Sorry, das wusste ich nicht.
Also hier der Inhalt der FRST.txt-Datei:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-01-2014
Ran by Fischer (administrator) on FLEISCHER-PC on 19-01-2014 12:59:50
Running from C:\Users\Fischer\Desktop\Neuer Ordner
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Logitech Inc.) C:\Program Files (x86)\Squeezebox\SqueezeTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
(Acer Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Abine Inc.) C:\Program Files (x86)\Ask.com\AbineSDK\IE\DNTPService.exe
(CallingID Ltd.) C:\Program Files (x86)\Ask.com\CallingIDSDK\CIDGlobalLight.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8312352 2009-10-29] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-18] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-11-11] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [ArcadeDeluxeAgent] - C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [419112 2009-10-29] (CyberLink Corp.)
HKLM-x32\...\Run: [PlayMovie] - C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe [181480 2010-01-18] (Acer Corp.)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [261888 2009-09-24] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1100368 2009-11-02] (Dritek System Inc.)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1573584 2012-10-19] (Ask)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2014-01-01] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
MountPoints2: {939b0fd2-42cc-11e1-a2fa-806e6f6e6963} - F:\ting.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xDF5A95D4F68FCC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
SearchScopes: HKCU - DefaultScope {409C27A9-C53A-4A35-B8E2-652B2DFE2F17} URL = hxxp://websearch.ask.com/custom/java/redirect?client=ie&tb=ORJ&o=100000026&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000
SearchScopes: HKCU - {3FCF2726-755C-433E-B377-C20AA65BEB60} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {409C27A9-C53A-4A35-B8E2-652B2DFE2F17} URL = hxxp://websearch.ask.com/custom/java/redirect?client=ie&tb=ORJ&o=100000026&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U37) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.370.6) - C:\Windows\SysWOW64\npdeployJava1.dll No File
CHR Extension: (YouTube) - C:\Users\Fischer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-18]
CHR Extension: (Google-Suche) - C:\Users\Fischer\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-18]
CHR Extension: (Google Wallet) - C:\Users\Fischer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-14]
CHR Extension: (Google Mail) - C:\Users\Fischer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-18]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2014-01-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2014-01-01] (Avira Operations GmbH & Co. KG)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-01-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-01-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-03] (Avira Operations GmbH & Co. KG)
S3 AX88772; C:\Windows\System32\DRIVERS\ax88772.sys [73728 2009-10-02] (ASIX Electronics Corp.)
U3 ffdyiuod; \??\C:\Users\Fischer\AppData\Local\Temp\ffdyiuod.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-19 12:58 - 2014-01-19 12:58 - 00000476 _____ C:\Users\Fischer\Desktop\defogger_disable.log
2014-01-19 12:58 - 2014-01-19 12:58 - 00000000 _____ C:\Users\Fischer\defogger_reenable
2014-01-19 11:11 - 2014-01-19 12:59 - 00000000 ____D C:\FRST
2014-01-19 10:17 - 2014-01-19 12:59 - 00000000 ____D C:\Users\Fischer\Desktop\Neuer Ordner
2014-01-16 21:22 - 2014-01-16 21:23 - 00000000 ____D C:\Users\Fischer\Desktop\fasching
2014-01-15 20:57 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 20:57 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 20:57 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 20:57 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 20:57 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 20:57 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 20:57 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 20:57 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 20:57 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-07 21:22 - 2014-01-07 21:22 - 00000000 ____D C:\Users\Fischer\Desktop\Mia
==================== One Month Modified Files and Folders =======
2014-01-19 12:59 - 2014-01-19 11:11 - 00000000 ____D C:\FRST
2014-01-19 12:59 - 2014-01-19 10:17 - 00000000 ____D C:\Users\Fischer\Desktop\Neuer Ordner
