entschuldige, ich dachte das wäre eine Reklame
Code:
Additional scan result of Farbar
1. FRST Addition:
Recovery Scan Tool (x64) Version: 11-03-2015
Ran by Holger Carlson at 2015-04-08 15:05:37
Running from F:\
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Absolute Uninstaller 5.3.1.20 (HKLM-x32\...\Absolute Uninstaller) (Version: 5.3.1.20 - Glarysoft Ltd)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 17.0.0.124 - Adobe Systems Incorporated)
Adobe Digital Editions 4.0 (HKLM-x32\...\Adobe Digital Editions 4.0) (Version: 4.0.3 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Alle meine Adressen 1.20 (HKLM-x32\...\AllemeineAdressen) (Version: - )
Amazon Kindle (HKU\S-1-5-21-171592873-1656066399-1947005370-1000\...\Amazon Kindle) (Version: - Amazon)
Anti-Twin (Installation 14.02.2015) (HKLM-x32\...\Anti-Twin 2015-02-14 11.26.34) (Version: - Joerg Rosenthal, Germany)
ASUS FancyStart (HKLM-x32\...\{2B81872B-A054-48DA-BE3B-FA5C164C303A}) (Version: - )
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2215 - AVAST Software)
AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.1.0.411 - AVG Technologies)
Avira (HKLM-x32\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG)
Avira (x32 Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden
Buchliebhaber 9.1.0 (HKLM-x32\...\Buchliebhaber_is1) (Version: - Matthies & Klock GmbH)
Glary Utilities 5.22 (HKLM-x32\...\Glary Utilities 5) (Version: 5.22.0.41 - Glarysoft Ltd)
GMX MediaCenter 1.5.2192.0 (HKU\S-1-5-21-171592873-1656066399-1947005370-1000\...\GMX Application {sync-000021}) (Version: 1.5.2192.0 - 1&1 Mail & Media GmbH)
GMX Softwareaktualisierung CE (HKU\S-1-5-21-171592873-1656066399-1947005370-1000\...\1&1 Mail & Media GmbH 1und1Softwareaktualisierung) (Version: 3.0.1.0 - 1&1 Mail & Media GmbH)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
MD Adressbuch 2012 (HKLM-x32\...\MD Adressbuch 2012_is1) (Version: - Stefan Göppert Softwareentwicklung)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
MyDriveConnect 3.3.0.1756 (HKLM-x32\...\MyDriveConnect) (Version: 3.3.0.1756 - TomTom)
MyFreeCodec (HKU\S-1-5-21-171592873-1656066399-1947005370-1000\...\MyFreeCodec) (Version: - )
paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC)
Pixum Fotobuch (HKLM-x32\...\Pixum Fotobuch) (Version: 5.1.7 - CEWE Stiftung u Co. KGaA)
SAMSUNG Mobile Composite Device Software (HKLM\...\SAMSUNG Mobile Composite Device) (Version: - )
Samsung Mobile Modem Device Software (HKLM\...\Samsung Mobile Modem Device) (Version: - )
SAMSUNG Mobile Modem Driver Set (HKLM\...\SAMSUNG Mobile Modem) (Version: - )
Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version: - )
SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version: - )
SAMSUNG Mobile USB Modem Software (HKLM\...\SAMSUNG Mobile USB Modem) (Version: - )
SAMSUNG USB Mobile Device Software (HKLM\...\SAMSUNG USB Mobile Device) (Version: - )
TomTom HOME (HKLM-x32\...\{BB05590A-6602-43F3-A400-77EA0976BC0A}) (Version: 2.9.8 - Ihr Firmenname)
TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: - )
Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation)
