Liebe Aneri,
ich habe eine mail bekommen, das das Logfile aus schritt 2 falsch ist. Ich habe es jetzt noch mal versucht, und das kam dabei raus, ich hoffe es stimmt. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 08.02.2015 12:12:48, SYSTEM, FAMILIE-738765D, Protection, Malware Protection, Starting,
Protection, 08.02.2015 12:12:49, SYSTEM, FAMILIE-738765D, Protection, Malware Protection, Started,
Protection, 08.02.2015 12:12:49, SYSTEM, FAMILIE-738765D, Protection, Malicious Website Protection, Starting,
Protection, 08.02.2015 12:14:49, SYSTEM, FAMILIE-738765D, Protection, Malicious Website Protection, Started,
Update, 08.02.2015 12:33:08, SYSTEM, FAMILIE-738765D, Scheduler, Malware Database, 2015.2.6.4, 2015.2.8.4,
Protection, 08.02.2015 12:33:08, SYSTEM, FAMILIE-738765D, Protection, Refresh, Starting,
Protection, 08.02.2015 12:33:08, SYSTEM, FAMILIE-738765D, Protection, Malicious Website Protection, Stopping,
Protection, 08.02.2015 12:33:09, SYSTEM, FAMILIE-738765D, Protection, Malicious Website Protection, Stopped,
Protection, 08.02.2015 12:33:28, SYSTEM, FAMILIE-738765D, Protection, Refresh, Success,
Protection, 08.02.2015 12:33:28, SYSTEM, FAMILIE-738765D, Protection, Malicious Website Protection, Starting,
Protection, 08.02.2015 12:33:43, SYSTEM, FAMILIE-738765D, Protection, Malicious Website Protection, Started,
Protection, 08.02.2015 13:05:51, SYSTEM, FAMILIE-738765D, Protection, Malware Protection, Starting,
Protection, 08.02.2015 13:05:52, SYSTEM, FAMILIE-738765D, Protection, Malware Protection, Started,
Protection, 08.02.2015 13:06:20, SYSTEM, FAMILIE-738765D, Protection, Malicious Website Protection, Starting,
Protection, 08.02.2015 13:06:37, SYSTEM, FAMILIE-738765D, Protection, Malicious Website Protection, Started,
(end)
So ich hoffe alles stimmt jetzt (für mich sieht das zwar alles gleich aus aber hoffentlich stimmt es jetzt)
Schritt 3 ist noch in bearbeitung...
Liebe Aneri,
hier kommt schritt 3: Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=c5f94e4e625d0b469e4e71d5d3f47b0f
# engine=22380
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-02-09 06:29:37
# local_time=2015-02-09 07:29:37 (+0100, Westeuropäische Normalzeit)
# country="Germany"
# lang=1031
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode_1='AVG Internet Security 2014'
# compatibility_mode=1049 16777213 100 100 111766 110636961 0 0
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 24090681 94796599 0 0
# scanned=86058
# found=2
# cleaned=2
# scan_time=8276
sh=DC69F69E0FE7B153118C9F4D4E59318027CF29C1 ft=1 fh=e9313ee6409597e8 vn="Variante von Win32/FileTypeAssistant.A evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Dokumente und Einstellungen\Marie-Sophie\Eigene Dateien\Downloads\FinalMediaPlayer2014U1Setup.exe"
sh=465433C37D42CC986DB0E1B60A9A482925950033 ft=1 fh=4f6ad7b3ad9b536c vn="Variante von Win32/InstallCore.SX evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Dokumente und Einstellungen\Marie-Sophie\Eigene Dateien\Downloads\FinalMediaPlayerSetup.exe" dankööö :)
So und hier ist jetzt das logfile von schritt 4:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-02-2015
Ran by Marie-Sophie (administrator) on FAMILIE-738765D on 09-02-2015 19:52:15
Running from C:\Dokumente und Einstellungen\Marie-Sophie\Eigene Dateien\Downloads
Loaded Profiles: Marie-Sophie (Available profiles: Marie-Sophie)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2014\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Programme\AVG\AVG2014\avgcsrvx.exe
(Microsoft Corporation) C:\Programme\Microsoft Security Client\MsMpEng.exe
(Intel(R) Corporation) C:\Programme\Intel\WiFi\bin\S24EvMon.exe
(Logitech Inc.) C:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\UMVPFSrv.exe
(Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe
(Broadcom Corporation) C:\Programme\Broadcom\ASFIPMon\AsfIpMon.exe
