02-14 21:47 - 00000000 ____D () C:\Users\Sven\Downloads\FRST-OlderVersion 2015-02-14 21:46 - 2015-02-14 21:46 - 00001707 _____ () C:\Users\Sven\Desktop\mbam.txt 2015-02-13 19:32 - 2015-02-13 19:32 - 00001126 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-02-13 19:30 - 2015-02-13 19:31 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.4.1028.exe 2015-02-13 19:16 - 2015-02-14 21:54 - 00000000 ____D () C:\AdwCleaner 2015-02-13 19:14 - 2015-02-13 19:14 - 02112512 _____ () C:\Users\Sven\Downloads\AdwCleaner_4.110.exe 2015-02-13 18:30 - 2015-02-13 18:41 - 00027703 _____ () C:\Users\Sven\Downloads\Addition.txt 2015-02-13 18:28 - 2015-02-15 15:19 - 00013160 _____ () C:\Users\Sven\Downloads\FRST.txt 2015-02-13 18:27 - 2015-02-15 15:19 - 00000000 ____D () C:\FRST 2015-02-11 21:37 - 2015-02-14 21:47 - 02134528 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe 2015-02-11 21:23 - 2015-02-11 21:23 - 00000470 _____ () C:\Users\Sven\Downloads\defogger_disable.log 2015-02-11 21:23 - 2015-02-11 21:23 - 00000000 _____ () C:\Users\Sven\defogger_reenable 2015-02-11 21:22 - 2015-02-11 21:22 - 00050477 _____ () C:\Users\Sven\Downloads\Defogger.exe 2015-02-11 21:07 - 2015-02-11 21:07 - 00002770 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2015-02-11 20:41 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2015-02-11 20:41 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2015-02-11 20:41 - 2014-12-09 00:12 - 00391526 _____ () C:\Windows\system32\ApnDatabase.xml 2015-02-11 20:40 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2015-02-11 20:16 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll 2015-02-11 20:16 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll 2015-02-11 20:15 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-02-11 20:15 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-02-11 20:15 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2015-02-11 20:15 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2015-02-11 20:15 - 2015-01-13 23:11 - 01762840 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-02-11 20:15 - 2015-01-13 23:04 - 01489072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-02-11 20:15 - 2015-01-10 10:10 - 07472960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-02-11 20:15 - 2015-01-10 10:10 - 01733440 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-02-11 20:15 - 2015-01-10 09:28 - 01498360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-02-11 20:15 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-02-11 20:15 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-02-11 20:15 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-02-11 20:15 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-02-11 20:15 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-02-11 20:15 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-02-11 20:15 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-02-11 20:15 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-02-11 20:15 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-02-11 20:15 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-02-11 20:15 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-02-11 20:15 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-02-11 20:15 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-02-11 20:14 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-02-11 20:14 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-02-11 20:14 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-02-11 20:14 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-02-11 20:14 - 2015-01-12 03:34 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-02-11 20:14 - 2015-01-12 03:32 - 06041088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-02-11 20:14 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-02-11 20:14 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-02-11 20:14 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-02-11 20:14 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-02-11 20:14 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-02-11 20:14 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-02-11 20:14 - 2015-01-12 02:58 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2015-02-11 20:14 - 2015-01-12 02:55 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-02-11 20:14 - 2015-01-12 02:51 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-02-11 20:14 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-02-11 20:14 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-02-11 20:14 - 2015-01-12 02:48 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-02-11 20:14 