ruthie1710 | 16.11.2013 17:56 | Hallo, vielen Dank für deine Antwort. Ich habe bereits gestern versucht den FRST durchzuführen, da das hier als vorbereitende Schritte gefordert wird. Deshalb habe ich wie gewünscht zuerst den Defogger installiert und drüber laufen lassen (ohne reenable), danach wollte ich den frst und den gmer. Beide hängen sich aber beim starten auf. Wenn ich den frst starten will, kommt zuerst eine fragebox, ob ich eine dial-Verbindung starten will, die mein Mann manchmal geschäftlich braucht, und wenn ich die wegklicke hängt sich der frst auf.
Ich habe aber vor ein paar Tagen schon den OTL scannen lassen und poste dir hier den logfile.
Defogger:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 22:10 on 15/11/2013 (zimmermann)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
OTL:
OTL Logfile: Code:
OTL logfile created on: 11/13/2013 4:16:09 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = F:\
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16721)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1.96 Gb Total Physical Memory | 1.21 Gb Available Physical Memory | 61.47% Memory free
3.92 Gb Paging File | 2.82 Gb Available in Paging File | 71.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 167.69 Gb Total Space | 51.64 Gb Free Space | 30.79% Space Free | Partition Type: NTFS
Drive D: | 50.09 Gb Total Space | 49.97 Gb Free Space | 99.76% Space Free | Partition Type: NTFS
Drive F: | 1.96 Gb Total Space | 1.94 Gb Free Space | 98.68% Space Free | Partition Type: FAT
Computer Name: ZIMMERMANN-PC | User Name: zimmermann | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/10/31 19:25:18 | 000,683,576 | ---- | M] (Avira Operations GmbH & Co. KG) -- c:\program files\avira\antivir desktop\avgnt.exe
PRC - [2013/07/22 10:09:08 | 000,162,856 | ---- | M] (Geek Software GmbH) -- C:\Program Files\PDF24\pdf24.exe
PRC - [2013/07/09 09:16:56 | 000,302,961 | ---- | M] () -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
PRC - [2013/07/06 09:18:17 | 000,879,456 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2013/05/16 09:59:00 | 003,830,224 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2013/05/16 09:56:34 | 001,033,688 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2013/05/16 09:56:30 | 001,817,560 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2013/05/15 12:21:32 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2012/12/05 13:22:40 | 000,092,632 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2012/12/05 13:22:38 | 000,247,768 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2012/11/23 03:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012/10/05 21:57:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- F:\OTL.exe
PRC - [2011/08/26 20:44:34 | 002,717,696 | ---- | M] (Eastman Kodak Company) -- C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe
PRC - [2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/01/19 10:34:48 | 002,201,192 | ---- | M] (SEC) -- C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
PRC - [2009/11/04 05:11:48 | 000,835,072 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2009/10/26 12:53:14 | 000,091,136 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
PRC - [2009/10/20 10:12:58 | 000,013,312 | ---- | M] (DoctorSoft) -- C:\Program Files\AnyPC Client\APLangApp.exe
PRC - [2009/10/13 11:03:04 | 000,716,800 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2009/08/13 20:58:10 | 000,044,312 | ---- | M] () -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe
PRC - [2009/03/30 11:34:36 | 000,241,664 | ---- | M] () -- C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe
PRC - [2008/10/24 14:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
PRC - [2008/08/10 18:15:22 | 000,221,253 | ---- | M] (Aventail Corporation) -- C:\Windows\System32\ngvpnmgr.exe
========== Modules (No Company Name) ==========
MOD - [2013/07/09 09:16:56 | 000,302,961 | ---- | M] () -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
MOD - [2013/05/16 09:55:28 | 000,161,112 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
MOD - [2013/05/16 09:55:26 | 000,113,496 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2013/05/16 09:55:24 | 000,416,600 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2012/02/17 19:55:35 | 000,166,912 | ---- | M] () -- C:\Program Files\WinRAR\rarext.dll
MOD - [2006/08/12 04:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDWSCService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDUpdateService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDScannerService)
SRV - [2013/11/07 10:48:35 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/10/31 19:25:40 | 000,440,376 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013/10/31 19:25:19 | 001,164,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe -- (AntiVirWebService)
SRV - [2013/10/31 19:25:19 | 000,440,376 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2013/10/10 08:32:39 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/07/09 09:16:56 | 000,285,795 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe -- (HOSTS Anti-PUPs)
SRV - [2013/05/27 05:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2012/12/05 13:22:40 | 000,092,632 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2010/07/28 21:41:11 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2009/08/13 20:58:10 | 000,044,312 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe -- (OberonGameConsoleService)
SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/03/30 11:34:36 | 000,241,664 | ---- | M] () [Auto | Running] -- C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe -- (UI Assistant Service)
SRV - [2008/10/24 14:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService)
SRV - [2008/08/10 18:15:22 | 000,221,253 | ---- | M] (Aventail Corporation) [Auto | Running] -- C:\Windows\System32\ngvpnmgr.exe -- (NgVpnMgr)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\dsNcAdpt.sys -- (dsNcAdpt)
DRV - [2013/10/31 19:25:19 | 000,137,208 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2013/10/31 19:25:19 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2013/10/31 19:25:19 | 000,067,680 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\avnetflt.sys -- (avnetflt)
DRV - [2013/10/31 19:25:19 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012/08/27 14:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2011/03/18 12:46:26 | 000,061,704 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2011/03/18 12:46:10 | 000,073,096 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K)
DRV - [2010/11/23 16:10:44 | 001,249,792 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2010/11/20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/09/28 10:22:00 | 000,315,392 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7)
DRV - [2009/07/14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/10 14:44:52 | 000,122,880 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV - [2009/01/12 09:12:56 | 000,105,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009/01/04 17:29:50 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009/01/04 17:29:50 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2008/12/11 22:11:04 | 000,022,528 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Unknown] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad)
DRV - [2008/12/11 22:11:04 | 000,018,816 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Stopped] -- C:\windows\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2008/10/29 16:35:32 | 000,007,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter.sys -- (massfilter)
DRV - [2008/08/10 18:14:42 | 000,023,192 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ngwfp.sys -- (NgWfp)
DRV - [2008/08/10 18:14:34 | 000,020,632 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ngfilter.sys -- (NgFilter)
DRV - [2008/08/10 18:14:28 | 000,077,464 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ngvpn.sys -- (NgVpn)
DRV - [2008/08/10 18:13:04 | 000,025,240 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nglog.sys -- (NgLog)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gmx.net/
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{4A2875B3-526E-4CDD-A4CD-55633DC6E280}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=287D2BE5-0407-4EDB-B631-443CCF0E0833&apn_sauid=9B86531E-9EA2-4DE0-A7E5-DF97FB5CD124
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: %7B195A3098-0BD5-4e90-AE22-BA1C540AFD1E%7D:4.0.4
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:25.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@innoplus.de/ino3DViewer: C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\T-Mobile Internet Manager 03\addon [2011/11/03 10:09:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/11/07 10:48:31 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/11/07 10:48:31 | 000,000,000 | ---D | M]
[2013/01/30 20:28:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Extensions
[2013/01/30 20:28:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2013/09/27 09:03:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Firefox\Profiles\ue9nijo9.default\extensions
[2013/05/25 22:14:15 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Firefox\Profiles\ue9nijo9.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2013/11/07 10:48:31 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2013/11/07 10:48:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\browser\extensions
[2013/11/07 10:48:36 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ==========
O1 HOSTS File: ([2013/11/12 10:13:17 | 001,587,203 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 212link.com
O1 - Hosts: 127.0.0.1 www.ping2it.com
O1 - Hosts: 127.0.0.1 dl.ividi.org
O1 - Hosts: 127.0.0.1 08sr.combineads.info
O1 - Hosts: 127.0.0.1 08srvr.combineads.info
O1 - Hosts: 127.0.0.1 12srvr.combineads.info
O1 - Hosts: 127.0.0.1 2010-fr.com
O1 - Hosts: 127.0.0.1 2012-new.biz
O1 - Hosts: 127.0.0.1 2319825.ourtoolbar.com
O1 - Hosts: 127.0.0.1 24h00business.com
O1 - Hosts: 127.0.0.1 a.daasafterdusk.com
O1 - Hosts: 127.0.0.1 ad.adn360.com
O1 - Hosts: 127.0.0.1 adeartss.eu
O1 - Hosts: 127.0.0.1 adesoeasy.eu
O1 - Hosts: 127.0.0.1 adf.girldatesforfree.net
O1 - Hosts: 127.0.0.1 adm.soft365.com
O1 - Hosts: 127.0.0.1 adomicileavail.googlepages.com
O1 - Hosts: 127.0.0.1 ads7.complexadveising.com
O1 - Hosts: 127.0.0.1 ads.aff.co
O1 - Hosts: 127.0.0.1 ads.alpha00001.com
O1 - Hosts: 127.0.0.1 ads.cloud4ads.com
O1 - Hosts: 127.0.0.1 ads.eorezo.com
O1 - Hosts: 127.0.0.1 ads.hooqy.com
O1 - Hosts: 127.0.0.1 ads.icksor.com
O1 - Hosts: 127.0.0.1 ads.regiedepub.com
O1 - Hosts: 51303 more lines...
