Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: general crawlers

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 13.01.2015, 19:05   #1
dms3333
 
general crawlers - Standard

general crawlers



Guten Tag

ich wollte gern erfragen was "general crawlers" sind , steht zwar viel bei google , aber dann auch wieder nichts , mal sind sie gefährlich und man soll was zum entfernen runterladen und kaufen , mal sind sie notwendig oder mindestens egal .????

Keine Ahnung , bei chrome hat sich was geändert und als ich von "Profil 1" zu "Cocktail" gewechselt bin , bekam ich den Hinweis das "general crawlers" geschlossen wurde .

Keine Ahnung was das bedeuted .

danke im voraus + m.f.g.

Alt 13.01.2015, 19:10   #2
schrauber
/// the machine
/// TB-Ausbilder
 

general crawlers - Standard

general crawlers



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 19.01.2015, 17:30   #3
dms3333
 
general crawlers - Standard

general crawlers



Hallo

O.K. ich mach das mal , danke für den Tipp .

m.f.g.

first datei
FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-01-2015
Ran by dirkdererste (administrator) on DIRKDERERSTE-PC on 19-01-2015 17:25:32
Running from C:\Users\dirkdererste\Downloads
Loaded Profiles: dirkdererste (Available profiles: dirkdererste)
Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files\ATK Hotkey\ASLDRSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
() C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVerMedia) C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
() C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe
(Microsoft Corp.) C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
(AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ATK0100) C:\Program Files\ATK Hotkey\HControl.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.25.11\GoogleCrashHandler.exe
() C:\Program Files\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Windows\System32\ASUSTPE.exe
(ASUS) C:\Program Files\ASUS\ASUS CopyProtect\ASPG.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
() C:\Program Files\ATK Hotkey\ATKOSD.exe
() C:\Program Files\ATK Hotkey\KBFiltr.exe
(AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4853760 2008-01-07] (Realtek Semiconductor)
HKLM\...\Run: [ASUSTPE] => C:\Windows\system32\ASUSTPE.exe [106496 2007-10-12] (ASUS)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguix.exe [1133584 2014-11-28] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-01-06] (Google Inc.)
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19ab7c-cbab-11e3-b7e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abdb-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abe7-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe8a-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe92-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe9e-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5dd-d506-11e3-befd-c030a9561ac3} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5e9-d506-11e3-befd-b68ac94258b5} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {31011372-66a4-11e4-88f4-adb511af100e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b50-3846-11e4-b727-a594aa94d86e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b5b-3846-11e4-b727-cfe712892541} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4235e5bc-8deb-11e3-bea2-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd209-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd244-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd24e-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd256-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd262-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb3442b-1faf-11e4-94c1-9483cebc1803} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb34437-1faf-11e4-94c1-ebf9039c5468} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5061e-2d56-11e4-806c-82b39df6fe7f} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5063d-2d56-11e4-806c-ff8e48defdcd} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {5899778b-f65b-11e3-908a-fe702680487d} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {589977db-f65b-11e3-908a-d444832a8c51} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7534b009-f659-11e3-935b-983f9ae39f7f} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba568-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba588-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {84d86f73-ebcf-11e3-99f4-e91098103f7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c282-3821-11e4-ac47-8fad69652c89} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c28d-3821-11e4-ac47-98a026ee637b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {8918ebcd-f632-11e3-a4cc-aae446c3b7d9} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {98b2279a-f666-11e3-82bf-8691ac93757f} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9d60af46-6833-11e4-9ae1-81f053ff7d7b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f017-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f054-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247885d-d82f-11e3-afed-ff56e36041fd} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247889a-d82f-11e3-afed-987030581f5d} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {b4a4281b-2f93-11e4-a053-b7ed9dff2029} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {ca5b6dde-19e3-11e0-83b8-806e6f6e6963} - E:\Autorun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {d85a1d2a-462a-11e4-94c3-8888219aad9a} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {db596716-c7e8-11e3-bdee-001e101fe70e} - I:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f01bf-2e39-11e4-b425-806e6f6e6963} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f0200-2e39-11e4-b425-c3e18252350b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {faf8fc99-6d70-11e4-b1d1-f474d68c3f10} - F:\AutoRun.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=BDKTDF&PC=BDT3&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = hxxp://start.gamesagogo.iplay.com/searchresultsredirect.aspx?o=chrome&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {47511E21-1A74-42AF-93B1-2D31D99E032B} URL = hxxp://de.wikipedia.org/wiki/Spezial:Search?search={searchTerms}
SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {7B240E59-FCB8-4F40-9C17-688AC4BBDB6A} URL = hxxp://rover.ebay.com/rover/1/707-37276-23097-0/4?satitle={searchTerms}
SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = hxxp://www2.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80772&lng=de
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Babylon Toolbar - {41B62AD3-5D43-40D1-9D43-F3539C1DB452} -  No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Toolbar: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} -  No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1

FireFox:
========
FF Plugin: @adobe.com/AuthorwarePlayer -> C:\WINDOWS\system32\Macromed\AUTHORWA\np32asw.dll (Macromedia, Inc.)
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1588098070-3651612994-842810468-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
FF Extension: No Name - C:\Users\dirkdererste\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com [2012-03-02]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-01-06]
FF HKLM\...\Firefox\Extensions: [quick_start@gmail.com] - C:\Users\dirkdererste\AppData\Roaming\Mozilla\Firefox\Profiles\5itzr609.default\extensions\quick_start@gmail.com

Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.ergebnisselive.de/"
CHR Profile: C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-21]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-07]
CHR Extension: (YouTube) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-21]
CHR Extension: (Google-Suche) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-16]
CHR Extension: (Google Wallet) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Google Mail) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-16]
CHR Profile: C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-13]
CHR Extension: (YouTube) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-19]
CHR Extension: (Google-Suche) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-19]
CHR Extension: (Value apps) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon [2014-03-20]
CHR Extension: (Google Wallet) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-13]
CHR Extension: (Google Mail) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-19]
CHR HKLM\...\Chrome\Extension: [aacbndibbcpajfgnkdkaakeiojmmgmnk] - C:\Users\dirkdererste\AppData\Roaming\Media Finder\Extensions\mf_plugin_gc.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [jpihmmhdcobmllpcnpfbhnipmhamldje] - C:\Users\dirkdererste\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-21]
CHR HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\DIRKDE~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [Not Found]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ALDITALKVerbindungsassistent_Service; C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [342984 2011-09-13] ()
R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () [File not signed]
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed]
R2 AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [339968 2008-03-13] (AVerMedia) [File not signed]
R2 AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [380928 2008-03-05] () [File not signed]
R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [696848 2014-11-28] (AVG Technologies CZ, s.r.o.)
R2 BingDesktopUpdate; C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-20] (Microsoft Corp.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2165560 2014-11-24] (AVG Technologies)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [35640 2014-11-24] (AVG Technologies)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
S3 ASPI; C:\Windows\System32\DRIVERS\ASPI32.sys [84832 2002-07-17] (Adaptec) [File not signed]
S3 AVerFx2hbtv; C:\Windows\System32\drivers\AVerFx2hbtv.sys [437888 2009-12-08] (AVerMedia TECHNOLOGIES, Inc.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( )
R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1772544 2008-05-22] ()
S3 tosporte; C:\Windows\System32\DRIVERS\tosporte.sys [41600 2006-10-10] (TOSHIBA Corporation) [File not signed]
S3 tosrfbd; C:\Windows\System32\DRIVERS\tosrfbd.sys [113792 2006-11-30] (TOSHIBA CORPORATION) [File not signed]
S3 tosrfbnp; C:\Windows\System32\Drivers\tosrfbnp.sys [36480 2006-11-20] (TOSHIBA Corporation) [File not signed]
S1 Tosrfcom; C:\Windows\System32\Drivers\tosrfcom.sys [64896 2005-08-01] (TOSHIBA Corporation) [File not signed]
S3 Tosrfhid; C:\Windows\System32\DRIVERS\Tosrfhid.sys [73600 2006-10-05] (TOSHIBA Corporation.) [File not signed]
S3 tosrfnds; C:\Windows\System32\DRIVERS\tosrfnds.sys [18612 2005-01-06] (TOSHIBA Corporation.) [File not signed]
S3 TosRfSnd; C:\Windows\System32\drivers\tosrfsnd.sys [53504 2006-11-02] (TOSHIBA Corporation) [File not signed]
S3 Tosrfusb; C:\Windows\System32\DRIVERS\tosrfusb.sys [40960 2006-10-27] (TOSHIBA CORPORATION) [File not signed]
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [12320 2014-08-28] (TuneUp Software)
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 HTCAND32; System32\Drivers\ANDROIDUSB.sys [X]
S3 hwusbfake; No ImagePath
S3 IpInIp; No ImagePath
S3 motmodem; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath
S3 usbbus; system32\DRIVERS\lgusbbus.sys [X]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X]
S3 USBModem; system32\DRIVERS\lgusbmodem.sys [X]
S3 VNUSB; system32\DRIVERS\VNUSB.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-19 17:25 - 2015-01-19 17:26 - 00024705 _____ () C:\Users\dirkdererste\Downloads\FRST.txt
2015-01-19 17:25 - 2015-01-19 17:25 - 00000000 ____D () C:\FRST
2015-01-19 17:24 - 2015-01-19 17:24 - 01118208 _____ (Farbar) C:\Users\dirkdererste\Downloads\FRST.exe
2015-01-18 09:43 - 2015-01-18 09:43 - 00002980 _____ () C:\Windows\PFRO.log
2015-01-17 18:00 - 2015-01-17 18:05 - 00000189 _____ () C:\Users\dirkdererste\Desktop\DAMEN.txt
2015-01-14 19:40 - 2015-01-14 19:40 - 05013680 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2015-01-14 17:28 - 2014-12-19 01:25 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 17:12 - 2014-12-06 04:14 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 17:12 - 2014-12-06 04:14 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 17:12 - 2014-12-06 04:14 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 17:12 - 2014-12-06 04:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-12 18:30 - 2015-01-12 18:36 - 00000022 _____ () C:\Users\dirkdererste\Downloads\Gmail.zip
2015-01-10 13:13 - 2015-01-10 13:13 - 00012602 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvv-2FbgLWtxKiUPAnNHg9Ex7XJiyYrBIUKWniOSaYy513hlfagHce8Y9q2fBnUi46j8LMJiN4Ibo0jYqNA5K4b4-2BrIkMFz4DmX-2BQqOw6O-2BALSXByyiQFSdvPgiEF8YKq1mRsmIvzrESP5BopAg0olkOxyP-2FBKvXhu1j
2015-01-10 13:13 - 2015-01-10 13:13 - 00006172 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvvsJzMbrsjw5UKW3z-2Bs2dvjRlPojiGebXy7e5eGczAbLu-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FO3NCXbmNOMaTkWVyij4LGMR
2015-01-10 13:12 - 2015-01-10 13:12 - 00014005 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvszYSjXqZ0eKiFnXjlLTe-2BMizo92Hdw-2BByllGk1G2Tgge-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FbWYBnp7TdSaoQHTs8HCgK
2015-01-10 13:12 - 2015-01-10 13:12 - 00014005 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvszYSjXqZ0eKiFnXjlLTe-2BMizo92Hdw-2BByllGk1G2Tgge-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FbWYBnp7TdSaoQHTs8 (1)
2015-01-10 13:11 - 2015-01-10 13:11 - 00006448 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvuNQjNdmO9DbIZqVdhXDmcImLLl-2FMJgwS5ROnb8F4Ar8-2B-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FO3NCXbmNOMaTkWVyij4LG
2015-01-06 20:46 - 2015-01-06 20:46 - 00001063 _____ () C:\Users\dirkdererste\Desktop\MAST.txt
2015-01-06 18:21 - 2015-01-06 18:21 - 00000864 _____ () C:\Users\dirkdererste\Desktop\DHL.txt
2015-01-02 13:14 - 2015-01-02 13:14 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\Amazon
2014-12-26 15:09 - 2014-12-26 15:16 - 00000122 _____ () C:\Users\dirkdererste\Desktop\TomTom Start 50EU Navigationsgerät 13 cm 5 Zoll Europa.txt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-19 17:25 - 2011-01-06 20:20 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-19 17:22 - 2006-11-02 13:47 - 00003616 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-19 17:22 - 2006-11-02 13:47 - 00003616 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-19 17:00 - 2014-03-24 23:00 - 01078984 _____ () C:\Windows\WindowsUpdate.log
2015-01-19 16:43 - 2011-01-06 20:20 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-19 16:42 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-18 21:50 - 2014-06-12 23:47 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-01-18 18:39 - 2012-07-16 10:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-18 18:36 - 2014-09-03 18:24 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\vlc
2015-01-18 18:25 - 2012-12-29 18:25 - 00000392 _____ () C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
2015-01-18 02:54 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\tracing
2015-01-16 13:04 - 2006-11-02 11:33 - 01543880 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-15 22:52 - 2012-07-27 19:58 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\Canon
2015-01-15 20:45 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-01-15 17:53 - 2014-11-02 10:34 - 00000000 ____D () C:\Users\dirkdererste\Desktop\Neuer Ordner
2015-01-15 00:38 - 2014-06-27 14:57 - 00000000 ____D () C:\Users\dirkdererste\Documents\AVerTV
2015-01-14 19:41 - 2012-04-08 09:03 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-01-14 19:41 - 2011-05-21 12:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-01-14 18:09 - 2014-11-05 18:03 - 00000000 ____D () C:\Users\dirkdererste\Desktop\Bewerbungszeug
2015-01-14 17:28 - 2013-07-19 12:23 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 17:13 - 2006-11-02 11:24 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-01-12 23:59 - 2011-01-07 15:25 - 00000000 ___RD () C:\Users\dirkdererste\Desktop\Kram
2015-01-12 17:02 - 2013-08-17 11:28 - 00000000 ____D () C:\Users\dirkdererste\AppData\Local\Freenet
2015-01-02 14:40 - 2011-01-07 15:36 - 00000000 ___RD () C:\Users\dirkdererste\Desktop\Mein Ordner
2014-12-31 12:13 - 2011-01-06 19:02 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-12-28 11:29 - 2011-01-06 21:31 - 00000000 ____D () C:\Users\dirkdererste\AppData\Local\Adobe

