Fremzugriff PayPal mit anschließendem Virusfund Hallo Trojaner-Board,
ich hatte heute einen Fremdzugriff auf meinen PayPal-Acc.
Daraufhin habe ich einen Scan mit AntiVir gemacht mit folgendem Log: Code:
10.11.2013 22:08 [Echtzeit-Scanner] Malware gefunden
In der Datei
'C:\$RECYCLE.BIN\S-1-5-21-1596228716-2741437735-1596447798-1000\$R29TTUP.exe'
wurde ein Virus oder unerwünschtes Programm 'ADWARE/Adware.Gen2' [adware]
gefunden.
Ausgeführte Aktion: Zugriff verweigern
10.11.2013 21:45 [System-Scanner] Malware gefunden
Die Datei 'C:\Users\Jan\AppData\Local\temp\7Zip__3154_il604572.exe'
enthielt einen Virus oder unerwünschtes Programm 'ADWARE/Adware.Gen2' [adware].
Durchgeführte Aktion(en):
Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '57bc60f9.qua'
verschoben!
10.11.2013 21:44 [Echtzeit-Scanner] Malware gefunden
In der Datei 'C:\Users\Jan\AppData\Local\temp\7Zip__3154_il604572.exe'
wurde ein Virus oder unerwünschtes Programm 'ADWARE/Adware.Gen2' [adware]
gefunden.
Ausgeführte Aktion: Zugriff verweigern
10.11.2013 21:36 [Echtzeit-Scanner] Malware gefunden
In der Datei 'C:\Downloads\samsung-scx-4200-series.exe'
wurde ein Virus oder unerwünschtes Programm 'ADWARE/InstallCore.Gen7' [adware]
gefunden.
Ausgeführte Aktion: Zugriff verweigern
10.11.2013 21:35 [Echtzeit-Scanner] Malware gefunden
In der Datei 'C:\Downloads\canon-utilities-photostitch.exe'
wurde ein Virus oder unerwünschtes Programm 'ADWARE/InstallCore.Gen7' [adware]
gefunden.
Ausgeführte Aktion: Zugriff verweigern Zusätzlich habe ich noch alle Spy-Programme, die sich auf meinen Rechner tümmeln, durchlaufen lassen.
SuperAntiSpy Code:
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com
Generated 11/10/2013 at 10:30 PM
Application Version : 5.6.1020
Core Rules Database Version : 10638
Trace Rules Database Version: 8450
Scan type : Quick Scan
Total Scan Time : 00:27:05
Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC Off - Administrator
Memory items scanned : 685
Memory threats detected : 0
Registry items scanned : 32575
Registry threats detected : 0
File items scanned : 14985
File threats detected : 105
Adware.Tracking Cookie
.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.office-discount.de [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.office-discount.de [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.office-discount.de [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
in.getclicky.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
insight.torbit.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.etracker.de [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.opodo.122.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.solvemedia.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.germanwings.112.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
t.bbtrack.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.ardmediathek.de [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.quiksilver.112.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
track.webtrekk.de [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.histats.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.histats.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.etracker.de [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.rambler.ru [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.click2sell.eu [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.histats.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.c.atdmt.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.c.atdmt.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.mediacenter.zwp-online.info [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.mediacenter.zwp-online.info [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.premiumtv.122.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
radservice.radroutenplaner.thueringen.de [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
radservice.radroutenplaner.thueringen.de [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
testdata.coremetrics.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.ipcmedia.122.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.autoscout24.112.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.blau.122.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
tracking.campz.de [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
statse.webtrendslive.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.etracker.de [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
stat.novasol.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.yadro.ru [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
de.sitestat.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.aok.122.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.survey.g.doubleclick.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.deutschepostag.112.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.paypal.112.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.xiti.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.xiti.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.oms.122.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.windfinder.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.windfinder.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
ad.zanox.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.olympiaverlag.122.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.leisure.122.2o7.net [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.stats.paypal.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ]
.vinsight.de [ C:\USERS\XX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VT8U74MO.DEFAULT-1383480083613\COOKIES.SQLITE ] AdwCleaner Code:
# AdwCleaner v3.011 - Bericht erstellt am 10/11/2013 um 21:53:38
# Updated 03/11/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzername : Jan - JAN-LAPTOP
# Gestartet von : C:\Users\Jan\Downloads\adw311cleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files\goforfiles
Ordner Gelöscht : C:\Users\Jan\AppData\Roaming\goforfiles
Datei Gelöscht : C:\Windows\System32\Tasks\GoforFilesUpdate
Datei Gelöscht : C:\Windows\System32\Tasks\Your File Updater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F748D79F-41FC-411B-AA5B-AEDD9DF2128B}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CF629E74-1FF3-49DD-82E8-0FB86FA74051}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1B02CA31-2861-4365-86BC-EDEB9AC66549}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16514
-\\ Mozilla Firefox v25.0 (de)
[ Datei : C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\vt8u74mo.default-1383480083613\prefs.js ]
*************************
AdwCleaner[R0].txt - [18578 octets] - [10/11/2013 21:49:02]
AdwCleaner[S0].txt - [1829 octets] - [10/11/2013 21:53:38]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1889 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Jan on 10.11.2013 at 22:38:19,08
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{544F52A2-4D6D-428B-A2DF-FB1EE3F0A263}
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10.11.2013 at 22:42:54,87
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes hat nichts gefunden.
