![]() |
| |||||||
Log-Analyse und Auswertung: Ebay Mahnung Mail Anhang geöffnetWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| | #1 |
| | Ebay Mahnung Mail Anhang geöffnet Hallo, meine Freundin hat an eine Mail mit einer angeblichen Mahnung von Ebay-Anwälten bekommen, hat aus Panik natürlich direkt den Anhang geöffnet und jetzt evtl nen Trojaner drauf? Ich habe bis jetzt wie in eurer Anleitung beschrieben defogger, frst und GMER drüberlaufen lassen. Die Logs dazu: FRST Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2014
Ran by Puschel (administrator) on KÖÖRRRT on 26-06-2014 23:13:36
Running from C:\Users\Puschel\Desktop
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\updrgui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-20] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-25] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-09-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491632 2012-09-10] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-17] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKU\S-1-5-21-2799476594-3240853191-3070442433-1002\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe "C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.uk.msn.com/HPNOT13/4
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM-x32 - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323895&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPFC3980F7-DD7B-4E02-9782-CE5F08F4EC13&q={searchTerms}&SSPV=
SearchScopes: HKCU - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll No File
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default
FF NewTab: about:blank
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\user.js
FF SearchPlugin: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: NoScript - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-19]
FF Extension: Adblock Plus - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-19]
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-09-18] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-06-17] (Avira Operations GmbH & Co. KG)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36520 2012-09-14] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-28] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-10] (Disc Soft Ltd)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-25] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-25] (Synaptics Incorporated)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-26 23:13 - 2014-06-26 23:13 - 00011904 _____ () C:\Users\Puschel\Desktop\FRST.txt
2014-06-26 23:11 - 2014-06-26 23:13 - 00000000 ____D () C:\FRST
2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log
2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable
2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe
2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe
2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe
2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-26 22:00 - 2014-06-26 22:01 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps
==================== One Month Modified Files and Folders =======
2014-06-26 23:13 - 2014-06-26 23:13 - 00011904 _____ () C:\Users\Puschel\Desktop\FRST.txt
2014-06-26 23:13 - 2014-06-26 23:11 - 00000000 ____D () C:\FRST
2014-06-26 23:11 - 2013-09-16 15:13 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2799476594-3240853191-3070442433-1002
2014-06-26 23:11 - 2012-10-20 07:07 - 00830120 _____ () C:\Windows\system32\perfh007.dat
2014-06-26 23:11 - 2012-10-20 07:07 - 00188224 _____ () C:\Windows\system32\perfc007.dat
2014-06-26 23:11 - 2012-07-26 09:28 - 01949368 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log
2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable
2014-06-26 23:10 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel
2014-06-26 23:07 - 2014-01-19 17:36 - 00000000 ____D () C:\Users\Puschel\AppData\Roaming\newnext.me
2014-06-26 23:06 - 2014-03-18 15:33 - 00437408 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-26 23:06 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-26 23:05 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 23:05 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 23:04 - 2013-09-16 15:06 - 01681996 _____ () C:\Windows\WindowsUpdate.log
2014-06-26 23:04 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-26 23:03 - 2014-04-10 19:04 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-26 23:02 - 2012-10-19 22:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-06-26 23:02 - 2012-08-04 00:37 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-06-26 23:00 - 2012-07-26 09:52 - 00000000 ____D () C:\Windows\ShellNew
2014-06-26 23:00 - 2012-07-26 07:26 - 00000076 _____ () C:\Windows\win.ini
2014-06-26 22:58 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-26 22:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe
2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe
2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe
2014-06-26 22:37 - 2014-04-14 18:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-26 22:02 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-06-26 22:01 - 2014-06-26 22:00 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps
2014-06-26 22:00 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel\AppData\Local\VirtualStore
2014-06-17 20:03 - 2013-09-24 12:47 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-06-17 20:03 - 2013-09-24 12:47 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
Some content of TEMP:
====================
C:\Users\Puschel\AppData\Local\Temp\6_Offer_15.exe
C:\Users\Puschel\AppData\Local\Temp\avgnt.exe
C:\Users\Puschel\AppData\Local\Temp\BackupSetup.exe
C:\Users\Puschel\AppData\Local\Temp\DownloadManager.exe
C:\Users\Puschel\AppData\Local\Temp\nse6761.exe
C:\Users\Puschel\AppData\Local\Temp\nse6BB5.exe
C:\Users\Puschel\AppData\Local\Temp\nse8D89.exe
C:\Users\Puschel\AppData\Local\Temp\nsq2AAE.exe
C:\Users\Puschel\AppData\Local\Temp\nsu64B2.exe
C:\Users\Puschel\AppData\Local\Temp\nsu6C52.exe
C:\Users\Puschel\AppData\Local\Temp\nsu6E75.exe
C:\Users\Puschel\AppData\Local\Temp\nsy69C0.exe
C:\Users\Puschel\AppData\Local\Temp\nsy8B94.exe
C:\Users\Puschel\AppData\Local\Temp\ose00000.exe
C:\Users\Puschel\AppData\Local\Temp\SearchProtectINT.exe
C:\Users\Puschel\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-26 21:59
==================== End Of Log ============================
GMER Beim Start von GMER kam direkt die Fehlermeldung "C:\Windows\System32\config\system Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird." Ich konnte danach aber ganz normal scannen. Nach dem Scan kam die gleiche Fehlermeldung für den Pfad C:\Users\Puschel\ntuser.dat Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-06-26 23:39:37
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002e TOSHIBA_MQ01ABD100 rev.AX001C 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\Puschel\AppData\Local\Temp\kfroqpob.sys
