![]() |
Rechner viel langsamer, stürzt häufig ab hallo, - habe ws vista, avast antivirus und google chrome - rechner ist letzte tage viel langsamer geworden und chrome friert bald den cursor ein, dann ist jede taste ohne reaktion, habe eindruck, das bald nix mehr geht - bei anwendung von gmer ist mehrmals das gleiche passiert - defogger hat auf schwarzer fläche nix angezeigt - frst 32bit ergebnisse sende ich hier - avast ergebisse lassen kein kopieren zu; da steht: einige dateien können nicht überprüft werden; bei status: fehler: archiv ist kennwortgeschützt vielen dank , bis bald Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:20-07-2014 Ran by tm (administrator) on TM-PC on 20-07-2014 20:45:29 Running from C:\Users\tm\Downloads Platform: Microsoft® Windows Vista™ Home Premium (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 7 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe () C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe () C:\Program Files\Samsung\Samsung Recovery Solution II\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe () C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (FUJIFILM Corporation) C:\Program Files\FinePixViewer\QuickDCF2.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe () C:\Users\tm\Downloads\Defogger (6).exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Farbar) C:\Users\tm\Downloads\FRST (4).exe ==================== Registry (Whitelisted) ================== HKLM\...\RunOnce: [AvgUninstallURL] => cmd.exe /c start hxxp://www.avg.de/de.special-uninstallation-feedback-lsf?lic=OUxTRlJFRS1WUFVaNy1HMk (the data entry has 177 more characters). HKU\.DEFAULT\...\Run: [Samsung.PCSync] => C:\Program Files\Samsung\Samsung PC Studio 7\PcSync2.exe [1294336 2008-09-18] (Time Information Services Ltd.) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [SpybotSD TeaTimer] => C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-01-26] (Google Inc.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\tm\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=7dd42 (the data entry has 82 more characters). HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [S60 PC Suite Tray] => C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe [699392 2008-12-06] () HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: F - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {18cd0e19-9393-11e1-94c8-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {28fd0733-d443-11e1-9967-0013776453a9} - H:\Menu.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {461fa564-22c4-11e1-90b4-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {461fa566-22c4-11e1-90b4-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {48a8bbfd-560a-11df-9857-0013776453a9} - F:\LaunchU3.exe -a HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {9b7a5ae1-d13f-11dd-aae1-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {9b7a5b06-d13f-11dd-aae1-0013776453a9} - G:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {ddab0c5a-e9c0-11e0-837a-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {f8940028-8263-11e0-ba62-db1fa4e62d98} - F:\Menu.exe AppInit_DLLs: C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2010-06-10] (Google) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ExifLauncher2.lnk ShortcutTarget: ExifLauncher2.lnk -> C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/?LinkId=69157 URLSearchHook: HKCU - (No Name) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File URLSearchHook: HKCU - (No Name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File SearchScopes: HKLM - DefaultScope {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} SearchScopes: HKLM - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} SearchScopes: HKCU - {70D46D94-BF1E-45ED-B567-48701376298E} URL = hxxp://127.0.0.1:4664/search&s=FbRkhSNyuC927LohHs6Uav7tIHA?q={searchTerms} SearchScopes: HKCU - {A8221FCE-87F0-4F05-AFFC-6F4672A6D922} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms} SearchScopes: HKCU - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://search.avg.com/route/?d=0&v=6.103.18.1&i=&tp=chrome&q={searchTerms}&lng={language}&iy=&ychte=us BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll No File BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) BHO: No Name -> {B922D405-6D13-4A2B-AE89-08A030DA4402} -> No File Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - No Name - {A057A204-BACC-4D26-9990-79A187E2698E} - No File Toolbar: HKCU - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml FF DefaultSearchEngine: WEB.DE Suche FF SelectedSearchEngine: WEB.DE Suche FF Homepage: hxxp://go.web.de/tb/mff_startpage FF Keyword.URL: user_pref("keyword.URL", ""); FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\webde-suche.xml FF Extension: WEB.DE MailCheck - C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\Extensions\toolbar@web.de.xpi [2012-12-14] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-11-09] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-07-20] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://www.google.com/" CHR DefaultSearchKeyword: web.de CHR DefaultNewTabURL: CHR Extension: (Google Docs) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-09] CHR Extension: (Google Drive) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-09] CHR Extension: (YouTube) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-09] CHR Extension: (Google-Suche) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-09] CHR Extension: (avast! Online Security) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-11-09] CHR Extension: (Google Wallet) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-09] CHR Extension: (Google