Anschließend hab ich defogger, FRST und GMER ausgeführt. Letzterer ist allerdings abgestürtzt.
FRST Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-11-2013 01
Ran by XX (administrator) on XX-LAPTOP on 10-11-2013 22:46:47
Running from C:\Users\XX\Downloads
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Tools\Avira\AntiVir Desktop\sched.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
(Avira Operations GmbH & Co. KG) C:\Tools\Avira\AntiVir Desktop\avgnt.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Acer Incorporated) C:\Program Files\PACKARD BELL\Packard Bell PowerSave Solution\ePowerTray.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Tools\Avira\AntiVir Desktop\avguard.exe
(Cisco Systems, Inc.) C:\Tools\VPN\cvpnd.exe
(Acer Incorporated) C:\Program Files\PACKARD BELL\Packard Bell PowerSave Solution\ePowerSvc.exe
(Garmin Ltd or its subsidiaries) C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Nero AG) C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
(Realtek Semiconductor Corp.) C:\Users\XX\AppData\Local\Temp\RtkBtMnt.exe
(Avira Operations GmbH & Co. KG) C:\Tools\Avira\AntiVir Desktop\avshadow.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Acer Incorporated) C:\Program Files\PACKARD BELL\Packard Bell PowerSave Solution\ePowerEvent.exe
(Ghisler Software GmbH) C:\Tools\totalcmd\TOTALCMD.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Mozilla Corporation) C:\Tools\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\PACKARD BELL\Packard Bell PowerSave Solution\ePowerTrayLauncher.exe [440864 2009-04-15] (Acer Incorporated)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6789664 2009-02-24] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1430824 2009-02-06] (Synaptics Incorporated)
HKLM\...\Run: [avgnt] - C:\Tools\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [862728 2009-02-12] (Dritek System Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\!SASWinLogon: C:\Tools\SUPERAntispyware\SASWINLO.DLL (SUPERAntiSpyware.com)
HKCU\...\Run: [] - [x]
HKCU\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKCU\...\Policies\Explorer: [StartMenuLogOff] 1
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default\...\RunOnce: [ScrSav] -
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\RunOnce: [ScrSav] -
HKU\Guest\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=2&o=vp32&d=0809&m=easynote_lj65
HKCU\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=2&o=vp32&d=0809&m=easynote_lj65
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {03B68182-2C6D-41C7-AC9F-F29BE03B86D2} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ]
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Tools\SUPERAntispyware\SASSEH.DLL [115440 2013-07-25] (SuperAdBlocker.com)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.123.1
FireFox:
========
FF ProfilePath: C:\Users\XX\AppData\Roaming\Mozilla\Firefox\Profiles\vt8u74mo.default-1383480083613
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Tools\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Tools\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Tools\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer - C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=1.1.0 - C:\Tools\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Tools\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @phonostar.de/phonostar - C:\Tools\phonostar-Player\npphonostarDetectNP.dll ( )
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\XX\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Extension: No Name - C:\Users\XX\AppData\Roaming\Mozilla\Firefox\Profiles\vt8u74mo.default-1383480083613\Extensions\trash
FF Extension: FoxTrick - C:\Users\XX\AppData\Roaming\Mozilla\Firefox\Profiles\vt8u74mo.default-1383480083613\Extensions\{9d1f059c-cada-4111-9696-41a62d64e3ba}
FF Extension: Adblock Plus - C:\Users\XX\AppData\Roaming\Mozilla\Firefox\Profiles\vt8u74mo.default-1383480083613\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: tabmix - C:\Users\XX\AppData\Roaming\Mozilla\Firefox\Profiles\vt8u74mo.default-1383480083613\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKCU\...\Firefox\Extensions: [lwoofer@lyricswoofer.co] - C:\Program Files\LyricsWoofer\125.xpi
FF StartMenuInternet: FIREFOX.EXE - C:\Tools\Mozilla Firefox\firefox.exe
========================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor6.0; C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [124832 2007-09-11] ()
R2 AntiVirSchedulerService; C:\Tools\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Tools\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 CVPND; C:\Tools\VPN\cvpnd.exe [1524512 2007-10-26] (Cisco Systems, Inc.)