WinZip Driver Updater (HKLM-x32\...\{9854A5C4-5BE5-46E2-A989-352DD8B37E20}_is1) (Version: 1.0.648.16298 - WinZip Computing, S.L. (WinZip Computing))
Wondershare Video Editor(Build 4.8.0) (HKLM-x32\...\Wondershare Video Editor_is1) (Version: - Wondershare Software)
XnView 2.25 (HKLM-x32\...\XnView_is1) (Version: 2.25 - Gougelet Pierre-e)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
08-04-2015 00:11:59 Wiederherstellungsvorgang
08-04-2015 10:17:37 Die Service Pack-Sicherungsdateien wurden entfernt.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2014-12-04 14:19 - 00000860 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {08B758AF-1A52-432B-8127-90EC4AA3A965} - System32\Tasks\{F2C2A228-7128-4269-BFD6-1BA7B353163D} => C:\Program Files (x86)\Matthies & Klock GmbH\Buchliebhaber\PR9\pdxrwn32.exe
Task: {098E8135-34F9-4A64-934D-CB129E5D2CDC} - \Google Updater and Installer No Task File <==== ATTENTION
Task: {0CE00D12-17CE-4495-BF65-180B9826F70C} - \{61A08136-196D-4297-89AD-D497D9417337} No Task File <==== ATTENTION
Task: {0D02835E-8E5B-471D-B8DD-C212A01D96EC} - \{D04405DF-9CCA-470D-B397-4843D8B97AF0} No Task File <==== ATTENTION
Task: {0D85BDAC-E5C7-468D-B749-BB89C6043C0C} - \{5287E865-8199-49E9-9791-D1D1C8255AD2} No Task File <==== ATTENTION
Task: {11951C30-7772-4873-A9C8-E7D79EC20876} - \{D8737E18-1D23-477D-AAC7-5336054949A5} No Task File <==== ATTENTION
Task: {13F363A7-DAF8-481E-B4FE-FE9B141B5AA3} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: {25201061-4215-47D1-9AD4-34EA219B3820} - System32\Tasks\{7BE02FCA-D2BD-4C97-AEEF-BEAB652E047F} => pcalua.exe -a E:\setup.exe -d E:\
Task: {28C6FF84-FF3C-482A-9DE2-C1E1A727942B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-06] (Adobe Systems Incorporated)
Task: {290FA810-6486-498B-959B-EF77EE05DD0F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-27] (Google Inc.)
Task: {2B0BE8B0-825F-4CBB-8C4D-91671BCB9A6A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {2FC8335C-FA90-4CEE-A686-C6B49483A403} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {3210E7F8-FB59-421F-B199-67709A46C787} - \{A6277D21-0A69-4926-8537-03083BD82DC4} No Task File <==== ATTENTION
Task: {334ED6C7-1F98-49AE-8A05-3E3B9A21315B} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {358F7EC5-6965-40B1-864E-007E2DF9341F} - System32\Tasks\{A2F92AC1-AFA1-4E86-8E4F-4320AF8CAFC8} => C:\Buchliebhaber\PR9\pdxrwn32.exe [2000-03-13] (Corel Corporation)
Task: {38A8F2A8-F514-4C70-A1BB-A5D46267F1FB} - \{F46C64DF-4E00-4451-B8AB-B1BD2B03A5D6} No Task File <==== ATTENTION
Task: {38ADF97D-C025-44B4-8A28-255AF09F87BD} - \{9623FEA8-9F14-41C1-B13F-5E2F1DDF2973} No Task File <==== ATTENTION
Task: {38F64A5C-9D9B-402B-A2B5-B669F928CBC9} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [2015-03-30] (Glarysoft Ltd)
Task: {3B3ABEC6-C5C7-4317-98AA-0E6A0A2CCF4B} - \{9DB39282-3B31-400F-9105-DE5FB32A8625} No Task File <==== ATTENTION
Task: {3D5A7F1A-A836-46DC-9849-9F87B83A84A3} - System32\Tasks\ASPG => C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS)
Task: {3DFA3AE3-36A5-43EE-86FD-5CFEE82FD09E} - \{010EC50E-DEBC-4DDF-818F-D8FD586C6441} No Task File <==== ATTENTION