Mail) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-09] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-09] ========================== Services (Whitelisted) ================= R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [116040 2008-09-10] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-06] (AVAST Software) S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-10] (Google) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45408 2008-11-24] (Microsoft Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44544 2008-12-03] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2008-12-03] (Hewlett-Packard) [File not signed] R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [171040 2007-01-08] () [File not signed] S2 Samsung Update Plus; C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe [73728 2007-06-28] () [File not signed] R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S3 TDslMgrService; C:\Program Files\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) [File not signed] S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-01-06] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2014-01-06] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2013-11-09] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-01-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2014-01-06] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2014-01-06] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2014-01-06] () R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) S3 dsltestSp5; C:\Windows\System32\Drivers\dsltestSp5.sys [26816 2007-09-12] (Printing Communications Assoc., Inc. (PCAUSA)) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2007-07-11] (SAMSUNG ELECTRONICS CO., LTD.) S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation) S3 NPF; C:\Windows\System32\drivers\npf.sys [34064 2007-11-06] (CACE Technologies) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [113664 2009-12-08] (Huawei Technologies Co., Ltd.) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-20 20:45 - 2014-07-20 20:45 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (4).exe 2014-07-20 20:44 - 2014-07-20 20:44 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (6).exe 2014-07-20 20:26 - 2014-07-20 20:26 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (4).exe 2014-07-20 20:16 - 2014-07-20 20:17 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (3).exe 2014-07-20 20:16 - 2014-07-20 20:16 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (5).exe 2014-07-20 19:45 - 2014-07-20 19:45 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (3).exe 2014-07-20 19:41 - 2014-07-20 19:41 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (2).exe 2014-07-20 19:40 - 2014-07-20 19:40 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (4).exe 2014-07-20 19:27 - 2014-07-20 19:27 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (2).exe 2014-07-20 19:25 - 2014-07-20 19:25 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (1).exe 2014-07-20 19:13 - 2014-07-20 19:14 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (1).exe 2014-07-20 19:10 - 2014-07-20 19:11 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (3).exe 2014-07-20 04:33 - 2014-07-20 04:33 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357.exe 2014-07-20 04:14 - 2014-07-20 20:20 - 00035689 _____ () C:\Users\tm\Downloads\Addition.txt 2014-07-20 04:10 - 2014-07-20 20:45 - 00019297 _____ () C:\Users\tm\Downloads\FRST.txt 2014-07-20 04:09 - 2014-07-20 20:45 - 00000000 ____D () C:\FRST 2014-07-20 04:08 - 2014-07-20 04:08 - 01079808 _____ (Farbar) C:\Users\tm\Downloads\FRST.exe 2014-07-20 04:04 - 2014-07-20 20:44 - 00000466 _____ () C:\Users\tm\Downloads\defogger_disable.log 2014-07-20 04:04 - 2014-07-20 04:04 - 00000000 _____ () C:\Users\tm\defogger_reenable 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger.exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (2).exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (1).exe 2014-07-20 03:48 - 2014-07-20 04:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-20 03:45 - 2014-07-20 03:45 - 00000000 ____D () C:\Windows\SQL9_KB970892_ENU 2014-07-20 03:27 - 2008-06-20 03:18 - 00781344 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2014-07-20 03:27 - 2008-06-20 03:18 - 00326160 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2014-07-20 03:27 - 2008-06-20 03:18 - 00105016 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2014-07-20 03:27 - 2008-06-20 03:18 - 00043544 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2014-07-20 03:27 - 2008-06-20 03:17 - 00622080 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-07-20 03:27 - 2008-06-20 03:17 - 00097800 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-07-20 03:27 - 2008-06-20 03:17 - 00037384 _____ (Microsoft Corporation) C:\Windows\system32\infocardcpl.cpl 2014-07-20 03:27 - 2008-06-20 03:17 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-07-20 03:19 - 2014-07-20 03:26 - 00196608 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.perf 2014-07-20 03:19 - 2014-07-20 03:26 - 00065536 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.dpx 2014-07-20 03:06 - 2008-07-27 20:00 - 00096760 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2014-07-20 03:04 - 2008-07-27 20:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-07-20 03:02 - 2010-02-21 01:54 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\nshhttp.dll 2014-07-20 03:01 - 2010-02-21 01:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\httpapi.dll 2014-07-20 03:01 - 2010-02-20 23:30 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2014-07-12 20:56 - 2014-07-12 20:56 - 00031744 _____ () C:\Users\tm\Downloads\Firmenlauf_Bielefeld_Anmeldung2014.xls 2014-07-06 19:07 - 2006-12-14 