![]() |
Problem mit JAVA Hallo... Seit ca. 10 Tage habe ich nur Werbungen, Pornografie und eine Meldung; Ihre JAVA Version ist veraltet.... Kennt ihr das Problem??? Ist egal ob ich ja, nein, abreche oder sonst was ich komme nicht weiter, mein PC zeigt 100 Male immer die gleiche Meldung, sodass ich Internet komplett ausschalten muss. ich habe schon JAVA deinstalliert und mehrere Male das PC auf ein früher Zeitpunkt gestellt... ich kann nicht Dowload, Google... sogar meine Registrierung bei euch musste ich per Handy machen. Jetzt habe ich erneut das PC aufgestellt auf Datum von 10.Okt. deshalb bin ich jetzt wieder in Internet aber in kurze Zeit währe ich schon wieder Werbung, unerwünschte Bilder usw... habe... ich habe fast null Kenntnisse bezüglich pc.... Könnten Ihr mir helfen... aber biete nur ziemlich klare Anweisungen !!! |
Hallo und :hallo: Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
|
:applaus:Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-11-2014 Ran by boggy at 2014-11-11 13:46:25 Running from C:\Users\boggy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q9P3U7K3 Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton 360 (Disabled - Out of date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} AS: Norton 360 (Disabled - Out of date) {631E4324-D31C-783F-EC5C-35AD42B18466} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton 360 (Disabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated) Advanced Driver Updater (HKLM-x32\...\Advanced Driver Updater_is1) (Version: 2.1.1086.11897 - Systweak Inc) Advanced System Protector (HKLM-x32\...\Advanced System Protector_is1) (Version: 2.1.1000.10158 - Systweak Inc) <==== ATTENTION D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden deal4real (HKLM-x32\...\{2FA77785-00C3-A920-6452-D4FE5C9C129F}) (Version: - "") DealsFactor (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - DealsFactor) <==== ATTENTION EPSON-Drucker-Software (HKLM-x32\...\EPSON Printer and Utilities) (Version: - ) Fast And Safe (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{64af91bf}) (Version: - GTgroup) <==== ATTENTION FMS (HKLM-x32\...\FMS) (Version: - ) Free Audio CD to MP3 Converter version 1.3.12.1228 (HKLM-x32\...\Free Audio CD to MP3 Converter_is1) (Version: 1.3.12.1228 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.1.1.0 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden HP LinkUp (HKLM-x32\...\{DB3147AB-4024-4773-8EC0-A1FE5B44933D}) (Version: 2.01.028 - Hewlett-Packard) HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard) HP Setup (HKLM-x32\...\{D35B72B6-F0E4-462B-BDEB-E08032B3B681}) (Version: 8.7.4747.3786 - Hewlett-Packard Company) HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13880.3792 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{34681D92-5958-406A-A654-1B57E7A7B3DC}) (Version: 6.0.4.1 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard) HP Update (HKLM-x32\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard) HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.9.0.0 - Hewlett-Packard) Intel(R) Identity Protection Technology 1.1.2.0 (HKLM-x32\...\{C01A86F5-56E7-101F-9BC9-E3F1025EB779}) (Version: 1.1.2.0 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation) Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.600 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Norton 360 (HKLM-x32\...\N360) (Version: 21.6.0.32 - Symantec Corporation) Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) OpenOffice.org 3.3 (HKLM-x32\...\{4286716B-1287-48E7-9078-3DC8248DBA96}) (Version: 3.3.9567 - OpenOffice.org) PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6463 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.0.4320 - CyberLink Corp.) Hidden SCL011 Contactless Reader (HKLM-x32\...\{101A21B2-E102-4F64-A7FA-CEF7182D0E2D}) (Version: 1.01 - SCM Microsystems) Snap.Do (HKLM-x32\...\{F97A8857-2A38-4CE9-A53A-F07E491F2DA8}) (Version: 11.77.1.17697 - ReSoft Ltd.) <==== ATTENTION Software Packages (HKU\S-1-5-21-1237914262-1250986476-3758271500-1000\...\Software Packages) (Version: - ) <==== ATTENTION topbuyerr (HKLM-x32\...\{FE139F4C-CE5B-121A-8A2D-191FA2226094}) (Version: - ToPbUYer) Video Power (HKLM-x32\...\{17DB3734-EAB4-4717-954B-C860EE162FBA}) (Version: 1.0.24 - Video Power) VIP Access SDK (1.0.1.4) (HKLM-x32\...\VIP Access SDK) (Version: 1.0.1.4 - Symantec Inc.) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 29-10-2014 13:32:09 Wiederherstellungsvorgang 29-10-2014 13:39:50 Windows Update 03-11-2014 10:17:13 Wiederherstellungsvorgang 03-11-2014 11:50:31 Windows Update 04-11-2014 14:00:10 Windows Update 04-11-2014 14:37:56 Wiederherstellungsvorgang 04-11-2014 15:04:17 Windows Update 05-11-2014 09:25:54 Removed Java 7 Update 60 05-11-2014 09:26:43 Removed Java 7 Update 60 05-11-2014 09:26:50 Windows Update 05-11-2014 09:29:56 Removed HP Vision Hardware Diagnostics 05-11-2014 09:30:56 Removed Norton Online Backup 05-11-2014 10:07:11 Windows Update 10-11-2014 12:25:59 Wiederherstellungsvorgang 10-11-2014 12:34:26 Windows Update 10-11-2014 13:11:53 Wiederherstellungsvorgang 10-11-2014 13:21:28 Windows Update 10-11-2014 13:59:26 Removed HP Update. 