![]() |
TR/Boigy.J' [trojan] Firefox stürzt ständig ab Hallo in die Runde, ich habe so ziemlich das gleiche Problem wie AceAndRoll es schon beschrieben hat: Zitat:
Noch mal zur Problematik: Seit mind. 3 Wochen stürzt firefox ständig ab, vorher erscheint keine Rückmeldung, das Browserfenster wird weiß nichts läuft mehr, alles andere aber funktioniert. Erst nachdem ich aktiv mit Avira gesucht habe, kommen diverse Virenfunde u.a. TR/Boigy.J' [trojan], sinowal, APPL/Paleo.A, und einige andere. Der Scan läuft noch (zurzeit sind es 11 Funde, 50% abgeschlossen) daher kann ich das Logfile noch nicht erstellen. Meine Frage ist auch was man am besten tut, wenn Avira fragt, entfernen oder in Quarantäne. Außerdem habe ich in den Einstellungen von neben meiner Rolle als PC-Admin, noch System, Ersteller und andere Admin gefunden, was ich etwas seltsam fand. Könnt ihr mir sagen, ob das normal ist? Der PC wird ausschließlich von mir selbst genutzt, es gibt außer einem Gast-Account keinen anderen. Danke für eure Hilfe! |
Hi, Systemscan mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
|
Ok, danke erst mal. Zwei Fragen: Warum kann ich keine Avira Logfile posten? Wie lange dauert der Scan in etwa? (weil Avira schon seit 4h scannt und ich irgendwann mal schlafen wollte..) Danke Felino Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-06-2013 03 Ran by Anne (administrator) on 10-06-2013 23:09:54 Running from C:\Users\Anne\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Adobe Systems Incorporated) c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files (x86)\Connectify\ConnectifyService.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Connectify) C:\Program Files (x86)\Connectify\ConnectifyD.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe (Acer) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Akamai Technologies, Inc.) C:\Users\Anne\AppData\Local\Akamai\netsession_win.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Intel Corporation) C:\Windows\system32\igfxext.exe (Akamai Technologies, Inc.) C:\Users\Anne\AppData\Local\Akamai\netsession_win.exe (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.EXE (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Windows\system32\taskmgr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (RealNetworks, Inc.) C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\NOTEPAD.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-06-04] (Synaptics Incorporated) HKLM\...\Run: [Acer ePower Management] C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [828960 2009-08-06] (Acer Incorporated) HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7833120 2009-05-22] (Realtek Semiconductor) HKLM\...\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-05-22] (Realtek Semiconductor Corp.) HKLM\...\Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [438784 2010-12-17] () HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [472992 2013-03-21] (Adobe Systems Incorporated) HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1475584 2010-11-20] (Microsoft Corporation) HKCU\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [x] HKCU\...\Run: [Akamai NetSession Interface] "C:\Users\Anne\AppData\Local\Akamai\netsession_win.exe" [4480768 2013-01-26] (Akamai Technologies, Inc.) HKCU\...\Run: [Connectify] C:\Program Files (x86)\Connectify\Connectify.exe [4013928 2012-11-09] (Connectify) HKCU\...\Run: [AdobeBridge] [x] HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [825864 2009-08-31] (Dritek System Inc.) HKLM-x32\...\Run: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [91432 2009-04-15] (CyberLink Corp.) HKLM-x32\...\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe" [50472 2009-04-15] (CyberLink Corp.) HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [309688 2012-10-11] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot [295072 2012-12-16] (RealNetworks, Inc.) HKLM-x32\...