Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Virenprogramme stürzen ab (https://www.trojaner-board.de/149127-virenprogramme-stuerzen-ab.html)

baumus 02.02.2014 23:32

Virenprogramme stürzen ab
 
Hallo, habe mir über eine helperbar, welche sich von selber auf meinem Laptop installiert hat anscheinend Viren oder PUPs eingefangen. Jegliche Virenprogramme (Malwarebytes, Adwcleaner) finden zwar sehr viel, stürzen aber bei Löschungsversuchen ab.
Mein Rechner verlangsamt sich zunehmends. Bitte um Hilfe! Hab gerade eben eine Logfile über Hijack this erstellt.

LG B

cosinus 02.02.2014 23:44

Hallo und :hallo:

Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden?

Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten!
Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht!




Zudem bitte auch ein Log mit Farbars Tool machen:

Scan mit Farbar's Recovery Scan Tool (FRST)

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

baumus 03.02.2014 00:09

Hallo, danke schon mal...ja heute hat malwarebytes 966 infizierte Objekte gefunden, hat sich aber leider aufgehängt...
Hier die Logfile :
FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2014 03
Ran by Seppi (administrator) on MICHAEL-PC on 03-02-2014 00:03:14
Running from C:\Users\Seppi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\79ZXE6AZ
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) ===================

(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_11_9_900_170_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [Dell Webcam Central] - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe [442536 2008-11-11] (Creative Technology Ltd.)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1983816 2009-03-24] (CANON INC.)
HKLM\...\Run: [CanonSolutionMenu] - C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [767312 2009-03-18] (CANON INC.)
HKLM\...\Run: [Malwarebytes Anti-Malware (reboot)] - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [887432 2013-04-04] (Malwarebytes Corporation)
HKLM\...\Run: [H2O] - C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe [385024 2005-10-22] (Team H2O)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-19] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
HKU\.DEFAULT\...\Run: [msnmsgr] - C:\Program Files\Windows Live\Messenger\msnmsgr.exe [3882312 2008-12-03] (Microsoft Corporation)
HKU\.DEFAULT\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe -update activex
HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\Run: [Ituvapxymi] - C:\Users\Seppi\AppData\Roaming\Paofon\gufio.exe
HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil32_11_9_900_170_ActiveX.exe [839560 2013-12-11] (Adobe Systems Incorporated)
HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\MountPoints2: {9d8c8a43-2261-11e0-8338-002219f09901} - F:\AUTOPLAY.EXE
HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\MountPoints2: {c3025575-aa9f-11e2-a46e-bed9dace8f6b} - G:\Startme.exe
HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\Winlogon: [Shell] Explorer.exe [2926592 2009-04-11] (Microsoft Corporation) <==== ATTENTION
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Michi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Seppi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8
SearchScopes: HKLM - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=07/01/2014&type=hp1000
SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=07/01/2014&type=hp1000
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=07/01/2014&type=hp1000
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=07/01/2014&type=hp1000
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
BHO: No Name - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -  No File
Toolbar: HKLM - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Yahoo Community Smartbar (by Linkury) - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKCU - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKCU - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540104} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks:  - {AEB6717E-7E19-11d0-97EE-00C04FD91972} -  No File [ ]
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Seppi\AppData\Roaming\Mozilla\Firefox\Profiles\q79z9d8h.default
FF NewTab: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=nt&fr=linkury-tb&installDate={installDate}&type=hp1000&q=
FF DefaultSearchEngine: Web Search
FF SelectedSearchEngine: Web Search
FF Homepage: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=hp&fr=linkury-tb&installDate=07/01/2014&type=hp1000
FF Keyword.URL: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=79bcb114-69eb-a44f-9032-07c4184de744&searchtype=ds&fr=linkury-tb&installDate=07/01/2014&type=hp1000&p=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX OVS Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Seppi\AppData\Roaming\Mozilla\Firefox\Profiles\q79z9d8h.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Plus-HD-4.8 - C:\Users\Seppi\AppData\Roaming\Mozilla\Firefox\Profiles\q79z9d8h.default\Extensions\9a1cadcd-98ec-4413-87d3-0f7c4253cd27@31f19576-e1e2-40bc-81ac-be7a5f1cf67c.com [2014-01-29]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Seppi\AppData\Roaming\Mozilla\Firefox\Profiles\q79z9d8h.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2013-08-03]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-01-07]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-01-07]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-01-07]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKCU\...\Firefox\Extensions: [{184AA5E6-741D-464a-820E-94B3ABC2F3B4}] - C:\Users\Seppi\AppData\Roaming\01003
FF Extension: Java String Helper - C:\Users\Seppi\AppData\Roaming\01003 [2012-02-08]

========================== Services (Whitelisted) =================

R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [81920 2009-03-20] (Andrea Electronics Corporation)
R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-19] (Avira Operations GmbH & Co. KG)
R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1528616 2010-03-23] (Cisco Systems, Inc.)
R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-12-18] (Stardock Corporation)
S3 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
R2 sprtsvc_DellSupportCenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2009-01-30] (SupportSoft, Inc.)
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe [254042 2009-03-20] (IDT, Inc.)

==================== Drivers (Whitelisted) ====================

S3 61883; C:\Windows\System32\DRIVERS\61883.sys [45696 2008-01-21] (Microsoft Corporation)
R2 Aspi32; C:\Windows\system32\Drivers\Aspi32.sys [25244 1999-09-10] (Adaptec)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-25] (Avira Operations GmbH & Co. KG)
R3 CLEDX; C:\Windows\System32\DRIVERS\cledx.sys [33792 2005-05-09] (Team H2O)
S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [308859 2010-03-23] (Cisco Systems, Inc.)
R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.)
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [26024 2009-12-17] (Elaborate Bytes AG)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2014-02-02] (Malwarebytes Corporation)
R3 OA008Ufd; C:\Windows\System32\DRIVERS\OA008Ufd.sys [133472 2009-02-10] (Creative Technology Ltd.)
R3 OA008Vid; C:\Windows\System32\DRIVERS\OA008Vid.sys [271616 2009-02-10] (Creative Technology Ltd.)
S3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1083520 2006-11-02] (Philips Semiconductors GmbH)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-15] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Michael\AppData\Local\Temp\catchme.sys [x]
U1 d3dsbe; \??\C:\Windows\system32\drivers\d3dsbe.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S2 Nsynas32; No ImagePath
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S2 Parclass; \SystemRoot\System32\Drivers\Parclass.sys [x]
S3 PCD5SRVC{3F6A8B78-EC003E00-05040104}; \??\C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [x]
S3 StarOpen; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-03 00:01 - 2014-02-03 00:03 - 00000000 ____D () C:\FRST
2014-02-02 23:49 - 2014-02-02 23:50 - 01137152 _____ (Farbar) C:\Users\Seppi\Downloads\FRST.exe
2014-02-02 23:42 - 2014-02-02 23:43 - 00000472 _____ () C:\Users\Seppi\Desktop\defogger_disable.log
2014-02-02 23:42 - 2014-02-02 23:42 - 00000000 _____ () C:\Users\Seppi\defogger_reenable
2014-02-02 23:22 - 2014-02-02 23:22 - 00009460 _____ () C:\Users\Seppi\Desktop\hijackthis2.txt
2014-02-02 23:21 - 2014-02-02 23:21 - 00008711 _____ () C:\Users\Seppi\Desktop\hijackthis.log
2014-02-01 20:23 - 2014-02-01 20:23 - 00139616 _____ () C:\Windows\Minidump\Mini020114-01.dmp
2014-01-13 21:57 - 2014-01-13 21:58 - 00139616 _____ () C:\Windows\Minidump\Mini011314-01.dmp
2014-01-10 20:35 - 2014-01-10 20:36 - 00139616 _____ () C:\Windows\Minidump\Mini011014-01.dmp
2014-01-08 20:17 - 2014-02-02 23:54 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-01-08 20:17 - 2014-01-08 20:17 - 00000868 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-08 20:17 - 2014-01-08 20:17 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-01-08 20:17 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-08 20:13 - 2014-01-08 20:16 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Seppi\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-07 23:48 - 2014-01-07 23:48 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\TuneUp Software
2014-01-07 23:40 - 2014-01-07 23:49 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-01-07 23:40 - 2014-01-07 23:41 - 34008992 _____ (DVDVideoSoft Ltd. ) C:\Users\Seppi\Downloads\FreeYouTubeToMP3Converter-3.12.20.1230.exe
2014-01-07 23:40 - 2014-01-07 23:40 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-01-07 23:36 - 2014-01-07 23:36 - 00002139 _____ () C:\Users\Seppi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-01-07 23:36 - 2014-01-07 23:36 - 00002109 _____ () C:\Users\Seppi\Desktop\Search.lnk
2014-01-07 23:35 - 2014-01-07 23:36 - 00000000 ____D () C:\Users\Seppi\AppData\Local\Smartbar
2014-01-07 23:34 - 2014-01-08 20:03 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\DVDVideoSoft
2014-01-07 23:34 - 2014-01-07 23:34 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\OpenCandy
2014-01-07 23:32 - 2014-01-07 23:33 - 32244744 _____ (DVDVideoSoft Ltd. ) C:\Users\Seppi\Downloads\FreeYouTubeDownload-3.2.20.1230.exe
2014-01-07 21:29 - 2014-01-29 22:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox

==================== One Month Modified Files and Folders =======

2014-02-03 00:03 - 2014-02-03 00:01 - 00000000 ____D () C:\FRST
2014-02-02 23:59 - 2012-06-18 21:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-02 23:58 - 2012-02-25 01:14 - 01456798 _____ () C:\Windows\WindowsUpdate.log
2014-02-02 23:54 - 2014-01-08 20:17 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-02-02 23:50 - 2014-02-02 23:49 - 01137152 _____ (Farbar) C:\Users\Seppi\Downloads\FRST.exe
2014-02-02 23:43 - 2014-02-02 23:42 - 00000472 _____ () C:\Users\Seppi\Desktop\defogger_disable.log
2014-02-02 23:42 - 2014-02-02 23:42 - 00000000 _____ () C:\Users\Seppi\defogger_reenable
2014-02-02 23:42 - 2011-02-12 16:36 - 00000000 ____D () C:\Users\Seppi
2014-02-02 23:40 - 2009-12-14 00:11 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-02 23:22 - 2014-02-02 23:22 - 00009460 _____ () C:\Users\Seppi\Desktop\hijackthis2.txt
2014-02-02 23:21 - 2014-02-02 23:21 - 00008711 _____ () C:\Users\Seppi\Desktop\hijackthis.log
2014-02-02 23:14 - 2013-10-01 10:17 - 00000000 ____D () C:\AdwCleaner
2014-02-02 23:02 - 2011-03-21 21:48 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\Skype
2014-02-02 22:55 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-02 22:55 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-02 16:59 - 2009-12-14 00:11 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-02 16:55 - 2010-08-27 14:45 - 00000000 ____D () C:\Program Files\Common Files\Akamai
2014-02-02 16:55 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-02 15:15 - 2006-11-02 14:01 - 00032562 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-01 20:23 - 2014-02-01 20:23 - 00139616 _____ () C:\Windows\Minidump\Mini020114-01.dmp
2014-02-01 20:23 - 2013-07-22 11:15 - 299486590 _____ () C:\Windows\MEMORY.DMP
2014-02-01 20:23 - 2010-03-26 12:38 - 00000000 ____D () C:\Windows\Minidump
2014-01-30 20:00 - 2013-08-03 12:03 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-01-29 22:18 - 2014-01-07 21:29 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-01-29 22:18 - 2013-08-03 12:03 - 00000808 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-01-26 13:52 - 2010-12-08 17:20 - 00001022 _____ () C:\Windows\Tasks\Google Software Updater.job
2014-01-13 21:58 - 2014-01-13 21:57 - 00139616 _____ () C:\Windows\Minidump\Mini011314-01.dmp
2014-01-10 20:36 - 2014-01-10 20:35 - 00139616 _____ () C:\Windows\Minidump\Mini011014-01.dmp
2014-01-08 20:17 - 2014-01-08 20:17 - 00000868 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-08 20:17 - 2014-01-08 20:17 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-01-08 20:16 - 2014-01-08 20:13 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Seppi\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-08 20:03 - 2014-01-07 23:34 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\DVDVideoSoft
2014-01-08 00:43 - 2011-10-06 20:14 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\Audacity
2014-01-08 00:36 - 2012-12-04 21:34 - 00039176 _____ () C:\Windows\PFRO.log
2014-01-08 00:33 - 2013-07-08 21:40 - 00000000 ____D () C:\Users\Seppi\Desktop\Neuer Ordner
2014-01-07 23:49 - 2014-01-07 23:40 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-01-07 23:48 - 2014-01-07 23:48 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\TuneUp Software
2014-01-07 23:41 - 2014-01-07 23:40 - 34008992 _____ (DVDVideoSoft Ltd. ) C:\Users\Seppi\Downloads\FreeYouTubeToMP3Converter-3.12.20.1230.exe
2014-01-07 23:40 - 2014-01-07 23:40 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-01-07 23:36 - 2014-01-07 23:36 - 00002139 _____ () C:\Users\Seppi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-01-07 23:36 - 2014-01-07 23:36 - 00002109 _____ () C:\Users\Seppi\Desktop\Search.lnk
2014-01-07 23:36 - 2014-01-07 23:35 - 00000000 ____D () C:\Users\Seppi\AppData\Local\Smartbar
2014-01-07 23:34 - 2014-01-07 23:34 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\OpenCandy
2014-01-07 23:33 - 2014-01-07 23:32 - 32244744 _____ (DVDVideoSoft Ltd. ) C:\Users\Seppi\Downloads\FreeYouTubeDownload-3.2.20.1230.exe
2014-01-07 22:25 - 2011-03-23 14:07 - 00035840 _____ () C:\Users\Seppi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Files to move or delete:
====================
C:\Users\Michael\AppData\Roaming\desktop.ini
C:\Users\Michael\avira_antivir_personal403_de.exe
C:\Users\Seppi\avira_antivir_personal403_de.exe
C:\Users\Seppi\CTX.DAT


Some content of TEMP:
====================
C:\Users\Michael\AppData\Local\temp\AUTOPLAY.EXE
C:\Users\Michael\AppData\Local\temp\BOOTDISK.EXE
C:\Users\Michael\AppData\Local\temp\CPUID.EXE
C:\Users\Michael\AppData\Local\temp\DivXSetup.exe
C:\Users\Michael\AppData\Local\temp\DOS4GW.EXE
C:\Users\Michael\AppData\Local\temp\EREGLIB.DLL
C:\Users\Michael\AppData\Local\temp\FlashPlayerUpdate.exe
C:\Users\Michael\AppData\Local\temp\HAVEVESA.EXE
C:\Users\Michael\AppData\Local\temp\HDDTEC.EXE
C:\Users\Michael\AppData\Local\temp\INSTALL.EXE
C:\Users\Michael\AppData\Local\temp\SETUP.EXE
C:\Users\Michael\AppData\Local\temp\SETUP32.EXE
C:\Users\Michael\AppData\Local\temp\SETUPL.DLL
C:\Users\Michael\AppData\Local\temp\UVCONFIG.EXE
C:\Users\Michael\AppData\Local\temp\WHAT.EXE
C:\Users\Michael\AppData\Local\temp\_SETUP.EXE
C:\Users\Seppi\AppData\Local\temp\avgnt.exe
C:\Users\Seppi\AppData\Local\temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Seppi\AppData\Local\temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Seppi\AppData\Local\temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Seppi\AppData\Local\temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Seppi\AppData\Local\temp\m2eyqkpa.dll
C:\Users\Seppi\AppData\Local\temp\Quarantine.exe
C:\Users\Seppi\AppData\Local\temp\SkypeSetup.exe
C:\Users\Seppi\AppData\Local\temp\Upgrade.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-02-02 17:05

==================== End Of Log ============================

--- --- ---

cosinus 03.02.2014 00:19

Log von MBAM posten, ohne die Funde zu entfernen...damit ich besser sehe womit wird es zu tun haben
Und das andere Log von FRST fehlt

baumus 03.02.2014 00:25

Hi, da sich malwarebytes aufgehängt hat...hab ich da kein logfile...soll ichs nochmal mit nem scan probieren? Adition logfile kommt :
Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-02-2014 03
Ran by Seppi at 2014-02-03 00:03:44
Running from C:\Users\Seppi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\79ZXE6AZ
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