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APLangApp] C:\Program Files\AnyPC Client\APLangApp.exe (DoctorSoft)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [EKAIO2StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [HOSTS Anti-Adware_PUPs] C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe ()
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupControlXP Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.68.161.141 217.68.161.171
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{235AE447-BE14-4A06-914F-D1A7B9BFA633}: DhcpNameServer = 217.68.161.141 217.68.161.171
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{95DE52F9-5E06-47C9-BE22-4B7FE2603F77}: DhcpNameServer = 192.168.168.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~2\browse~1\25911~1.18\{c16c1~1\mngr.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{b130e3cc-05f9-11e1-8855-0024545e3669}\Shell - "" = AutoRun
O33 - MountPoints2\{b130e3cc-05f9-11e1-8855-0024545e3669}\Shell\AutoRun\command - "" = F:\Install.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/11/13 12:56:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2013/11/13 12:56:42 | 000,067,680 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avnetflt.sys
[2013/11/08 10:50:48 | 000,000,000 | ---D | C] -- C:\Users\zimmermann\Desktop\Babyschwimmen
[2013/11/08 10:49:41 | 000,000,000 | ---D | C] -- C:\Users\zimmermann\Desktop\ofen
[2013/11/07 12:19:05 | 000,000,000 | ---D | C] -- C:\Users\zimmermann\Desktop\Maitte
[2013/11/07 10:48:30 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[1 C:\Users\zimmermann\Desktop\*.tmp files -> C:\Users\zimmermann\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/11/13 15:42:42 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2013/11/13 15:42:37 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013/11/13 12:46:58 | 000,014,736 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/11/13 12:46:58 | 000,014,736 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/11/13 11:45:38 | 1579,630,592 | -HS- | M] () -- C:\hiberfil.sys
[2013/11/12 10:57:31 | 000,917,742 | ---- | M] () -- C:\Users\zimmermann\Desktop\avira_fusebundlegen-win32-en.zip
[2013/11/12 10:21:53 | 001,085,542 | ---- | M] () -- C:\Users\zimmermann\Desktop\adwcleaner_3012.exe
[2013/11/12 10:13:17 | 001,587,203 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts
[2013/11/10 18:40:25 | 000,654,400 | ---- | M] () -- C:\windows\System32\perfh007.dat
[2013/11/10 18:40:25 | 000,616,242 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2013/11/10 18:40:25 | 000,130,240 | ---- | M] () -- C:\windows\System32\perfc007.dat
[2013/11/10 18:40:25 | 000,106,622 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2013/11/06 20:16:09 | 000,002,004 | -H-- | M] () -- C:\Users\zimmermann\Documents\Default.rdp
[2013/11/06 19:55:56 | 002,092,618 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts.20131112-101317.backup
[2013/11/01 20:36:39 | 000,184,251 | ---- | M] () -- C:\Users\zimmermann\Desktop\Terasse_ lippoldt.PDF
[2013/10/31 21:28:53 | 000,072,707 | ---- | M] () -- C:\Users\zimmermann\Documents\brandes küchenfliesen.PDF
[2013/10/31 19:25:19 | 000,137,208 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avipbb.sys
[2013/10/31 19:25:19 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avgntflt.sys
[2013/10/31 19:25:19 | 000,067,680 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avnetflt.sys
[2013/10/31 19:25:19 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avkmgr.sys
[2013/10/30 11:38:35 | 000,044,908 | ---- | M] () -- C:\Users\zimmermann\Documents\Rechnung Lidl 202531487 29.10.2013.PDF
[2013/10/29 10:33:18 | 000,084,693 | ---- | M] () -- C:\Users\zimmermann\Desktop\Vertrag Maitte.pdf
[2013/10/23 19:13:10 | 001,448,168 | ---- | M] () -- C:\Users\zimmermann\Documents\Stiftung Warentest Kaminöfen.pdf
[1 C:\Users\zimmermann\Desktop\*.tmp files -> C:\Users\zimmermann\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/11/12 10:55:13 | 000,917,742 | ---- | C] () -- C:\Users\zimmermann\Desktop\avira_fusebundlegen-win32-en.zip
[2013/11/12 10:21:44 | 001,085,542 | ---- | C] () -- C:\Users\zimmermann\Desktop\adwcleaner_3012.exe
[2013/11/01 20:42:34 | 000,184,251 | ---- | C] () -- C:\Users\zimmermann\Desktop\Terasse_ lippoldt.PDF
[2013/10/31 21:32:00 | 000,072,707 | ---- | C] () -- C:\Users\zimmermann\Documents\brandes küchenfliesen.PDF
[2013/10/30 11:39:19 | 000,044,908 | ---- | C] () -- C:\Users\zimmermann\Documents\Rechnung Lidl 202531487 29.10.2013.PDF
[2013/10/29 10:33:13 | 000,084,693 | ---- | C] () -- C:\Users\zimmermann\Desktop\Vertrag Maitte.pdf
[2013/10/23 19:13:10 | 001,448,168 | ---- | C] () -- C:\Users\zimmermann\Documents\Stiftung Warentest Kaminöfen.pdf
[2010/09/06 11:03:51 | 000,011,383 | ---- | C] () -- C:\Users\zimmermann\gsview32.ini
[2010/05/06 16:50:12 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe
========== ZeroAccess Check ==========
[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2010/05/08 11:57:15 | 000,000,000 | -HSD | M] -- C:\Users\zimmermann\AppData\Roaming\.#
[2011/11/03 11:14:25 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Aventail
[2010/12/19 12:11:19 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\elsterformular
[2013/01/10 11:28:55 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Fighters
[2011/04/09 17:39:53 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Foxit Software
[2010/05/08 11:55:33 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\GameConsole
[2011/07/21 15:12:51 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\GARMIN
[2011/11/02 19:22:45 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Go Go Gourmet
[2012/05/28 13:20:19 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\innoplus
[2010/09/01 17:45:20 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Juniper Networks
[2012/08/15 16:27:22 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\LaunchPad
[2012/02/08 10:10:33 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Opera
[2011/11/03 10:09:18 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Program Files
[2011/08/16 17:16:02 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Simfy
[2010/08/22 19:03:59 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Softland
[2013/01/30 20:28:34 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\TomTom
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2013/01/14 12:14:30 | 002,176,484 | ---- | C] ()(C:\Users\zimmermann\Desktop\_?ALLROUNDER?_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf) -- C:\Users\zimmermann\Desktop\_♥ALLROUNDER♥_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf
[2013/01/14 12:12:28 | 002,176,484 | ---- | M] ()(C:\Users\zimmermann\Desktop\_?ALLROUNDER?_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf) -- C:\Users\zimmermann\Desktop\_♥ALLROUNDER♥_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf
========== Alternate Data Streams ==========
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:A42A9F39
< End of report > --- --- ---
Vielen Dank,
ruthie
Hallo, vielen Dank für deine Antwort. Ich habe bereits gestern versucht den FRST durchzuführen, da das hier als vorbereitende Schritte gefordert wird. Deshalb habe ich wie gewünscht zuerst den Defogger installiert und drüber laufen lassen (ohne reenable), danach wollte ich den frst und den gmer. Beide hängen sich aber beim starten auf. Wenn ich den frst starten will, kommt zuerst eine fragebox, ob ich eine dial-Verbindung starten will, die mein Mann manchmal geschäftlich braucht, und wenn ich die wegklicke hängt sich der frst auf.