13:42 - 00069120 ____R (AVM Berlin) C:\Windows\system32\avmadd32.dll ==================== One Month Modified Files and Folders ======= 2014-07-20 20:45 - 2014-07-20 20:45 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (4).exe 2014-07-20 20:45 - 2014-07-20 04:10 - 00019297 _____ () C:\Users\tm\Downloads\FRST.txt 2014-07-20 20:45 - 2014-07-20 04:09 - 00000000 ____D () C:\FRST 2014-07-20 20:45 - 2008-03-30 15:28 - 00000412 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{7DE789EB-2CEE-4FAA-A54E-B1DE1CF3B6DF}.job 2014-07-20 20:45 - 2008-01-25 05:31 - 00000434 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{D9B30BB4-63C0-47D4-A444-A174F9308500}.job 2014-07-20 20:44 - 2014-07-20 20:44 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (6).exe 2014-07-20 20:44 - 2014-07-20 04:04 - 00000466 _____ () C:\Users\tm\Downloads\defogger_disable.log 2014-07-20 20:40 - 2011-05-29 04:42 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-20 20:40 - 2008-03-30 14:59 - 00000000 ____D () C:\Users\tm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-07-20 20:40 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-20 20:40 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-20 20:40 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-20 20:26 - 2014-07-20 20:26 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (4).exe 2014-07-20 20:20 - 2014-07-20 04:14 - 00035689 _____ () C:\Users\tm\Downloads\Addition.txt 2014-07-20 20:18 - 2011-05-29 04:42 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-20 20:17 - 2014-07-20 20:16 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (3).exe 2014-07-20 20:16 - 2014-07-20 20:16 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (5).exe 2014-07-20 20:13 - 2008-01-25 06:20 - 01084991 _____ () C:\Windows\WindowsUpdate.log 2014-07-20 19:45 - 2014-07-20 19:45 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (3).exe 2014-07-20 19:41 - 2014-07-20 19:41 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (2).exe 2014-07-20 19:40 - 2014-07-20 19:40 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (4).exe 2014-07-20 19:27 - 2014-07-20 19:27 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (2).exe 2014-07-20 19:25 - 2014-07-20 19:25 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (1).exe 2014-07-20 19:14 - 2014-07-20 19:13 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (1).exe 2014-07-20 19:11 - 2014-07-20 19:10 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (3).exe 2014-07-20 18:54 - 2012-12-27 20:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-20 17:25 - 2009-08-26 12:57 - 00000000 ____D () C:\Program Files\PC Connectivity Solution 2014-07-20 12:54 - 2007-07-11 00:17 - 00000012 _____ () C:\Windows\bthservsdp.dat 2014-07-20 12:54 - 2006-11-02 15:01 - 00032538 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-20 12:53 - 2014-05-01 20:12 - 00035328 _____ () C:\Users\tm\Documents\infobook.xls 2014-07-20 11:22 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-07-20 11:17 - 2007-07-10 07:07 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE 2014-07-20 11:17 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\system32\XPSViewer 2014-07-20 11:17 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-07-20 11:16 - 2008-08-23 19:22 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-20 11:16 - 2007-07-11 01:28 - 00034152 _____ () C:\Windows\PFRO.log 2014-07-20 04:33 - 2014-07-20 04:33 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357.exe 2014-07-20 04:08 - 2014-07-20 04:08 - 01079808 _____ (Farbar) C:\Users\tm\Downloads\FRST.exe 2014-07-20 04:04 - 2014-07-20 04:04 - 00000000 _____ () C:\Users\tm\defogger_reenable 2014-07-20 04:04 - 2008-03-30 14:58 - 00000000 ____D () C:\Users\tm 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger.exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (2).exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (1).exe 2014-07-20 04:02 - 2014-07-20 03:48 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-20 03:46 - 2006-11-02 12:33 - 01492226 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-20 03:45 - 2014-07-20 03:45 - 00000000 ____D () C:\Windows\SQL9_KB970892_ENU 2014-07-20 03:45 - 2007-07-11 01:13 - 00000000 ____D () C:\Program Files\Microsoft SQL Server 2014-07-20 03:26 - 2014-07-20 03:19 - 00196608 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.perf 2014-07-20 03:26 - 2014-07-20 03:19 - 00065536 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.dpx 2014-07-20 03:26 - 2010-05-29 15:47 - 58916864 _____ () C:\Windows\ocsetup_install_NetFx3.etl 2014-07-20 03:01 - 2011-01-14 02:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-20 02:58 - 2010-05-29 15:35 - 00284204 _____ () C:\Windows\msxml4-KB954430-enu.LOG 2014-07-20 02:56 - 2010-05-29 15:34 - 00288290 _____ () C:\Windows\msxml4-KB973688-enu.LOG 2014-07-18 16:04 - 2013-11-09 06:07 - 00001963 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-12 20:56 - 2014-07-12 20:56 - 00031744 _____ () C:\Users\tm\Downloads\Firmenlauf_Bielefeld_Anmeldung2014.xls 2014-07-10 22:04 - 2008-04-15 23:06 - 00066048 _____ () C:\Users\tm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-08 22:59 - 2012-12-27 20:40 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-07-08 22:59 - 2011-06-27 23:52 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-07-06 19:08 - 2013-02-09 20:46 - 00002963 _____ () C:\Windows\avmadd32.log 2014-07-06 19:07 - 2013-02-09 20:46 - 00000000 ____D () C:\Program Files\FRITZ!Box 2014-06-26 17:38 - 2006-11-02 12:24 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe Some content of TEMP: ==================== C:\Users\tm\AppData\Local\Temp\DataCard_Setup.exe C:\Users\tm\AppData\Local\Temp\ResetDevice.exe C:\Users\tm\AppData\Local\Temp\UNINSTALL.EXE C:\Users\tm\AppData\Local\Temp\_is227F.exe C:\Users\tm\AppData\Local\Temp\_is4847.