\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-18] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-10-11] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345312 2013-05-07] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [1073312 2012-03-09] (Adobe Systems Incorporated) HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Packard Bell\Screensaver\run_Packard Bell.exe /default [162336 2009-07-22] () HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Packard Bell\Screensaver\run_Packard Bell.exe /default [162336 2009-07-22] () AppInit_DLLs: C:\PROGRA~2\WIA6EB~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\WIA6EB~1\Datamngr\x64\IEBHO.dll [1791896 2011-08-09] (Bandoo Media, inc) Startup: C:\ProgramData\Start Menu\Programs\Startup\vpngui.exe.lnk ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{467D5E81-8349-4892-9E81-C3674ED8E451}\Icon09DB8A851.exe () Startup: C:\Users\Anne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ComplaintFreeWorld.lnk ShortcutTarget: ComplaintFreeWorld.lnk -> C:\Program Files (x86)\ComplaintFreeWorld\ComplaintFreeWorld.exe (No File) Startup: C:\Users\Anne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Search HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle Redirect URLSearchHook: (No Name) - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - No File HKLM SearchScopes: DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101} URL = hxxp://www.searchqu.com/web?src=ieb&appid=153&systemid=101&sr=0&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101} URL = hxxp://www.searchqu.com/web?src=ieb&appid=153&systemid=101&sr=0&q={searchTerms} HKLM-x32 SearchScopes: DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101} URL = hxxp://www.searchqu.com/web?src=ieb&appid=153&systemid=101&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101} URL = hxxp://www.searchqu.com/web?src=ieb&appid=153&systemid=101&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851647 SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2101} URL = hxxp://www.searchqu.com/web?src=ieb&appid=153&systemid=101&sr=0&q={searchTerms} SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851647 BHO: Loader Class - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WIA6EB~1\Datamngr\x64\BROWSE~1.DLL (Bandoo Media, inc) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll No File BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll () BHO-x32: Loader Class - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WIA6EB~1\Datamngr\BROWSE~1.DLL (Bandoo Media, inc) BHO-x32: BandooIEPlugin Class - {EB5CEE80-030A-4ED8-8E20-454E9C68380F} - C:\Program Files (x86)\Bandoo\Plugins\IE\ieplugin.dll No File Toolbar: HKLM-x32 - Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll () Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx Handler: msdaipp - No CLSID Value - Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler-x32: msdaipp - No CLSID Value - Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 129.143.2.1 129.143.2.4 Tcpip\..\Interfaces\{9779B8F3-DDDD-498B-B567-28A90AF70335}: [NameServer]192.168.249.1 FireFox: ======== FF ProfilePath: C:\Users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\2sl1gyjs.default FF SelectedSearchEngine: Google FF Homepage: hxxp://www.funkhauseuropa.de/ FF Keyword.URL: hxxp://www.searchqu.com/web?src=ffb&appid=153&systemid=101&sr=0&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8064.0206 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=16.0.0.282 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version=16.0.0.282 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Extension: Bandoo for Firefox - C:\Users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\2sl1gyjs.default\Extensions\ffox@bandoo.com FF Extension: Flashblock - C:\Users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\2sl1gyjs.