11-11-2014 08:58:57 Windows Update 11-11-2014 09:41:00 Wiederherstellungsvorgang 11-11-2014 12:30:15 HPSF Restore Point ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0A6724A5-FEA2-47E5-A010-D4AECE36479A} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {0B432395-8B52-4D6C-A202-FAFAFDF8AEF4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [2011-03-23] (Hewlett-Packard Company) Task: {1342129F-E4CE-4D24-9519-33787F86D812} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-11] (Google Inc.) Task: {15AD049E-06B4-420F-B7F5-6A36F56DEC7A} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-05-07] (Oracle Corporation) Task: {17759052-332E-486D-979F-1BC6908AC38E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-11] (Google Inc.) Task: {40D25A1D-0406-4006-B872-F41B50663FAE} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-09-12] (Adobe Systems Incorporated) Task: {44320FF3-D201-4AF8-A789-D551DC64B053} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2011-06-09] (Hewlett-Packard Company) Task: {4892A222-2612-4E02-B1E1-9CE6528C7584} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2011-05-10] (Hewlett-Packard) Task: {528EFDA6-8A8B-429B-9884-DA7B7302CA76} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe [2011-06-09] (Hewlett-Packard Company) Task: {5FE0D04C-E453-4485-97CC-A27F512AC68E} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\WSCStub.exe [2014-09-21] (Symantec Corporation) Task: {80A2C11A-22E9-4E83-B3E3-141B5B6FF970} - System32\Tasks\AdvancedDriverUpdater_UPDATES => C:\Program Files (x86)\Advanced Driver Updater\adu.exe [2012-08-29] (Systweak Inc) Task: {89F0941E-5449-49E4-9D62-9924B328004D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-16] (Adobe Systems Incorporated) Task: {ABE06CE1-7383-481F-B889-EC09F3FDFA67} - System32\Tasks\Advanced System Protector => C:\Program Files (x86)\Advanced System Protector\AspManager.exe [2012-10-17] (Systweak) <==== ATTENTION Task: {D0904250-EEBF-48E8-BE45-855DB7E1D30D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2011-06-09] (Hewlett-Packard Company) Task: {E82AF7C4-8810-494B-8FC4-1C65968EFADD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater\HPSFUpdater.exe [2011-06-09] (Hewlett-Packard) Task: {F24330B5-D53E-455B-89E8-F74ADE7E0E7E} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AdvancedDriverUpdater_UPDATES.job => C:\Program Files (x86)\Advanced Driver Updater\adu.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-10-17 00:17 - 2011-01-27 18:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-07-09 19:48 - 2014-07-09 19:48 - 04302848 _____ () C:\ProgramData\Fast And Safe\FastAndSafe_x64.dll 2011-01-17 16:19 - 2012-01-11 16:02 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 2014-11-11 13:30 - 2014-11-11 13:30 - 00765440 _____ () C:\ProgramData\deal4real\bQgg3wzEgWiAaj.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-1237914262-1250986476-3758271500-500 - Administrator - Disabled) boggy (S-1-5-21-1237914262-1250986476-3758271500-1000 - Administrator - Enabled) => C:\Users\boggy Gast (S-1-5-21-1237914262-1250986476-3758271500-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1237914262-1250986476-3758271500-1002 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= Name: Microsoft-Teredo-Tunneling-Adapter Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (11/11/2014 01:20:25 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/11/2014 01:20:24 PM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=B78} Application Virtualization Client konnte keine Verbindung mit der Datenstrom-URL 'hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7130.5000.sft' herstellen (Rückgabecode 2460420A-40002EFD, ursprünglicher Rückgabecode 2460420A-40002EFD). Error: (11/11/2014 09:54:57 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/11/2014 09:54:57 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=944} Application Virtualization Client konnte keine Verbindung mit der Datenstrom-URL 'hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7130.5000.sft' herstellen (Rückgabecode 2460420A-40002EFD, ursprünglicher Rückgabecode 2460420A-40002EFD). Error: (11/11/2014 10:11:03 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/11/2014 10:11:03 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=B24} Application Virtualization Client konnte keine Verbindung mit der Datenstrom-URL 'hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7130.5000.sft' herstellen (Rückgabecode 2460420A-40002EFD, ursprünglicher Rückgabecode 2460420A-40002EFD). Error: (11/10/2014 05:30:53 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/10/2014 05:30:53 PM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=9F0} Application Virtualization Client konnte keine Verbindung mit der Datenstrom-URL 'hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7130.5000.sft' herstellen (Rückgabecode 2460420A-40002EFD, ursprünglicher Rückgabecode 2460420A-40002EFD). Error: (11/10/2014 03:56:45 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/10/2014 03:56:45 PM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=9F8} Application Virtualization Client konnte keine Verbindung mit der Datenstrom-URL 'hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7130.5000.sft' herstellen (Rückgabecode 2460420A-40002EFD, ursprünglicher Rückgabecode 2460420A-40002EFD). System errors: ============= Error: (11/11/2014 01:20:13 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80004005 Error: (11/09/2014 03:55:12 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:33:36 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:33:06 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:32:25 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:32:25 