Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   WinVista: Trojaner-Alarm und Umleitung auf Werbung (https://www.trojaner-board.de/158083-winvista-trojaner-alarm-umleitung-werbung.html)

PapasPC 28.08.2014 22:57

WinVista: Trojaner-Alarm und Umleitung auf Werbung
 
Hallo liebes Trojaner-Board Team!

Ich sitze hier am Laptop meines Vaters, der mich am Ende seiones PC-Lateins um Hilfe bat. Sein Avira hatte wohl "Trojaner gemeldet", auch nachdem er einen USB-Stick insteckte. Außerdem wird Firefox auf Werbeseiten weitergeleitet und öfter poppen einfach Firefoxseiten auf. Beim vorletzten Avira-Scan gab es nen BSoD. Ich habe ihm einen meiner Norton Produktschlüsel gegeben, aber er konnte Norton nicht installieren. Auch der Norton Service hat es über Ferninstallation nicht geschafft Norton zum Laufen zu bringen.

Das hört sich doch interessant an, nicht wahr? :wtf:

Hier also erstmal die LogFiles im Anhang (waren zu viele Zeichen):

Ansonsten habe ich erstmal nichts unternommen.
Schon jetzt ein Herzliches Dankeschön von mir und meinem Vater! :dankeschoen:

LG,
Björn

smeenk 28.08.2014 23:34

:hallo:

Ich bin smeenk und ich werde versuchen dir zu helfen :)

Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
  • Bitte deaktiviere während des Scans alle Virenscanner, da sie das Ergebnis beeinflussen
  • Starte Zoek.exe mit einem Doppelklick.
  • Achtung: Das folgende Skript wurde nur für diesen speziellen Fall geschrieben und könnte andere Computer beschädigen.
  • Kopiere den Text der folgenden Box in das Skriptfenster von Zoek:
    Code:

    firefoxlook;
    filesrcm;
    installedprogs;
    C:\Windows\Tasks\Re-markit_wd.job;f
    {BFC3629B-CFB1-4029-A527-5ABE0092BB9A};c
    emptyalltemp;
    C:\Program Files\mozilla firefox\browser\searchplugins\awesomehp.xml;f
    C:\Users\Rolf\AppData\Local\Google\Chrome\User Data\Default\preferences;f
    resetieproxy;
    C:\Program Files\Re-markit-soft;fs
    C:\PROGRA~1\SupTab;fs
    services-list;
    chromelook;
    startupall;

  • Nun klicke auf "Run script" und sei geduldig bis das Skript durchläuft.
  • Wenn das Tool fertig ist wird sich Notepad mit dem Logfile öffnen (ggf. erst nach einem Neustart). Das Log befindet sich aber auch noch unter c:
  • Bitte poste mir das ZOEK-Log (möglichst in CODE-Tags - #-Symbol im Antwortfenster klicken)

PapasPC 29.08.2014 10:07

Hi smeenk!

Und schon jetzt erstmal vielen Dank!
Hier das Zoek Log:
Code:

Zoek.exe v5.0.0.0 Updated 28-08-2014
Tool run by Rolf on 29.08.2014 at  9:17:48,84.
Microsoft® Windows Vista™ Home Premium  6.0.6002 Service Pack 2 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Rolf\Documents\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

29.08.2014 09:21:48 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2050912381-1346219871-470563689-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BFC3629B-CFB1-4029-A527-5ABE0092BB9A} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Installed Programs ======================

32 Bit HP CIO Components Installer 
AAC Decoder 
Ace Stream Media 2.1.7.1 
Adobe Acrobat X Pro - English, Fran‡ais, Deutsch 
Adobe AIR 
Adobe Color Common Settings 
Adobe Creative Suite 6 Master Collection 
Adobe ExtendScript Toolkit 2 
Adobe Flash Player 14 Plugin 
Adobe Flash Player ActiveX 
Adobe Help Manager 
Adobe Reader 9.5.5 - Deutsch 
Adobe Setup 
Adobe Shockwave Player 11 
Adobe Widget Browser 
Apple Application Support 
Apple Mobile Device Support 
Apple Software Update 
AutoUpdate 
Avira 
Avira Free Antivirus 
awesomehp uninstaller 
bl 
Bonjour 
BufferChm 
Compatibility Pack fr 2007 Office System 
Content Transfer 
ConvertHelper 2.2 
Copy 
Corel MediaOne 
CorelDRAW Essential Edition 3 
CustomerResearchQFolder 
CyberLink MediaShow 
CyberLink PhotoNow 
CyberLink PowerDirector 
CyberLink PowerDVD 
CyberLink PowerProducer 
CyberLink YouCam 
DE 
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition 
Destination Component 
DeviceDiscovery 
DeviceManagementQFolder 
DivX Codec 
DivX Converter 
DivX Player 
DivX Plus DirectShow Filters 
DivX Version Checker 
DivX Web Player 
DJ_AIO_03_F4200_ProductContext 
DJ_AIO_03_F4200_Software 
DJ_AIO_03_F4200_Software_Min 
DMUninstaller 
Dolby Control Center 
DVD-Video-Zusatz-Software 
e-W”rterbcher 
eSupportQFolder 
F4200 
F4200_Help 
FormatFactory 3.3.2.0 
Google Chrome 
Google Earth 
Google Update Helper 
GPBaseService 
H.264 Decoder 
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) 
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) 
HP Customer Participation Program 10.0 
HP Deskjet F4200 All-In-One Driver Software 10.0 Rel .3 
HP Imaging Device Functions 10.0 
HP LJ300-400 color MFP M375-M475 
HP LJ300-400 color MFP M375-M475 Fax 
HP LJ300-400 M375-M475 HP Scan 
HP Photosmart Essential 2.5 
HP Product FWUpdater 
HP Smart Web Printing 4.60 
HP Solution Center 10.0 
HP Unified IO 
HP Update 
hpbDSService 
hpbM375M475DSService 
HPDiagnosticAlert 
HPLaserJet300-400ColorM375-M475Series_HelpLearnCenter_SI 
HPLJUTCore 
HPLJUTM375-M475 
hppFaxDrvM375M475 
hppLaserJetService 
hppM375_M475LaserJetService 
HPProductAssistant 
hppSendFaxM375M475 
hppToolboxProxyM375 
HPSSupply 
hpStatusAlerts 
hpStatusAlertsM375_M475 
IBM SPSS Statistics 21 
iCloud 
InstanceFinder 
iTunes 
Java 7 Update 67 
Java Auto Updater 
Java(TM) 6 Update 35 
Java(TM) 6 Update 7 
JustCloud 
LG PC Suite 
LG United Mobile Drivers 
MakeDisc 
MarketResearch 
McAfee Security Scan Plus 
Microsoft - Speichern als PDF oder XPS - Add-In fr 2007 Microsoft Office-Programme 
Microsoft .NET Framework 3.5 Language Pack SP1 - deu 
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU 
Microsoft .NET Framework 3.5 SP1 
Microsoft .NET Framework 4.5.1 
Microsoft .NET Framework 4.5.1 (DEU) 
Microsoft .NET Framework 4.5.1 (Deutsch) 
Microsoft Office 2007 Service Pack 3 (SP3) 
Microsoft Office Access MUI (German) 2010 
Microsoft Office Excel MUI (German) 2010 
Microsoft Office Groove MUI (German) 2010 
Microsoft Office InfoPath MUI (German) 2010 
Microsoft Office OneNote MUI (German) 2010 
Microsoft Office Outlook MUI (German) 2010 
Microsoft Office PowerPoint MUI (German) 2010 
Microsoft Office Professional Plus 2010 
Microsoft Office Project 2007 Service Pack 3 (SP3) 
Microsoft Office Project MUI (German) 2007 
Microsoft Office Project Professional 2007 
Microsoft Office Proof (English) 2007 
Microsoft Office Proof (English) 2010 
Microsoft Office Proof (French) 2007 
Microsoft Office Proof (French) 2010 
Microsoft Office Proof (German) 2007 
Microsoft Office Proof (German) 2010 
Microsoft Office Proof (Italian) 2007 
Microsoft Office Proof (Italian) 2010 
Microsoft Office Proofing (German) 2007 
Microsoft Office Proofing (German) 2010 
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) 
Microsoft Office Publisher MUI (German) 2010 
Microsoft Office Shared MUI (German) 2007 
Microsoft Office Shared MUI (German) 2010 
Microsoft Office Visio 2007 Service Pack 3 (SP3) 
Microsoft Office Visio MUI (German) 2007 
Microsoft Office Visio Professional 2007 
Microsoft Office Word MUI (German) 2010 
Microsoft Silverlight 
Microsoft SQL Server 2005 Compact Edition [DEU] 
Microsoft SQL Server 2005 Compact Edition [ENU] 
Microsoft Visual C++ 2005 Redistributable 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 
Microsoft_VC80_CRT_x86 
Microsoft_VC90_CRT_x86 
Microsoft_VC90_MFC_x86 
Microsoft_VC90_MFCLOC_x86 
MKV Splitter 
Mozilla Firefox 31.0 (x86 de) 
Mozilla Maintenance Service 
MSXML 4.0 SP2 (KB936181) 
MSXML 4.0 SP2 (KB941833) 
MSXML 4.0 SP2 (KB954430) 
MSXML 4.0 SP2 (KB973688) 
MSXML 4.0 SP3 Parser 
MSXML 4.0 SP3 Parser (KB2721691) 
MSXML 4.0 SP3 Parser (KB2758694) 
MSXML 4.0 SP3 Parser (KB973685) 
Nero 8 Essentials 
neroxml 
Nokia Connectivity Cable Driver 
NVIDIA Drivers 
NWZ-E440 WALKMAN Guide 
OVT Scanner X86 
PC-Bibliothek 
PDF Settings CS6 
PDFCreator 
ph 
PlayMemories Home 
PMB-Aktualisierungsprogramm 
PSSWCORE 
QuickTime 7 
Re-markit 
RealPlayer 
Realtek High Definition Audio Driver 
Realtek USB 2.0 Card Reader 
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) 
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) 
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629) 
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2861697) 
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869) 
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126) 
Security Update for Microsoft .NET Framework 4.5.1 (KB2931368) 
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596804) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2760415) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2817330) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2878233) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2880507) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2880508) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2881069) 32-Bit Edition 
Security Update for Microsoft Office 2010 (KB2553284) 32-Bit Edition 
Security Update for Microsoft Office 2010 (KB2687423) 32-Bit Edition 
Security Update for Microsoft Office 2010 (KB2760781) 32-Bit Edition 
Security Update for Microsoft Office 2010 (KB2810073) 32-Bit Edition 
Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition 
Security Update for Microsoft Office 2010 (KB2880971) 32-Bit Edition 
Security Update for Microsoft Office 2010 (KB2881071) 32-Bit Edition 
Security Update for Microsoft Office Visio 2007 suites (KB2596595) 32-Bit Edition 
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition 
Shockwave Director 11.0 
Shop for HP Supplies 
SketchUp Pro 8 
SkypeT 6.16 
SmartWebPrinting 
SolutionCenter 
SopCast 3.8.3 
Status 
Synaptics Pointing Device Driver 
TeamViewer 8 
Toolbox 
ToolboxProxy 
TrayApp 
Uninstall OVT Scanner 
UnloadSupport 
Update for 2007 Microsoft Office System (KB967642) 
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) 
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition 
Update for Microsoft Excel 2010 (KB2837600) 32-Bit Edition 
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition 
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition 
Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition 
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition 
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition 
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition 
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition 
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition 
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition 
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition 
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition 
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition 
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition 
Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition 
Update Manager 
VC80CRTRedist - 8.0.50727.4053 
VCRedistSetup 
VideoToolkit01 
VLC media player 2.0.1 
VO Package 
WebReg 
Winamp 
Windows Live Anmelde-Assistent 
Windows Live Fotogalerie 
Windows Live installer 
Windows Live Mail 
Windows Live Messenger 
Windows Live Writer 
Windows Media Player Firefox Plugin 
WinZip 
X10 Hardware(TM) 