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [576:612] fffff9600092c5e8
Thread [1512:1528] 00000000773d50a7
Thread [1512:1536] 00000000749c8064
Thread [1512:1560] 00000000746bbfb4
Thread [1512:1576] 00000000746bbfb4
Thread [1512:1580] 00000000746bbfb4
Thread [1512:1584] 00000000746bbfb4
Thread [1512:1600] 00000000745f304c
---- Processes - GMER 2.1 ----
Library C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll (*** suspicious ***) @ C:\Windows\SysWOW64\rundll32.exe [2532] (NewNext Helper Engine/NewNextDotMe)(2014-01-19 15:36:14) 0000000072000000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 27.06.2014 Scan Time: 00:07:28 Logfile: mbam.txt Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.06.26.09 Rootkit Database: v2014.06.23.02 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 8 CPU: x64 File System: NTFS User: Puschel Scan Type: Threat Scan Result: Completed Objects Scanned: 265594 Time Elapsed: 10 min, 30 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 7 PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, , [ce439edf7b0087afb1df182ef012659b], PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT, , [7a97b7c6a8d3e6503680f5dae220f60a], PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT2, , [b25f88f5691264d2a2155f70e81ae020], Registry Values: 3 PUP.Optional.NextLive.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|NextLive, C:\Windows\SysWOW64\rundll32.exe "C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l, , [62af077605763105851e9abf31d04cb4] PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT|Install, 1, , [7a97b7c6a8d3e6503680f5dae220f60a] PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT2|Install, 1, , [b25f88f5691264d2a2155f70e81ae020] Registry Data: 0 (No malicious items detected) Folders: 3 PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me, , [ec252a53e794ca6ca0f5bed6ff038c74], PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me\cache, , [ec252a53e794ca6ca0f5bed6ff038c74], PUP.Optional.BuzzIT.A, C:\Program Files (x86)\Buzz-it, , [3fd2bcc14437e056554da9fb4bb746ba], Files: 21 PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll, , [62af077605763105851e9abf31d04cb4], PUP.Optional.OutBrowse, C:\Users\Puschel\AppData\Local\Temp\DownloadManager.exe, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse6761.exe, , [20f1e39adc9f5fd7275215193fc247b9], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse6BB5.exe, , [f51c601da7d4191df188929cac55e917], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse8D89.exe, , [25ec7b02ff7cde58a7d26ec034cda45c], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsq2AAE.exe, , [d43d017c1d5e50e69bde1519fe039c64], PUP.Optional.SnapDo.A, C:\Users\Puschel\AppData\Local\Temp\Installer.msi, , [2de41469403bb2849eee0088a25f7789], PUP.Optional.Conduit.A, C:\Users\Puschel\AppData\Local\Temp\SearchProtectINT.exe, , [21f086f78bf0e94ddacd26fb877a857b], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu64B2.exe, , [32dfcfae1f5c96a0f881b27c986945bb], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu6C52.exe, , [36db2d50017a64d2ef8a4ee08879f907], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu6E75.exe, , [e52cfd8044371c1a9edb4fdfd62bd729], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsy69C0.exe, , [739e86f75625f244354463cb5da4cd33], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsy8B94.exe, , [838e196442390b2bd6a371bd9d649070], PUP.Optional.Outbrowse, C:\Users\Puschel\AppData\Local\Temp\l0ox0hvJ.exe.part, , [759ca3da1a612e08755211fe4bb9eb15], PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Local\genienext\nengine.dll, , [db36ed907efd40f62a79154436cb3ac6], PUP.Optional.Conduit.A, C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\searchplugins\conduit-search.xml, , [a46d75083b403105425714b1c73b26da], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\etxbsbelsd.pre, , [a9682f4eef8c360050eae8f11ce606fa], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\luahfxqpmy.pre, , [1df4aecf8eede94dd06a42970ef40df3], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\tyuhssockk.pre, , [c34e5429057691a5be7ce6f31de5c23e], PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.cookie, , [ec252a53e794ca6ca0f5bed6ff038c74], PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me\cache\spark.bin, , [ec252a53e794ca6ca0f5bed6ff038c74], Physical Sectors: 0 (No malicious items detected) (end) Grüße |
| | #2 |
| /// TB-Ausbilder /// Anleitungs-Guru ![]() ![]() ![]() ![]() ![]() | Ebay Mahnung Mail Anhang geöffnet![]() Mein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das... ![]()
Hinweis:Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden. Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert. Adware & Co. können wir sehr gut entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Du mein clean bekommst.Los geht's: Bitte auch die Addition.txt posten... Schritt 1 ![]() Bitte starte FRST erneut, markiere auch die checkbox und drücke auf Scan. Bitte poste mir den Inhalt der beiden Logs die erstellt werden.
__________________ |
| | #3 |
| | Ebay Mahnung Mail Anhang geöffnet Hier die Addition.txt
__________________Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-06-2014
Ran by Puschel at 2014-06-27 10:01:43
Running from C:\Users\Puschel\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.6.636 - Adobe Systems, Inc.)
AMD Accelerated Video Transcoding (Version: 12.5.100.20918 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.938.2 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{3CEC10BE-CD7C-8E99-E3AC-DD31F4416C1C}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
AMD Fuel (Version: 2012.0918.260.3365 - Ihr Firmenname) Hidden
AMD VISION Engine Control Center (x32 Version: 2012.0918.260.3365 - Ihr Firmenname) Hidden
AutomationML Editor (HKLM-x32\...\{1FF9E567-7A33-4278-87D3-2CB2E0E07DC9}) (Version: 3.0.0 - AutomationML)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.672 - Avira)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2.5712 - CyberLink Corp.)
CyberLink LabelPrint (x32 Version: 2.5.2.5712 - CyberLink Corp.) Hidden
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.2.2114 - CyberLink Corp.)
CyberLink Media Suite 10 (x32 Version: 10.0.2.2114 - CyberLink Corp.) Hidden
CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.2.3317 - CyberLink Corp.)
CyberLink PhotoDirector (x32 Version: 2.0.2.3317 - CyberLink Corp.) Hidden
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.2.2110 - CyberLink Corp.)
CyberLink Power2Go 8 (x32 Version: 8.0.2.2110 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.2.2126 - CyberLink Corp.)
CyberLink PowerDirector 10 (x32 Version: 10.0.2.2126 - CyberLink Corp.) Hidden
CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.7.4528 - CyberLink Corp.)