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:32:04 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:32:04 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:31:38 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:31:38 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Microsoft Office Sessions: ========================= Error: (11/11/2014 01:20:25 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/11/2014 01:20:24 PM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=B78} hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7130.5000.sft2460420A-40002EFD2460420A-40002EFD Error: (11/11/2014 09:54:57 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/11/2014 09:54:57 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=944} hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7130.5000.sft2460420A-40002EFD2460420A-40002EFD Error: (11/11/2014 10:11:03 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/11/2014 10:11:03 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=B24} hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7130.5000.sft2460420A-40002EFD2460420A-40002EFD Error: (11/10/2014 05:30:53 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/10/2014 05:30:53 PM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=9F0} hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7130.5000.sft2460420A-40002EFD2460420A-40002EFD Error: (11/10/2014 03:56:45 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/10/2014 03:56:45 PM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=9F8} hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7130.5000.sft2460420A-40002EFD2460420A-40002EFD ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz Percentage of memory in use: 48% Total physical RAM: 4000.82 MB Available physical RAM: 2077.18 MB Total Pagefile: 7999.81 MB Available Pagefile: 5873.03 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:918.72 GB) (Free:849.89 GB) NTFS Drive d: (HP_RECOVERY) (Fixed) (Total:12.69 GB) (Free:1.77 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive h: () (Removable) (Total:1.86 GB) (Free:1.14 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 1261E58F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=918.7 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=12.7 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 1.9 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-11-2014 |
Was ist mit meiner Frage nach bisherigen Virenfunden und den Logs dazu? Außerdem fehlt die FRST.txt, du hast 2x die Addition.txt gepostet. Bitte in CODE-Tags posten |
Sorry ich komme kaum in Internet deshalb beanworte ich zu spät... Ich habe 186 Malware!!! FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2014 --- --- --- Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-11-2014 Ran by boggy at 2014-11-15 12:37:19 Running from C:\Users\boggy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O76BR59E Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton 360 (Disabled - Out of date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} AS: Norton 360 (Disabled - Out of date) {631E4324-D31C-783F-EC5C-35AD42B18466} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton 360 (Disabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.223 - Adobe Systems Incorporated) Adobe Reader X (10.1.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems Incorporated) Advanced Driver Updater (HKLM-x32\...\Advanced Driver Updater_is1) (Version: 2.1.1086.11897 - Systweak Inc) Advanced System Protector (HKLM-x32\...\Advanced System Protector_is1) (Version: 2.1.1000.10158 - Systweak Inc) <==== ATTENTION D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden EPSON-Drucker-Software (HKLM-x32\...\EPSON Printer and Utilities) (Version: - ) Fast And Safe (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{64af91bf}) (Version: - GTgroup) <==== ATTENTION FMS (HKLM-x32\...\FMS) (Version: - ) Free Audio CD to MP3 Converter version 1.3.12.1228 (HKLM-x32\...\Free Audio CD to MP3 Converter_is1) (Version: 1.3.12.1228 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.1.1.0 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden HP LinkUp (HKLM-x32\...\{DB3147AB-4024-4773-8EC0-A1FE5B44933D}) (Version: 2.01.028 - Hewlett-Packard) HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard) HP Setup (HKLM-x32\...\{D35B72B6-F0E4-462B-BDEB-E08032B3B681}) (Version: 8.7.4747.3786 - Hewlett-Packard Company) HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13880.3792 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{34681D92-5958-406A-A654-1B57E7A7B3DC}) (Version: 6.0.4.1 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard) HP Update (HKLM-x32\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard) HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.9.0.0 - Hewlett-Packard) Intel(R) Identity Protection Technology 1.1.2.0 (HKLM-x32\...\{C01A86F5-56E7-101F-9BC9-E3F1025EB779}) (Version: 1.1.2.0 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation) Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.600 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Norton 360 (HKLM-x32\...\N360) (Version: 21.6.0.32 - Symantec Corporation) Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) OpenOffice.org 3.3 (HKLM-x32\...