gofurther | 25.08.2015 17:03 | alles durchgeführt Hallo Schrauber,
hier die logfiles und txt dateien Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 25.08.2015
Suchlaufzeit: 16:36
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.08.25.05
Rootkit-Datenbank: v2015.08.16.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: JPMK
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 322619
Abgelaufene Zeit: 25 Min., 1 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 7
PUP.Optional.SaveNewAppz.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C7405EEB-2E16-40FE-9E27-1F48CAAB15E1}, In Quarantäne, [7f8a94797912b87eb430267d82825da3],
PUP.Optional.SaveNewAppz.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0416BDB0-AFB0-4464-952D-1EAB5047B8E6}, In Quarantäne, [7f8a94797912b87eb430267d82825da3],
PUP.Optional.SaveNewAppz.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3F97FDF1-DA2B-4579-AD3E-E46641F9DBAB}, In Quarantäne, [7f8a94797912b87eb430267d82825da3],
PUP.Optional.SaveNewAppz.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A220BAB5-C335-48BA-8A01-309FDA37446F}, In Quarantäne, [7f8a94797912b87eb430267d82825da3],
PUP.Optional.FastSearchings, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}, In Quarantäne, [8c7d0d00701b96a0380d395d8e767789],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [d13841cc0e7d36002409ab0007fd6997],
PUP.Optional.WebSearchInfo, HKU\S-1-5-21-2802431009-2721445263-3219878338-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}, In Quarantäne, [41c8c14c97f4f44282ef1a6e9b699868],
Registrierungswerte: 9
PUP.Optional.WebSearchInfo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}, In Quarantäne, [62a7729b99f2fc3ac331811630d4ff01]
PUP.Optional.TheSearchPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}|FaviconURL, hxxp://websearch.thesearchpage.info/favicon.ico, In Quarantäne, [8d7c030a17745ed860483873b74db050]
PUP.Optional.TheSearchPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}|FaviconURLFallback, hxxp://websearch.thesearchpage.info/favicon.ico, In Quarantäne, [ec1dbe4fed9e48ee3771832821e307f9]
PUP.Optional.TheSearchPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}|URL, hxxp://websearch.thesearchpage.info/?l=1&q={searchTerms}&pid=21242&r=2015/02/02&hid=5588267861785443742&lg=EN&cc=DE&unqvl=74, In Quarantäne, [ab5e9677018a25119d0b4d5e758fbf41]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [d13841cc0e7d36002409ab0007fd6997]
PUP.Optional.WebSearchInfo, HKU\S-1-5-21-2802431009-2721445263-3219878338-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}, In Quarantäne, [9d6c9e6fa5e6e84efe74a9df17ed9c64]
PUP.Optional.TheSearchPage.A, HKU\S-1-5-21-2802431009-2721445263-3219878338-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}|FaviconURL, hxxp://websearch.thesearchpage.info/favicon.ico, In Quarantäne, [917814f95536a19566413d6ec044926e]
PUP.Optional.TheSearchPage.A, HKU\S-1-5-21-2802431009-2721445263-3219878338-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}|FaviconURLFallback, hxxp://websearch.thesearchpage.info/favicon.ico, In Quarantäne, [9c6d3ecfee9dd85e3a6d0c9fbb49f60a]
PUP.Optional.TheSearchPage.A, HKU\S-1-5-21-2802431009-2721445263-3219878338-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}|URL, hxxp://websearch.thesearchpage.info/?l=1&q={searchTerms}&pid=21242&r=2015/02/02&hid=5588267861785443742&lg=EN&cc=DE&unqvl=74, In Quarantäne, [65a4f31aa1eae0562b7c2c7f7193e61a]
Registrierungsdaten: 2
PUP.Optional.TheSearchPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://websearch.thesearchpage.info/?pid=21242&r=2015/02/02&hid=5588267861785443742&lg=EN&cc=DE&unqvl=74, Gut: (www.google.com), Schlecht: (hxxp://websearch.thesearchpage.info/?pid=21242&r=2015/02/02&hid=5588267861785443742&lg=EN&cc=DE&unqvl=74),Ersetzt,[c742da33a6e592a45aa4c688e0255da3]
PUP.Optional.TheSearchPage.A, HKU\S-1-5-21-2802431009-2721445263-3219878338-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://websearch.thesearchpage.info/?pid=21242&r=2015/02/02&hid=5588267861785443742&lg=EN&cc=DE&unqvl=74, Gut: (www.google.com), Schlecht: (hxxp://websearch.thesearchpage.info/?pid=21242&r=2015/02/02&hid=5588267861785443742&lg=EN&cc=DE&unqvl=74),Ersetzt,[5baee22beba00d2944bbc08e21e4e719]
Ordner: 5
PUP.Optional.SaveNewAppz.A, C:\Program Files\SaVeuNewaAppz, In Quarantäne, [7f8a94797912b87eb430267d82825da3],
PUP.Optional.Vaudix.A, C:\Program Files\Vaudiex, In Quarantäne, [c049d13c523975c11bde396a4eb6f20e],
PUP.Optional.Vaudix.A, C:\Program Files\Vaudiix, In Quarantäne, [898042cb5932ad89af4a9c0753b1df21],
PUP.Optional.CheapMe.A, C:\Program Files\CheApMee, In Quarantäne, [2adf2ce11477aa8c2699edb8c143a65a],
PUP.Optional.ShopDrop.A, C:\Program Files\SHOpDrop, In Quarantäne, [b3567f8e385341f54b57a85d8a796d93],
Dateien: 11
PUP.Optional.SaveNewAppz.A, C:\Program Files\SaVeuNewaAppz\LBMYGH6GU5LUkz.tlb, In Quarantäne, [7f8a94797912b87eb430267d82825da3],
PUP.Optional.SaveNewAppz.A, C:\Program Files\SaVeuNewaAppz\LBMYGH6GU5LUkz.dat, In Quarantäne, [7f8a94797912b87eb430267d82825da3],