R2 ePowerSvc; C:\Program Files\PACKARD BELL\Packard Bell PowerSave Solution\ePowerSvc.exe [703008 2009-04-15] (Acer Incorporated)
R2 Garmin Core Update Service; C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [220504 2013-08-22] (Garmin Ltd or its subsidiaries)
S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435016 2010-01-15] (TuneUp Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1044808 2009-12-09] (TuneUp Software)
S2 Norton Internet Security; "C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\Program Files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll" /prefetch:1
==================== Drivers (Whitelisted) ====================
R2 acedrv01; C:\Windows\system32\drivers\acedrv01.sys [93696 2011-04-06] (ACE GmbH)
R2 acedrv02; C:\Windows\system32\drivers\acedrv02.sys [97280 2011-04-06] (ACE GmbH)
R2 acedrv03; C:\Windows\system32\drivers\acedrv03.sys [97280 2011-04-06] (ACE GmbH)
R2 acedrv04; C:\Windows\system32\drivers\acedrv04.sys [97280 2011-04-06] (Protect Software GmbH)
R2 acedrv05; C:\Windows\system32\drivers\acedrv05.sys [97792 2011-04-06] (Protect Software GmbH)
R2 acedrv06; C:\Windows\system32\drivers\acedrv06.sys [99840 2011-04-06] (Protect Software GmbH)
R2 acedrv07; C:\Windows\system32\drivers\acedrv07.sys [101376 2011-04-06] (Protect Software GmbH)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2010-01-30] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-04-10] (Avira Operations GmbH & Co. KG)
S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306300 2007-10-26] (Cisco Systems, Inc.)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [41984 2006-12-08] (Samsung Electronics Co., Ltd.)
R3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [127376 2007-01-31] (Deterministic Networks, Inc.)
R1 DritekPortIO; C:\PROGRA~1\LAUNCH~1\DPortIO.sys [20112 2006-11-02] (Dritek System Inc.)
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [57800 2009-10-22] (FTDI Ltd.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2010-01-30] ()
S3 massfilter; C:\Windows\System32\DRIVERS\massfilter.sys [9216 2010-06-10] (MBB Incorporated)
R1 SASDIFSV; C:\Tools\SUPERAntispyware\SASDIFSV.SYS [12880 2013-07-25] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Tools\SUPERAntispyware\SASKUTIL.SYS [67664 2013-07-25] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [721904 2009-10-27] (Duplex Secure Ltd.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2008-01-24] (Samsung Electronics)
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2009-10-14] (TuneUp Software)
R3 vodafone_K3805-z_dc_enum; C:\Windows\System32\DRIVERS\vodafone_K3805-z_dc_enum.sys [80000 2010-03-01] (Vodafone)
S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [29192 2009-01-14] (Logitech Inc.)
S3 WsAudio_DeviceS(1); C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys [25704 2011-09-06] (Wondershare)
S3 WsAudio_DeviceS(2); C:\Windows\System32\drivers\WsAudio_DeviceS(2).sys [25704 2011-09-06] (Wondershare)
S3 WsAudio_DeviceS(3); C:\Windows\System32\drivers\WsAudio_DeviceS(3).sys [25704 2011-09-06] (Wondershare)
S3 WsAudio_DeviceS(4); C:\Windows\System32\drivers\WsAudio_DeviceS(4).sys [25704 2011-09-06] (Wondershare)
S3 WsAudio_DeviceS(5); C:\Windows\System32\drivers\WsAudio_DeviceS(5).sys [25704 2011-09-06] (Wondershare)
S3 xnacc; C:\Windows\System32\DRIVERS\xnacc.sys [521216 2008-01-21] (Microsoft Corporation)
S3 ZTEusbnet; C:\Windows\System32\DRIVERS\ZTEusbnet.sys [114688 2010-04-30] (ZTE Corporation)
S3 ZTEusbvoice; C:\Windows\System32\DRIVERS\ZTEusbvoice.sys [105856 2010-04-30] (ZTE Incorporated)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\XX\AppData\Local\Temp\catchme.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
S3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS [x]
S3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 RimUsb; System32\Drivers\RimUsb.sys [x]
S1 SRTSP; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS [x]
S1 SRTSPX; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS [x]