CyberLink PowerDVD (x32 Version: 10.0.7.4528 - CyberLink Corp.) Hidden
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.5.5811 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.5.5.5811 - CyberLink Corp.) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM\...\{2DEDBE5B-D538-43F3-83A7-B037D6B51A89}) (Version: 4.2.8.1 - Hewlett-Packard Company)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden
HP Postscript Converter (Version: 3.1.3591 - Hewlett-Packard) Hidden
HP Recovery Manager (x32 Version: 8.00 - Hewlett-Packard) Hidden
HP Wireless Button Driver (HKLM-x32\...\{941DE69D-6CEE-4171-8F1F-3D7E352AA498}) (Version: 1.0.6.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Language Pack 2007 - German/Deutsch (HKLM-x32\...\OMUI.de-de) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office O MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office SharePoint Designer MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office X MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.12 - Synaptics Incorporated)
VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN)
==================== Restore Points =========================
04-05-2014 14:04:18 Geplanter Prüfpunkt
26-06-2014 20:51:10 Microsoft Office wird entfernt
==================== Hosts content: ==========================
2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2A12643D-F816-4B74-9A8C-BFDEBD2F94C3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {665ABA0F-C344-4F9D-84DF-A4B54EE8BFAA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-09-05] (Hewlett-Packard Company)
Task: {6A135F4B-F40B-450A-B411-6107AE3BE08F} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-10-12] (CyberLink)
Task: {75FDDF18-9E8C-4DAA-A853-5DDA76EBAAE7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-18] (Adobe Systems Incorporated)
Task: {77D9D4FF-08A3-4CBB-A530-D72BA2C5AC46} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Opt-in For HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe
Task: {895E8F71-0D37-41A9-BC80-F6880C747D2C} - System32\Tasks\HPGenoobeReminder => C:\Program Files (x86)\Hewlett-Packard\HP Registration Service\HP GenOOBE\HPGenOOBE.exe
Task: {8C8824B8-BBAE-4997-A40C-5DBB12B8122A} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-08] (CyberLink)
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {AF8D4BBF-73F2-46FC-A798-06875FBCD3ED} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-01-31] (Microsoft Corporation)
Task: {B81FF858-55E7-4D9F-A91D-751724FD10BB} - System32\Tasks\Microsoft\Windows\Setup\Windows Upgrade Notification Task => C:\Windows\system32\NotificationUI.exe [2014-01-31] (Microsoft Corporation)
Task: {C515F61B-3573-490A-B552-98081D50927C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2012-09-18 04:12 - 2012-09-18 04:12 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2012-09-18 04:11 - 2012-09-18 04:11 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2012-09-18 03:58 - 2012-09-18 03:58 - 00369664 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2013-09-24 12:40 - 2014-06-11 14:33 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-03-27 04:46 - 2012-06-08 05:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2012-06-08 12:34 - 2012-06-08 12:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (06/27/2014 00:21:47 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm mbam.exe, Version 1.0.0.532 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: e78
Startzeit: 01cf9187bafb614c
Endzeit: 0
Anwendungspfad: C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
Berichts-ID: 3faa6cf6-fd80-11e3-be8b-7446a0822eb5
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (06/26/2014 10:01:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.2.9200.16420, Zeitstempel: 0x505a96c3
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x77045f8c
ID des fehlerhaften Prozesses: 0xed0
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Vollständiger Name des fehlerhaften Pakets: svchost.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe5
Error: (06/26/2014 10:01:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.2.9200.16420, Zeitstempel: 0x505a96c3
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x77045f8c
ID des fehlerhaften Prozesses: 0x898
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Vollständiger Name des fehlerhaften Pakets: svchost.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe5
Error: (06/26/2014 10:00:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.2.9200.16420, Zeitstempel: 0x505a96c3
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x77045f8c
ID des fehlerhaften Prozesses: 0xbe8
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Vollständiger Name des fehlerhaften Pakets: svchost.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe5
Error: (05/15/2014 08:40:17 AM) (Source: MsiInstaller) (EventID: 1024) (User: Köörrrt)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011007}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127
Error: (03/16/2014 07:21:21 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: b28
Startzeit: 01cf2ff0d0a57d80
Endzeit: 4294967295
Anwendungspfad: C:\Windows\syswow64\wwahost.exe
Berichts-ID: 4bc14c45-ad2f-11e3-be81-7446a0822eb5
Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App
Error: (03/16/2014 06:26:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Köörrrt)
Description: Das Paket „Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c“ wurde beendet, da das Anhalten zu lange dauerte.
Error: (02/03/2014 04:33:16 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 440
Startzeit: 01cf20037ea29089
Endzeit: 4294967295
Anwendungspfad: C:\Windows\syswow64\wwahost.exe
Berichts-ID: bd83e931-8cdf-11e3-be80-7446a0822eb5
Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App
Error: (02/03/2014 04:30:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Köörrrt)
Description: Das Paket „Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c“ wurde beendet, da das Anhalten zu lange dauerte.
Error: (02/01/2014 08:40:24 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 58c
Startzeit: 01cf1f638ae820c7
Endzeit: 4294967295
Anwendungspfad: C:\Windows\syswow64\wwahost.exe
Berichts-ID: 4e339a66-8b70-11e3-be80-7446a0822eb5
Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App
System errors:
=============
Error: (06/27/2014 09:53:01 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 27.06.2014 um 00:27:12 unerwartet heruntergefahren.
Error: (06/26/2014 11:33:20 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Audio Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/26/2014 11:28:22 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 26.06.2014 um 23:15:30 unerwartet heruntergefahren.
Error: (06/17/2014 08:22:12 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (05/14/2014 10:16:26 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 13.05.2014 um 17:21:33 unerwartet heruntergefahren.
Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (05/01/2014 09:16:42 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Microsoft Office Sessions:
=========================
Error: (06/27/2014 00:21:47 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: mbam.exe1.0.0.532e7801cf9187bafb614c0C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe3faa6cf6-fd80-11e3-be8b-7446a0822eb5
Error: (06/26/2014 10:01:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.2.9200.16420505a96c3unknown0.0.0.000000000c000000577045f8ced001cf917967b2de1fC:\Windows\SysWOW64\svchost.exeunknowna731f674-fd6c-11e3-be88-7446a0822eb5
Error: (06/26/2014 10:01:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.2.9200.16420505a96c3unknown0.0.0.000000000c000000577045f8c89801cf91795f05f585C:\Windows\SysWOW64\svchost.exeunknown9e82ac94-fd6c-11e3-be88-7446a0822eb5
Error: (06/26/2014 10:00:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.2.9200.16420505a96c3unknown0.0.0.000000000c000000577045f8cbe801cf91794a8f9f9fC:\Windows\SysWOW64\svchost.exeunknown8a3672cb-fd6c-11e3-be88-7446a0822eb5
Error: (05/15/2014 08:40:17 AM) (Source: MsiInstaller) (EventID: 1024) (User: Köörrrt)
Description: Adobe Reader XI - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011007}1625(NULL)(NULL)(NULL)
Error: (03/16/2014 07:21:21 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.2.9200.16420b2801cf2ff0d0a57d804294967295C:\Windows\syswow64\wwahost.exe4bc14c45-ad2f-11e3-be81-7446a0822eb5Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5cApp
Error: (03/16/2014 06:26:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Köörrrt)
Description: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c
Error: (02/03/2014 04:33:16 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.2.9200.1642044001cf20037ea290894294967295C:\Windows\syswow64\wwahost.exebd83e931-8cdf-11e3-be80-7446a0822eb5Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5cApp
Error: (02/03/2014 04:30:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Köörrrt)
Description: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c
Error: (02/01/2014 08:40:24 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.2.9200.1642058c01cf1f638ae820c74294967295C:\Windows\syswow64\wwahost.exe4e339a66-8b70-11e3-be80-7446a0822eb5Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5cApp
==================== Memory info ===========================
Percentage of memory in use: 18%
Total physical RAM: 7650.26 MB
Available physical RAM: 6198.35 MB
Total Pagefile: 9954.26 MB
Available Pagefile: 8404.2 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:914.06 GB) (Free:876.14 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVERY) (Fixed) (Total:16.68 GB) (Free:2.15 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: D4AD0251)
Partition: GPT Partition Type.