PUP.Optional.Vaudix.A, C:\Program Files\Vaudiex\RurW9x4uzyvk4q.tlb, In Quarantäne, [c049d13c523975c11bde396a4eb6f20e],
PUP.Optional.Vaudix.A, C:\Program Files\Vaudiex\RurW9x4uzyvk4q.dat, In Quarantäne, [c049d13c523975c11bde396a4eb6f20e],
PUP.Optional.Vaudix.A, C:\Program Files\Vaudiix\rO169JdmV2ksd4.tlb, In Quarantäne, [898042cb5932ad89af4a9c0753b1df21],
PUP.Optional.Vaudix.A, C:\Program Files\Vaudiix\rO169JdmV2ksd4.dat, In Quarantäne, [898042cb5932ad89af4a9c0753b1df21],
PUP.Optional.CheapMe.A, C:\Program Files\CheApMee\izqSi8wGXo1ruG.tlb, In Quarantäne, [2adf2ce11477aa8c2699edb8c143a65a],
PUP.Optional.CheapMe.A, C:\Program Files\CheApMee\izqSi8wGXo1ruG.dat, In Quarantäne, [2adf2ce11477aa8c2699edb8c143a65a],
PUP.Optional.ShopDrop.A, C:\Program Files\SHOpDrop\SHOpDrop.dat, In Quarantäne, [b3567f8e385341f54b57a85d8a796d93],
PUP.Optional.TheSearchPage.A, C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://websearch.thesearchpage.info/?pid=21242&r=2015/02/02&hid=5588267861785443742&lg=EN&cc=DE&unqvl=74&l=1&q=");), Ersetzt,[0bfe49c499f24de9e77e167d12f3728e]
PUP.Optional.AskAPN.Gen, C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\searchplugins\askcom.xml, In Quarantäne, [35d4b9547f0c6accfc58bad8f41111ef],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Code:
C:\Program Files\ReegularDeealss\ReegularDeealss.dat->C:\AdwCleaner\Quarantine\C\Program Files\ReegularDeealss\ReegularDeealss.dat.vir
C:\Program Files\VaeuDix\VaeuDix.dat->C:\AdwCleaner\Quarantine\C\Program Files\VaeuDix\VaeuDix.dat.vir
C:\Program Files\Live Earnings Checker for Google AdSense\Live Earnings Checker for Google AdSense.dat->C:\AdwCleaner\Quarantine\C\Program Files\Live Earnings Checker for Google AdSense\Live Earnings Checker for Google AdSense.dat.vir
C:\Users\JPMK\AppData\Local\eSupport.com\launcher32.dll->C:\AdwCleaner\Quarantine\C\Users\JPMK\AppData\Local\eSupport.com\launcher32.dll.vir Code:
C:\Program Files\ReegularDeealss\ReegularDeealss.dat->C:\AdwCleaner\Quarantine\C\Program Files\ReegularDeealss\ReegularDeealss.dat.vir
C:\Program Files\VaeuDix\VaeuDix.dat->C:\AdwCleaner\Quarantine\C\Program Files\VaeuDix\VaeuDix.dat.vir
C:\Program Files\Live Earnings Checker for Google AdSense\Live Earnings Checker for Google AdSense.dat->C:\AdwCleaner\Quarantine\C\Program Files\Live Earnings Checker for Google AdSense\Live Earnings Checker for Google AdSense.dat.vir
C:\Users\JPMK\AppData\Local\eSupport.com\launcher32.dll->C:\AdwCleaner\Quarantine\C\Users\JPMK\AppData\Local\eSupport.com\launcher32.dll.vir AdwCleaner Logfile: Code:
# AdwCleaner v5.003 - Bericht erstellt 25/08/2015 um 17:26:19
# Aktualisiert 20/08/2015 von Xplode
# Datenbank : 2015-08-23.3 [Server]
# Betriebssystem : Windows 7 Professional N Service Pack 1 (x86)
# Benutzername : JPMK - JPMK-PC
# Gestarted von : C:\Users\JPMK\Downloads\AdwCleaner_5.003.exe
# Option : Suchlauf
***** [ Dienste ] *****
***** [ Ordner ] *****
Ordner Gefunden : C:\Program Files\TampaGeneration
Ordner Gefunden : C:\Program Files\ReegularDeealss
Ordner Gefunden : C:\Program Files\VaeuDix
Ordner Gefunden : C:\Program Files\Live Earnings Checker for Google AdSense
Ordner Gefunden : C:\ProgramData\Ask
Ordner Gefunden : C:\Users\JPMK\AppData\Local\eSupport.com
***** [ Dateien ] *****
***** [ Verknüpfungen ] *****
***** [ Geplante Tasks ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{5D6736D5-0D77-46CE-9906-C4B2C679BF88}
Schlüssel Gefunden : HKCU\Software\eSupport.com
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Schlüssel Gefunden : HKLM\SOFTWARE\dt soft\daemon tools toolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Uniblue
Schlüssel Gefunden : HKLM\SOFTWARE\Uniblue\DriverScanner
***** [ Internetbrowser ] *****
[C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js] [Preference] Gefunden : user_pref("browser.search.defaultenginename,S", "WebSearch");
[C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js] [Preference] Gefunden : user_pref("browser.search.defaulturl", "hxxp://websearch.thesearchpage.info/?pid=21242&r=2015/02/02&hid=5588267861785443742&lg=EN&cc=DE&unqvl=74&l=1&q=");
[C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js] [Preference] Gefunden : user_pref("browser.search.order.1", "WebSearch");
[C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js] [Preference] Gefunden : user_pref("browser.search.order.1,S", "WebSearch");
[C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js] [Preference] Gefunden : user_pref("browser.search.selectedEngine", "WebSearch");
[C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js] [Preference] Gefunden : user_pref("browser.search.selectedEngine,S", "WebSearch");
[C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js] [Preference] Gefunden : user_pref("extensions.b4qAa4Xwgr62Ywgg.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.index[...]
[C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js] [Preference] Gefunden : user_pref("extensions.eXMj6dmWrfVGARrb.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.index[...]
