Hier kommt schon einmal das Ergenbis von AdwCleaner:
#AdwCleaner Logfile:
Code:
# AdwCleaner v2.304 - Datei am 04/07/2013 um 16:29:50 erstellt
# Aktualisiert am 03/07/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Business Service Pack 2 (32 bits)
# Benutzer : EUPROCON - EPCDESK05
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\EUPROCON\Downloads\Downloads\Programme\Rescue\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Ordner Gelöscht : C:\Users\EUPROCON\AppData\LocalLow\Softonic
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\Software\Description
***** [Internet Browser] *****
-\\ Internet Explorer v9.0.8112.16490
[OK] Die Registrierungsdatenbank ist sauber.
*************************
AdwCleaner[S1].txt - [923 octets] - [04/07/2013 16:29:50]
########## EOF - C:\AdwCleaner[S1].txt - [982 octets] ##########
--- --- ---
und hier das Ergenis vom JRT:
#
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows Vista (TM) Business x86
Ran by EUPROCON on 04.07.2013 at 16:37:23,90
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CD7ECDF3-9763-4584-B167-C4A61247BCF5}
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 04.07.2013 at 16:39:06,89
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
und hier das Ergebnis vom FSS:
#
Farbar Service Scanner Version: 27-06-2013
Ran by EUPROCON (administrator) on 04-07-2013 at 16:42:19
Running from "C:\Users\EUPROCON\Downloads\Downloads\Programme\Rescue"
Microsoft® Windows Vista™ Business Service Pack 2 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0
System Restore:
============
System Restore Disabled Policy:
========================
Security Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking LEGACY_wscsvc: ATTENTION!=====> Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist.
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
Other Services:
==============
File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcsvc.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys
[2013-06-13 06:50] - [2013-05-08 06:37] - 0905576 ____A (Microsoft Corporation) 548E198BAE21EFC21F8B5F0C1728AD27
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll
[2013-06-13 06:50] - [2013-04-24 06:00] - 0133120 ____A (Microsoft Corporation) 3EDE4C1F9672C972479201544969ADCB
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\ipnathlp.dll => MD5 is legit
C:\Windows\system32\iphlpsvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
**** End of log ****
und hier das Ergebnis vom FRST, für die Addition.txt muss ich aber den entsprechenden Haken setzen!
#
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-07-2013
Ran by EUPROCON (administrator) on 04-07-2013 16:45:33
Running from C:\Users\EUPROCON\Desktop
Microsoft® Windows Vista™ Business Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\system32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Symantec Corporation) C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
(Symantec Corporation) C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
(Motorola) C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe
(Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
(CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Farbar) C:\Users\EUPROCON\Downloads\Downloads\Programme\Rescue\FSS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe [x]
HKLM\...\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [174872 2007-03-21] (Intel Corporation)
HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [90112 2006-11-10] ()
HKLM\...\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start [81920 2006-10-03] (Macrovision Corporation)
HKLM\...\Run: [] [x]
HKLM\...\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [221184 2006-11-05] (Sonic Solutions)
HKLM\...\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [118784 2006-10-20] (CyberLink Corp.)