(AVG Technologies CZ, s.r.o.) C:\Programme\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Programme\AVG\AVG2014\avgwdsvc.exe
(Intel(R) Corporation) C:\Programme\Intel\WiFi\bin\EvtEng.exe
(SigmaTel, Inc.) C:\Programme\SigmaTel\C-Major Audio\WDM\stsystra.exe
(Dell Inc.) C:\Programme\Dell\QuickSet\quickset.exe
(Oracle Corporation) C:\Programme\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Wave Systems Corp.) C:\Programme\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe
(Wave Systems Corp.) C:\Programme\Wave Systems Corp\SecureUpgrade.exe
(Intel(R) Corporation) C:\Programme\Intel\WiFi\bin\ZCfgSvc.exe
(Intel(R) Corporation) C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\iFrmewrk.exe
(Adobe Systems Incorporated) C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard) C:\Programme\Hewlett-Packard\OrderReminder\OrderReminder.exe
(Logitech Inc.) C:\Programme\Logitech\LWS\Webcam Software\LWS.exe
(AVG Technologies CZ, s.r.o.) C:\Programme\AVG\AVG2014\avgui.exe
(Microsoft Corporation) C:\Programme\Microsoft Security Client\msseces.exe
(Oracle Corporation) C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
(Logitech Inc.) C:\Programme\Logitech\Vid HD\Vid.exe
(Dell Inc.) C:\Programme\Dell\QuickSet\NicConfigSvc.exe
() C:\Programme\Logitech\LWS\Webcam Software\CameraHelperShell.exe
(AVG Technologies CZ, s.r.o.) C:\Programme\AVG\AVG2014\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Programme\AVG\AVG2014\avgemcx.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Spotify Ltd) C:\Dokumente und Einstellungen\Marie-Sophie\Anwendungsdaten\Spotify\Data\SpotifyWebHelper.exe
(Intel(R) Corporation) C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe
(Skype Technologies S.A.) C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(SigmaTel, Inc.) C:\Programme\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe
(TOSHIBA CORPORATION.) C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
(McAfee, Inc.) C:\Programme\McAfee Security Scan\3.8.130\SSScheduler.exe
(Wave Systems Corp.) C:\Programme\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
(TOSHIBA CORPORATION.) C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
(TOSHIBA CORPORATION.) C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
(Intel(R) Corporation) C:\Programme\Intel\WiFi\bin\WLKEEPER.exe
(TOSHIBA CORPORATION.) C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
() C:\Programme\Gemeinsame Dateien\LogiShrd\LQCVFX\COCIManager.exe
(TOSHIBA CORPORATION.) C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
(TOSHIBA CORPORATION.) C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes Anti-Malware\mbam.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes Anti-Malware\mbamscheduler.exe
(Mozilla Corporation) C:\Programme\Mozilla Firefox\firefox.exe
(Farbar) C:\Dokumente und Einstellungen\Marie-Sophie\Eigene Dateien\Downloads\FRST(2).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SigmatelSysTrayApp] => C:\Programme\SigmaTel\C-Major Audio\WDM\stsystra.exe [405504 2007-05-10] (SigmaTel, Inc.)
HKLM\...\Run: [Dell QuickSet] => C:\Programme\Dell\QuickSet\quickset.exe [1245184 2008-02-22] (Dell Inc.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /installquiet
HKLM\...\Run: [NVHotkey] => rundll32.exe nvHotkey.dll,Start
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [ChangeTPMAuth] => C:\Programme\Wave Systems Corp\Common\ChangeTPMAuth.exe [184320 2009-02-26] (Wave Systems Corp.)
HKLM\...\Run: [WavXMgr] => C:\Programme\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe [145408 2009-03-06] (Wave Systems Corp.)
HKLM\...\Run: [SecureUpgrade] => C:\Programme\Wave Systems Corp\SecureUpgrade.exe [656696 2009-03-06] (Wave Systems Corp.)
HKLM\...\Run: [EmbassySecurityCheck] => C:\Programme\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe [95544 2009-03-06] (Wave Systems Corp.)