==================== End Of Log ============================
Die neue FRST.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2014
Ran by Puschel (administrator) on KÖÖRRRT on 27-06-2014 10:01:10
Running from C:\Users\Puschel\Desktop
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-20] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-25] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-09-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491632 2012-09-10] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-17] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKU\S-1-5-21-2799476594-3240853191-3070442433-1002\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe "C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.uk.msn.com/HPNOT13/4
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM-x32 - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323895&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPFC3980F7-DD7B-4E02-9782-CE5F08F4EC13&q={searchTerms}&SSPV=
SearchScopes: HKCU - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll No File
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default
FF NewTab: about:blank
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\user.js
FF SearchPlugin: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: NoScript - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-19]
FF Extension: Adblock Plus - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-19]
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-09-18] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-06-17] (Avira Operations GmbH & Co. KG)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36520 2012-09-14] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-28] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-10] (Disc Soft Ltd)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-27] (Malwarebytes Corporation)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-25] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-25] (Synaptics Incorporated)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-27 00:21 - 2014-06-27 00:21 - 00005709 _____ () C:\mbam.txt
2014-06-26 23:43 - 2014-06-27 00:21 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-26 23:43 - 2014-06-26 23:43 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-06-26 23:43 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-26 23:43 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-26 23:43 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-26 23:39 - 2014-06-26 23:39 - 00002446 _____ () C:\Users\Puschel\Desktop\GMER.txt
2014-06-26 23:14 - 2014-06-27 09:59 - 00025923 _____ () C:\Users\Puschel\Desktop\Addition.txt
2014-06-26 23:13 - 2014-06-27 10:01 - 00011745 _____ () C:\Users\Puschel\Desktop\FRST.txt
2014-06-26 23:11 - 2014-06-27 10:01 - 00000000 ____D () C:\FRST
2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log
2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable
2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe
2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe
2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe
2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-26 22:00 - 2014-06-26 22:01 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps
==================== One Month Modified Files and Folders =======
2014-06-27 10:01 - 2014-06-26 23:13 - 00011745 _____ () C:\Users\Puschel\Desktop\FRST.txt
2014-06-27 10:01 - 2014-06-26 23:11 - 00000000 ____D () C:\FRST
2014-06-27 10:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-06-27 09:59 - 2014-06-26 23:14 - 00025923 _____ () C:\Users\Puschel\Desktop\Addition.txt
2014-06-27 09:59 - 2012-10-20 07:07 - 00830120 _____ () C:\Windows\system32\perfh007.dat
2014-06-27 09:59 - 2012-10-20 07:07 - 00188224 _____ () C:\Windows\system32\perfc007.dat
2014-06-27 09:59 - 2012-07-26 09:28 - 01949368 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-27 09:53 - 2014-01-19 17:36 - 00000000 ____D () C:\Users\Puschel\AppData\Roaming\newnext.me
2014-06-27 09:53 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-27 00:21 - 2014-06-27 00:21 - 00005709 _____ () C:\mbam.txt
2014-06-27 00:21 - 2014-06-26 23:43 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-27 00:18 - 2013-09-16 15:13 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2799476594-3240853191-3070442433-1002
2014-06-26 23:43 - 2014-06-26 23:43 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-06-26 23:41 - 2013-09-16 15:06 - 01812375 _____ () C:\Windows\WindowsUpdate.log
2014-06-26 23:39 - 2014-06-26 23:39 - 00002446 _____ () C:\Users\Puschel\Desktop\GMER.txt
2014-06-26 23:37 - 2014-04-14 18:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-26 23:19 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log
2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable
2014-06-26 23:10 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel
2014-06-26 23:06 - 2014-03-18 15:33 - 00437408 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-26 23:05 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 23:05 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 23:04 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-26 23:03 - 2014-04-10 19:04 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-26 23:02 - 2012-08-04 00:37 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-06-26 23:00 - 2012-07-26 09:52 - 00000000 ____D () C:\Windows\ShellNew
2014-06-26 23:00 - 2012-07-26 07:26 - 00000076 _____ () C:\Windows\win.ini
2014-06-26 22:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe
2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe
2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe
2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-26 22:01 - 2014-06-26 22:00 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps
2014-06-26 22:00 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel\AppData\Local\VirtualStore
2014-06-17 20:03 - 2013-09-24 12:47 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-06-17 20:03 - 2013-09-24 12:47 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
Some content of TEMP:
====================
C:\Users\Puschel\AppData\Local\Temp\6_Offer_15.exe
C:\Users\Puschel\AppData\Local\Temp\avgnt.exe
C:\Users\Puschel\AppData\Local\Temp\BackupSetup.exe
C:\Users\Puschel\AppData\Local\Temp\DownloadManager.exe
C:\Users\Puschel\AppData\Local\Temp\nse6761.exe
C:\Users\Puschel\AppData\Local\Temp\nse6BB5.exe
C:\Users\Puschel\AppData\Local\Temp\nse8D89.exe
C:\Users\Puschel\AppData\Local\Temp\nsq2AAE.exe
C:\Users\Puschel\AppData\Local\Temp\nsu64B2.exe
C:\Users\Puschel\AppData\Local\Temp\nsu6C52.exe
C:\Users\Puschel\AppData\Local\Temp\nsu6E75.exe
C:\Users\Puschel\AppData\Local\Temp\nsy69C0.exe
C:\Users\Puschel\AppData\Local\Temp\nsy8B94.exe
C:\Users\Puschel\AppData\Local\Temp\ose00000.exe
C:\Users\Puschel\AppData\Local\Temp\SearchProtectINT.exe
C:\Users\Puschel\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-27 00:27
==================== End Of Log ============================
|
| | #4 |
| /// TB-Ausbilder /// Anleitungs-Guru ![]() ![]() ![]() ![]() ![]() | Ebay Mahnung Mail Anhang geöffnet Schritt 1
__________________ Gruß deeprybka ![]() Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
| | #5 |
| | Ebay Mahnung Mail Anhang geöffnet Inhalt der MBRMastr_2014.06.27_14.47.55: Code:
ATTFilter Detected Windows version: 6.2 Build 9200
Driver connection handle: 0x00000148
1 valid drive(s) found.
