![]() |
zu hoher Datenverbrauch, Malware Hallo, seit ein paar Tagen habe ich Probleme mit meinem PC/Vista (32bit). Ich gehe mit einem mobilcom debitel Stick (O2) ins Internet und habe mir wohl einiges eingefangen. Wenn ich den Stick starte, habe ich schon einen hohen Datenverbrauch, ohne irgendwas zu machen. Öffne ich dann Google Chrome Brower (habe alternativ auch Iron getestet) verbrauche ich 10x mehr als üblich. Besonders der upload ist sehr hoch und es läd weiter, obwohl ich nichts mehr mache. Gestern habe ich 4 verschiedene Anti Virus Programme geladen, bis ich einen gefunden habe, mit dem ich Malware kostenlos entfernen kann, aber das Problem wurde nicht wirklich behoben. In einem anderen Tread habe ich gesehen, das man einen Farbar Recovery Scan machen soll und dort finde ich beängstigende links von www.007guard.com angefangen, über 100sexlinks.com bis 123haustiereundmehr.com, die ich aber nie geöffnet habe. Was kann ich nun tun, um meinen PC zu reinigen? Da ich viele Pics gespeichert habe und mich allgemein nicht sehr gut auskenne, ist formatieren nicht so die beste Lösung. Vielen Dank schon mal. |
hi, Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
Das ist der Addition-Editor (ich habe den Tex kopiert, das ist ja ganz schön viel, wusste nicht, wie ich das sonst alles einfügen sollte^^): ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-891572633-1774761820-252287049-1000_Classes\CLSID\{3f04dadf-6ea4-44d1-a507-03cad176f443}\InprocServer32 -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.) CustomCLSID: HKU\S-1-5-21-891572633-1774761820-252287049-1000_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Sandra\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS) CustomCLSID: HKU\S-1-5-21-891572633-1774761820-252287049-1000_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\Sandra\AppData\Local\Google\Update\1.3.22.3\psuser.dll No File CustomCLSID: HKU\S-1-5-21-891572633-1774761820-252287049-1000_Classes\CLSID\{EB06378B-ABB6-4B3C-9B40-D488DD8A6E93}\InprocServer32 -> C:\Users\Sandra\AppData\Local\Google\Update\1.3.22.5\psuser.dll No File ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 12:23 - 2010-08-07 16:12 - 00415906 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123fporn.info 127.0.0.1 www.123fporn.info 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com There are 1000 more lines. ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {04672349-6C87-4543-9E6C-29D0CCC90F34} - \GPUP No Task File <==== ATTENTION Task: {05C028A0-C11B-4F15-B923-6B0DCD16EC40} - \f08de44e-751a-4092-ad9e-9c9a07ee0606-2 No Task File <==== ATTENTION Task: {06B3ECA7-D67D-4DAE-A65C-4A16AA407F52} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-07-24] (Google Inc.) Task: {127E4671-C565-43C0-A807-EDAA43B6BE0E} - \f08de44e-751a-4092-ad9e-9c9a07ee0606-1 No Task File <==== ATTENTION Task: {17C0D0B4-5297-416C-89B6-70D62348D1AE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {1D03FC86-0B87-442D-A3F6-00565DC6AD8D} - System32\Tasks\update-sys => C:\Program Files\Skillbrains\Updater\Updater.exe [2014-03-25] () Task: {279DCF4B-0AAA-4E8C-96A7-BC8E6FE40037} - System32\Tasks\ScanSoft Background Update => C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe Task: {3242C53A-87B1-4E03-A12D-E65046410206} - System32\Tasks\{BBC0DD05-563E-45DE-94E3-3D78AA7B2DA8} => C:\Program Files\Skype\Phone\Skype.exe Task: {4599A9A7-2950-49DA-9642-DFABDDB5A0CE} - \f08de44e-751a-4092-ad9e-9c9a07ee0606-3 No Task File <==== ATTENTION Task: {4A8AE827-7072-4A34-8F33-77D2F9805363} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Sandra => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-10] (Microsoft Corporation) Task: {4C2DE83B-06EF-4D34-8F6A-CF64C36B082D} - \1a7b6d14-5032-407e-918a-1cdab2120f8e-3 No Task File <==== ATTENTION Task: {4FA0E1BD-A5D1-4902-910A-FF8524AE7147} - System32\Tasks\{9E9A01BD-BCCD-4B27-9326-E45F95CFF5CD} => pcalua.exe -a "C:\Program Files\RealArcade\Installer\bin\gameinstaller.exe" -d C:\Users\Sandra\Desktop -c "C:\Program Files\RealArcade\Installer\bin\..\installerMain.clf" "C:\Users\Sandra\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5WVGCSFN\gameInitializer[1].rgi" Task: {590E9503-34A9-4868-99E3-5CDAAA16A602} - System32\Tasks\update-S-1-5-21-891572633-1774761820-252287049-1000 => C:\Program Files\Skillbrains\Updater\Updater.exe [2014-03-25] () Task: {6606CB3F-EFF4-4107-A848-B7029DE6EFB3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-14] (Adobe Systems Incorporated) Task: {69549D7C-CF36-47DD-A3E2-C9704D2A15C1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {6CA740DB-A552-42D6-8E81-453A8862BAC2} - \AmiUpdXp No Task File <==== ATTENTION Task: {78EAAA95-67B2-48D8-B67E-2CE5B38B3E82} - \1a7b6d14-5032-407e-918a-1cdab2120f8e-4 No Task File <==== ATTENTION Task: {7B3DBA45-99C5-4216-B2EF-E1CCA5D108B9} - System32\Tasks\{FA5F355F-9358-4DC5-9301-C2395B9662E9} => pcalua.exe -a