U3 kwloikow; \??\C:\Users\XX\AppData\Local\Temp\kwloikow.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-10 22:47 - 2013-11-10 22:47 - 00377856 _____ C:\Users\XX\Downloads\gmer_2.1.19163.exe
2013-11-10 22:46 - 2013-11-10 22:46 - 01090275 _____ (Farbar) C:\Users\XX\Downloads\FRST.exe
2013-11-10 22:46 - 2013-11-10 22:46 - 00000000 ____D C:\FRST
2013-11-10 22:45 - 2013-11-10 22:45 - 00000520 _____ C:\Users\XX\Downloads\defogger_disable.log
2013-11-10 22:42 - 2013-11-10 22:42 - 00001000 _____ C:\Users\XX\Desktop\JRT.txt
2013-11-10 22:41 - 2013-11-10 22:41 - 00013742 _____ C:\Users\XX\Desktop\SUPERAntiSpyware Scan Log - 11-10-2013 - 22-30-25.log
2013-11-10 22:38 - 2013-11-10 22:38 - 00000000 ____D C:\Windows\ERUNT
2013-11-10 22:37 - 2013-11-10 22:37 - 00050477 _____ C:\Users\XX\Downloads\Defogger.exe
2013-11-10 22:15 - 2013-11-10 22:15 - 01034531 _____ (Thisisu) C:\Users\XX\Downloads\JRT.exe
2013-11-10 22:11 - 2013-11-10 22:11 - 00003010 _____ C:\Users\XX\Desktop\Ereignisse.txt
2013-11-10 21:57 - 2013-11-10 21:57 - 00001969 _____ C:\Users\XX\Desktop\AdwCleaner[S0].txt
2013-11-10 21:48 - 2013-11-10 21:49 - 74812406 _____ C:\Users\XX\Downloads\wetransfer-030a33.zip
2013-11-10 21:40 - 2013-11-10 22:01 - 00000000 ____D C:\AdwCleaner
2013-11-10 21:40 - 2013-11-10 21:40 - 01073258 _____ C:\Users\XX\Downloads\adw311cleaner.exe
2013-11-09 12:57 - 2013-11-09 12:57 - 00038666 ____T C:\Users\XX\Desktop\BeKoAb 2012.prn
2013-11-08 14:08 - 2013-11-08 14:14 - 804423482 _____ C:\Users\XX\Desktop\192570796.mp4
2013-11-05 21:41 - 2013-11-05 22:18 - 337404843 _____ C:\Users\XX\Downloads\Vermessung.m4v
2013-11-05 21:41 - 2013-11-05 22:09 - 160715688 _____ C:\Users\XX\Downloads\RKP Registrat.m4v
2013-11-05 21:40 - 2013-11-05 22:05 - 145500042 _____ C:\Users\XX\Downloads\Registrierbehelf unterfüttern.m4v
2013-11-05 21:40 - 2013-11-05 22:00 - 110866916 _____ C:\Users\XX\Downloads\Gesichtsbogen.m4v
2013-11-05 21:13 - 2013-11-05 21:35 - 82980836 _____ C:\Users\XX\Downloads\Einsetzen.m4v
2013-11-05 21:13 - 2013-11-05 21:30 - 57418352 _____ C:\Users\XX\Downloads\Druckstellen.m4v
2013-11-05 21:13 - 2013-11-05 21:26 - 35333541 _____ C:\Users\XX\Downloads\Extension UK.mov
2013-11-05 21:13 - 2013-11-05 21:22 - 28950271 _____ C:\Users\XX\Downloads\Extension OK.mov
2013-11-03 15:04 - 2013-06-14 15:19 - 106788807 _____ C:\Users\XX\Desktop\SV SCHOTT Jena.wmv
2013-11-03 00:23 - 2013-11-03 00:23 - 00000000 ____D C:\Users\XX\Desktop\Milky Chance
2013-11-03 00:23 - 2013-11-03 00:23 - 00000000 ____D C:\Users\XX\Desktop\José González
2013-11-03 00:23 - 2013-11-03 00:23 - 00000000 ____D C:\Users\XX\Desktop\Daft Punk
2013-11-03 00:23 - 2013-11-03 00:23 - 00000000 ____D C:\Users\XX\Desktop\Bastille
2013-10-21 19:48 - 2013-10-08 06:50 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-21 19:48 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-21 19:48 - 2013-10-08 06:46 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-21 19:48 - 2013-10-08 06:46 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-21 19:47 - 2013-10-21 19:48 - 00004874 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log
2013-10-19 17:01 - 2013-11-10 22:06 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-19 17:01 - 2013-11-10 21:55 - 00001088 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
==================== One Month Modified Files and Folders =======
2013-11-10 22:47 - 2013-11-10 22:47 - 00377856 _____ C:\Users\XX\Downloads\gmer_2.1.19163.exe
2013-11-10 22:46 - 2013-11-10 22:46 - 01090275 _____ (Farbar) C:\Users\XX\Downloads\FRST.exe
2013-11-10 22:46 - 2013-11-10 22:46 - 00000000 ____D C:\FRST
2013-11-10 22:45 - 2013-11-10 22:45 - 00000520 _____ C:\Users\XX\Downloads\defogger_disable.log
2013-11-10 22:42 - 2013-11-10 22:42 - 00001000 _____ C:\Users\XX\Desktop\JRT.txt
2013-11-10 22:41 - 2013-11-10 22:41 - 00013742 _____ C:\Users\XX\Desktop\SUPERAntiSpyware Scan Log - 11-10-2013 - 22-30-25.log
2013-11-10 22:38 - 2013-11-10 22:38 - 00000000 ____D C:\Windows\ERUNT
2013-11-10 22:37 - 2013-11-10 22:37 - 00050477 _____ C:\Users\XX\Downloads\Defogger.exe
2013-11-10 22:30 - 2009-10-01 00:50 - 00000460 _____ C:\Windows\Tasks\Packard Bell Customer Registration Reminder - Administrator.job