[C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js] [Preference] Gefunden : user_pref("extensions.pKFbcuHSQm5sb2Sb.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"qjk5pds7qHY7rjC5qjn9rHC9rY\")>-1||url.indexOf(\"acebook\")>-1[...]
[C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js] [Preference] Gefunden : user_pref("extensions.q3IUmzVpW1Iq0MN0.scode", "(function(){try{if(window.location.href.indexOf(\"qjk5pds7qHY7rjC5qjn9rHC9rY\")>-1){return;}}catch(e){}try{var d=[[\"www.ewoss.com\",\"livewebcams.xyz\"[...]
[C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js] [Preference] Gefunden : user_pref("extensions.sR1CrpMHvqE38EOj.scode", "(function(){try{if(window.location.href.indexOf(\"qjk5pds7qHY7rjC5qjn9rHC9rY\")>-1){return;}}catch(e){}try{var d=[[\"livewebcams.xyz\",\"secure.dditserv[...]
[C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\prefs.js] [Preference] Gefunden : user_pref("keyword.URL", "hxxp://websearch.thesearchpage.info/?pid=21242&r=2015/02/02&hid=5588267861785443742&lg=EN&cc=DE&unqvl=74&l=1&q=");
[C:\Users\JPMK\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Gefunden : de.ask.com
[C:\Users\JPMK\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Gefunden : WebSearch
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4773 Bytes] ########## --- --- --- Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.7 (08.18.2015:1)
OS: Windows 7 Professional N x86
Ran by JPMK on 25.08.2015 at 17:38:37,83
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0E03C56C-C742-4EA3-83EF-AE71920E2FA8}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\JPMK\Appdata\Local\{05173853-bdba-7e93-ce4c-b002cfc95882}
~~~ FireFox
Successfully deleted the following from C:\Users\JPMK\AppData\Roaming\mozilla\firefox\profiles\0ykb3sya.default\prefs.js
user_pref(extensions.eXMj6dmWrfVGARrb.url, hxxp://skybardownloadstar.net/sync2/?q=hfZ9ofhUWchEAen0rTwGqdsMg708BNmGWj8wmihGheDUojw8rdsErTaEqjgGpihIC7n0rjkErTaHrjkHqdkHtNhVCT
Emptied folder: C:\Users\JPMK\AppData\Roaming\mozilla\firefox\profiles\0ykb3sya.default\minidumps [216 files]
~~~ Chrome
[C:\Users\JPMK\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\JPMK\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\JPMK\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\JPMK\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.08.2015 at 17:45:25,29
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x86) Version:24-08-2015
durchgeführt von JPMK (Administrator) auf JPMK-PC (25-08-2015 17:51:46)
Gestartet von C:\Users\JPMK\Downloads
Geladene Profile: JPMK (Verfügbare Profile: JPMK)
Platform: Microsoft Windows 7 Professional N Service Pack 1 (X86) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [HotkeyMon] => C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe [100328 2009-09-11] (ASUSTeK Computer Inc.)
HKLM\...\Run: [HotkeyService] => C:\Program Files\EeePC\HotkeyService\HotkeyService.exe [1021424 2009-10-16] (ASUSTeK Computer Inc.)
HKLM\...\Run: [SuperHybridEngine] => C:\Program Files\EeePC\SHE\SuperHybridEngine.exe [413688 2009-09-09] (ASUSTeK Computer Inc.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [1807240 2010-08-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [1821576 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKU\S-1-5-21-2802431009-2721445263-3219878338-1000\...\Run: [Dropbox Update] => C:\Users\JPMK\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-17] (Dropbox, Inc.)
HKU\S-1-5-21-2802431009-2721445263-3219878338-1000\...0c966feabec1\InprocServer32: [Default-shell32] ACHTUNG! ====> ZeroAccess?
Startup: C:\Users\JPMK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-07-15]
ShortcutTarget: Dropbox.lnk -> C:\Users\JPMK\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2802431009-2721445263-3219878338-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-06-25] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-06-25] (Oracle Corporation)
Winsock: Catalog5 01 C:\Windows\system32\mswsock.dll [231424 2013-10-15] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{B2839927-8A4B-4CDC-92A1-DD32A7D2AB7D}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{B5EAFAFE-8A5E-4DBA-996E-2985D0D0AEB9}: [DhcpNameServer] 192.168.120.211 192.168.120.254
FireFox:
========
FF ProfilePath: C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default
FF Homepage: hxxp://www.jpmk.de
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_194.dll [2015-06-26] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll [2013-04-03] (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll [2013-06-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-06-25] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=1.1.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-02-14] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-02-14] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-02-14] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-02-14] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-02-14] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll [2011-10-26] (Nullsoft, Inc.)
FF Extension: 360 Web Shield - C:\Users\JPMK\AppData\Roaming\Mozilla\Firefox\Profiles\0ykb3sya.default\Extensions\webshield@360safe.com [2015-02-24]
Chrome:
=======
CHR dev: Chrome dev build erkannt! <======= ACHTUNG
CHR Profile: C:\Users\JPMK\AppData\Local\Google\Chrome\User Data\Default
Opera:
=======
OPR Extension: (Adguard) - C:\Users\JPMK\AppData\Roaming\Opera Software\Opera Stable\Extensions\bopfaehpakahokaelnomggbohfbimcia [2014-09-13]
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S2 AsusService; C:\Windows\System32\AsusService.exe [224680 2011-07-13] ()
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2009-05-14] (Hewlett-Packard) [Datei ist nicht signiert]
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [32568 2013-08-22] (The OpenVPN Project)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2009-05-14] (Hewlett-Packard) [Datei ist nicht signiert]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 WTGService; C:\Program Files\Verbindungsassistent\WTGService.exe [329168 2010-02-23] ()
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [11296 2009-08-04] ()
R1 AsUpIO; C:\Windows\System32\drivers\AsUpIO.sys [11832 2011-02-09] ()
S3 AsusACPI; C:\Windows\System32\DRIVERS\ASUSACPI.sys [10752 2008-04-08] (ASUSTeK Computer Inc.)
R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [94720 2010-08-18] (ELAN Microelectronics Corp.)