HKLM\...\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe" [2020968 2007-02-13] (Symantec Corporation)
HKLM\...\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [16384 2007-11-15] ( )
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKCU\...\Run: [Sidebar] C:\Program Files\windows sidebar\sidebar.exe /autoRun [1233920 2009-04-11] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2013-06-20] (Google Inc.)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
Startup: C:\Users\EUPROCON\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
Tcpip\..\Interfaces\{312A21D2-F4E4-4219-A452-933C43BD8FA7}: [NameServer]192.168.100.7,192.168.100.17
========================== Services (Whitelisted) =================
R2 Automatisches LiveUpdate - Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [194240 2006-11-08] (Symantec Corporation)
S3 LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2541248 2006-11-08] (Symantec Corporation)
S3 MSSQL$MSSMLBIZ; c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
R2 NIS; C:\Program Files\Norton Internet Security\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation)
R2 Norton Save and Restore; C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe [2655848 2007-02-13] (Symantec Corporation)
R2 PST Service; C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola)
==================== Drivers (Whitelisted) ====================
R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130702.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2012-08-18] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2012-12-31] (Symantec Corporation)
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130702.001\IDSvix86.sys [386720 2013-04-25] (Symantec Corporation)
R3 LVUSBSta; C:\Windows\System32\drivers\LVUSBSta.sys [41888 2007-05-09] (Logitech Inc.)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130702.021\NAVENG.SYS [93272 2013-05-22] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130702.021\NAVEX15.SYS [1611992 2013-05-22] (Symantec Corporation)
R3 pepifilter; C:\Windows\System32\DRIVERS\lv302af.sys [14112 2007-05-09] (Logitech Inc.)
R3 PID_PEPI; C:\Windows\System32\DRIVERS\LV302V32.SYS [1276832 2007-05-09] (Logitech Inc.)
S3 R300; C:\Windows\System32\DRIVERS\atikmdag.sys [10070016 2012-11-16] (Advanced Micro Devices, Inc.)
S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation)
S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation)
S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation)
S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation)
S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [25512 2008-05-16] (MCCI Corporation)
S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation)
S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [115752 2008-05-16] (MCCI Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\NIS\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NIS\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NIS\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NIS\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-19] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NIS\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\NIS\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
R2 v2imount; C:\Windows\System32\DRIVERS\v2imount.sys [37864 2007-02-13] (Symantec Corporation)
S3 VProEventMonitor; C:\Windows\System32\DRIVERS\vproeventmonitor.sys [14072 2007-02-13] (Symantec Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-04 20:54 - 2013-07-04 20:54 - 00000000 ____D C:\_OTL
2013-07-04 16:45 - 2013-07-04 16:45 - 01373373 ____A (Farbar) C:\Users\EUPROCON\Desktop\FRST.exe
2013-07-04 16:42 - 2013-07-04 16:42 - 00003512 ____A C:\Users\EUPROCON\Desktop\FSS.txt
2013-07-04 16:39 - 2013-07-04 16:39 - 00000780 ____A C:\Users\EUPROCON\Desktop\JRT.txt
2013-07-04 16:37 - 2013-07-04 16:37 - 00000000 ____D C:\Windows\ERUNT
2013-07-04 16:37 - 2013-07-04 16:37 - 00000000 ____D C:\JRT