Task: {40210CAF-8AA2-4DD1-BDF5-BB204B73FB6C} - System32\Tasks\{42DB7226-BD17-443B-9B46-0B981C090BEB} => C:\Buchliebhaber\PR9\pdxrwn32.exe [2000-03-13] (Corel Corporation)
Task: {413B067F-3B28-4DF2-8F92-254BE963B97C} - System32\Tasks\{379D7A1C-5990-4F7B-8D7F-93DBB093395D} => C:\Buchliebhaber\PR9\pdxrwn32.exe [2000-03-13] (Corel Corporation)
Task: {41E4A974-3CB9-486E-B66F-D3F72922F49D} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-05-28] (ATK)
Task: {442B4BA7-EBD3-4530-973F-E7CC01346952} - \{BA46EF16-D5AD-455B-A934-5EFCEB3A4388} No Task File <==== ATTENTION
Task: {44B27208-7DF9-417C-85BA-311F6EE0FE37} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS)
Task: {46897D9B-08E1-407A-86D2-588D7ABBE189} - \{BE03A807-43D0-45D8-9633-BA1E5A2BF85C} No Task File <==== ATTENTION
Task: {47F29D00-B56D-4D0B-A245-F110AC103BA3} - \{DCE86621-269D-478F-9FAC-AF30D2697486} No Task File <==== ATTENTION
Task: {4A29309C-5F1C-4521-B5A3-74342AD4D434} - System32\Tasks\avastBCLRestartS-1-5-21-171592873-1656066399-1947005370-1000 => Chrome.exe
Task: {4ABBB83F-8527-455B-839D-0E31E9921ABF} - \{414946E3-07AA-4AF3-BB0D-E22440C7BAAE} No Task File <==== ATTENTION
Task: {4DB12196-A5A6-455A-A31E-8A8F9CDA048F} - \{00D6677F-309E-4218-BCA8-4C50017C8BFD} No Task File <==== ATTENTION
Task: {4E55F6B2-D76F-46DA-85CA-851B04EA102C} - System32\Tasks\4805 => Wscript.exe C:\Users\HOLGER~1\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION
Task: {536019A5-4DF9-4D2A-AB12-D4F97B46565A} - \{3542F023-1538-411B-9E77-ACAF5E3DCF29} No Task File <==== ATTENTION
Task: {570F0731-82FB-4801-9764-13133948D30D} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {61DA3565-D65E-4727-A79B-CFF46B7C83D0} - \{515B0C8B-D302-490D-B011-1690D5CB8DA8} No Task File <==== ATTENTION
Task: {67253C4B-AA19-4D28-A2C4-ACB82A1E8FB3} - \{8715223C-93FC-489B-A4F9-497C1B06356D} No Task File <==== ATTENTION
Task: {689876BF-828C-4CAC-B3C8-96B7A34B374C} - \{E27BA60A-F9D1-4950-AADD-E4C8BB8E3AE7} No Task File <==== ATTENTION
Task: {6B054A5F-A0E3-42EF-B939-199ECAD09EEE} - \Registration 1und1 Task No Task File <==== ATTENTION
Task: {73E334A0-2C62-4488-842A-B6047FD36A67} - \{4C3D4C4C-3DD2-436D-B415-CC9B34C519DA} No Task File <==== ATTENTION
Task: {7687468C-FCB9-4157-98A5-29F118266571} - \{80C774A3-BC4E-4FEF-B262-A5578F350E85} No Task File <==== ATTENTION
Task: {7D065A65-864E-4237-909F-B37C27ECC63A} - \{A86E51F0-822F-4FC6-9962-851362E69E65} No Task File <==== ATTENTION
Task: {813A7F73-0382-4A15-BA6D-549796A8A795} - \{A3123A1E-2B47-4121-992C-63487F1CE1F3} No Task File <==== ATTENTION
Task: {8280F3EA-A247-4A48-8F40-7F948D87EB49} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {833E3160-FE17-4A2E-8B96-5ACA617F1334} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-07-31] (ASUS)
Task: {83C4C39B-F484-45E4-B677-EFBBD3E1183A} - \{7874A9A9-C312-459B-A16C-50B15C6AE000} No Task File <==== ATTENTION
Task: {8B51862B-900B-4C95-A7D5-29D974D8EE26} - \{4BA2B75B-115C-4BCA-B45A-BD110E15FEF3} No Task File <==== ATTENTION
Task: {8E7BFA22-A9BF-4269-B793-D870D24D60C2} - System32\Tasks\0215tbUpdateInfo => C:\ProgramData\Avg_Update_0215tb\0215tb_{9AC9BD6A-EC15-4AF2-B2E9-45B20221802C}.exe [2015-02-27] ()
Task: {8F72ADBE-9038-41E9-86A7-8381B850A01F} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK)