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-02-11 20:14 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-02-11 20:14 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-02-11 20:14 - 2015-01-12 02:34 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2015-02-11 20:14 - 2015-01-12 02:30 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2015-02-11 20:14 - 2015-01-12 02:29 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-02-11 20:14 - 2015-01-12 02:27 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2015-02-11 20:14 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-02-11 20:14 - 2015-01-12 02:25 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-02-11 20:14 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-02-11 20:14 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-02-11 20:14 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-02-11 20:14 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-02-11 20:14 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-02-11 20:14 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-02-11 20:14 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-02-11 20:14 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-02-11 20:14 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-02-11 20:14 - 2015-01-10 08:00 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-02-11 20:14 - 2015-01-10 07:38 - 00359424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-02-11 20:13 - 2015-01-10 09:22 - 04175872 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-02-08 18:59 - 2015-02-08 18:59 - 00000000 ____D () C:\Users\Sven\AppData\Local\Skype 2015-02-08 18:58 - 2015-02-11 20:05 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Skype 2015-02-08 18:58 - 2015-02-11 20:05 - 00000000 ____D () C:\ProgramData\Skype 2015-02-08 18:56 - 2015-02-08 18:56 - 00002233 _____ () C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk 2015-02-08 18:56 - 2015-02-08 18:56 - 00002225 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014.lnk 2015-02-08 18:56 - 2015-02-08 18:56 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\TuneUp Software 2015-02-08 18:56 - 2015-02-08 18:56 - 00000000 ____D () C:\Users\Sven\AppData\Local\TuneUp Software 2015-02-08 18:56 - 2014-07-16 10:24 - 00040760 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2015-02-08 18:56 - 2014-07-16 10:24 - 00029496 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2015-02-08 18:56 - 2014-07-16 10:24 - 00025400 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll 2015-02-08 18:55 - 2015-02-08 18:56 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2014 2015-02-08 18:54 - 2015-02-08 18:54 - 00001560 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk 2015-02-08 18:53 - 2015-02-08 18:58 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-02-08 18:53 - 2015-02-08 18:53 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2015-02-08 18:53 - 2015-02-08 18:53 - 00000000 ____D () C:\Program Files (x86)\Free Codec Pack 2015-02-08 18:52 - 2015-02-08 18:52 - 03533008 _____ (DVDVideoSoft Ltd. ) C:\Users\Sven\Downloads\FreeYouTubeToMP3Converter.exe 2015-01-18 17:47 - 2015-01-18 17:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rob Papen Predator - Beat Version 2015-01-18 17:15 - 2015-01-18 17:15 - 00000814 _____ () C:\Users\Public\Desktop\Zynewave Podium.lnk 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\Users\Sven\Documents\Zynewave Podium Projects 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Zynewave 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zynewave 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\Program Files (x86)\Zynewave 2015-01-18 17:06 - 2015-01-18 17:06 - 00003064 _____ () C:\Windows\System32\Tasks\{9B9F2EF7-D444-4BAF-92FA-DA0DD1E9C56D} 2015-01-18 17:02 - 2015-01-18 17:02 - 00184320 _____ () C:\Users\Sven\Downloads\ReasonPatch(1).exe 2015-01-18 14:46 - 2015-01-18 17:02 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Propellerhead Software 2015-01-18 14:45 - 2015-01-18 14:45 - 00000000 ____D () C:\ProgramData\Propellerhead Software 2015-01-18 13:46 - 2015-01-18 13:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ableton 2015-01-18 13:46 - 2004-10-07 12:31 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71.dll 2015-01-18 13:46 - 2004-10-07 12:31 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2015-01-18 13:46 - 2004-10-07 12:31 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2015-01-18 13:46 - 2004-10-07 12:31 - 00212992 _____ (Propellerhead Software AB) C:\Windows\SysWOW64\ReWire.