2013-07-04 16:29 - 2013-07-04 16:30 - 00001050 ____A C:\AdwCleaner[S1].txt
2013-07-04 16:23 - 2013-07-04 16:23 - 00054310 ____A C:\OTL.Txt
2013-07-03 13:46 - 2013-07-03 13:46 - 00000000 ____D C:\FRST
2013-07-03 10:58 - 2013-07-03 10:58 - 00001036 ____A C:\Windows\System32\.crusader
2013-07-03 10:08 - 2013-07-03 10:58 - 00000000 ____D C:\ProgramData\HitmanPro
2013-07-01 08:57 - 2013-07-01 08:57 - 00001894 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-07-01 08:57 - 2013-07-01 08:57 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-07-01 08:57 - 2013-07-01 08:57 - 00000000 ____D C:\Program Files\Adobe
2013-07-01 08:27 - 2013-07-01 08:27 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-20 07:47 - 2013-06-20 07:47 - 00000000 ____D C:\Program Files\GUM16FB.tmp
2013-06-20 07:46 - 2013-07-04 16:32 - 00001098 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-20 07:46 - 2013-07-03 13:51 - 00001102 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-20 07:45 - 2013-06-20 07:46 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Deployment
2013-06-20 07:45 - 2013-06-20 07:45 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Apps\2.0
2013-06-13 20:50 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-13 20:50 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-13 20:50 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-13 20:50 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-13 20:50 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-13 20:50 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-13 20:50 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-13 20:50 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-13 20:50 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-13 20:50 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-13 20:50 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-13 20:50 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-13 20:50 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-13 20:50 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-13 20:50 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-13 20:50 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-13 06:50 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-13 06:50 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-06-13 06:50 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-06-13 06:50 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-13 06:50 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll
2013-06-13 06:50 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-13 06:50 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-13 06:50 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-13 06:50 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-13 06:50 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-13 06:50 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
==================== One Month Modified Files and Folders ========
2013-07-04 20:54 - 2013-07-04 20:54 - 00000000 ____D C:\_OTL
2013-07-04 16:45 - 2013-07-04 16:45 - 01373373 ____A (Farbar) C:\Users\EUPROCON\Desktop\FRST.exe
2013-07-04 16:42 - 2013-07-04 16:42 - 00003512 ____A C:\Users\EUPROCON\Desktop\FSS.txt
2013-07-04 16:39 - 2013-07-04 16:39 - 00000780 ____A C:\Users\EUPROCON\Desktop\JRT.txt
2013-07-04 16:37 - 2013-07-04 16:37 - 00000000 ____D C:\Windows\ERUNT
2013-07-04 16:37 - 2013-07-04 16:37 - 00000000 ____D C:\JRT
2013-07-04 16:37 - 2006-11-02 12:33 - 01601156 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-04 16:35 - 2008-01-26 13:38 - 01913092 ____A C:\Windows\WindowsUpdate.log
2013-07-04 16:32 - 2013-06-20 07:46 - 00001098 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-04 16:31 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-04 16:31 - 2006-11-02 14:47 - 00003552 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-04 16:31 - 2006-11-02 14:47 - 00003552 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-04 16:30 - 2013-07-04 16:29 - 00001050 ____A C:\AdwCleaner[S1].txt