==== Services (whitelist) ======================
Powered by E Dev

R2 - [AdobeARMservice] - Adobe Acrobat Update Service - "C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe"
R2 - [AntiVirSchedulerService] - Avira Planer - "C:\Program Files\Avira\AntiVir Desktop\sched.exe"
R2 - [AntiVirService] - Avira Echtzeit-Scanner - "C:\Program Files\Avira\AntiVir Desktop\avguard.exe"
R2 - [Apple Mobile Device] - Apple Mobile Device - "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
R2 - [Avira.OE.ServiceHost] - Avira Service Host - "C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe"
R2 - [Bonjour Service] - Dienst "Bonjour" - "C:\Program Files\Bonjour\mDNSResponder.exe"
R2 - [HP LaserJet Service] - HP LaserJet Service - "C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe"
R2 - [nvsvc] - NVIDIA Display Driver Service - C:\Windows\system32\nvvsvc.exe
R2 - [PMBDeviceInfoProvider] - PMBDeviceInfoProvider - "C:\Program Files\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe"
R2 - [slsvc] - Softwarelizenzierung - C:\Windows\system32\SLsvc.exe
R2 - [TeamViewer8] - TeamViewer 8 - "C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe"
R2 - [WSearch] - Windows Search - C:\Windows\system32\SearchIndexer.exe /Embedding
R3 - [ehRecvr] - Windows Media Center-Empfängerdienst - C:\Windows\ehome\ehRecvr.exe
R3 - [ehSched] - Windows Media Center-Planerdienst - C:\Windows\ehome\ehsched.exe
R3 - [iPod Service] - iPod-Dienst - "C:\Program Files\iPod\bin\iPodService.exe"
R3 - [VSS] - Volumeschattenkopie - C:\Windows\system32\vssvc.exe
R3 - [WMPNetworkSvc] - Windows Media Player-Netzwerkfreigabedienst - "C:\Program Files\Windows Media Player\wmpnetwk.exe"
R3 - [WPFFontCache_v0400] - Windows Presentation Foundation Font Cache 4.0.0.0 - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
S2 - [clr_optimization_v4.0.30319_32] - Microsoft .NET Framework NGEN v4.0.30319_X86 - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 - [gupdate1ca7c0d7f601a40] - Google Update Service (gupdate1ca7c0d7f601a40) - "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc
S2 - [SkypeUpdate] - Skype Updater - "C:\Program Files\Skype\Updater\Updater.exe"
S3 - [AdobeFlashPlayerUpdateSvc] - Adobe Flash Player Update Service - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
S3 - [ALG] - Gatewaydienst auf Anwendungsebene - C:\Windows\System32\alg.exe
S3 - [COMSysApp] - COM+-Systemanwendung - C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
S3 - [DFSR] - DFS-Replikation - C:\Windows\system32\DFSR.exe
S3 - [FontCache3.0.0.0] - Windows Presentation Foundation-Schriftartcache 3.0.0.0 - C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
S3 - [gupdatem] - Google Update-Dienst (gupdatem) - "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc
S3 - [HP DS Service] - HP DS Service - "C:\Program Files\HP\HPBDSService\HPBDSService.exe"
S3 - [McComponentHostService] - McAfee Security Scan Component Host Service - "C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe"
S3 - [Microsoft SharePoint Workspace Audit Service] - Microsoft SharePoint Workspace Audit Service - "C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" /auditservice
S3 - [MozillaMaintenance] - Mozilla Maintenance Service - "C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe"
S3 - [MSDTC] - Distributed Transaction Coordinator - C:\Windows\System32\msdtc.exe
S3 - [msiserver] - Windows Installer - C:\Windows\system32\msiexec /V
S3 - [odserv] - Microsoft Office Diagnostics Service - "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE"
S3 - [ose] - Office  Source Engine - "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
S3 - [osppsvc] - Office Software Protection Platform - "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
S3 - [RpcLocator] - RPC-Locator - C:\Windows\system32\locator.exe
S3 - [SNMPTRAP] - SNMP-Trap - C:\Windows\System32\snmptrap.exe
S3 - [SwitchBoard] - SwitchBoard - "C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
S3 - [TrustedInstaller] - Windows Modules Installer - C:\Windows\servicing\TrustedInstaller.exe
S3 - [vds] - Virtueller Datenträger - C:\Windows\System32\vds.exe
S3 - [WLSetupSvc] - Windows Live Setup Service - "C:\Program Files\Windows Live\installer\WLSetupSvc.exe"
S3 - [wmiApSrv] - WMI-Leistungsadapter - C:\Windows\system32\wbem\WmiApSrv.exe
S4 - [ACDaemon] - ArcSoft Connect Daemon - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
S4 - [aspnet_state] - ASP.NET-Zustandsdienst - C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
S4 - [clr_optimization_v2.0.50727_32] - Microsoft .NET Framework NGEN v2.0.50727_X86 - C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
S4 - [Nero BackItUp Scheduler 3] - Nero BackItUp Scheduler 3 - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
S4 - [NMIndexingService] - NMIndexingService - "C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe"
S4 - [PLFlash DeviceIoControl Service] - PLFlash DeviceIoControl Service - C:\Windows\system32\IoctlSvc.exe
S4 - [ProtexisLicensing] - ProtexisLicensing - C:\Windows\system32\PSIService.exe
S4 - [RichVideo] - Cyberlink RichVideo Service(CRVS) - "C:\Program Files\CyberLink\Shared Files\RichVideo.exe"
S4 - [usnjsvc] - Messenger USN Journal Reader-Service für freigegebene Ordner - "C:\Program Files\Windows Live\Messenger\usnsvc.exe"