 Update for Microsoft Office 2007 (KB2508958) (Version:  - Microsoft)
7-Zip 4.65 (Version:  - )
Adobe AIR (Version: 3.2.0.2070 - Adobe Systems Incorporated)
Adobe AIR (Version: 3.2.0.2070 - Adobe Systems Incorporated) Hidden
Adobe Anchor Service CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Asset Services CS3 (Version: 3 - Adobe Systems Incorporated) Hidden
Adobe Bridge CS3 (Version: 2 - Adobe Systems Incorporated) Hidden
Adobe Bridge Start Meeting (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Camera Raw 4.0 (Version: 4.0 - Adobe Systems Incorporated) Hidden
Adobe CMaps (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color Common Settings (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Default Language CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Device Central CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe ExtendScript Toolkit 2 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 11 ActiveX (Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Fonts All (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Help Viewer CS3 (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe Linguistics CS3 (Version: 3.0.0 - Adobe Systems Incorporated) Hidden
Adobe PDF Library Files (Version: 8.0 - Adobe Systems Incorporated) Hidden
Adobe Premiere Pro CS3 (Version: 3 - Adobe Systems Incorporated)
Adobe Premiere Pro CS3 (Version: 3 - Adobe Systems Incorporated) Hidden
Adobe Premiere Pro CS3 Functional Content (Version: 8 - Adobe Systems Incorporated) Hidden
Adobe Premiere Pro CS3 Third Party Content (Version: 3 - Adobe Systems Incorporated) Hidden
Adobe Reader 9.5.5 - Deutsch (Version: 9.5.5 - Adobe Systems Incorporated)
Adobe Setup (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Type Support (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Update Manager CS3 (Version: 5.1.0 - Adobe Systems Incorporated) Hidden
Adobe Version Cue CS3 Client (Version: 3 - Adobe Systems Incorporated) Hidden
Adobe XMP DVA Panels CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe XMP Panels CS3 (Version: 1.0 - Adobe Systems Incorporated) Hidden
Advanced Audio FX Engine (Version: 1.12.05 - Creative Technology Ltd)
Akamai NetSession Interface (HKCU Version:  - )
Akamai NetSession Interface Service (Version:  - )
Apple Application Support (Version: 2.3.2 - Apple Inc.)
Apple Mobile Device Support (Version: 6.0.1.3 - Apple Inc.)
Apple Software Update (Version: 2.1.3.127 - Apple Inc.)
Ashampoo Burning Studio 2010 Advanced (Version: 9.2.4 - ashampoo GmbH & Co. KG)
ATI Catalyst Control Center (Version: 2.008.1114.2148 - )
Audacity 1.3.12 (Unicode) (Version:  - Audacity Team)
AudibleManager (Version: 326928.-2.1999990966.1999989980 - Audible, Inc.)
Avira Free Antivirus (Version: 14.0.2.286 - Avira)
AviSynth 2.5 (Version:  - )
BitTorrent (Version: 7.2.0 - )
BlueVoda Website Builder 11.4G (Version:  - )
Bonjour (Version: 3.0.0.10 - Apple Inc.)
Bowling Evolution (Version:  - )
Canon Easy-WebPrint EX (Version:  - )
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (Version:  - )
Canon MP Navigator EX 3.0 (Version:  - )
Canon MP550 series Benutzerregistrierung (Version:  - )
Canon MP550 series MP Drivers (Version:  - )
Canon Utilities Easy-PhotoPrint EX (Version:  - )
Canon Utilities My Printer (Version:  - )
Canon Utilities Solution Menu (Version:  - )
Catalyst Control Center - Branding (Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Graphics Full New (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Graphics Light (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center InstallProxy (Version: 2008.1114.2149.39131 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization Chinese Standard (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization Chinese Traditional (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization Danish (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization Dutch (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization Finnish (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization French (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization German (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization Italian (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization Japanese (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization Korean (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization Norwegian (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization Portuguese (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization Russian (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization Spanish (Version: 2008.1114.2149.39131 - ATI) Hidden
Catalyst Control Center Localization Swedish (Version: 2008.1114.2149.39131 - ATI) Hidden
CCC Help Chinese Standard (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help Chinese Traditional (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help Danish (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help Dutch (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help English (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help Finnish (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help French (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help German (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help Italian (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help Japanese (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help Korean (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help Norwegian (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help Portuguese (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help Russian (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help Spanish (Version: 2008.1114.2148.39131 - ATI) Hidden
CCC Help Swedish (Version: 2008.1114.2148.39131 - ATI) Hidden
ccc-core-static (Version: 2008.1114.2149.39131 - ATI) Hidden
ccc-utility (Version: 2008.1114.2149.39131 - ATI) Hidden
CCleaner (Version: 2.30 - Piriform)
CDBurnerXP (Version: 4.3.8.2474 - CDBurnerXP)
Choice Guard (Version: 1.2.87.0 - Microsoft Corporation) Hidden
Chrysler Golf Challenge (Version:  - )
Cisco Systems VPN Client 5.0.07.0290 (Version: 5.0.6 - Cisco Systems, Inc.)
Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000 - Microsoft Corporation)
Dell DataSafe Online (Version: 1.1.0023 - Dell, Inc.)
Dell Dock (Version: 1.0.0 - Dell)
Dell Edoc Viewer (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (Version: 1.00.0000 - Dell Inc.)
Dell Support Center (Support Software) (Version: 2.2.09085 - Dell)
Dell Touchpad (Version: 12.0.1.0 - Synaptics)
Dell Video Chat (Version: 6.0 (6567) - SightSpeed Inc.)
Dell Webcam Central (Version: 1.02.06 - Creative Technology Ltd)
Dell-eBay (Version: 1.00.0000 - Dell)
DivX Version Checker (Version: 7.1.0.9 - DivX, Inc.)
DivX-Setup (Version: 2.3.0.20 - DivX, LLC)
Dropbox (HKCU Version: 2.0.22 - Dropbox, Inc.)
ElsterFormular (Version: 14.1.20130301 - Landesfinanzdirektion Thüringen)
eMule (Version:  - )
EVEREST Home Edition v2.20 (Version: 2.20 - Lavalys Inc)
FormatFactory 2.50 (Version: 2.50 - Free Time)
G*Power 3.1.3 (Version: 3.1.3 - Franz Faul, Uni Kiel, Germany)
GIMP 2.6.11 (Version: 2.6.11 - The GIMP Team)
Google Earth (Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (Version: 7.5.4805.320 - Google Inc.)
Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden
Google Updater (Version: 2.4.2432.1652 - Google Inc.)
GoToAssist 8.0.0.514 (Version:  - )
GUI for dvdauthor 1.07 (Version: 1.07 - Boraxsoft)
HijackThis 2.0.2 (Version: 2.0.2 - TrendMicro)
Integrated Webcam Driver (1.02.02.0106)  (Version: 1.02.02.0106 - Creative Technology Ltd.)
IsoBuster 2.8.5 (Version: 2.8.5 - Smart Projects)
iTunes (Version: 11.0.1.12 - Apple Inc.)
Java 7 Update 45 (Version: 7.0.450 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
JDownloader 0.9 (Version: 0.9 - AppWork GmbH)
Junk Mail filter update (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden
LECTURNITY Player (Version: 4.0.0000 - imc AG)
Leisure Suit Larry 7 (Version: 1.0.59 - Sierra)
LimeWire 5.1.3 (Version: 5.1.3 - Lime Wire, LLC)
Logic Audio Platinum v5.10 (Version:  - )
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300 - Malwarebytes Corporation)
Media Go (Version: 2.4.256 - Sony)
Media Go Video Playback Engine 1.116.101.02020 (Version: 1.116.101.02020 - Sony)
Mendeley Desktop 0.9.9 (Version: 0.9.9 - Mendeley Ltd.)
MFC RunTime files (Version: 1.0.0 - Extensoft) Hidden
Microsoft .NET Framework 3.5 SP1 (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (Version:  - Microsoft) Hidden
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version:  - Microsoft) Hidden
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Suite Activation Assistant (Version: 2.9 - Microsoft Corporation)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20513.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla)
Mozilla Maintenance Service (Version: 26.0 - Mozilla)
MPEG4E VFW - H.264/MPEG-4 AVC codec (remove only) (Version:  - )
MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero Control Center 10 (Version: 10.0.13100.3.1 - Nero AG) Hidden
Nero ControlCenter 10 Help (CHM) (Version: 1.0.10700 - Nero AG) Hidden
Nero Core Components 10 (Version: 2.0.15100.0.1 - Nero AG) Hidden
Nvu 1.0 (Version: 1.0 - Thorsten Fritz)
OpenOffice.org 3.1 (Version: 3.1.9399 - OpenOffice.org)
PlayStation(R)Store (Version: 4.14.6.15183 - Sony Computer Entertainment Inc.)
PowerDVD (Version: 8.1 - Dell)
QuickSet (Version: 9.2.13 - Dell Inc.)
Roxio Creator Audio (Version: 3.7.0 - Roxio) Hidden
Roxio Creator Copy (Version: 3.7.0 - Roxio) Hidden
Roxio Creator Data (Version: 3.7.0 - Roxio) Hidden
Roxio Creator DE (Version: 10.1 - Roxio)
Roxio Creator DE (Version: 3.7.0 - Roxio) Hidden
Roxio Creator Tools (Version: 3.7.0 - Roxio) Hidden
Roxio Express Labeler 3 (Version: 3.2.1 - Roxio) Hidden
Roxio Update Manager (Version: 6.0.0 - Roxio) Hidden
Shape Collage (Version:  - Shape Collage Inc.)
simfy (Version: 1.6.9 - simfy GmbH)
simfy (Version: 1.6.9 - simfy GmbH) Hidden
Skins (Version: 2008.1114.2149.39131 - ATI) Hidden
Skype Click to Call (Version: 5.9.9216 - Skype Technologies S.A.)
Skype™ 6.11 (Version: 6.11.102 - Skype Technologies S.A.)
SmartSound Common Data (Version: 1.1.0 - SmartSound Software Inc.)
SmartSound Common Data (Version: 1.1.0 - SmartSound Software Inc.) Hidden
SmartSound Quicktracks 5 (Version: 5.1.6 - SmartSound Software Inc.)
SmartSound Quicktracks 5 (Version: 5.1.6 - SmartSound Software Inc.) Hidden
Sony Ericsson Update Engine (Version: 2.13.6.201305161305 - Sony Ericsson Communications AB)
Sony PC Companion 2.10.181 (Version: 2.10.181 - Sony)
SopCast 3.2.4 (Version: 3.2.4 - SopCast.com)
Steinberg Groove Agent 2 (Version: 2.0.0 - Steinberg)
Steinberg Groove Agent 2 v2.0.0.28 (Version:  - )
Stream Torrent 1.0 (Version:  - )
SyncroSoft Emu (Remove only) (Version:  - )
Syncrosofts Lizenz Kontrolle (Version:  - Syncrosoft Hard- Und Software GmbH)
TVUPlayer 2.5.2.2 (Version: 2.5.2.2 - TVU networks)
Two Worlds Pinball (Version: 1.00 - TopWare Interactive Inc.)
Uniblue RegistryBooster (Version:  - Uniblue Systems Ltd)
Update for 2007 Microsoft Office System (KB967642) (Version:  - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (Version:  - Microsoft)
Vampireville . (Version:  - )
VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0 - DivX, Inc) Hidden
VirtualCloneDrive (Version:  - Elaborate Bytes)
VLC media player 1.0.1 (Version: 1.0.1 - VideoLAN Team)
vShare.tv plugin 1.3 (Version: 1.3 - vShare.tv, Inc.) <==== ATTENTION
Windows Live Call (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden
Windows Live Communications Platform (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden
Windows Live Essentials (Version: 14.0.8050.1202 - Microsoft Corporation)
Windows Live Essentials (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (Version: 14.0.8051.1204 - Microsoft Corporation) Hidden
Windows Live Mail (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden
Windows Live Messenger (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden
Windows Live Sync (Version: 14.0.8050.1202 - Microsoft Corporation)
Windows Live Toolbar (Version: 14.0.8052.1208 - Microsoft Corporation) Hidden
Windows Live Writer (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden
Windows Live-Uploadtool (Version: 14.0.8014.1029 - Microsoft Corporation)
Windows Media Encoder 9 Series (Version:  - )
Windows Media Encoder 9 Series (Version: 9.00.3374 - Microsoft Corporation) Hidden
Yahoo Community Smartbar (Version: 10.179.66.13636 - Linkury Inc.) <==== ATTENTION
Yahoo Community Smartbar Engine (HKCU Version: 10.179.66.13636 - Linkury Inc.) <==== ATTENTION
Zattoo 3.3.4 Beta (Version: 3.3.4 Beta - Zattoo Inc.)
Zattoo4 4.0.5 (Version: 4.0.5 - Zattoo Inc.)