==================== Files in the root of some directories =======
2007-06-12 19:34 - 2007-06-12 19:34 - 0035822 _____ () C:\Program Files\Common Files\ASPG_icon.ico
2008-05-22 18:35 - 2008-05-22 18:35 - 0051962 _____ () C:\Program Files\Common Files\banner.jpg
2008-07-02 04:28 - 2008-07-02 04:28 - 0061440 _____ () C:\Program Files\Common Files\CPInstallAction.dll
2011-10-30 00:00 - 2011-10-30 00:00 - 0024206 _____ () C:\Users\dirkdererste\AppData\Roaming\UserTile.png
2014-09-27 14:04 - 2014-09-27 14:05 - 0010828 _____ () C:\Users\dirkdererste\AppData\Roaming\WtgInstaller.txt
2011-01-06 20:24 - 2014-08-27 22:09 - 0001356 _____ () C:\Users\dirkdererste\AppData\Local\d3d9caps.dat
2011-01-07 14:57 - 2014-12-07 14:50 - 0020480 _____ () C:\Users\dirkdererste\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-03-21 16:25 - 2014-03-21 16:25 - 1172736 _____ (AnyProtect.com) C:\Users\dirkdererste\AppData\Local\nss61AF.tmp
2011-11-21 21:46 - 2011-11-21 21:46 - 0000000 _____ () C:\Users\dirkdererste\AppData\Local\{0CE875FA-9C01-4FE6-91E4-8DD35D1352B1}

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-19 16:50

==================== End Of Log ============================
         
--- --- ---

--- --- ---

--- --- ---

addition dateiFRST Additions Logfile:
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-01-2015
Ran by dirkdererste at 2015-01-19 17:26:53
Running from C:\Users\dirkdererste\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.257 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.257 - Adobe Systems Incorporated)
Adobe Reader X (10.1.13) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.13 - Adobe Systems Incorporated)
Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
AVerMedia A827 series driver 1.0.0.70 (HKLM\...\AVerMedia A827 series driver) (Version: 1.0.0.70 - AVerMedia TECHNOLOGIES, Inc.)
AVerMedia MCE Encoder 3.2.1.81 (HKLM\...\AVerMedia MCE Encoder) (Version: 3.2.1.81 - AVerMedia Technologies, Inc.)
AVerTV (HKLM\...\InstallShield_{E28B1E6F-E0AA-4228-AB89-DB4A0C89D426}) (Version: 6.0.12 - AVerMedia Technologies, Inc.)
AVerTV (Version: 6.0.12 - AVerMedia Technologies, Inc.) Hidden
AVG (HKLM\...\AvgZen) (Version: 1.0.445 - AVG Technologies)
AVG PC TuneUp 2015 (de-DE) (Version: 15.0.1001.238 - AVG Technologies) Hidden
AVG PC TuneUp 2015 (HKLM\...\AVG PC TuneUp) (Version: 15.0.1001.238 - AVG Technologies)
AVG PC TuneUp 2015 (Version: 15.0.1001.238 - AVG Technologies) Hidden
AVG Zen (Version: 1.0.445 - AVG Technologies) Hidden
FMW 1 (Version: 1.0.307 - AVG Technologies) Hidden
Freenet (HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Freenet) (Version:  - )
Google Chrome (HKLM\...\Google Chrome) (Version: 39.0.2171.99 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Mobile Broadband HL Service (HKLM\...\Mobile Broadband HL Service) (Version: 22.001.21.00.03 - Huawei Technologies Co.,Ltd)
Mobile Partner (HKLM\...\Mobile Partner) (Version: 16.002.03.01.40 - Huawei Technologies Co.,Ltd)
NAVIGON Fresh 3.5.1 (HKLM\...\NAVIGON Fresh) (Version: 3.5.1 - NAVIGON)
OpenOffice 4.1.0 (HKLM\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation)
TuneUp Utilities 2014 (de-DE) (Version: 14.0.1000.340 - TuneUp Software) Hidden
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{30A2652A-DDF7-45e7-ACA6-3EAB26FC8A4E}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{3f04dadf-6ea4-44d1-a507-03cad176f443}\InprocServer32 -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{41662FC2-0D57-4aff-AB27-AD2E12E7C273}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{448BB771-CFE2-47C4-BCDF-1FBF378E202C}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{7B342DC4-139A-4a46-8A93-DB0827CCEE9C}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\ooofilt.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{7FA8AE11-B3E3-4D88-AABF-255526CD1CE8}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{82154420-0FBF-11d4-8313-005004526AB4}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\propertyhdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{D0484DE6-AAEE-468a-991F-8D4B0737B57A}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{D2D59CD1-0A6A-4D36-AE20-47817077D57C}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{E5A0B632-DFBA-4549-9346-E414DA06E6F8}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{EE5D1EA4-D445-4289-B2FC-55FC93693917}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-1588098070-3651612994-842810468-1000_Classes\CLSID\{F616B81F-7BB8-4F22-B8A5-47428D59F8AD}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)

==================== Restore Points  =========================

16-01-2015 12:55:14 Windows Update
19-01-2015 16:55:09 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0912621A-00EC-4657-B9C6-8CEF5AA7DE79} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {0F30378C-16D5-4D3C-9D9C-59D4EA31F027} - System32\Tasks\FreeFileViewerUpdateChecker => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe [2012-10-13] (Bitberry Software) <==== ATTENTION
Task: {2004BDA4-28F1-4AE2-A2F1-8FC040BCC7B2} - System32\Tasks\Java(TM) Platform SE Auto Updater => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-09-26] (Oracle Corporation)
Task: {2227E28C-1A6A-4497-A69F-6944008C63DB} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {2D94D193-F98A-4DA2-B1BD-269A1A326B6F} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
Task: {479725C9-39E6-4667-917E-51ACAFA39A71} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd)
Task: {5BE27D58-1E5F-473A-9CA5-8828F1F7CCC5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: {7164F5F3-C504-40DF-9606-A00DF5D617EC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: {930061BF-B9A9-4095-84E0-0057E6798C68} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-14] (Adobe Systems Incorporated)
Task: {942306DB-F2AE-4AE2-86B2-35EBAD5CEF4D} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files\ASUS\SmartLogon\sensorsrv.exe [2008-06-18] (ASUS)
Task: {96F069A3-86B8-4EFE-B037-9E1C83FAF801} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {E4527CC0-ADE5-4F5B-B11A-0D5387AC057E} - System32\Tasks\Software Updater => D:\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe [2014-01-29] () <==== ATTENTION
Task: {E8D3CCEC-638E-46AD-80EA-92DA2943AFA3} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\AVG\AVG PC TuneUp\OneClick.exe [2014-11-24] (AVG Technologies)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FreeFileViewerUpdateChecker.job => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-01-06 23:54 - 2007-02-06 03:13 - 00094208 _____ () C:\Program Files\ATK Hotkey\ASLDRSrv.exe
2011-01-07 00:24 - 2007-08-08 09:08 - 00094208 _____ () C:\Program Files\ATKGFNEX\GFNEXSrv.exe
2014-09-27 14:05 - 2011-09-13 09:16 - 00342984 ____N () C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-06-27 14:55 - 2008-03-05 18:13 - 00380928 ____R () C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
2014-11-10 17:53 - 2013-07-23 04:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2012-12-29 20:05 - 2012-12-07 17:26 - 00167424 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
2011-01-07 00:23 - 2008-06-10 15:13 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll
2014-11-24 12:48 - 2014-11-24 12:48 - 00604472 _____ () C:\Program Files\AVG\AVG PC TuneUp\avgreplibx.dll
2011-01-06 23:54 - 2004-05-28 03:13 - 00057344 _____ () C:\Program Files\ATK Hotkey\CMSSC.dll
2011-01-06 23:55 - 2007-01-18 04:26 - 07708672 _____ () C:\Program Files\ATKOSD2\ATKOSD2.exe
2014-09-19 19:45 - 2014-09-19 19:45 - 31842816 _____ () C:\Program Files\AVG\Framework\Common\libcef.dll
2011-01-06 23:54 - 2006-12-19 02:26 - 02420736 _____ () C:\Program Files\ATK Hotkey\ATKOSD.exe
2011-01-06 23:54 - 2007-04-17 22:39 - 00077824 _____ () C:\Program Files\ATK Hotkey\KBFiltr.exe
2014-11-24 12:49 - 2014-11-24 12:49 - 00730936 _____ () C:\Program Files\AVG\AVG PC TuneUp\tulngx.dll
2015-01-16 02:27 - 2015-01-09 01:35 - 09009480 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.99\pdf.dll
2015-01-16 02:27 - 2015-01-09 01:35 - 01677128 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.99\ffmpegsumo.dll
2015-01-16 02:27 - 2015-01-09 01:35 - 14913352 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.99\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-1588098070-3651612994-842810468-500 - Administrator - Disabled)
dirkdererste (S-1-5-21-1588098070-3651612994-842810468-1000 - Administrator - Enabled) => C:\Users\dirkdererste
Gast (S-1-5-21-1588098070-3651612994-842810468-501 - Limited - Disabled)

==================== Faulty Device Manager Devices =============

Name: Microsoft-ISATAP-Adapter
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Synaptics PS/2 Port TouchPad
Description: Synaptics PS/2 Port TouchPad
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Synaptics
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: SiS191 Ethernet Controller
Description: SiS191 Ethernet Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Silicon Integrated Systems Corp.
Service: SiSGbeLH
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/19/2015 04:43:05 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2015 09:45:23 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2015 02:54:05 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/17/2015 09:44:08 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/16/2015 05:45:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/16/2015 03:50:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/16/2015 01:40:38 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/16/2015 00:47:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/15/2015 03:58:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/15/2015 00:51:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (01/19/2015 04:48:04 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (01/19/2015 04:44:21 PM) (Source: Dhcp) (EventID: 1001) (User: )
Description: Diesem Computer konnte keine Netzwerkadresse durch den DHCP-Server für die Netzwerkkarte mit der Netzwerkadresse 6223733B10C1 zugeteilt werden. Der folgende Fehler ist aufgetreten: 
%%258. Es wird weiterhin im Hintergrund versucht, eine Adresse vom Netzwerkadressserver (DHCP) zugeteilt zu bekommen.