S3 ewsercd; C:\Windows\System32\DRIVERS\ewsercd.sys [100224 2011-12-12] (Huawei Technologies Co., Ltd.)
S3 hwusbfake; C:\Windows\System32\DRIVERS\ewusbfake.sys [103040 2011-12-12] (Huawei Technologies Co., Ltd.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2011-09-20] ( )
R3 L1E; C:\Windows\System32\DRIVERS\L1E62x86.sys [47104 2009-07-14] (Atheros Communications, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2011-09-20] (Duplex Secure Ltd.)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [42496 2011-05-10] (Apple, Inc.) [Datei ist nicht signiert]
S3 catchme; \??\C:\Users\JPMK\AppData\Local\Temp\catchme.sys [X]
S1 MpKsl8183f8b3; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CC9AB812-B9B7-4D96-BAE3-DBC927328E0B}\MpKsl8183f8b3.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-08-25 17:50 - 2015-08-25 17:51 - 01690112 _____ (Farbar) C:\Users\JPMK\Downloads\FRST.exe
2015-08-25 17:45 - 2015-08-25 17:47 - 00001842 _____ C:\Users\JPMK\Desktop\JRT.txt
2015-08-25 17:37 - 2015-08-25 17:37 - 01798576 _____ (Malwarebytes Corporation) C:\Users\JPMK\Downloads\JRT.exe
2015-08-25 17:36 - 2015-08-25 17:29 - 00000618 _____ C:\Users\JPMK\Desktop\Quarantine.log
2015-08-25 17:36 - 2015-08-25 17:28 - 00004852 _____ C:\Users\JPMK\Desktop\AdwCleaner[S1].txt
2015-08-25 17:31 - 2015-08-25 17:31 - 00005155 _____ C:\Users\JPMK\Desktop\AdwCleaner[C1].txt
2015-08-25 17:26 - 2015-08-25 17:29 - 00000000 ____D C:\AdwCleaner
2015-08-25 17:24 - 2015-08-25 17:24 - 01605632 _____ C:\Users\JPMK\Downloads\AdwCleaner_5.003.exe
2015-08-25 17:04 - 2015-08-25 17:24 - 00007406 _____ C:\Users\JPMK\Desktop\mbam.txt
2015-08-25 16:34 - 2015-08-25 17:21 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-25 16:34 - 2015-08-25 16:34 - 00001064 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-08-25 16:34 - 2015-08-25 16:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-08-25 16:34 - 2015-08-25 16:34 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-08-25 16:34 - 2015-06-18 08:41 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-25 16:34 - 2015-06-18 08:41 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-08-25 16:34 - 2015-06-18 08:41 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-08-25 16:32 - 2015-08-25 16:32 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\JPMK\Downloads\mbam-setup-2.1.8.1057.exe
2015-08-24 13:58 - 2015-08-24 13:58 - 00016786 _____ C:\ComboFix.txt
2015-08-24 09:07 - 2015-08-24 09:07 - 05635234 ____R (Swearware) C:\Users\JPMK\Desktop\ComboFix.exe
2015-08-24 08:41 - 2015-08-24 08:41 - 00000000 ____D C:\Program Files\VS Revo Group
2015-08-22 11:08 - 2015-08-22 11:08 - 305392573 _____ C:\Windows\MEMORY.DMP
2015-08-22 11:08 - 2015-08-22 11:08 - 00144928 _____ C:\Windows\Minidump\082215-19874-01.dmp
2015-08-22 10:44 - 2015-08-22 10:46 - 00032032 _____ C:\Users\JPMK\Downloads\Addition.txt
2015-08-22 10:42 - 2015-08-25 17:51 - 00011506 _____ C:\Users\JPMK\Downloads\FRST.txt
2015-08-22 10:42 - 2015-08-25 17:51 - 00000000 ____D C:\FRST
2015-08-22 10:32 - 2015-08-22 10:40 - 00000522 _____ C:\Users\JPMK\Downloads\defogger_disable.log
2015-08-22 10:32 - 2015-08-22 10:32 - 00000000 _____ C:\Users\JPMK\defogger_reenable
2015-08-19 18:06 - 2015-08-11 02:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-19 18:06 - 2015-08-11 02:20 - 19871232 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-14 13:19 - 2015-08-14 13:19 - 00000000 ____D C:\Users\JPMK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-08-12 17:40 - 2015-07-30 15:13 - 00103120 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 13:18 - 2015-07-28 22:04 - 00015808 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-08-12 13:18 - 2015-07-28 22:00 - 00952832 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-08-12 13:18 - 2015-07-28 22:00 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-08-12 13:18 - 2015-07-28 22:00 - 00598528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-08-12 13:18 - 2015-07-28 22:00 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-08-12 13:18 - 2015-07-28 22:00 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-08-12 13:18 - 2015-07-28 22:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-08-12 13:18 - 2015-07-28 21:54 - 00934400 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-08-12 13:18 - 2015-07-20 19:56 - 02943488 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-08-12 13:18 - 2015-07-20 19:56 - 02061312 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-08-12 13:18 - 2015-07-20 19:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-08-12 13:18 - 2015-07-20 19:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-08-12 13:18 - 2015-07-20 19:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-08-12 13:18 - 2015-07-20 19:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-08-12 13:18 - 2015-07-20 19:56 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-08-12 13:18 - 2015-07-20 19:56 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-08-12 13:18 - 2015-07-20 19:56 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-08-12 13:18 - 2015-07-20 19:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-08-12 13:18 - 2015-07-20 19:56 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-08-12 13:18 - 2015-07-10 19:34 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-12 13:18 - 2015-07-10 19:34 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-08-12 13:18 - 2015-07-10 19:33 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2015-08-12 13:18 - 2015-07-09 19:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-12 13:18 - 2015-07-09 19:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-12 13:18 - 2015-07-01 22:30 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-12 13:18 - 2015-07-01 22:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-08-12 13:17 - 2015-07-15 19:59 - 03989952 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-08-12 13:17 - 2015-07-15 19:59 - 03934656 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-12 13:17 - 2015-07-15 19:59 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-08-12 13:17 - 2015-07-15 19:59 