2014-01-19 12:58 - 2014-01-19 12:58 - 00000476 _____ C:\Users\Fischer\Desktop\defogger_disable.log
2014-01-19 12:58 - 2014-01-19 12:58 - 00000000 _____ C:\Users\Fischer\defogger_reenable
2014-01-19 12:58 - 2011-10-21 11:12 - 00000000 ____D C:\Users\Fischer
2014-01-19 12:57 - 2012-11-18 19:25 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-19 12:41 - 2011-10-21 10:46 - 01916364 _____ C:\Windows\WindowsUpdate.log
2014-01-19 12:36 - 2012-04-10 20:05 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-19 12:20 - 2012-01-18 21:04 - 00000000 ____D C:\Users\Fischer\Documents\Outlook-Dateien
2014-01-19 11:14 - 2009-07-14 05:45 - 00015600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-19 11:14 - 2009-07-14 05:45 - 00015600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-19 10:22 - 2011-10-24 20:17 - 00003954 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{0A7068A7-EE7A-4506-91D9-D6ABDC893065}
2014-01-19 10:17 - 2012-11-18 19:25 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-19 10:17 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-19 10:16 - 2009-07-14 05:51 - 00075512 _____ C:\Windows\setupact.log
2014-01-17 00:08 - 2012-02-06 20:33 - 00000186 _____ C:\Users\Fischer\AppData\Roaming\default.rss
2014-01-17 00:08 - 2012-02-06 20:31 - 00000069 _____ C:\Windows\NeroDigital.ini
2014-01-17 00:06 - 2011-10-24 19:55 - 00000000 ____D C:\Users\Fischer\AppData\Roaming\SoftDMA
2014-01-17 00:06 - 2011-10-24 19:55 - 00000000 ____D C:\Users\Fischer\AppData\Local\PlayMovie
2014-01-17 00:05 - 2011-10-24 19:48 - 00008066 _____ C:\ProgramData\ArcadeDeluxe3.log
2014-01-17 00:04 - 2011-10-24 19:51 - 00000000 ____D C:\ProgramData\CyberLink
2014-01-17 00:04 - 2011-10-24 19:47 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-16 23:06 - 2009-07-14 19:18 - 00000000 ___RD C:\Users\Public\Recorded TV
2014-01-16 22:09 - 2012-10-16 13:01 - 00000000 ____D C:\Users\Fischer\AppData\Local\DoNotTrackPlus
2014-01-16 21:23 - 2014-01-16 21:22 - 00000000 ____D C:\Users\Fischer\Desktop\fasching
2014-01-15 21:20 - 2009-07-14 05:45 - 00416312 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-15 21:09 - 2013-08-16 21:52 - 00000000 ____D C:\Windows\system32\MRT
2014-01-15 21:07 - 2011-10-22 10:28 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-10 20:54 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2014-01-07 21:22 - 2014-01-07 21:22 - 00000000 ____D C:\Users\Fischer\Desktop\Mia
2014-01-01 21:09 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-01 11:54 - 2013-11-20 21:55 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-01-01 11:54 - 2013-11-20 21:55 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-01-01 11:54 - 2013-05-06 12:34 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-01-01 11:47 - 2013-02-25 21:17 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2014-01-01 11:47 - 2011-10-24 19:55 - 00000000 ____D C:\Users\Fischer\AppData\Roaming\PowerCinema
2014-01-01 11:47 - 2011-10-24 19:12 - 00000000 __RHD C:\MSOCache
2014-01-01 11:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2013-12-28 22:04 - 2013-08-26 19:42 - 00000000 ____D C:\Users\Fischer\Desktop\Neue Nachbarn-Kopien
2013-12-28 21:11 - 2013-06-24 20:48 - 00000000 ____D C:\ProgramData\tmp
Some content of TEMP:
====================
C:\Users\Fischer\AppData\Local\Temp\76E5.exe
C:\Users\Fischer\AppData\Local\Temp\ApnStub.exe
C:\Users\Fischer\AppData\Local\Temp\avgnt.exe
C:\Users\Fischer\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Users\Fischer\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe
C:\Users\Fischer\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe
C:\Users\Fischer\AppData\Local\Temp\jre-6u39-windows-i586-iftw.exe
C:\Users\Fischer\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\Fischer\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Fischer\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Fischer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Fischer\AppData\Local\Temp\ose00000.exe
C:\Users\Fischer\AppData\Local\Temp\pdf24-creator-update.exe
C:\Users\Fischer\AppData\Local\Temp\setup.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-30 20:41
==================== End Of Log ============================ --- --- ---
Dann hier noch die Addition.txt-Datei: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-01-2014 03
Ran by Fischer at 2014-01-19 11:14:01
Running from C:\Users\Fischer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NM2MG583
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Acer Arcade Deluxe (x32 Version: 3.0.7319 - CyberLink Corp.)