==================== Restore Points  =========================

10-01-2014 22:23:19 Geplanter Prüfpunkt
14-01-2014 21:25:56 Geplanter Prüfpunkt
16-01-2014 15:00:58 Geplanter Prüfpunkt
17-01-2014 16:44:36 Geplanter Prüfpunkt
24-01-2014 13:29:43 Geplanter Prüfpunkt
30-01-2014 23:40:08 Geplanter Prüfpunkt
31-01-2014 15:18:15 Geplanter Prüfpunkt

==================== Hosts content: ==========================

2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {4FD8B278-1024-41F6-BA4E-8D7D3EF242C2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-14] (Google Inc.)
Task: {6CEC5231-C292-4CDB-9129-C7CF8E11B1CA} - System32\Tasks\SaveSense => C:\Users\Seppi\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {8DEC571A-97A0-416F-B37E-A5275E54456E} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Michael => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation)
Task: {995B789E-8327-45B3-BFFA-8B2DFD36AC31} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {9A957BBA-74F5-4CFB-BA51-4C52162D78B4} - System32\Tasks\Google Software Updater => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-21] (Google)
Task: {B53A7D6F-CC86-4028-8120-4BEA0262D305} - System32\Tasks\{84F7D839-ED02-4268-91E6-BA8910CD21DB} => C:\Program Files\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {BD1AE1AD-2346-4629-8C98-A125EB06364C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-14] (Google Inc.)
Task: {CAD2ED30-6D9F-4BCC-9873-FFC6822F68A6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {E8B4B199-B07A-4E79-BB26-77D4BF04FB09} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Seppi => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation)
Task: {F3CD334F-2B45-4D35-90B1-5532B0312727} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\SaveSense.job => C:\Users\Seppi\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2009-05-23 03:34 - 2008-12-01 06:42 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"

==================== Faulty Device Manager Devices =============

Name: Microsoft-ISATAP-Adapter #5
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Microsoft-ISATAP-Adapter #18
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Microsoft-ISATAP-Adapter #23
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: ADS Instant HDTV PCI
Description: ADS Instant HDTV PCI
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: ADS Technologies
Service: Ph3xIB32
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Cisco Systems VPN Adapter
Description: Cisco Systems VPN Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: CVirtA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/02/2014 11:58:47 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546.

Error: (02/02/2014 11:58:47 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546.

Error: (02/02/2014 11:58:47 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546.

Error: (02/02/2014 11:58:47 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546.

Error: (02/02/2014 11:28:47 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546.

Error: (02/02/2014 11:28:47 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546.

Error: (02/02/2014 11:28:47 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546.

Error: (02/02/2014 11:28:47 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546.

Error: (02/02/2014 10:58:47 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546.

Error: (02/02/2014 10:58:47 PM) (Source: ESENT) (User: )
Description: wuaueng.dll (1224)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546.


System errors:
=============
Error: (02/02/2014 11:56:36 PM) (Source: atapi) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/02/2014 10:20:25 PM) (Source: atapi) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (02/02/2014 06:58:31 PM) (Source: Schannel) (User: )
Description: Eine SSL-Verbindungsanforderung wurde von einer Remoteclientanwendung übermittelt, aber keine der Verschlüsselungssammlungen, die von der Clientanwendung unterstützt werden, werden vom Server unterstützt. Die SSL-Verbindungsanforderung ist fehlgeschlagen.

Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: )
Description: Windows Driver Foundation - Benutzermodus-Treiberframework11200001Neustart des Diensts

Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: )
Description: Enumeratordienst für tragbare Geräte11200001Neustart des Diensts

Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: )
Description: Automatische WLAN-Konfiguration11200001Neustart des Diensts

Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: )
Description: Diagnosesystemhost1

Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: )
Description: Sitzungs-Manager für Desktopfenster-Manager11200001Neustart des Diensts

Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: )
Description: Überwachung verteilter Verknüpfungen (Client)11200001Neustart des Diensts

Error: (02/02/2014 05:56:23 PM) (Source: Service Control Manager) (User: )
Description: Tablet PC-Eingabedienst1600001Neustart des Diensts


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2014-01-07 23:56:52.183
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\verifier.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-01-07 23:05:38.233
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\verifier.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-08-20 22:48:10.603
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\verifier.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-07-04 23:30:14.424
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\verifier.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-03-15 21:43:44.033
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\verifier.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 51%
Total physical RAM: 3065.94 MB
Available physical RAM: 1490.11 MB
Total Pagefile: 6332.91 MB
Available Pagefile: 4506.97 MB
Total Virtual: 2047.88 MB
Available Virtual: 1883.2 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:283.4 GB) (Free:60.46 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:6.25 GB) NTFS
Drive g: (Volume) (Fixed) (Total:167.67 GB) (Free:167.58 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: 3FBE4D3F)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=283 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=168 GB) - (Type=OF Extended)

==================== End Of Log ============================


cosinus 03.02.2014 00:26

Hast du nen Quick oder Fullscan mit mbam gemacht?

baumus 03.02.2014 00:27

Quickscan

cosinus 03.02.2014 00:30

Dann mach dennochmal aber entferne die Funde nicht, damit du ans Log kommst

baumus 03.02.2014 00:53

Hallo, bin noch da, der hat nur ewig gebraucht...hier die logfile :
Code:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.02.02.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Seppi :: MICHAEL-PC [administrator]

03.02.2014 00:28:24
MBAM-log-2014-02-03 (00-52-30).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 308392
Time elapsed: 23 minute(s), 50 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 43
C:\Users\Seppi\AppData\Local\Smartbar (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\CSS (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\PublisherImages (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\ar (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\Configs (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\de (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\es (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\fr (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\he (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\helperbar@helperbar.com (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\PublisherImages (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\nl (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\pt (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\it (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\ru (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Application\tr (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Common (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Common\Configs (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Common\icons (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Common\iconsWide (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Common\ServicesPlugins (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\DistributionFiles (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\DistributionFiles\Configs (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\DistributionFiles\Profiles (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\DistributionFiles\RollBack (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\DistributionFiles\RollBack\Profiles (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Smartbar.exe_StrongName_vuedtbpoockmp1sq45awfxuouevabx0i (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Smartbar\Smartbar.exe_StrongName_vuedtbpoockmp1sq45awfxuouevabx0i\10.179.66.13636 (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Seppi\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\Seppi\AppData\Roaming\OpenCandy\BF96F10940144AC6B8B2C9BD208EE2CD (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\Seppi\AppData\Roaming\OpenCandy\F78A7195B32E48CA870189C219DE3BBD (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\Seppi\AppData\Roaming\SaveSense (PUP.Optional.SaveSense) -> No action taken.
C:\Users\Seppi\AppData\Roaming\SaveSense\UpdateProc (PUP.Optional.SaveSense) -> No action taken.
C:\Users\Seppi\AppData\Local\SaveSenseLive (PUP.Optional.SaveSense.A) -> No action taken.
C:\Users\Seppi\AppData\Local\SaveSenseLive\CrashReports (PUP.Optional.SaveSense.A) -> No action taken.
C:\Users\Seppi\AppData\Local\Plus-HD-4.8 (PUP.Optional.PlusHD.A) -> No action taken.