==== Deleting Files \ Folders ======================

C:\PROGRA~1\SupTab not found
"C:\Windows\Tasks\Re-markit_wd.job" deleted
"C:\Program Files\mozilla firefox\browser\searchplugins\awesomehp.xml" deleted
"C:\Users\Rolf\AppData\Local\Google\Chrome\User Data\Default\preferences" deleted
"C:\Program Files\Re-markit-soft\Re-markit_wd.exe" deleted
"C:\Program Files\Re-markit-soft" deleted

==== Files Recently Created / Modified ======================

====== C:\Windows ====
====== C:\Users\Rolf\AppData\Local\Temp ====
2014-08-16 07:45:41        A35F4433F3F927D2C736C16412BEDD1F        49744        ----a-w-        C:\Users\Gast\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
====== Java Cache =====
2014-08-23 07:32:35        E8C80BF60938EE72EE77AB866EA40E2B        282048        ----a-w-        C:\Users\Rolf\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\7e60542d-38ea16aa
2014-08-23 07:32:31        0B23B3044AE9E02DCE26DB4D5E007252        848        ----a-w-        C:\Users\Rolf\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\31b19ba-5e4e965b
2014-08-23 07:32:34        0B23B3044AE9E02DCE26DB4D5E007252        848        ----a-w-        C:\Users\Rolf\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\2bbaaf87-45468192
2014-08-23 07:32:34        C69B1D0FE7AE45E790808D20071A5958        107        ----a-w-        C:\Users\Rolf\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\2bbaaf87-e2e4c8970372d2fb4193a7ef29d16f6c3f08527947fcb9208b3a0e48820369fd-6.0.lap
====== C:\Windows\system32 =====
2014-08-29 06:14:28        9852A1B92487147563D83B638F1E8D37        297984        ----a-w-        C:\Windows\System32\gdi32.dll
2014-08-29 06:14:28        7350631241943D434C9DF900C079D8F7        2054656        ----a-w-        C:\Windows\System32\win32k.sys
2014-08-23 06:57:21        07EF2978A5BC36720378F95566697FD8        272808        ----a-w-        C:\Windows\System32\javaws.exe
2014-08-23 06:56:42        49E203776C2ACB289385168A9058EE9E        96680        ----a-w-        C:\Windows\System32\WindowsAccessBridge.dll
2014-08-23 06:56:42        3BDEB17FE6390BFF1BF3A2D964DE8E48        175528        ----a-w-        C:\Windows\System32\javaw.exe
2014-08-23 06:56:42        11FD45A41DF45298686ED39062AABE2A        175528        ----a-w-        C:\Windows\System32\java.exe
2014-08-15 09:05:06        A86F5EEC0ACEC16906532F2B1A7C00B6        8856        ----a-w-        C:\Windows\System32\icardres.dll
2014-08-15 09:05:06        667A4DAAD3AA57B1051484BAC057CF7C        619664        ----a-w-        C:\Windows\System32\icardagt.exe
2014-08-15 09:05:06        3662E6500C477AC0DFAECE4CF7B163B8        99480        ----a-w-        C:\Windows\System32\infocardapi.dll
2014-08-15 09:04:52        E66A29C118DE2FE3E5766E5C7A2E8E2B        35480        ----a-w-        C:\Windows\System32\TsWpfWrp.exe
====== C:\Windows\system32\drivers =====
2014-08-14 13:03:40        5C2C209CDEFBC51D83D66E8A53B2BE89        638400        ----a-w-        C:\Windows\System32\drivers\dxgkrnl.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-08-09 10:50:05        --------        d-----w-        C:\Program Files\iPod
2014-08-09 10:49:37        --------        d-----w-        C:\Program Files\iTunes
======= C: =====
====== C:\Users\Rolf\AppData\Roaming ======
2014-08-16 20:04:29        6F42C277F85B4EC3F58C96792D3D2713        524780        ----a-w-        C:\Windows\serviceprofiles\Localservice\AppData\Local\WPFFontCache_v0400-S-1-5-21-2050912381-1346219871-470563689-501-8192.dat
2014-08-16 07:43:13        --------        d-----w-        C:\Users\Gast\AppData\Local\Google
2014-08-10 16:41:57        10664C1AE9E52A08641C403D22EDCBED        524780        ----a-w-        C:\Windows\serviceprofiles\Localservice\AppData\Local\WPFFontCache_v0400-S-1-5-21-2050912381-1346219871-470563689-1002-8192.dat
2014-08-08 17:16:21        B344215A26CBB0EF2D96BEDBEC55F4C0        524780        ----a-w-        C:\Windows\serviceprofiles\Localservice\AppData\Local\WPFFontCache_v0400-S-1-5-21-2050912381-1346219871-470563689-1000-8192.dat
====== C:\Users\Rolf ======
2014-08-28 10:25:01        D41D8CD98F00B204E9800998ECF8427E        0        ----a-w-        C:\Users\Rolf\defogger_reenable
2014-08-09 10:51:46        --------        d-----w-        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-08-09 10:49:38        --------        d-----w-        C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-08-08 05:42:11        --------        d-----w-        C:\ProgramData\Package Cache
2014-08-05 09:08:36        --------        d-----w-        C:\Users\Rolf\Datenverstoss