Details for Disk 0 - TOSHIBA MQ01ABD100 Rev AX001C:
Device name : \\.\PhysicalDrive0
Geometry (C/H/S) : 121601/255/63
Boot loader reputation : Unknown
Cross view comparison : Passed
Partition table integrity: Passed
Boot loader hashes
SHA-1 : 639AC5CDF8A5CF3245975932C6A4215450A7B98F
MD5 : 5FB38429D5D77768867C76DCBDB35194
|
| | #6 |
| /// TB-Ausbilder /// Anleitungs-Guru ![]() ![]() ![]() ![]() ![]() | Ebay Mahnung Mail Anhang geöffnet Schritt 1 Downloade Dir bitte
Schritt 2 Scan mit Unter Erkennung und Schutz setze bitte einen Haken bei "Suche nach Rootkits". Klicke im Anschluss auf "Suchlauf", wähle den Bedrohungssuchlauf aus, aktualisiere die Datenbanken und klicke auf "Suchlauf jetzt starten". Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. (geht so...) Poste mir den Inhalt der Logdatei. Klicke dazu auf Verlauf und dann auf Anwendungsprotokolle. Wähle das neueste Suchlauf-Protokoll aus und klicke auf Ansicht. Klicke auf "In Zwischenablage kopieren" poste mir den Inhalt in Code-Tags als Antwort in den Thread. Schritt 3 ESET Online Scanner
Schritt 4 ![]() Bitte starte FRST erneut, markiere auch die checkbox und drücke auf Scan. Bitte poste mir den Inhalt der beiden Logs die erstellt werden. Gibt es jetzt noch Probleme mit dem PC? Wenn ja, welche?
__________________ --> Ebay Mahnung Mail Anhang geöffnet |
| | #7 |
| | Ebay Mahnung Mail Anhang geöffnet Adwcleaner log: Code:
ATTFilter # AdwCleaner v3.213 - Bericht erstellt am 27/06/2014 um 15:09:39
# Aktualisiert 23/06/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Puschel - KÖÖRRRT
# Gestartet von : C:\Users\Puschel\Desktop\adwcleaner_3.213.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\Mobogenie
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Users\Puschel\AppData\Local\genienext
Ordner Gelöscht : C:\Users\Puschel\AppData\Local\lollipop
Ordner Gelöscht : C:\Users\Puschel\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Puschel\AppData\Roaming\newnext.me
Ordner Gelöscht : C:\Users\Puschel\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Puschel\Documents\Mobogenie
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\Puschel\daemonprocess.txt
Datei Gelöscht : C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\searchplugins\conduit-search.xml
Datei Gelöscht : C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NextLive]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\lollipop
Schlüssel Gelöscht : HKCU\Software\SearchProtectINT
Schlüssel Gelöscht : HKCU\Software\SearchProtectInt2
Schlüssel Gelöscht : HKCU\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\Software\systweak
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16537
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Zeile gelöscht : user_pref("extensions.helperbar.Visibility", false);
Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "de");
Zeile gelöscht : user_pref("extensions.helperbar.downloadprovider", "ry_2908");
Zeile gelöscht : user_pref("extensions.helperbar.externalJsFiles", "{\"d\":\"[{\\\"ExcludeDomains\\\":[\\\"snap.do\\\",\\\"snapdo.com\\\"],\\\"hxxpInjection\\\":\\\"hxxp:\\\\\\/\\\\\\/i.shopopjs.info\\\\\\/opop\\\\\\/[...]
Zeile gelöscht : user_pref("extensions.helperbar.installationid", "0d3416dd-ebc1-456e-be6a-b5c51eeb57e8");
Zeile gelöscht : user_pref("extensions.helperbar.installdate", "19/01/2014");
Zeile gelöscht : user_pref("extensions.helperbar.lastExternalJsUpdate", "1390145792710");
Zeile gelöscht : user_pref("extensions.helperbar.publisher", "shopobrw");
*************************
AdwCleaner[R0].txt - [4546 octets] - [27/06/2014 15:08:35]
AdwCleaner[S0].txt - [4061 octets] - [27/06/2014 15:09:39]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4121 octets] ##########
Code:
ATTFilter mbam log: Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 27.06.2014 Scan Time: 15:14:10 Logfile: Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.06.27.05 Rootkit Database: v2014.06.23.02 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 8 CPU: x64 File System: NTFS User: Puschel Scan Type: Threat Scan Result: Completed Objects Scanned: 266289 Time Elapsed: 14 min, 27 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 1 PUP.Optional.BuzzIT.A, C:\Program Files (x86)\Buzz-it, Quarantined, [a04a82f9106b0d29050fcbda7d85c937], Files: 16 PUP.Optional.OutBrowse, C:\Users\Puschel\AppData\Local\Temp\DownloadManager.exe, Quarantined, [9a50aad1daa1e254df2e59c547b9bd43], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse6761.exe, Quarantined, [e307c0bb54271a1c345c40ee926fa35d], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse6BB5.exe, Quarantined, [a9414338ef8c1c1ad2be1d11847dd22e], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse8D89.exe, Quarantined, [ea000378215a06309cf4cf5f44bded13], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsq2AAE.exe, Quarantined, [9e4c1566a5d6191d167acd612ed3f709], PUP.Optional.SnapDo.A, C:\Users\Puschel\AppData\Local\Temp\Installer.msi, Quarantined, [3fabd9a248330f2781256325fc05aa56], PUP.Optional.Conduit.A, C:\Users\Puschel\AppData\Local\Temp\SearchProtectINT.exe, Quarantined, [42a87dfe4833da5c447a67baec15a957], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu64B2.exe, Quarantined, [32b82b500a7115216d237eb09a679e62], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu6C52.exe, Quarantined, [de0c1a61661550e6cbc5fa3442bff808], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu6E75.exe, Quarantined, [3dade4975c1fee48f49c5fcfb54ce020], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsy69C0.exe, Quarantined, [08e23c3fe497eb4b4d43c9652cd5f30d], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsy8B94.exe, Quarantined, [8f5b4e2d7efd2a0c7c149c92be436e92], PUP.Optional.Outbrowse, C:\Users\Puschel\AppData\Local\Temp\l0ox0hvJ.exe.part, Quarantined, [b4366615df9cd6605aed2fe03fc5af51], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\etxbsbelsd.pre, Quarantined, [49a1b4c7106b59dd18bf8058857d20e0], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\luahfxqpmy.pre, Quarantined, [edfdd1aa4a319f97d205f4e462a0b24e], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\tyuhssockk.pre, Quarantined, [11d9ea9187f41d1923b4a92fab57eb15], Physical Sectors: 0 (No malicious items detected) (end) Code:
ATTFilter ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=e40d0de937a5ff47bd05c903fb75034d
# engine=18917
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-06-27 02:29:11
# local_time=2014-06-27 04:29:11 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='Avira Desktop'
# compatibility_mode=1810 16777213 100 100 23412 23859871 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 5379312 25552621 0 0
# scanned=179379
# found=9
# cleaned=0
# scan_time=2768
sh=8E6A6992A3C7FEC4000FA1A4D764DD597109E0B5 ft=1 fh=c71c0011cd00713e vn="Win32/NextLive.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Mobogenie\nengine.dll.vir"
sh=8E6A6992A3C7FEC4000FA1A4D764DD597109E0B5 ft=1 fh=c71c0011cd00713e vn="Win32/NextLive.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Puschel\AppData\Local\genienext\nengine.dll.vir"
sh=8E6A6992A3C7FEC4000FA1A4D764DD597109E0B5 ft=1 fh=c71c0011cd00713e vn="Win32/NextLive.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll.vir"
sh=24BD4959CB8BA2D14453D3D2FE97A3D34550146E ft=1 fh=e247b72675f4f200 vn="Variante von Win32/Speedchecker.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Puschel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3QT7GS4M\pcspeedupSetup[1].exe"
sh=F61C6750D1032B04DFBEA218AE579B30A1DD1F45 ft=1 fh=e0df02dd5fbc1171 vn="Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Puschel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3QT7GS4M\SPSetup[1].exe"
sh=BC4111FE207B65C53AFFCBDEFA61F68D7B6C2E9C ft=1 fh=beafc52420be7958 vn="Win32/Mobogenie.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Puschel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QUKTG73J\Mobogenie_Setup_INT[1].exe"
sh=0934D2C2CEF97C188A533CDA1C6E79B8FE452A95 ft=1 fh=a3228e9da12970f7 vn="Variante von MSIL/Toolbar.Linkury.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Puschel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QUKTG73J\Shopop_Setup[1].exe"
sh=C4A6FCE0772792ED441793FBD22AC0E5605D1E89 ft=1 fh=8163f89546a047a4 vn="Win32/Toolbar.Conduit.R evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Puschel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QW7DYVJD\SearchProtectGeneric[1].exe"
sh=8BCEACCD38FD5D335AB197C66FD12A4D8D5EDBCA ft=0 fh=0000000000000000 vn="Variante von Generik.MCDRKTL Trojaner" ac=I fn="C:\Users\Puschel\AppData\Local\Temp\Paypal Ausgleich stornierten Zahlung Ihrer Bestellung vom 26.06.2014 an Daria Simstedt.zip"
FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2014
Ran by Puschel (administrator) on KÖÖRRRT on 27-06-2014 16:37:46
Running from C:\Users\Puschel\Desktop
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-20] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-25] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-09-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491632 2012-09-10] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-17] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.uk.msn.com/HPNOT13/4
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default
FF NewTab: about:blank
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: NoScript - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-19]
FF Extension: Adblock Plus - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-19]
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-09-18] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-06-17] (Avira Operations GmbH & Co. KG)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36520 2012-09-14] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-28] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-10] (Disc Soft Ltd)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-25] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-25] (Synaptics Incorporated)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
S3 a2dda; \??\C:\Users\Puschel\Desktop\MBRMastr.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-27 15:38 - 2014-06-27 15:38 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-06-27 15:37 - 2014-06-27 15:37 - 02347384 _____ (ESET) C:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe
2014-06-27 15:35 - 2014-06-27 15:36 - 00003147 _____ () C:\Users\Puschel\Desktop\mbam.txt
2014-06-27 15:11 - 2014-06-27 15:11 - 00004213 _____ () C:\Users\Puschel\Desktop\AdwCleaner[S0].txt
2014-06-27 15:08 - 2014-06-27 15:09 - 00000000 ____D () C:\AdwCleaner
2014-06-27 15:08 - 2014-06-27 15:08 - 01342659 _____ () C:\Users\Puschel\Desktop\adwcleaner_3.213.exe
2014-06-27 14:48 - 2014-06-27 14:48 - 00000153 _____ () C:\Users\Puschel\Desktop\unknown.zip
2014-06-27 14:47 - 2014-06-27 14:47 - 00788728 _____ (Emsisoft GmbH) C:\Users\Puschel\Desktop\mbrmastr.exe
2014-06-27 14:47 - 2014-06-27 14:47 - 00000528 _____ () C:\Users\Puschel\Desktop\MBRMastr_2014.06.27_14.47.55.txt
2014-06-27 14:47 - 2014-06-27 14:47 - 00000512 _____ () C:\Users\Puschel\Desktop\unknown.mbr
2014-06-27 00:21 - 2014-06-27 00:21 - 00005709 _____ () C:\mbam.txt
2014-06-26 23:43 - 2014-06-27 15:34 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-26 23:43 - 2014-06-26 23:43 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-06-26 23:43 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-26 23:43 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-26 23:43 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-26 23:39 - 2014-06-26 23:39 - 00002446 _____ () C:\Users\Puschel\Desktop\GMER.txt
2014-06-26 23:14 - 2014-06-27 10:02 - 00025922 _____ () C:\Users\Puschel\Desktop\Addition.txt
2014-06-26 23:13 - 2014-06-27 16:38 - 00010376 _____ () C:\Users\Puschel\Desktop\FRST.txt
2014-06-26 23:11 - 2014-06-27 16:37 - 00000000 ____D () C:\FRST
2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log
2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable
2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe
2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe
2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe
2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-26 22:00 - 2014-06-27 14:47 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps
==================== One Month Modified Files and Folders =======
2014-06-27 16:38 - 2014-06-26 23:13 - 00010376 _____ () C:\Users\Puschel\Desktop\FRST.txt
2014-06-27 16:37 - 2014-06-26 23:11 - 00000000 ____D () C:\FRST
2014-06-27 16:37 - 2014-04-14 18:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-27 16:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-06-27 15:38 - 2014-06-27 15:38 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-06-27 15:38 - 2012-10-20 07:07 - 00830120 _____ () C:\Windows\system32\perfh007.dat
2014-06-27 15:38 - 2012-10-20 07:07 - 00188224 _____ () C:\Windows\system32\perfc007.dat
2014-06-27 15:38 - 2012-07-26 09:28 - 01949368 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-27 15:37 - 2014-06-27 15:37 - 02347384 _____ (ESET) C:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe
2014-06-27 15:36 - 2014-06-27 15:35 - 00003147 _____ () C:\Users\Puschel\Desktop\mbam.txt
2014-06-27 15:36 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-27 15:36 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-27 15:34 - 2014-06-26 23:43 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-27 15:34 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-27 15:33 - 2012-08-04 00:23 - 00511272 _____ () C:\Windows\PFRO.log
2014-06-27 15:11 - 2014-06-27 15:11 - 00004213 _____ () C:\Users\Puschel\Desktop\AdwCleaner[S0].txt
2014-06-27 15:09 - 2014-06-27 15:08 - 00000000 ____D () C:\AdwCleaner
2014-06-27 15:09 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel
2014-06-27 15:08 - 2014-06-27 15:08 - 01342659 _____ () C:\Users\Puschel\Desktop\adwcleaner_3.213.exe
2014-06-27 14:48 - 2014-06-27 14:48 - 00000153 _____ () C:\Users\Puschel\Desktop\unknown.zip
2014-06-27 14:47 - 2014-06-27 14:47 - 00788728 _____ (Emsisoft GmbH) C:\Users\Puschel\Desktop\mbrmastr.exe
2014-06-27 14:47 - 2014-06-27 14:47 - 00000528 _____ () C:\Users\Puschel\Desktop\MBRMastr_2014.06.27_14.47.55.txt
2014-06-27 14:47 - 2014-06-27 14:47 - 00000512 _____ () C:\Users\Puschel\Desktop\unknown.mbr
2014-06-27 14:47 - 2014-06-26 22:00 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps
2014-06-27 10:02 - 2014-06-26 23:14 - 00025922 _____ () C:\Users\Puschel\Desktop\Addition.txt
2014-06-27 00:21 - 2014-06-27 00:21 - 00005709 _____ () C:\mbam.txt
2014-06-27 00:18 - 2013-09-16 15:13 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2799476594-3240853191-3070442433-1002
2014-06-26 23:43 - 2014-06-26 23:43 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-06-26 23:41 - 2013-09-16 15:06 - 01812375 _____ () C:\Windows\WindowsUpdate.log
2014-06-26 23:39 - 2014-06-26 23:39 - 00002446 _____ () C:\Users\Puschel\Desktop\GMER.txt
2014-06-26 23:19 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log
2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable
2014-06-26 23:06 - 2014-03-18 15:33 - 00437408 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-26 23:04 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-26 23:03 - 2014-04-10 19:04 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-26 23:02 - 2012-08-04 00:37 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-06-26 23:00 - 2012-07-26 09:52 - 00000000 ____D () C:\Windows\ShellNew
2014-06-26 23:00 - 2012-07-26 07:26 - 00000076 _____ () C:\Windows\win.ini
2014-06-26 22:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe
2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe
2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe
2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-26 22:00 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel\AppData\Local\VirtualStore
2014-06-17 20:03 - 2013-09-24 12:47 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-06-17 20:03 - 2013-09-24 12:47 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
Some content of TEMP:
====================
C:\Users\Puschel\AppData\Local\Temp\6_Offer_15.exe
C:\Users\Puschel\AppData\Local\Temp\avgnt.exe
C:\Users\Puschel\AppData\Local\Temp\BackupSetup.exe
C:\Users\Puschel\AppData\Local\Temp\ose00000.exe
C:\Users\Puschel\AppData\Local\Temp\Quarantine.exe
C:\Users\Puschel\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-27 10:14
==================== End Of Log ============================
--- --- --- --- --- --- Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-06-2014
Ran by Puschel at 2014-06-27 16:38:25
Running from C:\Users\Puschel\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.6.636 - Adobe Systems, Inc.)
AMD Accelerated Video Transcoding (Version: 12.5.100.20918 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.938.2 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{3CEC10BE-CD7C-8E99-E3AC-DD31F4416C1C}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
AMD Fuel (Version: 2012.0918.260.3365 - Ihr Firmenname) Hidden
AMD VISION Engine Control Center (x32 Version: 2012.0918.260.3365 - Ihr Firmenname) Hidden
AutomationML Editor (HKLM-x32\...\{1FF9E567-7A33-4278-87D3-2CB2E0E07DC9}) (Version: 3.0.0 - AutomationML)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.672 - Avira)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2.5712 - CyberLink Corp.)
CyberLink LabelPrint (x32 Version: 2.5.2.5712 - CyberLink Corp.) Hidden
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.2.2114 - CyberLink Corp.)
CyberLink Media Suite 10 (x32 Version: 10.0.2.2114 - CyberLink Corp.) Hidden
CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.2.3317 - CyberLink Corp.)
CyberLink PhotoDirector (x32 Version: 2.0.2.3317 - CyberLink Corp.) Hidden
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.2.2110 - CyberLink Corp.)
CyberLink Power2Go 8 (x32 Version: 8.0.2.2110 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.2.2126 - CyberLink Corp.)
CyberLink PowerDirector 10 (x32 Version: 10.0.2.2126 - CyberLink Corp.) Hidden
CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.7.4528 - CyberLink Corp.)