\{4286716B-1287-48E7-9078-3DC8248DBA96}) (Version: 3.3.9567 - OpenOffice.org) PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6463 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.0.4320 - CyberLink Corp.) Hidden SaveItCoupons (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - SaveItCoupons) <==== ATTENTION savernet (HKLM-x32\...\{614925F9-841A-53FE-A28F-DC30FA07239B}) (Version: - "") <==== ATTENTION SCL011 Contactless Reader (HKLM-x32\...\{101A21B2-E102-4F64-A7FA-CEF7182D0E2D}) (Version: 1.01 - SCM Microsystems) Snap.Do (HKLM-x32\...\{F97A8857-2A38-4CE9-A53A-F07E491F2DA8}) (Version: 11.77.1.17697 - ReSoft Ltd.) <==== ATTENTION Software Packages (HKU\S-1-5-21-1237914262-1250986476-3758271500-1000\...\Software Packages) (Version: - ) <==== ATTENTION topbuyerr (HKLM-x32\...\{FE139F4C-CE5B-121A-8A2D-191FA2226094}) (Version: - ToPbUYer) Video Power (HKLM-x32\...\{17DB3734-EAB4-4717-954B-C860EE162FBA}) (Version: 1.0.24 - Video Power) VIP Access SDK (1.0.1.4) (HKLM-x32\...\VIP Access SDK) (Version: 1.0.1.4 - Symantec Inc.) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) WinZip Malware Protector (HKLM-x32\...\WinZip Malware Protector_is1) (Version: 2.1.1000.10798 - WinZip International LLC) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 05-11-2014 10:07:11 Windows Update 10-11-2014 12:25:59 Wiederherstellungsvorgang 10-11-2014 12:34:26 Windows Update 10-11-2014 13:11:53 Wiederherstellungsvorgang 10-11-2014 13:21:28 Windows Update 10-11-2014 13:59:26 Removed HP Update. 11-11-2014 08:58:57 Windows Update 11-11-2014 09:41:00 Wiederherstellungsvorgang 11-11-2014 12:30:15 HPSF Restore Point 11-11-2014 13:04:23 Removed Java 7 Update 60 12-11-2014 17:46:36 Windows Update 15-11-2014 08:40:47 Removed Norton Online Backup 15-11-2014 09:08:01 Wiederherstellungsvorgang 15-11-2014 10:12:37 Windows-Sicherung 15-11-2014 10:17:28 Wiederherstellungsvorgang 15-11-2014 10:37:45 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0A6724A5-FEA2-47E5-A010-D4AECE36479A} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {0B432395-8B52-4D6C-A202-FAFAFDF8AEF4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [2011-03-23] (Hewlett-Packard Company) Task: {1342129F-E4CE-4D24-9519-33787F86D812} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-11] (Google Inc.) Task: {15AD049E-06B4-420F-B7F5-6A36F56DEC7A} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-05-07] (Oracle Corporation) Task: {17759052-332E-486D-979F-1BC6908AC38E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-11] (Google Inc.) Task: {40D25A1D-0406-4006-B872-F41B50663FAE} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated) Task: {44320FF3-D201-4AF8-A789-D551DC64B053} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2011-06-09] (Hewlett-Packard Company) Task: {4892A222-2612-4E02-B1E1-9CE6528C7584} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2011-05-10] (Hewlett-Packard) Task: {528EFDA6-8A8B-429B-9884-DA7B7302CA76} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe [2011-06-09] (Hewlett-Packard Company) Task: {5FE0D04C-E453-4485-97CC-A27F512AC68E} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\WSCStub.exe [2014-09-21] (Symantec Corporation) Task: {80A2C11A-22E9-4E83-B3E3-141B5B6FF970} - System32\Tasks\AdvancedDriverUpdater_UPDATES => C:\Program Files (x86)\Advanced Driver Updater\adu.exe [2012-08-29] (Systweak Inc) Task: {89F0941E-5449-49E4-9D62-9924B328004D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-15] (Adobe Systems Incorporated) Task: {907DD94B-5315-42C3-806D-9C2384BE987B} - System32\Tasks\WinZip Malware Protector_startup => C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe [2013-07-15] (Nico Mak Computing) Task: {ABE06CE1-7383-481F-B889-EC09F3FDFA67} - System32\Tasks\Advanced System Protector => C:\Program Files (x86)\Advanced System Protector\AspManager.exe [2012-10-17] (Systweak) <==== ATTENTION Task: {D0904250-EEBF-48E8-BE45-855DB7E1D30D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2011-06-09] (Hewlett-Packard Company) Task: {E82AF7C4-8810-494B-8FC4-1C65968EFADD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater\HPSFUpdater.exe [2011-06-09] (Hewlett-Packard) Task: {F24330B5-D53E-455B-89E8-F74ADE7E0E7E} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AdvancedDriverUpdater_UPDATES.job => C:\Program Files (x86)\Advanced Driver Updater\adu.exe Task: C:\Windows\Tasks\c509cbc0-4c69-4bcc-86b5-6cb1dcba61bf-5.job => C:\Users\boggy\AppData\Local\Weather It Up-BrowserExtensionUninstall\c509cbc0-4c69-4bcc-86b5-6cb1dcba61bf-5.exe Task: C:\Windows\Tasks\c7b116cb-b3a5-41d6-bde2-fc2c80b4960c-7.job => C:\Program Files (x86)\SmartSaver+ 15\c7b116cb-b3a5-41d6-bde2-fc2c80b4960c-7.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-10-17 00:17 - 2011-01-27 18:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-07-09 19:48 - 2014-07-09 19:48 - 04302848 _____ () C:\ProgramData\Fast And Safe\FastAndSafe_x64.dll 2011-01-17 16:19 - 2012-01-11 16:02 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 2014-11-15 11:59 - 2014-11-15 11:59 - 00756224 _____ () C:\ProgramData\savernet\46jVdVN5cgAJ7w.dll 2014-11-15 11:52 - 2013-02-28 16:53 - 00886272 _____ () C:\Program Files (x86)\WinZip Malware Protector\System.Data.SQLite.dll 2014-11-15 11:52 - 2013-07-15 16:53 - 01717936 _____ () C:\Program Files (x86)\WinZip Malware Protector\aspsys.dll 2014-11-15 11:52 - 2013-02-28 16:53 - 00168448 _____ () C:\Program Files (x86)\WinZip Malware Protector\UNRAR.DLL ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-1237914262-1250986476-3758271500-500 - Administrator - Disabled) boggy (S-1-5-21-1237914262-1250986476-3758271500-1000 - Administrator - Enabled) => C:\Users\boggy Gast (S-1-5-21-1237914262-1250986476-3758271500-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1237914262-1250986476-3758271500-1002 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= Name: Microsoft-Teredo-Tunneling-Adapter Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (11/15/2014 11:40:35 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/15/2014 11:40:35 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=9AC} Application Virtualization Client konnte keine Verbindung mit der Datenstrom-URL 'hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7137.5001.sft' herstellen (Rückgabecode 2460420A-40002EFD, ursprünglicher Rückgabecode 2460420A-40002EFD). Error: (11/15/2014 11:30:27 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/15/2014 11:30:27 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=9AC} Application Virtualization Client konnte keine Verbindung mit der Datenstrom-URL 'hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7137.5001.sft' herstellen (Rückgabecode 2460420A-40002EFD, ursprünglicher Rückgabecode 2460420A-40002EFD). Error: (11/15/2014 11:28:51 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Die Aktion kann nicht abgeschlossen werden. Versuchen Sie es erneut. Wenden Sie sich bei Fortbestehen des Problems an den Microsoft-Produktsupport. Error: (11/15/2014 10:18:01 AM) (Source: System Restore) (EventID: 8200) (User: ) Description: Fehler beim Initiieren der Systemwiederherstellung (Windows Update). Error: (11/15/2014 10:07:23 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: chrome.exe, Version: 35.0.1916.153, Zeitstempel: 0x538fb354 Name des fehlerhaften Moduls: chrome.dll, Version: 35.0.1916.153, Zeitstempel: 0x538fb051 Ausnahmecode: 0x80000003 Fehleroffset: 0x00485166 ID des fehlerhaften Prozesses: 0x2e4 Startzeit der fehlerhaften Anwendung: 0xchrome.exe0 Pfad der fehlerhaften Anwendung: chrome.exe1 Pfad des fehlerhaften Moduls: chrome.exe2 Berichtskennung: chrome.exe3 Error: (11/15/2014 09:47:44 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: PCSUQuickScan.exe, Version: 0.0.0.0, Zeitstempel: 0x54539729 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x5315a05a Ausnahmecode: 0xe06d7363 Fehleroffset: 0x000000000000940d ID des fehlerhaften Prozesses: 0x13f0 Startzeit der fehlerhaften Anwendung: 0xPCSUQuickScan.exe0 Pfad der fehlerhaften Anwendung: PCSUQuickScan.exe1 Pfad des fehlerhaften Moduls: PCSUQuickScan.exe2 Berichtskennung: PCSUQuickScan.exe3 Error: (11/15/2014 09:45:06 AM) (Source: MsiInstaller) (EventID: 11309) (User: boggy-HP) Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt. System error 3. Verify that the file exists and that you can access it. Error: (11/15/2014 09:33:37 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Fehler bei der Registrierung des Click-2-Run-Pakets. System errors: ============= Error: (11/15/2014 11:06:40 AM) (Source: volmgr) (EventID: 49) (User: ) Description: Die Konfiguration der Auslagerungsdatei für das Speicherabbild ist fehlgeschlagen. Stellen Sie sicher, dass eine Auslagerungsdatei auf der Startpartition vorhanden ist und dass diese groß genug ist, um den gesamten physikalischen Speicher abbilden zu können. Error: (11/12/2014 06:41:09 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/12/2014 06:41:09 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/11/2014 01:20:13 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80004005 Error: (11/09/2014 03:55:12 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:33:36 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:33:06 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:32:25 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:32:25 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:32:04 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Microsoft Office Sessions: ========================= Error: (11/15/2014 11:40:35 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/15/2014 11:40:35 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=9AC} hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7137.5001.sft2460420A-40002EFD2460420A-40002EFD Error: (11/15/2014 11:30:27 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/15/2014 11:30:27 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=9AC} hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7137.5001.sft2460420A-40002EFD2460420A-40002EFD Error: (11/15/2014 11:28:51 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Die Aktion kann nicht abgeschlossen werden. Versuchen Sie es erneut. Wenden Sie sich bei Fortbestehen des Problems an den Microsoft-Produktsupport. Error: (11/15/2014 10:18:01 AM) (Source: System Restore) (EventID: 8200) (User: ) Description: Windows Update0x81000101 Error: (11/15/2014 10:07:23 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: chrome.exe35.0.1916.153538fb354chrome.dll35.0.1916.153538fb05180000003004851662e401d000b366f4b56cC:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\chrome.dllce54f171-6ca6-11e4-aa7b-2c4138912aa6 Error: (11/15/2014 09:47:44 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: PCSUQuickScan.exe0.0.0.054539729KERNELBASE.dll6.1.7601.184095315a05ae06d7363000000000000940d13f001d000b0bf9ea4ceC:\Program Files (x86)\PC Speed Up\PCSUQuickScan.exeC:\Windows\system32\KERNELBASE.dll1068b73e-6ca4-11e4-aa7b-2c4138912aa6 Error: (11/15/2014 09:45:06 AM) (Source: MsiInstaller) (EventID: 11309) (User: boggy-HP) Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt. System error 3. Verify that the file exists and that you can access it.