2013-07-04 16:30 - 2008-01-26 13:45 - 00000012 ____A C:\Windows\bthservsdp.dat
2013-07-04 16:30 - 2006-11-02 15:01 - 00032510 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-04 16:23 - 2013-07-04 16:23 - 00054310 ____A C:\OTL.Txt
2013-07-04 16:22 - 2013-01-08 09:32 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-04 16:21 - 2013-01-01 14:41 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\SimpleSYN
2013-07-04 16:21 - 2012-12-30 23:02 - 00000000 ____D C:\users\EUPROCON
2013-07-03 13:51 - 2013-06-20 07:46 - 00001102 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-03 13:46 - 2013-07-03 13:46 - 00000000 ____D C:\FRST
2013-07-03 10:58 - 2013-07-03 10:58 - 00001036 ____A C:\Windows\System32\.crusader
2013-07-03 10:58 - 2013-07-03 10:08 - 00000000 ____D C:\ProgramData\HitmanPro
2013-07-03 09:01 - 2006-11-02 14:52 - 00026169 ____A C:\Windows\setupact.log
2013-07-01 18:40 - 2006-11-02 15:00 - 00035488 ____A C:\Windows\PFRO.log
2013-07-01 09:02 - 2012-12-30 23:47 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Adobe
2013-07-01 08:57 - 2013-07-01 08:57 - 00001894 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-07-01 08:57 - 2013-07-01 08:57 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-07-01 08:57 - 2013-07-01 08:57 - 00000000 ____D C:\Program Files\Adobe
2013-07-01 08:57 - 2008-01-26 14:02 - 00000000 ____D C:\ProgramData\Adobe
2013-07-01 08:27 - 2013-07-01 08:27 - 00000000 ____D C:\Windows\System32\appmgmt
2013-06-20 07:49 - 2012-12-30 23:05 - 00000000 ____D C:\Users\EUPROCON\AppData\Roaming\Google
2013-06-20 07:47 - 2013-06-20 07:47 - 00000000 ____D C:\Program Files\GUM16FB.tmp
2013-06-20 07:47 - 2012-12-30 23:04 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Google
2013-06-20 07:46 - 2013-06-20 07:45 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Deployment
2013-06-20 07:46 - 2008-01-26 14:01 - 00000000 ____D C:\ProgramData\Google
2013-06-20 07:46 - 2008-01-26 14:01 - 00000000 ____D C:\Program Files\Google
2013-06-20 07:45 - 2013-06-20 07:45 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Apps\2.0
2013-06-19 06:49 - 2012-12-31 14:00 - 00000000 ____D C:\Windows\System32\Drivers\NIS
2013-06-19 06:36 - 2012-12-31 14:01 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS
2013-06-19 06:36 - 2012-12-31 14:01 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT
2013-06-14 09:57 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-06-14 09:40 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-06-13 20:51 - 2008-01-26 13:54 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-06-13 20:49 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2013-06-12 17:23 - 2013-01-08 09:32 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-12 17:23 - 2013-01-08 09:32 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-04 16:37
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
und hier das Ergebnis des 2. Scan mit der Addition.txt
#FRST Additions Logfile:
Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 04-07-2013
Ran by EUPROCON at 2013-07-04 17:05:20
Running from C:\Users\EUPROCON\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
2007 Microsoft Office Suite Service Pack 3 (SP3)
2007 Microsoft Office system (Version: 12.0.6612.1000)
Adobe Flash Player 11 ActiveX (Version: 11.7.700.224)
Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7)
AMD APP SDK Runtime (Version: 10.0.937.2)
AMD Catalyst Install Manager (Version: 8.0.877.0)
ATI Catalyst Control Center (Version: 2.007.0914.2138)
Avanquest update (Version: 1.12)
Benutzerhandbuch
Browser Address Error Redirector (Version: 1.00.0000)
Business Contact Manager für Outlook 2007 SP2 (Version: 3.0.8619.1)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Core Implementation (Version: 2007.0914.2139.36828)
Catalyst Control Center Graphics Full Existing (Version: 2007.0914.2139.36828)