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} FF Extension: Searchqu Toolbar - C:\Users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\2sl1gyjs.default\Extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} FF Extension: uTorrentBar_DE Community Toolbar - C:\Users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\2sl1gyjs.default\Extensions\{c840e246-6b95-475e-9bd7-caa1c7eca9f2} FF Extension: No Name - C:\Users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\2sl1gyjs.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi FF Extension: No Name - C:\Users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\2sl1gyjs.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{go ogle:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParam eter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Shockwave for Director) - C:\Program Files (x86)\Mozilla Firefox\plugins\np32dsw.dll (Macromedia, Inc.) CHR Plugin: (DivX Web Player) - C:\Program Files (x86)\Mozilla Firefox\plugins\npdivx32.dll (DivX,Inc.) CHR Plugin: (Windows Genuine Advantage) - C:\Program Files (x86)\Mozilla Firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation) CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2003) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL (Microsoft Corporation) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpplugin.dll (RealPlayer) CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealDownloader Plugin) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) CHR Extension: (Google Docs) - C:\Users\Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (RealDownloader) - C:\Users\Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0 CHR Extension: (Gmail) - C:\Users\Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 Akamai; c:\program files (x86)\common files\akamai/netsession_win_ca0e279.dll [4561152 2013-03-22] (Akamai Technologies, Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86752 2013-03-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110816 2013-03-27] (Avira Operations GmbH & Co. KG) R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [65536 2012-11-09] () R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [844320 2009-08-06] (Acer Incorporated) R2 Greg_Service; C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe [1150496 2009-06-04] (Acer Incorporated) R2 HPSLPSVC; C:\Users\Anne\AppData\Local\Temp\7zS7362\hpslpsvc64.dll [1039360 2012-11-14] (Hewlett-Packard Co.) R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] () R2 Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [240160 2009-07-04] (Acer) S2 Bandoo Coordinator; "C:\Program Files (x86)\Bandoo\Bandoo.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-27] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-03-27] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-27] (Avira Operations GmbH & Co. KG) R1 cnnctfy2; C:\Windows\System32\DRIVERS\cnnctfy2.sys [31344 2013-02-22] (Connectify) R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [304784 2010-03-23] () R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [304784 2010-03-23] () S3 int15.sys; C:\Windows\System32\OEM\Factory\int15.sys [17952 2008-03-28] (Acer, Inc.) S3 int15.sys; C:\Windows\System32\OEM\Factory\int15.sys [17952 2008-03-28] (Acer, Inc.) S3 ssudobex; C:\Windows\System32\DRIVERS\ssudobex.sys [203104 2012-09-20] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-10 23:09 - 2013-06-10 23:09 - 01920086 ____A (Farbar) C:\Users\Anne\Desktop\FRST64.exe 2013-06-10 23:09 - 2013-06-10 23:09 - 00000000 ____D C:\FRST 2013-05-31 15:38 - 2013-05-31 15:38 - 00003584 ____A C:\Users\Anne\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-05-30 22:36 - 2013-05-31 00:00 - 00000000 ____D C:\Users\Anne\Desktop\Frustbilder 2013-05-30 18:35 - 2013-06-02 09:07 - 02277865 ____A C:\Users\Anne\Desktop\Online-Projekt pp.pptx 2013-05-25 13:12 - 2013-05-25 13:16 - 326894135 ____A C:\Users\Anne\Downloads\it's complicated (v1.1).mp4 2013-05-24 21:13 - 2013-05-24 23:26 - 00033670 ____A C:\Users\Anne\Desktop\radioDjv.odt 2013-05-24 20:49 - 2013-05-24 16:23 - 293822252 ____A C:\Users\Anne\Desktop\TASCAM_0048.wav 2013-05-24 20:43 - 2013-05-24 20:43 - 00000000 ____D C:\Users\Anne\AppData\Roaming\WinRAR 2013-05-24 20:43 - 2013-05-24 20:43 - 00000000 ____D C:\Program Files\WinRAR 2013-05-24 20:42 - 2013-05-24 20:42 - 01656459 ____A C:\Users\Anne\Desktop\winrar-x64-420.exe 2013-05-24 20:37 - 2013-05-24 20:37 - 203140410 ____A C:\Users\Anne\Desktop\TASCAM_0048.rar 2013-05-24 13:22 - 2013-05-24 13:36 - 510547782 ____A C:\Users\Anne\Desktop\Burschel Interview.wav 2013-05-24 12:40 - 2013-05-24 12:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-05-24 11:12 - 2013-04-05 08:52 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-05-24 11:12 - 2013-04-05 08:52 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-05-24 11:12 - 2013-04-05 08:52 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-05-24 11:12 - 2013-04-05 08:50 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-05-24 11:12 - 2013-04-05 08:50 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-05-24 11:12 - 2013-04-05 08:50 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-05-24 11:12 - 2013-04-05 08:50 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-05-24 11:12 - 2013-04-05 08:50 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-05-24 11:12 - 2013-04-05 08:50 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-05-24 11:12 - 2013-04-05 08:50 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-05-24 11:12 - 2013-04-05 08:50 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-05-24 11:12 - 2013-04-05 08:50 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-05-24 11:12 - 2013-04-05 07:28 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-05-24 11:12 - 2013-04-05 07:28 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-05-24 11:12 - 2013-04-05 07:26 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-05-24 11:12 - 2013-04-05 07:26 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-05-24 11:12 - 2013-04-05 07:26 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-05-24 11:12 - 2013-04-05 07:26 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-05-24 11:12 - 2013-04-05 07:26 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-05-24 11:12 - 2013-04-05 07:26 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-05-24 11:12 - 2013-04-05 07:26 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-05-24 11:12 - 2013-04-05 07:26 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-05-24 11:12 - 2013-04-05 07:26 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-05-24 11:12 - 2013-04-05 06:43 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-05-24 11:12 - 2013-04-05 06:29 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-05-24 11:11 - 2013-04-05 08:50 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-05-24 11:11 - 2013-04-05 08:50 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-05-24 11:11 - 2013-04-05 07:26 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-05-24 11:11 - 2013-04-05 07:26 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-05-23 22:12 - 2013-06-10 00:09 - 00000000 ____D C:\Users\Anne\Desktop\Film 2013-05-15 18:45 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-05-15 18:45 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys 2013-05-15 18:45 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe 2013-05-15 18:45 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-05-15 18:45 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-05-15 18:45 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-05-15 18:45 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll 2013-05-15 18:45 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-05-15 18:45 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-05-15 18:45 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-05-15 18:45 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll 2013-05-15 18:44 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-05-15 18:44 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll 2013-05-15 18:44 