![]() |
Windows 7 : Webseiten sind von werbe adds besetzt und werden ständig zu pop ups umgeleitet hxxp://aph.startofferfb.com/flv/de/index.html?sid=2338&dv1=ad2329-de&kw1=ad2329-de-lm&uuid=f46e86f8-f5c1-4768-7685-ef6deabf334e hxxp://offers.bycontext.com/scjs/tb/ctxjs/index.php?kw2=www.ard.de&affid=1151&subaff_id=726_22597&intformat=roll&nextpage=http%3A%2F%2Fwww.ard.de%2Fhome%2Fard%2FARD_Startseite%2F21920%2Findex. html&ch=10742&sbrand=DigiCoupon&folder=v6.1&typrd=ootd&cu=34590&country=DE&original_country= hxxp://datingportalonline.com/de/quiz/lp/1/ hxxp://albumsuper.info/passthrough?url=G8g89J3%2F8 einige Adressen der Webseiten ! |
hi, . Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
scan durchgeführt- hallo Schrauber habe den scan durchgeführt , konnte aber mit dem Thread keine Aktionen durchführen. habe deshalb auf konventionelle weise Infos kopiiert Gruß, Gropius FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015 |
Lade Dir bitte von hier ![]()
Scan mit Combofix
|
Revo Uninstaller und combofix durchgeführt Code: ComboFix 15-03-23.01 - Hirsch 22.03.2015 22:38:11.1.4 - x64 |
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Aktionen durchgeführt Hallo Schrauber, habe sämtliche Aktionen durchgeführt, incl. farbar scan : ww.malwarebytes.org Protection, 23.03.2015 19:46:41, SYSTEM, HIRSCH-PC, Protection, Malware Protection, Starting, Protection, 23.03.2015 19:46:41, SYSTEM, HIRSCH-PC, Protection, Malware Protection, Started, Protection, 23.03.2015 19:46:41, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Starting, Protection, 23.03.2015 19:46:41, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Started, Update, 23.03.2015 19:47:01, SYSTEM, HIRSCH-PC, Manual, Malware Database, 2015.3.9.5, 2015.3.23.6, Protection, 23.03.2015 19:47:01, SYSTEM, HIRSCH-PC, Protection, Refresh, Starting, Protection, 23.03.2015 19:47:01, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Stopping, Protection, 23.03.2015 19:47:01, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Stopped, Protection, 23.03.2015 19:47:05, SYSTEM, HIRSCH-PC, Protection, Refresh, Success, Protection, 23.03.2015 19:47:05, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Starting, Protection, 23.03.2015 19:47:05, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Started, Detection, 23.03.2015 19:50:14, SYSTEM, HIRSCH-PC, Protection, Malwareschutz, Datei, PUP.Optional.Multiplug, C:\Program Files (x86)\textenhance\textenhance.dll, Quarantine Failed, 5, Zugriff verweigert , [b33fde6ac9c155e1335c3fefe121df21] Scan, 23.03.2015 20:00:06, SYSTEM, HIRSCH-PC, Manual, Start: 23.03.2015 19:47:07, Dauer: 8 Minuten 15 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, "16" nicht-Malwareerkennung, Protection, 23.03.2015 20:02:02, SYSTEM, HIRSCH-PC, Protection, Malware Protection, Starting, Protection, 23.03.2015 20:02:02, SYSTEM, HIRSCH-PC, Protection, Malware Protection, Started, Protection, 23.03.2015 20:02:02, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Starting, Protection, 23.03.2015 20:02:05, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Started, (end) Code:
www.malwarebytes.org Protection, 23.03.2015 19:46:41, SYSTEM, HIRSCH-PC, Protection, Malware Protection, Starting, Protection, 23.03.2015 19:46:41, SYSTEM, HIRSCH-PC, Protection, Malware Protection, Started, Protection, 23.03.2015 19:46:41, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Starting, Protection, 23.03.2015 19:46:41, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Started, Update, 23.03.2015 19:47:01, SYSTEM, HIRSCH-PC, Manual, Malware Database, 2015.3.9.5, 2015.3.23.6, Protection, 23.03.2015 19:47:01, SYSTEM, HIRSCH-PC, Protection, Refresh, Starting, Protection, 23.03.2015 19:47:01, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Stopping, Protection, 23.03.2015 19:47:01, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Stopped, Protection, 23.03.2015 19:47:05, SYSTEM, HIRSCH-PC, Protection, Refresh, Success, Protection, 23.03.2015 19:47:05, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Starting, Protection, 23.03.2015 19:47:05, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Started, Detection, 23.03.2015 19:50:14, SYSTEM, HIRSCH-PC, Protection, Malwareschutz, Datei, PUP.Optional.Multiplug, C:\Program Files (x86)\textenhance\textenhance.dll, Quarantine Failed, 5, Zugriff verweigert , [b33fde6ac9c155e1335c3fefe121df21] Scan, 23.03.2015 20:00:06, SYSTEM, HIRSCH-PC, Manual, Start: 23.03.2015 19:47:07, Dauer: 8 Minuten 15 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, "16" nicht-Malwareerkennung, Protection, 23.03.2015 20:02:02, SYSTEM, HIRSCH-PC, Protection, Malware Protection, Starting, Protection, 23.03.2015 20:02:02, SYSTEM, HIRSCH-PC, Protection, Malware Protection, Started, Protection, 23.03.2015 20:02:02, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Starting, Protection, 23.03.2015 20:02:05, SYSTEM, HIRSCH-PC, Protection, Malicious Website Protection, Started, (end)AdwCleaner Logfile: Code: # AdwCleaner v4.113 - Bericht erstellt 23/03/2015 um 20:16:47 Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015 Ran by Hirsch at 2015-03-23 20:34:49 Running from C:\Users\Hirsch\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A} AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 3Dconnexion 3DxSoftware (HKLM-x32\...