HKLM\...\Run: [IntelZeroConfig] => C:\Programme\Intel\WiFi\bin\ZCfgSvc.exe [1372160 2009-11-03] (Intel(R) Corporation)
HKLM\...\Run: [IntelWireless] => C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\iFrmewrk.exe [1202448 2009-11-03] (Intel(R) Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [OrderReminder] => C:\Programme\Hewlett-Packard\OrderReminder\OrderReminder.exe [98304 2006-01-30] (Hewlett-Packard)
HKLM\...\Run: [LWS] => C:\Programme\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-11-11] (Logitech Inc.)
HKLM\...\Run: [AVG_UI] => C:\Programme\AVG\AVG2014\avgui.exe [4908592 2013-10-07] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [MSC] => c:\Programme\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-1275210071-162531612-1801674531-1004\...\Run: [Logitech Vid] => C:\Programme\Logitech\Vid HD\Vid.exe [6129496 2011-01-13] (Logitech Inc.)
HKU\S-1-5-21-1275210071-162531612-1801674531-1004\...\Run: [Spotify Web Helper] => C:\Dokumente und Einstellungen\Marie-Sophie\Anwendungsdaten\Spotify\Data\SpotifyWebHelper.exe [1676344 2015-01-06] (Spotify Ltd)
HKU\S-1-5-21-1275210071-162531612-1801674531-1004\...\Run: [Spotify] => C:\Dokumente und Einstellungen\Marie-Sophie\Anwendungsdaten\Spotify\spotify.exe [6737976 2015-01-06] (Spotify Ltd)
HKU\S-1-5-21-1275210071-162531612-1801674531-1004\...\MountPoints2: {b2b734a8-2b45-11e2-b60a-001c231d850e} - F:\iLinker.exe
HKU\S-1-5-18\...\Run: [DWQueuedReporting] => c:\Programme\Gemeinsame Dateien\Microsoft Shared\DW\DWTRIG20.EXE [437160 2007-02-26] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [WUAppSetup] => C:\Programme\Gemeinsame Dateien\logishrd\WUApp32.exe [465944 2012-01-18] ()
Lsa: [Authentication Packages] msv1_0 wvauth nwprovau
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Bluetooth Manager.lnk
ShortcutTarget: Bluetooth Manager.lnk -> C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Programme\McAfee Security Scan\3.8.130\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Winsol_Autostart.lnk
ShortcutTarget: Winsol_Autostart.lnk -> C:\Programme\Technische Alternative\Winsol\Winsol.exe (Technische Alternative)
Startup: C:\Dokumente und Einstellungen\Felix\Startmenü\Programme\Autostart\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Programme\OpenOffice.org 3\program\quickstart.exe (No File)
Startup: C:\Dokumente und Einstellungen\Rainer\Startmenü\Programme\Autostart\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Programme\OpenOffice.org 3\program\quickstart.exe (No File)
ShellIconOverlayIdentifiers: [EnabledUnlockedFDEIconOverlay] -> {30D3C2AF-9709-4D05-9CF4-13335F3C1E4A} => C:\Programme\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll (Wave Systems Corp.)
ShellIconOverlayIdentifiers: [UninitializedFdeIconOverlay] -> {CF08DA3E-C97D-4891-A66B-E39B28DD270F} => C:\Programme\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll (Wave Systems Corp.)
BootExecute: autocheck autochk * C:\PROGRA~1\AVG\AVG2014\avgrsx.exe /sync /restart
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-1275210071-162531612-1801674531-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Programme\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\Marie-Sophie\Anwendungsdaten\Mozilla\Firefox\Profiles\vidkqbpe.default
FF DefaultSearchEngine: Google
FF Homepage: about:home
FF Keyword.URL:
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=10.55.2 -> C:\Programme\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 -> C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/McAfeeMssPlugin -> C:\Programme\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @protectdisc.com/NPMPDRM -> C:\Programme\Gemeinsame Dateien\mpDRM\NPMPDRM.dll ( )
FF Plugin: Adobe Reader -> C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Skype Click to Call - C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-11-16]
FF Extension: Java Console - C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-11-16]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-11-28]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ASFIPmon; C:\Programme\Broadcom\ASFIPMon\AsfIpMon.exe [79432 2006-12-19] (Broadcom Corporation)
S2 avgfws; C:\Programme\AVG\AVG2014\avgfws.exe [1358944 2013-09-25] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Programme\AVG\AVG2014\avgidsagent.exe [3538480 2013-10-03] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Programme\AVG\AVG2014\avgwdsvc.exe [301152 2013-09-25] (AVG Technologies CZ, s.r.o.)