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-12 13:17 - 2015-07-15 19:59 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-08-12 13:17 - 2015-07-15 19:56 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-12 13:17 - 2015-07-15 19:55 - 01159168 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-08-12 13:17 - 2015-07-15 19:55 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-08-12 13:17 - 2015-07-15 19:55 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-08-12 13:17 - 2015-07-15 19:55 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-08-12 13:17 - 2015-07-15 19:55 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-08-12 13:17 - 2015-07-15 19:55 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-08-12 13:17 - 2015-07-15 19:55 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-08-12 13:17 - 2015-07-15 19:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-08-12 13:17 - 2015-07-15 19:55 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-08-12 13:17 - 2015-07-15 19:54 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-08-12 13:17 - 2015-07-15 19:54 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-08-12 13:17 - 2015-07-15 19:54 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-08-12 13:17 - 2015-07-15 19:54 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-08-12 13:17 - 2015-07-15 19:54 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-08-12 13:17 - 2015-07-15 19:54 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-08-12 13:17 - 2015-07-15 19:54 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-08-12 13:17 - 2015-07-15 19:54 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-12 13:17 - 2015-07-15 19:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-08-12 13:17 - 2015-07-15 19:54 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-08-12 13:17 - 2015-07-15 19:54 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-08-12 13:17 - 2015-07-15 19:54 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-08-12 13:17 - 2015-07-15 19:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-08-12 13:17 - 2015-07-15 19:49 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-08-12 13:17 - 2015-07-15 19:48 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-08-12 13:17 - 2015-07-15 19:44 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-08-12 13:17 - 2015-07-15 19:44 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-08-12 13:17 - 2015-07-15 18:36 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-08-12 13:17 - 2015-07-15 18:36 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-08-12 13:17 - 2015-07-15 18:36 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-08-12 13:16 - 2015-07-30 19:57 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-08-12 13:16 - 2015-07-30 19:57 - 01251328 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-12 13:16 - 2015-07-30 19:57 - 00909824 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-12 13:16 - 2015-07-30 19:57 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-08-12 13:16 - 2015-07-30 19:57 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-12 13:16 - 2015-07-30 19:57 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-08-12 13:16 - 2015-07-30 19:57 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-08-12 13:16 - 2015-07-30 18:52 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-12 13:16 - 2015-07-30 18:49 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-12 13:16 - 2015-07-21 02:12 - 00342736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-08-12 13:16 - 2015-07-16 21:50 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-08-12 13:16 - 2015-07-16 21:43 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-08-12 13:16 - 2015-07-16 21:39 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-08-12 13:16 - 2015-07-16 21:32 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-12 13:16 - 2015-07-16 21:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-12 13:16 - 2015-07-16 21:06 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-08-12 13:16 - 2015-07-16 20:38 - 01310720 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-12 13:15 - 2015-07-16 22:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-08-12 13:15 - 2015-07-16 21:51 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-12 13:15 - 2015-07-16 21:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-08-12 13:15 - 2015-07-16 21:50 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-12 13:15 - 2015-07-16 21:49 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-08-12 13:15 - 2015-07-16 21:45 - 02279424 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-12 13:15 - 2015-07-16 21:43 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-12 13:15 - 2015-07-16 21:41 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-12 13:15 - 2015-07-16 21:39 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-12 13:15 - 2015-07-16 21:39 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-12 13:15 - 2015-07-16 21:38 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-08-12 13:15 - 2015-07-16 21:29 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-12 13:15 - 2015-07-16 21:20 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-08-12 13:15 - 2015-07-16 21:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-12 13:15 - 2015-07-16 21:17 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-12 13:15 - 2015-07-16 21:12 - 04520448 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-12 13:15 - 2015-07-16 21:10 - 12856832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-12 13:15 - 2015-07-16 21:06 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-12 13:15 - 2015-07-16 21:06 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-12 13:15 - 2015-07-16 21:05 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-08-12 13:15 - 2015-07-16 20:42 - 01951232 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-12 13:15 - 2015-07-16 20:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-08-12 13:15 - 2015-07-10 19:34 - 12875776 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-12 13:15 - 2015-05-09 20:09 - 00715200 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-08-12 13:14 - 2015-07-15 04:55 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-12 13:13 - 2015-07-15 04:55 - 01390592 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-12 13:13 - 2015-07-15 04:55 - 01241088 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-12 13:13 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-08-12 13:13 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-07-30 23:15 - 2015-08-22 11:15 - 00000946 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-08-25 17:39 - 2009-07-14 06:02 - 00028160 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-25 17:39 - 2009-07-14 06:02 - 00028160 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-25 17:34 - 2011-09-19 20:30 - 01262017 _____ C:\Windows\WindowsUpdate.log