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (11/15/2014 09:33:37 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Fehler bei der Registrierung des Click-2-Run-Pakets. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz Percentage of memory in use: 51% Total physical RAM: 4000.82 MB Available physical RAM: 1945.32 MB Total Pagefile: 7999.81 MB Available Pagefile: 5885.86 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:918.72 GB) (Free:848.77 GB) NTFS Drive d: (HP_RECOVERY) (Fixed) (Total:12.69 GB) (Free:1.77 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (BADRA 2014) (Removable) (Total:14.44 GB) (Free:14.44 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 1261E58F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=918.7 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=12.7 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 14.5 GB) (Disk ID: 309D271B) Partition 1: (Not Active) - (Size=14.5 GB) - (Type=0B) ==================== End Of Log ============================Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-11-2014 Ran by boggy at 2014-11-15 12:37:19 Running from C:\Users\boggy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O76BR59E Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton 360 (Disabled - Out of date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} AS: Norton 360 (Disabled - Out of date) {631E4324-D31C-783F-EC5C-35AD42B18466} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton 360 (Disabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.223 - Adobe Systems Incorporated) Adobe Reader X (10.1.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems Incorporated) Advanced Driver Updater (HKLM-x32\...\Advanced Driver Updater_is1) (Version: 2.1.1086.11897 - Systweak Inc) Advanced System Protector (HKLM-x32\...\Advanced System Protector_is1) (Version: 2.1.1000.10158 - Systweak Inc) <==== ATTENTION D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden EPSON-Drucker-Software (HKLM-x32\...\EPSON Printer and Utilities) (Version: - ) Fast And Safe (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{64af91bf}) (Version: - GTgroup) <==== ATTENTION FMS (HKLM-x32\...\FMS) (Version: - ) Free Audio CD to MP3 Converter version 1.3.12.1228 (HKLM-x32\...\Free Audio CD to MP3 Converter_is1) (Version: 1.3.12.1228 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.1.1.0 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden HP LinkUp (HKLM-x32\...\{DB3147AB-4024-4773-8EC0-A1FE5B44933D}) (Version: 2.01.028 - Hewlett-Packard) HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard) HP Setup (HKLM-x32\...\{D35B72B6-F0E4-462B-BDEB-E08032B3B681}) (Version: 8.7.4747.3786 - Hewlett-Packard Company) HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13880.3792 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{34681D92-5958-406A-A654-1B57E7A7B3DC}) (Version: 6.0.4.1 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard) HP Update (HKLM-x32\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard) HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.9.0.0 - Hewlett-Packard) Intel(R) Identity Protection Technology 1.1.2.0 (HKLM-x32\...\{C01A86F5-56E7-101F-9BC9-E3F1025EB779}) (Version: 1.1.2.0 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation) Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.600 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Norton 360 (HKLM-x32\...\N360) (Version: 21.6.0.32 - Symantec Corporation) Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) OpenOffice.org 3.3 (HKLM-x32\...\{4286716B-1287-48E7-9078-3DC8248DBA96}) (Version: 3.3.9567 - OpenOffice.org) PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6463 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.0.4320 - CyberLink Corp.) Hidden SaveItCoupons (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - SaveItCoupons) <==== ATTENTION savernet (HKLM-x32\...\{614925F9-841A-53FE-A28F-DC30FA07239B}) (Version: - "") <==== ATTENTION SCL011 Contactless Reader (HKLM-x32\...\{101A21B2-E102-4F64-A7FA-CEF7182D0E2D}) (Version: 1.01 - SCM Microsystems) Snap.Do (HKLM-x32\...\{F97A8857-2A38-4CE9-A53A-F07E491F2DA8}) (Version: 11.77.1.17697 - ReSoft Ltd.) <==== ATTENTION Software Packages (HKU\S-1-5-21-1237914262-1250986476-3758271500-1000\...\Software Packages) (Version: - ) <==== ATTENTION topbuyerr (HKLM-x32\...\{FE139F4C-CE5B-121A-8A2D-191FA2226094}) (Version: - ToPbUYer) Video Power (HKLM-x32\...\{17DB3734-EAB4-4717-954B-C860EE162FBA}) (Version: 1.0.24 - Video Power) VIP Access SDK (1.0.1.4) (HKLM-x32\...\VIP Access SDK) (Version: 1.0.1.4 - Symantec Inc.) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) WinZip Malware Protector (HKLM-x32\...\WinZip Malware Protector_is1) (Version: 2.1.1000.10798 - WinZip International LLC) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 05-11-2014 10:07:11 Windows Update 10-11-2014 12:25:59 Wiederherstellungsvorgang 10-11-2014 12:34:26 Windows Update 10-11-2014 13:11:53 Wiederherstellungsvorgang 10-11-2014 13:21:28 Windows Update 10-11-2014 13:59:26 Removed HP Update. 