Acer Arcade Deluxe (x32 Version: 3.0.7319 - CyberLink Corp.) Hidden
Acer Backup Manager (x32 Version: 2.0.0.29 - NewTech Infosystems)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (x32 Version: 11.0.06 - Adobe Systems Incorporated)
Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
ALDI NORD Bestellsoftware 4.12.2 (x32 Version: 4.12.2 - ORWO Net)
Ask Toolbar (x32 Version: 1.15.26.0 - Ask.com) <==== ATTENTION
ATI AVIVO64 Codecs (Version: 10.11.0.41111 - ATI Technologies Inc.) Hidden
ATI Catalyst Install Manager (Version: 3.0.750.0 - ATI Technologies, Inc.)
Avira Free Antivirus (x32 Version: 14.0.2.286 - Avira)
Avira SearchFree Toolbar plus Web Protection Updater (HKCU Version: 1.4.1.29781 - Ask.com)
Backup Manager Basic (x32 Version: 2.0.0.29 - NewTech Infosystems) Hidden
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2009.1111.2327.42077 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2009.1111.2327.42077 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2009.1111.2327.42077 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2009.1111.2327.42077 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.1111.2327.42077 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2009.1111.2327.42077 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2009.1111.2327.42077 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Czech (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Danish (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Dutch (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help English (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Finnish (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help French (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help German (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Greek (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Italian (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Japanese (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Korean (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Polish (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Russian (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Spanish (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Swedish (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Thai (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
CCC Help Turkish (x32 Version: 2009.1111.2326.42077 - ATI) Hidden
ccc-core-static (x32 Version: 2009.1111.2327.42077 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2009.1111.2327.42077 - ATI) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32 Version: - Microsoft)
DVDFab 7.0.4.0 (15/04/2010) (x32 Version: - Fengtao Software Inc.)
Google Chrome (x32 Version: 32.0.1700.76 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (x32 Version: 7.5.4805.320 - Google Inc.)
Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
Java 7 Update 45 (x32 Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Launch Manager (x32 Version: 3.0.04 - Acer Inc.)
Logitech Media Server 7.7.3 (x32 Version: 7.7.3 - Logitech)
McAfee Security Scan Plus (Version: 3.8.130.10 - McAfee, Inc.)