Ich habe aber vor ein paar Tagen schon den OTL scannen lassen und poste dir hier den logfile.
Defogger:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 22:10 on 15/11/2013 (zimmermann)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
OTL:
OTL Logfile: Code:
OTL logfile created on: 11/13/2013 4:16:09 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = F:\
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16721)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1.96 Gb Total Physical Memory | 1.21 Gb Available Physical Memory | 61.47% Memory free
3.92 Gb Paging File | 2.82 Gb Available in Paging File | 71.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 167.69 Gb Total Space | 51.64 Gb Free Space | 30.79% Space Free | Partition Type: NTFS
Drive D: | 50.09 Gb Total Space | 49.97 Gb Free Space | 99.76% Space Free | Partition Type: NTFS
Drive F: | 1.96 Gb Total Space | 1.94 Gb Free Space | 98.68% Space Free | Partition Type: FAT
Computer Name: ZIMMERMANN-PC | User Name: zimmermann | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/10/31 19:25:18 | 000,683,576 | ---- | M] (Avira Operations GmbH & Co. KG) -- c:\program files\avira\antivir desktop\avgnt.exe
PRC - [2013/07/22 10:09:08 | 000,162,856 | ---- | M] (Geek Software GmbH) -- C:\Program Files\PDF24\pdf24.exe
PRC - [2013/07/09 09:16:56 | 000,302,961 | ---- | M] () -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
PRC - [2013/07/06 09:18:17 | 000,879,456 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2013/05/16 09:59:00 | 003,830,224 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2013/05/16 09:56:34 | 001,033,688 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2013/05/16 09:56:30 | 001,817,560 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2013/05/15 12:21:32 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2012/12/05 13:22:40 | 000,092,632 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2012/12/05 13:22:38 | 000,247,768 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2012/11/23 03:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012/10/05 21:57:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- F:\OTL.exe
PRC - [2011/08/26 20:44:34 | 002,717,696 | ---- | M] (Eastman Kodak Company) -- C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe
PRC - [2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/01/19 10:34:48 | 002,201,192 | ---- | M] (SEC) -- C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
PRC - [2009/11/04 05:11:48 | 000,835,072 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2009/10/26 12:53:14 | 000,091,136 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
PRC - [2009/10/20 10:12:58 | 000,013,312 | ---- | M] (DoctorSoft) -- C:\Program Files\AnyPC Client\APLangApp.exe
PRC - [2009/10/13 11:03:04 | 000,716,800 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2009/08/13 20:58:10 | 000,044,312 | ---- | M] () -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe
PRC - [2009/03/30 11:34:36 | 000,241,664 | ---- | M] () -- C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe
PRC - [2008/10/24 14:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
PRC - [2008/08/10 18:15:22 | 000,221,253 | ---- | M] (Aventail Corporation) -- C:\Windows\System32\ngvpnmgr.exe
========== Modules (No Company Name) ==========
MOD - [2013/07/09 09:16:56 | 000,302,961 | ---- | M] () -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
MOD - [2013/05/16 09:55:28 | 000,161,112 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
MOD - [2013/05/16 09:55:26 | 000,113,496 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2013/05/16 09:55:24 | 000,416,600 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2012/02/17 19:55:35 | 000,166,912 | ---- | M] () -- C:\Program Files\WinRAR\rarext.dll
MOD - [2006/08/12 04:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDWSCService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDUpdateService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDScannerService)
SRV - [2013/11/07 10:48:35 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/10/31 19:25:40 | 000,440,376 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013/10/31 19:25:19 | 001,164,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe -- (AntiVirWebService)
SRV - [2013/10/31 19:25:19 | 000,440,376 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2013/10/10 08:32:39 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/07/09 09:16:56 | 000,285,795 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe -- (HOSTS Anti-PUPs)
SRV - [2013/05/27 05:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2012/12/05 13:22:40 | 000,092,632 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2010/07/28 21:41:11 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2009/08/13 20:58:10 | 000,044,312 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe -- (OberonGameConsoleService)
SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/03/30 11:34:36 | 000,241,664 | ---- | M] () [Auto | Running] -- C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe -- (UI Assistant Service)
SRV - [2008/10/24 14:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService)
SRV - [2008/08/10 18:15:22 | 000,221,253 | ---- | M] (Aventail Corporation) [Auto | Running] -- C:\Windows\System32\ngvpnmgr.exe -- (NgVpnMgr)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\dsNcAdpt.sys -- (dsNcAdpt)
DRV - [2013/10/31 19:25:19 | 000,137,208 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2013/10/31 19:25:19 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2013/10/31 19:25:19 | 000,067,680 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\avnetflt.sys -- (avnetflt)
DRV - [2013/10/31 19:25:19 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012/08/27 14:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2011/03/18 12:46:26 | 000,061,704 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2011/03/18 12:46:10 | 000,073,096 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K)
DRV - [2010/11/23 16:10:44 | 001,249,792 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2010/11/20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/09/28 10:22:00 | 000,315,392 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7)
DRV - [2009/07/14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/10 14:44:52 | 000,122,880 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV - [2009/01/12 09:12:56 | 000,105,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009/01/04 17:29:50 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009/01/04 17:29:50 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2008/12/11 22:11:04 | 000,022,528 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Unknown] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad)
DRV - [2008/12/11 22:11:04 | 000,018,816 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Stopped] -- C:\windows\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2008/10/29 16:35:32 | 000,007,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter.sys -- (massfilter)