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-20 20:46 ==================== End Of Log ============================ Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:20-07-2014 Ran by tm (administrator) on TM-PC on 20-07-2014 20:46:39 Running from C:\Users\tm\Downloads Platform: Microsoft® Windows Vista™ Home Premium (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 7 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe () C:\Program Files\Samsung\Samsung Recovery Solution II\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe () C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (FUJIFILM Corporation) C:\Program Files\FinePixViewer\QuickDCF2.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe () C:\Users\tm\Downloads\Defogger (6).exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Farbar) C:\Users\tm\Downloads\FRST (4).exe () C:\Program Files\Samsung\Samsung Update Plus\SLUTrayNotifier.exe ==================== Registry (Whitelisted) ================== HKLM\...\RunOnce: [AvgUninstallURL] => cmd.exe /c start hxxp://www.avg.de/de.special-uninstallation-feedback-lsf?lic=OUxTRlJFRS1WUFVaNy1HMk (the data entry has 177 more characters). HKU\.DEFAULT\...\Run: [Samsung.PCSync] => C:\Program Files\Samsung\Samsung PC Studio 7\PcSync2.exe [1294336 2008-09-18] (Time Information Services Ltd.) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [SpybotSD TeaTimer] => C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-01-26] (Google Inc.) HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\tm\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=7dd42 (the data entry has 82 more characters). HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\Run: [S60 PC Suite Tray] => C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe [699392 2008-12-06] () HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: F - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {18cd0e19-9393-11e1-94c8-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {28fd0733-d443-11e1-9967-0013776453a9} - H:\Menu.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {461fa564-22c4-11e1-90b4-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {461fa566-22c4-11e1-90b4-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {48a8bbfd-560a-11df-9857-0013776453a9} - F:\LaunchU3.exe -a HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {9b7a5ae1-d13f-11dd-aae1-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {9b7a5b06-d13f-11dd-aae1-0013776453a9} - G:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {ddab0c5a-e9c0-11e0-837a-0013776453a9} - F:\AutoRun.exe HKU\S-1-5-21-3037083410-1282845951-3713001464-1003\...\MountPoints2: {f8940028-8263-11e0-ba62-db1fa4e62d98} - F:\Menu.exe AppInit_DLLs: C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2010-06-10] (Google) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ExifLauncher2.lnk ShortcutTarget: ExifLauncher2.lnk -> C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/?LinkId=69157 URLSearchHook: HKCU - (No Name) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File URLSearchHook: HKCU - (No Name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File SearchScopes: HKLM - DefaultScope {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} SearchScopes: HKLM - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} SearchScopes: HKCU - {70D46D94-BF1E-45ED-B567-48701376298E} URL = hxxp://127.0.0.1:4664/search&s=FbRkhSNyuC927LohHs6Uav7tIHA?q={searchTerms} SearchScopes: HKCU - {A8221FCE-87F0-4F05-AFFC-6F4672A6D922} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms} SearchScopes: HKCU - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = hxxp://search.avg.com/route/?d=0&v=6.103.18.1&i=&tp=chrome&q={searchTerms}&lng={language}&iy=&ychte=us BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll No File BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) BHO: No Name -> {B922D405-6D13-4A2B-AE89-08A030DA4402} -> No File Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - No Name - {A057A204-BACC-4D26-9990-79A187E2698E} - No File Toolbar: HKCU - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml FF DefaultSearchEngine: WEB.DE Suche FF SelectedSearchEngine: WEB.DE Suche FF Homepage: hxxp://go.web.de/tb/mff_startpage FF Keyword.URL: user_pref("keyword.URL", ""); FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\searchplugins\webde-suche.xml FF Extension: WEB.DE MailCheck - C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\Extensions\toolbar@web.de.xpi [2012-12-14] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-11-09] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-07-20] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://www.google.com/" CHR DefaultSearchKeyword: web.de CHR DefaultNewTabURL: CHR Extension: (Google Docs) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-09] CHR Extension: (Google Drive) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-09] CHR Extension: (YouTube) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-09] CHR Extension: (Google-Suche) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-09] CHR Extension: (avast! Online Security) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-11-09] CHR Extension: (Google Wallet) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-09] CHR Extension: (Google Mail) - C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-09] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-09] ========================== Services (Whitelisted) ================= R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [116040 2008-09-10] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-06] (AVAST