\{BAFCA6AC-8B37-405B-B57E-C1D45DE70ACC}) (Version: 3.7.18 - 3Dconnexion) 3Dconnexion 3DxWare (x64) (Version: 6.07.0013 - 3Dconnexion) Hidden 3Dconnexion Add-In for AutoCAD 2007 (x32 Version: 4.4.1 - 3Dconnexion) Hidden 3Dconnexion Add-In for AutoCAD 2008 (x32 Version: 4.4.1 - 3Dconnexion) Hidden 3Dconnexion Add-In for AutoCAD 2008 (x64) (Version: 4.4.1 - 3Dconnexion) Hidden 3Dconnexion Add-In for AutoCAD 2009 (x32 Version: 4.4.1 - 3Dconnexion) Hidden 3Dconnexion Add-In for AutoCAD 2009 (x64) (Version: 4.4.1 - 3Dconnexion) Hidden 3Dconnexion Add-In for AutoCAD 2010 (x32 Version: 4.4.2 - 3Dconnexion) Hidden 3Dconnexion Add-In for AutoCAD 2010 (x64) (Version: 4.4.2 - 3Dconnexion) Hidden 3Dconnexion Add-In for Inventor (x32 Version: 1.6.1 - 3Dconnexion) Hidden 3Dconnexion Add-In for Inventor (x64) (Version: 1.6.1 - 3Dconnexion) Hidden 3Dconnexion Add-In for Solid Edge (x32 Version: 2.15.0 - 3Dconnexion) Hidden 3Dconnexion Add-In for Solid Edge (x64) (Version: 2.15.0 - 3Dconnexion) Hidden 3Dconnexion Add-In for SolidWorks (x32 Version: 2.14.2 - 3Dconnexion) Hidden 3Dconnexion Add-In for SolidWorks (x64) (Version: 2.14.2 - 3Dconnexion) Hidden 3Dconnexion Add-On for XSI (x32 Version: 2.4.0 - 3Dconnexion) Hidden 3Dconnexion Add-On for XSI (x64) (Version: 2.4.0 - 3Dconnexion) Hidden 3Dconnexion Extension for SketchUp (x32 Version: 2.1.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for 3ds Max 2008 (x32 Version: 4.8.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for 3ds Max 2008 (x64) (Version: 4.8.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for 3ds Max 2009 (x32 Version: 4.8.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for 3ds Max 2009 (x64) (Version: 4.8.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for 3ds Max 2010 (x32 Version: 4.8.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for 3ds Max 2010 (x64) (Version: 4.8.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for 3ds max 6 - 8 (x32 Version: 4.8.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for 3ds Max 9 (x32 Version: 4.8.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for 3ds Max 9 (x64) (Version: 4.8.1 - 3Dconnexion) Hidden 3Dconnexion Plug-in for Acrobat 3D (x32 Version: 1.0.6.495 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Maya 2008 (x32 Version: 3.7.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Maya 2008 (x64) (Version: 3.7.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Maya 2009 (x32 Version: 3.7.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Maya 2009 (x64) (Version: 3.7.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Maya 6 (x32 Version: 3.7.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Maya 6.5 (x32 Version: 3.7.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Maya 7 (x32 Version: 3.7.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Maya 8 (x32 Version: 3.7.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Maya 8 (x64) (Version: 3.7.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Maya 8.5 (x32 Version: 3.7.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Maya 8.5 (x64) (Version: 3.7.1 - 3Dconnexion) Hidden 3Dconnexion Plug-In for NX 3.0 (x32 Version: 2.6.0 - 3Dconnexion) Hidden 3Dconnexion Plug-In for NX 4.0 (x32 Version: 2.6.0 - 3Dconnexion) Hidden 3Dconnexion Plug-In for NX 4.0 (x64) (Version: 2.6.0 - 3Dconnexion) Hidden 3Dconnexion Plug-In for NX 5.0 (x32 Version: 2.6.0 - 3Dconnexion) Hidden 3Dconnexion Plug-In for NX 5.0 (x64) (Version: 2.6.0 - 3Dconnexion) Hidden 3Dconnexion Plug-In for NX 6.0 (x32 Version: 2.6.0 - 3Dconnexion) Hidden 3Dconnexion Plug-In for NX 6.0 (x64) (Version: 2.6.0 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Photoshop CS2 (x32 Version: 1.2.8 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Photoshop CS3 (x32 Version: 2.0.6.3897 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Photoshop CS4 (x32 Version: 2.0.9.4200 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Photoshop CS4 (x64) (Version: 2.1.0 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Pro/ENGINEER WF2 (x32 Version: 1.6.0 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Pro/ENGINEER WF3 (x32 Version: 1.6.0 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Pro/ENGINEER WF3 (x64) (Version: 1.6.0 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Pro/ENGINEER WF4 (x32 Version: 1.6.0 - 3Dconnexion) Hidden 3Dconnexion Plug-In for Pro/ENGINEER WF4 (x64) (Version: 1.6.0 - 3Dconnexion) Hidden 3Dconnexion Plug-in for QuickTime VR (x32 Version: 1.1.10 - 3Dconnexion) Hidden 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) ABBYY FineReader 9.0 Sprint (HKLM-x32\...\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY) ABBYY FineReader 9.0 Sprint (x32 Version: 9.01.513.58212 - ABBYY) Hidden Adblock Plus für IE (32-Bit- und 64-Bit) (HKLM\...\{E407C8D7-09C6-4056-BFAD-68C5FD8340F0}) (Version: 1.3 - Eyeo GmbH) Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Photoshop 7.0 (HKLM-x32\...\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Apple Application Support (HKLM-x32\...\{A83279FD-CA4B-4206-9535-90974DE76654}) (Version: 2.1.5 - Apple Inc.) AudioCatalyst (HKLM-x32\...\AudioCatalyst) (Version: - ) Audiograbber 1.83 SE (HKLM-x32\...\Audiograbber) (Version: 1.83 SE - Audiograbber Deutschland) AutoCAD 2011 - Deutsch (HKLM\...