====== C: exe-files ==
2014-08-23 06:56:30        F67D9621616CB31217A497FEDE4913F5        16296        ----a-w-        C:\Program Files\Java\jre7\bin\pack200.exe
2014-08-23 06:56:30        CEEFA72555A8FAD52C29BA17AE3E6DEF        16296        ----a-w-        C:\Program Files\Java\jre7\bin\servertool.exe
2014-08-23 06:56:30        C3F55C9B02A22EC0B345E20AE9AE9B71        16296        ----a-w-        C:\Program Files\Java\jre7\bin\klist.exe
2014-08-23 06:56:30        A788E5ED0454307CBCFB95CC33E5F717        16808        ----a-w-        C:\Program Files\Java\jre7\bin\orbd.exe
2014-08-23 06:56:30        A6B7A388547C4CDF4D8F2AF55D79AC85        145832        ----a-w-        C:\Program Files\Java\jre7\bin\unpack200.exe
2014-08-23 06:56:30        8B986C008892DB58928BC72483ADF7B9        16808        ----a-w-        C:\Program Files\Java\jre7\bin\tnameserv.exe
2014-08-23 06:56:30        7ED5C21F9F29B5278FFF39718C667235        16296        ----a-w-        C:\Program Files\Java\jre7\bin\ktab.exe
2014-08-23 06:56:30        7DC9A0127F850997B4CFD9923C680D7D        16296        ----a-w-        C:\Program Files\Java\jre7\bin\keytool.exe
2014-08-23 06:56:30        7BDCC29DDFBB355761A018A74D4A1E8C        16296        ----a-w-        C:\Program Files\Java\jre7\bin\rmiregistry.exe
2014-08-23 06:56:30        7A17013ABD895DFBD61A5AF9996D0E5E        50088        ----a-w-        C:\Program Files\Java\jre7\bin\ssvagent.exe
2014-08-23 06:56:30        48442596BFEB26E56898A0E4D2596A95        16296        ----a-w-        C:\Program Files\Java\jre7\bin\policytool.exe
2014-08-23 06:56:30        34CEC403ED594B55D55DED61A3A53DAF        16296        ----a-w-        C:\Program Files\Java\jre7\bin\rmid.exe
2014-08-23 06:56:30        0371CFD6228F89B5B9E20F67807987FE        16296        ----a-w-        C:\Program Files\Java\jre7\bin\kinit.exe
2014-08-23 06:56:29        F69D8BDC202973592D710BC913D01919        48040        ----a-w-        C:\Program Files\Java\jre7\bin\jabswitch.exe
2014-08-23 06:56:29        EC4C47AADE6606AFCDEAB28E29654ECE        75688        ----a-w-        C:\Program Files\Java\jre7\bin\jp2launcher.exe
2014-08-23 06:56:29        C8883F91C31CAC40890AC8B668E05F61        16296        ----a-w-        C:\Program Files\Java\jre7\bin\java-rmi.exe
2014-08-23 06:56:29        BF918C9473D64BBD53C22C47045883F5        182696        ----a-w-        C:\Program Files\Java\jre7\bin\jqs.exe
2014-08-23 06:56:29        8B657BA869AE7D3C6A29792C986E0DD5        68008        ----a-w-        C:\Program Files\Java\jre7\bin\javacpl.exe
2014-08-23 06:56:29        3BDEB17FE6390BFF1BF3A2D964DE8E48        175528        ----a-w-        C:\Program Files\Java\jre7\bin\javaw.exe
2014-08-23 06:56:29        11FD45A41DF45298686ED39062AABE2A        175528        ----a-w-        C:\Program Files\Java\jre7\bin\java.exe
2014-08-23 06:56:29        07EF2978A5BC36720378F95566697FD8        272808        ----a-w-        C:\Program Files\Java\jre7\bin\javaws.exe
2014-08-23 06:43:57        65D82D98BDE731750CD407D1103AC2C5        755832        ------w-        C:\ProgramData\Package Cache\{e67154a7-9cc5-4167-b782-f3982bc6c70d}\Avira.OE.Setup.Bundle.exe
=== C: other files ==
2014-08-28 15:10:53        9E3104392AAA41E9F3688A18A25E4DF1        904        ----a-w-        C:\Users\Rolf\AppData\Local\Temp\0x800705AA_7e7a698d6e205bf1682b6ce86e3e78dd6b537b05.zip
2014-08-23 06:56:30        F3EABF8A2AF5C0D8BAE022EE6C17FD91        18650        ----a-w-        C:\Program Files\Java\jre7\lib\deploy\ffjcext.zip

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter"
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter"
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem"

[HKEY_USERS\S-1-5-21-2050912381-1346219871-470563689-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe"
"Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun"
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe"
"OfficeSyncProcess"="C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"UpdatePDRShortCut"="C:\Program Files\HomeCinema\PowerDirector\MUITransfer\MUIStartMenu.exe C:\Program Files\HomeCinema\PowerDirector UpdateWithCreateOnce Software\CyberLink\PowerDirector\7.0"
"RtHDVCpl"="RtHDVCpl.exe"
"Skytel"="Skytel.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit"
"avgnt"="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe /min"
"HP LJ300-400 color MFP M375-M475 Series Fax"="C:\Program Files\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe HP LJ300-400 color MFP M375-M475 Series Fax"
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices"
"AdobeAAMUpdater-1.0"="C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"SwitchBoard"="C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
"AdobeCS6ServiceManager"="C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe -launchedbylogin"
"Adobe Acrobat Speed Launcher"="C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"APSDaemon"="C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe -atboottime"
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"Avira Systray"="C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe"
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices"
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
"RemoteControl"="C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe"
"StatusAlerts"="C:\Program Files\HP\StatusAlerts\bin\HPStatusAlerts.exe /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on"
"Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe"
"Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun"
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe"
"OfficeSyncProcess"="C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"Appinit_Dlls"="C:\\PROGRA~1\\SupTab\\SEARCH~1.DLL"

==== Startup Registry Disabled ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Acrobat Assistant 8.0]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Acrobat Assistant 8.0"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Adobe\\Acrobat 8.0\\Acrobat\\Acrotray.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe_ID0EYTHM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Adobe_ID0EYTHM"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\ADOBEV~1\\Server\\bin\\VERSIO~2.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AppleSyncNotifier]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AppleSyncNotifier"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\AppleSyncNotifier.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="APSDaemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ContentTransferWMDetector.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ContentTransferWMDetector.exe"
"hkey"="HKLM"
"command"="C:\\Program Files\\Sony\\Content Transfer\\ContentTransferWMDetector.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GrooveMonitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GrooveMonitor"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Common Files\\Nero\\Lib\\NMIndexStoreSvr.exe\" ASO-616B5711-6DAE-4795-A05F-39A1E5104020"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ISUSPM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ISUSPM"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\ISUSPM.exe\" -scheduler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LanguageShortcut]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LanguageShortcut"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\HomeCinema\\PowerDVD\\Language\\Language.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NBKeyScan]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NBKeyScan"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Nero\\Nero8\\Nero BackItUp\\NBKeyScan.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Norton Download Manager{NIS_prod_1.6.18_18.6.0.29}]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Norton Download Manager{NIS_prod_1.6.18_18.6.0.29}"
"hkey"="HKCU"
"command"="C:\\Users\\Public\\Downloads\\Norton\\{NIS_prod_1.6.18_18.6.0.29}\\NISDownloader (1).exe /m"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NortonSupport]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NortonSupport"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Norton Internet Security\\Engine\\19.1.0.28\\symerr.exe\" /supportreboot"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PMBVolumeWatcher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PMBVolumeWatcher"
"hkey"="HKLM"
"command"="C:\\Program Files\\Sony\\PlayMemories Home\\PMBVolumeWatcher.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="QuickTime Task"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TkBellExe"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\toolbar_eula_launcher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="toolbar_eula_launcher"
"hkey"="HKLM"
"command"="C:\\Program Files\\GoogleEULA\\EULALauncher.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UCam_Menu]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UCam_Menu"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\HomeCinema\\YouCam\\MUITransfer\\MUIStartMenu.exe\" \"C:\\Program Files\\HomeCinema\\YouCam\" UpdateWithCreateOnce \"Software\\CyberLink\\YouCam\\2.0\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdatePPShortCut]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UpdatePPShortCut"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\HomeCinema\\PowerProducer\\MUITransfer\\MUIStartMenu.exe\" \"C:\\Program Files\\HomeCinema\\PowerProducer\" update \"Software\\CyberLink\\PowerProducer\\5.0\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinampAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WinampAgent"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Winamp\\winampa.exe\""