Software) S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-10] (Google) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45408 2008-11-24] (Microsoft Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44544 2008-12-03] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2008-12-03] (Hewlett-Packard) [File not signed] R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [171040 2007-01-08] () [File not signed] S2 Samsung Update Plus; C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe [73728 2007-06-28] () [File not signed] R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S3 TDslMgrService; C:\Program Files\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) [File not signed] S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-01-06] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2014-01-06] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2013-11-09] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-01-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2014-01-06] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2014-01-06] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2014-01-06] () R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) S3 dsltestSp5; C:\Windows\System32\Drivers\dsltestSp5.sys [26816 2007-09-12] (Printing Communications Assoc., Inc. (PCAUSA)) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2007-07-11] (SAMSUNG ELECTRONICS CO., LTD.) S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation) S3 NPF; C:\Windows\System32\drivers\npf.sys [34064 2007-11-06] (CACE Technologies) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [113664 2009-12-08] (Huawei Technologies Co., Ltd.) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-20 20:45 - 2014-07-20 20:45 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (4).exe 2014-07-20 20:44 - 2014-07-20 20:44 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (6).exe 2014-07-20 20:26 - 2014-07-20 20:26 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (4).exe 2014-07-20 20:16 - 2014-07-20 20:17 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (3).exe 2014-07-20 20:16 - 2014-07-20 20:16 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (5).exe 2014-07-20 19:45 - 2014-07-20 19:45 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (3).exe 2014-07-20 19:41 - 2014-07-20 19:41 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (2).exe 2014-07-20 19:40 - 2014-07-20 19:40 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (4).exe 2014-07-20 19:27 - 2014-07-20 19:27 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (2).exe 2014-07-20 19:25 - 2014-07-20 19:25 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (1).exe 2014-07-20 19:13 - 2014-07-20 19:14 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (1).exe 2014-07-20 19:10 - 2014-07-20 19:11 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (3).exe 2014-07-20 04:33 - 2014-07-20 04:33 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357.exe 2014-07-20 04:14 - 2014-07-20 20:20 - 00035689 _____ () C:\Users\tm\Downloads\Addition.txt 2014-07-20 04:10 - 2014-07-20 20:46 - 00019207 _____ () C:\Users\tm\Downloads\FRST.txt 2014-07-20 04:09 - 2014-07-20 20:46 - 00000000 ____D () C:\FRST 2014-07-20 04:08 - 2014-07-20 04:08 - 01079808 _____ (Farbar) C:\Users\tm\Downloads\FRST.exe 2014-07-20 04:04 - 2014-07-20 20:44 - 00000466 _____ () C:\Users\tm\Downloads\defogger_disable.log 2014-07-20 04:04 - 2014-07-20 04:04 - 00000000 _____ () C:\Users\tm\defogger_reenable 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger.exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (2).exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (1).exe 2014-07-20 03:48 - 2014-07-20 04:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-20 03:45 - 2014-07-20 03:45 - 00000000 ____D () C:\Windows\SQL9_KB970892_ENU 2014-07-20 03:27 - 2008-06-20 03:18 - 00781344 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2014-07-20 03:27 - 2008-06-20 03:18 - 00326160 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2014-07-20 03:27 - 2008-06-20 03:18 - 00105016 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2014-07-20 03:27 - 2008-06-20 03:18 - 00043544 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2014-07-20 03:27 - 2008-06-20 03:17 - 00622080 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-07-20 03:27 - 2008-06-20 03:17 - 00097800 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-07-20 03:27 - 2008-06-20 03:17 - 00037384 _____ (Microsoft Corporation) C:\Windows\system32\infocardcpl.cpl 2014-07-20 03:27 - 2008-06-20 03:17 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-07-20 03:19 - 2014-07-20 03:26 - 00196608 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.perf 2014-07-20 03:19 - 2014-07-20 03:26 - 00065536 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.dpx 2014-07-20 03:06 - 2008-07-27 20:00 - 00096760 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-07-20 03:05 - 2008-07-27 20:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2014-07-20 03:04 - 2008-07-27 20:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-07-20 03:02 - 2010-02-21 01:54 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\nshhttp.dll 2014-07-20 03:01 - 2010-02-21 01:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\httpapi.dll 2014-07-20 03:01 - 2010-02-20 23:30 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2014-07-12 20:56 - 2014-07-12 20:56 - 00031744 _____ () C:\Users\tm\Downloads\Firmenlauf_Bielefeld_Anmeldung2014.xls 2014-07-06 19:07 - 2006-12-14 13:42 - 00069120 ____R (AVM Berlin) C:\Windows\system32\avmadd32.dll ==================== One Month Modified Files and Folders ======= 2014-07-20 20:46 - 2014-07-20 04:10 - 00019207 _____ () C:\Users\tm\Downloads\FRST.txt 2014-07-20 20:46 - 2014-07-20 04:09 - 00000000 ____D () C:\FRST 2014-07-20 20:45 - 2014-07-20 20:45 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (4).exe 2014-07-20 20:45 - 2008-03-30 15:28 - 00000412 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{7DE789EB-2CEE-4FAA-A54E-B1DE1CF3B6DF}.job 2014-07-20 20:45 - 2008-01-25 05:31 - 00000434 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{D9B30BB4-63C0-47D4-A444-A174F9308500}.job 2014-07-20 20:44 - 2014-07-20 20:44 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (6).exe 2014-07-20 20:44 - 2014-07-20 04:04 - 00000466 _____ () C:\Users\tm\Downloads\defogger_disable.log 2014-07-20 20:43 - 2008-01-25 06:20 - 01084991 _____ () C:\Windows\WindowsUpdate.log 2014-07-20 20:40 - 2011-05-29 04:42 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-20 20:40 - 2008-03-30 14:59 - 00000000 ____D () C:\Users\tm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-07-20 20:40 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-20 20:40 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-20 20:40 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-20 20:26 - 2014-07-20 20:26 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (4).exe 2014-07-20 20:20 - 2014-07-20 04:14 - 00035689 _____ () C:\Users\tm\Downloads\Addition.txt 2014-07-20 20:18 - 2011-05-29 04:42 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-20 20:17 - 2014-07-20 20:16 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (3).exe 2014-07-20 20:16 - 2014-07-20 20:16 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (5).exe 2014-07-20 19:45 - 2014-07-20 19:45 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (3).exe 2014-07-20 19:41 - 2014-07-20 19:41 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (2).exe 2014-07-20 19:40 - 2014-07-20 19:40 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (4).exe 2014-07-20 19:27 - 2014-07-20 19:27 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (2).exe 2014-07-20 19:25 - 2014-07-20 19:25 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357 (1).exe 2014-07-20 19:14 - 2014-07-20 19:13 - 01080320 _____ (Farbar) C:\Users\tm\Downloads\FRST (1).exe 2014-07-20 19:11 - 2014-07-20 19:10 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (3).exe 2014-07-20 18:54 - 2012-12-27 20:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-20 17:25 - 2009-08-26 12:57 - 00000000 ____D () C:\Program Files\PC Connectivity Solution 2014-07-20 12:54 - 2007-07-11 00:17 - 00000012 _____ () C:\Windows\bthservsdp.dat 2014-07-20 12:54 - 2006-11-02 15:01 - 00032538 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-20 12:53 - 2014-05-01 20:12 - 00035328 _____ () C:\Users\tm\Documents\infobook.xls 2014-07-20 11:22 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-07-20 11:17 - 2007-07-10 07:07 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE 2014-07-20 11:17 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\system32\XPSViewer 2014-07-20 11:17 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-07-20 11:16 - 2008-08-23 19:22 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-20 11:16 - 2007-07-11 01:28 - 00034152 _____ () C:\Windows\PFRO.log 2014-07-20 04:33 - 2014-07-20 04:33 - 00380416 _____ () C:\Users\tm\Downloads\Gmer-19357.exe 2014-07-20 04:08 - 2014-07-20 04:08 - 01079808 _____ (Farbar) C:\Users\tm\Downloads\FRST.exe 2014-07-20 04:04 - 2014-07-20 04:04 - 00000000 _____ () C:\Users\tm\defogger_reenable 2014-07-20 04:04 - 2008-03-30 14:58 - 00000000 ____D () C:\Users\tm 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger.exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (2).exe 2014-07-20 04:02 - 2014-07-20 04:02 - 00050477 _____ () C:\Users\tm\Downloads\Defogger (1).exe 2014-07-20 04:02 - 2014-07-20 03:48 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-20 03:46 - 2006-11-02 12:33 - 01492226 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-20 03:45 - 2014-07-20 03:45 - 00000000 ____D () C:\Windows\SQL9_KB970892_ENU 2014-07-20 03:45 - 2007-07-11 01:13 - 00000000 ____D () C:\Program Files\Microsoft SQL Server 2014-07-20 03:26 - 2014-07-20 03:19 - 00196608 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.perf 2014-07-20 03:26 - 2014-07-20 03:19 - 00065536 _____ () C:\Windows\ocsetup_cbs_install_NetFx3.dpx 2014-07-20 03:26 - 2010-05-29 15:47 - 58916864 _____ () C:\Windows\ocsetup_install_NetFx3.etl 2014-07-20 03:01 - 2011-01-14 02:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-20 02:58 - 2010-05-29 15:35 - 00284204 _____ () C:\Windows\msxml4-KB954430-enu.LOG 2014-07-20 02:56 - 2010-05-29 15:34 - 00288290 _____ () C:\Windows\msxml4-KB973688-enu.LOG 2014-07-18 16:04 - 2013-11-09 06:07 - 00001963 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-12 20:56 - 2014-07-12 20:56 - 00031744 _____ () C:\Users\tm\Downloads\Firmenlauf_Bielefeld_Anmeldung2014.xls 2014-07-10 22:04 - 2008-04-15 23:06 - 00066048 _____ () C:\Users\tm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-08 22:59 - 2012-12-27 20:40 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-07-08 22:59 - 2011-06-27 23:52 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-07-06 19:08 - 2013-02-09 20:46 - 00002963 _____ () C:\Windows\avmadd32.log 2014-07-06 19:07 - 2013-02-09 20:46 - 00000000 ____D () C:\Program Files\FRITZ!Box 2014-06-26 17:38 - 2006-11-02 12:24 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe Some content of TEMP: ==================== C:\Users\tm\AppData\Local\Temp\DataCard_Setup.exe C:\Users\tm\AppData\Local\Temp\ResetDevice.exe C:\Users\tm\AppData\Local\Temp\UNINSTALL.EXE C:\Users\tm\AppData\Local\Temp\_is227F.exe C:\Users\tm\AppData\Local\Temp\_is4847.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-20 20:46 ==================== End Of Log ============================ |
