![]() |
|
Log-Analyse und Auswertung: Windows8, Popups, Werbung im Browser,Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Windows8, Popups, Werbung im Browser, Hallo, ich habe seit einiger Zeit sehr nervige Probleme mit meinem Laptop. Ich habe leider nicht ganz so viel Ahnung von Pc`s und hoffe das ihr mir helfen könnt ![]() Ich habe Windows 8.Sobald ich im Firefox bin,öffnen sich andauernd Popups Tabs und viel viel Werbung in seperaten Fenstern. Seit ca 2 Wochen ist es noch schlimmer geworden,ich brauche noch nicht einmal ein neuen Tab öffnen,schon öffnen sie Popups Fenster.Mein Laptop ist allgemein seit dem sehr sehr langsam geworden,was mich zur Weißglut bringt. Ich habe schon einige Treads hier gelesen und von selbst das Programm Combofix heruntergeladen.Werde dies hoffentlich gleich hier richtig einsetzen. Ganz Liebe Grüße Martina ComboFix 14-02-20.01 - Sam 20.02.2014 23:24:06.1.4 - x64 Microsoft Windows 8 6.2.9200.0.1252.49.1031.18.3914.1373 [GMT 1:00] ausgeführt von:: c:\users\Sam\Downloads\ComboFix.exe AV: Avira Desktop *Enabled/Outdated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Avira Desktop *Enabled/Outdated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\END c:\program files (x86)\HappyLyrics c:\program files (x86)\LyricStar c:\program files (x86)\SearchProtect c:\program files (x86)\SearchProtect\EULA.txt c:\program files (x86)\SearchProtect\Main\bin\CltMngSvc.exe c:\program files (x86)\SearchProtect\Main\bin\SPTool.dll c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1389820982737 c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1389820983141 c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1390842325098 c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1390842325288 c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1391059342992 c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1391059344773 c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1391498605506 c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1391498605584 c:\program files (x86)\SearchProtect\Main\bin\uninstall.exe c:\program files (x86)\SearchProtect\Main\rep\SystemRepository.dat c:\program files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe c:\program files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe c:\program files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll c:\program files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll c:\program files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll c:\program files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll c:\program files (x86)\SearchProtect\UI\bin\cltmngui.exe c:\program files (x86)\SearchProtect\UI\dialogs\bubble\bubble.css c:\program files (x86)\SearchProtect\UI\dialogs\bubble\bubble.html c:\program files (x86)\SearchProtect\UI\dialogs\bubble\bubble.js c:\program files (x86)\SearchProtect\UI\dialogs\bubble\defaults.js c:\program files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\bg.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\hez.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\text-field.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\v.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\x.png c:\program files (x86)\SearchProtect\UI\dialogs\libs\defaults.js c:\program files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js c:\program files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js c:\program files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js c:\program files (x86)\SearchProtect\UI\dialogs\libs\main.js c:\program files (x86)\SearchProtect\UI\dialogs\libs\SPDialogAPI.js c:\program files (x86)\SearchProtect\UI\dialogs\protection\defaults.js c:\program files (x86)\SearchProtect\UI\dialogs\protection\protection.css c:\program files (x86)\SearchProtect\UI\dialogs\protection\protection.html c:\program files (x86)\SearchProtect\UI\dialogs\protection\protection.js c:\program files (x86)\SearchProtect\UI\dialogs\protectionDS\defaults.js c:\program files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.css c:\program files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.html c:\program files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.js c:\program files (x86)\SearchProtect\UI\dialogs\settings.html c:\program files (x86)\SearchProtect\UI\dialogs\settings\defaults.js c:\program files (x86)\SearchProtect\UI\dialogs\settings\settings.css c:\program files (x86)\SearchProtect\UI\dialogs\settings\settings.html c:\program files (x86)\SearchProtect\UI\dialogs\settings\settings.js c:\program files (x86)\SearchProtect\UI\dialogs\style.css c:\program files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js c:\program files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css c:\program files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html c:\program files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js c:\program files (x86)\uLyrics c:\program files (x86)\uLyrics\00.crx c:\program files (x86)\uLyrics\00.xpi c:\program files (x86)\uLyrics\01.crx c:\program files (x86)\uLyrics\01.xpi c:\program files (x86)\uLyrics\02.crx c:\program files (x86)\uLyrics\02.xpi c:\program files (x86)\uLyrics\130.crx c:\program files (x86)\uLyrics\130.dat c:\program files (x86)\uLyrics\130.xpi c:\program files (x86)\uLyrics\chrome.manifest c:\program files (x86)\uLyrics\crx.dat c:\program files (x86)\uLyrics\crx.db c:\program files (x86)\uLyrics\sqlite3.dll c:\program files (x86)\uLyrics\Uninstall.exe c:\program files (x86)\uLyrics\xpi.dat c:\program files (x86)\uLyrics\xpi.db c:\program files (x86)\Uniblue\SpeedUpMyPC c:\program files (x86)\Uniblue\SpeedUpMyPC\cwebpage.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\InstallerExtensions.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\intermediate_views.dat c:\program files (x86)\Uniblue\SpeedUpMyPC\latest_scan_results.xsl c:\program files (x86)\Uniblue\SpeedUpMyPC\Launcher.exe c:\program files (x86)\Uniblue\SpeedUpMyPC\library.dat c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\br\br.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\br\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\de\de.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\de\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\dk\dk.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\dk\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\en\en.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\en\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\es\es.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\es\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\fi\fi.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\fi\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\fr\fr.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\fr\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\it\it.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\it\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\jp\jp.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\jp\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\nl\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\nl\nl.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\no\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\no\no.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\ru\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\ru\ru.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\se\LC_MESSAGES\messages.mo c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\se\se.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\Microsoft.VC90.CRT.manifest c:\program files (x86)\Uniblue\SpeedUpMyPC\msvcp90.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\msvcr90.dll c:\program files (x86)\Uniblue\SpeedUpMyPC\repair_transform.xsl c:\program files (x86)\Uniblue\SpeedUpMyPC\sp_move_serial.exe c:\program files (x86)\Uniblue\SpeedUpMyPC\spmonitor.exe c:\program files (x86)\Uniblue\SpeedUpMyPC\spnotifier.exe c:\program files (x86)\Uniblue\SpeedUpMyPC\sump.exe c:\program files (x86)\Uniblue\SpeedUpMyPC\Third Party Terms\comtypes.txt c:\program files (x86)\Uniblue\SpeedUpMyPC\Third Party Terms\cwebpage.dll.html c:\program files (x86)\Uniblue\SpeedUpMyPC\Third Party Terms\decorator.py.txt c:\program files (x86)\Uniblue\SpeedUpMyPC\Third Party Terms\ordereddict.py.txt c:\program files (x86)\Uniblue\SpeedUpMyPC\Third Party Terms\py2exe.txt c:\program files (x86)\Uniblue\SpeedUpMyPC\Third Party Terms\python-changes.txt c:\program files (x86)\Uniblue\SpeedUpMyPC\Third Party Terms\python.txt c:\program files (x86)\Uniblue\SpeedUpMyPC\Third Party Terms\simplejson.txt c:\program files (x86)\Uniblue\SpeedUpMyPC\Third Party Terms\wmi.txt c:\program files (x86)\Uniblue\SpeedUpMyPC\unins000.dat c:\program files (x86)\Uniblue\SpeedUpMyPC\unins000.exe c:\program files (x86)\Uniblue\SpeedUpMyPC\unins000.msg c:\program files (x86)\Uniblue\SpeedUpMyPC\views.dat c:\users\Sam\AppData\Local\Temp\jna-Sam\jna588979871683591182.dll c:\users\Sam\AppData\Roaming\Microsoft\Windows\Recent\Thumbs.db c:\windows\Tasks\SpeedUpMyPC.job . . ((((((((((((((((((((((( Dateien erstellt von 2014-01-20 bis 2014-02-20 )))))))))))))))))))))))))))))) . . 