CyberLink PowerDVD (x32 Version: 10.0.7.4528 - CyberLink Corp.) Hidden
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.5.5811 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.5.5.5811 - CyberLink Corp.) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM\...\{2DEDBE5B-D538-43F3-83A7-B037D6B51A89}) (Version: 4.2.8.1 - Hewlett-Packard Company)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden
HP Postscript Converter (Version: 3.1.3591 - Hewlett-Packard) Hidden
HP Recovery Manager (x32 Version: 8.00 - Hewlett-Packard) Hidden
HP Wireless Button Driver (HKLM-x32\...\{941DE69D-6CEE-4171-8F1F-3D7E352AA498}) (Version: 1.0.6.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Language Pack 2007 - German/Deutsch (HKLM-x32\...\OMUI.de-de) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office O MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office SharePoint Designer MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office X MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 30.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.12 - Synaptics Incorporated)
VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN)
==================== Restore Points =========================
04-05-2014 14:04:18 Geplanter Prüfpunkt
26-06-2014 20:51:10 Microsoft Office wird entfernt
==================== Hosts content: ==========================
2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2A12643D-F816-4B74-9A8C-BFDEBD2F94C3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {665ABA0F-C344-4F9D-84DF-A4B54EE8BFAA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-09-05] (Hewlett-Packard Company)
Task: {6A135F4B-F40B-450A-B411-6107AE3BE08F} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-10-12] (CyberLink)
Task: {75FDDF18-9E8C-4DAA-A853-5DDA76EBAAE7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-18] (Adobe Systems Incorporated)
Task: {77D9D4FF-08A3-4CBB-A530-D72BA2C5AC46} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Opt-in For HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe
Task: {895E8F71-0D37-41A9-BC80-F6880C747D2C} - System32\Tasks\HPGenoobeReminder => C:\Program Files (x86)\Hewlett-Packard\HP Registration Service\HP GenOOBE\HPGenOOBE.exe
Task: {8C8824B8-BBAE-4997-A40C-5DBB12B8122A} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-08] (CyberLink)
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {AF8D4BBF-73F2-46FC-A798-06875FBCD3ED} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-01-31] (Microsoft Corporation)
Task: {B81FF858-55E7-4D9F-A91D-751724FD10BB} - System32\Tasks\Microsoft\Windows\Setup\Windows Upgrade Notification Task => C:\Windows\system32\NotificationUI.exe [2014-01-31] (Microsoft Corporation)
Task: {C515F61B-3573-490A-B552-98081D50927C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2012-09-18 04:12 - 2012-09-18 04:12 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2012-09-18 04:11 - 2012-09-18 04:11 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2012-09-18 03:58 - 2012-09-18 03:58 - 00369664 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2013-03-27 04:46 - 2012-06-08 05:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2012-06-08 12:34 - 2012-06-08 12:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2013-09-24 12:40 - 2014-06-27 15:36 - 03852912 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (06/27/2014 04:35:30 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
Error: (06/27/2014 04:31:10 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
Error: (06/27/2014 03:38:08 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
Error: (06/27/2014 03:38:08 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
Error: (06/27/2014 03:38:01 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
Error: (06/27/2014 03:38:01 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
Error: (06/27/2014 03:38:01 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
Error: (06/27/2014 03:37:46 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
Error: (06/27/2014 02:47:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbrmastr.exe, Version: 1.0.0.349, Zeitstempel: 0x5093115e
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc000070a
Fehleroffset: 0x000b0e7a
ID des fehlerhaften Prozesses: 0x540
Startzeit der fehlerhaften Anwendung: 0xmbrmastr.exe0
Pfad der fehlerhaften Anwendung: mbrmastr.exe1
Pfad des fehlerhaften Moduls: mbrmastr.exe2
Berichtskennung: mbrmastr.exe3
Vollständiger Name des fehlerhaften Pakets: mbrmastr.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: mbrmastr.exe5
Error: (06/27/2014 00:21:47 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm mbam.exe, Version 1.0.0.532 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: e78
Startzeit: 01cf9187bafb614c
Endzeit: 0
Anwendungspfad: C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
Berichts-ID: 3faa6cf6-fd80-11e3-be8b-7446a0822eb5
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
System errors:
=============
Error: (06/27/2014 09:53:01 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 27.06.2014 um 00:27:12 unerwartet heruntergefahren.
Error: (06/26/2014 11:33:20 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Audio Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/26/2014 11:28:22 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 26.06.2014 um 23:15:30 unerwartet heruntergefahren.
Error: (06/17/2014 08:22:12 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (05/14/2014 10:16:26 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 13.05.2014 um 17:21:33 unerwartet heruntergefahren.
Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (05/01/2014 09:16:42 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Microsoft Office Sessions:
=========================
Error: (06/27/2014 04:35:30 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe
Error: (06/27/2014 04:31:10 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe
Error: (06/27/2014 03:38:08 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe
Error: (06/27/2014 03:38:08 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe
Error: (06/27/2014 03:38:01 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe
Error: (06/27/2014 03:38:01 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe
Error: (06/27/2014 03:38:01 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe
Error: (06/27/2014 03:37:46 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifestC:\Users\Puschel\Desktop\esetsmartinstaller_deu.exe
Error: (06/27/2014 02:47:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: mbrmastr.exe1.0.0.3495093115entdll.dll6.2.9200.16578515fac6ec000070a000b0e7a54001cf9205ed512c87C:\Users\Puschel\Desktop\mbrmastr.exeC:\Windows\SYSTEM32\ntdll.dll342bdef0-fdf9-11e3-be8c-7446a0822eb5
Error: (06/27/2014 00:21:47 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: mbam.exe1.0.0.532e7801cf9187bafb614c0C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe3faa6cf6-fd80-11e3-be8b-7446a0822eb5
==================== Memory info ===========================
Percentage of memory in use: 21%
Total physical RAM: 7650.26 MB
Available physical RAM: 6016.3 MB
Total Pagefile: 9954.26 MB
Available Pagefile: 8039.7 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:914.06 GB) (Free:875.98 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVERY) (Fixed) (Total:16.68 GB) (Free:2.15 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: D4AD0251)
Partition: GPT Partition Type.
==================== End Of Log ============================
|
| | #8 |
| /// TB-Ausbilder /// Anleitungs-Guru ![]() ![]() ![]() ![]() ![]() | Ebay Mahnung Mail Anhang geöffnet Hi, Datenträgerbereinigung
Flashplayer updaten bei Gelegenheit. Aufräumen: Defogger: Falls benutzt worden, Defogger nochmal starten und auf re-enable klicken. Anschließend: Gibts jetzt noch Probleme mit Deinem Rechner? Oder hast Du noch Fragen? NEIN? Alle Logs gepostet? Ja! Dann lade Dir bitte
Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst. Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen. ![]() >>clean<< Wir haben es geschafft! ![]() Die Logs sehen für mich im Moment sauber aus. ![]() Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst... und/oder das Forum mit einer kleinen Spende unterstützen. ![]() Es bleibt mir nur noch, Dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen. ![]() Epilog: Tipps, Dos & Don'ts Aktualität von System und SoftwareDas Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die Auch die installierte Software sollte immer in der aktuellsten Version vorliegen. Speziell gilt das für die Browser , Java , Flash-Player
Sicherheits-SoftwareEine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine infizierte Datei nicht erkennt). Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt. Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons als Empfehlung gibt:
(Un-)Sicheres Verhalten im InternetNebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert. Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
Allgemeine HinweiseAbschließend noch ein paar grundsätzliche Bemerkungen:
__________________ Gruß deeprybka ![]() Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer Geändert von deeprybka (27.06.2014 um 16:08 Uhr) |
| | #9 |
| | Ebay Mahnung Mail Anhang geöffnet Danke für die hervorragende Hilfe! Ich wünsche dir noch ein angenehmes Wochenende und hoffentlich auf Nimmerwiedersehen |
| | #10 |
| /// TB-Ausbilder /// Anleitungs-Guru ![]() ![]() ![]() ![]() ![]() | Ebay Mahnung Mail Anhang geöffnet OK... ![]() Alles Gute!
__________________ Gruß deeprybka ![]() Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
![]() |