C:\Users\Sandra\Documents\vlc-1.0.3-win32.exe -d C:\Users\Sandra\Documents Task: {856ED67D-DEF9-447F-82D4-B8D739621AD8} - \f08de44e-751a-4092-ad9e-9c9a07ee0606-5 No Task File <==== ATTENTION Task: {88A46644-2A4D-4B05-9655-D38622DCC782} - System32\Tasks\{BC4D9D0F-7DF9-421D-A196-5DF2608A37C5} => pcalua.exe -a C:\Users\Sandra\Desktop\streamripper-windows-installer-1.64.6.exe -d C:\Users\Sandra\Desktop Task: {96BCD58D-B94D-4717-8068-89EDB44C6EA5} - System32\Tasks\{41BFFA87-B312-43F9-AE86-C48DDF479674} => pcalua.exe -a "C:\Users\Sandra\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q9I9INF2\gamesplayerinstall.exe" -d C:\Users\Sandra\Desktop Task: {A51642B9-2DC1-4268-9DD6-1D5F5FC1F573} - \SimpleFiles Installer Starter No Task File <==== ATTENTION Task: {B8E12A15-CD06-4C84-9B38-0B43993598C4} - System32\Tasks\{B9615E8E-AFEA-4B25-8042-16B0D1EC9B17} => pcalua.exe -a "C:\Users\Sandra\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MNAY72AE\IE8-Setup-Full-32[1].exe" -d C:\Users\Sandra\Desktop Task: {C2A98972-5255-46A0-BA57-0BAA9F59F799} - System32\Tasks\{4BB544CD-66D4-419C-B209-BEEE863EAFF5} => pcalua.exe -a C:\Users\Sandra\Desktop\softonic-Deutsch.exe -d C:\Users\Sandra\Desktop <==== ATTENTION Task: {C6B5B700-5F50-4BDF-AFE0-8FAC63AC5F50} - System32\Tasks\AFC Secure Net Task => C:\Program Files\AFC Secure Net\amjob.exe <==== ATTENTION Task: {CF87E585-8CF9-44D9-92B1-70DF85502219} - System32\Tasks\Google Updater and Installer => C:\Users\Sandra\AppData\Local\Google\Update\GoogleUpdate.exe Task: {D0260882-6FD0-4214-9AA5-A85C10C79D2E} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {D26D54EB-ED86-4549-AA55-10AFD4BF6595} - System32\Tasks\Program Security Task => C:\Program Files\Program Security\ProgramSecurity.exe [2015-04-08] (Secure Updater) Task: {D7CC05C7-2469-4295-A0B3-C7B55306AFB5} - System32\Tasks\{C02FE5B2-2FE4-419B-9D53-4B5CBF562CDE} => pcalua.exe -a C:\Users\Sandra\Desktop\Download\qc848deu.exe -d C:\Users\Sandra\Desktop\Download Task: {E7C317C7-946E-43E5-A9B5-61E1572C5722} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-12-17] (Oracle Corporation) Task: {EEDC6659-64C5-480B-8B1C-FE772757C3D2} - \f08de44e-751a-4092-ad9e-9c9a07ee0606-4 No Task File <==== ATTENTION Task: {F8DA7A8C-6417-4D00-A265-E23F812C0583} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\TuneUp Utilities 2013\OneClick.exe Task: {FADB5DAD-656F-432B-98A7-7AE8CB0CBDFA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-07-24] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\update-S-1-5-21-891572633-1774761820-252287049-1000.job => C:\Program Files\Skillbrains\Updater\Updater.exe Task: C:\Windows\Tasks\update-sys.job => C:\Program Files\Skillbrains\Updater\Updater.exe ==================== Loaded Modules (Whitelisted) ============== 2014-09-22 08:39 - 2012-03-14 12:05 - 00053312 _____ () C:\Program Files\Sparhandy Modem\BackgroundService\ServiceManager.exe 2014-09-09 10:03 - 2013-04-15 18:40 - 00329872 ____N () C:\Program Files\XSManager\WTGService.exe 2014-09-22 08:39 - 2012-10-29 13:08 - 00118784 _____ () C:\Program Files\Sparhandy Modem\BackgroundService\ModemListener.exe 2013-12-31 23:46 - 2013-12-12 21:56 - 03145536 _____ () C:\Users\Sandra\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe 2014-03-23 18:49 - 2010-05-13 10:41 - 00594432 _____ () C:\Program Files\congstar\Internetmanager\Bin\dbus-1.dll 2014-03-23 18:49 - 2010-05-13 10:41 - 00157696 _____ () C:\Program Files\congstar\Internetmanager\Bin\libgconf-2.dll 2014-03-23 18:49 - 2010-06-17 09:53 - 00089600 _____ () C:\Program Files\congstar\Internetmanager\Bin\itapi.dll 2014-03-23 18:49 - 2008-05-06 13:50 - 00971776 _____ () C:\Program Files\congstar\Internetmanager\Bin\libxml2.dll 2014-03-23 18:49 - 2009-03-28 09:19 - 00080688 _____ () C:\Program Files\congstar\Internetmanager\Bin\zlib1.dll 2014-03-23 18:49 - 2010-06-17 09:53 - 00054272 _____ () C:\Program Files\congstar\Internetmanager\Bin\coder.dll 2014-03-23 18:49 - 2010-06-17 09:53 - 00025088 _____ () C:\Program Files\congstar\Internetmanager\Bin\log.dll 2014-03-23 18:49 - 2010-06-17 09:53 - 00043008 _____ () C:\Program Files\congstar\Internetmanager\Bin\audio.dll 2014-03-23 18:49 - 2010-06-12 08:10 - 00034304 _____ () C:\Program Files\congstar\Internetmanager\Bin\libctlsvr.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 02091152 ____N () C:\Program Files\XSManager\XSManager.exe 2014-09-09 10:03 - 2013-04-15 18:40 - 00018576 ____N () C:\Program Files\XSManager\WTGDebugs.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00399504 ____N () C:\Program Files\XSManager\WtgCore.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00049808 ____N () C:\Program Files\XSManager\WtgDriverInstall.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00231568 ____N () C:\Program Files\XSManager\WtgUtil.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00186512 ____N () C:\Program Files\XSManager\WtgDetection.