2014-02-20 22:39 . 2014-02-20 22:39 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-02-20 22:39 . 2014-02-20 22:39 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2014-02-20 22:06 . 2014-02-20 22:06 312744 ----a-w- c:\windows\system32\javaws.exe 2014-02-20 22:06 . 2014-02-20 22:06 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2014-02-20 22:06 . 2014-02-20 22:06 189352 ----a-w- c:\windows\system32\javaw.exe 2014-02-20 22:06 . 2014-02-20 22:06 189352 ----a-w- c:\windows\system32\java.exe 2014-02-20 22:06 . 2014-02-20 22:06 -------- d-----w- c:\program files\Java 2014-02-15 20:11 . 2014-02-17 20:06 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2014-02-12 23:29 . 2014-02-01 09:19 2241536 ----a-w- c:\windows\system32\wininet.dll 2014-02-12 23:28 . 2014-01-12 23:30 2238976 ----a-w- c:\windows\system32\d3d10warp.dll 2014-02-12 23:28 . 2013-11-20 00:15 3842560 ----a-w- c:\windows\system32\d2d1.dll 2014-02-12 23:28 . 2013-11-19 23:57 3288576 ----a-w- c:\windows\SysWow64\d2d1.dll 2014-02-12 23:28 . 2014-01-12 23:30 2032640 ----a-w- c:\windows\SysWow64\d3d10warp.dll 2014-02-04 08:02 . 2014-02-04 08:02 -------- d-----w- c:\users\Sam\AppData\Local\AskPartnerNetwork . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-02-16 23:34 . 2013-03-12 13:59 88567024 ----a-w- c:\windows\system32\MRT.exe 2014-01-30 21:10 . 2013-11-22 10:17 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-01-30 21:10 . 2013-11-22 10:17 694240 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-12-18 13:28 . 2013-09-07 18:13 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-12-18 13:28 . 2013-09-07 18:13 131576 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-12-18 13:28 . 2013-09-07 18:13 108440 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-12-07 06:37 . 2014-01-15 21:46 688640 ----a-w- c:\windows\system32\WSShared.dll 2013-12-07 06:37 . 2014-01-15 21:46 163840 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-12-07 05:15 . 2014-01-15 21:46 562688 ----a-w- c:\windows\SysWow64\WSShared.dll 2013-12-07 05:15 . 2014-01-15 21:46 124928 ----a-w- c:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-11-23 06:43 . 2013-12-17 22:58 420864 ----a-w- c:\windows\system32\WMPhoto.dll 2013-11-23 05:05 . 2013-12-17 22:58 368640 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2010-03-02 12:18 . 2013-01-18 13:55 417792 ----a-w- c:\program files (x86)\kompozer.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{e44a1809-4d10-4ab8-b343-3326b64c7cdd}"= "c:\program files (x86)\entrusted\prxtbentr.dll" [2013-03-05 231168] . [HKEY_CLASSES_ROOT\clsid\{e44a1809-4d10-4ab8-b343-3326b64c7cdd}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}] 2013-12-20 19:17 12240 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}] 2013-05-20 10:02 295832 ----a-w- c:\program files (x86)\Delta\delta\1.8.21.5\bh\delta.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{e44a1809-4d10-4ab8-b343-3326b64c7cdd}] 2013-03-05 12:37 231168 ----a-w- c:\program files (x86)\entrusted\prxtbentr.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}] 2013-07-11 20:29 277512 ----a-w- c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{e44a1809-4d10-4ab8-b343-3326b64c7cdd}"= "c:\program files (x86)\entrusted\prxtbentr.dll" [2013-03-05 231168] "{82E1477C-B154-48D3-9891-33D83C26BCD3}"= "c:\program files (x86)\Delta\delta\1.8.21.5\deltaTlbr.dll" [2013-05-20 284056] "{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-12-20 12240] . [HKEY_CLASSES_ROOT\clsid\{e44a1809-4d10-4ab8-b343-3326b64c7cdd}] . [HKEY_CLASSES_ROOT\clsid\{82e1477c-b154-48d3-9891-33d83c26bcd3}] [HKEY_CLASSES_ROOT\delta.deltadskBnd.1] [HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] [HKEY_CLASSES_ROOT\delta.deltadskBnd] . [HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1EldosIconOverlay-cbfs4-0] @="{8B2D6EE4-8991-49EF-8527-C5D531AF328E}" [HKEY_CLASSES_ROOT\CLSID\{8B2D6EE4-8991-49EF-8527-C5D531AF328E}] 2013-07-03 10:21 156520 ----a-w- c:\program files (x86)\Common Files\CBFS\WOW64\cbfsMntNtf4.