Error: (01/19/2015 04:43:27 PM) (Source: Dhcp) (EventID: 1002) (User: )
Description: Die IP-Adresslease 192.168.8.100 für die Netzwerkkarte mit der Netzwerkadresse 6223733B10C1 wurde durch den DHCP-Server 192.168.8.1 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).

Error: (01/19/2015 04:43:06 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Tosrfcom

Error: (01/18/2015 09:45:33 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (01/18/2015 09:45:23 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Tosrfcom

Error: (01/18/2015 09:44:06 AM) (Source: Dhcp) (EventID: 1002) (User: )
Description: Die IP-Adresslease 192.168.8.100 für die Netzwerkkarte mit der Netzwerkadresse CEBAC3BD9E48 wurde durch den DHCP-Server 192.168.8.1 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).

Error: (01/18/2015 03:05:03 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt.

	Neue Signaturversion: 

	Vorherige Signaturversion: 1.191.2526.0

	Aktualisierungsquelle: %NT-AUTORITÄT59

	Aktualisierungsphase: 4.4.0304.00

	Quellpfad: 4.4.0304.01

	Signaturtyp: %NT-AUTORITÄT602

	Aktualisierungstyp: %NT-AUTORITÄT604

	Benutzer: NT-AUTORITÄT\SYSTEM

	Aktuelle Modulversion: %NT-AUTORITÄT605

	Vorherige Modulversion: %NT-AUTORITÄT606

	Fehlercode: %NT-AUTORITÄT607

	Fehlerbeschreibung: %NT-AUTORITÄT608

Error: (01/18/2015 03:01:29 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (01/18/2015 02:54:08 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Tosrfcom


Microsoft Office Sessions:
=========================
Error: (01/19/2015 04:43:05 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2015 09:45:23 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2015 02:54:05 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/17/2015 09:44:08 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/16/2015 05:45:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/16/2015 03:50:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/16/2015 01:40:38 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/16/2015 00:47:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/15/2015 03:58:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/15/2015 00:51:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
  Date: 2014-09-20 11:04:04.356
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-20 11:04:03.778
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-20 11:04:03.169
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-20 11:04:02.542
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-20 11:04:00.510
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-20 11:03:59.900
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-20 11:03:59.291
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-20 11:03:58.525
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-08-28 00:14:54.077
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\KLKBDFLT2X86\klkbdflt2.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-08-28 00:14:53.562
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\KLKBDFLT2X86\klkbdflt2.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info =========================== 

Processor: Intel(R) Pentium(R) Dual CPU T3200 @ 2.00GHz
Percentage of memory in use: 51%
Total physical RAM: 3070.54 MB
Available physical RAM: 1480.24 MB
Total Pagefile: 6351.21 MB
Available Pagefile: 4570.25 MB
Total Virtual: 2047.88 MB
Available Virtual: 1900.52 MB

==================== Drives ================================

Drive c: (VistaOS) (Fixed) (Total:139.73 GB) (Free:51.59 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:93.15 GB) (Free:65.03 GB) NTFS
Drive e: (DEPECHE MODE - Alive In Berlin) (CDROM) (Total:7.72 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.9 GB) (Disk ID: 03942D70)
Partition 1: (Active) - (Size=139.7 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=93.2 GB) - (Type=OF Extended)

==================== End Of Log ============================
         
--- --- ---
__________________

Alt 19.01.2015, 20:19   #4
schrauber
/// the machine
/// TB-Ausbilder
 

general crawlers - Standard

general crawlers



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 26.01.2015, 18:28   #5
dms3333
 
general crawlers - Standard

general crawlers



Hallo

und danke erstmal dafür -
ich werde das mal machen , aber nicht heute . scheint ja eine ziemlich umständliche aktion zu sein .
habe ich denn was auf dem rechner was nicht drauf gehört ?

m.f.g.


Alt 26.01.2015, 22:38   #6
schrauber
/// the machine
/// TB-Ausbilder
 

general crawlers - Standard

general crawlers



Jo, Adware
__________________
--> general crawlers

Alt 31.01.2015, 12:24   #7
dms3333
 
general crawlers - Standard

general crawlers



Hey
danke nochmal für die info , habe jetzt mal alles durchgeführt und für mich als mr.ahnungslos ist aber kein unterschied festzustellen . sollte ich diese prozedur nun öfter anwenden ?

Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software


Protection, 30.01.2015 22:48:08, SYSTEM, DIRKDERERSTE-PC, Protection, Malware Protection, Starting,
Protection, 30.01.2015 22:48:08, SYSTEM, DIRKDERERSTE-PC, Protection, Malware Protection, Started,
Protection, 30.01.2015 22:48:08, SYSTEM, DIRKDERERSTE-PC, Protection, Malicious Website Protection, Starting,
Protection, 30.01.2015 22:48:12, SYSTEM, DIRKDERERSTE-PC, Protection, Malicious Website Protection, Started,
Update, 30.01.2015 22:48:17, SYSTEM, DIRKDERERSTE-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1,
Update, 30.01.2015 22:48:17, SYSTEM, DIRKDERERSTE-PC, Manual, Rootkit Database, 2014.11.18.1, 2015.1.14.1,
Update, 30.01.2015 22:48:33, SYSTEM, DIRKDERERSTE-PC, Manual, Malware Database, 2014.11.20.6, 2015.1.30.8,
Protection, 30.01.2015 22:48:33, SYSTEM, DIRKDERERSTE-PC, Protection, Refresh, Starting,
Protection, 30.01.2015 22:48:33, SYSTEM, DIRKDERERSTE-PC, Protection, Malicious Website Protection, Stopping,
Protection, 30.01.2015 22:48:33, SYSTEM, DIRKDERERSTE-PC, Protection, Malicious Website Protection, Stopped,
Protection, 30.01.2015 22:48:41, SYSTEM, DIRKDERERSTE-PC, Protection, Refresh, Success,
Protection, 30.01.2015 22:48:41, SYSTEM, DIRKDERERSTE-PC, Protection, Malicious Website Protection, Starting,
Protection, 30.01.2015 22:48:42, SYSTEM, DIRKDERERSTE-PC, Protection, Malicious Website Protection, Started,

(end)
----------------------------------------
# AdwCleaner v4.109 - Bericht erstellt am 30/01/2015 um 23:23:39
# Aktualisiert 24/01/2015 von Xplode
# Database : 2015-01-26.1 [Live]
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzername : dirkdererste - DIRKDERERSTE-PC
# Gestartet von : C:\Users\dirkdererste\Downloads\AdwCleaner_4.109.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\PC Drivers HeadQuarters
Ordner Gelöscht : C:\Program Files\AnyProtectEx
Ordner Gelöscht : C:\Program Files\GamesBar
Ordner Gelöscht : C:\Users\DIRKDE~1\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\dirkdererste\AppData\Local\Babylon
Ordner Gelöscht : C:\Users\dirkdererste\AppData\Local\Tuguu_SL
Ordner Gelöscht : C:\Users\dirkdererste\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\dirkdererste\AppData\Roaming\Security System 2
Ordner Gelöscht : C:\Users\dirkdererste\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\dirkdererste\AppData\Roaming\Toolplugin
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Windows\system32\roboot.exe

***** [ Tasks ] *****

Task Gelöscht : Software Updater

------------------------------------------------JRT Logfile:
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by dirkdererste on 30.01.2015 at 23:34:36,35
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}



~~~ Files

Successfully deleted: [File] C:\Windows\prefetch\DRIVERSETUP.EXE-DD5C1BF6.pf



~~~ Folders

Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin"
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{01A287B1-81EF-48DF-92F9-0E4C0DFE5F89}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{03191E75-FC96-480E-BBA9-1F0014E37125}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{04081FCE-23A4-4D2C-AC17-3983BCBF5BD7}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{04B93C16-5B07-4B9F-96E5-18A79E822B00}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{05FB68B2-FADF-4184-A8F7-439B3648F860}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{06E8E259-1F28-43C1-BEE0-5CABC037E469}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{098479FC-3EC2-476C-8AA7-0A0835D4EFA8}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{0B078C03-6539-4602-B2A3-4CC5C1A85470}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{0B9C2737-4CC3-472F-9313-2D9AB1EFBB0E}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{12261B67-F504-4C1C-85BD-53F4B84F9529}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{1337A515-BFA1-4934-811A-3E19EBBF7D39}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{154B8B71-5704-424E-998B-BE686D1787B3}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{16FC69FA-486F-414A-918F-7413B6F5B6AA}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{19B47451-7F46-408F-AB64-E361A0D2B61E}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{1A447DCA-F9B3-4CDD-9E2A-E767FA8B18E1}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{1E04EE68-3030-4835-BE0F-A2344311AAE2}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{1E2EE9A3-7D38-4E28-AEC8-4490BB365FF3}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{1E915829-88BC-4A78-AEEE-1218C5A7DCB3}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{1F8D53A0-AE05-4F2D-B07A-743A12062924}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{21C04126-09D6-400E-9A42-26D4D8864679}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{22C42200-2648-429B-A77D-0C1FD0104329}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{25F3A22E-47CB-4394-B043-610F584A9754}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{26ED7610-FE03-416F-BEB7-84D6B22816C2}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{2770D1AD-2590-469B-8FC7-C926DB37B97C}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{2A17CE64-7731-4A9E-982F-54825E54EAA5}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{2CE09DFB-6589-48CD-B460-ACB4A2A4398F}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{2F238C06-75A9-49BF-8073-9DFA7365A820}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{2F68A8FA-82C7-45DA-9BF5-3D3BF4576B70}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{2F7DA4A7-1379-4217-AF55-BB95B6827338}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{30E60BAC-F497-486B-9BEC-5E91CCC3A72D}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{316C08E0-ED0E-4734-A461-F368787406D9}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{31871A65-0A52-4032-A035-CB42BC1F9838}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{339D9740-E2E7-41DA-AD97-FAE675D06212}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{3628DB2B-5B6B-420F-9225-8D4CDE1448EB}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{3E360FE0-AC4D-4669-A40D-089CEDD0BF92}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{41AB9376-6297-4DD1-9103-5301B226B1AE}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{49709AC6-8080-4823-9B6F-A27662A577E1}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{4ADCD0C3-0A07-483C-BA3C-454BD495AD8F}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{4B3289CB-6241-47CA-AF22-76A3C3F8AFAB}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{4D0EB893-DE8A-488B-9856-235E903C98FB}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{52AD7779-58CF-44BE-838A-927CBF4DC5E4}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{52BCCE54-4968-43FA-ADC4-5A3F59C01F40}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{5C629297-41DD-4564-8C7C-C4F04082B943}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{60B0E168-BD5C-407D-874E-266493D843EF}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{617A780B-4BEE-4E20-8DBE-589270F57BBB}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{65217493-C958-47FC-A19C-67AF53D1B4CB}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{676CC973-B8DE-4A39-B31A-D6A41C4EFEAF}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{67B9690D-CF31-430A-A1F7-B2CF39B20A3D}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{6A67D21D-A943-4AF4-9EEC-BDF550FE9574}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{6B55CF83-A6CB-40C8-9915-CE40A2BA3969}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{6C5D25EB-1910-4924-AAE7-0FD49A5B1DB6}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{6C674FD5-C129-4FDC-9B61-D9E14B9F9652}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{72B05727-4FB8-467F-8FC5-1F94C4900CE1}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{73147042-00CD-4B3E-959A-B95BE8BE93C3}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{73698C02-9A20-4AFB-ABA3-E01DA5949F81}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{77BD3833-FB57-49B8-A32E-638166A333EB}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{7AF635C5-97EA-4FEF-8FED-E0D9A4BAABE8}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{7BE22156-CA58-47D4-B38D-64BA209BECA8}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{7D3AEA8D-AA93-42E6-AE3D-CD7BCDD185C9}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{85D87357-D550-4E24-B74A-ADB2F88362AB}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{880D30D0-75E1-4E21-9C8A-BAFA05027FB6}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{8EDED6F0-B914-4628-9C73-F967EC88CD1F}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{8FB9E7CD-1E20-4A37-9986-EB1DFB8AECEB}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{9237A495-6E8D-44C3-B9B5-6FE399FB72AD}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{936198E1-C708-4D12-8716-D27629103C2B}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{9A931F4A-9929-46CA-B131-B91415BCF8B3}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{9BD92546-27A1-4A2F-9EB1-36517D1A5486}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{9F959141-2DE9-4B2C-8CE1-6B48581754F7}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{A0B08665-8162-40A4-AF01-C37ACBC1AB1C}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{A57AF6E7-518C-46AD-81DB-2F9F7D8AAFDC}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{A5AFB053-BC1C-43E4-B7A4-6550EB534BFF}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{A627AAE2-2DD6-4B45-964A-0DB43F3062BE}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{A70111A7-3B41-4546-A96A-44C5DCB6DF73}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{A88903AB-3840-4AEA-AC8E-1316B8B5C258}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{AB232FD8-6567-4226-902D-5B5864A268FA}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{B11233FC-CC80-4E0B-A789-1482002A4419}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{B9538D8E-F44C-4405-954F-70444B95CE31}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{BE2DE09F-9AA7-491C-B18C-FCA07848F75C}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{BF1C8246-BD10-4495-A3AB-41FD5F0F0284}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{C6870E8C-36AE-42D7-A927-38E91AC920DF}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{CC90E0D2-ED01-4D61-9335-61EF75D99180}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{CD2303BD-D2DA-445C-BD33-1FD1B9E8EC96}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{CFC345DA-4616-49CA-A184-583B9DDCF450}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{D0C97D88-10E7-43AF-9167-5895249DDCF3}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{D3C233DB-5B7C-4FC5-84B2-D734EB616499}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{DD809FBD-C7BC-48A1-8BBB-C37899077A25}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{E15485D4-9BD8-4374-A903-366BC97A6F39}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{E27C459C-8A57-4008-A949-F33FD125696C}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{E28C7A92-A90C-4CDC-8A00-2F48F6166ADF}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{ED58AA0B-1F60-469A-A559-E761942EE4E8}
Successfully deleted: [Empty Folder] C:\Users\dirkdererste\appdata\local\{FBFB72F6-8D2E-4E37-9E99-B5E965D5FE3C}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.01.2015 at 23:39:35,09
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
--- --- ---