Files Detected: 0
(No malicious items detected)

(end)


cosinus 03.02.2014 00:55

Scheint nur Adware nur sein, aber lass mal tiefer scannen mit MBAR

Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

baumus 03.02.2014 01:06

Hallo, der kann den DDA driver nicht laden...soll ich dann rebooten?

cosinus 03.02.2014 01:09

Wirst du nicht gefragt ob ja oder nein?

baumus 03.02.2014 01:10

Doch...wollt dich nur nochmal fragen :)

cosinus 03.02.2014 01:12

Klick auf nein und ohn Reboot scannen lassen

baumus 03.02.2014 01:13

Nächste Nachricht : Could not install driver on boot. Scan can´t contnue...

cosinus 03.02.2014 01:13

Dann wirste wohl rebooten müssen :pfeiff:

baumus 03.02.2014 01:15

..dass heißt neustart oder? wenn ich nein klicke macht auch nicht weiter...
scan failed

cosinus 03.02.2014 01:27

Schon zu spät heute? :D
DDA installieren, Windows neu starten, scannen lassen

baumus 03.02.2014 21:18

Supi...spät wie...naja super bowl...obwohl ich das spiel nicht versteh. Na auf jedanfall scaned er jetzt

Hello again, ich hab jetzt zwei logfiles von mbar : vor dem clean und nach den clean. Soll ich dir mal beide zuschicken. Danke schonmal für deine zeit

Ich schicke dir mal beide logfiles :

vor dem clean :

Code:

Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org

Database version: v2014.02.02.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Seppi :: MICHAEL-PC [administrator]

03.02.2014 01:35:06
mbar-log-2014-02-03 (01-35-06).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 311925
Time elapsed: 1 hour(s), 4 minute(s), 32 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 2
HKCU\SOFTWARE\CLASSES\linkrdr.AIEbho (Trojan.Banker) -> Delete on reboot.
HKCU\SOFTWARE\CLASSES\linkrdr.AIEbho.1 (Trojan.Banker) -> Delete on reboot.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)


nach dem clean :

Code:

Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org

Database version: v2014.02.03.01

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Seppi :: MICHAEL-PC [administrator]

03.02.2014 02:57:26
mbar-log-2014-02-03 (02-57-26).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 312141
Time elapsed: 1 hour(s), 5 minute(s), 14 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

Hallo, wenn du mal Zeit hast, hab dir beide logfiles vom mbar scan geschickt...
Danke für die Hilfe

cosinus 03.02.2014 21:33

Adware/Junkware/Toolbars entfernen


1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




3. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


baumus 03.02.2014 21:43

Hi, also der adwcleaner stürzt leider bei ca. 10 % während des Löschvorgangs ab...hab ich auch schon öfter probiert

cosinus 03.02.2014 21:45

Dann spinnt da aber noch kräftig etwas rum! :balla:

Bitte jetzt ein Log mit CF machen:

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


baumus 03.02.2014 22:08

Hallo logfile leider zu lang...:pfeiff:

baumus 03.02.2014 22:32

Hallo ich hänge dir jetzt mal die zip datei an...

cosinus 03.02.2014 23:19

Ok, einiges entfernt :D
Bitte nochmal adwCleaner neu runterladen und nochmal probieren

baumus 03.02.2014 23:43

...leider das gleiche Ergebnis...stürzt nach 3 sekunden ab

cosinus 03.02.2014 23:43

Dann erste Vorbehandlung mit Malwarebyts Anti-Malware, das stürzte doch auch ab vorher oder?

baumus 03.02.2014 23:50

ich probiere jetzt malewarebytes nochmal...das stürzte bisher beim versuch ab die infizierten Daten zu löschen

cosinus 03.02.2014 23:59

Mach mal :D

baumus 04.02.2014 00:11

funzt leider nicht...beim versuch die angeklickten daten zu löschen steigt malewarebytes sofort aus

Malwarebytes war bis jetzt echt unschlagbar... hatte da nie Probleme...seit sich diese helperbar installiert hat...

cosinus 04.02.2014 00:25

Hast schon JRT probiert? Wenn nicht, dann das zuerst
Bisher war die Reihenfolge MBAM, adwCleaner, JRT aber immer gut. Naja, manchmal gibt es Ausnahmen

baumus 04.02.2014 00:47

Hab jetzt JRT ausprobiert, war wohl der Schlüssel. Danach den adwcleaner...allerdings gibt es noch drei dateien die der adwcleaner nicht wegbekommt. Ich poste dir das logfile
Code:

# AdwCleaner v3.018 - Bericht erstellt am 04/02/2014 um 00:38:47
# Updated 28/01/2014 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzername : Seppi - MICHAEL-PC
# Gestartet von : C:\Users\Seppi\Downloads\adwcleaner-3.018.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Browser ] *****

-\\ Internet Explorer v9.0.8112.16506


-\\ Mozilla Firefox v26.0 (de)

[ Datei : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\trjms3ui.default\prefs.js ]


[ Datei : C:\Users\Seppi\AppData\Roaming\Mozilla\Firefox\Profiles\q79z9d8h.default\prefs.js ]


[ Datei : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\zdk0d1rc.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [15954 octets] - [01/10/2013 10:17:55]
AdwCleaner[R10].txt - [2221 octets] - [04/02/2014 00:37:50]
AdwCleaner[R1].txt - [11199 octets] - [02/02/2014 23:10:20]
AdwCleaner[R2].txt - [11160 octets] - [03/02/2014 19:59:34]
AdwCleaner[R3].txt - [11326 octets] - [03/02/2014 21:37:38]
AdwCleaner[R4].txt - [10848 octets] - [03/02/2014 22:37:18]
AdwCleaner[R5].txt - [11036 octets] - [03/02/2014 23:29:04]
AdwCleaner[R6].txt - [11156 octets] - [03/02/2014 23:38:40]
AdwCleaner[R7].txt - [11208 octets] - [04/02/2014 00:03:03]
AdwCleaner[R8].txt - [11328 octets] - [04/02/2014 00:20:37]
AdwCleaner[R9].txt - [8748 octets] - [04/02/2014 00:32:22]
AdwCleaner[S0].txt - [16032 octets] - [01/10/2013 10:23:37]
AdwCleaner[S10].txt - [1610 octets] - [04/02/2014 00:38:47]
AdwCleaner[S1].txt - [480 octets] - [02/02/2014 23:14:03]
AdwCleaner[S2].txt - [359 octets] - [03/02/2014 20:00:59]
AdwCleaner[S3].txt - [365 octets] - [03/02/2014 21:39:05]
AdwCleaner[S4].txt - [365 octets] - [03/02/2014 22:38:33]
AdwCleaner[S5].txt - [433 octets] - [03/02/2014 23:29:38]
AdwCleaner[S6].txt - [433 octets] - [03/02/2014 23:40:30]
AdwCleaner[S7].txt - [365 octets] - [04/02/2014 00:03:41]
AdwCleaner[S8].txt - [365 octets] - [04/02/2014 00:21:17]
AdwCleaner[S9].txt - [8449 octets] - [04/02/2014 00:33:09]

########## EOF - C:\AdwCleaner\AdwCleaner[S10].txt - [2203 octets] ##########


cosinus 04.02.2014 00:55

Log von JRT?

baumus 04.02.2014 01:00

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.0 (01.07.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Seppi on 04.02.2014 at  0:28:24,71
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113}



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho.1
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smartbarbackup
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smartbarlog
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\iesmartbar.bandobjectattribute
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\iesmartbar.dockingpanel
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\iesmartbar.iesmartbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\iesmartbar.iesmartbarbandobject
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\iesmartbar.smartbardisplaystate
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\iesmartbar.smartbarmenuform
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchthewebarp
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220422592214}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660466596614}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660466596614}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}



~~~ Files

Successfully deleted: [File] C:\Windows\System32\Tasks\SaveSense
Successfully disinfected: [Shortcut] C:\Users\Seppi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Search.lnk
Successfully disinfected: [Shortcut] C:\Users\Seppi\AppData\Roaming\microsoft\windows\start menu\Programs\Search.lnk
Successfully repaired: [Shortcut] C:\Users\Seppi\desktop\Search.lnk