hi, ![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Scan mit Combofix
|
- strg+a funktioniert, aber bei strg+c tut sich nix - raute symbol nicht zu finden es ist soweit: Combofix Logfile: Code: ComboFix 14-07-20.02 - tm 20.07.2014 23:16:32.1.2 - x86 61A349592C4728853F4A90FF78F7628E |
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
AdwCleaner Logfile: Code: # AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 23:40:35 AdwCleaner Logfile: Code: # AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 23:40:35 AdwCleaner Logfile: Code: # AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 23:40:35 -\\ Internet Explorer v7.0.6000.16982 -\\ Mozilla Firefox v24.0 (en-US) [ Datei : C:\Users\tm\AppData\Roaming\Mozilla\Firefox\Profiles\4774widz.default\prefs.js ] -\\ Google Chrome v36.0.1985.125 [ Datei : C:\Users\tm\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [5015 octets] - [21/07/2014 23:40:35] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [5075 octets] ########## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.3 (03.23.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by tm on 22.07.2014 at 21:43:15,51 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\features\cb2848362903cd24ea1a37254619a177 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\products\cb2848362903cd24ea1a37254619a177 Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-9990-79A187E26990} ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\tm\AppData\Roaming\mozilla\firefox\profiles\4774widz.default\minidumps [226 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 22.07.2014 at 21:54:14,80 Computer was rebooted End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:21-07-2014 bis bald, euer dieter |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
- ich habe den eset scanner seit 16stunden an, er ist jetzt bei 98%, der rechner war im ruhezustand in der nacht, die eset uhr ist aber weitergegangen - er hat bereits 10 infizierte dateien gefunden - ist das üblich, das das so lange dauert? jawoll, es ist soweit: ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=76bdcc2de68d0c43af9f7306214d3c01 # engine=19334 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-07-25 06:24:18 # local_time=2014-07-25 08:24:18 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.0.6000 NT # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 98 17278307 22346467 0 0 # compatibility_mode_1='' # compatibility_mode=5892 16776574 100 100 19101997 243845386 0 0 # scanned=147548 # found=10 # cleaned=0 # scan_time=75375 sh=D39337387252F3C67C67B40452DBD80C7A3CE2A5 ft=1 fh=c9d8a8c0ff01a86e vn="Variante von Win32/Riern.AA Trojaner" ac=I fn="C:\Users\tm\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\tm\AppData\Roaming\Adobe\Update\flacor.dat" sh=EF097CD8073F19703A541003CA291A668E8BD219 ft=0 fh=0000000000000000 vn="HTML/Ransom.H Trojaner" ac=I fn="C:\Users\tm\AppData\Local\Mozilla\Firefox\Profiles\4774widz.default\Cache\9\4A\EA7E8d01" sh=C70B34671A8D78751C45EC3DD93E26F9D09ECE31 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\tm\AppData\LocalLow\Sun\Java\Deployment\cache\javapi\v1.0\jar\bzdufrxqcqipxw.jar-27093f0d-28a045e2.zip" sh=4C4EFBE3CF33F25B3BFC407AF2D60986C7707F91 ft=0 fh=0000000000000000 vn="Variante von Java/TrojanDownloader.OpenConnection.MU Trojaner" ac=I fn="C:\Users\tm\AppData\LocalLow\Sun\Java\Deployment\cache\javapi\v1.0\jar\ceptjust.jar-7057084d-4caf34b3.zip" sh=87117AE79FC23396658D402115227BE5AD7E98F0 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\tm\AppData\LocalLow\Sun\Java\Deployment\cache\javapi\v1.0\jar\javaobe.jar-5d04cda4-67996a01.zip" sh=122E9BC17C6D3BA220F10B91F6AE5CC55141890B ft=0 fh=0000000000000000 vn="Java/TrojanDownloader.Agent.NEW Trojaner" ac=I fn="C:\Users\tm\AppData\LocalLow\Sun\Java\Deployment\cache\javapi\v1.0\jar\pul.jar-6b476721-4b601169.zip" sh=8A4DE7D389D7A596C40F2B2D23C1FC141A955EE4 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\tm\AppData\LocalLow\Sun\Java\Deployment\cache\javapi\v1.0\jar\rox.jar-36741d87-53f2352f.zip" sh=51B2020A5C9F59DD907BEA7A33536860B333F35C ft=0 fh=0000000000000000 vn="Java/Agent.DU Trojaner" ac=I fn="C:\Users\tm\AppData\LocalLow\Sun\Java\Deployment\cache\javapi\v1.0\jar\worms.jar-615a03d4-774d41be.zip" sh=BCBD47A2AFB0A7956BBF88F9F625E00D17319CAB ft=1 fh=220efb76e017b9c0 vn="Win32/RegistryBooster evtl. unerwünschte Anwendung" ac=I fn="C:\Users\tm\Documents\registrybooster.exe" sh=1EA929535B44A59063BBE3001195697C7711C73F ft=0 fh=0000000000000000 vn="möglicherweise Variante von Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\f0973.msi" Results of screen317's Security Check version 0.99.85 Windows Vista x86 Out of date service pack!! Internet Explorer 7 Out of date! ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Out of date HijackThis installed! Spybot - Search & Destroy HijackThis 2.0.2 Java 2 Runtime Environment, SE v1.4.2_15 Java version out of Date! Adobe Flash Player 14.0.0.145 Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox 24.0 Firefox out of Date! Google Chrome 35.0.1916.153 Google Chrome 36.0.1985.125 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe ESET ESET Online Scanner OnlineScannerApp.exe Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe Malwarebytes Anti-Malware mbamscheduler.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:24-07-2014 01 --- --- --- |
Ja der dauert schon. Java, Adobe, Firefox und unbedingt Windows updaten. Da fehlt ein ganzes Servicepack. Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig :) Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :) Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