Catalyst Control Center Graphics Full New (Version: 2007.0914.2139.36828)
Catalyst Control Center Graphics Light (Version: 2007.0914.2139.36828)
Catalyst Control Center Graphics Previews Common (Version: 2007.0914.2139.36828)
Catalyst Control Center Graphics Previews Common (Version: 2012.1116.1515.27190)
Catalyst Control Center Graphics Previews Vista (Version: 2007.0914.2139.36828)
Catalyst Control Center InstallProxy (Version: 2012.1116.1515.27190)
Catalyst Control Center Localization All (Version: 2012.1116.1515.27190)
Catalyst Control Center Localization Chinese Standard (Version: 2007.0914.2139.36828)
Catalyst Control Center Localization Chinese Traditional (Version: 2007.0914.2139.36828)
Catalyst Control Center Localization French (Version: 2007.0914.2139.36828)
Catalyst Control Center Localization German (Version: 2007.0914.2139.36828)
Catalyst Control Center Localization Hungarian (Version: 2007.0914.2139.36828)
Catalyst Control Center Localization Italian (Version: 2007.0914.2139.36828)
Catalyst Control Center Localization Japanese (Version: 2007.0914.2139.36828)
Catalyst Control Center Localization Korean (Version: 2007.0914.2139.36828)
Catalyst Control Center Localization Polish (Version: 2007.0914.2139.36828)
Catalyst Control Center Localization Portuguese (Version: 2007.0914.2139.36828)
Catalyst Control Center Localization Spanish (Version: 2007.0914.2139.36828)
Catalyst Control Center Localization Thai (Version: 2007.0914.2139.36828)
Catalyst Control Center Localization Turkish (Version: 2007.0914.2139.36828)
CCC Help Chinese Standard (Version: 2007.0914.2138.36828)
CCC Help Chinese Standard (Version: 2012.1116.1514.27190)
CCC Help Chinese Traditional (Version: 2007.0914.2138.36828)
CCC Help Chinese Traditional (Version: 2012.1116.1514.27190)
CCC Help Czech (Version: 2012.1116.1514.27190)
CCC Help Danish (Version: 2012.1116.1514.27190)
CCC Help Dutch (Version: 2012.1116.1514.27190)
CCC Help English (Version: 2007.0914.2138.36828)
CCC Help English (Version: 2012.1116.1514.27190)
CCC Help Finnish (Version: 2012.1116.1514.27190)
CCC Help French (Version: 2007.0914.2138.36828)
CCC Help French (Version: 2012.1116.1514.27190)
CCC Help German (Version: 2007.0914.2138.36828)
CCC Help German (Version: 2012.1116.1514.27190)
CCC Help Greek (Version: 2012.1116.1514.27190)
CCC Help Hungarian (Version: 2007.0914.2138.36828)
CCC Help Hungarian (Version: 2012.1116.1514.27190)
CCC Help Italian (Version: 2007.0914.2138.36828)
CCC Help Italian (Version: 2012.1116.1514.27190)
CCC Help Japanese (Version: 2007.0914.2138.36828)
CCC Help Japanese (Version: 2012.1116.1514.27190)
CCC Help Korean (Version: 2007.0914.2138.36828)
CCC Help Korean (Version: 2012.1116.1514.27190)
CCC Help Norwegian (Version: 2012.1116.1514.27190)
CCC Help Polish (Version: 2007.0914.2138.36828)
CCC Help Polish (Version: 2012.1116.1514.27190)
CCC Help Portuguese (Version: 2007.0914.2138.36828)
CCC Help Portuguese (Version: 2012.1116.1514.27190)
CCC Help Russian (Version: 2012.1116.1514.27190)
CCC Help Spanish (Version: 2007.0914.2138.36828)
CCC Help Spanish (Version: 2012.1116.1514.27190)
CCC Help Swedish (Version: 2012.1116.1514.27190)
CCC Help Thai (Version: 2007.0914.2138.36828)
CCC Help Thai (Version: 2012.1116.1514.27190)
CCC Help Turkish (Version: 2007.0914.2138.36828)
CCC Help Turkish (Version: 2012.1116.1514.27190)
ccc-core-static (Version: 2007.0914.2139.36828)
ccc-utility (Version: 2007.0914.2139.36828)
ccc-utility (Version: 2012.1116.1515.27190)
D3DX10 (Version: 15.4.2368.0902)
Dell DataSafe (Version: 2.00.0000)
Dell Handbuch zum Einstieg (Version: 1.00.0000)
Dell Support Center (Version: 2.0.07311)
Evernote v. 4.6.4 (Version: 4.6.4.8136)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.5.4209.2358)
Google Update Helper (Version: 1.3.21.145)
Intel(R) Matrix Storage Manager
Intel(R) PRO Network Connections 12.1.11.0 (Version: )
Java(TM) 6 Update 39 (Version: 6.0.390)