DRV - [2008/08/10 18:14:42 | 000,023,192 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ngwfp.sys -- (NgWfp)
DRV - [2008/08/10 18:14:34 | 000,020,632 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ngfilter.sys -- (NgFilter)
DRV - [2008/08/10 18:14:28 | 000,077,464 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ngvpn.sys -- (NgVpn)
DRV - [2008/08/10 18:13:04 | 000,025,240 | ---- | M] (Aventail Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nglog.sys -- (NgLog)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gmx.net/
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{4A2875B3-526E-4CDD-A4CD-55633DC6E280}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=287D2BE5-0407-4EDB-B631-443CCF0E0833&apn_sauid=9B86531E-9EA2-4DE0-A7E5-DF97FB5CD124
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: %7B195A3098-0BD5-4e90-AE22-BA1C540AFD1E%7D:4.0.4
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:25.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@innoplus.de/ino3DViewer: C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\T-Mobile Internet Manager 03\addon [2011/11/03 10:09:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/11/07 10:48:31 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/11/07 10:48:31 | 000,000,000 | ---D | M]
[2013/01/30 20:28:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Extensions
[2013/01/30 20:28:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2013/09/27 09:03:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Firefox\Profiles\ue9nijo9.default\extensions
[2013/05/25 22:14:15 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Users\zimmermann\AppData\Roaming\mozilla\Firefox\Profiles\ue9nijo9.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2013/11/07 10:48:31 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2013/11/07 10:48:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\browser\extensions
[2013/11/07 10:48:36 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ==========
O1 HOSTS File: ([2013/11/12 10:13:17 | 001,587,203 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 212link.com
O1 - Hosts: 127.0.0.1 www.ping2it.com
O1 - Hosts: 127.0.0.1 dl.ividi.org
O1 - Hosts: 127.0.0.1 08sr.combineads.info
O1 - Hosts: 127.0.0.1 08srvr.combineads.info
O1 - Hosts: 127.0.0.1 12srvr.combineads.info
O1 - Hosts: 127.0.0.1 2010-fr.com
O1 - Hosts: 127.0.0.1 2012-new.biz
O1 - Hosts: 127.0.0.1 2319825.ourtoolbar.com
O1 - Hosts: 127.0.0.1 24h00business.com
O1 - Hosts: 127.0.0.1 a.daasafterdusk.com
O1 - Hosts: 127.0.0.1 ad.adn360.com
O1 - Hosts: 127.0.0.1 adeartss.eu
O1 - Hosts: 127.0.0.1 adesoeasy.eu
O1 - Hosts: 127.0.0.1 adf.girldatesforfree.net
O1 - Hosts: 127.0.0.1 adm.soft365.com
O1 - Hosts: 127.0.0.1 adomicileavail.googlepages.com
O1 - Hosts: 127.0.0.1 ads7.complexadveising.com
O1 - Hosts: 127.0.0.1 ads.aff.co
O1 - Hosts: 127.0.0.1 ads.alpha00001.com
O1 - Hosts: 127.0.0.1 ads.cloud4ads.com
O1 - Hosts: 127.0.0.1 ads.eorezo.com
O1 - Hosts: 127.0.0.1 ads.hooqy.com
O1 - Hosts: 127.0.0.1 ads.icksor.com
O1 - Hosts: 127.0.0.1 ads.regiedepub.com
O1 - Hosts: 51303 more lines...
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APLangApp] C:\Program Files\AnyPC Client\APLangApp.exe (DoctorSoft)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [EKAIO2StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [HOSTS Anti-Adware_PUPs] C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe ()
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupControlXP Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.68.161.141 217.68.161.171
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{235AE447-BE14-4A06-914F-D1A7B9BFA633}: DhcpNameServer = 217.68.161.141 217.68.161.171
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{95DE52F9-5E06-47C9-BE22-4B7FE2603F77}: DhcpNameServer = 192.168.168.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~2\browse~1\25911~1.18\{c16c1~1\mngr.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{b130e3cc-05f9-11e1-8855-0024545e3669}\Shell - "" = AutoRun
O33 - MountPoints2\{b130e3cc-05f9-11e1-8855-0024545e3669}\Shell\AutoRun\command - "" = F:\Install.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/11/13 12:56:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2013/11/13 12:56:42 | 000,067,680 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avnetflt.sys
[2013/11/08 10:50:48 | 000,000,000 | ---D | C] -- C:\Users\zimmermann\Desktop\Babyschwimmen
[2013/11/08 10:49:41 | 000,000,000 | ---D | C] -- C:\Users\zimmermann\Desktop\ofen
[2013/11/07 12:19:05 | 000,000,000 | ---D | C] -- C:\Users\zimmermann\Desktop\Maitte
[2013/11/07 10:48:30 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[1 C:\Users\zimmermann\Desktop\*.tmp files -> C:\Users\zimmermann\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/11/13 15:42:42 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2013/11/13 15:42:37 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013/11/13 12:46:58 | 000,014,736 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/11/13 12:46:58 | 000,014,736 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/11/13 11:45:38 | 1579,630,592 | -HS- | M] () -- C:\hiberfil.sys
[2013/11/12 10:57:31 | 000,917,742 | ---- | M] () -- C:\Users\zimmermann\Desktop\avira_fusebundlegen-win32-en.zip
[2013/11/12 10:21:53 | 001,085,542 | ---- | M] () -- C:\Users\zimmermann\Desktop\adwcleaner_3012.exe
[2013/11/12 10:13:17 | 001,587,203 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts
[2013/11/10 18:40:25 | 000,654,400 | ---- | M] () -- C:\windows\System32\perfh007.dat
[2013/11/10 18:40:25 | 000,616,242 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2013/11/10 18:40:25 | 000,130,240 | ---- | M] () -- C:\windows\System32\perfc007.dat
[2013/11/10 18:40:25 | 000,106,622 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2013/11/06 20:16:09 | 000,002,004 | -H-- | M] () -- C:\Users\zimmermann\Documents\Default.rdp
[2013/11/06 19:55:56 | 002,092,618 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts.20131112-101317.backup
[2013/11/01 20:36:39 | 000,184,251 | ---- | M] () -- C:\Users\zimmermann\Desktop\Terasse_ lippoldt.PDF
[2013/10/31 21:28:53 | 000,072,707 | ---- | M] () -- C:\Users\zimmermann\Documents\brandes küchenfliesen.PDF
[2013/10/31 19:25:19 | 000,137,208 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avipbb.sys
[2013/10/31 19:25:19 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avgntflt.sys
[2013/10/31 19:25:19 | 000,067,680 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avnetflt.sys
[2013/10/31 19:25:19 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avkmgr.sys
[2013/10/30 11:38:35 | 000,044,908 | ---- | M] () -- C:\Users\zimmermann\Documents\Rechnung Lidl 202531487 29.10.2013.PDF
[2013/10/29 10:33:18 | 000,084,693 | ---- | M] () -- C:\Users\zimmermann\Desktop\Vertrag Maitte.pdf
[2013/10/23 19:13:10 | 001,448,168 | ---- | M] () -- C:\Users\zimmermann\Documents\Stiftung Warentest Kaminöfen.pdf