Task: {933153D3-FF7D-4F2F-93DB-4EE18AEC267A} - \{58E9C4A2-89D5-4097-9A1D-3C7212CC100A} No Task File <==== ATTENTION
Task: {95298E87-8CFD-4CCA-890F-8B7D7730CF74} - \{E2D6ACFE-B61E-4447-AE80-4B0CA9F20914} No Task File <==== ATTENTION
Task: {961A4741-EA5F-4FD4-9F58-9824862E1432} - System32\Tasks\0 => Iexplore.exe <==== ATTENTION
Task: {9AA4F3F3-6B2F-4EA6-B81B-1EA4DF38689E} - \{F99ED12E-E280-47FF-9CC7-4FA9874C09B4} No Task File <==== ATTENTION
Task: {9C67CD09-48FC-4280-A9C2-7D5BE146C9A7} - System32\Tasks\GU5SkipUAC => C:\Program Files (x86)\Glary Utilities 5\Integrator.exe [2015-03-30] (Glarysoft Ltd)
Task: {A7177D9F-E795-4EEA-9386-C0AB9B1E6555} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {AB825B6B-2DF7-408C-A17E-B405E72C327C} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] ()
Task: {ABE155A8-22A7-4F41-A3D7-35B367212640} - \{8EE0BDD3-D87C-4147-865B-EF850579BBB3} No Task File <==== ATTENTION
Task: {B35D3966-C1EC-4ABB-BAC5-D82790C11C3F} - \{E3C1408B-870F-4E8E-863D-53964BB8AC89} No Task File <==== ATTENTION
Task: {B39D560A-BEBE-44B2-BB96-2FB0031EFCB1} - System32\Tasks\{5F6DAA4F-722D-4B6E-9C1D-E206E1B3507A} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{F193FC0E-9E18-40FC-A974-509A1BDD240A}\setup.exe" -c -runfromtemp -l0x0407 -removeonly
Task: {B3AA75D5-DCF3-4574-8832-4A1FD12772EC} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-04-06] (Avast Software s.r.o.)
Task: {B3C1DDB0-DE41-4A0A-BF91-DBEDCF91283A} - \{579791C6-84C4-4514-8990-62DE88C0F405} No Task File <==== ATTENTION
Task: {B4381734-38BC-4416-BA34-AD5B873F9C57} - \Java Update Scheduler No Task File <==== ATTENTION
Task: {B4906D30-8E70-438F-ACE2-F49B1DBE7445} - \{94AA3650-9FB1-4CD9-A08A-C903E473EBCE} No Task File <==== ATTENTION
Task: {B967227B-B6FD-4E2D-8835-423AB6A11D89} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-27] (Google Inc.)
Task: {BE3C31CF-63BD-4BBF-B1EC-7B0AD8E1475C} - \{766A2B2A-5AE1-40C4-B5D1-3ACEE3EDB174} No Task File <==== ATTENTION
Task: {BF27F29A-158B-4BB3-8BCE-76285F22E1E8} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe
Task: {C070E538-D27F-40CE-A149-1F519DE498C9} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {C9922EB1-0689-4006-9DE5-EC7322657A2E} - \{3A7AA56D-B373-4984-B360-5A49D81838B3} No Task File <==== ATTENTION
Task: {D10B95EB-9C87-4E4B-B2A9-7995BACE3748} - System32\Tasks\ASUSControlDeck => C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe [2010-06-09] (asus)
Task: {D3A8949A-66C0-404E-A951-6D81347CC413} - \{5F42D548-089A-4880-B17A-030133EB09AE} No Task File <==== ATTENTION
Task: {D3DCDC2E-0597-4E10-B9B2-DA8A9D0B8184} - \{C8855EFF-1C49-474C-8EC9-A88A46937291} No Task File <==== ATTENTION
Task: {D79B06A8-69BD-44AF-A4F9-51F90B02F5F9} - \{010E4118-67B1-49F2-B0A9-AEBEB8C22ED8} No Task File <==== ATTENTION
Task: {D804B95C-2E56-41A3-BA15-CBFF3F453270} - \{D1412BBD-3329-445E-BAAC-11DAA3F957DE} No Task File <==== ATTENTION
Task: {D97583DC-E996-4394-9850-866EE5071AA3} - \{54761E2D-0F8D-4150-9BAF-A6C950ABC57C} No Task File <==== ATTENTION
Task: {DCCEAEA3-B771-45EF-B482-A5AF7C257613} - \{F268C70D-1377-46B5-B8EF-B0F597A319DD} No Task File <==== ATTENTION