2013-11-10 22:27 - 2013-08-14 16:50 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-10 22:15 - 2013-11-10 22:15 - 01034531 _____ (Thisisu) C:\Users\XX\Downloads\JRT.exe
2013-11-10 22:11 - 2013-11-10 22:11 - 00003010 _____ C:\Users\XX\Desktop\Ereignisse.txt
2013-11-10 22:06 - 2013-10-19 17:01 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-10 22:01 - 2013-11-10 21:40 - 00000000 ____D C:\AdwCleaner
2013-11-10 21:59 - 2009-08-15 09:40 - 01750977 _____ C:\Windows\WindowsUpdate.log
2013-11-10 21:57 - 2013-11-10 21:57 - 00001969 _____ C:\Users\XX\Desktop\AdwCleaner[S0].txt
2013-11-10 21:55 - 2013-10-19 17:01 - 00001088 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-10 21:55 - 2013-08-15 11:17 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-10 21:55 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-10 21:55 - 2006-11-02 13:47 - 00004384 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-10 21:55 - 2006-11-02 13:47 - 00004384 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-10 21:54 - 2006-11-02 14:01 - 00032558 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-10 21:49 - 2013-11-10 21:48 - 74812406 _____ C:\Users\XX\Downloads\wetransfer-030a33.zip
2013-11-10 21:40 - 2013-11-10 21:40 - 01073258 _____ C:\Users\XX\Downloads\adw311cleaner.exe
2013-11-09 12:57 - 2013-11-09 12:57 - 00038666 ____T C:\Users\XX\Desktop\BeKoAb 2012.prn
2013-11-08 15:09 - 2010-09-19 20:57 - 00000000 ____D C:\Users\XX\AppData\Roaming\vlc
2013-11-08 14:14 - 2013-11-08 14:08 - 804423482 _____ C:\Users\XX\Desktop\192570796.mp4
2013-11-08 11:01 - 2012-05-03 13:25 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-11-07 16:07 - 2008-01-21 08:16 - 01454144 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-07 16:01 - 2009-10-02 18:25 - 00000000 ____D C:\Tools
2013-11-05 22:18 - 2013-11-05 21:41 - 337404843 _____ C:\Users\XX\Downloads\Vermessung.m4v
2013-11-05 22:09 - 2013-11-05 21:41 - 160715688 _____ C:\Users\XX\Downloads\RKP Registrat.m4v
2013-11-05 22:05 - 2013-11-05 21:40 - 145500042 _____ C:\Users\XX\Downloads\Registrierbehelf unterfüttern.m4v
2013-11-05 22:00 - 2013-11-05 21:40 - 110866916 _____ C:\Users\XX\Downloads\Gesichtsbogen.m4v
2013-11-05 21:35 - 2013-11-05 21:13 - 82980836 _____ C:\Users\XX\Downloads\Einsetzen.m4v
2013-11-05 21:30 - 2013-11-05 21:13 - 57418352 _____ C:\Users\XX\Downloads\Druckstellen.m4v
2013-11-05 21:26 - 2013-11-05 21:13 - 35333541 _____ C:\Users\XX\Downloads\Extension UK.mov
2013-11-05 21:22 - 2013-11-05 21:13 - 28950271 _____ C:\Users\XX\Downloads\Extension OK.mov
2013-11-03 16:05 - 2009-10-02 20:33 - 00000000 ____D C:\Users\XX\AppData\Roaming\XnView
2013-11-03 12:59 - 2009-11-08 19:52 - 00000000 ____D C:\Users\XX\AppData\Local\Paint.NET
2013-11-03 00:23 - 2013-11-03 00:23 - 00000000 ____D C:\Users\XX\Desktop\Milky Chance
2013-11-03 00:23 - 2013-11-03 00:23 - 00000000 ____D C:\Users\XX\Desktop\José González
2013-11-03 00:23 - 2013-11-03 00:23 - 00000000 ____D C:\Users\XX\Desktop\Daft Punk
2013-11-03 00:23 - 2013-11-03 00:23 - 00000000 ____D C:\Users\XX\Desktop\Bastille
2013-11-03 00:09 - 2010-12-27 12:20 - 00074648 _____ C:\Windows\setupact.log
2013-10-21 19:48 - 2013-10-21 19:47 - 00004874 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log
2013-10-21 19:48 - 2009-12-13 00:18 - 00000000 ____D C:\Program Files\Java
2013-10-19 17:05 - 2010-10-04 17:25 - 00000000 ____D C:\Program Files\Google
2013-10-16 14:26 - 2013-06-04 10:56 - 00000040 _____ C:\Autoconfig.ini
2013-10-13 23:10 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-10-13 22:53 - 2006-11-02 13:47 - 00310624 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-13 22:51 - 2012-12-14 20:40 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-13 22:51 - 2010-12-27 12:40 - 00141988 _____ C:\Windows\PFRO.log
Some content of TEMP:
====================
C:\Users\XX\AppData\Local\temp\jre-7u45-windows-i586-iftw.exe
C:\Users\XX\AppData\Local\temp\nvStInst.exe
C:\Users\XX\AppData\Local\temp\RtkBtMnt.exe
C:\Users\XX\AppData\Local\temp\sdanircmdc.exe
C:\Users\XX\AppData\Local\temp\Setup_Der-Fluch-des-Goldes-XS_DL.exe