Java(TM) SE Runtime Environment 6 (Version: 1.6.0.0)
Junk Mail filter update (Version: 15.4.3502.0922)
LiveUpdate 3.2 (Symantec Corporation) (Version: 3.2.0.26)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Office 2003 Web Components (Version: 11.0.8003.0)
Microsoft Office 2007 Primary Interop Assemblies (Version: 12.0.4518.1014)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1)
Microsoft Office Outlook Connector (Version: 14.0.5118.5000)
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Professional Hybrid 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Small Business Connectivity Components (Version: 2.0.7024.0)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) (Version: 9.4.5000.00)
Microsoft SQL Server Native Client (Version: 9.00.5000.00)
Microsoft SQL Server VSS Writer (Version: 9.00.5000.00)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (Version: 10.0.30319)
Motorola Device Manager (Version: 2.3.9)
Motorola Device Software Update (Version: 13.02.1402)
Motorola Mobile Drivers Installation 6.0.0 (Version: 6.0.0)
MSVCRT (Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (Version: 4.30.2100.0)
Norton Internet Security (Version: 20.4.0.40)
Norton Save and Restore (Version: 2.0.0.19488)
PowerDVD (Version: 7.0)
Realtek High Definition Audio Driver
Roxio Creator Audio (Version: 3.3.0)
Roxio Creator BDAV Plugin (Version: 3.3.0)
Roxio Creator Copy (Version: 3.3.0)
Roxio Creator Data (Version: 3.3.0)
Roxio Creator DE (Version: 3.3.0)
Roxio Creator Tools (Version: 3.3.0)
Roxio Express Labeler (Version: 2.1.0)
Roxio MyDVD DE (Version: 9.0.116)
Roxio Update Manager (Version: 3.0.0)
Segoe UI (Version: 15.4.2271.0615)
SimpleSYN 2.1 (Version: 2.1.4189)
Skins (Version: 2007.0914.2139.36828)
Sonic Activation Module (Version: 1.0)
Sony Ericsson PC Suite 4.006.00 (Version: 4.006.00)
Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (Version: 9.00.5000.00)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817327) 32-Bit Edition
Update für Microsoft Office Excel 2007 Help (KB963678)
Update für Microsoft Office Outlook 2007 Help (KB963677)
Update für Microsoft Office Powerpoint 2007 Help (KB963669)
Update für Microsoft Office Word 2007 Help (KB963665)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Messenger (Version: 15.4.3538.0513)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Windows Mobile-Gerätecenter (Version: 6.1.6965.0)
Windows Mobile-Gerätecenter: Treiberupdate (Version: 6.1.6965.0)
==================== Restore Points =========================
12-06-2013 09:26:19 Geplanter Prüfpunkt
13-06-2013 05:06:24 Geplanter Prüfpunkt
13-06-2013 18:47:52 Windows Update
14-06-2013 10:35:31 Geplanter Prüfpunkt
17-06-2013 06:57:07 Geplanter Prüfpunkt
19-06-2013 07:50:51 Geplanter Prüfpunkt
20-06-2013 05:25:49 Geplanter Prüfpunkt
20-06-2013 19:18:54 Geplanter Prüfpunkt
21-06-2013 08:37:36 Geplanter Prüfpunkt
24-06-2013 06:19:00 Geplanter Prüfpunkt
25-06-2013 09:31:19 Geplanter Prüfpunkt
26-06-2013 07:04:17 Geplanter Prüfpunkt
27-06-2013 08:04:37 Geplanter Prüfpunkt
28-06-2013 05:12:20 Geplanter Prüfpunkt
01-07-2013 05:26:55 Geplanter Prüfpunkt
01-07-2013 06:26:32 Removed Adobe Reader X (10.1.7) - Deutsch.
02-07-2013 08:40:07 Geplanter Prüfpunkt
03-07-2013 05:22:38 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {00B99C81-FEA0-4EA8-A2DD-8497265D8DBD} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {0CAB7B68-718C-40E0-B83B-89DDF7007DC8} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation)
Task: {150171E4-43E8-4CAE-9215-09B289C0B60B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-06-20] (Google Inc.)
Task: {155723BA-60E2-4354-93AF-84EAC8D3C2D8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2012-12-31] ()
Task: {238816F3-39F2-4B65-90F6-A098D9F50160} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated)
Task: {252FCF61-1430-4291-A46E-883AD1A7DB80} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-06-20] (Google Inc.)