\AutoCAD 2011 - Deutsch) (Version: 18.1.49.0 - Autodesk) AutoCAD 2011 - Deutsch (Version: 18.1.49.0 - Autodesk) Hidden AutoCAD 2011 Language Pack - Deutsch (Version: 18.1.49.0 - Autodesk) Hidden AutoCAD Mechanical 2011 Language Pack - Deutsch (Version: 15.0.46.0 - Autodesk) Hidden Autodesk Design Review 2011 (HKLM-x32\...\Autodesk Design Review 2011) (Version: 11.0.0.86 - Autodesk, Inc.) Autodesk Design Review 2011 (x32 Version: 11.0.0.86 - Autodesk, Inc.) Hidden Autodesk Inventor Content Center Libraries 2011 (Desktop Content) (HKLM\...\{7244B345-B413-408B-9D04-F55BE1CC93FA}) (Version: 15.0.0000.23900 - Autodesk, Inc.) Autodesk Inventor Professional 2011 (Version: 15.0.0000.23900 - Autodesk) Hidden Autodesk Inventor Professional 2011 Deutsch (HKLM\...\Autodesk Inventor Professional 2011) (Version: 15.0.0000.23900 - Autodesk) Autodesk Inventor Professional 2011 Language Pack - Deutsch (Version: 15.0.0000.23900 - Autodesk) Hidden Autodesk Material Library 2011 (HKLM-x32\...\{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}) (Version: 2.0.0.100 - Autodesk) Autodesk Material Library 2011 Base Image library (HKLM-x32\...\{CD1E078C-A6B9-47DA-B035-6365C85C7832}) (Version: 2.0.0.49 - Autodesk) Autodesk Material Library 2011 Medium Image library (HKLM-x32\...\{975951E7-14D0-49AF-A630-89680D12D7F6}) (Version: 2.0.0.49 - Autodesk) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Browser 7 der Telekom (HKLM-x32\...\Browser 7 der Telekom 22.18 (x86 de)) (Version: 22.18 - Deutsche Telekom AG) Browser 7 Maintenance Service (HKLM-x32\...\Browser7MaintenanceService) (Version: 22.18 - Deutsche Telekom AG) Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.3.5.0 - Canon Inc.) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: - ) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.3.8.2523 - CDBurnerXP) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP) Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.55 - Cliqz.com) DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation) Druckerdeinstallation für EPSON PX820FWD Series (HKLM\...\EPSON PX820FWD Series) (Version: - SEIKO EPSON Corporation) DWG TrueView 2011 (HKLM\...\DWG TrueView 2011) (Version: 18.1.49.0 - Autodesk) DWG TrueView 2011 (Version: 18.1.49.0 - Autodesk) Hidden EPSON Advanced Printer Driver 4 (HKLM-x32\...\{11FF6AF6-0141-4EF8-829A-989459A1E5D8}) (Version: 4.56.0000 - SEIKO EPSON CORPORATION) EPSON APD4 Point and Print Support (x32 Version: 4.56.0000 - SEIKO EPSON CORPORATION) Hidden Epson Easy Photo Print 2 (HKLM-x32\...\{310C1558-F6B5-4889-98B0-7471966BA7F2}) (Version: 2.2.3.0 - SEIKO EPSON CORPORATION) Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION) Epson Event Manager (HKLM-x32\...\{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}) (Version: 2.40.0001 - SEIKO EPSON CORPORATION) EPSON Port Communication Service (HKLM\...\{CA5BA3A3-E944-4FAD-A943-B020425F496B}) (Version: 3.12.0 - SEIKO EPSON CORPORATION) Epson Print CD (HKLM-x32\...\{D16A31F9-276D-4968-A753-FFEAC56995D0}) (Version: 2.00.00 - SEIKO EPSON CORPORATION) EPSON PX720WD Series Manual (HKLM-x32\...\EPSON PX720WD Series Manual) (Version: - ) EPSON PX720WD Series Network Guide (HKLM-x32\...\EPSON PX720WD Series Network Guide) (Version: - ) EPSON PX720WD Series Printer Uninstall (HKLM\...\EPSON PX720WD Series) (Version: - SEIKO EPSON Corporation) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.4j - SEIKO EPSON CORPORATION) EpsonNet Setup 3.3 (HKLM-x32\...\{C9D8A041-2963-4B31-8FFC-1500F3DB9293}) (Version: 3.3a - SEIKO EPSON CORPORATION) FARO LS 1.1.406.58 (HKLM-x32\...\{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}) (Version: 4.6.58.2 - FARO Scanner Production) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 41.0.2272.101 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Hotfix für Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789) (HKLM-x32\...\{8E87B944-4815-3C5E-947F-5035C9F64362}.KB947789) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2008 Remote Debugger Light (x64) - DEU (KB944899) (HKLM-x32\...\{E6420CCB-92BE-3ACB-BDC3-69FBDD319C94}.KB944899) (Version: 1 - Microsoft Corporation) InstPortMon (x32 Version: 1.4.0.0 - InstPortMon) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.28 - Irfan Skiljan) Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden LEGO® Harry Potter™: Die Jahre 5-7 (HKLM-x32\...\{5C5A944F-096E-4ADD-B8E8-887F18BA6228}) (Version: 1.0.0.0 - WB Games) LEGO® Indiana Jones™ 2 (x32 Version: 1.00.0000 - LucasArts) Hidden LEGO® Indiana Jones™ 2:*Die neuen Abenteuer (HKLM-x32\...\InstallShield_{11192AA7-FBE3-4150-9667-EE7279CCC769}) (Version: 1.00.0000 - LucasArts) LEGO® Star Wars™: Die Komplette Saga (HKLM-x32\...\InstallShield_{D596980D-17BE-4425-B8F0-5640719AADE9}) (Version: 1.00.0000 - LucasArts) LEGO® Star Wars™: The Complete Saga (x32 Version: 1.00.0000 - LucasArts) Hidden Malwarebytes Anti-Malware Version 2.1.4.1018 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation) Mediencenter 3.9.1055.64 (HKU\S-1-5-21-2187199526-2023232132-3882960752-1000\...\Mediencenter) (Version: 3.9.1055.64 - Deutsche Telekom AG) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation) Microsoft Office 2003 Web Components (HKLM-x32\...\{90120000-00A4-0409-0000-0000000FF1CE}) (Version: 12.0.6213.1000 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU (HKLM\...\Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU) (Version: - Microsoft Corporation) Microsoft Visual Studio 2005 Tools for Applications - ENU (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Applications - ENU) (Version: - Microsoft Corporation) Microsoft Visual Studio 2008 Remote Debugger Light (x64) - DEU (HKLM\...\Microsoft Visual Studio 2008 Remote Debugger Light (x64) - DEU) (Version: - Microsoft Corporation) Microsoft Visual Studio 2008 Remote Debugger Light (x64) - DEU Service Pack 1 (KB945140) (HKLM-x32\...\{E6420CCB-92BE-3ACB-BDC3-69FBDD319C94}.KB945140) (Version: 1 - Microsoft Corporation) Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU (HKLM\...\Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU) (Version: - Microsoft Corporation) Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU Service Pack 1 (KB945140) (HKLM-x32\...\{90A80D89-A0E4-33C1-B13D-B93CB3496867}.KB945140) (Version: 1 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2.0 Language Pack - DEU (HKLM-x32\...\{8E87B944-4815-3C5E-947F-5035C9F64362}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - DEU (HKLM-x32\...\{76DAEC83-AF7B-333C-8A53-83D7C7D39199}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mozilla Firefox 36.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0.1 (x86 de)) (Version: 36.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 36.0.1 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Netzmanager (HKLM-x32\...\Netzmanager) (Version: 1.081 - Deutsche Telekom AG) Netzmanager (Version: 1.081 - Deutsche Telekom AG, Marmiko IT-Solutions GmbH) Hidden NVIDIA 3D Vision Treiber 311.66 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.66 - NVIDIA Corporation) NVIDIA Grafiktreiber 311.66 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.66 - NVIDIA Corporation) NVIDIA nView 140.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 140.54 - NVIDIA Corporation) OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) Oracle VM VirtualBox 4.3.20 (HKLM\...\{86401870-7AB7-4A8D-8AD6-12B27DF2E6E3}) (Version: 4.3.20 - Oracle Corporation) PDF24 Creator 2.9.9 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Pflanzen gegen Zombies (HKLM-x32\...\Pflanzen gegen Zombies) (Version: - PopCap Games) Pharao (HKLM-x32\...\Pharao) (Version: - ) QuickTime (HKLM-x32\...\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.) Realtek Ethernet Controller Driver For Windows Vista and Later (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0009 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6251 - Realtek Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) SL-6555-SBK (HKLM-x32\...\{7AB86D35-DF3B-407F-B43E-468345DABF29}) (Version: 1.00.0000 - GASIA) Speedport W 102 Stick (HKLM-x32\...\InstallShield_{5E93BA4E-69A0-46A7-B634-3E762FF9B6F9}) (Version: 1.0.0.18 - Deutsche Telekom AG) Speedport W 102 Stick (x32 Version: 1.0.0.18 - Deutsche Telekom AG) Hidden TomTom HOME (HKLM-x32\...\{99072AB4-D795-44D5-9D65-E3C9F8322C97}) (Version: 2.9.7 - Ihr Firmenname) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) VBA (2627.01) (x32 Version: 6.03.00.9402 - Microsoft Corporation) Hidden VBA (2701.01) (x32 Version: 6.03.00.9402 - Microsoft Corporation) Hidden Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-2187199526-2023232132-3882960752-1000_Classes\CLSID\{268502F4-815D-4358-A8D6-B783FDB58EF0}\InprocServer32 -> C:\Users\Hirsch\AppData\Roaming\Telekom\MediencenterSync\DTAG.Mediencenter.ContextMenuHandler.dll (Deutsche Telekom AG) CustomCLSID: HKU\S-1-5-21-2187199526-2023232132-3882960752-1000_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2011\DWGVIEWRficn.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-2187199526-2023232132-3882960752-1000_Classes\CLSID\{528EE335-5034-4EFC-834E-63E5F02D2BC2}\InprocServer32 -> C:\Users\Hirsch\AppData\Roaming\Telekom\MediencenterSync\DTAG.Mediencenter.IconOverlayHandler.dll (Deutsche Telekom AG) CustomCLSID: HKU\S-1-5-21-2187199526-2023232132-3882960752-1000_Classes\CLSID\{6066ADF0-9EB0-43E5-ADB6-990F5A3B979C}\InprocServer32 -> C:\Users\Hirsch\AppData\Roaming\Telekom\MediencenterSync\DTAG.Mediencenter.IconOverlayHandler.dll (Deutsche Telekom AG) CustomCLSID: HKU\S-1-5-21-2187199526-2023232132-3882960752-1000_Classes\CLSID\{6D7AE628-FF41-4CD3-91DD-34825BB1A251}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2011\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-2187199526-2023232132-3882960752-1000_Classes\CLSID\{77BC4082-DB5F-439A-8DC8-F9E24A63B0DE}\InprocServer32 -> C:\Users\Hirsch\AppData\Roaming\Telekom\MediencenterSync\DTAG.Mediencenter.IconOverlayHandler.dll (Deutsche Telekom AG) CustomCLSID: HKU\S-1-5-21-2187199526-2023232132-3882960752-1000_Classes\CLSID\{C92FB640-AD4D-498A-9979-A51A2540C977}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2011\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-2187199526-2023232132-3882960752-1000_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2011\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-2187199526-2023232132-3882960752-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2011\acadficn.dll (Autodesk, Inc.) ==================== Restore Points ========================= 22-03-2015 22:20:00 Revo Uninstaller's restore point - pdfforge Toolbar v10.5 22-03-2015 22:20:20 Removed pdfforge Toolbar v10.5. 