[1 C:\Users\zimmermann\Desktop\*.tmp files -> C:\Users\zimmermann\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/11/12 10:55:13 | 000,917,742 | ---- | C] () -- C:\Users\zimmermann\Desktop\avira_fusebundlegen-win32-en.zip
[2013/11/12 10:21:44 | 001,085,542 | ---- | C] () -- C:\Users\zimmermann\Desktop\adwcleaner_3012.exe
[2013/11/01 20:42:34 | 000,184,251 | ---- | C] () -- C:\Users\zimmermann\Desktop\Terasse_ lippoldt.PDF
[2013/10/31 21:32:00 | 000,072,707 | ---- | C] () -- C:\Users\zimmermann\Documents\brandes küchenfliesen.PDF
[2013/10/30 11:39:19 | 000,044,908 | ---- | C] () -- C:\Users\zimmermann\Documents\Rechnung Lidl 202531487 29.10.2013.PDF
[2013/10/29 10:33:13 | 000,084,693 | ---- | C] () -- C:\Users\zimmermann\Desktop\Vertrag Maitte.pdf
[2013/10/23 19:13:10 | 001,448,168 | ---- | C] () -- C:\Users\zimmermann\Documents\Stiftung Warentest Kaminöfen.pdf
[2010/09/06 11:03:51 | 000,011,383 | ---- | C] () -- C:\Users\zimmermann\gsview32.ini
[2010/05/06 16:50:12 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe
========== ZeroAccess Check ==========
[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2010/05/08 11:57:15 | 000,000,000 | -HSD | M] -- C:\Users\zimmermann\AppData\Roaming\.#
[2011/11/03 11:14:25 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Aventail
[2010/12/19 12:11:19 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\elsterformular
[2013/01/10 11:28:55 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Fighters
[2011/04/09 17:39:53 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Foxit Software
[2010/05/08 11:55:33 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\GameConsole
[2011/07/21 15:12:51 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\GARMIN
[2011/11/02 19:22:45 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Go Go Gourmet
[2012/05/28 13:20:19 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\innoplus
[2010/09/01 17:45:20 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Juniper Networks
[2012/08/15 16:27:22 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\LaunchPad
[2012/02/08 10:10:33 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Opera
[2011/11/03 10:09:18 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Program Files
[2011/08/16 17:16:02 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Simfy
[2010/08/22 19:03:59 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\Softland
[2013/01/30 20:28:34 | 000,000,000 | ---D | M] -- C:\Users\zimmermann\AppData\Roaming\TomTom
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2013/01/14 12:14:30 | 002,176,484 | ---- | C] ()(C:\Users\zimmermann\Desktop\_?ALLROUNDER?_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf) -- C:\Users\zimmermann\Desktop\_♥ALLROUNDER♥_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf
[2013/01/14 12:12:28 | 002,176,484 | ---- | M] ()(C:\Users\zimmermann\Desktop\_?ALLROUNDER?_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf) -- C:\Users\zimmermann\Desktop\_♥ALLROUNDER♥_ Teutonia Mistral P 09 Vario Plus Tragetasche Winterfußsack (neu) _ eBay.pdf
========== Alternate Data Streams ==========
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:A42A9F39
< End of report > --- --- ---
Vielen Dank,
ruthie
Hallo Schrauber,
jetzt hat es doch noch funktioniert, keine Ahnung warum. Hier die beiden Files:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-11-2013
Ran by zimmermann (administrator) on ZIMMERMANN-PC on 16-11-2013 17:50:03
Running from C:\Users\zimmermann\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Aventail Corporation) C:\windows\system32\ngvpnmgr.exe
() C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
() C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe
() C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(SEC) C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
(SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(DoctorSoft) C:\Program Files\AnyPC Client\APLangApp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Eastman Kodak Company) C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
(Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\windows\system32\igfxext.exe
(Intel Corporation) C:\windows\system32\igfxsrvc.exe
(Opera Software) C:\Program Files\Opera\opera.exe
(Farbar) C:\Users\zimmermann\Desktop\FRST-1.exe
(Microsoft Corporation) C:\windows\system32\wuauclt.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8120864 2009-12-14] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated)
HKLM\...\Run: [APLangApp] - C:\Program Files\AnyPC Client\APLangApp.exe [13312 2009-10-20] (DoctorSoft)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [] - [x]
HKLM\...\Run: [EKAIO2StatusMonitor] - C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe [2717696 2011-08-26] (Eastman Kodak Company)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [HOSTS Anti-Adware_PUPs] - C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe [302961 2013-07-09] ()
HKLM\...\Run: [PDFPrint] - C:\Program Files\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH)
MountPoints2: {b130e3cc-05f9-11e1-8855-0024545e3669} - F:\Install.exe
AppInit_DLLs: c:\progra~2\browse~1\25911~1.18\{c16c1~1\mngr.dll [ ] ()
Startup: C:\Users\zimmermann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gmx.net/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {4A2875B3-526E-4CDD-A4CD-55633DC6E280} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=287D2BE5-0407-4EDB-B631-443CCF0E0833&apn_sauid=9B86531E-9EA2-4DE0-A7E5-DF97FB5CD124
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 217.68.161.141 217.68.161.171
FireFox:
========
FF ProfilePath: C:\Users\zimmermann\AppData\Roaming\Mozilla\Firefox\Profiles\ue9nijo9.default
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @garmin.com/GpsControl - C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin: @innoplus.de/ino3DViewer - C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden)
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Garmin Communicator - C:\Users\zimmermann\AppData\Roaming\Mozilla\Firefox\Profiles\ue9nijo9.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
FF HKLM\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile Internet Manager 03\addon
FF Extension: Bytemobile Optimization Client - C:\Program Files\T-Mobile Internet Manager 03\addon
Chrome:
=======
========================== Services (Whitelisted) =================
R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S2 HOSTS Anti-PUPs; C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe [285795 2013-07-09] ()
R2 NgVpnMgr; C:\windows\system32\ngvpnmgr.exe [221253 2008-08-10] (Aventail Corporation)
R2 OberonGameConsoleService; C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe [44312 2009-08-13] ()
R2 UI Assistant Service; C:\Program Files\T-Mobile Internet Manager 03\AssistantServices.exe [241664 2009-03-30] ()
==================== Drivers (Whitelisted) ====================
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [61704 2011-03-18] (FTDI Ltd.)
S3 grmnusb; C:\Windows\System32\drivers\grmnusb.sys [9344 2009-04-17] (GARMIN Corp.)