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00092304 ____N () C:\Program Files\XSManager\WtgPorts.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00112784 ____N () C:\Program Files\XSManager\WtgDatabase.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00084112 ____N () C:\Program Files\XSManager\WtgDialup.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00145552 ____N () C:\Program Files\XSManager\WtgBluetooth.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 01374352 ____N () C:\Program Files\XSManager\4GSystems_OneClickAssistantGer.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00604304 ____N () C:\Program Files\XSManager\WTGXMLUtil.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00202896 ____N () C:\Program Files\XSManager\WTGSMSPCClient.Dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00011920 ____N () C:\Program Files\XSManager\4GSystems_WTGSMSPCClientGer.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00018064 ____N () C:\Program Files\XSManager\WTGDriverInstallX.Dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00263312 ____N () C:\Program Files\XSManager\WtgMobileBroadband7.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00546960 ____N () C:\Program Files\XSManager\WtgNdisQmiUtil.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 01374352 ____N () C:\Program Files\XSManager\NDISDirectDial.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00028304 ____N () C:\Program Files\XSManager\LogModule.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00084112 ____N () C:\Program Files\XSManager\ToolKit.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00067728 ____N () C:\Program Files\XSManager\tinyxml.dll 2014-09-09 10:03 - 2013-04-15 18:40 - 00444560 ____N () C:\Program Files\XSManager\sqlite3.dll 2014-03-23 18:49 - 2010-05-13 10:42 - 00215552 _____ () C:\Program Files\congstar\Internetmanager\Bin\dbus-daemon.exe 2014-03-23 18:49 - 2007-09-09 17:07 - 00151552 _____ () C:\Program Files\congstar\Internetmanager\Bin\libexpat.dll 2014-03-23 18:49 - 2010-05-13 10:42 - 00043008 _____ () C:\Program Files\congstar\Internetmanager\Bin\gconfd-2.exe 2014-03-23 18:49 - 2010-05-13 10:41 - 00055808 _____ () C:\Program Files\congstar\Internetmanager\Bin\libgconfbackend-xml.dll 2014-03-23 18:49 - 2010-05-13 10:42 - 00031232 _____ () C:\Program Files\congstar\Internetmanager\Bin\db_daemon.exe 2014-03-23 18:49 - 2010-05-13 10:39 - 00341504 _____ () C:\Program Files\congstar\Internetmanager\Bin\sqlite3.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData:$SS_DESCRIPTOR_PVX2VCGFMV89V8N4TKBRVDNGCMXLJ4M28WLP36MVLGKMVW5FS4K5 AlternateDataStreams: C:\Users\All Users:$SS_DESCRIPTOR_PVX2VCGFMV89V8N4TKBRVDNGCMXLJ4M28WLP36MVLGKMVW5FS4K5 AlternateDataStreams: C:\Users\Sandra:zylomtest AlternateDataStreams: C:\Users\Sandra:zylomtr{0000278T-TT9K-T8DU-07LG-28DG94S2MVVU} AlternateDataStreams: C:\Users\Sandra:zylomtr{00013KEU-UKQE-K6V0-6C5V-289TUR10SVUF} AlternateDataStreams: C:\Users\Sandra:zylomtr{00013KEU-UKQE-K6V0-70L9-2A8RJ1B4CV8I} AlternateDataStreams: C:\Users\Sandra:zylomtr{00013KEU-UKQE-K6V0-70L9-2A8RJ1B4CVBF} AlternateDataStreams: C:\Users\Sandra:zylomtr{00013KEU-UKQE-K6V0-70L9-2A8RJ1B4CVF7} AlternateDataStreams: C:\Users\Sandra:zylomtr{00013KEU-UKQE-K6V0-70L9-2A8RJ1B4CVM5} AlternateDataStreams: C:\Users\Sandra:zylomtr{00013KEU-UKQE-K6V0-9MH3-26R8QGLT2VVT} AlternateDataStreams: C:\Users\Sandra:zylomtr{00013KEU-UKQE-K6V0-GEOR-27TDF94KAVLB} AlternateDataStreams: C:\Users\Sandra:zylomtr{00013KEU-UKQE-K6V0-GEOR-27TDF94KAVPT} AlternateDataStreams: C:\Users\Sandra:zylomtr{00013KEU-UKQE-K6V0-GEOR-27TDF94KAVS5} AlternateDataStreams: C:\Users\Sandra:zylomtr{00013KEU-UKQE-K6V0-GEOR-27TDF94KAVUD} AlternateDataStreams: C:\Users\Sandra:zylomtr{00013KEU-UKQE-K6V0-ONL2-28KUTKHT8DD5} AlternateDataStreams: C:\Users\Sandra:zylomtr{00013KEU-UKQE-K6V0-TONE-28JR2EO88NS1} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG1-1VH8-28I0EFCC2VST} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG1-1VH8-28I0EFCC2VVP} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG1-3BG4-281NL05DCVSB} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG1-3BG4-281NL05DCVTO} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG1-CMRU-27KCBJ656VVU} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG1-ELL4-28F9S56GIVQN} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG1-ELL4-28F9S56GIVTO} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG1-ELL4-28F9S56GIVV1} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG1-J24H-293SB52ICVVE} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG1-J24H-298CPF2SOVVG} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG2-BTPP-21HGNJ8AQVVU} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG2-LKCU-2AJQPJA4AVHE} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG2-LKCU-2AJQPJA4AVLT} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG2-Q64S-2675H2