R2 EvtEng; C:\Programme\Intel\WiFi\bin\EvtEng.exe [874768 2009-11-03] (Intel(R) Corporation)
R2 JavaQuickStarterService; C:\Programme\Java\jre7\bin\jqs.exe [182696 2014-05-06] (Oracle Corporation)
R2 MBAMScheduler; C:\Programme\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Programme\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [114288 2014-11-16] (Mozilla Foundation)
R2 MsMpSvc; c:\Programme\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation)
R2 NICCONFIGSVC; C:\Programme\Dell\QuickSet\NICCONFIGSVC.exe [475136 2008-02-22] (Dell Inc.) [File not signed]
R2 NWCWorkstation; C:\WINDOWS\System32\nwwks.dll [65536 2008-04-14] (Microsoft Corporation)
R2 NwSapAgent; C:\WINDOWS\System32\ipxsap.dll [66560 2008-04-14] (Microsoft Corporation)
R2 RegSrvc; C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe [473360 2009-11-03] (Intel(R) Corporation)
R2 S24EventMonitor; C:\Programme\Intel\WiFi\bin\S24EvMon.exe [909312 2009-11-03] (Intel(R) Corporation) [File not signed]
S3 SecureStorageService; C:\Programme\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe [638976 2008-12-12] (Wave Systems Corp.) [File not signed]
R2 Skype C2C Service; C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.)
R2 STacSV; C:\Programme\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\StacSV.exe [94208 2007-05-10] (SigmaTel, Inc.)
S2 tcsd_win32.exe; C:\Programme\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1273856 2008-11-12] () [File not signed]
R2 TdmService; C:\Programme\Wave Systems Corp\Trusted Drive Manager\TdmService.exe [991232 2009-02-18] (Wave Systems Corp.) [File not signed]
R2 UMVPFSrv; C:\Programme\Gemeinsame Dateien\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
R2 WLANKEEPER; C:\Programme\Intel\WiFi\bin\WLKeeper.exe [348160 2009-11-03] (Intel(R) Corporation) [File not signed]
S2 TuneUp.UtilitiesSvc; "C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 acedrv11; C:\WINDOWS\system32\drivers\acedrv11.sys [185472 2010-02-24] (Protect Software GmbH)
R1 APPDRV; C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS [16128 2005-08-12] (Dell Inc) [File not signed]
R2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [278984 2012-03-27] ()
R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [120632 2013-09-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdriverx.sys [209208 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [145720 2013-09-02] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\WINDOWS\System32\DRIVERS\avgidsshimx.sys [22840 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [176952 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [223032 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [102200 2013-08-20] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [27448 2013-09-08] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\WINDOWS\System32\DRIVERS\avgtdix.sys [193848 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [42784 2014-08-26] (AVG Technologies)
R2 BASFND; C:\Programme\Broadcom\ASFIPMon\BASFND.sys [10480 2006-12-19] (Broadcom Corporation) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 CSRBC; C:\WINDOWS\System32\Drivers\csrbcxp.sys [31744 2007-01-16] (CSR, plc) [File not signed]
S3 FTDIBUS; C:\WINDOWS\System32\drivers\ftdibus.sys [61704 2011-03-18] (FTDI Ltd.)
R3 guardian2; C:\WINDOWS\System32\Drivers\oz776.sys [68696 2007-12-23] (O2Micro)
R3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [211200 2007-08-02] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [989952 2007-08-02] (Conexant Systems, Inc.)