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\McAfee Security Scan Plus.lnk"
"backup"="C:\\Windows\\pss\\McAfee Security Scan Plus.lnk.CommonStartup"
"backupExtension"=".CommonStartup"
"command"="C:\\PROGRA~1\\MCAFEE~1\\309042~1.318\\SSSCHE~1.EXE "
"item"="McAfee Security Scan Plus"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\WinZip Quick Pick.lnk"
"backup"="C:\\Windows\\pss\\WinZip Quick Pick.lnk.CommonStartup"
"backupExtension"=".CommonStartup"
"command"="C:\\PROGRA~1\\WinZip\\WZQKPICK.EXE "
"item"="WinZip Quick Pick"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Rolf^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office Groove.lnk]
"path"="C:\\Users\\Rolf\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Microsoft Office Groove.lnk"
"backup"="C:\\Windows\\pss\\Microsoft Office Groove.lnk.Startup"
"backupExtension"=".Startup"
"command"="C:\\PROGRA~1\\MI1933~1\\Office12\\GROOVE.EXE -background"
"item"="Microsoft Office Groove"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BackupStack]


==== Startup Folders ======================

2010-06-08 14:10:11        1161        ----a-w-        C:\Users\Gabi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
2013-04-13 11:37:18        1149        ----a-w-        C:\Users\Gabi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
2014-04-18 09:23:20        1923        ----a-w-        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [09.07.2014 11:20]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [13.12.2009 18:00]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [13.12.2009 18:00]
C:\Windows\tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job --ah----- C:\Windows\system32\msfeedssync.exe [24.07.2014 19:48]

==== Other Scheduled Tasks ======================

"C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\system32\tasks\AdobeAAMUpdater-1.0-Rolf-PC-Rolf" [C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\HPLJCustParticipation" ["C:\Program Files\HP\HPLJUT\HPLJUTSCH.exe"]
"C:\Windows\system32\tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}" [C:\Windows\system32\msfeedssync.exe]
"C:\Windows\system32\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files\Apple Software Update\SoftwareUpdate.exe]
"C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"web2pdfextension@web2pdf.adobedotcom"="C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn" [02.06.2014 14:49]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" [04.04.2014 12:36]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Gabi\AppData\Roaming\Mozilla\Firefox\Profiles\m8yv1nzb.default
- MediaPlayerEnhance - %ProfilePath%\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com
- Deutsches Wrterbuch - %ProfilePath%\extensions\de-DE@dictionaries.addons.mozilla.org
- British English Dictionary - %ProfilePath%\extensions\en-GB@dictionaries.addons.mozilla.org
- Pocket - %ProfilePath%\extensions\isreaditlater@ideashower.com
- Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
- PDF Download - %ProfilePath%\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
- Fire.fm - %ProfilePath%\extensions\{6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}
- DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
- SearchPreview - %ProfilePath%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
- YouTube to MP3 - %ProfilePath%\extensions\youtube2mp3@mondayx.de.xpi
- Flagfox - %ProfilePath%\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- Download Statusbar - %ProfilePath%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
- Extended Statusbar - %ProfilePath%\extensions\{daf44bf7-a45e-4450-979c-91cf07434c3d}.xpi

ProfilePath: C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\9fe330nl.default
- Undetermined - C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
- Undetermined - %ProfilePath%\extensions\staged-xpis
- Undetermined - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

ProfilePath: C:\Users\Rolf\AppData\Roaming\Mozilla\Firefox\Profiles\8908hkg2.default
- TS Magic Player - C:\Users\Rolf\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org
- Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
- Avira Browser Safety - %ProfilePath%\extensions\abs@avira.com
- Deutsches Wrterbuch - %ProfilePath%\extensions\de-DE@dictionaries.addons.mozilla.org
- British English Dictionary - %ProfilePath%\extensions\en-GB@dictionaries.addons.mozilla.org
- Pocket - %ProfilePath%\extensions\isreaditlater@ideashower.com
- Undetermined - %ProfilePath%\extensions\staged
- YouTube to MP3 ConverterDownload YouTube to MP4 - %ProfilePath%\extensions\YoutubeToMp3@wontube.com
- Fire.fm - %ProfilePath%\extensions\{6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}
- WOT - %ProfilePath%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
- DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
- SearchPreview - %ProfilePath%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
- Ghostery - %ProfilePath%\extensions\firefox@ghostery.com.xpi
- Youtube To MP3 PRO converter - %ProfilePath%\extensions\jid0-irAmugmQgdURBSCIFZAcjR8ZQMg@jetpack.xpi
- YouTube to MP3 - %ProfilePath%\extensions\youtube2mp3@mondayx.de.xpi
- YouTube to MP3 ConverterDownload YouTube to MP4 - %ProfilePath%\extensions\YoutubeToMp3@wontube.com.xpi
- Flagfox - %ProfilePath%\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- BetterPrivacy - %ProfilePath%\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
- Download Statusbar - %ProfilePath%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
- Extended Statusbar - %ProfilePath%\extensions\{daf44bf7-a45e-4450-979c-91cf07434c3d}.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Rolf\AppData\Roaming\Mozilla\Firefox\Profiles\8908hkg2.default
9EE20E6E2E3F94714D44F739B9A228F4        - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_179.dll -        Shockwave Flash
14D06C3796CE3F6BA8F43CDF3AD65D76        - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll -        Java(TM) Platform SE 7 U67
0A6E5E3BEF374AA2F47071E7374EAD7B        - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll -        Java Deployment Toolkit 7.0.670.1
FB5621842FDABF9F8359775573498FBC        - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll -        Google Update
893BF7D2261C56C24F813405D9D018E0        - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.1.0.30716.0.dll -        Silverlight Plug-In
893BF7D2261C56C24F813405D9D018E0        - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll -        Silverlight Plug-In
1E5E8C84DE796A01D1D46E3A660690F1        - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll -        Adobe Acrobat
E30C13DE5E2B96341BD1B0691A9AFB32        - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll -        QuickTime Plug-in 7.7.5
4310CAACD0FF0506C55389F04ED6049F        - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll -        QuickTime Plug-in 7.7.5
08EF980C9444262DB84C5106BCCA990C        - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll -        QuickTime Plug-in 7.7.5
0E56A9CBF2B73E1C3186094C108690CA        - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll -        QuickTime Plug-in 7.7.5
E972DDCDBEFDED34BCB7B2D1035883E5        - C:\Program Files\QuickTime\Plugins\npqtplugin.dll -        QuickTime Plug-in 7.7.5
B5371D2C9017EEE216B5361D600B3543        - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll -        iTunes Application Detector
C694F47FB5870679B9C0D8D4BE97556B        - C:\Users\Rolf\AppData\Roaming\ACEStream\player\npace_plugin.dll -        Ace Stream P2P Multimedia Plug-in
5B92CB0A3EEE50F6B9AE036B4F9B0F0C        - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll -        Google Earth Plugin
AE84791D996D1F05A2446B0C447D937A        - C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll -        Adobe Acrobat
AE84791D996D1F05A2446B0C447D937A        - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll -        Adobe Acrobat
F00DA1A135FCA11D4426D9A5AB72CF0F        - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll -        AdobeAAMDetect
1F8FFDE82C52353906244AFDC6BAF2AB        - C:\Program Files\VideoLAN\VLC\npvlc.dll -        VLC Web Plugin
DD33975DCFE8C020C07F6707F81A1D12        - c:\program files\real\realplayer\Netscape6\nprjplug.dll -        RealJukebox NS Plugin
65FB4909BD29CAAA81FDC69AD21BB905        - c:\program files\real\realplayer\Netscape6\nppl3260.dll -        RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)
01F0264937036BD962563F1ADF35CE72        - c:\program files\real\realplayer\Netscape6\nprpjplug.dll -        RealPlayer Version Plugin
E93467C5327C2760FCAB2B4670847496        - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll -        DivX Player Netscape Plugin
1DE714BB4BB48B10BC94FF84C9BC6471        - C:\Program Files\DivX\DivX Web Player\npdivx32.dll -        DivX Web Player
AB87EEFFD18F2BAAFC274E7075EA6C67        - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll -        Windows Presentation Foundation / Windows Presentation Foundation
ACEF2CBC1032BC14D112EB4494537DA5        - C:\Windows\system32\Adobe\Director\np32dsw.dll -        Shockwave for Director / Shockwave for Director
8DA2ED6B04EA33F2EAE8BA883F903729        - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll -        Microsoft® Silverlight
41561B8AE9E551BD08304D48DAA900FA        - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll -        AdobeAAMDetect