- konnte kein fixlog.txt erstellen; habe folgendes gemacht:- kopieren ins notepad-datei umbenennen in fixlog.txt-speichern unter-desktop-frst fix-ergebnis:no fixlist found - der rechner beginnt erst jetzt nach dem tfc schneller zu werden, auch ms office: war denn insgesamt ein virus schuld an dieser komplexen verlangsamung? - soll ich fortsetzen mit deinen tipps wie defogger und combofix etc.? |
`Bei dir läuft FRST aus dem Download Ordner, also muss ide fixlist auch in den Download Ordner :) |
- wo finde ich den dowlnload order? - defogger konnte ich auf re-enable stellen - combofix/unnstall konnte nicht gefunden werden erschien nach ok; bin auf C: und habe es umbenannt mit gleichem ergebnis delfix hier: # DelFix v10.7 - Datei am 29/07/2014 um 18:51:33 erstellt # Aktualisiert am 27/04/2014 von Xplode # Benutzer : tm - TM-PC # Betriebssystem : Windows Vista (TM) Home Premium (32 bits) ~ Aktiviere die Benutzerkontensteuerung ... OK ~ Entferne die Bereinigungsprogramme ... Gelöscht : C:\Qoobox Gelöscht : C:\FRST Gelöscht : C:\AdwCleaner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hijackthis Gelöscht : C:\Program Files\Trend Micro\Hijackthis Gelöscht : C:\ComboFix.txt Gelöscht : C:\Users\tm\Desktop\JRT.txt Gelöscht : C:\Users\tm\Desktop\HijackThis.lnk Gelöscht : C:\Users\tm\Downloads\Addition.txt Gelöscht : C:\Users\tm\Downloads\adwcleaner_3.216 (1).exe Gelöscht : C:\Users\tm\Downloads\adwcleaner_3.216 (2).exe Gelöscht : C:\Users\tm\Downloads\adwcleaner_3.216 (3).exe Gelöscht : C:\Users\tm\Downloads\adwcleaner_3.216.exe Gelöscht : C:\Users\tm\Downloads\ComboFix.exe Gelöscht : C:\Users\tm\Downloads\Defogger (1).exe Gelöscht : C:\Users\tm\Downloads\Defogger (2).exe Gelöscht : C:\Users\tm\Downloads\Defogger (3).exe Gelöscht : C:\Users\tm\Downloads\Defogger (4).exe Gelöscht : C:\Users\tm\Downloads\Defogger (5).exe Gelöscht : C:\Users\tm\Downloads\Defogger (6).exe Gelöscht : C:\Users\tm\Downloads\Defogger (7).exe Gelöscht : C:\Users\tm\Downloads\Defogger (8).exe Gelöscht : C:\Users\tm\Downloads\Defogger.exe Gelöscht : C:\Users\tm\Downloads\defogger_disable.log Gelöscht : C:\Users\tm\Downloads\defogger_enable.log Gelöscht : C:\Users\tm\Downloads\esetsmartinstaller_deu (1).exe Gelöscht : C:\Users\tm\Downloads\esetsmartinstaller_deu (2).exe Gelöscht : C:\Users\tm\Downloads\esetsmartinstaller_deu.exe Gelöscht : C:\Users\tm\Downloads\FRST (1).exe Gelöscht : C:\Users\tm\Downloads\FRST (10).exe Gelöscht : C:\Users\tm\Downloads\FRST (11).exe Gelöscht : C:\Users\tm\Downloads\FRST (12).exe Gelöscht : C:\Users\tm\Downloads\FRST (13).exe Gelöscht : C:\Users\tm\Downloads\FRST (14).exe Gelöscht : C:\Users\tm\Downloads\FRST (2).exe Gelöscht : C:\Users\tm\Downloads\FRST (3).exe Gelöscht : C:\Users\tm\Downloads\FRST (4).exe Gelöscht : C:\Users\tm\Downloads\FRST (5).exe Gelöscht : C:\Users\tm\Downloads\FRST (6).exe Gelöscht : C:\Users\tm\Downloads\FRST (7).exe Gelöscht : C:\Users\tm\Downloads\FRST (8).exe Gelöscht : C:\Users\tm\Downloads\FRST (9).exe Gelöscht : C:\Users\tm\Downloads\FRST.exe Gelöscht : C:\Users\tm\Downloads\FRST.txt Gelöscht : C:\Users\tm\Downloads\JRT.exe Gelöscht : C:\Users\tm\Downloads\SecurityCheck.exe Gelöscht : C:\Users\tm\Downloads\TFC (1).exe Gelöscht : C:\Users\tm\Downloads\TFC (2).exe Gelöscht : C:\Users\tm\Downloads\TFC.exe Gelöscht : C:\Windows\grep.exe Gelöscht : C:\Windows\PEV.exe Gelöscht : C:\Windows\NIRCMD.exe Gelöscht : C:\Windows\MBR.exe Gelöscht : C:\Windows\SED.exe Gelöscht : C:\Windows\SWREG.exe Gelöscht : C:\Windows\SWSC.exe Gelöscht : C:\Windows\SWXCACLS.exe Gelöscht : C:\Windows\Zip.exe Gelöscht : HKLM\SOFTWARE\OldTimer Tools Gelöscht : HKLM\SOFTWARE\AdwCleaner Gelöscht : HKLM\SOFTWARE\Swearware Gelöscht : HKLM\SOFTWARE\TrendMicro\Hijackthis Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hijackthis Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\HijackThis.exe ~ Erstelle ein Backup der Registrierungsdatenbank ... OK ~ Lösche die Wiederherstellungspunkte ... Gelöscht : RP #1262 [ComboFix created restore point | 07/20/2014 21:12:37] Gelöscht : RP #1264 [Windows Update | 07/26/2014 18:54:29] Gelöscht : RP #1265 [Windows Update | 07/27/2014 08:21:44] Gelöscht : RP #1266 [Windows Update | 07/27/2014 08:29:16] Gelöscht : RP #1267 [Windows-Sicherung | 07/27/2014 17:00:35] Ein neuer Wiederherstellungspunkt wurde erstellt ! ~ Stelle die Systemeinstellungen wieder her ... OK ########## - EOF - ########## - gehe nun über zu deinen tipps zur absicherung |
Im WIndows Explorer, dort ist links oben ein Ordner Downloads. Ich frage mich wie Du FRST gestartet hast wenn Du nicht weißt wo der Download Ordner ist..... |
- viel schneller ist mein Rechner leider nicht geworden, das Hauptproblem ist, dass google chrome alle 5 Minuten abstürzt, inzwischen nicht mehr auszuhalten! Habe es gelöscht und wieder drauf, aber keine Besserung! Vor Wochen hatte es aber funktioniert; was tun? - Mozilla tuts schon lange nicht; konnte zudem nicht gelöscht werden: Systemsteuerung-Programme-deinstallieren- nix tut sich - seit etlichen Monaten zeigt MS Vista an, das die Arbeitsspeicher voll sei und geleert werden sollte; wie geht das? bis bald Dieter |
Revo Uninstaller - Download - Filepony damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.google.com/chrome/answer/3296214?hl=de Ist Chrome nun besser? |
- habe beide Schritte ausgeführt, aber noch immer stürzt chrome ab - ms word braucht öfters ganze 60sek um zu öffnen, oder ist blockiert; furchtbar - es erscheint seit vielen Wochen -Arbeitsspeicher ist voll-! ist das wirklich der Fall? wie kann ich sie denn leeren? ein plug-in (shockwave-flash) funktioniert nicht-plug.in anhalten - ist eben erschienen, schon öfters |
Alle Zeitangaben in WEZ +1. Es ist jetzt 11:59 Uhr. |
Copyright ©2000-2025, Trojaner-Board