2015-08-25 17:32 - 2015-06-17 15:20 - 00001220 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2802431009-2721445263-3219878338-1000UA.job
2015-08-25 17:32 - 2011-10-04 17:51 - 00000000 ___RD C:\Users\JPMK\Dropbox
2015-08-25 17:32 - 2011-10-04 17:45 - 00000000 ____D C:\Users\JPMK\AppData\Roaming\Dropbox
2015-08-25 17:31 - 2015-06-24 12:08 - 00001848 _____ C:\Windows\setupact.log
2015-08-25 17:31 - 2009-07-14 06:17 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-25 17:18 - 2014-01-25 12:19 - 00432440 _____ C:\Windows\PFRO.log
2015-08-25 16:34 - 2012-06-18 11:39 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-24 13:58 - 2012-07-21 22:43 - 00000000 ____D C:\Qoobox
2015-08-24 12:19 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2015-08-22 11:40 - 2010-11-20 23:03 - 01629284 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-22 11:08 - 2012-06-08 20:31 - 00000000 ____D C:\Windows\Minidump
2015-08-22 10:32 - 2011-09-19 20:35 - 00000000 ____D C:\Users\JPMK
2015-08-19 17:25 - 2013-11-27 12:50 - 00002054 ____H C:\Users\JPMK\Documents\Default.rdp
2015-08-19 13:23 - 2009-07-14 06:51 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-08-18 14:14 - 2012-08-04 21:18 - 00000000 ____D C:\Program Files\Opera
2015-08-17 12:44 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2015-08-17 11:58 - 2011-09-20 13:56 - 00000000 ____D C:\Users\JPMK\AppData\Roaming\Notepad++
2015-08-14 11:23 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-08-14 11:05 - 2014-01-25 12:19 - 00405752 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-14 11:02 - 2014-12-11 16:59 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-14 11:02 - 2014-04-30 19:05 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-08-14 11:02 - 2011-04-12 04:17 - 00000000 ____D C:\Windows\system32\Drivers\de-DE
2015-08-14 11:02 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2015-08-12 18:20 - 2011-09-20 17:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-12 18:19 - 2011-09-20 17:38 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-12 18:17 - 2011-09-20 14:37 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-12 17:56 - 2015-04-24 10:35 - 129304528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-12 17:56 - 2013-08-20 16:32 - 00000000 ____D C:\Windows\system32\MRT
2015-08-12 17:42 - 2009-07-14 04:04 - 00000513 _____ C:\Windows\win.ini
2015-08-04 13:20 - 2011-09-19 21:26 - 00000000 ____D C:\Windows\Panther
2015-08-04 13:00 - 2015-07-10 15:32 - 00000000 ____D C:\$Windows.~BT
2015-08-03 12:05 - 2015-06-17 15:20 - 00001168 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2802431009-2721445263-3219878338-1000Core.job
2015-07-30 23:15 - 2014-08-14 20:31 - 00000000 ____D C:\Users\JPMK\AppData\Local\Adobe
2015-07-30 23:15 - 2012-06-18 09:59 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-07-30 23:15 - 2012-06-18 09:59 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-07-30 14:41 - 2015-04-09 09:55 - 00000000 ___SD C:\Windows\system32\GWX
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2012-05-12 21:38 - 2012-05-31 19:20 - 0000028 _____ () C:\Users\JPMK\AppData\Roaming\PhonerLitesettings.ini
2011-09-30 17:56 - 2015-06-23 16:06 - 0006777 _____ () C:\ProgramData\hpzinstall.log
ZeroAccess:
C:\Users\JPMK\AppData\Local\{05173853-bdba-7e93-ce4c-b002cfc95882}
Einige Dateien in TEMP:
====================
C:\Users\JPMK\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmprrzfyr.dll
C:\Users\JPMK\AppData\Local\temp\sqlite3.dll
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-08-22 11:31
==================== Ende vom FRST.txt ============================ Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x86) Version:21-08-2015 03
durchgeführt von JPMK (2015-08-22 10:44:43)
Gestartet von C:\Users\JPMK\Downloads
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-2802431009-2721445263-3219878338-500 - Administrator - Disabled)
Gast (S-1-5-21-2802431009-2721445263-3219878338-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2802431009-2721445263-3219878338-1002 - Limited - Enabled)
JPMK (S-1-5-21-2802431009-2721445263-3219878338-1000 - Administrator - Enabled) => C:\Users\JPMK
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
32 Bit HP CIO Components Installer (Version: 6.1.2 - Hewlett-Packard) Hidden
7-Zip 9.22beta (HKLM\...\7-Zip) (Version: - )
Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.194 - Adobe Systems Incorporated)
Adobe Flash Player 18 PPAPI (HKLM\...\Adobe Flash Player PPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.)
Apple Application Support (HKLM\...\{F5266D28-E0B2-4130-BFC5-EE155AD514DC}) (Version: 2.3 - Apple Inc.)
ASUSUpdate (HKLM\...\{587178E7-B1DF-494E-9838-FA4DD36E873C}) (Version: 7.18.03 - ASUSTeK Computer Inc.)
Audible Download Manager (HKLM\...\AudibleDownloadManager) (Version: 6.6.0.15 - Audible, Inc.)
BoxyGen (HKLM\...\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{dd693f9b}) (Version: - BoxyGen) <==== ACHTUNG
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
CrystalDiskInfo 4.0.2 (HKLM\...\CrystalDiskInfo_is1) (Version: 4.0.2 - Crystal Dew World)
DesignPro 5 (Version: 5.5.708 - Avery Dennison) Hidden
Dropbox (HKU\S-1-5-21-2802431009-2721445263-3219878338-1000\...\Dropbox) (Version: 3.8.6 - Dropbox, Inc.)
ETDWare PS/2-X86 7.0.5.14_WHQL (HKLM\...\Elantech) (Version: 7.0.5.14 - ELAN Microelectronic Corp.)