C:\Users\XX\AppData\Local\temp\SkypeSetup.exe
C:\Users\XX\AppData\Local\temp\SSUPDATE.EXE
C:\Users\XX\AppData\Local\temp\tmp6354.exe
C:\Users\XX\AppData\Local\temp\UpdUninstall.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-10 22:02
==================== End Of Log ============================ Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 10-11-2013 01
Ran by XX at 2013-11-10 22:48:21
Running from C:\Users\XX\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe AIR (Version: 3.5.0.600)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Photoshop Elements 6.0 (Version: 6.0)
Adobe Reader X (10.1.4) - Deutsch (Version: 10.1.4)
Adobe Shockwave Player 12.0 (Version: 12.0.2.122)
Advertising Center (Version: 0.0.0.1)
Anno 1404 (Version: 1.00.0000)
Apple Application Support (Version: 2.1.7)
Audiograbber Lame-MP3-Plugin (Version: 1.0)
Avira Free Antivirus (Version: 13.0.0.4052)
Choice Guard (Version: 1.2.87.0)
CicloTour 4.4 (Version: 4.4)
CicloTrainer 5.00 (Version: 5)
Cisco Systems VPN Client 5.0.02.0090 (Version: 5.0.2)
Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000)
Counter-Strike
Counter-Strike 1.6 (Version: 1.00.0000)
CyberLink PowerDVD 8 (Version: 8.0.2430.50)
DivX Converter (Version: 7.1.0)
DivX-Setup (Version: 2.0.4.2)
Dropbox (HKCU Version: 1.4.17)
Dungeon Siege 2
Elevated Installer (Version: 2.2.21)
ERUNT 1.1j
FIFA 11 (Version: 1.0)
Free M4a to MP3 Converter 7.0
FreePDF (Remove only)
Garmin Express (Version: 2.2.21)
Garmin Express Tray (Version: 2.2.21)
Garmin Update Service (Version: 2.2.21)
Google Earth Plug-in (Version: 7.1.1.1888)
Google Update Helper (Version: 1.3.21.165)
GPL Ghostscript (Version: 9.02)
GTA San Andreas (Version: 1.00.00001)
Guitar Pro 5.2
Hactronic 1.82 (Version: 1.82)
Hattrick Organizer (remove only)
HISTO interaktiv 1.0
Hugin 2012.0.0 (Version: 2012.0.0 hg_a6e4184ad538)
Identity Card (Version: 4.04.3005)
ImagXpress (Version: 7.0.74.0)
InCD Help (Version: 6.4.0.0)
InfoCentre (Version: 3.01.3002)
iTunes (Version: 10.1.0.56)
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
Java DB 10.5.3.0 (Version: 10.5.3.0)
Java(TM) 6 Update 35 (Version: 6.0.350)
Java(TM) SE Development Kit 6 Update 23 (Version: 1.6.0.230)
Launch Manager (Version: 2.0.01)
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
MATLAB R2009b (Version: 7.9)
Mediscript-CD GK1
Menu Templates - Starter Kit (Version: 9.4.1.0)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Age of Empires II
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1)
Microsoft Office Standard Edition 2003 (Version: 11.0.8173.0)
Microsoft Office Suite Activation Assistant (Version: 2.9)
Microsoft PowerPoint Viewer (Version: 14.0.7015.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft_VC100_CRT_SP1_x86 (Version: 10.0.40219.1)
Moorhuhn Remake (Version: 1.00.0000)
Moorhuhnjagd
Movie Templates - Starter Kit (Version: 9.4.1.0)
Mozilla Firefox 25.0 (x86 de) (Version: 25.0)
Mozilla Maintenance Service (Version: 25.0)
Mozilla Thunderbird 24.1.0 (x86 de) (Version: 24.1.0)
MSVC80_x86_v2 (Version: 1.0.3.0)
MSVC90_x86 (Version: 1.0.1.2)
MSVCRT (Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Need for Speed™ SHIFT Demo (Version: 1.0.0.0)
Nero 9 Essentials
Nero BurnRights (Version: 2.99.6.100)
Nero BurnRights (Version: 3.4.7.100)
Nero ControlCenter (Version: 9.0.0.1)
Nero CoverDesigner (Version: 4.4.7.100)
Nero CoverDesigner Help (Version: 4.4.2.100)
Nero Disc Copy Gadget (Version: 2.4.17.0)
Nero Disc Copy Gadget Help (Version: 2.2.7.0)
Nero DiscSpeed (Version: 4.99.5.105)
Nero DiscSpeed (Version: 5.4.7.100)
Nero DriveSpeed (Version: 3.99.5.105)
Nero DriveSpeed (Version: 4.4.7.100)
Nero Express Help (Version: 9.2.2.100)
Nero InfoTool (Version: 5.99.5.105)
Nero InfoTool (Version: 6.4.7.100)
Nero Installer (Version: 2.0.0.1)
Nero Online Upgrade (Version: 1.3.0.0)
Nero Rescue Agent (Version: 2.4.4.100)
Nero RescueAgent Help (Version: 1.99.0.1)
Nero ShowTime (Version: 4.99.0.0)
Nero ShowTime (Version: 5.4.12.100)
Nero StartSmart (Version: 9.4.9.100)
Nero StartSmart Help (Version: 9.4.8.100)
Nero Vision (Version: 0.0.0.1)
Nero Vision (Version: 6.4.7.100)