Menu Templates - Starter Kit (x32 Version: 9.4.6.0 - Nero AG) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office 2010 Service Pack 1 (SP1) (x32 Version: - Microsoft)
Microsoft Office 2010 Service Pack 1 (SP1) (x32 Version: - Microsoft) Hidden
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Movie Templates - Starter Kit (x32 Version: 9.4.6.0 - Nero AG) Hidden
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation)
Nero 9 Essentials (x32 Version: - Nero AG)
Nero BurnRights (x32 Version: 3.4.13.100 - Nero AG) Hidden
Nero BurnRights Help (x32 Version: 3.4.4.100 - Nero AG) Hidden
Nero ControlCenter (x32 Version: 9.0.0.1 - Nero AG) Hidden
Nero CoverDesigner (x32 Version: 4.4.12.100 - Nero AG) Hidden
Nero CoverDesigner Help (x32 Version: 4.4.9.100 - Nero AG) Hidden
Nero Disc Copy Gadget (x32 Version: 2.4.34.0 - Nero AG) Hidden
Nero Disc Copy Gadget Help (x32 Version: 2.4.34.0 - Nero AG) Hidden
Nero DiscSpeed (x32 Version: 5.4.13.100 - Nero AG) Hidden
Nero DiscSpeed Help (x32 Version: 5.4.4.100 - Nero AG) Hidden
Nero DriveSpeed (x32 Version: 4.4.12.100 - Nero AG) Hidden
Nero DriveSpeed Help (x32 Version: 4.4.4.100 - Nero AG) Hidden
Nero Express Help (x32 Version: 9.4.27.100 - Nero AG) Hidden
Nero InfoTool (x32 Version: 6.4.12.100 - Nero AG) Hidden
Nero InfoTool Help (x32 Version: 6.4.4.100 - Nero AG) Hidden
Nero Installer (x32 Version: 4.4.9.0 - Nero AG) Hidden
Nero Online Upgrade (x32 Version: 1.3.0.0 - Nero AG) Hidden
Nero Rescue Agent (x32 Version: 2.4.14.100 - Nero AG) Hidden
Nero RescueAgent Help (x32 Version: 2.4.4.100 - Nero AG) Hidden
Nero ShowTime (x32 Version: 5.4.0.100 - Nero AG) Hidden
Nero ShowTime (x32 Version: 5.4.21.100 - Nero AG) Hidden
Nero StartSmart (x32 Version: 9.4.19.100 - Nero AG) Hidden
Nero StartSmart Help (x32 Version: 9.4.19.100 - Nero AG) Hidden
Nero Vision (x32 Version: 6.4.16.100 - Nero AG) Hidden
Nero Vision Help (x32 Version: 6.4.15.100 - Nero AG) Hidden
NeroExpress (x32 Version: 9.4.27.100 - Nero AG) Hidden
neroxml (x32 Version: 1.0.0 - Nero AG) Hidden
PDF24 Creator 5.2.0 (x32 Version: - PDF24.org)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.5969 - Realtek Semiconductor Corp.)
Rossmann Fotowelt Software 4.12.1 (x32 Version: 4.12.1 - ORWO Net)
Synaptics Pointing Device Driver (Version: 14.0.6.0 - Synaptics Incorporated)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553065) (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2566458) (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (x32 Version: - Microsoft)
WinRAR 4.01 (64-Bit) (Version: 4.01.0 - win.rar GmbH)
==================== Restore Points =========================
15-11-2013 19:05:43 Windows Update
03-12-2013 20:54:31 Windows Update
11-12-2013 21:45:17 Windows Update
16-12-2013 20:49:00 Windows Update
01-01-2014 12:35:56 Windows Update
15-01-2014 20:06:54 Windows Update
16-01-2014 23:03:24 Installiert Suite
==================== Hosts content: ==========================
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {1975732F-2F82-485A-84C7-65A387ED01E7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-12] (Adobe Systems Incorporated)
Task: {1C3585F1-AA06-4407-8780-4823DBC442CF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-18] (Google Inc.)
Task: {3BC72FB8-8188-4449-9C8D-EEEF166CD525} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-18] (Google Inc.)