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
bopakagnckmlgajfccecajhnimjiiedh - No path found[]
flliilndjeohchalpbbcdekjklbdgfkk - No path found[]
pelmeidfhdlhlbjimpabfcbnnojbboma - C:\Users\Rolf\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx[18.03.2014 02:56]

Google Wallet - Rolf\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
undetermined - Rolf\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx

==== Chromium Startpages ======================

C:\Users\Gabi\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "hxxp://www.google.com",


==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-2050912381-1346219871-470563689-1000\Software\Mozilla\Firefox\Extensions\{9cf78b6e-ee8e-4c00-b8aa-b2fd1da84db4} deleted successfully

==== Reset IE Proxy ======================

Value(s) before fix:
"ProxyServer"="http=127.0.0.1:13828"
"ProxyOverride.Bonjour"=""
"ProxyEnable"=dword:00000000

Value(s) after fix:
"ProxyOverride.Bonjour"=""
"ProxyEnable"=dword:00000000

==== Empty IE Cache ======================

C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Gabi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Gabi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Gabi\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Rolf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Rolf\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Rolf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50MVPF30 will be deleted at reboot
C:\Users\Rolf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Gabi\AppData\Local\Mozilla\Firefox\Profiles\m8yv1nzb.default\Cache emptied successfully
C:\Users\Gast\AppData\Local\Mozilla\Firefox\Profiles\9fe330nl.default\Cache emptied successfully
C:\Users\Rolf\AppData\Local\Mozilla\Firefox\Profiles\8908hkg2.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Gabi\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Rolf\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=16 folders=1 1500652 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Gabi\AppData\Local\Temp emptied successfully
C:\Users\Gast\AppData\Local\Temp emptied successfully
C:\Users\Rolf\AppData\Local\Temp will be emptied at reboot
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Rolf\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Rolf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\ehmsdri.log" not deleted
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\ehRecvr.log" not deleted
"C:\Users\Rolf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50MVPF30" not found

==== EOF on 29.08.2014 at 11:01:12,11 ======================

Awaiting your commands... :applaus:

LG,
Björn

smeenk 29.08.2014 12:13

Hallo Björn

Wir entfernen noch einige Überreste :)

  • Bitte deaktiviere während des Scans alle Virenscanner, da sie das Ergebnis beeinflussen
  • Starte Zoek.exe mit einem Doppelklick.
  • Achtung: Das folgende Skript wurde nur für diesen speziellen Fall geschrieben und könnte andere Computer beschädigen.
  • Kopiere den Text der folgenden Box in das Skriptfenster von Zoek:
    Code:

    emptyfolderscheck;delete
    awesomehp uninstaller;u
    shortcutfix;
    VO Package;u
    resetieproxy;
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BackupStack];r
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows];r
    "Appinit_Dlls"=-;r
    Re-markit;u
    emptyclsid;

  • Nun klicke auf "Run script" und sei geduldig bis das Skript durchläuft.
  • Wenn das Tool fertig ist wird sich Notepad mit dem Logfile öffnen (ggf. erst nach einem Neustart). Das Log befindet sich aber auch noch unter c:
  • Bitte poste mir das ZOEK-Log (möglichst in CODE-Tags - #-Symbol im Antwortfenster klicken)


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

PapasPC 29.08.2014 16:17

So, hier die Logfiles.

Nochmal Zoek:
Code:

Zoek.exe v5.0.0.0 Updated 28-08-2014
Tool run by Rolf on 29.08.2014 at 13:24:04,66.
Microsoft® Windows Vista™ Home Premium  6.0.6002 Service Pack 2 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Rolf\Documents\Downloads\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2014-08-29-090112.log        50901 bytes

==== Empty Folders Check ======================

C:\Program Files\Hewlett-Packard deleted successfully
C:\Users\Rolf\AppData\Local\LogMeIn Rescue Applet deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2050912381-1346219871-470563689-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7E853D72-626A-48EC-A868-BA8D5E23E045} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{9d81af43-de53-48d0-a199-42c2a226b24c} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BackupStack]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"Appinit_Dlls"=-

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"web2pdfextension@web2pdf.adobedotcom"="C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn" [02.06.2014 14:49]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" [04.04.2014 12:36]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Gabi\AppData\Roaming\Mozilla\Firefox\Profiles\m8yv1nzb.default
- MediaPlayerEnhance - %ProfilePath%\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com
- Deutsches Wrterbuch - %ProfilePath%\extensions\de-DE@dictionaries.addons.mozilla.org
- British English Dictionary - %ProfilePath%\extensions\en-GB@dictionaries.addons.mozilla.org
- Pocket - %ProfilePath%\extensions\isreaditlater@ideashower.com
- Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
- PDF Download - %ProfilePath%\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
- Fire.fm - %ProfilePath%\extensions\{6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}
- DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
- SearchPreview - %ProfilePath%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
- YouTube to MP3 - %ProfilePath%\extensions\youtube2mp3@mondayx.de.xpi
- Flagfox - %ProfilePath%\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- Download Statusbar - %ProfilePath%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
- Extended Statusbar - %ProfilePath%\extensions\{daf44bf7-a45e-4450-979c-91cf07434c3d}.xpi

ProfilePath: C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\9fe330nl.default
- Undetermined - C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
- Undetermined - %ProfilePath%\extensions\staged-xpis
- Undetermined - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