NeroExpress (Version: 9.4.9.100)
neroxml (Version: 1.0.0)
Nokia Connectivity Cable Driver (Version: 7.1.101.0)
Nokia PC Suite (Version: 7.1.62.1)
Nokia Suite (Version: 3.7.22.0)
Norton Internet Security (Version: 16.0.0.125)
NVIDIA 3D Vision Treiber 310.90 (Version: 310.90)
NVIDIA Grafiktreiber 310.90 (Version: 310.90)
NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0)
NVIDIA Install Application (Version: 2.1002.95.599)
NVIDIA PhysX (Version: 9.12.1031)
NVIDIA PhysX-Systemsoftware 9.12.1031 (Version: 9.12.1031)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.1090)
NVIDIA Systemsteuerung 310.90 (Version: 310.90)
NVIDIA Update 1.11.3 (Version: 1.11.3)
NVIDIA Update Components (Version: 1.11.3)
Ovis pdf-Office 9.0 (Version: 9.0.2)
Packard Bell Customer Registration (Version: 1.07.3004)
Packard Bell PowerSave Solution (Version: 4.01.3013)
Packard Bell Recovery Management (Version: 4.00.3005)
Paint.NET v3.5.11 (Version: 3.61.0)
PC Connectivity Solution (Version: 12.0.76.0)
Perfect Effects 3 Free (Version: 3.0.2)
phonostar-Player Version 3.02.5
Picasa 3 (Version: 3.9)
QuickTime (Version: 7.68.75.0)
Realtek High Definition Audio Driver (Version: 6.0.1.5798)
Realtek USB 2.0 Card Reader (Version: 6.0.6000.20125)
RedMon - Redirection Port Monitor
Saal Design Software (Version: 3.1.26)
Samsung SCX-4200 Series
Samsung Universal Print Driver 2 (Version: 2.50.02.00)
Scan2PDF 1.6
SetupMyPC (Version: 3.04.3002)
Skype™ 5.10 (Version: 5.10.116)
SleepTimer Ultimate 1.11
Source SDK Base 2007
Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0)
Sports Car GT
Steam (Version: 1.0.0.0)
SUPERAntiSpyware (Version: 4.47.1000)
swMSM (Version: 12.0.0.1)
Synaptics Pointing Device Driver (Version: 12.2.2.0)
TmNationsForever
Total Commander (Remove or Repair) (Version: 7.50a)
Tropico
TuneUp Utilities (Version: 9.0.3000.52)
TuneUp Utilities Language Pack (de-DE) (Version: 9.0.3000.52)
Unity Web Player (HKCU Version: )
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Updator (Version: 3.02.3003.0)
VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0)
Video Web Camera (Version: 0.5.0.4)
Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (Version: 9.0.30729.01)
Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0)
VLC media player 2.0.6 (Version: 2.0.6)
Windows Live Anmelde-Assistent (Version: 5.000.818.6)
Windows Live Communications Platform (Version: 14.0.8050.1202)
Windows Live Essentials (Version: 14.0.8050.1202)
Windows Live Fotogalerie (Version: 14.0.8051.1204)
Windows Live Sync (Version: 14.0.8050.1202)
Windows-Treiberpaket - Nokia Modem (02/25/2011 4.7) (Version: 02/25/2011 4.7)
Windows-Treiberpaket - Nokia Modem (02/25/2011 7.01.0.9) (Version: 02/25/2011 7.01.0.9)
Windows-Treiberpaket - Nokia pccsmcfd “LegacyDriver” (05/31/2012 7.1.2.0) (Version: 05/31/2012 7.1.2.0)
WinRAR
WordToPDF 2.4 (Version: 2.4)
Xerox Phaser 6110MFP
XnView 1.96.5 (Version: 1.96.5)
==================== Restore Points =========================
11-10-2013 08:22:55 Geplanter Prüfpunkt
13-10-2013 01:35:14 Geplanter Prüfpunkt
21-10-2013 18:45:15 Installed Java 7 Update 45
25-10-2013 10:28:57 Geplanter Prüfpunkt
09-11-2013 21:21:55 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2006-11-02 11:23 - 2009-10-11 15:28 - 00000935 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 im.adtech.de
127.0.0.1 adserver.adtech.de
127.0.0.1 adtech.de
127.0.0.1 atwola.com
127.0.0.1 adserver.71i.de
127.0.0.1 adicqserver.71i.de
127.0.0.1 71i.de
==================== Scheduled Tasks (whitelisted) =============
Task: {10C27B7C-B7D4-4657-9964-6AF6358C3EF9} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Task: {18B0AF01-166C-4349-A3A2-672ADEAB9DD7} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {1B02CA31-2861-4365-86BC-EDEB9AC66549} - \Your File Updater No Task File
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3441A846-EDE8-4A2F-865B-188C94FA9EF0} - System32\Tasks\Automatische Problemsuche => C:\Program Files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-12-09] (TuneUp Software)