22-03-2015 22:22:01 Revo Uninstaller's restore point - UniDeals 22-03-2015 22:23:32 Revo Uninstaller's restore point - UpgradeTower 22-03-2015 22:24:32 Revo Uninstaller's restore point - UpgradeTower ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2015-03-22 22:44 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {03A802D7-9C00-4A50-922C-9CF8FDAE5183} - System32\Tasks\{A353AEDC-23B7-4C9E-AFD1-5660BBB90314} => E:\SETUP\AVA\AVASETUP.EXE Task: {095E769B-F7DD-4EC7-8230-C1B9CDE14EE1} - System32\Tasks\{5B1D2268-CEC9-4ED7-8155-31DAC3E70CDD} => E:\SETUP\AVA\AVASETUP.EXE Task: {0B7FDB54-F86B-45E0-A967-BEA45F8C5937} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-22] (Google Inc.) Task: {15BA3597-7D60-43E3-92E7-E2C8282F8B56} - System32\Tasks\{37E31E53-97C7-4930-AC70-BF312228EC7D} => E:\SETUP\AVA\AVASETUP.EXE Task: {17BFA44C-2371-4C96-A738-820445EB6440} - System32\Tasks\{8A491BC5-0827-472D-8C9D-85373067D7A4} => C:\Users\Hirsch\AppData\Roaming\Telekom\MediencenterSync\Mediencenter.exe [2014-06-12] (Deutsche Telekom AG) Task: {3680A978-D45D-4C16-9F67-7065FF268AA1} - System32\Tasks\{FB3661B0-6D6E-4ECB-8221-2E122BD1FCC5} => E:\SETUP\AVA\avaunclw.EXE Task: {3683FAAB-550A-4AE0-8786-3158A7C778D8} - System32\Tasks\{A611182B-6E8A-45CC-8755-FEE969672739} => E:\SETUP\AVA\AVASETUP.EXE Task: {39EB7FBA-37D2-4110-AB9E-1C3B46CFB3AF} - System32\Tasks\{2922904D-8937-4790-A2D0-AE53AFA9AB67} => E:\SETUP\AVA\AVASETUP.EXE Task: {3B03088C-B7B6-4D79-A9F4-30DE6431206D} - System32\Tasks\{BEA9A642-122D-4A79-9421-72B545C09EC3} => pcalua.exe -a "C:\Users\Hirsch\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A2S0SSF4\browser7_setup.exe" -d C:\Users\Hirsch\Desktop Task: {40E37EFF-1C7A-48D5-B71F-11D4A8454FBB} - System32\Tasks\{78887DC1-D6D1-44CF-A411-D8C7CCC5DF39} => E:\SETUP\AVA\AVASETUP.EXE Task: {426DE9E6-CEC4-4843-8FD1-D5B7DBBDCF4B} - System32\Tasks\{05A6BE47-480D-497C-BCF3-87697BFF1E3E} => pcalua.exe -a E:\SETUP\AVA\WIN95_NT.EXE -d E:\SETUP\AVA Task: {4765F6E7-3255-4E1C-A24A-221E563F1A5A} - System32\Tasks\{58EBEBA9-CABE-4D1E-8CD4-087DD1F2DC32} => pcalua.exe -a "C:\Program Files (x86)\NCH Swift Sound\Switch\uninst.exe" Task: {47A6816A-9B14-438C-985A-EBF9087487B7} - System32\Tasks\{76EF6236-BCB5-4945-B3E8-ED736144C6CF} => E:\SETUP\AVA\avaunclw.EXE Task: {4861217E-E8C5-40F4-B146-DE8771777045} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-22] (Google Inc.) Task: {4908300D-36AA-490B-9131-C84765EF6D35} - System32\Tasks\{90C8495B-5BB9-4559-8A3E-9F142FA21F90} => E:\SETUP\AVA\AVASETUP.EXE Task: {492C2D85-F5CF-414A-A1F2-B9E3DE2CAB3F} - System32\Tasks\{B46DDA80-51EE-42EC-B317-6133A856C9EF} => E:\SETUP\AVA\avaunclw.EXE Task: {51DEC541-A61A-4542-9A95-12EDDA2D9BD2} - System32\Tasks\{E0F4272E-8FB8-46E6-B0C1-C276F55F78C5} => E:\SETUP\AVA\AVASETUP.EXE Task: {52549604-C6D5-45FC-A7B6-4BE72B3AE9B0} - System32\Tasks\{FF5B6ADD-845A-440C-B232-45251635CC94} => E:\SETUP\AVA\AVASETUP.EXE Task: {599521B0-80A1-4E22-8FBD-4EE123EE236B} - System32\Tasks\{69FD49CB-0394-4642-A899-94556B86E62F} => D:\Program Files (x86)\Anno 1701\Anno1701.exe Task: {5B6F4D44-8BBE-4A1B-BF4A-2838B4D900B3} - System32\Tasks\{EAE2E67D-6EF0-4BEE-B4AD-EEE7B16845CA} => E:\SETUP\AVA\avaunclw.EXE Task: {5DC50593-4CE7-4DFD-A62E-EF1FEDE13A40} - System32\Tasks\{8B502DA7-3164-4E54-992A-454F2ACF148F} => E:\SETUP\AVA\avaunclw.EXE Task: {5E65B3FE-F5F1-49D4-A7FA-59E092D474D5} - System32\Tasks\{AA6918EC-1B9E-4D66-88A4-FAA1FD7900B0} => E:\SETUP\AVA\AVASETUP.EXE Task: {698E9ED3-4D0B-4F59-AC6F-DB4ECECD356C} - System32\Tasks\{D771194E-5B87-4770-90B9-3E8EC28A81F4} => D:\Program Files (x86)\Anno 1701\Anno1701.exe Task: {6C937BE4-E194-4795-AD81-807713E8076C} - System32\Tasks\{BEFC6386-BC88-4830-A59C-29D3CC33007B} => pcalua.exe -a "D:\Programme\ACAD 10\Autocad2010\setup.exe" -d "D:\Programme\ACAD 10\Autocad2010" Task: {70981963-EC73-45AB-9149-889038EDC943} - System32\Tasks\{9173555F-7807-4E64-A911-60AC506461DE} => E:\SETUP\AVA\AVASETUP.EXE Task: {758B26F6-23A2-49DB-A3B3-D9CF90F86F26} - System32\Tasks\{53655515-AE6E-4247-B034-588872FCCA63} => pcalua.exe -a F:\Autocad2010\setup.exe -d F:\Autocad2010 Task: {775915A2-AA12-4132-9765-64076D053582} - System32\Tasks\{B6968E2F-A947-4F0A-91D3-E6DACE8FD7B3} => E:\SETUP\AVA\AVASETUP.EXE Task: {77EA3B80-442B-46BE-80D7-2740C95028FC} - System32\Tasks\{FDE6CE8E-FE55-44F2-AF3B-8DD03A3D1350} => E:\SETUP\AVA\AVASETUP.EXE Task: {785C0C6B-7B7D-471C-9A39-AA3169730478} - System32\Tasks\{FC4ACFED-1D0E-482D-A2DF-FA8385805AF3} => E:\SETUP\AVA\avaunclw.EXE Task: {796D5C83-903E-46CA-A841-873031704245} - System32\Tasks\{5B2A0A36-1EE7-4AD0-BD41-0EC7FBE7B33B} => E:\SETUP\AVA\AVASETUP.EXE Task: {7A573E94-CD74-434A-92B1-78753F408B9C} - System32\Tasks\{744644A6-D3CD-4916-8996-F3B90DCAA1F3} => E:\SETUP.EXE Task: {8324A627-C0BE-4224-9DCD-9A18C7068552} - System32\Tasks\{E9E489A8-6C85-4FCC-9A12-DAAC244CC154} => E:\SETUP\AVA\AVASETUP.EXE Task: {88D35C1F-5789-4478-93FC-8887EC83A66D} - System32\Tasks\{7F0D2E53-CB1E-47B8-AB22-51356915A2D0} => E:\SETUP\AVA\AVASETUP.EXE Task: {8A218625-7B27-4569-89C1-306B00306859} - System32\Tasks\{29973BFC-3D13-4F89-8708-AD6385FD4F06} => E:\SETUP\AVA\avaunclw.EXE Task: {8A9BB4EC-6B29-4818-BA2E-9EB7D4D7C66B} - System32\Tasks\{1E22F022-30F0-4DDD-90F9-846CB6769688} => E:\SETUP\AVA\avaunclw.EXE Task: {8ABCCD08-AA40-4C7D-B1A2-CF6CE1A7581F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-06] (Adobe Systems Incorporated) Task: {902D67E9-62C0-4A57-B677-F66B790C0E14} - System32\Tasks\{6AA5FF11-14CA-4C54-A1A4-57E779FC015A} => E:\SETUP\AVA\avaunclw.EXE