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-15 15:11 - 2014-08-15 11:50 - 00001148 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-15 15:01 - 2013-11-25 11:55 - 01926914 _____ () C:\Windows\WindowsUpdate.log 2015-02-15 15:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2015-02-14 21:41 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp 2015-02-14 21:40 - 2014-09-12 19:07 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-02-14 21:38 - 2015-01-03 13:07 - 00000000 ____D () C:\Users\Sven\OneDrive 2015-02-14 21:35 - 2014-08-15 11:50 - 00001144 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-14 21:35 - 2013-08-22 15:46 - 00033466 _____ () C:\Windows\setupact.log 2015-02-14 21:35 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-14 21:34 - 2013-09-06 05:51 - 01059394 _____ () C:\Windows\PFRO.log 2015-02-14 21:34 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Performance 2015-02-14 21:34 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-02-13 23:06 - 2013-11-25 12:02 - 00065536 _____ () C:\Windows\system32\spu_storage.bin 2015-02-13 19:32 - 2014-09-12 19:07 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-02-13 19:31 - 2013-11-25 20:47 - 00765582 _____ () C:\Windows\system32\perfh007.dat 2015-02-13 19:31 - 2013-11-25 20:47 - 00159366 _____ () C:\Windows\system32\perfc007.dat 2015-02-13 19:31 - 2013-09-06 05:58 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-13 19:25 - 2013-08-22 15:44 - 00362760 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-02-11 21:43 - 2014-02-01 20:41 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1764654466-1334418769-576482932-1001 2015-02-11 21:24 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-02-11 21:23 - 2014-02-01 20:34 - 00000000 ____D () C:\Users\Sven 2015-02-10 18:53 - 2013-11-25 11:59 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-10 18:52 - 2014-04-06 18:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-10 18:52 - 2014-04-06 18:04 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-02-08 18:55 - 2014-04-25 18:40 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DVDVideoSoft 2015-02-08 18:54 - 2014-04-25 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-02-08 18:54 - 2014-04-25 18:42 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2015-02-08 18:36 - 2014-06-01 22:06 - 00000000 ____D () C:\Users\Sven\AppData\Local\CrashDumps 2015-02-06 18:06 - 2014-08-15 11:50 - 00004120 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-06 18:06 - 2014-08-15 11:50 - 00003884 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-04 22:17 - 2014-10-03 16:14 - 00000000 ____D () C:\Users\Sven\Documents\Texte 2015-02-03 20:31 - 2014-07-13 13:06 - 00714720 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-02-03 20:31 - 2014-07-13 13:06 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-01-28 19:44 - 2014-09-02 18:51 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-01-24 07:31 - 2014-12-04 20:10 - 00002054 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2015-01-24 07:31 - 2014-09-02 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony 2015-01-24 07:31 - 2013-11-25 12:21 - 00272510 _____ () C:\Windows\DPINST.LOG 2015-01-24 07:29 - 2013-11-25 12:20 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-01-18 14:46 - 2014-02-01 20:34 - 00000000 ____D () C:\Users\Sven\AppData\Local\VirtualStore ==================== Files in the root of some directories ======= 2013-11-25 12:24 - 2013-11-25 12:24 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some content of TEMP: ==================== C:\Users\Sven\AppData\Local\Temp\avgnt.exe C:\Users\Sven\AppData\Local\Temp\drm_dialogs.dll C:\Users\Sven\AppData\Local\Temp\drm_dyndata_7330014.dll C:\Users\Sven\AppData\Local\Temp\FreeYouTubeToMP3Converter.exe C:\Users\Sven\AppData\Local\Temp\Quarantine.exe C:\Users\Sven\AppData\Local\Temp\sqlite3.dll C:\Users\Sven\AppData\Local\Temp\tmp3E5B.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-11 21:14 ==================== End Of Log ============================ Gruß BTao |
15.02.2015, 15:55 | #10 |
/// Malwareteam | Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Hi, tritt die Werbung in allen Browsern auf oder nur in Google Chrome?
__________________ Gruß, Jonas |
15.02.2015, 16:26 | #11 |
| Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Explorer läuft normal, keine neuen Fenster, keine Popups, Mozilla habe ich nicht installiert. Also scheint es nur bei Chrome das Problem zu geben. Grüße |
15.02.2015, 16:51 | #12 |
/// Malwareteam | Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Ok, wie ich vermutet hatte. Schritt 1 Öffne Google Chrome.
Wenn der erste Schritt nicht funktioniert hat, dann bitte Chrome komplett deinstallieren und wieder neuinstallieren. Schritt 2 Starte noch einmal FRST.