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Sam\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Sam\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Sam\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay-cbfs4-0] @="{19AEA017-901E-44D7-9432-E69D17D9B3F6}" [HKEY_CLASSES_ROOT\CLSID\{19AEA017-901E-44D7-9432-E69D17D9B3F6}] 2013-07-03 10:21 156520 ----a-w- c:\program files (x86)\Common Files\CBFS\WOW64\cbfsMntNtf4.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HP Photosmart 5510 series (NET)"="c:\program files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" [2012-10-17 2573416] "BackgroundContainer"="c:\users\Sam\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll" [2013-11-06 319264] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Dolby Home Theater v4"="c:\dolby pcee4\pcee4.exe" [2012-07-25 508656] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "PDFPrint"="c:\program files (x86)\PDF24\pdf24.exe" [2013-02-19 162856] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-02-20 689744] "ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-12-20 1778640] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-11-01 152392] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-10-28 49208] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SpUninstallDeleteDir"="rmdir" [X] "IsMyWinLockerReboot"="msiexec.exe" [2012-07-26 62976] . c:\users\Sam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Sam\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-1-3 30714328] . c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\ Acer Backup Manager Tray.lnk - c:\program files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe -h -k [2012-8-23 533568] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "EnableUIADesktopToggle"= 0 (0x0) "EnableCursorSuppression"= 1 (0x1) "ConsentPromptBehaviorUser"= 3 (0x3) . [hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\SharedTaskScheduler] "{D027F06D-B66D-49D6-A57F-C782D5638BD3}"= "c:\program files (x86)\Common Files\CBFS\WOW64\cbfsMntNtf4.dll" [2013-07-03 156520] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "EldosMountNotificator-cbfs4-0"= {D027F06D-B66D-49D6-A57F-C782D5638BD3} - c:\program files (x86)\Common Files\CBFS\WOW64\cbfsMntNtf4.dll [2013-07-03 156520] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x] R2 CLKMSVC10_96E434EB;CyberLink Product - 2012/09/28 00:44;c:\program files (x86)\Acer\clear.fi SDK21\Movie\NavFilter\kmsvc.exe;c:\program files (x86)\Acer\clear.fi SDK21\Movie\NavFilter\kmsvc.exe [x] R2 CltMngSvc;Search Protect by Conduit Service;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R2 tor;Tor Win32 Service;c:\program files (x86)\Tor\tor.exe;c:\program files (x86)\Tor\tor.exe [x] R3 DeviceFastLaneService;Device Fast-lane Service;c:\program files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe;c:\program files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [x] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbdev.sys [x] R3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x] S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 cbfs4-0;cbfs4-0;c:\program files (x86)\Common Files\CBFS\cbfs4.sys;c:\program files (x86)\Common Files\CBFS\cbfs4.sys [x] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 APNMCP;Ask Aktualisierungsdienst;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x] S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [x] S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x] S2 CCDMonitorService;CCDMonitorService;c:\program files (x86)\Acer\Acer Cloud\CCDMonitorService.exe;c:\program files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [x] S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x] S2 ETDService;Elan Service;c:\program files\Elantech\ETDService.exe;c:\program files\Elantech\ETDService.exe [x] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [x] S2 RfButtonDriverService;Dritek RF Button Command