E5QVUG} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG2-Q64S-2675H2E5QVVI} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG3-1EMN-28M5NPU00VV4} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG3-40QI-27REBT9KOVTG} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG3-40QI-27REBT9KOVVU} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG3-4A90-24BL1LF8IVV1} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG3-GQ8O-29APM3QU0VVP} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG3-L1G2-28QRSPMS6VVH} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG3-M7KB-24AAHNHOQVVQ} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG3-S3H7-2A5PQROOQVVB} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG3-S3H7-2A5PQROOQVVP} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG4-5TO3-2831TOKLCVVG} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG4-74E3-28689HMLOVVS} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG4-MO09-24UF17SCEVUK} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG4-OK39-27NOI1CL8VVO} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG4-RLQO-285DUDG5UVUV} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG4-RLQO-285DUDG5UVVH} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG5-8A6T-26VOTC6OMVQN} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG5-8A6T-26VOTC6OMVV8} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG5-C61F-283VSOALEVTK} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG5-C61F-283VSOALEVUH} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG5-C61F-283VSOALEVVK} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG5-EG1B-25KGP2UCCVUF} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG5-S5RF-2A7U3EJND000} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG6-3908-29CNF5LCOVND} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG6-3908-29CNF5LCOVUA} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG6-OKQM-24KG7RVO4VVI} AlternateDataStreams: C:\Users\Sandra:zylomtr{000HQ7FF-AD7A-3FG7-E9E4-28HCA9OPAVTD} AlternateDataStreams: C:\Users\Sandra:zylomtr{007F99P2-504Q-L9VJ-AT87-509CA1F53AR6} AlternateDataStreams: C:\ProgramData\Anwendungsdaten:$SS_DESCRIPTOR_PVX2VCGFMV89V8N4TKBRVDNGCMXLJ4M28WLP36MVLGKMVW5FS4K5 AlternateDataStreams: C:\ProgramData\Application Data:$SS_DESCRIPTOR_PVX2VCGFMV89V8N4TKBRVDNGCMXLJ4M28WLP36MVLGKMVW5FS4K5 AlternateDataStreams: C:\ProgramData\TEMP:008586AE AlternateDataStreams: C:\ProgramData\TEMP:0406003C AlternateDataStreams: C:\ProgramData\TEMP:041C0562 AlternateDataStreams: C:\ProgramData\TEMP:04BB186B AlternateDataStreams: C:\ProgramData\TEMP:054F0F17 AlternateDataStreams: C:\ProgramData\TEMP:058A7351 AlternateDataStreams: C:\ProgramData\TEMP:070D9534 AlternateDataStreams: C:\ProgramData\TEMP:0C5BC70E AlternateDataStreams: C:\ProgramData\TEMP:0E22C5DB AlternateDataStreams: C:\ProgramData\TEMP:0E67073E AlternateDataStreams: C:\ProgramData\TEMP:0E684AC9 AlternateDataStreams: C:\ProgramData\TEMP:0EC7A545 AlternateDataStreams: C:\ProgramData\TEMP:0F38B460 AlternateDataStreams: C:\ProgramData\TEMP:0F3F6B1E AlternateDataStreams: C:\ProgramData\TEMP:109734F6 AlternateDataStreams: C:\ProgramData\TEMP:10D98D98 AlternateDataStreams: C:\ProgramData\TEMP:123A86B5 AlternateDataStreams: C:\ProgramData\TEMP:12D2EB9C AlternateDataStreams: C:\ProgramData\TEMP:12EA4DC9 AlternateDataStreams: C:\ProgramData\TEMP:1316EAD4 AlternateDataStreams: C:\ProgramData\TEMP:1392F09D AlternateDataStreams: C:\ProgramData\TEMP:15752405 AlternateDataStreams: C:\ProgramData\TEMP:178093AE AlternateDataStreams: C:\ProgramData\TEMP:17F7AEA3 AlternateDataStreams: C:\ProgramData\TEMP:18A6D2CC AlternateDataStreams: C:\ProgramData\TEMP:193CB03B AlternateDataStreams: C:\ProgramData\TEMP:1A4BF204 AlternateDataStreams: C:\ProgramData\TEMP:1B927722 AlternateDataStreams: C:\ProgramData\TEMP:1BD02801 AlternateDataStreams: C:\ProgramData\TEMP:1ECED34B AlternateDataStreams: C:\ProgramData\TEMP:1F4329D4 AlternateDataStreams: C:\ProgramData\TEMP:204BEE0F AlternateDataStreams: C:\ProgramData\TEMP:206470A5 AlternateDataStreams: C:\ProgramData\TEMP:225CD7D5 AlternateDataStreams: C:\ProgramData\TEMP:2495D97A AlternateDataStreams: C:\ProgramData\TEMP:25249477 AlternateDataStreams: C:\ProgramData\TEMP:27F44544 AlternateDataStreams: C:\ProgramData\TEMP:29629382 AlternateDataStreams: C:\ProgramData\TEMP:2C678471 AlternateDataStreams: C:\ProgramData\TEMP:2D78CEB3 AlternateDataStreams: C:\ProgramData\TEMP:2E45FA8F AlternateDataStreams: C:\ProgramData\TEMP:2EC5D66C AlternateDataStreams: C:\ProgramData\TEMP:2F6462DF AlternateDataStreams: C:\ProgramData\TEMP:2FBB2B9B AlternateDataStreams: C:\ProgramData\TEMP:2FC7B9E4 AlternateDataStreams: C:\ProgramData\TEMP:32A82570 AlternateDataStreams: C:\ProgramData\TEMP:32FC67BC AlternateDataStreams: C:\ProgramData\TEMP:32FFF2D1 AlternateDataStreams: C:\ProgramData\TEMP:35C78DCC AlternateDataStreams: C:\ProgramData\TEMP:35FAD15D