R2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [25416 2012-03-27] ()
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [114904 2015-02-09] (Malwarebytes Corporation)
R0 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 NETw5x32; C:\WINDOWS\System32\DRIVERS\NETw5x32.sys [4221952 2009-10-26] (Intel Corporation)
R2 NwlnkIpx; C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-14] (Microsoft Corporation)
R2 NwlnkNb; C:\WINDOWS\System32\DRIVERS\nwlnknb.sys [63232 2008-04-14] (Microsoft Corporation)
R2 NwlnkSpx; C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys [55936 2008-04-14] (Microsoft Corporation)
R3 NWRDR; C:\WINDOWS\System32\DRIVERS\nwrdr.sys [163584 2008-04-14] (Microsoft Corporation)
R0 PBADRV; C:\WINDOWS\System32\DRIVERS\PBADRV.sys [26608 2009-03-06] (Dell Inc)
R2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [11904 2008-08-13] (Intel Corporation)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1222840 2007-05-10] (SigmaTel, Inc.)
R2 WavxDMgr; C:\WINDOWS\System32\DRIVERS\WavxDMgr.sys [208824 2009-03-06] (Wave Systems Corp.)
S1 aklzcwsr; \??\C:\WINDOWS\system32\drivers\aklzcwsr.sys [X]
S3 Avgfwfd; system32\DRIVERS\avgfwdx.sys [X]
S0 cerc6; No ImagePath
S1 icbxejmq; \??\C:\WINDOWS\system32\drivers\icbxejmq.sys [X]
S4 IntelIde; No ImagePath
S3 TuneUpUtilitiesDrv; \??\C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [X]
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-09 19:20 - 2015-02-09 19:20 - 00001648 _____ () C:\mbam.txt
2015-02-09 19:19 - 2015-02-09 19:19 - 00001648 _____ () C:\Dokumente und Einstellungen\Marie-Sophie\Desktop\mbam.txt
2015-02-09 17:06 - 2015-02-09 17:06 - 00000000 ____D () C:\Programme\ESET
2015-02-08 13:36 - 2015-02-08 13:36 - 00000588 _____ () C:\Dokumente und Einstellungen\Marie-Sophie\Desktop\JRT.txt
2015-02-08 13:02 - 2015-02-09 15:14 - 00000000 _____ () C:\Dokumente und Einstellungen\Marie-Sophie\Lokale Einstellungen\Anwendungsdaten\WavXMapDrive.bat
2015-02-08 13:02 - 2015-02-08 13:02 - 00000000 ____D () C:\Dokumente und Einstellungen\Marie-Sophie\Anwendungsdaten\Dell
2015-02-08 12:52 - 2015-02-08 13:00 - 00000000 ____D () C:\AdwCleaner
2015-02-08 12:32 - 2015-02-08 12:32 - 00000889 _____ () C:\Dokumente und Einstellungen\Marie-Sophie\Desktop\Revo Uninstaller.lnk
2015-02-08 12:32 - 2015-02-08 12:32 - 00000000 ____D () C:\Programme\VS Revo Group
2015-02-07 17:59 - 2015-02-09 19:52 - 00000000 ____D () C:\FRST
2015-02-05 21:52 - 2015-02-05 21:52 - 00000000 ____D () C:\Avenger
2015-02-05 20:35 - 2015-02-09 17:45 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-02-05 20:34 - 2015-02-09 15:26 - 00000749 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-05 20:34 - 2015-02-09 15:26 - 00000000 ____D () C:\Programme\Malwarebytes Anti-Malware
2015-02-05 20:34 - 2015-02-05 20:34 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes Anti-Malware
2015-02-05 20:34 - 2015-02-05 20:34 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
2015-02-05 20:34 - 2014-11-21 06:14 - 00054360 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-02-05 20:34 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-09 19:52 - 2011-11-29 15:21 - 00000000 ____D () C:\Dokumente und Einstellungen\Marie-Sophie\Lokale Einstellungen\Temp
2015-02-09 19:46 - 2013-03-25 12:03 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-02-09 18:47 - 2011-10-31 23:17 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MFAData
2015-02-09 18:02 - 2014-11-16 15:46 - 00000000 ____D () C:\Programme\Mozilla Firefox
2015-02-09 17:06 - 2011-10-30 14:04 - 00000000 ___RD () C:\Programme
2015-02-09 15:26 - 2011-10-30 13:13 - 01712225 _____ () C:\WINDOWS\WindowsUpdate.log
2015-02-09 15:25 - 2011-10-30 13:17 - 00000000 ____D () C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Temp