Service;c:\windows\RfBtnSvc64.exe;c:\windows\RfBtnSvc64.exe [x] S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x] S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x] S3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x] S3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;c:\windows\System32\drivers\btath_bus.sys;c:\windows\SYSNATIVE\drivers\btath_bus.sys [x] S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\System32\drivers\btath_hcrp.sys;c:\windows\SYSNATIVE\drivers\btath_hcrp.sys [x] S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x] S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\System32\drivers\btath_rcp.sys;c:\windows\SYSNATIVE\drivers\btath_rcp.sys [x] S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x] S3 BthLEEnum;Treiber für energiearme Bluetooth-Geräte;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x] S3 ePowerSvc;ePower Service;c:\program files\Acer\Acer Power Management\ePowerSvc.exe;c:\program files\Acer\Acer Power Management\ePowerSvc.exe [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C63x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C63x64.sys [x] S3 Ps2Kb2Hid;PS/2 Keyboard to HID Driver;c:\windows\System32\drivers\aPs2Kb2Hid.sys;c:\windows\SYSNATIVE\drivers\aPs2Kb2Hid.sys [x] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}] 2013-09-05 14:04 215416 ----a-w- c:\program files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll . Inhalt des "geplante Tasks" Ordners . 2014-02-20 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-25 22:44] . 2014-02-20 c:\windows\Tasks\dsmonitor.job - c:\program files (x86)\Uniblue\DriverScanner\dsmonitor.exe [2013-07-11 13:47] . 2014-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cec6062773ac00.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-16 16:22] . 2014-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-16 16:22] . 2013-09-16 c:\windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job - c:\program files (x86)\TuneUp Utilities 2013\OneClick.exe [2013-01-28 13:15] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}] 2013-12-20 19:17 13776 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}] 2013-07-11 20:29 336904 ----a-w- c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll" [2013-12-20 13776] . [HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1EldosIconOverlay-cbfs4-0] @="{8B2D6EE4-8991-49EF-8527-C5D531AF328E}" [HKEY_CLASSES_ROOT\CLSID\{8B2D6EE4-8991-49EF-8527-C5D531AF328E}] 2013-07-03 10:22 182632 ----a-w- c:\program files (x86)\Common Files\CBFS\cbfsMntNtf4.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Sam\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Sam\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Sam\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Sam\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay-cbfs4-0] @="{19AEA017-901E-44D7-9432-E69D17D9B3F6}" [HKEY_CLASSES_ROOT\CLSID\{19AEA017-901E-44D7-9432-E69D17D9B3F6}] 2013-07-03 10:22 182632 ----a-w- c:\program files (x86)\Common Files\CBFS\cbfsMntNtf4.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-07-27 12937872] "RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2012-07-10 1214608] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-03-18 171040] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-03-18 399392] "Persistence"="c:\windows\system32\igfxpers.exe" [2013-03-18 441888] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler] "{D027F06D-B66D-49D6-A57F-C782D5638BD3}"= "c:\program files (x86)\Common Files\CBFS\cbfsMntNtf4.dll" [2013-07-03 182632] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=10&cc=&mi=589b67d000000000000020689d6fc7dd mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\Sam\AppData\Roaming\Mozilla\Firefox\Profiles\5375jkd4.