S3 MBAMSwissArmy; C:\windows\system32\drivers\mbamswissarmy.sys [40776 2013-11-14] (Malwarebytes Corporation)
S3 NgFilter; C:\Windows\System32\DRIVERS\ngfilter.sys [20632 2008-08-10] (Aventail Corporation)
R3 NgLog; C:\Windows\System32\DRIVERS\nglog.sys [25240 2008-08-10] (Aventail Corporation)
R3 NgVpn; C:\Windows\System32\DRIVERS\ngvpn.sys [77464 2008-08-10] (Aventail Corporation)
R3 NgWfp; C:\Windows\System32\DRIVERS\ngwfp.sys [23192 2008-08-10] (Aventail Corporation)
R1 SABI; C:\windows\system32\Drivers\SABI.sys [10752 2009-05-28] (SAMSUNG ELECTRONICS)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
S3 dsNcAdpt; system32\DRIVERS\dsNcAdpt.sys [x]
U3 kfryrpod; \??\C:\Users\ZIMMER~1\AppData\Local\Temp\kfryrpod.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-16 17:50 - 2013-11-16 17:50 - 00011304 _____ C:\Users\zimmermann\Desktop\FRST.txt
2013-11-16 17:50 - 2013-11-16 17:50 - 00000000 ____D C:\FRST
2013-11-15 22:53 - 2013-04-04 13:45 - 00377856 _____ C:\Users\zimmermann\Desktop\gmer_2.1.19163.exe
2013-11-15 22:28 - 2013-11-14 00:02 - 01090529 _____ (Farbar) C:\Users\zimmermann\Desktop\FRST-1.exe
2013-11-15 22:10 - 2013-11-15 22:16 - 00000482 _____ C:\Users\zimmermann\Desktop\defogger_disable.log
2013-11-15 22:10 - 2013-11-15 22:10 - 00000000 _____ C:\Users\zimmermann\defogger_reenable
2013-11-15 22:04 - 2013-11-15 21:52 - 00050477 _____ C:\Users\zimmermann\Desktop\Defogger.exe
2013-11-15 00:15 - 2013-11-15 00:15 - 00000079 _____ C:\windows\wininit.ini
2013-11-15 00:09 - 2013-11-15 00:09 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2013-11-14 18:52 - 2013-11-14 18:52 - 00040776 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamswissarmy.sys
2013-11-14 18:33 - 2013-11-12 10:13 - 01587203 _____ C:\windows\system32\Drivers\etc\hosts.20131114-183350.backup
2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\Malwarebytes
2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-14 18:16 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2013-11-14 18:16 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2013-11-14 18:16 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2013-11-14 18:16 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-11-14 18:16 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
2013-11-14 18:16 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2013-11-14 18:16 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\credui.dll
2013-11-14 18:16 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2013-11-14 18:16 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2013-11-14 18:16 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2013-11-14 18:16 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2013-11-14 18:16 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2013-11-14 18:16 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2013-11-14 18:16 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2013-11-14 18:16 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2013-11-14 18:16 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2013-11-14 18:16 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2013-11-14 18:16 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2013-11-14 10:47 - 2013-10-12 08:04 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-11-14 10:47 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-11-14 10:47 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-11-14 10:47 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-11-14 10:47 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-11-14 10:47 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-11-14 10:47 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-11-14 10:47 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-11-14 10:47 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-11-14 10:47 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-11-14 10:47 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-11-14 10:47 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-11-14 10:47 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-11-14 10:47 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-11-14 10:47 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-11-14 10:47 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-11-13 18:52 - 2013-11-12 10:13 - 01587203 ____R C:\windows\system32\Drivers\etc\hosts.20131113-185208.backup
2013-11-13 12:54 - 2013-11-13 12:55 - 126764512 _____ C:\Users\zimmermann\Downloads\avira_free_antivirus_de.exe
2013-11-12 10:55 - 2013-11-12 10:57 - 00917742 _____ C:\Users\zimmermann\Desktop\avira_fusebundlegen-win32-en.zip
2013-11-12 10:21 - 2013-11-12 10:21 - 01085542 _____ C:\Users\zimmermann\Desktop\adwcleaner_3012.exe
2013-11-12 10:13 - 2013-11-06 19:55 - 02092618 _____ C:\windows\system32\Drivers\etc\hosts.20131112-101317.backup
2013-11-07 12:19 - 2013-11-07 12:19 - 00000000 ____D C:\Users\zimmermann\Desktop\Maitte
2013-11-07 10:48 - 2013-11-13 18:12 - 00000000 ____D C:\Program Files\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2013-11-16 17:50 - 2013-11-16 17:50 - 00011304 _____ C:\Users\zimmermann\Desktop\FRST.txt
2013-11-16 17:50 - 2013-11-16 17:50 - 00000000 ____D C:\FRST
2013-11-16 17:49 - 2012-06-24 11:23 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-11-16 17:49 - 2009-12-05 03:40 - 01866928 _____ C:\windows\WindowsUpdate.log
2013-11-15 22:29 - 2009-07-14 05:34 - 00014736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-15 22:29 - 2009-07-14 05:34 - 00014736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-15 22:16 - 2013-11-15 22:10 - 00000482 _____ C:\Users\zimmermann\Desktop\defogger_disable.log
2013-11-15 22:10 - 2013-11-15 22:10 - 00000000 _____ C:\Users\zimmermann\defogger_reenable
2013-11-15 22:10 - 2010-05-06 16:48 - 00000000 ____D C:\Users\zimmermann
2013-11-15 22:05 - 2009-07-26 21:06 - 01498742 _____ C:\windows\system32\PerfStringBackup.INI
2013-11-15 21:52 - 2013-11-15 22:04 - 00050477 _____ C:\Users\zimmermann\Desktop\Defogger.exe
2013-11-15 00:15 - 2013-11-15 00:15 - 00000079 _____ C:\windows\wininit.ini
2013-11-15 00:15 - 2013-07-09 09:21 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2013-11-15 00:09 - 2013-11-15 00:09 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2013-11-14 23:53 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\NDF
2013-11-14 23:28 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-11-14 23:27 - 2009-07-14 05:39 - 00138020 _____ C:\windows\setupact.log
2013-11-14 23:27 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\de-DE
2013-11-14 20:22 - 2010-05-06 16:57 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-14 19:25 - 2009-12-05 04:19 - 00968620 _____ C:\windows\PFRO.log
2013-11-14 18:52 - 2013-11-14 18:52 - 00040776 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamswissarmy.sys
2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\Malwarebytes
2013-11-14 18:24 - 2013-11-14 18:24 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-14 10:47 - 2013-07-26 09:49 - 00000000 ____D C:\windows\system32\MRT
2013-11-14 10:45 - 2010-06-22 07:34 - 80340640 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-11-14 00:02 - 2013-11-15 22:28 - 01090529 _____ (Farbar) C:\Users\zimmermann\Desktop\FRST-1.exe