Task: {286240E7-7A81-41B2-A5A9-3BE9A8C9AD78} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2012-12-31] (Microsoft Corporation)
Task: {2DE18FE4-6467-484F-8431-206702EC5546} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation)
Task: {2E5B7D97-F14C-4CFF-864E-620AABA892D1} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {31D0C8A4-B75D-4D62-A659-434925C2BAAA} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation)
Task: {4B1C44C0-0C36-46E2-A44D-00330FC1779C} - System32\Tasks\Motorola Device Manager Update => C:\Program Files\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-03-25] ()
Task: {4D72741E-769C-45DB-8604-CB8EBDADAA29} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {65F13DF8-CD1A-4844-8722-FA6950B590A4} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation)
Task: {68BD8876-790B-41BE-8CA7-9DD9C5A902DF} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {9939460C-8C1C-458D-961D-47E52C71DEDF} - System32\Tasks\Motorola Device Manager Initial Update => C:\Program Files\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-03-25] ()
Task: {9A6891EF-765E-4FA7-BD40-E14660D05EDC} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation)
Task: {CA78D833-DD8F-4AF2-83B4-D702882ECF8A} - System32\Tasks\WPD\SqmUpload_S-1-5-21-488772620-2242768751-4285676057-1003 => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation)
Task: {CFECDF04-592C-434A-9A23-BA5E3EE2C6A5} - System32\Tasks\Motorola Device Manager Engine => C:\Program Files\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-03-25] ()
Task: {D138F985-86A8-41BB-A566-156B9D649048} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\VistaSP1CEIP => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation)
Task: {F7841EB9-9AD6-4997-B8E8-02200781B08F} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {FF98BB55-CC50-434A-BEE0-946A0C290230} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2013-07-04 16:56:45.312
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-04 16:56:45.205
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-04 16:56:45.099
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-04 16:56:44.993
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-04 16:56:37.755
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-04 16:56:37.649
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-04 16:56:37.542
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-04 16:56:37.436
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-04 16:56:36.307
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130702.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-04 16:56:36.178
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130702.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 52%
Total physical RAM: 2045.45 MB
Available physical RAM: 971.61 MB
Total Pagefile: 4327.95 MB
Available Pagefile: 3062.41 MB
Total Virtual: 2047.88 MB
Available Virtual: 1894.69 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:216 GB) (Free:143.49 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DELL BACKUP) (Fixed) (Total:72.03 GB) (Free:43.5 GB) NTFS
Drive e: (RECOVERY) (Fixed) (Total:10 GB) (Free:1.78 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: 50000000)
Partition 1: (Not Active) - (Size=55 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=10 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=216 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=72 GB) - (Type=OF Extended)
==================== End Of Log ============================
--- --- ---
Hallo Schrauber,
ich habe den Rechner zwischenzeitlich neu gestartet. Eigentlich macht er (fast) alles, was er soll, allerdinge besteht nach wie vor das Thema, dass der Sicherheitscenterdienst ausgeschaltet ist und sich nicht einschalten lässt. Ein zweites Thema versuche ich auf einem anderen Wege zu lösen.
Gruß
Michael
By the way, ich sehe zwischenzeitlich fast 400 Hits auf dem Thema, heißt das, dass es soviele weiter Problemfälle gibt?
Hallo Schrauber,
mein Virenscanner hat eben einen Vollscann durchgeführt und drei signifikante Bedrohungen erkannt und behoben. Hier die Screenshots:
1.
====================
Dateiname: igjc.class
Bedrohungsname: Trojan.Maljava
Vollständiger Pfad: c:\users\euprocon\appdata\locallow\sun\java\deployment\cache\6.0\44\1000236c-31e6bd23
____________________________
Details
Unbekannte Community-Verbreitung,* Unbekanntes Alter,* Risiko Hoch
Ursprung
Heruntergeladen von*Unbekannt
Aktivität
Ausgeführte Aktionen: Ausgeführte Aktionen: 1
____________________________
Auf Computern ab*04.07.2013 um 20:29:00
Zuletzt verwendet*04.07.2013 um 19:57:29
Start-Element*Nein
Gestarted*Nein
____________________________
Unbekannt
Es ist nicht bekannt, wie viele Benutzer in der Norton Community diese Datei verwendet haben.
Unbekannt
Diese Dateiversion ist nicht bekannt.
Hoch
Das Risiko dieser Datei ist hoch.