EVEREST Home Edition v2.20 (HKLM\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc)
FreePDF (Remove only) (HKLM\...\FreePDF_XP) (Version: - )
GPL Ghostscript 8.70 (HKLM\...\GPL Ghostscript 8.70) (Version: - )
Hotkey Service (HKLM\...\{71C0E38E-09F2-4386-9977-404D4F6640CD}) (Version: 1.15 - AsusTek Computer)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
Java 7 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft IntelliPoint 8.2 (HKLM\...\Microsoft IntelliPoint 8.2) (Version: 8.20.468.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 39.0 (x86 de) (HKLM\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Notepad++ (HKLM\...\Notepad++) (Version: 5.9.3 - )
OpenVPN 2.3.2-I003 (HKLM\...\OpenVPN) (Version: 2.3.2-I003 - )
Opera Stable 31.0.1889.174 (HKLM\...\Opera 31.0.1889.174) (Version: 31.0.1889.174 - Opera Software)
PhonerLite 1.95 (HKLM\...\PhonerLite_is1) (Version: 1.95 - sipgate GmbH)
QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Super Hybrid Engine (HKLM\...\{88F08F98-12BC-4613-81A2-8F9B88CFC73E}) (Version: 2.09 - AsusTek Computer)
SuperMailer 7.03 (HKLM\...\Newsletter Software SuperMailer_is1) (Version: 7.03 - Mirko Boeer Softwareentwicklungen)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - )
The AdBlocker (HKLM\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - The AdBlocker) <==== ACHTUNG
Vaudiix (HKLM\...\{681002C6-5019-81A2-7871-A43754F71E56}) (Version: - Vaudix) <==== ACHTUNG
Verbindungsassistent (HKLM\...\Verbindungsassistent) (Version: 2.1 - Verbindungsassistent)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Winamp (HKLM\...\Winamp) (Version: 5.622 - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKU\S-1-5-21-2802431009-2721445263-3219878338-1000\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\JPMK\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Users\JPMK\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\JPMK\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\JPMK\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\JPMK\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\JPMK\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\JPMK\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\JPMK\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll Keine Datei
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\localserver32 -> C:\Users\JPMK\AppData\Local\Temp\Cce8b929B8a11\temp\Download.exe Keine Datei
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\JPMK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2802431009-2721445263-3219878338-1000_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\JPMK\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)
==================== Wiederherstellungspunkte =========================
15-07-2015 16:04:56 Windows Update
17-07-2015 14:58:41 Windows Update
31-07-2015 00:47:55 Geplanter Prüfpunkt
31-07-2015 02:05:32 Windows Update
04-08-2015 12:17:52 Windows Update
07-08-2015 13:14:28 Windows Update
12-08-2015 17:36:21 Windows Update
17-08-2015 12:00:38 Windows Update
19-08-2015 18:05:51 Windows Update
==================== Hosts Inhalt: ==========================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2009-07-14 04:04 - 2012-07-21 23:08 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {09E939BB-9F02-44AA-8D68-7CE6190A336A} - System32\Tasks\Opera scheduled Autoupdate 1390644265 => C:\Program Files\Opera\launcher.exe [2015-08-17] (Opera Software)
Task: {20119DB6-1614-4D5F-9543-07F1073A6067} - System32\Tasks\{60BF42AD-07B3-482E-B8EA-EE908ECF543B} => pcalua.exe -a "C:\ProgramData\The AdBlocker\The AdBlocker.exe" -c /progname=The AdBlocker /progver=3.4.2 /progpub=The AdBlocker /proguninstallurl=asdahjka.com /deleteappfolder=0 /VERYSILENT
Task: {29AD6E70-8C0B-466C-88C0-A788833DBC21} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {2D48C6DC-EAB7-494F-A1C0-9AA1EE9DA1FE} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2802431009-2721445263-3219878338-1000UA => C:\Users\JPMK\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17] (Dropbox, Inc.)
Task: {786259ED-CC57-4AED-9765-50A78D7D5DD7} - System32\Tasks\{BF3B84D4-E7F2-459C-82C2-1273669C8BB1} => Firefox.exe hxxp://ui.skype.com/ui/0/6.14.60.104/de/abandoninstall?page=tsProgressBar
Task: {79DE96A6-9BFB-4543-A0C8-301B0CFD860F} - System32\Tasks\SUPERAntiSpyware Scheduled Task 93571adc-355b-430e-af9d-dcadfbada7f7 => C:\Program Files\SUPERAntiSpyware\SASTask.exe
Task: {8033D5A8-0DEA-45FB-B796-4D1C55704E57} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2802431009-2721445263-3219878338-1000Core => C:\Users\JPMK\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17] (Dropbox, Inc.)
Task: {803BAE99-B553-46D2-BE44-A932B6E07EC6} - System32\Tasks\ASUS\ASUS Update Checker => C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe [2009-12-28] (ASUSTeK Computer Inc.)
Task: {8A828015-5F12-4E66-934C-4EB974FAFE8A} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {A73F9F01-8286-43CC-8618-9355E669AB67} - System32\Tasks\SUPERAntiSpyware Scheduled Task 4cc4769d-f0ed-4185-9b29-c8cb21518a2d => C:\Program Files\SUPERAntiSpyware\SASTask.exe
Task: {A91D650D-8BBB-4DEB-BEA9-DC521554B09D} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => c:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-08-01] (Microsoft Corporation)
Task: {ED6A962C-6350-46DD-95A4-1C1A5A5512BB} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\system32\Macromed\Flash\FlashUtil32_18_0_0_209_pepper.exe [2015-07-30] (Adobe Systems Incorporated)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\system32\Macromed\Flash\FlashUtil32_18_0_0_209_pepper.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2802431009-2721445263-3219878338-1000Core.job => C:\Users\JPMK\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2802431009-2721445263-3219878338-1000UA.job => C:\Users\JPMK\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 4cc4769d-f0ed-4185-9b29-c8cb21518a2d.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 93571adc-355b-430e-af9d-dcadfbada7f7.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2011-09-20 10:24 - 2005-01-06 18:33 - 00116224 _____ () C:\Windows\System32\redmonnt.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2011-09-19 20:48 - 2011-07-13 09:38 - 00224680 _____ () C:\Windows\System32\AsusService.exe
2015-08-22 09:53 - 2015-08-22 09:53 - 00071168 _____ () c:\users\jpmk\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpo7lvyk.dll
2015-08-14 13:19 - 2015-08-05 22:49 - 00012800 _____ () C:\Users\JPMK\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll
2015-07-15 13:04 - 2015-08-05 22:49 - 00779776 _____ () C:\Users\JPMK\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-08-14 13:19 - 2015-08-05 22:49 - 00056320 _____ () C:\Users\JPMK\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-08-14 13:19 - 2015-08-05 22:49 - 00012288 _____ () C:\Users\JPMK\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll
2011-12-12 10:53 - 2010-02-23 12:01 - 00329168 ____N () C:\Program Files\Verbindungsassistent\WTGService.exe
2015-08-22 10:31 - 2015-08-22 10:32 - 00050477 _____ () C:\Users\JPMK\Downloads\Defogger.exe