~~~ Folders

Successfully deleted: [Folder] "C:\Users\Seppi\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Users\Seppi\appdata\local\savesenselive"
Successfully deleted: [Folder] "C:\Users\Seppi\appdata\local\smartbar"
Successfully deleted: [Folder] "C:\Users\Seppi\appdata\locallow\smartbar"
Successfully deleted: [Folder] "C:\Program Files\qualitink"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uniblue"
Successfully deleted: [Folder] "C:\Users\Seppi\AppData\Roaming\microsoft\windows\start menu\programs\torntv.com"



~~~ FireFox

Successfully deleted: [File] C:\user.js
Successfully deleted: [File] C:\Users\Seppi\AppData\Roaming\mozilla\firefox\profiles\q79z9d8h.default\searchplugins\web search.xml
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\\{184aa5e6-741d-464a-820e-94b3abc2f3b4}
Successfully deleted the following from C:\Users\Seppi\AppData\Roaming\mozilla\firefox\profiles\q79z9d8h.default\prefs.js

user_pref("browser.search.defaultenginename", "Web Search");
user_pref("browser.search.selectedEngine", "Web Search");
user_pref("extensions.crossrider.bic", "143586ce87e9f65a3ae38dba441dbe81");
user_pref("extensions.iminent.admin", false);
user_pref("extensions.iminent.aflt", "orgnl");
user_pref("extensions.iminent.appId", "{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}");
user_pref("extensions.iminent.autoRvrt", "false");
user_pref("extensions.iminent.dfltLng", "");
user_pref("extensions.iminent.excTlbr", false);
user_pref("extensions.iminent.ffxUnstlRst", false);
user_pref("extensions.iminent.id", "30e8d1240000000000000022fb4c0df6");
user_pref("extensions.iminent.instlDay", "16028");
user_pref("extensions.iminent.instlRef", "");
user_pref("extensions.iminent.newTab", false);
user_pref("extensions.iminent.prdct", "iminent");
user_pref("extensions.iminent.prtnrId", "iminent");
user_pref("extensions.iminent.rvrt", "false");
user_pref("extensions.iminent.smplGrp", "none");
user_pref("extensions.iminent.tlbrId", "YBCPCSTIPO");
user_pref("extensions.iminent.tlbrSrchUrl", "hxxp://start.iminent.com/?ref=toolbarm#q=");
user_pref("extensions.iminent.vrsn", "1.8.26.8");
user_pref("extensions.iminent.vrsnTs", "1.8.26.81:28:14");
user_pref("extensions.iminent.vrsni", "1.8.26.8");
user_pref("iminent.enabledAds", "false");
Emptied folder: C:\Users\Seppi\AppData\Roaming\mozilla\firefox\profiles\q79z9d8h.default\minidumps [12 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 04.02.2014 at  0:31:08,83
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


cosinus 04.02.2014 01:03

Malwarebytes....JETZT :D

baumus 04.02.2014 01:05

Habi...log...1 datei...bei der stürzt er leider aber auch ab


Code:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.02.02.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Seppi :: MICHAEL-PC [administrator]

04.02.2014 00:49:15
MBAM-log-2014-02-04 (01-02-20).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 305884
Time elapsed: 12 minute(s), 50 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\Users\Seppi\AppData\Local\Plus-HD-4.8 (PUP.Optional.PlusHD.A) -> No action taken.

Files Detected: 0
(No malicious items detected)

(end)


cosinus 04.02.2014 01:42

Zitat:

Database version: v2014.02.02.05
möööpp....du hast mbam vorher nicht aktualisiert :D

baumus 04.02.2014 02:02

aaaaber auch mit neuer Version steigt er leider aus...
Weißt du was das ist?



Code:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.02.04.01

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Seppi :: MICHAEL-PC [administrator]

04.02.2014 01:45:51
MBAM-log-2014-02-04 (01-59-36).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 305788
Time elapsed: 13 minute(s), 35 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\Users\Seppi\AppData\Local\Plus-HD-4.8 (PUP.Optional.PlusHD.A) -> No action taken.

Files Detected: 0
(No malicious items detected)

(end)


cosinus 04.02.2014 02:07

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Users\Seppi\AppData\Local\Plus-HD-4.8

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


baumus 04.02.2014 02:15

oki...

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 01-02-2014 03
Ran by Seppi at 2014-02-04 02:14:18 Run:1
Running from C:\Users\Seppi\Downloads
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
C:\Users\Seppi\AppData\Local\Plus-HD-4.8
*****************

C:\Users\Seppi\AppData\Local\Plus-HD-4.8 => Moved successfully.

==== End of Fixlog ====


cosinus 04.02.2014 02:58

Malwarebytes Anti-Malware wiederholen

baumus 04.02.2014 14:07

Hello, hab jetzt malwarebytes wiederholt...und er findet nichts mehr , dennoch findet der adwcleaner drei Dateien, welche er nicht löschen kann. Komischerweise haben die auch kein Häkchen am rand zu an,- oder abklicken.

Log von malwarebytes :
Code:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.02.04.01

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Seppi :: MICHAEL-PC [administrator]

04.02.2014 13:42:49
mbam-log-2014-02-04 (13-42-49).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 306338
Time elapsed: 15 minute(s), 24 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)



und dann noch das adwcleaner log :
Code:

# AdwCleaner v3.018 - Bericht erstellt am 04/02/2014 um 14:06:12
# Updated 28/01/2014 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzername : Seppi - MICHAEL-PC
# Gestartet von : C:\Users\Seppi\Downloads\adwcleaner-3.018.exe
# Option : Suchen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Browser ] *****

-\\ Internet Explorer v9.0.8112.16506


-\\ Mozilla Firefox v26.0 (de)

[ Datei : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\trjms3ui.default\prefs.js ]


[ Datei : C:\Users\Seppi\AppData\Roaming\Mozilla\Firefox\Profiles\q79z9d8h.default\prefs.js ]


[ Datei : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\zdk0d1rc.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [15954 octets] - [01/10/2013 10:17:55]
AdwCleaner[R10].txt - [2221 octets] - [04/02/2014 00:37:50]
AdwCleaner[R11].txt - [2344 octets] - [04/02/2014 00:43:03]
AdwCleaner[R12].txt - [2405 octets] - [04/02/2014 01:14:34]
AdwCleaner[R13].txt - [2527 octets] - [04/02/2014 01:18:44]
AdwCleaner[R14].txt - [2588 octets] - [04/02/2014 13:59:58]
AdwCleaner[R15].txt - [1244 octets] - [04/02/2014 14:06:12]
AdwCleaner[R1].txt - [11199 octets] - [02/02/2014 23:10:20]
AdwCleaner[R2].txt - [11160 octets] - [03/02/2014 19:59:34]
AdwCleaner[R3].txt - [11326 octets] - [03/02/2014 21:37:38]
AdwCleaner[R4].txt - [10848 octets] - [03/02/2014 22:37:18]
AdwCleaner[R5].txt - [11036 octets] - [03/02/2014 23:29:04]
AdwCleaner[R6].txt - [11156 octets] - [03/02/2014 23:38:40]
AdwCleaner[R7].txt - [11208 octets] - [04/02/2014 00:03:03]
AdwCleaner[R8].txt - [11328 octets] - [04/02/2014 00:20:37]
AdwCleaner[R9].txt - [8748 octets] - [04/02/2014 00:32:22]
AdwCleaner[S0].txt - [16032 octets] - [01/10/2013 10:23:37]
AdwCleaner[S10].txt - [2284 octets] - [04/02/2014 00:38:47]
AdwCleaner[S11].txt - [2467 octets] - [04/02/2014 01:15:24]
AdwCleaner[S1].txt - [480 octets] - [02/02/2014 23:14:03]
AdwCleaner[S2].txt - [359 octets] - [03/02/2014 20:00:59]
AdwCleaner[S3].txt - [365 octets] - [03/02/2014 21:39:05]
AdwCleaner[S4].txt - [365 octets] - [03/02/2014 22:38:33]
AdwCleaner[S5].txt - [433 octets] - [03/02/2014 23:29:38]
AdwCleaner[S6].txt - [433 octets] - [03/02/2014 23:40:30]
AdwCleaner[S7].txt - [365 octets] - [04/02/2014 00:03:41]
AdwCleaner[S8].txt - [365 octets] - [04/02/2014 00:21:17]
AdwCleaner[S9].txt - [8449 octets] - [04/02/2014 00:33:09]

########## EOF - C:\AdwCleaner\AdwCleaner[R15].txt - [2568 octets] ##########


cosinus 04.02.2014 15:42

Frisches FRST Log bitte :D

baumus 04.02.2014 15:54

here you go...


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2014 03
Ran by Seppi (administrator) on MICHAEL-PC on 04-02-2014 15:53:01
Running from C:\Users\Seppi\Downloads
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) ===================

(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Creative Technology Ltd.) C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Team H2O) C:\Program Files\Syncrosoft\POS\H2O\cledx.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_11_9_900_170_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Dell Webcam Central] - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe [442536 2008-11-11] (Creative Technology Ltd.)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1983816 2009-03-24] (CANON INC.)
HKLM\...\Run: [CanonSolutionMenu] - C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [767312 2009-03-18] (CANON INC.)
HKLM\...\Run: [Malwarebytes Anti-Malware (reboot)] - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [887432 2013-04-04] (Malwarebytes Corporation)
HKLM\...\Run: [H2O] - C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe [385024 2005-10-22] (Team H2O)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-19] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
HKU\.DEFAULT\...\Run: [msnmsgr] - C:\Program Files\Windows Live\Messenger\msnmsgr.exe [3882312 2008-12-03] (Microsoft Corporation)
HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-1390377413-2575980544-3326841737-1002\...\Winlogon: [Shell] Explorer.exe [2926592 2009-04-11] (Microsoft Corporation) <==== ATTENTION