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3281675&CUI=UN16582794111258225&UM=2&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/ FF - user.js: extensions.delta.tlbrSrchUrl - FF - user.js: extensions.delta.id - 589b67d000000000000020689d6fc7dd FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} FF - user.js: extensions.delta.instlDay - 15897 FF - user.js: extensions.delta.vrsn - 1.8.21.5 FF - user.js: extensions.delta.vrsni - 1.8.21.5 FF - user.js: extensions.delta.vrsnTs - 1.8.21.522:24 FF - user.js: extensions.delta.prtnrId - delta FF - user.js: extensions.delta.prdct - delta FF - user.js: extensions.delta.aflt - babsst FF - user.js: extensions.delta.smplGrp - none FF - user.js: extensions.delta.tlbrId - base FF - user.js: extensions.delta.instlRef - sst FF - user.js: extensions.delta.dfltLng - de FF - user.js: extensions.delta.excTlbr - false FF - user.js: extensions.delta.ffxUnstlRst - true FF - user.js: extensions.delta.admin - false FF - user.js: extensions.delta_i.babTrack - affID=121563&tl=162546700&tsp=4940 FF - user.js: extensions.delta_i.babExt - FF - user.js: extensions.delta_i.srcExt - ss FF - user.js: extensions.delta.autoRvrt - false FF - user.js: extensions.delta.rvrt - false FF - user.js: extensions.delta.newTab - false FF - user.js: extensions.autoDisableScopes - 0 FF - user.js: extensions.shownSelectionUI - true FF - user.js: extensions.Softonic.tlbrSrchUrl - hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=589b67d000000000000020689d6fc7dd&q= FF - user.js: extensions.Softonic.id - 589b67d000000000000020689d6fc7dd FF - user.js: extensions.Softonic.appId - {7ABBFE1C-E485-44AA-8F36-353751B4124D} FF - user.js: extensions.Softonic.instlDay - 16058 FF - user.js: extensions.Softonic.vrsn - 1.8.21.14 FF - user.js: extensions.Softonic.vrsni - 1.8.21.14 FF - user.js: extensions.Softonic.vrsnTs - 1.8.21.1416:42 FF - user.js: extensions.Softonic.prtnrId - softonic FF - user.js: extensions.Softonic.prdct - Softonic FF - user.js: extensions.Softonic.aflt - OC FF - user.js: extensions.Softonic.smplGrp - none FF - user.js: extensions.Softonic.tlbrId - opencandy2013 FF - user.js: extensions.Softonic.instlRef - MOY00621 FF - user.js: extensions.Softonic.dfltLng - de FF - user.js: extensions.Softonic.excTlbr - false FF - user.js: extensions.Softonic.ffxUnstlRst - false FF - user.js: extensions.Softonic.admin - false FF - user.js: extensions.Softonic.autoRvrt - false FF - user.js: extensions.Softonic.rvrt - false FF - user.js: extensions.Softonic.hmpg - true FF - user.js: extensions.Softonic.hmpgUrl - hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=589b67d000000000000020689d6fc7dd FF - user.js: extensions.Softonic.dfltSrch - true FF - user.js: extensions.Softonic.srchPrvdr - Search the web (Softonic) FF - user.js: extensions.Softonic.dnsErr - true FF - user.js: extensions.Softonic.newTab - true FF - user.js: extensions.Softonic.newTabUrl - hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=589b67d000000000000020689d6fc7dd . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) Toolbar-Locked - (no file) WebBrowser-{E44A1809-4D10-4AB8-B343-3326B64C7CDD} - (no file) HKLM-Run-BtPreLoad - c:\program files (x86)\Bluetooth Suite\BtPreLoad.exe SSODL-EldosMountNotificator-cbfs4-0 REG_SZ {D027F06D-B66D-49D6-A57F-C782D5638BD3}- - (no file) AddRemove-SearchProtect - c:\progra~2\SearchProtect\Main\bin\uninstall.exe AddRemove-{594d45c1-9a2d-4581-9060-c0159fb819b0} - c:\program files (x86)\uLyrics\Uninstall.exe AddRemove-{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1 - c:\program files (x86)\Uniblue\SpeedUpMyPC\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}] @Denied: (A) (Everyone) "Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane\0] "Key"="ActionsPane" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) @SACL=(02 0000) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Launch Manager\LMutilps32.exe c:\windows\SysWOW64\Rundll32.exe c:\program files (x86)\Launch Manager\LManager.exe c:\program files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe c:\program files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe c:\users\Sam\AppData\Roaming\Dropbox\bin\Dropbox.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe c:\program files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe c:\program files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\windows\syswow64\wwahost.exe c:\program files (x86)\TuneUp Utilities 2013\TUAutoUpdateCheck.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-02-20 23:58:55 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-02-20 22:58 . Vor Suchlauf: 10 Verzeichnis(se), 88.134.754.304 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 91.846.868.992 Bytes frei . - - End Of File - - C08D8907FF495DF0C2C2B4E5D56DAE89 |