AlternateDataStreams: C:\ProgramData\TEMP:3651A580 AlternateDataStreams: C:\ProgramData\TEMP:36A39835 AlternateDataStreams: C:\ProgramData\TEMP:370E4EFB AlternateDataStreams: C:\ProgramData\TEMP:386B39C3 AlternateDataStreams: C:\ProgramData\TEMP:38FF076E AlternateDataStreams: C:\ProgramData\TEMP:3AD6342E AlternateDataStreams: C:\ProgramData\TEMP:3B812EE0 AlternateDataStreams: C:\ProgramData\TEMP:3D186293 AlternateDataStreams: C:\ProgramData\TEMP:3D36932D AlternateDataStreams: C:\ProgramData\TEMP:3D6B89CE AlternateDataStreams: C:\ProgramData\TEMP:3DB6F365 AlternateDataStreams: C:\ProgramData\TEMP:3E06C78F AlternateDataStreams: C:\ProgramData\TEMP:405D842B AlternateDataStreams: C:\ProgramData\TEMP:413E2927 AlternateDataStreams: C:\ProgramData\TEMP:425759C6 AlternateDataStreams: C:\ProgramData\TEMP:42A3BDD7 AlternateDataStreams: C:\ProgramData\TEMP:43C9D140 AlternateDataStreams: C:\ProgramData\TEMP:471AD3D0 AlternateDataStreams: C:\ProgramData\TEMP:47A24D4B AlternateDataStreams: C:\ProgramData\TEMP:48977386 AlternateDataStreams: C:\ProgramData\TEMP:4A2862FF AlternateDataStreams: C:\ProgramData\TEMP:4A448DB2 AlternateDataStreams: C:\ProgramData\TEMP:4B1195DD AlternateDataStreams: C:\ProgramData\TEMP:4C528C86 AlternateDataStreams: C:\ProgramData\TEMP:4E243396 AlternateDataStreams: C:\ProgramData\TEMP:4E6B8D68 AlternateDataStreams: C:\ProgramData\TEMP:4EE323A4 AlternateDataStreams: C:\ProgramData\TEMP:4EF94CF3 AlternateDataStreams: C:\ProgramData\TEMP:4FE30352 AlternateDataStreams: C:\ProgramData\TEMP:4FE42FFC AlternateDataStreams: C:\ProgramData\TEMP:50636E35 AlternateDataStreams: C:\ProgramData\TEMP:5080697C AlternateDataStreams: C:\ProgramData\TEMP:5197985B AlternateDataStreams: C:\ProgramData\TEMP:5335CE76 AlternateDataStreams: C:\ProgramData\TEMP:53DF59D1 AlternateDataStreams: C:\ProgramData\TEMP:551BED5F AlternateDataStreams: C:\ProgramData\TEMP:55E1514E AlternateDataStreams: C:\ProgramData\TEMP:56C17A93 AlternateDataStreams: C:\ProgramData\TEMP:57176330 AlternateDataStreams: C:\ProgramData\TEMP:57B2B96C AlternateDataStreams: C:\ProgramData\TEMP:583FE1DA AlternateDataStreams: C:\ProgramData\TEMP:592D7272 AlternateDataStreams: C:\ProgramData\TEMP:5A8F8A0C AlternateDataStreams: C:\ProgramData\TEMP:5AE33054 AlternateDataStreams: C:\ProgramData\TEMP:5D10C56A AlternateDataStreams: C:\ProgramData\TEMP:5D351BC6 AlternateDataStreams: C:\ProgramData\TEMP:5E9B629B AlternateDataStreams: C:\ProgramData\TEMP:5F538558 AlternateDataStreams: C:\ProgramData\TEMP:5FA4CB99 AlternateDataStreams: C:\ProgramData\TEMP:6017A808 AlternateDataStreams: C:\ProgramData\TEMP:61A065F2 AlternateDataStreams: C:\ProgramData\TEMP:61B54B15 AlternateDataStreams: C:\ProgramData\TEMP:6247E766 AlternateDataStreams: C:\ProgramData\TEMP:62525FE7 AlternateDataStreams: C:\ProgramData\TEMP:63B94956 AlternateDataStreams: C:\ProgramData\TEMP:661DC753 AlternateDataStreams: C:\ProgramData\TEMP:663B62CA AlternateDataStreams: C:\ProgramData\TEMP:66871744 AlternateDataStreams: C:\ProgramData\TEMP:68A56598 AlternateDataStreams: C:\ProgramData\TEMP:69AF9D20 AlternateDataStreams: C:\ProgramData\TEMP:6E11933F AlternateDataStreams: C:\ProgramData\TEMP:6F0B6A5A AlternateDataStreams: C:\ProgramData\TEMP:6FD26134 AlternateDataStreams: C:\ProgramData\TEMP:6FD3C973 AlternateDataStreams: C:\ProgramData\TEMP:6FE17A89 AlternateDataStreams: C:\ProgramData\TEMP:701FCC18 AlternateDataStreams: C:\ProgramData\TEMP:708BB0FA AlternateDataStreams: C:\ProgramData\TEMP:7124B44D AlternateDataStreams: C:\ProgramData\TEMP:71612023 AlternateDataStreams: C:\ProgramData\TEMP:71FA8B7F AlternateDataStreams: C:\ProgramData\TEMP:73461BFA AlternateDataStreams: C:\ProgramData\TEMP:737160C1 AlternateDataStreams: C:\ProgramData\TEMP:73AFBB96 AlternateDataStreams: C:\ProgramData\TEMP:74091520 AlternateDataStreams: C:\ProgramData\TEMP:7547DA5B AlternateDataStreams: C:\ProgramData\TEMP:78739EC9 AlternateDataStreams: C:\ProgramData\TEMP:7881FECE AlternateDataStreams: C:\ProgramData\TEMP:7A032A04 AlternateDataStreams: C:\ProgramData\TEMP:7A3AAF2E AlternateDataStreams: C:\ProgramData\TEMP:7AF9CAEB AlternateDataStreams: C:\ProgramData\TEMP:80EA2EA3 AlternateDataStreams: C:\ProgramData\TEMP:80F63EC3 AlternateDataStreams: C:\ProgramData\TEMP:8140CB50 AlternateDataStreams: C:\ProgramData\TEMP:81653DC8 AlternateDataStreams: C:\ProgramData\TEMP:8247A199 AlternateDataStreams: C:\ProgramData\TEMP:870649A4 AlternateDataStreams: C:\ProgramData\TEMP:883EDFB5 AlternateDataStreams: C:\ProgramData\TEMP:88698068 AlternateDataStreams: C:\ProgramData\TEMP:88A44CC1 AlternateDataStreams: C:\ProgramData\TEMP:8924043A AlternateDataStreams: C:\ProgramData\TEMP:8944C195 AlternateDataStreams: C:\ProgramData\TEMP:89CF6F9C AlternateDataStreams: C:\ProgramData\TEMP:8AD1F2E0 AlternateDataStreams: C:\ProgramData\TEMP:8B4B9596 AlternateDataStreams: C:\ProgramData\TEMP:8BA6C9F8 AlternateDataStreams: C:\ProgramData\TEMP:8BFA0030 