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Michi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Seppi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKLM - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKCU - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540104} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks:  - {AEB6717E-7E19-11d0-97EE-00C04FD91972} -  No File [ ]
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Seppi\AppData\Roaming\Mozilla\Firefox\Profiles\q79z9d8h.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX OVS Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Seppi\AppData\Roaming\Mozilla\Firefox\Profiles\q79z9d8h.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2013-08-03]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-01-07]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-01-07]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-01-07]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []

========================== Services (Whitelisted) =================

R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [81920 2009-03-20] (Andrea Electronics Corporation)
R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-19] (Avira Operations GmbH & Co. KG)
R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1528616 2010-03-23] (Cisco Systems, Inc.)
R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-12-18] (Stardock Corporation)
S3 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
R2 sprtsvc_DellSupportCenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2009-01-30] (SupportSoft, Inc.)
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe [254042 2009-03-20] (IDT, Inc.)

==================== Drivers (Whitelisted) ====================

S3 61883; C:\Windows\System32\DRIVERS\61883.sys [45696 2008-01-21] (Microsoft Corporation)
R2 Aspi32; C:\Windows\system32\Drivers\Aspi32.sys [25244 1999-09-10] (Adaptec)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-25] (Avira Operations GmbH & Co. KG)
R3 CLEDX; C:\Windows\System32\DRIVERS\cledx.sys [33792 2005-05-09] (Team H2O)
S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [308859 2010-03-23] (Cisco Systems, Inc.)
R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.)
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [26024 2009-12-17] (Elaborate Bytes AG)
R3 OA008Ufd; C:\Windows\System32\DRIVERS\OA008Ufd.sys [133472 2009-02-10] (Creative Technology Ltd.)
R3 OA008Vid; C:\Windows\System32\DRIVERS\OA008Vid.sys [271616 2009-02-10] (Creative Technology Ltd.)
S3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1083520 2006-11-02] (Philips Semiconductors GmbH)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-15] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Seppi\AppData\Local\Temp\catchme.sys [x]
U1 d3dsbe; \??\C:\Windows\system32\drivers\d3dsbe.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S2 Nsynas32; No ImagePath
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S2 Parclass; \SystemRoot\System32\Drivers\Parclass.sys [x]
S3 PCD5SRVC{3F6A8B78-EC003E00-05040104}; \??\C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [x]
S3 StarOpen; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-04 15:53 - 2014-02-04 15:53 - 00018278 _____ () C:\Users\Seppi\Downloads\FRST.txt
2014-02-04 00:31 - 2014-02-04 00:31 - 00005417 _____ () C:\Users\Seppi\Desktop\JRT.txt
2014-02-04 00:28 - 2014-02-04 00:28 - 00000000 ____D () C:\Windows\ERUNT
2014-02-03 22:24 - 2014-02-03 22:24 - 00009060 _____ () C:\Users\Seppi\Desktop\ComboFix.zip
2014-02-03 22:04 - 2014-02-03 22:04 - 00124008 _____ () C:\ComboFix.txt
2014-02-03 21:50 - 2014-02-03 22:04 - 00000000 ____D () C:\ComboFix
2014-02-03 21:49 - 2014-02-03 22:04 - 00000000 ____D () C:\Qoobox
2014-02-03 21:47 - 2014-02-03 21:49 - 05179684 ____R (Swearware) C:\Users\Seppi\Desktop\ComboFix.exe
2014-02-03 21:37 - 2014-02-03 21:37 - 01166132 _____ () C:\Users\Seppi\Downloads\adwcleaner-3.018.exe
2014-02-03 00:59 - 2014-02-03 13:03 - 00000000 ____D () C:\Users\Seppi\Desktop\mbar
2014-02-03 00:59 - 2014-02-03 02:55 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-02-03 00:57 - 2014-02-03 00:58 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Seppi\Desktop\mbar-1.07.0.1009.exe
2014-02-03 00:01 - 2014-02-04 15:53 - 00000000 ____D () C:\FRST
2014-02-02 23:49 - 2014-02-02 23:50 - 01137152 _____ (Farbar) C:\Users\Seppi\Downloads\FRST.exe
2014-02-02 23:42 - 2014-02-02 23:42 - 00000000 _____ () C:\Users\Seppi\defogger_reenable
2014-02-01 20:23 - 2014-02-01 20:23 - 00139616 _____ () C:\Windows\Minidump\Mini020114-01.dmp
2014-01-13 21:57 - 2014-01-13 21:58 - 00139616 _____ () C:\Windows\Minidump\Mini011314-01.dmp
2014-01-10 20:35 - 2014-01-10 20:36 - 00139616 _____ () C:\Windows\Minidump\Mini011014-01.dmp
2014-01-08 20:17 - 2014-01-08 20:17 - 00000868 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-08 20:17 - 2014-01-08 20:17 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-01-08 20:17 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-08 20:13 - 2014-01-08 20:16 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Seppi\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-07 23:48 - 2014-01-07 23:48 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\TuneUp Software
2014-01-07 23:40 - 2014-01-07 23:49 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-01-07 23:40 - 2014-01-07 23:41 - 34008992 _____ (DVDVideoSoft Ltd. ) C:\Users\Seppi\Downloads\FreeYouTubeToMP3Converter-3.12.20.1230.exe
2014-01-07 23:40 - 2014-01-07 23:40 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-01-07 23:36 - 2014-02-04 00:31 - 00001797 _____ () C:\Users\Seppi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-01-07 23:36 - 2014-02-04 00:31 - 00001767 _____ () C:\Users\Seppi\Desktop\Search.lnk
2014-01-07 23:34 - 2014-01-08 20:03 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\DVDVideoSoft
2014-01-07 23:32 - 2014-01-07 23:33 - 32244744 _____ (DVDVideoSoft Ltd. ) C:\Users\Seppi\Downloads\FreeYouTubeDownload-3.2.20.1230.exe
2014-01-07 21:29 - 2014-01-29 22:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox

==================== One Month Modified Files and Folders =======

2014-02-04 15:53 - 2014-02-04 15:53 - 00018278 _____ () C:\Users\Seppi\Downloads\FRST.txt
2014-02-04 15:53 - 2014-02-03 00:01 - 00000000 ____D () C:\FRST
2014-02-04 15:51 - 2011-03-21 21:48 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\Skype
2014-02-04 15:40 - 2009-12-14 00:11 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-04 14:59 - 2012-06-18 21:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-04 14:55 - 2012-02-25 01:14 - 01551103 _____ () C:\Windows\WindowsUpdate.log
2014-02-04 14:21 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-04 14:21 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-04 14:06 - 2013-10-01 10:17 - 00000000 ____D () C:\AdwCleaner
2014-02-04 12:40 - 2009-12-14 00:11 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-04 12:21 - 2010-08-27 14:45 - 00000000 ____D () C:\Program Files\Common Files\Akamai
2014-02-04 12:21 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-04 02:29 - 2006-11-02 14:01 - 00032562 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-04 00:31 - 2014-02-04 00:31 - 00005417 _____ () C:\Users\Seppi\Desktop\JRT.txt
2014-02-04 00:31 - 2014-01-07 23:36 - 00001797 _____ () C:\Users\Seppi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-02-04 00:31 - 2014-01-07 23:36 - 00001767 _____ () C:\Users\Seppi\Desktop\Search.lnk
2014-02-04 00:28 - 2014-02-04 00:28 - 00000000 ____D () C:\Windows\ERUNT
2014-02-03 23:31 - 2012-12-04 21:34 - 00039722 _____ () C:\Windows\PFRO.log
2014-02-03 22:43 - 2012-04-15 19:21 - 00002339 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-02-03 22:24 - 2014-02-03 22:24 - 00009060 _____ () C:\Users\Seppi\Desktop\ComboFix.zip
2014-02-03 22:04 - 2014-02-03 22:04 - 00124008 _____ () C:\ComboFix.txt
2014-02-03 22:04 - 2014-02-03 21:50 - 00000000 ____D () C:\ComboFix
2014-02-03 22:04 - 2014-02-03 21:49 - 00000000 ____D () C:\Qoobox
2014-02-03 22:02 - 2006-11-02 11:23 - 00000385 _____ () C:\Windows\system.ini
2014-02-03 22:00 - 2011-02-12 16:36 - 00000000 ____D () C:\Users\Seppi
2014-02-03 22:00 - 2009-06-03 22:44 - 00000000 ____D () C:\Users\Michael
2014-02-03 21:49 - 2014-02-03 21:47 - 05179684 ____R (Swearware) C:\Users\Seppi\Desktop\ComboFix.exe
2014-02-03 21:37 - 2014-02-03 21:37 - 01166132 _____ () C:\Users\Seppi\Downloads\adwcleaner-3.018.exe
2014-02-03 13:03 - 2014-02-03 00:59 - 00000000 ____D () C:\Users\Seppi\Desktop\mbar
2014-02-03 13:03 - 2010-12-08 17:20 - 00001022 _____ () C:\Windows\Tasks\Google Software Updater.job
2014-02-03 02:55 - 2014-02-03 00:59 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-02-03 00:58 - 2014-02-03 00:57 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Seppi\Desktop\mbar-1.07.0.1009.exe
2014-02-02 23:50 - 2014-02-02 23:49 - 01137152 _____ (Farbar) C:\Users\Seppi\Downloads\FRST.exe
2014-02-02 23:42 - 2014-02-02 23:42 - 00000000 _____ () C:\Users\Seppi\defogger_reenable