Art der Bedrohung: Virus. Programme, die andere Programme, Dateien oder Computerbereiche infizieren, indem sie sich einfügen oder anhängen.
____________________________
Quelle: externe Medien
___________________________
Dateiaktionen
igjc.class[Enthalten in] c:\users\euprocon\appdata\locallow\sun\java\deployment\cache\6.0\44\1000236c-31e6bd23Gelöscht
____________________________
Dateiabdruck - SHA:
21aed8cbc5fbc1231deb17f8dc8638308af6f0f27fe0ba7a59a246304eba4f1b
Dateiabdruck - MD5:
Nicht verfügbar
=====================
2.
=====================
Dateiname: igjc.class
Bedrohungsname: Trojan.Maljava
Vollständiger Pfad: c:\users\euprocon\appdata\locallow\sun\java\deployment\cache\6.0\58\79632ba-57ac9334
____________________________
Details
Unbekannte Community-Verbreitung,* Unbekanntes Alter,* Risiko Hoch
Ursprung
Heruntergeladen von*Unbekannt
Aktivität
Ausgeführte Aktionen: Ausgeführte Aktionen: 1
____________________________
Auf Computern ab*04.07.2013 um 20:31:49
Zuletzt verwendet*04.07.2013 um 19:57:35
Start-Element*Nein
Gestarted*Nein
____________________________
Unbekannt
Es ist nicht bekannt, wie viele Benutzer in der Norton Community diese Datei verwendet haben.
Unbekannt
Diese Dateiversion ist nicht bekannt.
Hoch
Das Risiko dieser Datei ist hoch.
Art der Bedrohung: Virus. Programme, die andere Programme, Dateien oder Computerbereiche infizieren, indem sie sich einfügen oder anhängen.
____________________________
Quelle: externe Medien
____________________________
Dateiaktionen
igjc.class[Enthalten in] c:\users\euprocon\appdata\locallow\sun\java\deployment\cache\6.0\58\79632ba-57ac9334Gelöscht
____________________________
Dateiabdruck - SHA:
21aed8cbc5fbc1231deb17f8dc8638308af6f0f27fe0ba7a59a246304eba4f1b
Dateiabdruck - MD5:
Nicht verfügbar
======================
und 3. (den Anhang habe ich sicherlich nicht geöffnet, wahrscheinlich war der schon rausgeflogen)
======================
Dateiname: pixmania gift voucher.scr
Bedrohungsname: Trojan Horse
Vollständiger Pfad: pixmania gift voucher.zip
____________________________
Details
Unbekannte Community-Verbreitung,* Unbekanntes Alter,* Risiko Hoch
Ursprung
Gesendet von"pixmania.com service" <e-gift@pixmania.com>
Aktivität
Ausgeführte Aktionen: Ausgeführte Aktionen: 1
____________________________
Auf Computern ab*Nicht verfügbar
Zuletzt verwendet*07.06.2013 um 11:13:12
Start-Element*Nein
Gestarted*Nein
____________________________
Unbekannt
Es ist nicht bekannt, wie viele Benutzer in der Norton Community diese Datei verwendet haben.
Unbekannt
Diese Dateiversion ist nicht bekannt.
Hoch
Das Risiko dieser Datei ist hoch.
Art der Bedrohung: Virus. Programme, die andere Programme, Dateien oder Computerbereiche infizieren, indem sie sich einfügen oder anhängen.
____________________________
Quelle: externe Medien
Betreff: Pixmania Gift Voucher (50 EUR)
Absender: "pixmania.com service" <e-gift@pixmania.com>
Empfänger: "esfb" <diam.Duis@quis.org>
____________________________
Dateiaktionen
pixmania gift voucher.scr[Enthalten in] pixmania gift voucher.zip [in einem E-Mail-Anhang]
____________________________
Dateiabdruck - SHA:
4a6837755926dc26b45677347df673edd0c7168e05995d4a321afc26336e80a5
Dateiabdruck - MD5:
Nicht verfügbar
===========================