----------------------------------------------------------------
FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-01-2015 01
Ran by dirkdererste (administrator) on DIRKDERERSTE-PC on 30-01-2015 23:41:46
Running from C:\Users\dirkdererste\Downloads
Loaded Profiles: dirkdererste (Available profiles: dirkdererste)
Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files\ATK Hotkey\ASLDRSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(ATK0100) C:\Program Files\ATK Hotkey\HControl.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
() C:\Program Files\ATKOSD2\ATKOSD2.exe
() C:\Program Files\Wireless Console 2\wcourier.exe
() C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe
(ASUS) C:\Program Files\ASUS\ASUS CopyProtect\ASPG.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVerMedia) C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
() C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe
() C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
(Microsoft Corp.) C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files\ATK Hotkey\ATKOSD.exe
(Malwarebytes Corporation) C:\ Malwarebytes Anti-Malware \mbamscheduler.exe
() C:\Program Files\ATK Hotkey\KBFiltr.exe
(Malwarebytes Corporation) C:\ Malwarebytes Anti-Malware \mbamservice.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Malwarebytes Corporation) C:\ Malwarebytes Anti-Malware \mbam.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(ASUS) C:\Windows\System32\ASUSTPE.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 10.0\Reader\reader_sl.exe
(Farbar) C:\Users\dirkdererste\Downloads\FRST (1).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4853760 2008-01-07] (Realtek Semiconductor)
HKLM\...\Run: [ASUSTPE] => C:\Windows\system32\ASUSTPE.exe [106496 2007-10-12] (ASUS)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguix.exe [1140688 2015-01-16] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-01-06] (Google Inc.)
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19ab7c-cbab-11e3-b7e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abdb-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abe7-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe8a-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe92-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe9e-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5dd-d506-11e3-befd-c030a9561ac3} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5e9-d506-11e3-befd-b68ac94258b5} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {31011372-66a4-11e4-88f4-adb511af100e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b50-3846-11e4-b727-a594aa94d86e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b5b-3846-11e4-b727-cfe712892541} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4235e5bc-8deb-11e3-bea2-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd209-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd244-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd24e-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd256-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd262-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb3442b-1faf-11e4-94c1-9483cebc1803} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb34437-1faf-11e4-94c1-ebf9039c5468} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5061e-2d56-11e4-806c-82b39df6fe7f} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5063d-2d56-11e4-806c-ff8e48defdcd} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {5899778b-f65b-11e3-908a-fe702680487d} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {589977db-f65b-11e3-908a-d444832a8c51} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7534b009-f659-11e3-935b-983f9ae39f7f} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba568-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba588-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {84d86f73-ebcf-11e3-99f4-e91098103f7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c282-3821-11e4-ac47-8fad69652c89} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c28d-3821-11e4-ac47-98a026ee637b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {8918ebcd-f632-11e3-a4cc-aae446c3b7d9} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {98b2279a-f666-11e3-82bf-8691ac93757f} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9d60af46-6833-11e4-9ae1-81f053ff7d7b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f017-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f054-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247885d-d82f-11e3-afed-ff56e36041fd} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247889a-d82f-11e3-afed-987030581f5d} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {b4a4281b-2f93-11e4-a053-b7ed9dff2029} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {ca5b6dde-19e3-11e0-83b8-806e6f6e6963} - E:\Autorun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {d85a1d2a-462a-11e4-94c3-8888219aad9a} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {db596716-c7e8-11e3-bdee-001e101fe70e} - I:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f01bf-2e39-11e4-b425-806e6f6e6963} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f0200-2e39-11e4-b425-c3e18252350b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {faf8fc99-6d70-11e4-b1d1-f474d68c3f10} - F:\AutoRun.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = hxxp://start.gamesagogo.iplay.com/searchresultsredirect.aspx?o=chrome&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {47511E21-1A74-42AF-93B1-2D31D99E032B} URL = hxxp://de.wikipedia.org/wiki/Spezial:Search?search={searchTerms}
SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {7B240E59-FCB8-4F40-9C17-688AC4BBDB6A} URL = hxxp://rover.ebay.com/rover/1/707-37276-23097-0/4?satitle={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Babylon Toolbar - {41B62AD3-5D43-40D1-9D43-F3539C1DB452} -  No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1

FireFox:
========
FF Plugin: @adobe.com/AuthorwarePlayer -> C:\WINDOWS\system32\Macromed\AUTHORWA\np32asw.dll (Macromedia, Inc.)
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1588098070-3651612994-842810468-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-01-06]

Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.ergebnisselive.de/"
CHR Profile: C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-21]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-07]
CHR Extension: (YouTube) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-21]
CHR Extension: (Google-Suche) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-16]
CHR Extension: (Google Wallet) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Google Mail) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-16]
CHR Profile: C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-13]
CHR Extension: (YouTube) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-19]
CHR Extension: (Google-Suche) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-19]
CHR Extension: (Value apps) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon [2014-03-20]
CHR Extension: (Google Wallet) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-13]
CHR Extension: (Google Mail) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-19]
CHR HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\DIRKDE~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [Not Found]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ALDITALKVerbindungsassistent_Service; C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [342984 2011-09-13] ()
R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () [File not signed]
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed]
R2 AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [339968 2008-03-13] (AVerMedia) [File not signed]
R2 AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [380928 2008-03-05] () [File not signed]
R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [703952 2015-01-16] (AVG Technologies CZ, s.r.o.)
R2 BingDesktopUpdate; C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-20] (Microsoft Corp.)
R2 MBAMScheduler; C:\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2165560 2014-11-24] (AVG Technologies)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [35640 2014-11-24] (AVG Technologies)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
S3 ASPI; C:\Windows\System32\DRIVERS\ASPI32.sys [84832 2002-07-17] (Adaptec) [File not signed]
S3 AVerFx2hbtv; C:\Windows\System32\drivers\AVerFx2hbtv.sys [437888 2009-12-08] (AVerMedia TECHNOLOGIES, Inc.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( )
R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-01-30] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1772544 2008-05-22] ()
S3 tosporte; C:\Windows\System32\DRIVERS\tosporte.sys [41600 2006-10-10] (TOSHIBA Corporation) [File not signed]
S3 tosrfbd; C:\Windows\System32\DRIVERS\tosrfbd.sys [113792 2006-11-30] (TOSHIBA CORPORATION) [File not signed]
S3 tosrfbnp; C:\Windows\System32\Drivers\tosrfbnp.sys [36480 2006-11-20] (TOSHIBA Corporation) [File not signed]
S1 Tosrfcom; C:\Windows\System32\Drivers\tosrfcom.sys [64896 2005-08-01] (TOSHIBA Corporation) [File not signed]
S3 Tosrfhid; C:\Windows\System32\DRIVERS\Tosrfhid.sys [73600 2006-10-05] (TOSHIBA Corporation.) [File not signed]
S3 tosrfnds; C:\Windows\System32\DRIVERS\tosrfnds.sys [18612 2005-01-06] (TOSHIBA Corporation.) [File not signed]
S3 TosRfSnd; C:\Windows\System32\drivers\tosrfsnd.sys [53504 2006-11-02] (TOSHIBA Corporation) [File not signed]
S3 Tosrfusb; C:\Windows\System32\DRIVERS\tosrfusb.sys [40960 2006-10-27] (TOSHIBA CORPORATION) [File not signed]
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [12320 2014-08-28] (TuneUp Software)
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 HTCAND32; System32\Drivers\ANDROIDUSB.sys [X]
S3 hwusbfake; No ImagePath
S3 IpInIp; No ImagePath
S3 motmodem; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath
S3 usbbus; system32\DRIVERS\lgusbbus.sys [X]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X]
S3 USBModem; system32\DRIVERS\lgusbmodem.sys [X]
S3 VNUSB; system32\DRIVERS\VNUSB.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-30 23:41 - 2015-01-30 23:41 - 01121792 _____ (Farbar) C:\Users\dirkdererste\Downloads\FRST (1).exe
2015-01-30 23:39 - 2015-01-30 23:39 - 00011221 _____ () C:\Users\dirkdererste\Desktop\JRT.txt
2015-01-30 23:34 - 2015-01-30 23:34 - 00000000 ____D () C:\Windows\ERUNT
2015-01-30 23:32 - 2015-01-30 23:32 - 01707939 _____ (Thisisu) C:\Users\dirkdererste\Downloads\JRT.exe
2015-01-30 23:31 - 2015-01-30 23:31 - 00011039 _____ () C:\Users\dirkdererste\Desktop\AdwCleaner[S0].txt
2015-01-30 23:17 - 2015-01-30 23:23 - 00000000 ____D () C:\AdwCleaner
2015-01-30 23:16 - 2015-01-30 23:16 - 02194432 _____ () C:\Users\dirkdererste\Downloads\AdwCleaner_4.109.exe
2015-01-30 23:14 - 2015-01-30 23:14 - 00001444 _____ () C:\Users\dirkdererste\Desktop\antimalware.txt
2015-01-30 22:48 - 2015-01-30 23:30 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-30 22:47 - 2015-01-30 22:47 - 00000660 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-01-30 22:47 - 2015-01-30 22:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-01-30 22:47 - 2015-01-30 22:47 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-30 22:47 - 2015-01-30 22:47 - 00000000 ____D () C:\ Malwarebytes Anti-Malware 
2015-01-30 22:47 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-30 22:47 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-30 22:47 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-30 22:44 - 2015-01-30 22:44 - 00000551 _____ () C:\Users\dirkdererste\Desktop\ddd.txt
2015-01-30 22:41 - 2015-01-30 22:42 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\dirkdererste\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-27 19:05 - 2015-01-27 19:03 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2015-01-27 19:05 - 2015-01-27 19:03 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2015-01-27 19:05 - 2015-01-27 19:03 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-01-21 18:11 - 2015-01-30 23:28 - 00012758 _____ () C:\Windows\PFRO.log
2015-01-20 19:53 - 2015-01-20 19:55 - 00000000 ___RD () C:\Users\dirkdererste\Desktop\Write
2015-01-20 19:45 - 2015-01-20 19:45 - 00000000 ____D () C:\Users\Public\Documents\sun
2015-01-20 19:44 - 2015-01-20 19:44 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\LibreOffice
2015-01-20 19:42 - 2015-01-20 19:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.2
2015-01-20 19:36 - 2015-01-20 19:42 - 00000000 ____D () C:\Program Files\LibreOffice 4
2015-01-20 19:31 - 2015-01-20 19:31 - 00000000 ____D () C:\Users\dirkdererste\Desktop\LernZeugs
2015-01-20 13:43 - 2015-01-20 13:52 - 220569600 _____ () C:\Users\dirkdererste\LibreOffice_4.2.8_Win_x86.msi
2015-01-19 17:26 - 2015-01-19 17:27 - 00027860 _____ () C:\Users\dirkdererste\Downloads\Addition.txt
2015-01-19 17:25 - 2015-01-30 23:41 - 00024162 _____ () C:\Users\dirkdererste\Downloads\FRST.txt
2015-01-19 17:25 - 2015-01-30 23:41 - 00000000 ____D () C:\FRST
2015-01-19 17:24 - 2015-01-19 17:24 - 01118208 _____ (Farbar) C:\Users\dirkdererste\Downloads\FRST.exe
2015-01-14 17:28 - 2014-12-19 01:25 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 17:12 - 2014-12-06 04:14 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 17:12 - 2014-12-06 04:14 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 17:12 - 2014-12-06 04:14 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 17:12 - 2014-12-06 04:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-12 18:30 - 2015-01-12 18:36 - 00000022 _____ () C:\Users\dirkdererste\Downloads\Gmail.zip
2015-01-10 13:13 - 2015-01-10 13:13 - 00012602 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvv-2FbgLWtxKiUPAnNHg9Ex7XJiyYrBIUKWniOSaYy513hlfagHce8Y9q2fBnUi46j8LMJiN4Ibo0jYqNA5K4b4-2BrIkMFz4DmX-2BQqOw6O-2BALSXByyiQFSdvPgiEF8YKq1mRsmIvzrESP5BopAg0olkOxyP-2FBKvXhu1j
2015-01-10 13:13 - 2015-01-10 13:13 - 00006172 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvvsJzMbrsjw5UKW3z-2Bs2dvjRlPojiGebXy7e5eGczAbLu-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FO3NCXbmNOMaTkWVyij4LGMR
2015-01-10 13:12 - 2015-01-10 13:12 - 00014005 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvszYSjXqZ0eKiFnXjlLTe-2BMizo92Hdw-2BByllGk1G2Tgge-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FbWYBnp7TdSaoQHTs8HCgK
2015-01-10 13:12 - 2015-01-10 13:12 - 00014005 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvszYSjXqZ0eKiFnXjlLTe-2BMizo92Hdw-2BByllGk1G2Tgge-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FbWYBnp7TdSaoQHTs8 (1)
2015-01-10 13:11 - 2015-01-10 13:11 - 00006448 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvuNQjNdmO9DbIZqVdhXDmcImLLl-2FMJgwS5ROnb8F4Ar8-2B-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FO3NCXbmNOMaTkWVyij4LG
2015-01-06 20:46 - 2015-01-06 20:46 - 00001063 _____ () C:\Users\dirkdererste\Desktop\MAST.txt
2015-01-02 13:14 - 2015-01-02 13:14 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\Amazon

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-30 23:39 - 2012-07-16 10:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-30 23:33 - 2014-03-24 23:00 - 01526593 _____ () C:\Windows\WindowsUpdate.log
2015-01-30 23:28 - 2011-01-06 20:20 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-30 23:28 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-30 23:28 - 2006-11-02 13:47 - 00003616 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-30 23:28 - 2006-11-02 13:47 - 00003616 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-30 23:26 - 2012-05-06 11:55 - 00000000 ____D () C:\Windows\de
2015-01-30 23:25 - 2014-06-12 23:47 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-01-30 23:25 - 2011-01-06 20:20 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-30 18:28 - 2012-12-29 18:25 - 00000392 _____ () C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
2015-01-30 15:53 - 2006-11-02 11:33 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-30 00:21 - 2014-06-27 14:57 - 00000000 ____D () C:\Users\dirkdererste\Documents\AVerTV
2015-01-29 18:32 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\tracing
2015-01-27 19:06 - 2013-10-21 16:27 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-27 19:05 - 2011-01-10 00:43 - 00000000 ____D () C:\Program Files\Java
2015-01-27 19:04 - 2014-11-04 16:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-01-27 19:03 - 2014-11-04 16:35 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2015-01-25 12:50 - 2012-04-08 09:03 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-01-25 12:50 - 2011-05-21 12:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-01-24 17:16 - 2014-09-03 18:24 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\vlc
2015-01-21 18:11 - 2014-09-14 00:30 - 00299008 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-20 20:53 - 2014-09-14 09:32 - 00065328 _____ () C:\Users\dirkdererste\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-20 19:32 - 2011-01-06 16:43 - 00000000 ____D () C:\Users\dirkdererste
2015-01-15 22:52 - 2012-07-27 19:58 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\Canon
2015-01-15 20:45 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-01-15 17:53 - 2014-11-02 10:34 - 00000000 ____D () C:\Users\dirkdererste\Desktop\Neuer Ordner
2015-01-14 17:28 - 2013-07-19 12:23 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 17:13 - 2006-11-02 11:24 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-01-12 23:59 - 2011-01-07 15:25 - 00000000 ___RD () C:\Users\dirkdererste\Desktop\Kram
2015-01-12 17:02 - 2013-08-17 11:28 - 00000000 ____D () C:\Users\dirkdererste\AppData\Local\Freenet
2015-01-02 14:40 - 2011-01-07 15:36 - 00000000 ___RD () C:\Users\dirkdererste\Desktop\Mein Ordner
2014-12-31 12:13 - 2011-01-06 19:02 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

==================== Files in the root of some directories =======

2007-06-12 19:34 - 2007-06-12 19:34 - 0035822 _____ () C:\Program Files\Common Files\ASPG_icon.ico
2008-05-22 18:35 - 2008-05-22 18:35 - 0051962 _____ () C:\Program Files\Common Files\banner.jpg
2008-07-02 04:28 - 2008-07-02 04:28 - 0061440 _____ () C:\Program Files\Common Files\CPInstallAction.dll
2011-10-30 00:00 - 2011-10-30 00:00 - 0024206 _____ () C:\Users\dirkdererste\AppData\Roaming\UserTile.png
2014-09-27 14:04 - 2014-09-27 14:05 - 0010828 _____ () C:\Users\dirkdererste\AppData\Roaming\WtgInstaller.txt
2011-01-06 20:24 - 2014-08-27 22:09 - 0001356 _____ () C:\Users\dirkdererste\AppData\Local\d3d9caps.dat
2011-01-07 14:57 - 2014-12-07 14:50 - 0020480 _____ () C:\Users\dirkdererste\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-03-21 16:25 - 2014-03-21 16:25 - 1172736 _____ (AnyProtect.com) C:\Users\dirkdererste\AppData\Local\nss61AF.tmp
2011-11-21 21:46 - 2011-11-21 21:46 - 0000000 _____ () C:\Users\dirkdererste\AppData\Local\{0CE875FA-9C01-4FE6-91E4-8DD35D1352B1}

Some content of TEMP:
====================
C:\Users\dirkdererste\AppData\Local\Temp\avguirn_082101543405.exe
C:\Users\dirkdererste\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\dirkdererste\AppData\Local\Temp\Quarantine.exe
C:\Users\dirkdererste\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-30 23:37

==================== End Of Log ============================
         
--- --- ---

Alt 31.01.2015, 16:01   #8
schrauber
/// the machine
/// TB-Ausbilder
 

general crawlers - Standard

general crawlers




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 03.02.2015, 17:07   #9
dms3333
 
general crawlers - Standard

general crawlers



Hey

danke für den tipp , werde ich mal machen , aber kann es sein das die ganze scannerei eine wechselwirkung mit meinem tune up utilities hat ? ich denke mal ja , weil seit samstag geht das nicht mehr , es stürzt bei jedem scan einfach ab .

Alt 03.02.2015, 21:07   #10
schrauber
/// the machine
/// TB-Ausbilder
 

general crawlers - Standard

general crawlers



Nö, wir haben bis jetzt nur ADware entfernt. Aber falls Du vor hast aus deinem Rechner nen Toaster zu bauen kannste Tune Up weiter benutzen.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 07.02.2015, 12:02   #11
dms3333
 
general crawlers - Standard

general crawlers



`n toaster habe ich ja schon , meinste man braucht das nicht ? ich finds praktisch weil man immer was bereinigen kann und so , habe aber auch schon öfter gehört dass das was für dummies ist , aber bin ich ja auch . von daher . schaden richtet es ja wohl nicht an .


m.f.g.