ProfilePath: C:\Users\Rolf\AppData\Roaming\Mozilla\Firefox\Profiles\8908hkg2.default
- TS Magic Player - C:\Users\Rolf\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org
- Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
- Avira Browser Safety - %ProfilePath%\extensions\abs@avira.com
- Deutsches Wrterbuch - %ProfilePath%\extensions\de-DE@dictionaries.addons.mozilla.org
- British English Dictionary - %ProfilePath%\extensions\en-GB@dictionaries.addons.mozilla.org
- Pocket - %ProfilePath%\extensions\isreaditlater@ideashower.com
- Undetermined - %ProfilePath%\extensions\staged
- YouTube to MP3 ConverterDownload YouTube to MP4 - %ProfilePath%\extensions\YoutubeToMp3@wontube.com
- Fire.fm - %ProfilePath%\extensions\{6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}
- WOT - %ProfilePath%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
- DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
- SearchPreview - %ProfilePath%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
- Ghostery - %ProfilePath%\extensions\firefox@ghostery.com.xpi
- Youtube To MP3 PRO converter - %ProfilePath%\extensions\jid0-irAmugmQgdURBSCIFZAcjR8ZQMg@jetpack.xpi
- YouTube to MP3 - %ProfilePath%\extensions\youtube2mp3@mondayx.de.xpi
- YouTube to MP3 ConverterDownload YouTube to MP4 - %ProfilePath%\extensions\YoutubeToMp3@wontube.com.xpi
- Flagfox - %ProfilePath%\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- BetterPrivacy - %ProfilePath%\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
- Download Statusbar - %ProfilePath%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
- Extended Statusbar - %ProfilePath%\extensions\{daf44bf7-a45e-4450-979c-91cf07434c3d}.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Rolf\AppData\Roaming\Mozilla\Firefox\Profiles\8908hkg2.default
9EE20E6E2E3F94714D44F739B9A228F4        - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_179.dll -        Shockwave Flash
14D06C3796CE3F6BA8F43CDF3AD65D76        - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll -        Java(TM) Platform SE 7 U67
0A6E5E3BEF374AA2F47071E7374EAD7B        - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll -        Java Deployment Toolkit 7.0.670.1
FB5621842FDABF9F8359775573498FBC        - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll -        Google Update
893BF7D2261C56C24F813405D9D018E0        - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.1.0.30716.0.dll -        Silverlight Plug-In
893BF7D2261C56C24F813405D9D018E0        - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll -        Silverlight Plug-In
1E5E8C84DE796A01D1D46E3A660690F1        - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll -        Adobe Acrobat
E30C13DE5E2B96341BD1B0691A9AFB32        - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll -        QuickTime Plug-in 7.7.5
4310CAACD0FF0506C55389F04ED6049F        - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll -        QuickTime Plug-in 7.7.5
08EF980C9444262DB84C5106BCCA990C        - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll -        QuickTime Plug-in 7.7.5
0E56A9CBF2B73E1C3186094C108690CA        - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll -        QuickTime Plug-in 7.7.5
E972DDCDBEFDED34BCB7B2D1035883E5        - C:\Program Files\QuickTime\Plugins\npqtplugin.dll -        QuickTime Plug-in 7.7.5
B5371D2C9017EEE216B5361D600B3543        - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll -        iTunes Application Detector
C694F47FB5870679B9C0D8D4BE97556B        - C:\Users\Rolf\AppData\Roaming\ACEStream\player\npace_plugin.dll -        Ace Stream P2P Multimedia Plug-in
5B92CB0A3EEE50F6B9AE036B4F9B0F0C        - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll -        Google Earth Plugin
AE84791D996D1F05A2446B0C447D937A        - C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll -        Adobe Acrobat
AE84791D996D1F05A2446B0C447D937A        - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll -        Adobe Acrobat
F00DA1A135FCA11D4426D9A5AB72CF0F        - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll -        AdobeAAMDetect
1F8FFDE82C52353906244AFDC6BAF2AB        - C:\Program Files\VideoLAN\VLC\npvlc.dll -        VLC Web Plugin
DD33975DCFE8C020C07F6707F81A1D12        - c:\program files\real\realplayer\Netscape6\nprjplug.dll -        RealJukebox NS Plugin
65FB4909BD29CAAA81FDC69AD21BB905        - c:\program files\real\realplayer\Netscape6\nppl3260.dll -        RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)
01F0264937036BD962563F1ADF35CE72        - c:\program files\real\realplayer\Netscape6\nprpjplug.dll -        RealPlayer Version Plugin
E93467C5327C2760FCAB2B4670847496        - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll -        DivX Player Netscape Plugin
1DE714BB4BB48B10BC94FF84C9BC6471        - C:\Program Files\DivX\DivX Web Player\npdivx32.dll -        DivX Web Player
AB87EEFFD18F2BAAFC274E7075EA6C67        - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll -        Windows Presentation Foundation / Windows Presentation Foundation
ACEF2CBC1032BC14D112EB4494537DA5        - C:\Windows\system32\Adobe\Director\np32dsw.dll -        Shockwave for Director / Shockwave for Director
8DA2ED6B04EA33F2EAE8BA883F903729        - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll -        Microsoft® Silverlight
41561B8AE9E551BD08304D48DAA900FA        - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll -        AdobeAAMDetect


==== shortcuts on Users Desktops ======================

C:\Users\Gabi\Desktop\SopCast.lnk - C:\Program Files\SopCast\SopCast.exe
C:\Users\Gast\Desktop\SopCast.lnk - C:\Program Files\SopCast\SopCast.exe
C:\Users\Rolf\Desktop\Ace Player.lnk - C:\Users\Rolf\AppData\Roaming\ACEStream\player\ace_player.exe
C:\Users\Rolf\Desktop\Bluetooth-Geräte - Verknüpfung.lnk - 
C:\Users\Rolf\Desktop\e-Wörterbücher.lnk - 
C:\Users\Rolf\Desktop\Format Factory.lnk - C:\Program Files\FreeTime\FormatFactory\FormatFactory.exe
C:\Users\Rolf\Desktop\Microsoft Outlook 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\outicon.exe
C:\Users\Rolf\Desktop\Norton Download Manager.lnk - C:\Users\Public\Downloads\Norton\{NIS_prod_1.6.18_18.6.0.29}\NISDownloader (1).exe
C:\Users\Rolf\Desktop\Norton-Installationsdateien.lnk - C:\Users\Public\Downloads\Norton\{NIS_prod_1.6.18_18.6.0.29}
C:\Users\Rolf\Desktop\PC-Bibliothek 2.0.lnk - C:\PC-BIB\pc_bib2.exe
C:\Users\Rolf\Desktop\SopCast.lnk - C:\Program Files\SopCast\SopCast.exe
C:\Users\Rolf\Desktop\Sync Folder.lnk - C:\Program Files\JustCloud\JustCloud.exe opensync

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat.exe
C:\Users\Public\Desktop\Adobe Application Manager.lnk - C:\Program Files\Common Files\Adobe\OOBE\PDApp\core\PDapp.exe --appletID=CCM_UI --appletVersion=1.0 --workflow=CCM_workflow_launch
C:\Users\Public\Desktop\Adobe Reader 9.lnk - C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe
C:\Users\Public\Desktop\Avira Control Center.lnk - C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
C:\Users\Public\Desktop\Avira.lnk - C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe /showMiniGui
C:\Users\Public\Desktop\Content Transfer.lnk - C:\Program Files\Sony\Content Transfer\ContentTransfer.exe
C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Public\Desktop\Google Earth.lnk - C:\Program Files\Google\Google Earth\client\googleearth.exe
C:\Users\Public\Desktop\HP LJ300-400 color MFP M375-M475 - Hilfe- und Lern-Center.lnk - C:\Program Files\HP\HP LJ300-400 color M375-M475\Help_Learn\Help.exe
C:\Users\Public\Desktop\HP LJ300-400 M375-M475 Scan.lnk - C:\Program Files\HP\HP LJ300-400 color MFP M375-M475\Bin\HPScan.exe
C:\Users\Public\Desktop\HP Photosmart Essential 2.5.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe
C:\Users\Public\Desktop\iTunes.lnk - C:\Program Files\iTunes\iTunes.exe
C:\Users\Public\Desktop\LayOut 3.lnk - C:\Program Files\Google\Google SketchUp 8\LayOut\LayOut.exe
C:\Users\Public\Desktop\LG PC Suite.Lnk - C:\Program Files\LG Electronics\LG PC Suite\LGPCSuite.exe
C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\McUICnt.exe SecurityScanner.dll
C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk - C:\Program Files\Nero\Nero8\Nero StartSmart\NeroStartSmart.exe -ScParameter=65 
C:\Users\Public\Desktop\PlayMemories Home.lnk - C:\Program Files\Sony\PlayMemories Home\PMBBrowser.exe
C:\Users\Public\Desktop\SketchUp 8.lnk - C:\Program Files\Google\Google SketchUp 8\SketchUp.exe
C:\Users\Public\Desktop\Style Builder 2.lnk - C:\Program Files\Google\Google SketchUp 8\Style Builder\Style Builder.exe
C:\Users\Public\Desktop\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe
C:\Users\Public\Desktop\VLC media player.lnk - C:\Program Files\VideoLAN\VLC\vlc.exe

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\My Avira\Avira.lnk - C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe /showMiniGui
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\iTunes.lnk - C:\Program Files\iTunes\iTunes.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\Über iTunes.lnk - 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk - C:\Program Files\Java\jre7\bin\javacpl.exe -tab about
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk - C:\Program Files\Java\jre7\bin\javacpl.exe -tab update
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk - C:\Program Files\Java\jre7\bin\javacpl.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk - 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.lnk - 