Task: {955F2756-BBF9-4656-ACD8-DA46A7CA2884} - System32\Tasks\{A8DB0328-C7E7-4459-9CF5-D122B4252BC5} => E:\SETUP\AVA\avaunclw.EXE Task: {98EFCE30-F900-4E36-8D25-CD2A1FEDAF5D} - System32\Tasks\{CE0AC151-7887-4DD4-A2A4-ECCE1B41AF23} => E:\SETUP\AVA\avaunclw.EXE Task: {9938CEB8-C75D-494C-8302-4F37F084DDA5} - System32\Tasks\{63707C85-4B83-4D94-89FA-C0B0D1EBCBFA} => E:\SETUP\AVA\avaunclw.EXE Task: {9B701B93-9C67-4F33-88AB-1D45D46F48D3} - System32\Tasks\{79DD91F1-65D2-4F26-A71D-F6A0DB70D51C} => D:\Program Files (x86)\Anno 1701\Anno1701.exe Task: {9C3F5DB4-224F-42DC-9362-182C466BB243} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {A1D60D55-A6B8-401B-BC05-2938E02DF2F2} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => d:\program files\windows defender\MpCmdRun.exe Task: {AA17F1F8-0378-415E-8083-915C68468EB6} - System32\Tasks\{D03C9452-2414-48EC-A478-625F580D4201} => E:\SETUP.EXE Task: {AFDC45E2-9C50-4F98-812C-AEB60B8961DB} - System32\Tasks\{C8B017ED-20B3-4EDD-9839-99AD57308AC2} => C:\Users\Hirsch\AppData\Roaming\Telekom\MediencenterSync\Mediencenter.exe [2014-06-12] (Deutsche Telekom AG) Task: {B0124F15-53F3-432D-99B4-DC965CADA429} - System32\Tasks\{A467B903-37D0-47DD-A345-33C0C27F2226} => E:\SETUP\AVA\avaunclw.EXE Task: {B2695097-A58B-4C7D-BBC3-201D2F4EDA34} - System32\Tasks\{880FBB61-895A-446E-9C64-583EBF4B207C} => E:\SETUP\AVA\avaunclw.EXE Task: {BC12705E-4C3A-44FD-A01C-D5999504A14B} - System32\Tasks\{D98D3287-0290-4206-AA1F-65633307CC0A} => D:\Program Files (x86)\Anno 1701\Anno1701.exe Task: {BCBA29E7-8D9A-4892-BC84-5090CE8D924C} - System32\Tasks\{649D52C7-7F1F-46C1-A067-EC2503691A55} => E:\SETUP\AVA\avaunclw.EXE Task: {C0A96053-525D-4B5D-A06C-DAE323B3D58F} - System32\Tasks\{FC9216FF-88D6-44B1-A6F3-EC8F187CD1CB} => E:\SETUP\AVA\avaunclw.EXE Task: {C4E8B14A-4159-4C58-BDAD-281DBBFC97E8} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => d:\program files\windows defender\MpCmdRun.exe Task: {CABA6CAD-17F6-4514-AF59-A54B7529FA38} - System32\Tasks\{3E39EA55-2645-4D9D-80EC-10461DCEB904} => E:\SETUP\AVA\avaunclw.EXE Task: {D11A5E19-E3A6-47F4-9B00-7FFEA3097A01} - System32\Tasks\{42CC6D07-F239-49ED-94CC-A53DE4B6E47B} => E:\SETUP\AVA\avaunclw.EXE Task: {D426F0EE-9B40-4E8B-B164-B1084EDF5BE5} - System32\Tasks\{93722E7B-D3AD-4402-BBF6-A40CA7FEAAEA} => E:\SETUP\AVA\AVASETUP.EXE Task: {D5EDB7CA-74F2-4E39-B81C-31E77C76044D} - System32\Tasks\{861F5B64-1A25-4A5B-9799-1BA399025242} => E:\SETUP\AVA\avaunclw.EXE Task: {D7FE51DB-CEC1-40D6-8FDA-27C43C493B4F} - System32\Tasks\{B7566758-2E03-4F3E-839B-D48E43DF59E1} => E:\SETUP\AVA\AVASETUP.EXE Task: {DA29AA06-703E-453D-9CE2-04608B80AB06} - System32\Tasks\{59CAFA48-4691-40F9-AB33-3E668F1FC136} => E:\SETUP\AVA\avaunclw.EXE Task: {E9A5A4CE-8A9D-4599-A44F-6BA2EADBDB82} - System32\Tasks\{7438B355-E58E-469E-88C3-388B6E29FFDD} => E:\SETUP\AVA\AVASETUP.EXE Task: {F23A47F9-F738-4398-BADB-C2DEF9ADC1E7} - System32\Tasks\{C779561F-6027-4589-ADED-C133791D7DD7} => E:\SETUP\AVA\AVASETUP.EXE Task: {F29138E7-632F-4F07-884A-365C1BF3FB92} - System32\Tasks\{2B2C7A8F-E5EC-4695-BCA8-83D4C87DEC20} => E:\SETUP\AVA\avaunclw.EXE Task: {FCAC3370-A54B-4DB8-8F5B-4DA2D88BC98D} - System32\Tasks\{9A73101E-7F47-483D-9625-466F2C8E32BB} => E:\SETUP\AVA\avaunclw.EXE Task: {FD5059AB-E67E-4032-AAE8-5617EF75A70F} - System32\Tasks\{E6018344-F5DD-42CD-A316-7ED8E2C0F40E} => E:\SETUP\AVA\avaunclw.EXE Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2014-12-30 13:41 - 2013-05-14 14:53 - 00087328 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-11-14 10:43 - 2009-09-08 22:12 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE 2010-01-23 04:12 - 2010-01-23 04:12 - 00673792 _____ () C:\Program Files\Autodesk\Inventor 2011\Moldflow\bin\mitsijm.exe 2010-10-19 08:31 - 2010-10-19 08:31 - 00205312 _____ () D:\Programme\Netzmanager\NMInfraIS2\driver64\SoftplugLib.DLL ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2187199526-2023232132-3882960752-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Hirsch\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Speedport W 102 WLAN Manager.lnk => C:\Windows\pss\Speedport W 102 WLAN Manager.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Start 3DxWare.lnk => C:\Windows\pss\Start 3DxWare.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Hirsch^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Mediencenter.lnk => C:\Windows\pss\Mediencenter.lnk.Startup MSCONFIG\startupfolder: C:^Users^Hirsch^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Netzmanager.lnk => C:\Windows\pss\Netzmanager.lnk.Startup ==================== Accounts: ============================= Administrator (S-1-5-21-2187199526-2023232132-3882960752-500 - Administrator - Disabled) Gast (S-1-5-21-2187199526-2023232132-3882960752-501 - Limited - Disabled) Hirsch (S-1-5-21-2187199526-2023232132-3882960752-1000 - Administrator - Enabled) => C:\Users\Hirsch HomeGroupUser$ (S-1-5-21-2187199526-2023232132-3882960752-1003 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-2400 CPU @ 3.10GHz Percentage of memory in use: 30% Total physical RAM: 8173.25 MB Available physical RAM: 5690.23 MB Total Pagefile: 16344.69 MB Available Pagefile: 13493.94 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:100 GB) (Free:14.09 GB) NTFS Drive d: (Daten) (Fixed) (Total:831.41 GB) (Free:627.6 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: F9C7661C) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=100 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=831.4 GB) - (Type=07 NTFS) ==================== End Of Log ============================Gruß und danke Gropius |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