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-2802431009-2721445263-3219878338-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\JPMK\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Datenträger ist nicht mit dem Internet verbunden.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: ) (ConsentPromptBehaviorUser: ) (EnableLUA: )
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Audible Download Manager.lnk => C:\Windows\pss\Audible Download Manager.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Google Calendar Sync.lnk => C:\Windows\pss\Google Calendar Sync.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: FreePDF Assistant => C:\Program Files\FreePDF_XP\fpassist.exe
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: WinampAgent => "C:\Program Files\Winamp\winampa.exe"
==================== FirewallRules (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [WMP-In-UDP-x86] => (Allow) %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe
FirewallRules: [WMP-Out-UDP-x86] => (Allow) %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe
FirewallRules: [WMP-Out-TCP-x86] => (Allow) %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe
FirewallRules: [{E926E57D-011D-4F63-BCC5-FFCFDC28D091}] => (Allow) %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe
FirewallRules: [{CE504808-152F-4073-8BB9-0F8E7C4D30C6}] => (Allow) %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe
FirewallRules: [{AB3FBA72-52C3-4476-9A38-230DBE05659B}] => (Allow) %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe
FirewallRules: [{8E644689-0B18-4959-B6E4-8182FB08D4F9}] => (Allow) C:\Program Files\Opera\opera.exe
FirewallRules: [{0C4778F2-1EAA-48DD-8956-39F99FDECAD1}] => (Allow) C:\Program Files\Opera\opera.exe
FirewallRules: [TCP Query User{EA31FE1F-A7F7-480C-B817-1D5A3DFFE00A}C:\program files\phonerlite\phonerlite.exe] => (Allow) C:\program files\phonerlite\phonerlite.exe
FirewallRules: [UDP Query User{D5428F10-2A02-4210-9D3E-41821FAF887F}C:\program files\phonerlite\phonerlite.exe] => (Allow) C:\program files\phonerlite\phonerlite.exe
FirewallRules: [{251291AE-16A5-4C31-8BB1-4EE850C577F0}] => (Allow) C:\Program Files\Opera\opera.exe
FirewallRules: [{C693F284-C4C1-4334-B5A3-77F9F168538F}] => (Allow) C:\Program Files\Opera\opera.exe
FirewallRules: [TCP Query User{9B1E2630-F73F-4F02-BD66-D371DAEE7113}C:\program files\winamp\winamp.exe] => (Block) C:\program files\winamp\winamp.exe
FirewallRules: [UDP Query User{BA464C09-C826-4EF9-AB15-49FF25EE2852}C:\program files\winamp\winamp.exe] => (Block) C:\program files\winamp\winamp.exe
FirewallRules: [TCP Query User{0FA39756-E630-4457-8CAE-7B9E96004DCB}C:\program files\winamp\winamp.exe] => (Block) C:\program files\winamp\winamp.exe
FirewallRules: [UDP Query User{BD4AEE2B-A0C3-4491-98F9-9D52897F85BA}C:\program files\winamp\winamp.exe] => (Block) C:\program files\winamp\winamp.exe
FirewallRules: [{686F00C3-41C8-4F88-BCC2-76AE4FD17D5F}] => (Allow) C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{FAB3964F-E824-4E86-809D-1D7F92401658}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{D82ECA1C-2EA7-420F-B711-4D7A026D810B}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{9B19CA83-A8E3-4540-B8F1-B61F76925247}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{3ADD1F3C-1DFE-4328-894E-E47CDFB35CF1}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{6FBD2CFB-06BB-4E00-95E5-AEC3EA5F5AAA}C:\users\jpmk\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\jpmk\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{BEBB0234-0B34-44DD-B694-767F85B24AA3}C:\users\jpmk\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\jpmk\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{CA6BDE61-AF57-4E0A-81A3-F15F3F95A720}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{B689EBB4-1BEE-4027-B64B-0CD1304736E9}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [TCP Query User{506C047A-3DCD-41B3-9CFB-D3EB2CC89E8B}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{400B4F17-3F21-4CCE-9191-C6C7FEEF5E96}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{CDE8E1F9-571E-4214-AFD1-509E8CD22360}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{A298CF85-A33F-4D42-B0AF-2B5D7E9DFB21}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (08/22/2015 09:53:47 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/19/2015 12:52:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/18/2015 02:07:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/18/2015 10:22:01 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/17/2015 11:56:49 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/14/2015 11:05:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/12/2015 11:27:36 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/12/2015 09:09:17 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/07/2015 01:04:33 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/05/2015 09:22:22 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Systemfehler:
=============
Error: (08/22/2015 10:18:15 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80240020 fehlgeschlagen: Upgrade auf Windows 10 Pro N
Error: (08/22/2015 09:53:40 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (08/19/2015 01:00:11 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80240020 fehlgeschlagen: Upgrade auf Windows 10 Pro N
Error: (08/19/2015 12:52:50 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (08/18/2015 02:07:12 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (08/18/2015 10:40:25 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80240020 fehlgeschlagen: Upgrade auf Windows 10 Pro N
Error: (08/18/2015 10:22:03 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (08/17/2015 12:06:59 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80240020 fehlgeschlagen: Upgrade auf Windows 10 Pro N
Error: (08/17/2015 12:05:47 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80240020 fehlgeschlagen: Upgrade auf Windows 10 Pro N
Error: (08/17/2015 11:56:34 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Microsoft Office:
=========================
Error: (08/22/2015 09:53:47 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/19/2015 12:52:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/18/2015 02:07:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/18/2015 10:22:01 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/17/2015 11:56:49 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/14/2015 11:05:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/12/2015 11:27:36 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/12/2015 09:09:17 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/07/2015 01:04:33 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/05/2015 09:22:22 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Processor: Intel(R) Atom(TM) CPU N270 @ 1.60GHz
Prozentuale Nutzung des RAM: 54%
Installierter physikalischer RAM: 2039.24 MB
Verfügbarer physikalischer RAM: 935.69 MB
Summe virtueller Speicher: 4078.48 MB
Verfügbarer virtueller Speicher: 2794.79 MB
==================== Laufwerke ================================
Drive c: () (Fixed) (Total:297.99 GB) (Free:226.07 GB) NTFS
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: D2C16FE5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)
==================== Ende vom raportu ============================ Besen Dank!!!
Bin gespannt auf Dein Feedback.
LG
gofurther |