11-11-2014 08:58:57 Windows Update 11-11-2014 09:41:00 Wiederherstellungsvorgang 11-11-2014 12:30:15 HPSF Restore Point 11-11-2014 13:04:23 Removed Java 7 Update 60 12-11-2014 17:46:36 Windows Update 15-11-2014 08:40:47 Removed Norton Online Backup 15-11-2014 09:08:01 Wiederherstellungsvorgang 15-11-2014 10:12:37 Windows-Sicherung 15-11-2014 10:17:28 Wiederherstellungsvorgang 15-11-2014 10:37:45 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0A6724A5-FEA2-47E5-A010-D4AECE36479A} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {0B432395-8B52-4D6C-A202-FAFAFDF8AEF4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [2011-03-23] (Hewlett-Packard Company) Task: {1342129F-E4CE-4D24-9519-33787F86D812} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-11] (Google Inc.) Task: {15AD049E-06B4-420F-B7F5-6A36F56DEC7A} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-05-07] (Oracle Corporation) Task: {17759052-332E-486D-979F-1BC6908AC38E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-11] (Google Inc.) Task: {40D25A1D-0406-4006-B872-F41B50663FAE} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated) Task: {44320FF3-D201-4AF8-A789-D551DC64B053} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2011-06-09] (Hewlett-Packard Company) Task: {4892A222-2612-4E02-B1E1-9CE6528C7584} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2011-05-10] (Hewlett-Packard) Task: {528EFDA6-8A8B-429B-9884-DA7B7302CA76} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe [2011-06-09] (Hewlett-Packard Company) Task: {5FE0D04C-E453-4485-97CC-A27F512AC68E} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\WSCStub.exe [2014-09-21] (Symantec Corporation) Task: {80A2C11A-22E9-4E83-B3E3-141B5B6FF970} - System32\Tasks\AdvancedDriverUpdater_UPDATES => C:\Program Files (x86)\Advanced Driver Updater\adu.exe [2012-08-29] (Systweak Inc) Task: {89F0941E-5449-49E4-9D62-9924B328004D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-15] (Adobe Systems Incorporated) Task: {907DD94B-5315-42C3-806D-9C2384BE987B} - System32\Tasks\WinZip Malware Protector_startup => C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe [2013-07-15] (Nico Mak Computing) Task: {ABE06CE1-7383-481F-B889-EC09F3FDFA67} - System32\Tasks\Advanced System Protector => C:\Program Files (x86)\Advanced System Protector\AspManager.exe [2012-10-17] (Systweak) <==== ATTENTION Task: {D0904250-EEBF-48E8-BE45-855DB7E1D30D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2011-06-09] (Hewlett-Packard Company) Task: {E82AF7C4-8810-494B-8FC4-1C65968EFADD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater\HPSFUpdater.exe [2011-06-09] (Hewlett-Packard) Task: {F24330B5-D53E-455B-89E8-F74ADE7E0E7E} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AdvancedDriverUpdater_UPDATES.job => C:\Program Files (x86)\Advanced Driver Updater\adu.exe Task: C:\Windows\Tasks\c509cbc0-4c69-4bcc-86b5-6cb1dcba61bf-5.job => C:\Users\boggy\AppData\Local\Weather It Up-BrowserExtensionUninstall\c509cbc0-4c69-4bcc-86b5-6cb1dcba61bf-5.exe Task: C:\Windows\Tasks\c7b116cb-b3a5-41d6-bde2-fc2c80b4960c-7.job => C:\Program Files (x86)\SmartSaver+ 15\c7b116cb-b3a5-41d6-bde2-fc2c80b4960c-7.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-10-17 00:17 - 2011-01-27 18:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-07-09 19:48 - 2014-07-09 19:48 - 04302848 _____ () C:\ProgramData\Fast And Safe\FastAndSafe_x64.dll 2011-01-17 16:19 - 2012-01-11 16:02 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 2014-11-15 11:59 - 2014-11-15 11:59 - 00756224 _____ () C:\ProgramData\savernet\46jVdVN5cgAJ7w.dll 2014-11-15 11:52 - 2013-02-28 16:53 - 00886272 _____ () C:\Program Files (x86)\WinZip Malware Protector\System.Data.SQLite.dll 2014-11-15 11:52 - 2013-07-15 16:53 - 01717936 _____ () C:\Program Files (x86)\WinZip Malware Protector\aspsys.dll 2014-11-15 11:52 - 2013-02-28 16:53 - 00168448 _____ () C:\Program Files (x86)\WinZip Malware Protector\UNRAR.DLL ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-1237914262-1250986476-3758271500-500 - Administrator - Disabled) boggy (S-1-5-21-1237914262-1250986476-3758271500-1000 - Administrator - Enabled) => C:\Users\boggy Gast (S-1-5-21-1237914262-1250986476-3758271500-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1237914262-1250986476-3758271500-1002 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= Name: Microsoft-Teredo-Tunneling-Adapter Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (11/15/2014 11:40:35 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/15/2014 11:40:35 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=9AC} Application Virtualization Client konnte keine Verbindung mit der Datenstrom-URL 'hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7137.5001.sft' herstellen (Rückgabecode 2460420A-40002EFD, ursprünglicher Rückgabecode 2460420A-40002EFD). Error: (11/15/2014 11:30:27 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/15/2014 11:30:27 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=9AC} Application Virtualization Client konnte keine Verbindung mit der Datenstrom-URL 'hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7137.5001.sft' herstellen (Rückgabecode 2460420A-40002EFD, ursprünglicher Rückgabecode 2460420A-40002EFD). Error: (11/15/2014 11:28:51 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Die Aktion kann nicht abgeschlossen werden. Versuchen Sie es erneut. Wenden Sie sich bei Fortbestehen des Problems an den Microsoft-Produktsupport. Error: (11/15/2014 10:18:01 AM) (Source: System Restore) (EventID: 8200) (User: ) Description: Fehler beim Initiieren der Systemwiederherstellung (Windows