AlternateDataStreams: C:\ProgramData\TEMP:8CCDAB14 AlternateDataStreams: C:\ProgramData\TEMP:8D5A0C4E AlternateDataStreams: C:\ProgramData\TEMP:8FA72FF8 AlternateDataStreams: C:\ProgramData\TEMP:9026FFAC AlternateDataStreams: C:\ProgramData\TEMP:90D89144 AlternateDataStreams: C:\ProgramData\TEMP:918B7566 AlternateDataStreams: C:\ProgramData\TEMP:91DEEE71 AlternateDataStreams: C:\ProgramData\TEMP:92A815D8 AlternateDataStreams: C:\ProgramData\TEMP:93B0BB6F AlternateDataStreams: C:\ProgramData\TEMP:943E8182 AlternateDataStreams: C:\ProgramData\TEMP:953FDC1A AlternateDataStreams: C:\ProgramData\TEMP:957E9765 AlternateDataStreams: C:\ProgramData\TEMP:97C4F81F AlternateDataStreams: C:\ProgramData\TEMP:98982C88 AlternateDataStreams: C:\ProgramData\TEMP:996104FC AlternateDataStreams: C:\ProgramData\TEMP:9A7BF72D AlternateDataStreams: C:\ProgramData\TEMP:9AE67195 AlternateDataStreams: C:\ProgramData\TEMP:9D03192E AlternateDataStreams: C:\ProgramData\TEMP:9DB67071 AlternateDataStreams: C:\ProgramData\TEMP:9DCE3A1C AlternateDataStreams: C:\ProgramData\TEMP:9E9A3410 AlternateDataStreams: C:\ProgramData\TEMP:9F50A55A AlternateDataStreams: C:\ProgramData\TEMP:A02025CE AlternateDataStreams: C:\ProgramData\TEMP:A0C7D68A AlternateDataStreams: C:\ProgramData\TEMP:A0CB43B2 AlternateDataStreams: C:\ProgramData\TEMP:A26AFC00 AlternateDataStreams: C:\ProgramData\TEMP:A296A63F AlternateDataStreams: C:\ProgramData\TEMP:A5584049 AlternateDataStreams: C:\ProgramData\TEMP:A5FC8FA1 AlternateDataStreams: C:\ProgramData\TEMP:A60D0FA6 AlternateDataStreams: C:\ProgramData\TEMP:A6CDBCAC AlternateDataStreams: C:\ProgramData\TEMP:A7B70C4E AlternateDataStreams: C:\ProgramData\TEMP:AABCC5A7 AlternateDataStreams: C:\ProgramData\TEMP:AB82C54F AlternateDataStreams: C:\ProgramData\TEMP:AC0528D9 AlternateDataStreams: C:\ProgramData\TEMP:AC57032B AlternateDataStreams: C:\ProgramData\TEMP:AC73CDCE AlternateDataStreams: C:\ProgramData\TEMP:AD727397 AlternateDataStreams: C:\ProgramData\TEMP:ADFAD95A AlternateDataStreams: C:\ProgramData\TEMP:AED33A42 AlternateDataStreams: C:\ProgramData\TEMP:B093E177 AlternateDataStreams: C:\ProgramData\TEMP:B1FBBD09 AlternateDataStreams: C:\ProgramData\TEMP:B4980368 AlternateDataStreams: C:\ProgramData\TEMP:B64F7263 AlternateDataStreams: C:\ProgramData\TEMP:B8EA2C49 AlternateDataStreams: C:\ProgramData\TEMP:B8EB1B99 AlternateDataStreams: C:\ProgramData\TEMP:BD27B7FC AlternateDataStreams: C:\ProgramData\TEMP:BD8C785E AlternateDataStreams: C:\ProgramData\TEMP:BDCD0530 AlternateDataStreams: C:\ProgramData\TEMP:BDF08FAF AlternateDataStreams: C:\ProgramData\TEMP:BE40C8A2 AlternateDataStreams: C:\ProgramData\TEMP:BF6C81B2 AlternateDataStreams: C:\ProgramData\TEMP:C07A6A6B AlternateDataStreams: C:\ProgramData\TEMP:C0A9D0E7 AlternateDataStreams: C:\ProgramData\TEMP:C22674B6 AlternateDataStreams: C:\ProgramData\TEMP:C30487EE AlternateDataStreams: C:\ProgramData\TEMP:C3392F75 AlternateDataStreams: C:\ProgramData\TEMP:C35B4B19 AlternateDataStreams: C:\ProgramData\TEMP:C36B1175 AlternateDataStreams: C:\ProgramData\TEMP:C48A983C AlternateDataStreams: C:\ProgramData\TEMP:C4AB79AE AlternateDataStreams: C:\ProgramData\TEMP:C5E2BAEE AlternateDataStreams: C:\ProgramData\TEMP:C611D6C8 AlternateDataStreams: C:\ProgramData\TEMP:C72A744C AlternateDataStreams: C:\ProgramData\TEMP:C76CFF82 AlternateDataStreams: C:\ProgramData\TEMP:C7973317 AlternateDataStreams: C:\ProgramData\TEMP:C81D3839 AlternateDataStreams: C:\ProgramData\TEMP:C86B29EB AlternateDataStreams: C:\ProgramData\TEMP:C9CDDE5E AlternateDataStreams: C:\ProgramData\TEMP:CA0CE093 AlternateDataStreams: C:\ProgramData\TEMP:CA8D6B60 AlternateDataStreams: C:\ProgramData\TEMP:CA99FD89 AlternateDataStreams: C:\ProgramData\TEMP:CAF8DAC8 AlternateDataStreams: C:\ProgramData\TEMP:CB0EB1DE AlternateDataStreams: C:\ProgramData\TEMP:CB0FEE2B AlternateDataStreams: C:\ProgramData\TEMP:CB16385F AlternateDataStreams: C:\ProgramData\TEMP:CE6885F1 AlternateDataStreams: C:\ProgramData\TEMP:CF1334B0 AlternateDataStreams: C:\ProgramData\TEMP:CF61CE5A AlternateDataStreams: C:\ProgramData\TEMP:CFDE7852 AlternateDataStreams: C:\ProgramData\TEMP:CFFC9DD0 AlternateDataStreams: C:\ProgramData\TEMP:D0D17155 AlternateDataStreams: C:\ProgramData\TEMP:D2397415 AlternateDataStreams: C:\ProgramData\TEMP:D2C57161 AlternateDataStreams: C:\ProgramData\TEMP:D2D4B33E AlternateDataStreams: C:\ProgramData\TEMP:D354012D AlternateDataStreams: C:\ProgramData\TEMP:D390A6A7 AlternateDataStreams: C:\ProgramData\TEMP:D3A89E47 AlternateDataStreams: C:\ProgramData\TEMP:D3A8AA31 AlternateDataStreams: C:\ProgramData\TEMP:D453E38B AlternateDataStreams: C:\ProgramData\TEMP:D46ECFD5 AlternateDataStreams: C:\ProgramData\TEMP:D4BB0AD6 AlternateDataStreams: C:\ProgramData\TEMP:D74C2847 AlternateDataStreams: C:\ProgramData\TEMP:D8D58038 AlternateDataStreams: C:\ProgramData\TEMP:D8F9D810 AlternateDataStreams: C:\ProgramData\TEMP:D9B1EB7E