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll 2013-05-12 13:15 - 2013-05-12 13:15 - 00000162 ___AH C:\Users\Anne\Desktop\~$line-Projekt.odt 2013-05-11 23:46 - 2013-05-11 23:46 - 00000000 ____D C:\Users\Anne\AppData\Roaming\Greyfirst 2013-05-11 23:46 - 2013-05-11 23:46 - 00000000 ____D C:\Users\Anne\AppData\Local\Greyfirst 2013-05-11 23:43 - 2013-05-11 23:43 - 00001841 ____A C:\Users\Public\Desktop\Celtx.lnk 2013-05-11 23:43 - 2013-05-11 23:43 - 00000000 ____D C:\Program Files (x86)\Celtx ==================== One Month Modified Files and Folders ======= 2013-06-10 23:09 - 2013-06-10 23:09 - 01920086 ____A (Farbar) C:\Users\Anne\Desktop\FRST64.exe 2013-06-10 23:09 - 2013-06-10 23:09 - 00000000 ____D C:\FRST 2013-06-10 23:06 - 2013-04-22 18:56 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-06-10 22:48 - 2013-05-09 14:08 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-06-10 22:38 - 2010-02-08 21:51 - 00000000 ____D C:\Users\Anne\AppData\Roaming\Skype 2013-06-10 22:14 - 2013-01-18 02:29 - 00002534 __ASH C:\ProgramData\b39f1879-7dc1-4555-b48f-d1519f03ed90 2013-06-10 19:30 - 2009-10-20 08:47 - 01874402 ____A C:\Windows\WindowsUpdate.log 2013-06-10 14:43 - 2013-01-18 02:38 - 00000000 ____D C:\ProgramData\b46280da-2f30-4ebe-ad7c-da0e56f0640d 2013-06-10 14:32 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\sysprep 2013-06-10 14:29 - 2009-07-14 06:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-06-10 14:29 - 2009-07-14 06:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-06-10 14:28 - 2009-10-20 18:39 - 00654400 ____A C:\Windows\System32\perfh007.dat 2013-06-10 14:28 - 2009-10-20 18:39 - 00130240 ____A C:\Windows\System32\perfc007.dat 2013-06-10 14:28 - 2009-07-14 07:13 - 01498742 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-10 14:22 - 2013-04-22 18:56 - 00001102 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-06-10 14:20 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-10 14:20 - 2009-07-14 06:51 - 00105357 ____A C:\Windows\setupact.log 2013-06-10 14:20 - 2009-07-14 06:45 - 05068160 ____A C:\Windows\System32\FNTCACHE.DAT 2013-06-10 14:18 - 2012-05-07 23:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-06-10 14:18 - 2009-08-18 10:35 - 00374092 ____A C:\Windows\PFRO.log 2013-06-10 00:09 - 2013-05-23 22:12 - 00000000 ____D C:\Users\Anne\Desktop\Film 2013-06-09 19:54 - 2012-12-01 14:55 - 00000000 ____D C:\Users\Anne\AppData\Roaming\Dropbox 2013-06-05 19:06 - 2011-07-16 17:01 - 01749504 __ASH C:\Users\Anne\Desktop\Thumbs.db 2013-06-05 19:02 - 2010-02-08 20:59 - 00119616 ____A C:\Users\Anne\AppData\Local\GDIPFONTCACHEV1.DAT 2013-06-05 15:26 - 2009-08-18 10:13 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-06-04 16:30 - 2012-12-01 15:07 - 00000000 ___RD C:\Users\Anne\Dropbox 2013-06-04 15:57 - 2012-12-01 15:07 - 00001025 ____A C:\Users\Anne\Desktop\Dropbox.lnk 2013-06-04 15:57 - 2010-02-08 21:47 - 00000858 ____A C:\Windows\wininit.ini 2013-06-02 09:07 - 2013-05-30 18:35 - 02277865 ____A C:\Users\Anne\Desktop\Online-Projekt pp.pptx 2013-05-31 15:38 - 2013-05-31 15:38 - 00003584 ____A C:\Users\Anne\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-05-31 00:00 - 2013-05-30 22:36 - 00000000 ____D C:\Users\Anne\Desktop\Frustbilder 2013-05-30 22:36 - 2013-01-10 00:29 - 00000000 ____D C:\Users\Anne\Desktop\Arbeitsprobe 2013-05-30 18:25 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF 2013-05-26 16:41 - 2013-02-27 22:29 - 00000099 ____A C:\Users\Public\LMDebug.log 2013-05-25 13:16 - 2013-05-25 13:12 - 326894135 ____A C:\Users\Anne\Downloads\it's complicated (v1.1).mp4 2013-05-25 02:00 - 2010-02-08 21:05 - 00000000 ____D C:\Users\Anne\AppData\Local\Adobe 2013-05-24 23:26 - 2013-05-24 21:13 - 00033670 ____A C:\Users\Anne\Desktop\radioDjv.odt 2013-05-24 20:43 - 2013-05-24 20:43 - 00000000 ____D C:\Users\Anne\AppData\Roaming\WinRAR 2013-05-24 20:43 - 2013-05-24 20:43 - 00000000 ____D C:\Program Files\WinRAR 2013-05-24 20:42 - 2013-05-24 20:42 - 01656459 ____A