Task: {DD20FA04-E2E5-4565-BC1F-EF251B8CF767} - \{017BCEFC-6CC0-4438-9C8C-8201389B3A60} No Task File <==== ATTENTION
Task: {DF172056-6ED6-443A-A038-9148CCA273FB} - System32\Tasks\{31DF2CAA-6FE5-4163-BE60-BDF22507129E} => pcalua.exe -a E:\setup.exe -d E:\
Task: {E4FADBEF-BD70-4875-9F9E-1F514FAE9ACE} - \{428451EA-30BB-4D09-B88F-21C45644BDDD} No Task File <==== ATTENTION
Task: {EBAEA87A-60D8-457D-B7BE-FDDEE0C029B6} - \{E72F77B1-78E7-4B59-A542-303E6C370E31} No Task File <==== ATTENTION
Task: {EBC17C4A-B399-454D-880A-2B7927689200} - System32\Tasks\{B499114B-BC27-40FC-98B1-F18D60669500} => pcalua.exe -a C:\ProgramData\ZombieInvasion\uninstall.exe -c /kb=y /ic=1
Task: {EBDB75AC-DD2E-4374-8CA6-CA615964EFDF} - System32\Tasks\{F24AA02C-94D0-40B1-9DB0-D88D09B26BA3} => C:\Program Files (x86)\Matthies & Klock GmbH\Buchliebhaber\PR9\pdxrwn32.exe
Task: {F088DE68-E8E0-404D-A03F-71D270529CAA} - \{C9155B3B-9625-4BCA-8DC8-57E7BE8F3A16} No Task File <==== ATTENTION
Task: {F291C6EE-C628-4432-9AA6-72AB2B105BB0} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: {F2C3A777-E8AA-4F3A-BAFD-9404E1BEA2BA} - \SidebarExecute No Task File <==== ATTENTION
Task: {FCC576CF-4869-4F53-B945-CC818F71D6F7} - \{A56BDF5A-F4F1-4A50-8871-D8B38E0FE432} No Task File <==== ATTENTION
Task: C:\Windows\Tasks\0215tbUpdateInfo.job => C:\ProgramData\Avg_Update_0215tb\0215tb_{9AC9BD6A-EC15-4AF2-B2E9-45B20221802C}.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GlaryInitialize 5.job => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2015-03-23 11:39 - 2015-03-23 11:39 - 00620056 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
2010-03-05 18:21 - 2010-03-05 18:21 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2007-06-15 19:28 - 2007-06-15 19:28 - 00104960 _____ () C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt64.dll
2007-06-02 01:52 - 2007-06-02 01:52 - 00159744 _____ () C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
2010-01-11 19:27 - 2010-01-11 19:27 - 00017920 _____ () C:\Program Files\P4G\DevMng.dll
2010-05-06 03:22 - 2010-05-06 03:22 - 00108544 _____ () C:\Program Files\P4G\OvrClk.dll
2008-10-01 08:02 - 2008-10-01 08:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2010-10-08 21:01 - 2007-11-30 20:20 - 00051768 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
2010-10-08 20:22 - 2010-04-06 08:29 - 00244904 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2015-04-06 17:55 - 2015-04-06 17:55 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-04-06 17:55 - 2015-04-06 17:55 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-04-07 23:05 - 2015-04-07 23:05 - 02924544 _____ () C:\Program Files\AVAST Software\Avast\defs\15040701\algo.dll
2015-04-08 14:54 - 2015-04-08 14:54 - 02925056 _____ () C:\Program Files\AVAST Software\Avast\defs\15040801\algo.dll
2015-04-06 17:55 - 2015-04-06 17:55 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-03-30 08:07 - 2015-03-30 08:07 - 00080160 _____ () C:\Program Files (x86)\Glary Utilities 5\zlib1.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:AD022376
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
HKU\S-1-5-21-171592873-1656066399-1947005370-1000\Software\Classes\exefile: <===== ATTENTION!