scans durchgeführt ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=7d49bae8d2ee064abd8cd3c74807edd4 # engine=23061 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-03-25 02:41:36 # local_time=2015-03-25 03:41:36 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Microsoft Security Essentials' # compatibility_mode=5895 16777213 100 100 3588463 121432506 0 0 # scanned=323362 # found=35 # cleaned=0 # scan_time=18429 sh=CF07840FDAACB1C08C4631D8AA3EDD6AE6EE7669 ft=0 fh=0000000000000000 vn="JS/Adware.MultiPlug.B Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\nakjoahhlolhapnffeplmapojlpghggn\content.js.vir" sh=5B91857833C7437ED06B32C59FE667E6D476F644 ft=0 fh=0000000000000000 vn="JS/Adware.MultiPlug.B Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\nakjoahhlolhapnffeplmapojlpghggn\lsdb.js.vir" sh=F29A350B46F56C99E415B6F3CCFCFC0445DEF518 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\nakjoahhlolhapnffeplmapojlpghggn\QC.js.vir" sh=416B0B1A975917D06689FFD00E296B4765B20563 ft=1 fh=c71c0011d040f6f7 vn="Variante von Win32/Adware.MultiPlug.FL Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\DIgiCoupon\j1RTG3NIuoe6m5.dll.vir" sh=03D1B31F6C684652CEA2295012ECBE0188DC1BD7 ft=1 fh=cecc82c612b87102 vn="Variante von Win64/Adware.MultiPlug.G Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\DIgiCoupon\j1RTG3NIuoe6m5.x64.dll.vir" sh=E21925D4668B45A13039145DA92605F2E94203C2 ft=1 fh=c71c0011c2c93f7a vn="Variante von Win32/Adware.MultiPlug.FL Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\DoiagiSavEr\WY80Ud9jL68K8c.dll.vir" sh=38F72F47F02CD2CFAB38CB64AA2ED872B6E50BD4 ft=1 fh=cecc82c6214ddae3 vn="Variante von Win64/Adware.MultiPlug.G Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\DoiagiSavEr\WY80Ud9jL68K8c.x64.dll.vir" sh=685A825E6BB59AE55AB87883A21F31565DCB7DE2 ft=1 fh=c71c0011531e4386 vn="Variante von Win32/Adware.MultiPlug.FL Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\JoniCOuppon\iOdpWOsRRZzewX.dll.vir" sh=A8F15ED21D868056F59115EB4FB87436A2261CB8 ft=1 fh=cecc82c67c46b0e6 vn="Variante von Win64/Adware.MultiPlug.G Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\JoniCOuppon\iOdpWOsRRZzewX.x64.dll.vir" sh=7B20BB8492ECF340BC237A08DAEFC93AADDF6CF7 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Qoobox\Quarantine\C\Users\Hirsch\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmocchgkijnbjdjkmlglaemjhhdiobbp\184\BzMuL.js.vir" sh=CF07840FDAACB1C08C4631D8AA3EDD6AE6EE7669 ft=0 fh=0000000000000000 vn="JS/Adware.MultiPlug.B Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Hirsch\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmocchgkijnbjdjkmlglaemjhhdiobbp\184\content.js.vir" sh=5B91857833C7437ED06B32C59FE667E6D476F644 ft=0 fh=0000000000000000 vn="JS/Adware.MultiPlug.B Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Hirsch\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmocchgkijnbjdjkmlglaemjhhdiobbp\184\lsdb.js.vir" sh=3FDD5E0436D39E09ADA01CBF118482E153E19898 ft=1 fh=1f16a728f3002118 vn="Variante von Win32/SoftPulse.X evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Hirsch\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BWA8QQ12\Installation.exe.jsfo38g.partial" sh=844DE02B0EC03D58B8CB8751367B30DA47C22466 ft=1 fh=ac3e871310858703 vn="Variante von Win32/ReImageRepair.E evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Hirsch\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N84GMTU7\ReimagePackage1808x64d[1].exe" sh=B9C9D380B89C9D9AF2D1736FCD0D1CFEF4FB5121 ft=1 fh=65cbba18ed465624 vn="Variante von Win32/SoftPulse.X evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Hirsch\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A7ZUXJH5\Setup[1].exe" sh=69BE762A0694BF1F8A4833C813C6D55CC1A5B485 ft=1 fh=92c3a2ac227b9b3a vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Hirsch\Downloads\Firefox - CHIP-Installer(1).exe" sh=25BAAE2B0F86473C2E14B4BC904B9EBE7D13DE87 ft=1 fh=e58471882e3cbfd2 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Hirsch\Downloads\Firefox - CHIP-Installer.exe" sh=AA016D7660A0FCEF9BFA368E044BA0C32A18DA81 ft=1 fh=c71c00116360c19a vn="Variante von Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSID53C.tmp" sh=2136C1FAF232A67D700F8AA71ADE2B1DDBB6236A ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2011-04-22 095733\Backup Files 2011-05-29 194730\Backup files 1.zip" sh=8EE1152A30F83ED3D749D4DA498E07212DA39825 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2012-04-22 190000\Backup Files 2012-04-22 190000\Backup files 2.zip" sh=9CBEF0BEE1C9061E4C7F6B36CA88F8912239EA34 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2012-04-22 190000\Backup Files 2012-04-22 190000\Backup files 3.zip" sh=45A5DBA60604B28B97F88566B2A98D8C6F2199C4 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2012-12-09 195730\Backup Files 2012-12-09 195730\Backup files 2.zip" sh=B69EF9DB6AFF79BA297F516039897DE261AD8F88 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2013-12-15 204417\Backup Files 2013-12-15 204417\Backup