2014-02-01 20:23 - 2014-02-01 20:23 - 00139616 _____ () C:\Windows\Minidump\Mini020114-01.dmp
2014-02-01 20:23 - 2013-07-22 11:15 - 299486590 _____ () C:\Windows\MEMORY.DMP
2014-02-01 20:23 - 2010-03-26 12:38 - 00000000 ____D () C:\Windows\Minidump
2014-01-30 20:00 - 2013-08-03 12:03 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-01-29 22:18 - 2014-01-07 21:29 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-01-29 22:18 - 2013-08-03 12:03 - 00000808 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-01-13 21:58 - 2014-01-13 21:57 - 00139616 _____ () C:\Windows\Minidump\Mini011314-01.dmp
2014-01-10 20:36 - 2014-01-10 20:35 - 00139616 _____ () C:\Windows\Minidump\Mini011014-01.dmp
2014-01-08 20:17 - 2014-01-08 20:17 - 00000868 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-08 20:17 - 2014-01-08 20:17 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-01-08 20:16 - 2014-01-08 20:13 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Seppi\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-08 20:03 - 2014-01-07 23:34 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\DVDVideoSoft
2014-01-08 00:43 - 2011-10-06 20:14 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\Audacity
2014-01-08 00:33 - 2013-07-08 21:40 - 00000000 ____D () C:\Users\Seppi\Desktop\Neuer Ordner
2014-01-07 23:49 - 2014-01-07 23:40 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-01-07 23:48 - 2014-01-07 23:48 - 00000000 ____D () C:\Users\Seppi\AppData\Roaming\TuneUp Software
2014-01-07 23:41 - 2014-01-07 23:40 - 34008992 _____ (DVDVideoSoft Ltd. ) C:\Users\Seppi\Downloads\FreeYouTubeToMP3Converter-3.12.20.1230.exe
2014-01-07 23:40 - 2014-01-07 23:40 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-01-07 23:33 - 2014-01-07 23:32 - 32244744 _____ (DVDVideoSoft Ltd. ) C:\Users\Seppi\Downloads\FreeYouTubeDownload-3.2.20.1230.exe
2014-01-07 22:25 - 2011-03-23 14:07 - 00035840 _____ () C:\Users\Seppi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Files to move or delete:
====================
C:\Users\Michael\AppData\Roaming\desktop.ini
C:\Users\Seppi\CTX.DAT


Some content of TEMP:
====================
C:\Users\Seppi\AppData\Local\temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-02-04 12:27

==================== End Of Log ============================

--- --- ---

cosinus 04.02.2014 16:24

Kontrollscan bitte


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


baumus 04.02.2014 16:53

ups...hab leider avira angelassen...ist das eine Problem? wahrscheinlich ja oder
scan läuft noch

cosinus 04.02.2014 17:00

Ja, Beenden, Avira ausmachen

baumus 04.02.2014 19:37

So ....

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=8bbef1d4aec3f845bf2a40ff37010dd8
# engine=16937
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-04 04:01:31
# local_time=2014-02-04 05:01:31 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1799 16775165 100 95 20052 137296575 12822 0
# compatibility_mode=5892 16776574 100 100 100583 229062419 0 0
# scanned=16578
# found=0
# cleaned=0
# scan_time=691
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=8bbef1d4aec3f845bf2a40ff37010dd8
# engine=16937
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-04 06:12:28
# local_time=2014-02-04 07:12:28 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1799 16775165 100 95 27909 137304432 20679 0
# compatibility_mode=5892 16776574 100 100 112040 229070276 0 0
# scanned=279454
# found=28
# cleaned=0
# scan_time=7626
sh=547F689B328FC78AC920973A783CD810D9F42B76 ft=0 fh=0000000000000000 vn="HTML/Iframe.B.Gen virus" ac=I fn="C:\Users\Michael\AppData\Local\Mozilla\Firefox\Profiles\trjms3ui.default\Cache\B33FD5F3d01"
sh=3191D100BD56416B388154827D6F191A916E918B ft=0 fh=0000000000000000 vn="HTML/Iframe.B.Gen virus" ac=I fn="C:\Users\Seppi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\06JWUZ7U\1009[1].htm"
sh=7D3889ECF1BE9CB4B015609108BD1B56C29A54A0 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\7fc0234a-4fb0155a"
sh=427DFDC9226A69A57FC5C1904E681E74BEF4FFBF ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-1493.FY trojan" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\75a2e50d-322bb21b"
sh=6E1728F6001E378F51DE56C257995D1D87876C5C ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\69b01b91-6d1449e5"
sh=D35842F0D78E2E9D9BAAE2620551ED4A067F707C ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-1723.DC trojan" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\51c36d12-5cbc04e9"
sh=3B3120C29C60A4795F57EAE082D1AC263CDA49C3 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\76123017-25c7f9b7"
sh=19B62337C2094E8D6C9563D6DAF9CF9B29C3D8A9 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-0507.EK trojan" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\65d7558-1c36a7a8"
sh=EADA9A4466F75B2AB671F32953A7AAA689D68C7D ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\656ce259-74e8cbb1"
sh=368ED9CAF0A8607522F9C6ED719D3098C63ECB4C ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\66da5259-4add86ce"
sh=445A281D8236F06974CA5455B98A5FDD392A270E ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-2423.O trojan" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\378c31e-568bd1d0"
sh=2F310EF06659DAC551DD57B805026E95554DF416 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\6f60c6de-5c2411df"
sh=3B3120C29C60A4795F57EAE082D1AC263CDA49C3 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\520dbfa1-5330ae23"
sh=C0CBADE9FB4628378EEA190AB7A1D29B48853EC2 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\432f6762-30a98ded"
sh=F8B2251C0EDD15E7CCC1D432118E5C9BA39C7642 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-1493.FY trojan" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\2c6763-4e9b8d09"
sh=309B57BC57124D618381F77F4E855A2D2B8168BE ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\961d984-1b147db0"
sh=8CD0C1E4D2D4B5E2A68879C69B81BE4C507B68DF ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\7913346b-56c8947f"
sh=8CD0C1E4D2D4B5E2A68879C69B81BE4C507B68DF ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\7913346b-6dacdbc7"
sh=CD7D018963FF86B9CECEB8EFB7DCDD85D5B87647 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\560e7f2d-4f1d7a1b"
sh=4B6F5BD2ED99B7A5568644625953BAD22273D243 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-4681.J trojan" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\7798906d-756b0ff2"
sh=18BFC6F1B1991C360CDFFD213D404079546B4D6C ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\3b6de1f0-3caee814"
sh=0F44A245DBD67A0E990F30DDD63AB7E240F4F807 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.NAY trojan" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\46916a45-6b2a4784"
sh=634BCFBEC88323EC2E154D0D097AFA685677933B ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\2f2c3672-2ba84aec"
sh=999FD845FF4812B775F9D16F06E347B4BD616B25 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\4a53972-60439f20"
sh=427DFDC9226A69A57FC5C1904E681E74BEF4FFBF ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-1493.FY trojan" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\6b0052f2-49ff8925"
sh=8E32C1F31B6C27201093D9D646B812350ED5ABFC ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-1493.FY trojan" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\45379b36-641a07be"
sh=9802F7621093DBFC4382358338668406F1C98DD4 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\66145f9-78536d2f"
sh=1AC26CB8FDF81414EB4B18F4E03D03526CBFDDE2 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Seppi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\58de40fb-717108a5"


cosinus 04.02.2014 19:41

Nur Müll in tmp und cache

TFC - Temp File Cleaner

Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
  • Öffne die TFC.exe.
    Vista und Win 7 User mit Rechtsklick "als Administrator starten".
  • Schließe alle anderen Programme.
  • Drücke auf den Button Start.
  • Falls du zu einem Neustart aufgefordert wirst, bestätige diesen.




Sieht soweit ok aus :daumenhoc

Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

baumus 04.02.2014 19:50

Also...bis halt auf die drei Dateien aus dem adwcleaner... die sind immer noch da.
Aber ich bekomme keine pop ups mehr oder irgendwelche PC Leistung ist zu schwach Banner...Herzlichen Dank schonmal.
Soll ich es jetzt dabei belassen ? Waren da jetzt irgendwelche Hämmer dabei?

cosinus 04.02.2014 19:58

Dann wären wir durch! :daumenhoc


Falls du noch Lob oder Kritik loswerden möchtest => Lob, Kritik und Wünsche - Trojaner-Board

Die Programme, die hier zum Einsatz kamen, können alle deinstalliert werden.

Helfen kann dir dabei delfix:


Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.






Bitte abschließend noch die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate
Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.
Windows Vista/7: Start, Systemsteuerung, Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks findest du hier => Browsers and Plugins - FilePony.de

Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

baumus 04.02.2014 20:07

ehm..also danke, der tfc cleaner ist allerdings abgestürzt...:pfeiff:


Alle Zeitangaben in WEZ +1. Es ist jetzt 22:25 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131