C:\Users\Anne\Desktop\winrar-x64-420.exe 2013-05-24 20:37 - 2013-05-24 20:37 - 203140410 ____A C:\Users\Anne\Desktop\TASCAM_0048.rar 2013-05-24 16:23 - 2013-05-24 20:49 - 293822252 ____A C:\Users\Anne\Desktop\TASCAM_0048.wav 2013-05-24 13:36 - 2013-05-24 13:22 - 510547782 ____A C:\Users\Anne\Desktop\Burschel Interview.wav 2013-05-24 12:40 - 2013-05-24 12:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-05-24 11:21 - 2010-02-09 19:36 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-05-23 22:27 - 2012-04-24 15:21 - 00000000 ____D C:\Users\Anne\Documents\2012 2013-05-23 22:18 - 2010-02-08 20:58 - 00000000 ____D C:\users\Anne 2013-05-23 22:17 - 2012-07-02 20:04 - 00000000 ____D C:\Users\Anne\Desktop\UniTübingenMedienwissenschaft 2013-05-14 21:34 - 2013-05-09 14:08 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-05-14 21:34 - 2013-05-09 14:08 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-05-12 13:15 - 2013-05-12 13:15 - 00000162 ___AH C:\Users\Anne\Desktop\~$line-Projekt.odt 2013-05-11 23:46 - 2013-05-11 23:46 - 00000000 ____D C:\Users\Anne\AppData\Roaming\Greyfirst 2013-05-11 23:46 - 2013-05-11 23:46 - 00000000 ____D C:\Users\Anne\AppData\Local\Greyfirst 2013-05-11 23:43 - 2013-05-11 23:43 - 00001841 ____A C:\Users\Public\Desktop\Celtx.lnk 2013-05-11 23:43 - 2013-05-11 23:43 - 00000000 ____D C:\Program Files (x86)\Celtx Files to move or delete: ==================== C:\ProgramData\FullRemove.exe C:\ProgramData\dsgsdgdsgdsgw.bat C:\ProgramData\dsgsdgdsgdsgw.pad C:\ProgramData\dsgsdgdsgdsgw.reg ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-03-22 14:38 ==================== End Of Log ============================ Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-06-2013 03 |
Fix mit FRST Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{467D5E81-8349-4892-9E81-C3674ED8E451}\Icon09DB8A851.exe ()
|
Code: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-06-2013 03 |
Immer langsam, ich kann nicht zaubern :) Avira Logfile bitte noch posten. Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden ).
|
Code: Avira Free Antivirus Code: OTL logfile created on: 11.06.2013 16:30:35 - Run 1 Code: OTL Extras logfile created on: 11.06.2013 16:30:35 - Run 1 |
Du sammelst Adware :) Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches OTL log bitte. Noch Probleme? |
Und das soll ich jetzt alles nacheinander machen? oder waren das Alternativen? Code: OTL Extras logfile created on: 11.06.2013 16:30:35 - Run 1 Code: # AdwCleaner v2.303 - Datei am 11/06/2013 um 18:14:01 erstellt |
Der link geht bei mir. Junkware Removal Tool Download Und bitte alles der Reihe nach machen, sprich OTL am schluss, und alle Logs auf einmal posten. |
Es geht immer noch nicht. Der download klappt, sobald ich aber die Datei auführen will erscheint ein Fenster (betitelt: 7 Zip SFX) "archive error. could not create folder C:/JRT. Zugriff verweigert" und es geht nicht weiter.. |
Ok dann lass das weg. Noch nen Onlinescan, dann sollten wir durch sein. ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches OTL log. Noch Probleme? |
Sorry, dass ich lange nicht geantwortet habe. Das hat private Gründe. Leider ist das Problem immer noch nicht behoben. Gibt es zu dem Online scan auch eine Alternative, habe nämlich grad keine externe Festplatte. Der Security check link funktioniert irgendwie auch nicht. Bitte schreibe mir noch eine mögliche Alternative, oder soll ich noch mal einen aktuellen scan von OTL oder ähnlichem schicken? Danke dir!! OK, security check hat jetzt doch geklappt. hier ist das Logfile: Code: Results of screen317's Security Check version 0.99.64 Code: OTL logfile created on: 25.06.2013 13:52:43 - Run 2 |
Für den Onlinescan brauchst Du keine Externe Platte. Da steht nur das, falls Du eine Platte hast, kannste die dranhängen und eben mit scannen lassen :) Also mach bitte noch ESET. |
Code: ESETSmartInstaller@High as downloader log: |
Alle Zeitangaben in WEZ +1. Es ist jetzt 03:21 Uhr. |
Copyright ©2000-2025, Trojaner-Board