Sind die Probleme immernoch vorhanden? Poste folgende Logfiles in deiner nächsten Antwort:
__________________ Gruß, Jonas |
15.02.2015, 18:02 | #13 |
| Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Hey, also Chrome musste De- und Neu-installiert werden. Hier das frische FRST. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-02-2015 Ran by Sven (administrator) on SVENS-NOTEBOOK on 15-02-2015 17:54:53 Running from C:\Users\Sven\Downloads Loaded Profiles: Sven (Available profiles: Sven) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMEvent.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QASvc.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\RMSvc.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QAEvent.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QAMsg.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMTray.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QuickAccess.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Greenshot) C:\Program Files\Greenshot\Greenshot.exe (Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Recovery Management\Notification\Notification.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2890056 2013-09-06] (ELAN Microelectronics Corp.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor) HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [495616 2014-05-12] (Greenshot) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-25] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.) HKLM-x32\...\Run: [ReCycle Patch] => "E:\Sven\Musiktools\Reason\ReasonPatch(1).exe" -s HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] ( (Atheros Communications)) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466144 2014-11-27] (Sony) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\MountPoints2: {9c949fe8-e681-11e3-8270-0c54a5328d5d} - "E:\Setup.exe" HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\MountPoints2: {e17883e0-90bf-11e3-825e-0c54a5328d5d} - "E:\Setup.exe" HKU\S-1-5-21-1764654466-1334418769-576482932-1001\...\MountPoints2: {fb0770f4-313c-11e4-8278-0c54a5328d5d} - "E:\Startme.exe" ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1764654466-1334418769-576482932-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKU\S-1-5-21-1764654466-1334418769-576482932-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=APJB SearchScopes: HKU\S-1-5-21-1764654466-1334418769-576482932-1001 -> {9EEA33CA-9F50-43C5-997E-7C9707250F33} URL = Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () Chrome: ======= CHR Profile: C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-15] CHR Extension: (Google Docs) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-15] CHR Extension: (Google Drive) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-15] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-02-15] CHR Extension: (YouTube) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-15] CHR Extension: (Google-Suche) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-15] CHR Extension: (Google Tabellen) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-15] CHR Extension: (Google Wallet) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-15] CHR Extension: (Google Mail) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-15] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-20] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe [2650696 2013-07-26] (Acer Incorporated) R3 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [663592 2013-07-05] (Acer Incorporated) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101192 2013-09-06] (ELAN Microelectronics Corp.) R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [File not signed] R2 LMSvc; C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe [457768 2013-08-03] (Acer Incorporate) R3 QASvc; C:\Program Files\Packard Bell\Packard Bell Quick Access\QASvc.exe [457768 2013-08-02] (Acer Incorporate) R3 RMSvc; C:\Program Files\Packard Bell\Packard Bell Quick Access\RMSvc.exe [448040 2013-08-02] (Acer Incorporate) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Qualcomm Atheros Communications, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [138240 2013-06-22] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-16] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-16] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-14] (Malwarebytes Corporation) R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-15 17:51 - 2015-02-15 17:51 - 00002279 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-02-15 17:51 - 2015-02-15 17:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-02-15 17:47 - 2015-02-15 17:52 - 00001136 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-15 17:47 - 2015-02-15 17:52 - 00001132 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-15 17:47 - 2015-02-15 17:47 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-15 17:47 - 2015-02-15 17:47 - 00003872 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-15 17:47 - 2015-02-15 17:47 - 00000000 ____D () C:\Users\Sven\AppData\Local\Deployment 2015-02-15 17:47 - 2015-02-15 17:47 - 00000000 ____D () C:\Users\Sven\AppData\Local\Apps\2.0 2015-02-15 16:19 - 2015-02-15 16:19 - 00000000 __SHD () C:\Users\Sven\AppData\Local\EmieBrowserModeList 2015-02-15 11:48 - 2015-02-15 11:48 - 02347384 _____ (ESET) C:\Users\Sven\Downloads\esetsmartinstaller_deu.exe 2015-02-15 11:48 - 2015-02-15 11:48 - 00000000 ____D () C:\Program Files (x86)\ESET 2015-02-14 21:47 - 2015-02-14 21:47 - 00000000 ____D () C:\Users\Sven\Downloads\FRST-OlderVersion 2015-02-14 21:46 - 2015-02-14 21:46 - 00001707 _____ () C:\Users\Sven\Desktop\mbam.txt 2015-02-13 19:32 - 2015-02-13 19:32 - 00001126 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-02-13 19:30 - 2015-02-13 19:31 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.4.1028.exe 2015-02-13 19:16 - 2015-02-14 21:54 - 00000000 ____D () C:\AdwCleaner 2015-02-13 19:14 - 2015-02-13 19:14 - 02112512 _____ () C:\Users\Sven\Downloads\AdwCleaner_4.110.exe 2015-02-13 18:30 - 2015-02-13 18:41 - 00027703 _____ () C:\Users\Sven\Downloads\Addition.txt 2015-02-13 18:28 - 2015-02-15 17:54 - 00012862 _____ () C:\Users\Sven\Downloads\FRST.txt 2015-02-13 18:27 - 2015-02-15 17:54 - 00000000 ____D () C:\FRST 2015-02-11 21:37 - 2015-02-14 21:47 - 02134528 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe 2015-02-11 21:23 - 2015-02-11 21:23 - 00000470 _____ () C:\Users\Sven\Downloads\defogger_disable.log 2015-02-11 21:23 - 2015-02-11 21:23 - 00000000 _____ () C:\Users\Sven\defogger_reenable 2015-02-11 21:22 - 2015-02-11 21:22 - 00050477 _____ () C:\Users\Sven\Downloads\Defogger.exe 2015-02-11 20:41 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2015-02-11 20:41 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2015-02-11 20:41 - 2014-12-09 00:12 - 00391526 _____ () C:\Windows\system32\ApnDatabase.xml 2015-02-11 20:40 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2015-02-11 20:16 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll 2015-02-11 20:16 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll 2015-02-11 20:15 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-02-11 20:15 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-02-11 20:15 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2015-02-11 20:15 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2015-02-11 20:15 - 2015-01-13 23:11 - 01762840 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-02-11 20:15 - 2015-01-13 23:04 - 01489072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-02-11 20:15 - 2015-01-10 10:10 - 07472960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-02-11 20:15 - 2015-01-10 10:10 - 01733440 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-02-11 20:15 - 2015-01-10 09:28 - 01498360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-02-11 20:15 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-02-11 20:15 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-02-11 20:15 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-02-11 20:15 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-02-11 20:15 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-02-11 20:15 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-02-11 20:15 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-02-11 20:15 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-02-11 20:15 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-02-11 20:15 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-02-11 20:15 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-02-11 20:15 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-02-11 20:15 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-02-11 20:14 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-02-11 20:14 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-02-11 20:14 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-02-11 20:14 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-02-11 20:14 - 2015-01-12 03:34 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-02-11 20:14 - 2015-01-12 03:32 - 06041088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-02-11 20:14 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-02-11 20:14 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-02-11 20:14 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-02-11 20:14 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-02-11 20:14 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-02-11 20:14 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-02-11 20:14 - 2015-01-12 02:58 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2015-02-11 20:14 - 2015-01-12 02:55 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-02-11 20:14 - 2015-01-12 02:51 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-02-11 20:14 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-02-11 20:14 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-02-11 20:14 - 2015-01-12 02:48 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-02-11 