AlternateDataStreams: C:\ProgramData\TEMP:DC21D414 AlternateDataStreams: C:\ProgramData\TEMP:DD04902E AlternateDataStreams: C:\ProgramData\TEMP:DE47A3DA AlternateDataStreams: C:\ProgramData\TEMP:DE9AC04F AlternateDataStreams: C:\ProgramData\TEMP:DF0BC727 AlternateDataStreams: C:\ProgramData\TEMP:E14FA16F AlternateDataStreams: C:\ProgramData\TEMP:E1610EDC AlternateDataStreams: C:\ProgramData\TEMP:E1D818F7 AlternateDataStreams: C:\ProgramData\TEMP:E3B5F2D1 AlternateDataStreams: C:\ProgramData\TEMP:E411AA0D AlternateDataStreams: C:\ProgramData\TEMP:E4FCDFD9 AlternateDataStreams: C:\ProgramData\TEMP:E6A96BE9 AlternateDataStreams: C:\ProgramData\TEMP:E6D148BC AlternateDataStreams: C:\ProgramData\TEMP:E732B44B AlternateDataStreams: C:\ProgramData\TEMP:E774F04D AlternateDataStreams: C:\ProgramData\TEMP:E7B4296D AlternateDataStreams: C:\ProgramData\TEMP:E7B49FBF AlternateDataStreams: C:\ProgramData\TEMP:E7C9DAAE AlternateDataStreams: C:\ProgramData\TEMP:E8CB831A AlternateDataStreams: C:\ProgramData\TEMP:EA10407C AlternateDataStreams: C:\ProgramData\TEMP:EA1919C7 AlternateDataStreams: C:\ProgramData\TEMP:EA701346 AlternateDataStreams: C:\ProgramData\TEMP:EA7D76BE AlternateDataStreams: C:\ProgramData\TEMP:EAEE7554 AlternateDataStreams: C:\ProgramData\TEMP:EB333CFC AlternateDataStreams: C:\ProgramData\TEMP:EB5BDBB0 AlternateDataStreams: C:\ProgramData\TEMP:EDC744FB AlternateDataStreams: C:\ProgramData\TEMP:EEED3F26 AlternateDataStreams: C:\ProgramData\TEMP:EF0C5444 AlternateDataStreams: C:\ProgramData\TEMP:EF5B3572 AlternateDataStreams: C:\ProgramData\TEMP:F0A06891 AlternateDataStreams: C:\ProgramData\TEMP:F3029A65 AlternateDataStreams: C:\ProgramData\TEMP:F3EFA8A8 AlternateDataStreams: C:\ProgramData\TEMP:F43B7E8F AlternateDataStreams: C:\ProgramData\TEMP:F7370879 AlternateDataStreams: C:\ProgramData\TEMP:F7F6E6CB AlternateDataStreams: C:\ProgramData\TEMP:F81E7082 AlternateDataStreams: C:\ProgramData\TEMP:F8F070C2 AlternateDataStreams: C:\ProgramData\TEMP:F9E46E4C AlternateDataStreams: C:\ProgramData\TEMP:F9EDCFB0 AlternateDataStreams: C:\ProgramData\TEMP:FAFEC4B9 AlternateDataStreams: C:\ProgramData\TEMP:FB647F34 AlternateDataStreams: C:\ProgramData\TEMP:FD000392 AlternateDataStreams: C:\ProgramData\TEMP:FD38E906 AlternateDataStreams: C:\ProgramData\TEMP:FECEF728 ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com There are 7358 more restricted sites. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-891572633-1774761820-252287049-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Sandra\Application Data\Pictures\Drache1.jpg DNS Servers: 193.189.244.225 - 193.189.244.206 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: ) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [TCP Query User{637B9502-262B-4680-8440-9F93780503AB}C:\program files\internet explorer\iexplore.exe] => (Block) C:\program files\internet explorer\iexplore.exe FirewallRules: [UDP Query User{4B1D55F8-D758-4657-AC3A-DE59BD432B5C}C:\program files\internet explorer\iexplore.exe] => (Block) C:\program files\internet explorer\iexplore.exe FirewallRules: [{763A9BFE-AF9D-4598-AB33-0CAC42C4329F}] => (Allow) C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe FirewallRules: [{82E6866A-456B-4FA2-9255-CEA55E07F257}] => (Allow) C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe FirewallRules: [{8532313D-6991-4F90-9020-D160BD8A8231}] => (Allow) C:\Program Files\Tobit Radio.fx\Client\rfx-client.exe FirewallRules: [{9017EDC8-49B9-46D6-8FA3-C11EBC31FCBC}] => (Allow) C:\Program Files\Tobit Radio.fx\Client\rfx-client.exe FirewallRules: [{37EFC497-31E9-4305-80D8-8FD93559F3DF}] => (Allow) C:\Program Files\TeamViewer\Version5\TeamViewer.exe FirewallRules: [{9EA43957-1A2C-419E-8F50-22BF8DE39B4C}] => (Allow) C:\Program Files\TeamViewer\Version5\TeamViewer.exe FirewallRules: [TCP Query User{73E83C09-C343-42F5-9C06-7F29244FF95A}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe FirewallRules: [UDP Query User{5EC8FB2D-F09E-4C5A-B679-54FADA91474C}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe FirewallRules: [{6F4D1074-856A-4C64-ACF8-1CD93154FD0F}] => (Allow) LPort=80 FirewallRules: [{2B5F215C-83D8-405F-B200-FA3FDBA04952}] => (Allow) LPort=80 FirewallRules: [{08C8CF5F-BCE2-42AD-A410-83781F5BCAC2}] => (Allow) LPort=80 FirewallRules: [{BDA735D0-96F0-44A4-8EA9-FC9899EE3BE7}] => (Allow) C:\Program Files\congstar\Internetmanager\Bin\MainApp.exe FirewallRules: [{399DF4C3-B2CC-4BB5-A184-3794FE94AF1F}] => (Allow) C:\Program Files\congstar\Internetmanager\Bin\MainApp.exe FirewallRules: [{4DC96EA1-4031-485D-973D-1E0610F18211}] => (Allow) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{703AC5DC-7522-4A5E-BAB6-EBE9B22E80F6}] => (Allow) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [TCP Query User{693FFD98-9206-4546-9E8B-515167CFDED1}C:\program files\srware iron\iron.exe] => (Block) C:\program files\srware iron\iron.exe FirewallRules: [UDP Query