Task: {D47A45D8-66CC-4821-8E4F-54001082500A} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2013-04-30] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2011-10-22 09:56 - 2011-05-28 21:05 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll
2009-07-29 12:10 - 2009-07-29 12:10 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2011-10-22 11:15 - 2011-10-22 11:15 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2012-10-16 12:58 - 2012-09-19 18:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2009-02-02 16:33 - 2009-02-02 16:33 - 00460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2008-09-28 16:55 - 2008-09-28 16:55 - 01076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00028774 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00024679 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\c5cce8d16a1bd48692b421dcf46d3396\Util.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00032878 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00024701 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00028779 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00020601 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\4461f48e31bde5c56b31b973b773de09\List.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00118918 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00082048 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00020576 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00036964 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\f233f63b6654362865c7577442edb9e3\Win32.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00020590 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00082033 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00024676 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00061540 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\e56c61f7248672819579325af3387035\POSIX.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00094334 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\eb138ef0e4282611dbf485a302784646\LibYAML.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00053340 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00184414 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\bd5179a413bc0c4b82eedc22c6cab101\re.dll
2014-01-19 10:17 - 2014-01-19 10:17 - 00024701 ____R () C:\Users\Fischer\AppData\Local\Temp\pdk-Fischer-1952\93e7e3d6030f426844228042348210cf\Service.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2010-12-21 01:15 - 2010-12-21 01:15 - 01041248 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2013-03-10 22:39 - 2013-03-10 22:39 - 00597880 _____ () C:\Program Files (x86)\Ask.com\AbineSDK\IE\DNTPContentFilter.dll
2013-03-10 22:39 - 2013-03-10 22:39 - 00051728 _____ () C:\Program Files (x86)\Ask.com\AbineSDK\IE\DNTPServicePS.dll
2013-03-10 22:39 - 2013-03-10 22:39 - 00227192 _____ () C:\Program Files (x86)\Ask.com\AbineSDK\IE\DNTPButton.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/15/2014 09:25:15 PM) (Source: Application Hang) (User: )
Description: Programm iexplore.exe, Version 11.0.9600.16428 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 424
Startzeit: 01cf122f9750a237
Endzeit: 0
Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe
Berichts-ID: 14f1d327-7e23-11e3-90b8-00262d776ff4
Error: (01/05/2014 11:21:49 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00006400
ID des fehlerhaften Prozesses: 0x7f0
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (01/01/2014 00:24:40 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7
Ausnahmecode: 0xc000041d
Fehleroffset: 0x00038e19
ID des fehlerhaften Prozesses: 0x12cc
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (01/01/2014 00:24:34 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00038e19
ID des fehlerhaften Prozesses: 0x12cc
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (01/01/2014 11:49:01 AM) (Source: Avira Antivirus) (User: NT-AUTORITÄT)
Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
Error: (12/26/2013 03:38:52 PM) (Source: Winlogon) (User: )
Description: Der Windows-Anmeldeprozess wurde unerwartet beendet.
Error: (12/16/2013 09:50:41 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b96f
Ausnahmecode: 0xc000041d
Fehleroffset: 0x0002afdb
ID des fehlerhaften Prozesses: 0x12d0
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (12/16/2013 09:49:57 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16428, Zeitstempel: 0x525b664c
Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b96f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002afdb
ID des fehlerhaften Prozesses: 0x12d0
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Error: (12/03/2013 11:23:27 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001487
ID des fehlerhaften Prozesses: 0x85c
Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0
Pfad der fehlerhaften Anwendung: avnotify.exe1
Pfad des fehlerhaften Moduls: avnotify.exe2
Berichtskennung: avnotify.exe3
Error: (12/03/2013 11:23:23 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT)
Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
System errors:
=============