20:14 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-02-11 20:14 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-02-11 20:14 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-02-11 20:14 - 2015-01-12 02:34 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2015-02-11 20:14 - 2015-01-12 02:30 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2015-02-11 20:14 - 2015-01-12 02:29 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-02-11 20:14 - 2015-01-12 02:27 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2015-02-11 20:14 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-02-11 20:14 - 2015-01-12 02:25 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-02-11 20:14 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-02-11 20:14 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-02-11 20:14 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-02-11 20:14 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-02-11 20:14 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-02-11 20:14 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-02-11 20:14 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-02-11 20:14 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-02-11 20:14 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-02-11 20:14 - 2015-01-10 08:00 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-02-11 20:14 - 2015-01-10 07:38 - 00359424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-02-11 20:13 - 2015-01-10 09:22 - 04175872 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-02-08 18:59 - 2015-02-08 18:59 - 00000000 ____D () C:\Users\Sven\AppData\Local\Skype 2015-02-08 18:58 - 2015-02-11 20:05 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Skype 2015-02-08 18:58 - 2015-02-11 20:05 - 00000000 ____D () C:\ProgramData\Skype 2015-02-08 18:56 - 2015-02-08 18:56 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\TuneUp Software 2015-02-08 18:56 - 2015-02-08 18:56 - 00000000 ____D () C:\Users\Sven\AppData\Local\TuneUp Software 2015-02-08 18:54 - 2015-02-08 18:54 - 00001560 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk 2015-02-08 18:53 - 2015-02-08 18:58 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-02-08 18:53 - 2015-02-08 18:53 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2015-02-08 18:53 - 2015-02-08 18:53 - 00000000 ____D () C:\Program Files (x86)\Free Codec Pack 2015-02-08 18:52 - 2015-02-08 18:52 - 03533008 _____ (DVDVideoSoft Ltd. ) C:\Users\Sven\Downloads\FreeYouTubeToMP3Converter.exe 2015-01-18 17:47 - 2015-01-18 17:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rob Papen Predator - Beat Version 2015-01-18 17:15 - 2015-01-18 17:15 - 00000814 _____ () C:\Users\Public\Desktop\Zynewave Podium.lnk 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\Users\Sven\Documents\Zynewave Podium Projects 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Zynewave 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zynewave 2015-01-18 17:15 - 2015-01-18 17:15 - 00000000 ____D () C:\Program Files (x86)\Zynewave 2015-01-18 17:06 - 2015-01-18 17:06 - 00003064 _____ () C:\Windows\System32\Tasks\{9B9F2EF7-D444-4BAF-92FA-DA0DD1E9C56D} 2015-01-18 17:02 - 2015-01-18 17:02 - 00184320 _____ () C:\Users\Sven\Downloads\ReasonPatch(1).exe 2015-01-18 14:46 - 2015-01-18 17:02 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Propellerhead Software 2015-01-18 14:45 - 2015-01-18 14:45 - 00000000 ____D () C:\ProgramData\Propellerhead Software 2015-01-18 13:46 - 2015-01-18 13:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ableton 2015-01-18 13:46 - 2004-10-07 12:31 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71.dll 2015-01-18 13:46 - 2004-10-07 12:31 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2015-01-18 13:46 - 2004-10-07 12:31 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2015-01-18 13:46 - 2004-10-07 12:31 - 00212992 _____ (Propellerhead Software AB) C:\Windows\SysWOW64\ReWire.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-15 17:51 - 2014-08-15 11:50 - 00000000 ____D () C:\Program Files (x86)\Google 2015-02-15 17:51 - 2014-08-15 11:49 - 00000000 ____D () C:\Users\Sven\AppData\Local\Google 2015-02-15 17:49 - 2014-02-01 20:41 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1764654466-1334418769-576482932-1001 2015-02-15 17:00 - 2013-11-25 11:55 - 01955533 _____ () C:\Windows\WindowsUpdate.log 2015-02-15 17:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2015-02-15 15:00 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp 2015-02-14 21:40 - 2014-09-12 19:07 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-02-14 21:38 - 2015-01-03 13:07 - 00000000 ____D () C:\Users\Sven\OneDrive 2015-02-14 21:35 - 2013-08-22 15:46 - 00033466 _____ () C:\Windows\setupact.log 2015-02-14 21:35 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-14 21:34 - 2013-09-06 05:51 - 01059394 _____ () C:\Windows\PFRO.log 2015-02-14 21:34 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Performance 