==== shortcuts in Quick Launch ======================

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - 
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - 
C:\Users\Gabi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Adobe Acrobat 8 Professional.lnk - 
C:\Users\Gabi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Gabi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Excel 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\xlicons.exe
C:\Users\Gabi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\outicon.exe
C:\Users\Gabi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Word 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\wordicon.exe
C:\Users\Gabi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Gabi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 
C:\Users\Gabi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - 
C:\Users\Gast\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Gast\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 
C:\Users\Gast\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - 
C:\Users\Rolf\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Adobe Acrobat 8 Professional.lnk - 
C:\Users\Rolf\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Rolf\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Excel 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\xlicons.exe
C:\Users\Rolf\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\outicon.exe
C:\Users\Rolf\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Word 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\wordicon.exe
C:\Users\Rolf\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Rolf\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart Essentials.lnk - C:\Program Files\Nero\Nero8\Nero StartSmart\NeroStartSmart.exe -ScParameter=65 
C:\Users\Rolf\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 

==== Reset IE Proxy ======================

Value(s) before fix:
"ProxyOverride.Bonjour"=""
"ProxyEnable"=dword:00000000

Value(s) after fix:
"ProxyOverride.Bonjour"=""
"ProxyEnable"=dword:00000000

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\awesomehp uninstaller deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\c657f8f0-597a-49b4-9835-e252fa248185 deleted successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=16 folders=1 1500652 bytes)

==== EOF on 29.08.2014 at 13:46:41,80 ======================


Und dann noch AdwCleaner:
Code:

# AdwCleaner v3.308 - Bericht erstellt am 29/08/2014 um 14:41:57
# Aktualisiert 20/08/2014 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzername : Rolf - ROLF-PC
# Gestartet von : C:\Users\Rolf\Documents\Downloads\adwcleaner_3.308.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\Program Files\Uninstaller
Ordner Gelöscht : C:\Users\Rolf\AppData\Local\Tuguu_SL
Ordner Gelöscht : C:\Users\Gabi\AppData\Roaming\Mozilla\Firefox\Profiles\m8yv1nzb.default\Extensions\isreaditlater@ideashower.com
Ordner Gelöscht : C:\Users\Rolf\AppData\Roaming\Mozilla\Firefox\Profiles\8908hkg2.default\Extensions\isreaditlater@ideashower.com
Ordner Gelöscht : C:\Users\Rolf\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcpfhaghaadpjpgocojgnlhjcieeooel
Ordner Gelöscht : C:\Users\Rolf\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm
Ordner Gelöscht : C:\Users\Rolf\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
Datei Gelöscht : C:\Users\Rolf\Desktop\Sync Folder.lnk
Datei Gelöscht : C:\Users\Rolf\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx
Datei Gelöscht : C:\Users\Rolf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Rolf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal

***** [ Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Schlüssel Gelöscht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Re_Markit
Schlüssel Gelöscht : HKLM\SOFTWARE\awesomehpSoftware
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DMUninstaller
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\awesomehp uninstaller
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DMUninstaller
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\VOPackage

***** [ Browser ] *****

-\\ Internet Explorer v9.0.8112.16563


-\\ Mozilla Firefox v31.0 (x86 de)

[ Datei : C:\Users\Gabi\AppData\Roaming\Mozilla\Firefox\Profiles\m8yv1nzb.default\prefs.js ]

Zeile gelöscht : user_pref("extensions.a0c822a17a68f40669257d229458d21ca9c178d17dc614aafb2da1425ac7300accom44150.44150.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "145742ba6e27cf25dc3d7c10e5db7f00");

[ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\9fe330nl.default\prefs.js ]


[ Datei : C:\Users\Rolf\AppData\Roaming\Mozilla\Firefox\Profiles\8908hkg2.default\prefs.js ]

Zeile gelöscht : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
Zeile gelöscht : user_pref("extensions.quick_start.enable_search1", false);
Zeile gelöscht : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);

-\\ Google Chrome v36.0.1985.143

[ Datei : C:\Users\Gabi\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [61227 octets] - [19/03/2014 15:01:52]
AdwCleaner[R1].txt - [4472 octets] - [29/08/2014 14:09:34]
AdwCleaner[S0].txt - [59803 octets] - [19/03/2014 15:15:20]
AdwCleaner[S1].txt - [4097 octets] - [29/08/2014 14:41:57]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4157 octets] ##########

Ich fahre jetzt zu ner Hochzeit, also stress Dich nicht mit diesem Thread hier. Falls wir tatsächlich bereits am Ende der Bereinigung sein sollten, sag bitte noch wie wir uns für Deine Hilfe erkenntlich zeigen können.

LG,
Björn

smeenk 30.08.2014 07:58

Merkst Du momentan noch einige Probleme?

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

PapasPC 31.08.2014 19:34

Hallo smeenk,

da Björn zu einer Hochzeit gefahren ist, antworte ich heute (Vater) mal. Hier ist der Inhalt des Textdokuments.

Results of screen317's Security Check version 0.99.87
Windows Vista Service Pack 2 x86
Internet Explorer 9
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 67
Java(TM) 6 Update 35
Java(TM) 6 Update 7
Adobe Flash Player 14.0.0.179
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox (31.0)
Google Chrome 36.0.1985.125
Google Chrome 36.0.1985.143
````````Process Check: objlist.exe by Laurent````````
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````


Falls nun alles OK sein sollte, teile uns bitte noch mit, wie wir uns für Deine Hilfe erkenntlich zeigen können.

LG Rolf :dankeschoen:

Guten Moorgen smeenk.
Ich habe gestern Abend folgende Meldung erhalten:

Echtzeit-Scanner
Es wurde ein Virus oder unerwünschtes Programm gefunden!
Funde
Objekt Fund Aktion
zoek.exe HEUR/APC (Cloud) In Charantäne verschieben

Diese Aktion habe ich dann durchgeführt.

Ansonsten habe ich keine Probleme feststellen können oder Werbung erhalten.

Gruß, Rolf

Moin, bin zurück. Sorry für vergessene Code-tags. Die Zoek.exe-Meldung war natürlich false positive.
Sieht ganz gut aus, oder?

LG,
Björn

smeenk 01.09.2014 22:32

Hallo Björn und Rolf :)

Sieht gut aus :daumenhoc

Zoek.exe wird öfter falsch angezeigt.

Mach mal diese Check: https://www.mozilla.org/de/plugincheck/‎
Veraltete Plugins aktualisieren lassen.

Zur Kontrolle erneut SecurityCheck drehen und mir der Log posten.

Grüße
Smeenk

PapasPC 02.09.2014 11:21

Hallo smeenk,

die Plugins wurden aktualisiert und ein paar entfernt. Hier ist der Logfile des erneuten Security Checks:

Code:


 Results of screen317's Security Check version 0.99.87 
 Windows Vista Service Pack 2 x86 
 Internet Explorer 9 
 Internet Explorer 8 
``````````````Antivirus/Firewall Check:``````````````
Avira Desktop 
 Antivirus up to date! 
`````````Anti-malware/Other Utilities Check:`````````
 Java 7 Update 67 
 Java(TM) 6 Update 35 
 Java(TM) 6 Update 7 
 Adobe Flash Player    14.0.0.179 
 Adobe Reader 9 Adobe Reader out of Date!
 Mozilla Firefox (31.0)
 Google Chrome 36.0.1985.125 
 Google Chrome 36.0.1985.143 
````````Process Check: objlist.exe by Laurent```````` 
 Avira Antivir avgnt.exe
 Avira Antivir avguard.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````

Vielen Dank und eine schöne Woche!

Gruß

Rolf

smeenk 04.09.2014 21:16

Meiner Meinung nach sind wir Fertig :)

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :)

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Damit wünsche ich dir noch viel Spaß beim Surfen im Internet :daumenhoc

... und vielleicht möchtest du ja das Trojaner-Board unterstützen?

Grüße
Smeenk


Alle Zeitangaben in WEZ +1. Es ist jetzt 11:13 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19