2015-02-09 15:23 - 2014-05-06 23:53 - 00000386 ____H () C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2015-02-09 15:16 - 2014-10-20 20:02 - 00000000 ____D () C:\Dokumente und Einstellungen\Marie-Sophie\Anwendungsdaten\Spotify
2015-02-09 15:15 - 2011-10-31 00:07 - 00032536 _____ () C:\WINDOWS\system32\nvModes.001
2015-02-09 15:15 - 2008-04-14 00:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2015-02-09 15:14 - 2011-10-31 00:06 - 00201679 _____ () C:\WINDOWS\system32\nvapps.xml
2015-02-09 15:14 - 2011-10-30 14:07 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-02-09 15:14 - 2011-10-30 14:07 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2015-02-09 15:13 - 2014-05-06 23:43 - 00000224 _____ () C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Benachrichtigung – Anmeldung.job
2015-02-09 15:13 - 2011-10-30 13:18 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-02-09 15:12 - 2011-11-29 15:21 - 00000190 ___SH () C:\Dokumente und Einstellungen\Marie-Sophie\ntuser.ini
2015-02-09 15:12 - 2011-11-29 15:21 - 00000000 ____D () C:\Dokumente und Einstellungen\Marie-Sophie
2015-02-09 15:12 - 2011-10-30 13:18 - 00031938 _____ () C:\WINDOWS\SchedLgU.Txt
2015-02-09 15:11 - 2011-12-01 21:38 - 00000000 ____D () C:\Dokumente und Einstellungen\Rainer - User\Lokale Einstellungen\Temp
2015-02-09 15:10 - 2011-10-30 13:19 - 00000000 ____D () C:\Dokumente und Einstellungen\Rainer\Lokale Einstellungen\Temp
2015-02-09 15:07 - 2011-12-01 15:22 - 00000000 ____D () C:\Dokumente und Einstellungen\Felix\Lokale Einstellungen\Temp
2015-02-09 15:03 - 2011-11-28 16:08 - 00000000 ____D () C:\Dokumente und Einstellungen\Conny\Lokale Einstellungen\Temp
2015-02-09 14:59 - 2013-06-27 15:59 - 00120364 _____ () C:\WINDOWS\setupapi.log
2015-02-08 13:00 - 2011-11-29 15:23 - 00000749 _____ () C:\Dokumente und Einstellungen\Marie-Sophie\Startmenü\Programme\Internet Explorer.lnk
2015-02-08 13:00 - 2011-11-29 15:21 - 00000000 ___RD () C:\Dokumente und Einstellungen\Marie-Sophie\Startmenü\Programme
2015-02-08 13:00 - 2011-10-31 23:30 - 00131072 _____ () C:\WINDOWS\system32\config\TuneUp.evt
2015-02-08 13:00 - 2011-10-31 22:36 - 00000702 _____ () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Mozilla Firefox.lnk
2015-02-08 13:00 - 2011-10-31 22:36 - 00000696 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
2015-02-08 13:00 - 2011-10-30 14:04 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme
2015-02-07 17:49 - 2013-03-25 12:03 - 00701616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-02-07 17:49 - 2011-11-27 22:25 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-02-06 14:19 - 2011-10-31 00:07 - 00032536 _____ () C:\WINDOWS\system32\nvModes.dat
2015-02-05 21:52 - 2014-01-24 16:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2898715$
2015-02-05 20:12 - 2013-11-11 19:16 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-02-05 20:03 - 2011-11-27 14:20 - 110348472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-02-05 19:24 - 2014-10-20 20:04 - 00000000 ____D () C:\Dokumente und Einstellungen\Marie-Sophie\Lokale Einstellungen\Anwendungsdaten\Spotify
==================== Files in the root of some directories =======
2013-06-27 15:36 - 2014-05-09 17:05 - 0003728 _____ () C:\Programme\Mozilla Firefoxavg-secure-search.xml
2012-01-15 11:00 - 2014-12-08 20:35 - 0007168 _____ () C:\Dokumente und Einstellungen\Marie-Sophie\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-02-08 13:02 - 2015-02-09 15:14 - 0000000 _____ () C:\Dokumente und Einstellungen\Marie-Sophie\Lokale Einstellungen\Anwendungsdaten\WavXMapDrive.bat
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================ --- --- ---
--- --- ---
ich weis nicht, ob wir jetzt fertig sind odere ob alles stimmt, aber ich bedanke micht trotzdem noch mal :) |