2013-11-13 18:12 - 2013-11-07 10:48 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-13 17:32 - 2010-11-24 11:13 - 00927232 ___SH C:\Users\zimmermann\Desktop\Thumbs.db
2013-11-13 12:55 - 2013-11-13 12:54 - 126764512 _____ C:\Users\zimmermann\Downloads\avira_free_antivirus_de.exe
2013-11-13 11:30 - 2013-08-29 16:12 - 00009284 _____ C:\Users\zimmermann\Desktop\Hochzeit.xlsx
2013-11-12 10:57 - 2013-11-12 10:55 - 00917742 _____ C:\Users\zimmermann\Desktop\avira_fusebundlegen-win32-en.zip
2013-11-12 10:28 - 2013-08-27 20:11 - 00000000 ____D C:\AdwCleaner
2013-11-12 10:21 - 2013-11-12 10:21 - 01085542 _____ C:\Users\zimmermann\Desktop\adwcleaner_3012.exe
2013-11-12 10:13 - 2013-11-14 18:33 - 01587203 _____ C:\windows\system32\Drivers\etc\hosts.20131114-183350.backup
2013-11-12 10:13 - 2013-11-13 18:52 - 01587203 ____R C:\windows\system32\Drivers\etc\hosts.20131113-185208.backup
2013-11-08 20:33 - 2012-03-11 17:41 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\vlc
2013-11-08 20:26 - 2012-07-07 18:29 - 00000000 ____D C:\Users\zimmermann\AppData\Roaming\dvdcss
2013-11-07 12:19 - 2013-11-07 12:19 - 00000000 ____D C:\Users\zimmermann\Desktop\Maitte
2013-11-06 20:16 - 2011-11-03 11:16 - 00002004 ____H C:\Users\zimmermann\Documents\Default.rdp
2013-11-06 19:55 - 2013-11-12 10:13 - 02092618 _____ C:\windows\system32\Drivers\etc\hosts.20131112-101317.backup
2013-10-22 18:00 - 2009-07-14 03:37 - 00000000 ____D C:\windows\rescache
Some content of TEMP:
====================
C:\Users\zimmermann\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-10 19:21
==================== End Of Log ============================ --- --- ---
--- --- ---
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 14-11-2013
Ran by zimmermann at 2013-11-16 17:50:44
Running from C:\Users\zimmermann\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
==================== Installed Programs ======================
Update for Microsoft Office 2007 (KB2508958)
3D-Viewer-innoplus (Version: 14.00.70)
AAVUpdateManager (Version: 16.00.0000)
Adobe AIR (Version: 2.7.1.19610)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Reader 9.5.1 - Deutsch (Version: 9.5.1)
AnyPC Client (Version: 1.0.0.23)
Atheros Client Installation Program (Version: 1.0.1.0805)
Aventail Connect (Version: 9.1.33)
BatteryLifeExtender (Version: 1.0.1)
Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000)
doPDF 7.1 printer
Easy Display Manager (Version: 3.0)
Easy Network Manager (Version: 4.2.6)
Easy SpeedUp Manager (Version: 3.0.0.5)
EasyBatteryManager (Version: 4.0.0.3)
Edna Bricht Aus - Sammler Edition (Version: 1.0)
Foxit Reader (Version: 4.3.1.323)
Game Pack (Version: 5.3.0.10)
Garmin BaseCamp (Version: 3.2.1)
Garmin TransAlpin v2 (Version: 2.0.0.0)
Garmin USB Drivers (Version: 2.3.0.0)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Intel(R) Graphics Media Accelerator Driver (Version: 8.15.10.2202)
Intel® Matrix Storage Manager
Java 7 Update 25 (Version: 7.0.250)
Java Auto Updater (Version: 2.1.9.5)
Junk Mail filter update (Version: 14.0.8089.726)
Marvell Miniport Driver (Version: 11.22.3.3)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Choice Guard (Version: 2.0.48.0)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1)
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Suite Activation Assistant (Version: 2.9)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual Basic 6.0 Enterprise Edition (Deutsch)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (Version: 10.0.40303)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (Version: 10.0.40308)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU (Version: 10.0.40303)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (Version: 10.0.40303)
Microsoft Web Publishing Wizard 1.53
Microsoft Works (Version: 9.7.0621)
MSVCRT (Version: 14.0.1468.721)
Opera 12.16 (Version: 12.16.1860)
PDF24 Creator 5.7.0
Realtek High Definition Audio Driver (Version: 6.0.1.6003)
Samsung Recovery Solution 4 (Version: 4.0.0.6)
Samsung Support Center (Version: 1.0.21)
Samsung Update Plus (Version: 2.0)
Steuer-Spar-Erklärung 2011 (Version: 16.06)
Synaptics Pointing Device Driver (Version: 15.0.10.0)
T-Mobile Internet Manager 03 (Version: 1.0.0.1)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825642) 32-Bit Edition
Update für Microsoft Office Excel 2007 Help (KB963678)
Update für Microsoft Office Outlook 2007 Help (KB963677)
Update für Microsoft Office Powerpoint 2007 Help (KB963669)
Update für Microsoft Office Word 2007 Help (KB963665)
User Guide (Version: 1.0)
VLC media player 2.0.1 (Version: 2.0.1)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) (Version: 06/03/2009 2.3.0.0)
Windows Live Call (Version: 14.0.8064.0206)
Windows Live Communications Platform (Version: 14.0.8064.206)
Windows Live Essentials (Version: 14.0.8089.0726)
Windows Live Essentials (Version: 14.0.8089.726)
Windows Live Family Safety (Version: 14.0.8093.805)
Windows Live Fotogalerie (Version: 14.0.8081.709)
Windows Live ID-Anmelde-Assistent (Version: 6.500.3165.0)
Windows Live Mail (Version: 14.0.8089.0726)
Windows Live Messenger (Version: 14.0.8089.0726)
Windows Live Movie Maker (Version: 14.0.8091.0730)
Windows Live Sync (Version: 14.0.8089.726)
Windows Live Writer (Version: 14.0.8089.0726)
Windows Live-Uploadtool (Version: 14.0.8014.1029)
WinRAR 4.11 (32-Bit) (Version: 4.11.0)
==================== Restore Points =========================
22-08-2013 18:26:12 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2009-07-14 03:04 - 2013-11-12 10:13 - 01587203 ____N C:\windows\system32\Drivers\etc\hosts
127.0.0.1 212link.com
127.0.0.1 www.ping2it.com
127.0.0.1 dl.ividi.org
127.0.0.1 08sr.combineads.info
127.0.0.1 08srvr.combineads.info
127.0.0.1 12srvr.combineads.info
127.0.0.1 2010-fr.com
127.0.0.1 2012-new.biz
127.0.0.1 2319825.ourtoolbar.com
127.0.0.1 24h00business.com
127.0.0.1 a.daasafterdusk.com
127.0.0.1 ad.adn360.com
127.0.0.1 adeartss.eu
127.0.0.1 adesoeasy.eu
127.0.0.1 adf.girldatesforfree.net
127.0.0.1 adm.soft365.com
127.0.0.1 adomicileavail.googlepages.com
127.0.0.1 ads7.complexadveising.com
127.0.0.1 ads.aff.co
127.0.0.1 ads.alpha00001.com
127.0.0.1 ads.cloud4ads.com
127.0.0.1 ads.eorezo.com
127.0.0.1 ads.hooqy.com
127.0.0.1 ads.icksor.com
127.0.0.1 ads.regiedepub.com
127.0.0.1 ads.sucomspot.com
127.0.0.1 ads.tersecta.com
127.0.0.1 a.dungtank.com
127.0.0.1 adwcleaner.programmesetjeux.com
There are 1000 more lines.
==================== Scheduled Tasks (whitelisted) =============
Task: {210FA61D-92F6-4FEE-B312-06AF7D4D93D5} - System32\Tasks\APSchedulerC => C:\Program Files\AnyPC Client\APLanMgrC.exe [2009-10-20] (DoctorSoft)
Task: {2D577A20-059C-43FE-B6C0-1FB82EC956F8} - System32\Tasks\BatteryLifeExtender => C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2009-11-19] (Samsung Electronics. Co. Ltd.)
Task: {48A6287D-9267-44E7-99FD-21FCA0982FF8} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe [2010-04-20] ()
Task: {56D2FA95-1D75-45C8-90A0-CB573A6E4439} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-10] (Adobe Systems Incorporated)
Task: {5F228EBA-627F-4F7A-99DA-16995E5B9D76} - System32\Tasks\advSRS4 => C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2010-01-19] (SEC)
Task: {88A49655-48B3-4C5D-8CD2-9B43A4A79D2F} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2009-11-04] (Samsung Electronics Co., Ltd.)