Alt 07.02.2015, 15:52   #12
schrauber
/// the machine
/// TB-Ausbilder
 

general crawlers - Standard

general crawlers



Zitat:
schaden richtet es ja wohl nicht an
https://www.google.de/search?q=weil&...+zerst%C3%B6rt
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 07.02.2015, 18:26   #13
dms3333
 
general crawlers - Standard

general crawlers



so , auch erledigt

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=bd5a45e1632b9648924ab16d72318762
# engine=22353
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2015-02-07 05:01:02
# local_time=2015-02-07 06:01:02 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode_1=''
# compatibility_mode=5892 16776574 100 100 22542911 260861190 0 0
# scanned=223934
# found=15
# cleaned=15
# scan_time=19728
sh=68F39FDC5C97B7D3B93A4B793E3E9DAF1ED75344 ft=1 fh=c71c0011ed98cc6f vn="Variante von Win32/Toolbar.Babylon.F evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\dirkdererste\AppData\Local\Babylon\Setup\BExternal.dll.vir"
sh=D128CBAF3DEF02BD11A92A43C36D540E47BF06E0 ft=1 fh=6abf192eb2d8af09 vn="Variante von Win32/Toolbar.Babylon.E evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\dirkdererste\AppData\Local\Babylon\Setup\IECookieLow.dll.vir"
sh=C88D76106C34D093167BD69B433CFF15F24CFE68 ft=1 fh=c9f8a6e51b4e4ea2 vn="Variante von Win32/Toolbar.Babylon.E evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\dirkdererste\AppData\Local\Babylon\Setup\Setup.exe.vir"
sh=1D9AE65A97C417A8083FB38EFDB8022EAE3A9698 ft=1 fh=8dd7dc1cf3445b5c vn="Variante von Win32/Adware.Synatix.A Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\dirkdererste\AppData\Roaming\Security System 2\uninstaller.exe.vir"
sh=6FA33E5768F1E40A7CAA358C9A03356D7002119A ft=1 fh=35739b1b5e17d626 vn="Variante von Win32/Systweak.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Windows\system32\roboot.exe.vir"
sh=348832D64C253FE6E7E770656518076BB4E3C61F ft=1 fh=4a025439f848ffb5 vn="Win32/AnyProtect.D evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\AppData\Local\nss61AF.tmp"
sh=62D0AD7E219D16AB54D31417D58D40D550B4C1D9 ft=0 fh=0000000000000000 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\111127120115106.rsc"
sh=8E3FB0901E5AFC704B4609902ED0DFBAD4F93092 ft=0 fh=0000000000000000 vn="HTML/Iframe.B.Gen Virus (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\AppData\Roaming\AVG\Rescue\Track Eraser\111227230414798.rsc"
sh=FDCBC8D81CF255A328EE31C244613B1B5C56DC43 ft=1 fh=cfb484d79a6c1c3a vn="Variante von Win32/Toolbar.Visicom.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\AppData\Roaming\VisicomToolBar\gamesagogo_en_w3i_toolbar_3.2.0.36.exe"
sh=1F53DE2B098AF90931AE36750AB4B0D779A7C2CB ft=1 fh=3b09867ae1cba431 vn="Win32/OpenCandy potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\Downloads\FreeAVIVideoConverter_CB-DL-Manager [1].exe"
sh=3132CEDD6066AEFD82FC7CEB210193DD5CBA2678 ft=1 fh=26d53975373e166e vn="Variante von Win32/InstallCore.PK evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\Downloads\FreeAVIVideoConverter_CB-DL-Manager.exe"
sh=8B1451E9C3E7A5028CC7BF5A7D3E8B5B1C69EFAF ft=1 fh=72d46938dae5e617 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\Downloads\VLC media player 32 Bit - CHIP-Installer (1).exe"
sh=DB189999FB75EE11E3CBD4FCF30550FCA92514A7 ft=1 fh=4c37e42dc2a8448f vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\Downloads\VLC media player 32 Bit - CHIP-Installer.exe"
sh=F711D2AA2F4CC4C6DA8C668A566152517DA39F1B ft=0 fh=0000000000000000 vn="Variante von Win32/Systweak.L evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\Downloads\wz180gev-32.msi"
sh=A981E3D6F03D3BD57D1472F33A4093A01533F8A8 ft=1 fh=7aaf7b3d0491af48 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\dirkdererste\Downloads\wzmp_8.exe"


-------------------------------------------------------------------------------------

Results of screen317's Security Check version 0.99.95
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
AVG PC TuneUp 2015
AVG PC TuneUp 2015 (de-DE)
AVG PC TuneUp 2015
TuneUp Utilities 2014 (de-DE)
Java 8 Update 31
Java version 32-bit out of Date!
Java 64-bit 8 Update 31
Adobe Flash Player 16.0.0.305
Adobe Reader 10.1.13 Adobe Reader out of Date!
Google Chrome (40.0.2214.111)
Google Chrome (40.0.2214.94)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````


---------------------------------------------------------------------------------
FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 07-02-2015
Ran by dirkdererste (administrator) on DIRKDERERSTE-PC on 07-02-2015 18:18:41
Running from C:\Users\dirkdererste\Downloads
Loaded Profiles: dirkdererste (Available profiles: dirkdererste)
Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files\ATK Hotkey\ASLDRSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
() C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVerMedia) C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
() C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe
(Microsoft Corp.) C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
(ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(ATK0100) C:\Program Files\ATK Hotkey\HControl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
() C:\Program Files\ATKOSD2\ATKOSD2.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(ASUS) C:\Program Files\ASUS\ASUS CopyProtect\ASPG.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Windows\System32\ASUSTPE.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
() C:\Program Files\ATK Hotkey\ATKOSD.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
() C:\Program Files\ATK Hotkey\KBFiltr.exe
(AVG Technologies) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Farbar) C:\Users\dirkdererste\Downloads\FRST (2).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4853760 2008-01-07] (Realtek Semiconductor)
HKLM\...\Run: [ASUSTPE] => C:\Windows\system32\ASUSTPE.exe [106496 2007-10-12] (ASUS)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguix.exe [1140688 2015-01-16] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-01-06] (Google Inc.)
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19ab7c-cbab-11e3-b7e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abdb-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abe7-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe8a-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe92-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe9e-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5dd-d506-11e3-befd-c030a9561ac3} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5e9-d506-11e3-befd-b68ac94258b5} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {31011372-66a4-11e4-88f4-adb511af100e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b50-3846-11e4-b727-a594aa94d86e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b5b-3846-11e4-b727-cfe712892541} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4235e5bc-8deb-11e3-bea2-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd209-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd244-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd24e-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd256-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd262-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb3442b-1faf-11e4-94c1-9483cebc1803} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb34437-1faf-11e4-94c1-ebf9039c5468} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5061e-2d56-11e4-806c-82b39df6fe7f} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5063d-2d56-11e4-806c-ff8e48defdcd} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {5899778b-f65b-11e3-908a-fe702680487d} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {589977db-f65b-11e3-908a-d444832a8c51} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7534b009-f659-11e3-935b-983f9ae39f7f} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba568-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba588-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {84d86f73-ebcf-11e3-99f4-e91098103f7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c282-3821-11e4-ac47-8fad69652c89} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c28d-3821-11e4-ac47-98a026ee637b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {8918ebcd-f632-11e3-a4cc-aae446c3b7d9} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {98b2279a-f666-11e3-82bf-8691ac93757f} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9d60af46-6833-11e4-9ae1-81f053ff7d7b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f017-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f054-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247885d-d82f-11e3-afed-ff56e36041fd} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247889a-d82f-11e3-afed-987030581f5d} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {b4a4281b-2f93-11e4-a053-b7ed9dff2029} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {ca5b6dde-19e3-11e0-83b8-806e6f6e6963} - E:\Autorun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {d85a1d2a-462a-11e4-94c3-8888219aad9a} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {db596716-c7e8-11e3-bdee-001e101fe70e} - I:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f01bf-2e39-11e4-b425-806e6f6e6963} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f0200-2e39-11e4-b425-c3e18252350b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {faf8fc99-6d70-11e4-b1d1-f474d68c3f10} - F:\AutoRun.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = hxxp://start.gamesagogo.iplay.com/searchresultsredirect.aspx?o=chrome&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {47511E21-1A74-42AF-93B1-2D31D99E032B} URL = hxxp://de.wikipedia.org/wiki/Spezial:Search?search={searchTerms}
SearchScopes: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> {7B240E59-FCB8-4F40-9C17-688AC4BBDB6A} URL = hxxp://rover.ebay.com/rover/1/707-37276-23097-0/4?satitle={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Babylon Toolbar - {41B62AD3-5D43-40D1-9D43-F3539C1DB452} -  No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKU\S-1-5-21-1588098070-3651612994-842810468-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1

FireFox:
========
FF Plugin: @adobe.com/AuthorwarePlayer -> C:\WINDOWS\system32\Macromed\AUTHORWA\np32asw.dll (Macromedia, Inc.)
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1588098070-3651612994-842810468-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-01-06]

Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.ergebnisselive.de/"
CHR Profile: C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-21]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-07]
CHR Extension: (YouTube) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-21]
CHR Extension: (Google-Suche) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-16]
CHR Extension: (Internet Speed Tracker) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\jinlofiojphnmpllecgejammnjcmeipf [2015-02-07]
CHR Extension: (Google Wallet) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Google Mail) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-16]
CHR Profile: C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-13]
CHR Extension: (YouTube) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-19]
CHR Extension: (Google-Suche) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-19]
CHR Extension: (Value apps) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon [2014-03-20]
CHR Extension: (Google Wallet) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-13]
CHR Extension: (Google Mail) - C:\Users\dirkdererste\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-19]
CHR HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\DIRKDE~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [Not Found]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ALDITALKVerbindungsassistent_Service; C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [342984 2011-09-13] ()
R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () [File not signed]
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed]
R2 AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [339968 2008-03-13] (AVerMedia) [File not signed]
R2 AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [380928 2008-03-05] () [File not signed]
R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [703952 2015-01-16] (AVG Technologies CZ, s.r.o.)
R2 BingDesktopUpdate; C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-20] (Microsoft Corp.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2161976 2015-01-30] (AVG Technologies)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [36664 2015-01-30] (AVG Technologies)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
S3 ASPI; C:\Windows\System32\DRIVERS\ASPI32.sys [84832 2002-07-17] (Adaptec) [File not signed]
S3 AVerFx2hbtv; C:\Windows\System32\drivers\AVerFx2hbtv.sys [437888 2009-12-08] (AVerMedia TECHNOLOGIES, Inc.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( )
R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1772544 2008-05-22] ()
S3 tosporte; C:\Windows\System32\DRIVERS\tosporte.sys [41600 2006-10-10] (TOSHIBA Corporation) [File not signed]
S3 tosrfbd; C:\Windows\System32\DRIVERS\tosrfbd.sys [113792 2006-11-30] (TOSHIBA CORPORATION) [File not signed]
S3 tosrfbnp; C:\Windows\System32\Drivers\tosrfbnp.sys [36480 2006-11-20] (TOSHIBA Corporation) [File not signed]
S1 Tosrfcom; C:\Windows\System32\Drivers\tosrfcom.sys [64896 2005-08-01] (TOSHIBA Corporation) [File not signed]
S3 Tosrfhid; C:\Windows\System32\DRIVERS\Tosrfhid.sys [73600 2006-10-05] (TOSHIBA Corporation.) [File not signed]
S3 tosrfnds; C:\Windows\System32\DRIVERS\tosrfnds.sys [18612 2005-01-06] (TOSHIBA Corporation.) [File not signed]
S3 TosRfSnd; C:\Windows\System32\drivers\tosrfsnd.sys [53504 2006-11-02] (TOSHIBA Corporation) [File not signed]
S3 Tosrfusb; C:\Windows\System32\DRIVERS\tosrfusb.sys [40960 2006-10-27] (TOSHIBA CORPORATION) [File not signed]
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [12320 2014-08-28] (TuneUp Software)
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 HTCAND32; System32\Drivers\ANDROIDUSB.sys [X]
S3 hwusbfake; No ImagePath
S3 IpInIp; No ImagePath
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 motmodem; No ImagePath
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath
S3 usbbus; system32\DRIVERS\lgusbbus.sys [X]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X]
S3 USBModem; system32\DRIVERS\lgusbmodem.sys [X]
S3 VNUSB; system32\DRIVERS\VNUSB.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-07 18:18 - 2015-02-07 18:18 - 01124352 _____ (Farbar) C:\Users\dirkdererste\Downloads\FRST (2).exe
2015-02-07 18:17 - 2015-02-07 18:17 - 00001080 _____ () C:\Users\dirkdererste\Desktop\checkup.txt
2015-02-07 18:08 - 2015-02-07 18:08 - 00852573 _____ () C:\Users\dirkdererste\Downloads\SecurityCheck.exe
2015-02-07 18:03 - 2015-02-07 18:04 - 00004530 _____ () C:\Users\dirkdererste\Desktop\ESET.txt
2015-02-07 12:20 - 2015-02-07 12:20 - 02347384 _____ (ESET) C:\Users\dirkdererste\Downloads\esetsmartinstaller_deu.exe
2015-02-06 00:11 - 2015-02-06 00:11 - 00003660 _____ () C:\Windows\PFRO.log
2015-02-05 19:41 - 2015-01-30 17:22 - 00036664 _____ (AVG Technologies) C:\Windows\system32\uxtuneup.dll
2015-02-05 19:41 - 2015-01-30 17:22 - 00025912 _____ (AVG Technologies) C:\Windows\system32\authuitu.dll
2015-02-01 00:05 - 2015-02-01 00:06 - 16634392 _____ (AVG Technologies) C:\Users\dirkdererste\Downloads\avg_gse_stb_all_445p1_105.exe
2015-02-01 00:01 - 2015-02-01 00:01 - 04579240 _____ (AVG Technologies) C:\Users\dirkdererste\Downloads\avg_isct_stb_all_2015_5315_evol1.exe
2015-02-01 00:01 - 2015-02-01 00:01 - 00000000 ____D () C:\Users\dirkdererste\AppData\Local\Avg2015
2015-01-30 23:41 - 2015-01-30 23:41 - 01121792 _____ (Farbar) C:\Users\dirkdererste\Downloads\FRST (1).exe
2015-01-30 23:34 - 2015-01-30 23:34 - 00000000 ____D () C:\Windows\ERUNT
2015-01-30 23:32 - 2015-01-30 23:32 - 01707939 _____ (Thisisu) C:\Users\dirkdererste\Downloads\JRT.exe
2015-01-30 23:17 - 2015-01-30 23:23 - 00000000 ____D () C:\AdwCleaner
2015-01-30 23:16 - 2015-01-30 23:16 - 02194432 _____ () C:\Users\dirkdererste\Downloads\AdwCleaner_4.109.exe
2015-01-30 22:47 - 2015-01-30 22:47 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-30 22:41 - 2015-01-30 22:42 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\dirkdererste\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-27 19:05 - 2015-01-27 19:03 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2015-01-27 19:05 - 2015-01-27 19:03 - 00176552 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2015-01-27 19:05 - 2015-01-27 19:03 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-01-20 19:45 - 2015-01-20 19:45 - 00000000 ____D () C:\Users\Public\Documents\sun
2015-01-20 19:44 - 2015-01-20 19:44 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\LibreOffice
2015-01-20 19:31 - 2015-02-04 18:53 - 00000000 ____D () C:\Users\dirkdererste\Desktop\LernZeugs
2015-01-20 13:43 - 2015-01-20 13:52 - 220569600 _____ () C:\Users\dirkdererste\LibreOffice_4.2.8_Win_x86.msi
2015-01-19 17:26 - 2015-01-19 17:27 - 00027860 _____ () C:\Users\dirkdererste\Downloads\Addition.txt
2015-01-19 17:25 - 2015-02-07 18:18 - 00023713 _____ () C:\Users\dirkdererste\Downloads\FRST.txt
2015-01-19 17:25 - 2015-02-07 18:18 - 00000000 ____D () C:\FRST
2015-01-19 17:24 - 2015-01-19 17:24 - 01118208 _____ (Farbar) C:\Users\dirkdererste\Downloads\FRST.exe
2015-01-14 17:28 - 2014-12-19 01:25 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 17:12 - 2014-12-06 04:14 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 17:12 - 2014-12-06 04:14 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 17:12 - 2014-12-06 04:14 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 17:12 - 2014-12-06 04:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-12 18:30 - 2015-01-12 18:36 - 00000022 _____ () C:\Users\dirkdererste\Downloads\Gmail.zip
2015-01-10 13:13 - 2015-01-10 13:13 - 00012602 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvv-2FbgLWtxKiUPAnNHg9Ex7XJiyYrBIUKWniOSaYy513hlfagHce8Y9q2fBnUi46j8LMJiN4Ibo0jYqNA5K4b4-2BrIkMFz4DmX-2BQqOw6O-2BALSXByyiQFSdvPgiEF8YKq1mRsmIvzrESP5BopAg0olkOxyP-2FBKvXhu1j
2015-01-10 13:13 - 2015-01-10 13:13 - 00006172 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvvsJzMbrsjw5UKW3z-2Bs2dvjRlPojiGebXy7e5eGczAbLu-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FO3NCXbmNOMaTkWVyij4LGMR
2015-01-10 13:12 - 2015-01-10 13:12 - 00014005 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvszYSjXqZ0eKiFnXjlLTe-2BMizo92Hdw-2BByllGk1G2Tgge-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FbWYBnp7TdSaoQHTs8HCgK
2015-01-10 13:12 - 2015-01-10 13:12 - 00014005 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvszYSjXqZ0eKiFnXjlLTe-2BMizo92Hdw-2BByllGk1G2Tgge-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FbWYBnp7TdSaoQHTs8 (1)
2015-01-10 13:11 - 2015-01-10 13:11 - 00006448 _____ () C:\Users\dirkdererste\Downloads\4kbummR90KOm0GtSATKY1HiWBsOle7bQtBdR2-2B-2BQrvuNQjNdmO9DbIZqVdhXDmcImLLl-2FMJgwS5ROnb8F4Ar8-2B-2Fst-2BAeh3lCgzd-2BAklnTAaiN9ayJ-2B3dY86Y-2FJN0-2Bup4ZhGSDsuyfA6RNC5TeOl4bInpuDfFpLs3n-2BeOATVw74-2FO3NCXbmNOMaTkWVyij4LG

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-07 18:17 - 2006-11-02 11:33 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-07 17:57 - 2012-12-29 18:23 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\VisicomToolBar
2015-02-07 17:41 - 2011-01-06 20:20 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-07 17:39 - 2012-07-16 10:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-07 17:11 - 2006-11-02 13:47 - 00003616 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-07 17:11 - 2006-11-02 13:47 - 00003616 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-07 16:41 - 2011-01-06 20:20 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-07 15:45 - 2014-09-03 18:24 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\vlc
2015-02-07 09:31 - 2014-03-24 23:00 - 01943143 _____ () C:\Windows\WindowsUpdate.log
2015-02-07 09:11 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-06 22:43 - 2014-06-12 23:47 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-06 18:25 - 2012-12-29 18:25 - 00000392 _____ () C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
2015-02-05 23:36 - 2014-06-27 14:57 - 00000000 ____D () C:\Users\dirkdererste\Documents\AVerTV
2015-02-05 19:39 - 2012-04-08 09:03 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-02-05 19:39 - 2011-05-21 12:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-02-04 23:50 - 2011-01-06 16:43 - 00000000 ____D () C:\Users\dirkdererste
2015-02-01 10:11 - 2014-09-14 00:30 - 00259816 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-01 00:14 - 2014-09-14 09:32 - 00057120 _____ () C:\Users\dirkdererste\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-01 00:09 - 2014-09-19 19:44 - 00000000 ____D () C:\Users\dirkdererste\AppData\Local\AvgSetupLog
2015-02-01 00:04 - 2011-11-15 19:32 - 00000000 ____D () C:\ProgramData\MFAData
2015-01-31 20:54 - 2014-11-02 10:34 - 00000000 ____D () C:\Users\dirkdererste\Desktop\Neuer Ordner
2015-01-30 23:26 - 2012-05-06 11:55 - 00000000 ____D () C:\Windows\de
2015-01-30 17:23 - 2014-09-19 19:58 - 00037176 _____ (AVG Technologies) C:\Windows\system32\TURegOpt.exe
2015-01-29 18:32 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\tracing
2015-01-27 19:06 - 2013-10-21 16:27 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-27 19:05 - 2011-01-10 00:43 - 00000000 ____D () C:\Program Files\Java
2015-01-27 19:04 - 2014-11-04 16:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-01-27 19:03 - 2014-11-04 16:35 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2015-01-15 22:52 - 2012-07-27 19:58 - 00000000 ____D () C:\Users\dirkdererste\AppData\Roaming\Canon
2015-01-15 20:45 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-01-14 17:28 - 2013-07-19 12:23 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 17:13 - 2006-11-02 11:24 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-01-12 23:59 - 2011-01-07 15:25 - 00000000 ___RD () C:\Users\dirkdererste\Desktop\Kram

==================== Files in the root of some directories =======

2007-06-12 19:34 - 2007-06-12 19:34 - 0035822 _____ () C:\Program Files\Common Files\ASPG_icon.ico
2008-05-22 18:35 - 2008-05-22 18:35 - 0051962 _____ () C:\Program Files\Common Files\banner.jpg
2008-07-02 04:28 - 2008-07-02 04:28 - 0061440 _____ () C:\Program Files\Common Files\CPInstallAction.dll
2011-10-30 00:00 - 2011-10-30 00:00 - 0024206 _____ () C:\Users\dirkdererste\AppData\Roaming\UserTile.png
2014-09-27 14:04 - 2014-09-27 14:05 - 0010828 _____ () C:\Users\dirkdererste\AppData\Roaming\WtgInstaller.txt
2011-01-06 20:24 - 2014-08-27 22:09 - 0001356 _____ () C:\Users\dirkdererste\AppData\Local\d3d9caps.dat
2011-11-21 21:46 - 2011-11-21 21:46 - 0000000 _____ () C:\Users\dirkdererste\AppData\Local\{0CE875FA-9C01-4FE6-91E4-8DD35D1352B1}

Some content of TEMP:
====================
C:\Users\dirkdererste\AppData\Local\Temp\avguirn_082101543405.exe
C:\Users\dirkdererste\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\dirkdererste\AppData\Local\Temp\Quarantine.exe
C:\Users\dirkdererste\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-07 09:18

==================== End Of Log ============================
         
--- --- ---

Alt 08.02.2015, 11:16   #14
schrauber
/// the machine
/// TB-Ausbilder
 

general crawlers - Standard

general crawlers



Adobe updaten.

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19ab7c-cbab-11e3-b7e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abdb-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abe7-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe8a-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe92-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe9e-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5dd-d506-11e3-befd-c030a9561ac3} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5e9-d506-11e3-befd-b68ac94258b5} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {31011372-66a4-11e4-88f4-adb511af100e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b50-3846-11e4-b727-a594aa94d86e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b5b-3846-11e4-b727-cfe712892541} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4235e5bc-8deb-11e3-bea2-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd209-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd244-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd24e-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd256-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd262-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb3442b-1faf-11e4-94c1-9483cebc1803} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb34437-1faf-11e4-94c1-ebf9039c5468} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5061e-2d56-11e4-806c-82b39df6fe7f} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5063d-2d56-11e4-806c-ff8e48defdcd} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {5899778b-f65b-11e3-908a-fe702680487d} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {589977db-f65b-11e3-908a-d444832a8c51} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7534b009-f659-11e3-935b-983f9ae39f7f} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba568-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba588-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {84d86f73-ebcf-11e3-99f4-e91098103f7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c282-3821-11e4-ac47-8fad69652c89} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c28d-3821-11e4-ac47-98a026ee637b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {8918ebcd-f632-11e3-a4cc-aae446c3b7d9} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {98b2279a-f666-11e3-82bf-8691ac93757f} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9d60af46-6833-11e4-9ae1-81f053ff7d7b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f017-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f054-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247885d-d82f-11e3-afed-ff56e36041fd} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247889a-d82f-11e3-afed-987030581f5d} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {b4a4281b-2f93-11e4-a053-b7ed9dff2029} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {ca5b6dde-19e3-11e0-83b8-806e6f6e6963} - E:\Autorun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {d85a1d2a-462a-11e4-94c3-8888219aad9a} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {db596716-c7e8-11e3-bdee-001e101fe70e} - I:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f01bf-2e39-11e4-b425-806e6f6e6963} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f0200-2e39-11e4-b425-c3e18252350b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {faf8fc99-6d70-11e4-b1d1-f474d68c3f10} - F:\AutoRun.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
Emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.





Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.02.2015, 19:24   #15
dms3333
 
general crawlers - Standard

general crawlers



hallo

also eine Fixlog.txt erstellt das nicht , es erstellt eine FRST.txt und eine Addition.txt Datei .

hallo , nochmal

jetzt ging`s doch

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 08-02-2015
Ran by dirkdererste at 2015-02-09 19:03:58 Run:1
Running from C:\Users\dirkdererste\Desktop
Loaded Profiles: dirkdererste (Available profiles: dirkdererste)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19ab7c-cbab-11e3-b7e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abdb-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {0e19abe7-cbab-11e3-b7e1-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe8a-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe92-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {18a9fe9e-c7c1-11e3-bd56-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5dd-d506-11e3-befd-c030a9561ac3} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {2505d5e9-d506-11e3-befd-b68ac94258b5} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {31011372-66a4-11e4-88f4-adb511af100e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b50-3846-11e4-b727-a594aa94d86e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {41a94b5b-3846-11e4-b727-cfe712892541} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4235e5bc-8deb-11e3-bea2-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd209-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd244-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd24e-cc5b-11e3-bf9d-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd256-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {437dd262-cc5b-11e3-bf9d-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb3442b-1faf-11e4-94c1-9483cebc1803} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {4fb34437-1faf-11e4-94c1-ebf9039c5468} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5061e-2d56-11e4-806c-82b39df6fe7f} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {53a5063d-2d56-11e4-806c-ff8e48defdcd} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {5899778b-f65b-11e3-908a-fe702680487d} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {589977db-f65b-11e3-908a-d444832a8c51} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7534b009-f659-11e3-935b-983f9ae39f7f} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba568-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {7f8ba588-c57e-11e3-9624-00235462ea7e} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {84d86f73-ebcf-11e3-99f4-e91098103f7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c282-3821-11e4-ac47-8fad69652c89} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {85d3c28d-3821-11e4-ac47-98a026ee637b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {8918ebcd-f632-11e3-a4cc-aae446c3b7d9} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {98b2279a-f666-11e3-82bf-8691ac93757f} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9d60af46-6833-11e4-9ae1-81f053ff7d7b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f017-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {9e75f054-cc80-11e3-86e1-00235462ea7e} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247885d-d82f-11e3-afed-ff56e36041fd} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {a247889a-d82f-11e3-afed-987030581f5d} - F:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {b4a4281b-2f93-11e4-a053-b7ed9dff2029} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {ca5b6dde-19e3-11e0-83b8-806e6f6e6963} - E:\Autorun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {d85a1d2a-462a-11e4-94c3-8888219aad9a} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {db596716-c7e8-11e3-bdee-001e101fe70e} - I:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f01bf-2e39-11e4-b425-806e6f6e6963} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {f08f0200-2e39-11e4-b425-c3e18252350b} - F:\AutoRun.exe
HKU\S-1-5-21-1588098070-3651612994-842810468-1000\...\MountPoints2: {faf8fc99-6d70-11e4-b1d1-f474d68c3f10} - F:\AutoRun.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
Emptytemp:

*****************

"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e19ab7c-cbab-11e3-b7e1-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{0e19ab7c-cbab-11e3-b7e1-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e19abdb-cbab-11e3-b7e1-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{0e19abdb-cbab-11e3-b7e1-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e19abe7-cbab-11e3-b7e1-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{0e19abe7-cbab-11e3-b7e1-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{18a9fe8a-c7c1-11e3-bd56-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{18a9fe8a-c7c1-11e3-bd56-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{18a9fe92-c7c1-11e3-bd56-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{18a9fe92-c7c1-11e3-bd56-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{18a9fe9e-c7c1-11e3-bd56-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{18a9fe9e-c7c1-11e3-bd56-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2505d5dd-d506-11e3-befd-c030a9561ac3}" => Key deleted successfully.
HKCR\CLSID\{2505d5dd-d506-11e3-befd-c030a9561ac3} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2505d5e9-d506-11e3-befd-b68ac94258b5}" => Key deleted successfully.
HKCR\CLSID\{2505d5e9-d506-11e3-befd-b68ac94258b5} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{31011372-66a4-11e4-88f4-adb511af100e}" => Key deleted successfully.
HKCR\CLSID\{31011372-66a4-11e4-88f4-adb511af100e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{41a94b50-3846-11e4-b727-a594aa94d86e}" => Key deleted successfully.
HKCR\CLSID\{41a94b50-3846-11e4-b727-a594aa94d86e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{41a94b5b-3846-11e4-b727-cfe712892541}" => Key deleted successfully.
HKCR\CLSID\{41a94b5b-3846-11e4-b727-cfe712892541} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4235e5bc-8deb-11e3-bea2-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{4235e5bc-8deb-11e3-bea2-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{437dd209-cc5b-11e3-bf9d-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{437dd209-cc5b-11e3-bf9d-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{437dd244-cc5b-11e3-bf9d-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{437dd244-cc5b-11e3-bf9d-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{437dd24e-cc5b-11e3-bf9d-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{437dd24e-cc5b-11e3-bf9d-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{437dd256-cc5b-11e3-bf9d-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{437dd256-cc5b-11e3-bf9d-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{437dd262-cc5b-11e3-bf9d-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{437dd262-cc5b-11e3-bf9d-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4fb3442b-1faf-11e4-94c1-9483cebc1803}" => Key deleted successfully.
HKCR\CLSID\{4fb3442b-1faf-11e4-94c1-9483cebc1803} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4fb34437-1faf-11e4-94c1-ebf9039c5468}" => Key deleted successfully.
HKCR\CLSID\{4fb34437-1faf-11e4-94c1-ebf9039c5468} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{53a5061e-2d56-11e4-806c-82b39df6fe7f}" => Key deleted successfully.
HKCR\CLSID\{53a5061e-2d56-11e4-806c-82b39df6fe7f} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{53a5063d-2d56-11e4-806c-ff8e48defdcd}" => Key deleted successfully.
HKCR\CLSID\{53a5063d-2d56-11e4-806c-ff8e48defdcd} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5899778b-f65b-11e3-908a-fe702680487d}" => Key deleted successfully.
HKCR\CLSID\{5899778b-f65b-11e3-908a-fe702680487d} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{589977db-f65b-11e3-908a-d444832a8c51}" => Key deleted successfully.
HKCR\CLSID\{589977db-f65b-11e3-908a-d444832a8c51} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7534b009-f659-11e3-935b-983f9ae39f7f}" => Key deleted successfully.
HKCR\CLSID\{7534b009-f659-11e3-935b-983f9ae39f7f} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7f8ba568-c57e-11e3-9624-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{7f8ba568-c57e-11e3-9624-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7f8ba588-c57e-11e3-9624-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{7f8ba588-c57e-11e3-9624-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{84d86f73-ebcf-11e3-99f4-e91098103f7e}" => Key deleted successfully.
HKCR\CLSID\{84d86f73-ebcf-11e3-99f4-e91098103f7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{85d3c282-3821-11e4-ac47-8fad69652c89}" => Key deleted successfully.
HKCR\CLSID\{85d3c282-3821-11e4-ac47-8fad69652c89} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{85d3c28d-3821-11e4-ac47-98a026ee637b}" => Key deleted successfully.
HKCR\CLSID\{85d3c28d-3821-11e4-ac47-98a026ee637b} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8918ebcd-f632-11e3-a4cc-aae446c3b7d9}" => Key deleted successfully.
HKCR\CLSID\{8918ebcd-f632-11e3-a4cc-aae446c3b7d9} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{98b2279a-f666-11e3-82bf-8691ac93757f}" => Key deleted successfully.
HKCR\CLSID\{98b2279a-f666-11e3-82bf-8691ac93757f} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9d60af46-6833-11e4-9ae1-81f053ff7d7b}" => Key deleted successfully.
HKCR\CLSID\{9d60af46-6833-11e4-9ae1-81f053ff7d7b} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e75f017-cc80-11e3-86e1-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{9e75f017-cc80-11e3-86e1-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e75f054-cc80-11e3-86e1-00235462ea7e}" => Key deleted successfully.
HKCR\CLSID\{9e75f054-cc80-11e3-86e1-00235462ea7e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a247885d-d82f-11e3-afed-ff56e36041fd}" => Key deleted successfully.
HKCR\CLSID\{a247885d-d82f-11e3-afed-ff56e36041fd} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a247889a-d82f-11e3-afed-987030581f5d}" => Key deleted successfully.
HKCR\CLSID\{a247889a-d82f-11e3-afed-987030581f5d} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b4a4281b-2f93-11e4-a053-b7ed9dff2029}" => Key deleted successfully.
HKCR\CLSID\{b4a4281b-2f93-11e4-a053-b7ed9dff2029} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ca5b6dde-19e3-11e0-83b8-806e6f6e6963}" => Key deleted successfully.
HKCR\CLSID\{ca5b6dde-19e3-11e0-83b8-806e6f6e6963} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d85a1d2a-462a-11e4-94c3-8888219aad9a}" => Key deleted successfully.
HKCR\CLSID\{d85a1d2a-462a-11e4-94c3-8888219aad9a} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{db596716-c7e8-11e3-bdee-001e101fe70e}" => Key deleted successfully.
HKCR\CLSID\{db596716-c7e8-11e3-bdee-001e101fe70e} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f08f01bf-2e39-11e4-b425-806e6f6e6963}" => Key deleted successfully.
HKCR\CLSID\{f08f01bf-2e39-11e4-b425-806e6f6e6963} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f08f0200-2e39-11e4-b425-c3e18252350b}" => Key deleted successfully.
HKCR\CLSID\{f08f0200-2e39-11e4-b425-c3e18252350b} => Key not found.
"HKU\S-1-5-21-1588098070-3651612994-842810468-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{faf8fc99-6d70-11e4-b1d1-f474d68c3f10}" => Key deleted successfully.
HKCR\CLSID\{faf8fc99-6d70-11e4-b1d1-f474d68c3f10} => Key not found.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
EmptyTemp: => Removed 230.4 MB temporary data.


The system needed a reboot.

==== End of Fixlog 19:04:10 ====

hat gleich neugestartet .
was mir aufgefallen ist , meine googlestarobefläche sieht anders aus , das hatte ich mal was runtergeladen , weil es sich als googlechromedownload ausgab , was dann irgendwie alles verändert hat und sich ewig nicht mehr wegmachen lies , ich glaube dass das jetzt ganz weg ist .habe aber vergessen wie der scheiß geheissen hat . das hatte jedenfalls jeden browser übernommen . jetzt scheint das ganz weg zu sein .
und das tuneup dachte ich ist ganz gut , weil mei laptop immer so laut ist , dachte ich ich kann dadurch was verbessern , ist aber nicht so . aber das mir das was kaputt macht habe ich jetzt auch noch nicht gemerkt , und ich nehme das schon seit 4 jahren oder so .
was du jetzt mit defogger meinst weiß ich aber nicht , soll ich das jetzt nachdem alles fertig ist runterladen und durchlaufen lassen ? was ist wenn ich das was ich runtergeladen habe einfach behalte und es ab und zu alles so durchlaufen lasse wie jetzt die tage ? stört doch nicht oder ?


ansonsten danke für die hilfe . wenn ich mal etwas abzwiegen kann spende ich mal was .
arbeite z.zt. nicht , da ist das etwas schwierig .
wenn du das löschst was du löschen willst , bleibt ja die konversation hier erhalte , so das ich jederzeit mal was nachlesen kann , oder ?
ansonsten nochmal danke .
m.f.g.

Antwort

Themen zu general crawlers
ahnung, chrome, entferne, entfernen, gefährlich, general, general crawlers, geschlossen, geändert, google, guten, hinweis, kaufen, mindestens, nichts, notwendig, profil, runterladen




Zum Thema general crawlers - Guten Tag ich wollte gern erfragen was "general crawlers" sind , steht zwar viel bei google , aber dann auch wieder nichts , mal sind sie gefährlich und man soll - general crawlers...
Archiv
Du betrachtest: general crawlers auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.