files 3.zip" sh=E2E3CEE85C01DC1892A136693406E184FE62FCEF ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2013-12-15 204417\Backup Files 2013-12-15 204417\Backup files 4.zip" sh=2ABFCD9D2DACBC34A67258EAA88C574CE3D4D93B ft=0 fh=0000000000000000 vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2013-12-15 204417\Backup Files 2014-01-05 190001\Backup files 1.zip" sh=A954319B0A609C9AE28185D99AEBFFD322C35023 ft=0 fh=0000000000000000 vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2014-08-10 195555\Backup Files 2014-08-10 195555\Backup files 2.zip" sh=163BDEF61643ECCE313F579176F42B80ED04A998 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2014-08-10 195555\Backup Files 2014-08-10 195555\Backup files 5.zip" sh=55170CC9BAA5A36DD5BEAA4BDDA92753A6B5A79A ft=0 fh=0000000000000000 vn="Variante von Win32/DealPly.R evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2014-12-08 081311\Backup Files 2014-12-08 081311\Backup files 3.zip" sh=A9AD0EA24DFFEC9626B4554F7A301410327F8FDE ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2014-12-08 081311\Backup Files 2014-12-08 081311\Backup files 5.zip" sh=CF7CA5C24CBD864C39B6C677FF21B457C7956F77 ft=0 fh=0000000000000000 vn="Variante von Win32/AdInstaller evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2014-12-08 081311\Backup Files 2015-01-19 081949\Backup files 1.zip" sh=D06431149DBF59AB2E7820861EE5EC328D030065 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="D:\HIRSCH-PC\Backup Set 2014-12-08 081311\Backup Files 2015-02-15 191900\Backup files 1.zip" sh=E7B7D282C3B42B1E7A4452D368CA6E35B187EC75 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2014-12-08 081311\Backup Files 2015-03-01 190000\Backup files 4.zip" sh=86D68B191BB1E810EB0853EDDF15343B69C59E2F ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="D:\HIRSCH-PC\Backup Set 2015-03-22 215556\Backup Files 2015-03-22 215556\Backup files 3.zip" sh=0A02FFE2B69585260454EE489B74BE7F37C98E44 ft=0 fh=0000000000000000 vn="Variante von Win32/AdInstaller evtl. unerwünschte Anwendung" ac=I fn="D:\HIRSCH-PC\Backup Set 2015-03-22 215556\Backup Files 2015-03-22 215556\Backup files 8.zip" sh=AFBC0B833C008AB713246FAB14A5F2B24555773C ft=1 fh=613c209c493fe473 vn="Variante von Win32/SweetIM.B evtl. unerwünschte Anwendung" ac=I fn="D:\Programme\PDFConverterSetup.exe" Code: Results of screen317's Security Check version 0.99.97 Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Alles Paletti Danke! Gruß, Gropius |
Java updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Cleanup: (Die Reihenfolge ist hier entscheidend) Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken. Falls Combofix verwendet wurde: http://deeprybka.trojaner-board.de/b.../combofix2.pngCombofix deinstallieren .
Alle Logs gepostet? Dann lade Dir bitte http://filepony.de/icon/tiny/delfix.pngDelFix herunter.
Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst. Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen. Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...:dankeschoen:und/oder das Forum mit einer kleinen Spende http://www.trojaner-board.de/extra/spende.png unterstützen. :applaus: http://deeprybka.trojaner-board.de/b...ast/schild.pngAbsicherung: Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen: Browser Java Flash-Player PDF-Reader Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren. Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen. Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig. Verwende ein Antivirusprogramm mit Echtzeitscanner und stets aktueller Signaturendatenbank. Meine Empfehlung: http://filepony.de/icon/emsisoft_anti_malware.png Emsisoft Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen. Optional: http://filepony.de/icon/noscript.png NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen. http://filepony.de/icon/malwarebytes_anti_exploit.pngMalwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen. Lade Software von einem sauberen Portal wie http://filepony.de/images/microbanner.gif. Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen. Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwarecleaner . Abschließend noch ein paar grundsätzliche Bemerkungen: Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems. Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden. |
Java updaten klappt nicht hallo Schrauber, das Java Update klappt nicht. Nach der Eingabe erhalte ich die Nachricht CHR konnte nicht gefunden werden Gruß, Gropius |
Häh? Was genau machst Du? :) |
inhalt von fix log Hallo Schrauber, habe nicht richtig gelesen bzw gepennt :stirn:. Gruß, Gropius Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by Hirsch at 2015-03-29 13:02:19 Run:1 Running from C:\Users\Hirsch\Desktop Loaded Profiles: Hirsch (Available profiles: Hirsch) Boot Mode: Normal ============================================== Content of fixlist: ***************** CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Emptytemp: ***************** "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. EmptyTemp: => Removed 1.7 GB temporary data. The system needed a reboot. ==== End of Fixlog 13:03:14 ====[/CODE] |
ok, dann jetzt das Cleanup :) |
Clean up duchgeführt Hallo Schrauber, habe das clean up durchgeführt. Ist damit alles erledigt? Gruß, Gropius |
Alle Zeitangaben in WEZ +1. Es ist jetzt 16:26 Uhr. |
Copyright ©2000-2025, Trojaner-Board