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-171592873-1656066399-1947005370-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Holger Carlson\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.2.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: ADSMTray => C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: RemoteControl9 => "C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe"
MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
==================== Accounts: =============================
Administrator (S-1-5-21-171592873-1656066399-1947005370-500 - Administrator - Disabled)
Gast (S-1-5-21-171592873-1656066399-1947005370-501 - Limited - Disabled)
Holger Carlson (S-1-5-21-171592873-1656066399-1947005370-1000 - Administrator - Enabled) => C:\Users\Holger Carlson
HomeGroupUser$ (S-1-5-21-171592873-1656066399-1947005370-1002 - Limited - Enabled)
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (04/08/2015 10:17:37 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {838dcb48-10f2-4035-8955-78846a8e7807}
Error: (04/08/2015 09:50:44 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm iexplore.exe, Version 11.0.9600.17689 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 230
Startzeit: 01d071cc5aec4b5f
Endzeit: 390
Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe
Berichts-ID: ef1bd15d-ddc3-11e4-8f0d-20cf30cfa402
Error: (04/08/2015 00:28:45 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm iexplore.exe, Version 11.0.9600.17689 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 730
Startzeit: 01d0718193adbd30
Endzeit: 0
Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe
Berichts-ID: 6645c20b-dd75-11e4-be47-20cf30cfa402
Error: (04/08/2015 00:17:27 AM) (Source: System Restore) (EventID: 8210) (User: )
Description: Unbekannter Fehler bei der Systemwiederherstellung: (Windows-Sicherung). Zusätzliche Informationen: 0x80070005.
Error: (04/07/2015 11:53:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm iexplore.exe, Version 11.0.9600.17689 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 194
Startzeit: 01d0717cecf34e3b
Endzeit: 78
Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe
Berichts-ID: 78fbce4e-dd70-11e4-ba94-20cf30cfa402
Error: (04/07/2015 11:50:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm iexplore.exe, Version 11.0.9600.17689 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1364
Startzeit: 01d0717aa5f796e2
Endzeit: 0
Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe
Berichts-ID:
Error: (04/07/2015 11:48:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 11.0.9600.17689, Zeitstempel: 0x54e6869b
Name des fehlerhaften Moduls: aswWebRepIE64.dll, Version: 10.0.0.44, Zeitstempel: 0x5501a3ca
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000116a3
ID des fehlerhaften Prozesses: 0x14f4
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3
Error: (04/07/2015 11:47:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 11.0.9600.17689, Zeitstempel: 0x54e6869b
Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7c92c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000019868
ID des fehlerhaften Prozesses: 0xc08
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3
Error: (04/07/2015 11:34:28 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm iexplore.exe, Version 11.0.9600.17689 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: b94
Startzeit: 01d0717a6ba74781
Endzeit: 16
Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe
Berichts-ID: d76c519b-dd6d-11e4-ba94-20cf30cfa402
Error: (04/07/2015 11:32:59 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm iexplore.exe, Version 11.0.9600.17689 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 28c
Startzeit: 01d0717824c2c90c
Endzeit: 0
Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe
Berichts-ID:
System errors:
=============
Error: (04/08/2015 02:53:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "sbapifs" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/08/2015 09:09:43 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "sbapifs" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/08/2015 00:16:02 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "sbapifs" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/08/2015 00:13:50 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.
Modulpfad: C:\Windows\System32\IWMSSvc.dll
Error: (04/07/2015 11:15:19 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "sbapifs" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/07/2015 08:12:10 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
Error: (04/07/2015 07:13:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "sbapifs" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/07/2015 00:46:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "sbapifs" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/07/2015 00:45:27 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.
Modulpfad: C:\Windows\System32\IWMSSvc.dll
Error: (04/07/2015 00:45:27 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.