Update). Error: (11/15/2014 10:07:23 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: chrome.exe, Version: 35.0.1916.153, Zeitstempel: 0x538fb354 Name des fehlerhaften Moduls: chrome.dll, Version: 35.0.1916.153, Zeitstempel: 0x538fb051 Ausnahmecode: 0x80000003 Fehleroffset: 0x00485166 ID des fehlerhaften Prozesses: 0x2e4 Startzeit der fehlerhaften Anwendung: 0xchrome.exe0 Pfad der fehlerhaften Anwendung: chrome.exe1 Pfad des fehlerhaften Moduls: chrome.exe2 Berichtskennung: chrome.exe3 Error: (11/15/2014 09:47:44 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: PCSUQuickScan.exe, Version: 0.0.0.0, Zeitstempel: 0x54539729 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x5315a05a Ausnahmecode: 0xe06d7363 Fehleroffset: 0x000000000000940d ID des fehlerhaften Prozesses: 0x13f0 Startzeit der fehlerhaften Anwendung: 0xPCSUQuickScan.exe0 Pfad der fehlerhaften Anwendung: PCSUQuickScan.exe1 Pfad des fehlerhaften Moduls: PCSUQuickScan.exe2 Berichtskennung: PCSUQuickScan.exe3 Error: (11/15/2014 09:45:06 AM) (Source: MsiInstaller) (EventID: 11309) (User: boggy-HP) Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt. System error 3. Verify that the file exists and that you can access it. Error: (11/15/2014 09:33:37 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Nur zur Information. Fehler bei der Registrierung des Click-2-Run-Pakets. System errors: ============= Error: (11/15/2014 11:06:40 AM) (Source: volmgr) (EventID: 49) (User: ) Description: Die Konfiguration der Auslagerungsdatei für das Speicherabbild ist fehlgeschlagen. Stellen Sie sicher, dass eine Auslagerungsdatei auf der Startpartition vorhanden ist und dass diese groß genug ist, um den gesamten physikalischen Speicher abbilden zu können. Error: (11/12/2014 06:41:09 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/12/2014 06:41:09 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/11/2014 01:20:13 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80004005 Error: (11/09/2014 03:55:12 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:33:36 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:33:06 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:32:25 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:32:25 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (11/07/2014 02:32:04 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Microsoft Office Sessions: ========================= Error: (11/15/2014 11:40:35 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/15/2014 11:40:35 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=9AC} hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7137.5001.sft2460420A-40002EFD2460420A-40002EFD Error: (11/15/2014 11:30:27 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Fehler bei der Registrierung des Click-2-Run-Pakets. Error: (11/15/2014 11:30:27 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: ) Description: {tid=9AC} hxxp://c2r.microsoft.com/ConsumerC2R/de-de/14.0.4763.1000/ConsumerC2R.de-de_14.0.7137.5001.sft2460420A-40002EFD2460420A-40002EFD Error: (11/15/2014 11:28:51 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Die Aktion kann nicht abgeschlossen werden. Versuchen Sie es erneut. Wenden Sie sich bei Fortbestehen des Problems an den Microsoft-Produktsupport. Error: (11/15/2014 10:18:01 AM) (Source: System Restore) (EventID: 8200) (User: ) Description: Windows Update0x81000101 Error: (11/15/2014 10:07:23 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: chrome.exe35.0.1916.153538fb354chrome.dll35.0.1916.153538fb05180000003004851662e401d000b366f4b56cC:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\chrome.dllce54f171-6ca6-11e4-aa7b-2c4138912aa6 Error: (11/15/2014 09:47:44 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: PCSUQuickScan.exe0.0.0.054539729KERNELBASE.dll6.1.7601.184095315a05ae06d7363000000000000940d13f001d000b0bf9ea4ceC:\Program Files (x86)\PC Speed Up\PCSUQuickScan.exeC:\Windows\system32\KERNELBASE.dll1068b73e-6ca4-11e4-aa7b-2c4138912aa6 Error: (11/15/2014 09:45:06 AM) (Source: MsiInstaller) (EventID: 11309) (User: boggy-HP) Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt. System error 3. Verify that the file exists and that you can access it.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (11/15/2014 09:33:37 AM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Fehler bei der Registrierung des Click-2-Run-Pakets. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz Percentage of memory in use: 51% Total physical RAM: 4000.82 MB Available physical RAM: 1945.32 MB Total Pagefile: 7999.81 MB Available Pagefile: 5885.86 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:918.72 GB) (Free:848.77 GB) NTFS Drive d: (HP_RECOVERY) (Fixed) (Total:12.69 GB) (Free:1.77 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (BADRA 2014) (Removable) (Total:14.44 GB) (Free:14.44 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 1261E58F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=918.7 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=12.7 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 14.5 GB) (Disk ID: 309D271B) Partition 1: (Not Active) - (Size=14.5 GB) - (Type=0B) ==================== End Of Log ============================[/CODE] |
Wieso denn schon wieder FRST-Logs, du solltest doch Virenscanner-Log mit den besagten Funden posten |
Alle Zeitangaben in WEZ +1. Es ist jetzt 05:34 Uhr. |
Copyright ©2000-2025, Trojaner-Board