2015-02-14 21:34 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-02-13 23:06 - 2013-11-25 12:02 - 00065536 _____ () C:\Windows\system32\spu_storage.bin 2015-02-13 19:32 - 2014-09-12 19:07 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-02-13 19:31 - 2013-11-25 20:47 - 00765582 _____ () C:\Windows\system32\perfh007.dat 2015-02-13 19:31 - 2013-11-25 20:47 - 00159366 _____ () C:\Windows\system32\perfc007.dat 2015-02-13 19:31 - 2013-09-06 05:58 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-13 19:25 - 2013-08-22 15:44 - 00362760 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-02-11 21:24 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-02-11 21:23 - 2014-02-01 20:34 - 00000000 ____D () C:\Users\Sven 2015-02-10 18:53 - 2013-11-25 11:59 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-10 18:52 - 2014-04-06 18:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-10 18:52 - 2014-04-06 18:04 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-02-08 18:55 - 2014-04-25 18:40 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DVDVideoSoft 2015-02-08 18:54 - 2014-04-25 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-02-08 18:54 - 2014-04-25 18:42 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2015-02-08 18:36 - 2014-06-01 22:06 - 00000000 ____D () C:\Users\Sven\AppData\Local\CrashDumps 2015-02-04 22:17 - 2014-10-03 16:14 - 00000000 ____D () C:\Users\Sven\Documents\Texte 2015-02-03 20:31 - 2014-07-13 13:06 - 00714720 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-02-03 20:31 - 2014-07-13 13:06 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-01-28 19:44 - 2014-09-02 18:51 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-01-24 07:31 - 2014-12-04 20:10 - 00002054 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2015-01-24 07:31 - 2014-09-02 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony 2015-01-24 07:31 - 2013-11-25 12:21 - 00272510 _____ () C:\Windows\DPINST.LOG 2015-01-24 07:29 - 2013-11-25 12:20 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-01-18 14:46 - 2014-02-01 20:34 - 00000000 ____D () C:\Users\Sven\AppData\Local\VirtualStore ==================== Files in the root of some directories ======= 2013-11-25 12:24 - 2013-11-25 12:24 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some content of TEMP: ==================== C:\Users\Sven\AppData\Local\Temp\avgnt.exe C:\Users\Sven\AppData\Local\Temp\drm_dialogs.dll C:\Users\Sven\AppData\Local\Temp\drm_dyndata_7330014.dll C:\Users\Sven\AppData\Local\Temp\DseShExt-x64.dll C:\Users\Sven\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Sven\AppData\Local\Temp\FreeYouTubeToMP3Converter.exe C:\Users\Sven\AppData\Local\Temp\Quarantine.exe C:\Users\Sven\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\Sven\AppData\Local\Temp\SDShelEx-x64.dll C:\Users\Sven\AppData\Local\Temp\sqlite3.dll C:\Users\Sven\AppData\Local\Temp\tmp3E5B.exe C:\Users\Sven\AppData\Local\Temp\TUUUninstallHelper.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-11 21:14 ==================== End Of Log ============================ |
15.02.2015, 19:24 | #14 | ||||||||
/// Malwareteam | Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Moin, sieht alles gut soweit aus. Wenn du jetzt keine Probleme oder Fragen mehr hast, sind wir fertig . Cleanup Falls du Malwarebytes Anti-Malware und den ESET Online Scanner nicht mehr behalten möchtest, kannst du diese über die Systemsteuerung deinstallieren. Ich empfehle dir, mindestens ein Programm zu behalten (näheres in den Tipps). Windows XP: Start --> Systemsteuerung --> Kategorieansicht auswählen (falls nicht voreingestellt) --> SoftwareDie Reihenfolge ist hier entscheidend.
In deinen Logfiles sehe ich im Moment keine schädlichen Einträge mehr, du bist in meinen Augen Clean. Für die Zukunft habe ich dir Tipps aufgeschrieben, damit du uns in nächster Zeit nicht mehr brauchst . Tipps - Frequently Asked Questions (FAQ)/Häufig gestellte Fragen Welcher Antivirenscanner ist der beste?
Aber Updates muss ich immer installieren, oder?
Ok, muss ich auf etwas achten, wenn ich im Internet surfe?
Welche Programme sollte ich nicht verwenden?
Gibt es noch weitere Tipps, um mich zu schützen? Wenn dich das Thema Computersicherheit interessiert und du noch mehr Tipps und Tricks zum Schutz deines Rechners haben willst, ist der Emsisoft Blog genau richtig für dich .
Wenn du die Arbeit des Trojaner-Boards unterstützen möchtest, kannst du gerne spenden . Ich wünsche dir eine schöne und malwarefreie Zeit .
__________________ Gruß, Jonas |
15.02.2015, 19:55 | #15 |
| Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! Yuhuuuu ! Danke Jonas für Deine Hilfe. Ich habe Defogger genutzt, bevor ich hier um Rat gefragt habe, jetzt aber schon gelöscht, und das re-enable zu aktivieren. Muss ich defogger nun nochmal installieren? |
Themen zu Es öffnen sich alle 10 Sekunden neue Fenster! Hilfe! |
abstürze, beheben, fenster, hilfe, hilfe!, klicke, klicken, meldung, neue, sekunden, öffnen |