Error: (01/17/2014 00:00:02 AM) (Source: cdrom) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (01/16/2014 11:59:55 PM) (Source: cdrom) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (01/16/2014 11:59:48 PM) (Source: cdrom) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (01/16/2014 11:59:41 PM) (Source: cdrom) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (01/16/2014 11:59:34 PM) (Source: cdrom) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (01/16/2014 11:59:27 PM) (Source: cdrom) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (01/16/2014 11:59:20 PM) (Source: cdrom) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (01/16/2014 11:59:13 PM) (Source: cdrom) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (01/16/2014 11:59:06 PM) (Source: cdrom) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (01/16/2014 11:59:00 PM) (Source: cdrom) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Microsoft Office Sessions:
=========================
Error: (01/15/2014 09:25:15 PM) (Source: Application Hang)(User: )
Description: iexplore.exe11.0.9600.1642842401cf122f9750a2370C:\Program Files\Internet Explorer\iexplore.exe14f1d327-7e23-11e3-90b8-00262d776ff4
Error: (01/05/2014 11:21:49 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cunknown0.0.0.000000000c0000005000064007f001cf0a5b96464bebC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEunknownc4b16863-7657-11e3-b0ec-00262d776ff4
Error: (01/01/2014 00:24:40 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cntdll.dll6.1.7601.18247521ea8e7c000041d00038e1912cc01cf06dfb2083354C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\ntdll.dll4d54c1d1-72d7-11e3-89e0-00262d776ff4
Error: (01/01/2014 00:24:34 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cntdll.dll6.1.7601.18247521ea8e7c000000500038e1912cc01cf06dfb2083354C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\ntdll.dll4a3030b4-72d7-11e3-89e0-00262d776ff4
Error: (01/01/2014 11:49:01 AM) (Source: Avira Antivirus)(User: NT-AUTORITÄT)
Description: 0x0
Error: (12/26/2013 03:38:52 PM) (Source: Winlogon)(User: )
Description:
Error: (12/16/2013 09:50:41 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cole32.dll6.1.7601.175144ce7b96fc000041d0002afdb12d001cefaa008ee66f1C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\ole32.dllb94acc8d-6693-11e3-9568-00262d776ff4
Error: (12/16/2013 09:49:57 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.16428525b664cole32.dll6.1.7601.175144ce7b96fc00000050002afdb12d001cefaa008ee66f1C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\ole32.dll9ec1353f-6693-11e3-9568-00262d776ff4
Error: (12/03/2013 11:23:27 PM) (Source: Application Error)(User: )
Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c00000050000148785c01cef076495d5d02C:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe87965913-5c69-11e3-a54b-00262d776ff4
Error: (12/03/2013 11:23:23 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT)
Description: 0x0
==================== Memory info ===========================
Percentage of memory in use: 31%
Total physical RAM: 6004.5 MB
Available physical RAM: 4110.13 MB
Total Pagefile: 12007.18 MB
Available Pagefile: 9752.87 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (Windows 7) (Fixed) (Total:228.36 GB) (Free:144.09 GB) NTFS
Drive d: (Daten) (Fixed) (Total:224.61 GB) (Free:193.36 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: DF90DF90)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=228 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=225 GB) - (Type=OF Extended)
==================== End Of Log ============================ und dann noch der LOG-File aus "GMER": Code:
GMER 2.1.19322 - hxxp://www.gmer.net
Rootkit scan 2014-01-19 12:54:39
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD5000BEVT-22A0RT0 rev.01.01A01 465,76GB
Running: gmer.exe; Driver: C:\Users\Fischer\AppData\Local\Temp\ffdyiuod.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80003206000 45 bytes [00, 00, 16, 02, 4E, 74, 66, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff8000320602f 10 bytes [00, 01, 00, 06, 00, 00, 00, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[1012] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076fb1465 2 bytes [FB, 76]
.text C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[1012] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076fb14bb 2 bytes [FB, 76]
.text ... * 2
.text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[2760] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076fb1465 2 bytes [FB, 76]
.text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[2760] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076fb14bb 2 bytes [FB, 76]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[1452] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076fb1465 2 bytes [FB, 76]
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[1452] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076fb14bb 2 bytes [FB, 76]
.text ... * 2
.text C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe[3980] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076fb1465 2 bytes [FB, 76]
.text C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe[3980] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076fb14bb 2 bytes [FB, 76]
.text ... * 2
---- EOF - GMER 2.1 ---- Ich hoffe jetzt ist es einfacher. Ich habe da noch dieses defogger_disable.log angelegt. Brauchst du die auch noch?
Danke
Weber75 |