Modulpfad: C:\Windows\System32\IWMSSvc.dll
Microsoft Office Sessions:
=========================
Error: (04/08/2015 10:17:37 AM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {838dcb48-10f2-4035-8955-78846a8e7807}
Error: (04/08/2015 09:50:44 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe11.0.9600.1768923001d071cc5aec4b5f390C:\Program Files\Internet Explorer\iexplore.exeef1bd15d-ddc3-11e4-8f0d-20cf30cfa402
Error: (04/08/2015 00:28:45 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe11.0.9600.1768973001d0718193adbd300C:\Program Files\Internet Explorer\iexplore.exe6645c20b-dd75-11e4-be47-20cf30cfa402
Error: (04/08/2015 00:17:27 AM) (Source: System Restore) (EventID: 8210) (User: )
Description: Windows-Sicherung0x80070005
Error: (04/07/2015 11:53:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe11.0.9600.1768919401d0717cecf34e3b78C:\Program Files\Internet Explorer\iexplore.exe78fbce4e-dd70-11e4-ba94-20cf30cfa402
Error: (04/07/2015 11:50:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe11.0.9600.17689136401d0717aa5f796e20C:\Program Files\Internet Explorer\iexplore.exe
Error: (04/07/2015 11:48:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.1768954e6869baswWebRepIE64.dll10.0.0.445501a3cac000000500000000000116a314f401d0717c85862374C:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\AVAST Software\Avast\aswWebRepIE64.dlld836be9e-dd6f-11e4-ba94-20cf30cfa402
Error: (04/07/2015 11:47:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.1768954e6869bole32.dll6.1.7601.175144ce7c92cc00000050000000000019868c0801d0717c4fd15be8C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\ole32.dllacd6a0e2-dd6f-11e4-ba94-20cf30cfa402
Error: (04/07/2015 11:34:28 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe11.0.9600.17689b9401d0717a6ba7478116C:\Program Files\Internet Explorer\iexplore.exed76c519b-dd6d-11e4-ba94-20cf30cfa402
Error: (04/07/2015 11:32:59 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe11.0.9600.1768928c01d0717824c2c90c0C:\Program Files\Internet Explorer\iexplore.exe
CodeIntegrity Errors:
===================================
Date: 2015-02-10 19:35:28.928
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\emOEM64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2015-02-10 19:35:28.536
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\emOEM64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-12-29 18:03:12.533
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\HOLGER~1\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-12-29 18:03:12.393
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\HOLGER~1\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-12-29 18:03:11.993
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-12-29 18:03:11.843
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) CPU P6100 @ 2.00GHz
Percentage of memory in use: 48%
Total physical RAM: 2924.57 MB
Available physical RAM: 1492.74 MB
Total Pagefile: 6147.32 MB
Available Pagefile: 4319.39 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:72.69 GB) (Free:5.35 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Data) (Fixed) (Total:205.87 GB) (Free:23.08 GB) NTFS
Drive f: (VIEDO) (Removable) (Total:14.7 GB) (Free:14.7 GB) FAT32
Drive s: (EX SPEICHER) (Removable) (Total:7.51 GB) (Free:4.24 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 0237A506)
Partition 1: (Not Active) - (Size=19.5 GB) - (Type=1C)
Partition 2: (Active) - (Size=72.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=205.9 GB) - (Type=OF Extended)
========================================================
Disk: 1 (Size: 7.5 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
========================================================
Disk: 2 (Size: 14.7 GB) (Disk ID: 6E652072)
No partition Table on disk 2.