Task: {8D4D5684-8FAB-4077-95EB-C9C0BBB68E80} - System32\Tasks\EasySpeedUpManager => C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe [2009-10-13] (Samsung Electronics Co., Ltd.)
Task: {9A171F4D-432A-42AF-A3CC-EBCB4A1C5430} - System32\Tasks\SamsungSupportCenter => C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [2009-10-26] (SAMSUNG Electronics)
Task: {A27BCA4D-2345-41B2-B23F-C1C1C656C2F4} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation)
Task: {B0B9B8F6-0C8D-4755-997C-110671056F18} - System32\Tasks\VisualBeeRecovery => C:\Users\zimmermann\AppData\Local\VisualBeeExe\VisualBeeRecovery.exe
Task: {CC0D875C-93E1-46F8-B7B7-80E0B3BCFA41} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2009-10-16] (SAMSUNG Electronics co., LTD.)
Task: {E4D704BA-DD15-44B2-A951-16E1AAAB8843} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2012-04-21 17:40 - 2012-02-17 19:55 - 00166912 _____ () C:\Program Files\WinRAR\rarext.dll
2009-12-05 03:54 - 2006-08-12 04:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\Temp:A42A9F39
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (11/16/2013 11:55:54 AM) (Source: System Restore) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x80042308).
Error: (11/16/2013 11:55:54 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Volume bzw. Datenträger ist nicht richtig angeschlossen oder wurde nicht gefunden.
Fehlerkontext: GetComputerNameEx(3, NULL, [0]) [0].
Vorgang:
BeginPrepareSnapshot wird verarbeitet
Snapshotkontext
Kontext:
Ausführungskontext: System Provider
Volumename: \\?\Volume{edcff9ed-e1d4-11de-abe6-806e6f6e6963}\
Snapshot-ID: {74dbca27-4965-44e4-b10e-a448e13bfb79}
Error: (11/15/2013 10:54:38 PM) (Source: Application Hang) (User: )
Description: Programm gmer_2.1.19163.exe, Version 2.1.19163.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 14f0
Startzeit: 01cee24d34810fc8
Endzeit: 16
Anwendungspfad: C:\Users\zimmermann\Desktop\gmer_2.1.19163.exe
Berichts-ID: 8182d7cd-4e40-11e3-89dc-415645000030
Error: (11/15/2013 10:48:31 PM) (Source: Application Hang) (User: )
Description: Programm FRST-1.exe, Version 3.3.8.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1348
Startzeit: 01cee24c03335286
Endzeit: 32
Anwendungspfad: C:\Users\zimmermann\Desktop\FRST-1.exe
Berichts-ID: a5178cb1-4e3f-11e3-89dc-415645000030
Error: (11/15/2013 10:30:07 PM) (Source: Application Hang) (User: )
Description: Programm FRST-1.exe, Version 3.3.8.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 162c
Startzeit: 01cee2499dc77558
Endzeit: 16
Anwendungspfad: C:\Users\zimmermann\Desktop\FRST-1.exe
Berichts-ID: f8d139da-4e3c-11e3-89dc-415645000030
Error: (11/15/2013 10:25:10 PM) (Source: Application Hang) (User: )
Description: Programm FRST.exe, Version 3.3.8.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: e84
Startzeit: 01cee2491d9a3cc7
Endzeit: 31
Anwendungspfad: C:\Users\zimmermann\Desktop\FRST.exe
Berichts-ID: 6548104f-4e3c-11e3-89dc-415645000030
Error: (11/15/2013 10:24:20 PM) (Source: Application Hang) (User: )
Description: Programm FRST.exe, Version 3.3.8.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: fbc
Startzeit: 01cee248e32f50de
Endzeit: 31
Anwendungspfad: C:\Users\zimmermann\Desktop\FRST.exe
Berichts-ID: 452ffc0d-4e3c-11e3-89dc-415645000030
Error: (11/15/2013 00:01:05 AM) (Source: Application Hang) (User: )
Description: Programm iexplore.exe, Version 10.0.9200.16736 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1638
Startzeit: 01cee18c6fd5a75d
Endzeit: 32
Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe
Berichts-ID:
Error: (11/14/2013 11:50:48 PM) (Source: Application Hang) (User: )
Description: Programm DllHost.exe, Version 6.1.7600.16385 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 414
Startzeit: 01cee18bc6cccfc8
Endzeit: 16
Anwendungspfad: C:\windows\system32\DllHost.exe
Berichts-ID: 2ce27710-4d7f-11e3-89dc-415645000030
Error: (11/14/2013 11:41:03 PM) (Source: Application Hang) (User: )
Description: Programm DllHost.exe, Version 6.1.7600.16385 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 139c
Startzeit: 01cee18a26fe7c20
Endzeit: 0
Anwendungspfad: C:\windows\system32\DllHost.exe
Berichts-ID: 9cae6874-4d7d-11e3-89dc-415645000030
System errors:
=============
Error: (11/16/2013 05:50:44 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst LanmanWorkstation erreicht.
Error: (11/16/2013 05:50:14 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht.
Error: (11/16/2013 05:49:44 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht.
Error: (11/16/2013 11:48:51 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht.
Error: (11/16/2013 11:43:32 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht.
Error: (11/16/2013 11:43:02 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht.
Error: (11/16/2013 11:42:32 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst LanmanWorkstation erreicht.
Error: (11/16/2013 11:42:02 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht.
Error: (11/16/2013 11:41:32 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht.
Error: (11/15/2013 10:42:31 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht.
Microsoft Office Sessions:
=========================
Error: (12/31/2011 00:21:41 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3 seconds with 0 seconds of active time. This session ended with a crash.
Error: (12/31/2011 00:15:32 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4 seconds with 0 seconds of active time. This session ended with a crash.
Error: (12/31/2011 00:13:00 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8 seconds with 0 seconds of active time. This session ended with a crash.
Error: (12/31/2011 00:05:12 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2 seconds with 0 seconds of active time. This session ended with a crash.
Error: (07/19/2011 03:26:55 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6557.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 17601 seconds with 540 seconds of active time. This session ended with a crash.
Error: (04/28/2011 03:36:25 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6 seconds with 0 seconds of active time. This session ended with a crash.
Error: (03/08/2011 04:19:42 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 19069 seconds with 480 seconds of active time. This session ended with a crash.
Error: (03/02/2011 09:21:14 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 11 seconds with 0 seconds of active time. This session ended with a crash.
Error: (09/05/2010 11:12:31 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6535.5002, Microsoft Office Version: 12.0.6425.1000. This session lasted 260 seconds with 0 seconds of active time. This session ended with a crash.
Error: (09/03/2010 00:04:32 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 11832 seconds with 1920 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Percentage of memory in use: 41%
Total physical RAM: 2008.61 MB
Available physical RAM: 1179.36 MB
Total Pagefile: 4017.21 MB
Available Pagefile: 2966.48 MB
Total Virtual: 2047.88 MB
Available Virtual: 1909.88 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:167.69 GB) (Free:52.33 GB) NTFS
Drive d: () (Fixed) (Total:50.09 GB) (Free:49.97 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 233 GB) (Disk ID: 0E0EF5DF)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=168 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=50 GB) - (Type=07 NTFS)
==================== End Of Log ============================ --- --- --- |