Task: {38CF9C61-E853-4950-9D88-79D17C295E80} - System32\Tasks\Acer\Burn Notification => C:\Program Files\PACKARD BELL\Packard Bell Recovery Management\NotificationCenter\Notification.exe [2009-02-05] (Acer)
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {88CF5228-2D40-46AB-B098-E65F0EF6BDBC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-19] (Google Inc.)
Task: {A3A6901E-EF35-48A5-BCC3-DF34066F6C60} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files\TuneUp Utilities 2010\OneClick.exe [2009-12-09] (TuneUp Software)
Task: {B7C13088-C47E-43F1-A12B-A63D25665A04} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-08] (Adobe Systems Incorporated)
Task: {BC593797-8906-4C08-8A6E-AF3BC17210B2} - System32\Tasks\Packard Bell Customer Registration Reminder - Administrator => C:\Program Files\PACKARD BELL\Packard Bell Customer Registration\PBCReg.exe [2009-03-30] (Acer Incorporated)
Task: {CF629E74-1FF3-49DD-82E8-0FB86FA74051} - \GoforFilesUpdate No Task File
Task: {DFC37D91-208D-428A-A74A-1823D8C6A858} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-19] (Google Inc.)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {ECD6909B-3C17-4B35-9892-CD640CEE128F} - System32\Tasks\Google Updater and Installer => C:\Users\XX\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {F0294881-C63D-4FDB-BA86-DE552197188A} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Packard Bell Customer Registration Reminder - Administrator.job => C:\Program Files\Packard Bell\Packard Bell Customer Registration\PBCReg.exe
==================== Loaded Modules (whitelisted) =============
2009-03-20 08:52 - 2003-06-07 06:30 - 00057344 _____ () C:\Program Files\Launch Manager\PowerUtl.dll
2013-11-05 22:59 - 2013-11-05 22:59 - 03368048 _____ () C:\Tools\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name: Microsoft-ISATAP-Adapter #9
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
Name: Cisco Systems VPN Adapter
Description: Cisco Systems VPN Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: CVirtA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2013-07-25 19:59:23.538
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_b2bfcb7c66ac7d10\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-25 19:59:22.929
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_b2bfcb7c66ac7d10\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-25 19:59:22.290
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_b2bfcb7c66ac7d10\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-25 19:59:21.666
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_b2bfcb7c66ac7d10\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-25 19:59:21.026
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_b2bfcb7c66ac7d10\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-25 19:59:20.402
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_b2bfcb7c66ac7d10\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-25 19:59:19.684
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18427_none_b30f7c1866701ed5\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-25 19:59:19.092
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18427_none_b30f7c1866701ed5\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-25 19:59:18.499
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18427_none_b30f7c1866701ed5\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-07-25 19:59:17.906
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18427_none_b30f7c1866701ed5\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 46%
Total physical RAM: 3069.04 MB
Available physical RAM: 1641.61 MB
Total Pagefile: 6380.33 MB
Available Pagefile: 4969.91 MB
Total Virtual: 2047.88 MB
Available Virtual: 1903.77 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:285.08 GB) (Free:23.96 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: CF8E25A6)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=285 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Ich würde mich freuen, wenn sich jemand dem Problem widmen kann. Eine kurze Ansage á la "am besten du formatierst" reicht mir auch. :)
Ich wünsche Euch einen schönen Abend und besten Dank im Voraus!
Grüße |