==================== End Of Log ============================
2. Quarantäne aus ADWCleaner:
C:\ProgramData\AVG Secure Search\Logger\logger.properties->C:\AdwCleaner\Quarantine\C\ProgramData\AVG Secure Search\Logger\logger.properties.vir
C:\ProgramData\AVG Security Toolbar\TBCampaignINSP.txt->C:\AdwCleaner\Quarantine\C\ProgramData\AVG Security Toolbar\TBCampaignINSP.txt.vir
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe->C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir
C:\ProgramData\WindowsMangerProtect\update\conf->C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\update\conf.vir
C:\ProgramData\IHProtectUpDate\update\conf->C:\AdwCleaner\Quarantine\C\ProgramData\IHProtectUpDate\update\conf.vir
C:\ProgramData\e6ad6c22000030b3\BITE952.tmp->C:\AdwCleaner\Quarantine\C\ProgramData\e6ad6c22000030b3\BITE952.tmp.vir
C:\Program Files (x86)\XTab\BrowerWatchFF.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchFF.dll.vir
C:\Program Files (x86)\XTab\BrowserAction.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowserAction.dll.vir
C:\Program Files (x86)\XTab\CmdShell.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\CmdShell.exe.vir
C:\Program Files (x86)\XTab\conf->C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\conf.vir
C:\Program Files (x86)\XTab\HPNotify.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\HPNotify.exe.vir
C:\Program Files (x86)\XTab\IeWatchDog.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\IeWatchDog.dll.vir
C:\Program Files (x86)\XTab\msvcp110.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\msvcp110.dll.vir
C:\Program Files (x86)\XTab\msvcr110.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\msvcr110.dll.vir
C:\Program Files (x86)\XTab\ProtectService.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\ProtectService.exe.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\InstalledProducts.ini->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\InstalledProducts.ini.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\log4cplusU.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\log4cplusU.dll.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\loggingserver.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\loggingserver.exe.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\ToolbarUpdater.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\ToolbarUpdater.exe.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\updater.xml->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\updater.xml.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\UpdaterConfig.ini->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\UpdaterConfig.ini.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.3.0\log4cplusU.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.3.0\log4cplusU.dll.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.3.0\loggingserver.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.3.0\loggingserver.exe.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.3.0\ToolbarUpdater.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.3.0\ToolbarUpdater.exe.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.3.0\updater.xml->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.3.0\updater.xml.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.3.0\UpdaterConfig.ini->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.3.0\UpdaterConfig.ini.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.3.0\ViProtocol.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.3.0\ViProtocol.dll.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\ToolBandTlb\18.3.0\toolband->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\ToolBandTlb\18.3.0\toolband.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.4.0\avgtbr.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.4.0\avgtbr.dll.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.4.0\manifest.json->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.4.0\manifest.json.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.4.0\ScriptHelper.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.4.0\ScriptHelper.exe.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.3.0\manifest.json->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.3.0\manifest.json.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.3.0\ScriptHelper.exe->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.3.0\ScriptHelper.exe.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\NativeBrowserApi\18.4.0\NativeBrowserApi.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\NativeBrowserApi\18.4.0\NativeBrowserApi.dll.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\NativeBrowserApi\18.3.0\NativeBrowserApi.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\NativeBrowserApi\18.3.0\NativeBrowserApi.dll.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\18.4.0\avgdttbx.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\18.4.0\avgdttbx.dll.vir
C:\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\18.3.0\avgdttbx.dll->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\18.3.0\avgdttbx.dll.vir
C:\Users\Holger Carlson\Documents\Optimizer Pro\CookiesException.txt->C:\AdwCleaner\Quarantine\C\Users\Holger Carlson\Documents\Optimizer Pro\CookiesException.txt.vir
C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb->C:\AdwCleaner\Quarantine\C\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb.vir
C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml->C:\AdwCleaner\Quarantine\C\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml.vir
C:\Users\Holger Carlson\AppData\Roaming\Mozilla\Firefox\Profiles\ekdrwrk5.default\user.js->C:\AdwCleaner\Quarantine\C\Users\Holger Carlson\AppData\Roaming\Mozilla\Firefox\Profiles\ekdrwrk5.default\user.js.vir
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk->C:\AdwCleaner\Quarantine\C\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk.vir
C:\Users\Holger Carlson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk->C:\AdwCleaner\Quarantine\C\Users\Holger Carlson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk.vir
C:\Users\Holger Carlson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk->C:\AdwCleaner\Quarantine\C\Users\Holger Carlson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk.vir
C:\Users\Holger Carlson\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk->C:\AdwCleaner\Quarantine\C\Users\Holger Carlson\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk.vir
C:\Users\Holger Carlson\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk->C:\AdwCleaner\Quarantine\C\Users\Holger Carlson\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk.vir
C:\Users\Holger Carlson\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk->C:\AdwCleaner\Quarantine\C\Users\Holger Carlson\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk.vir
ich hoffe, das ist jetzt richtig.
nochmal sorry, sorry