User{2DB7ECB7-1B5A-42D4-A8C1-1637A28909B6}C:\program files\srware iron\iron.exe] => (Block) C:\program files\srware iron\iron.exe FirewallRules: [TCP Query User{0ED3ABDE-419A-434E-8596-7305420D9041}C:\program files\mozilla firefox\plugin-container.exe] => (Block) C:\program files\mozilla firefox\plugin-container.exe FirewallRules: [UDP Query User{6DCD1365-4EA1-411A-977B-99384019AD14}C:\program files\mozilla firefox\plugin-container.exe] => (Block) C:\program files\mozilla firefox\plugin-container.exe FirewallRules: [TCP Query User{0921335B-E9C8-4FCC-94EC-E44FB6528D9A}C:\program files\srware iron\iron.exe] => (Block) C:\program files\srware iron\iron.exe FirewallRules: [UDP Query User{9F6876B9-17C8-4B97-ADAB-8ECEB11B70A6}C:\program files\srware iron\iron.exe] => (Block) C:\program files\srware iron\iron.exe FirewallRules: [{94631EAF-E186-4D79-8B1C-8D1900F8E2D1}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{64977571-955F-4037-91F7-77A705548C8F}] => (Allow) C:\Program Files\Norpalla\bin\Norpalla.BRT.Helper.exe FirewallRules: [{99A14943-855E-48FF-9794-EC516BE5D315}] => (Allow) C:\Program Files\Norpalla\bin\Norpalla.BRT.Helper.exe FirewallRules: [{A631F5FE-0753-4E43-98C5-953A91EAE2F4}] => (Allow) C:\Program Files\Bench\Proxy\proc.exe FirewallRules: [{666CE59E-EEF3-49BB-AF43-8645562FA2DE}] => (Allow) C:\Program Files\Bench\Proxy\pwdg.exe FirewallRules: [{827C6E82-CF2B-4BAE-ADF2-D78AC6A4761A}] => (Allow) C:\Users\Sandra\uber-strike-cheats-ohne.exe FirewallRules: [{0B8A5018-DC8F-41A9-AC1F-E6FEDFC84BCA}] => (Allow) C:\Users\Sandra\uber-strike-cheats-ohne.exe FirewallRules: [{79F79E0B-50B1-4617-9B45-36391DF95D42}] => (Allow) C:\Program Files\SimpleFiles\SimpleFiles.exe FirewallRules: [{2C11D001-28E2-4BD0-9E9F-9F6F7AF546F7}] => (Allow) C:\Program Files\SimpleFiles\SimpleFiles.exe FirewallRules: [{B0040FE3-CDCC-4F29-B004-87F4A6574B76}] => (Allow) C:\Program Files\SimpleFiles\downloader.exe FirewallRules: [{CC29AF40-6ED8-4CE4-B529-003AEC14CED2}] => (Allow) C:\Program Files\SimpleFiles\downloader.exe FirewallRules: [{956D70E1-9AA4-49B3-9947-EA8F2091C006}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{E189E505-C50E-465C-BEC6-C6B777FFB910} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{8CA9262A-0035-43CE-8CC2-4191FAFA1ADF} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{8CA9262A-0035-43CE-8CC2-4191FAFA1ADF} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{8CA9262A-0035-43CE-8CC2-4191FAFA1ADF} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{8CA9262A-0035-43CE-8CC2-4191FAFA1ADF} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{8CA9262A-0035-43CE-8CC2-4191FAFA1ADF} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{8CA9262A-0035-43CE-8CC2-4191FAFA1ADF} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{8CA9262A-0035-43CE-8CC2-4191FAFA1ADF} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{789BFD34-EEE8-45EF-8A5B-071CE20B26E9} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{789BFD34-EEE8-45EF-8A5B-071CE20B26E9} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{789BFD34-EEE8-45EF-8A5B-071CE20B26E9} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{789BFD34-EEE8-45EF-8A5B-071CE20B26E9} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{789BFD34-EEE8-45EF-8A5B-071CE20B26E9} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{789BFD34-EEE8-45EF-8A5B-071CE20B26E9} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{789BFD34-EEE8-45EF-8A5B-071CE20B26E9} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{C352FDDF-4836-4F23-A92A-F8E58BDF829D} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{C352FDDF-4836-4F23-A92A-F8E58BDF829D} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{49DB607C-93BE-4DE2-A90B-007796BCC80E} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{49DB607C-93BE-4DE2-A90B-007796BCC80E} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{49DB607C-93BE-4DE2-A90B-007796BCC80E} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{F4A3DCDE-5A33-4E9D-8E66-AA41066E6DC3} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{F9F0F3DE-5AE4-45F1-8A61-30484AAEC5A6} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{BE2E9025-8DB8-430E-BD83-F989B5EF45D1} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{00EDA72F-48BB-431A-8289-56EEE99128CF} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/25/2015 08:03:07 AM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Eintrag <C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\LBZQXNMY\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#CDN.MOVAD.NET\SETTINGS.SOL> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/25/2015 08:03:07 AM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Eintrag <C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\LBZQXNMY\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#CDN.MOVAD.NET\SETTINGS.SOL> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/24/2015 11:13:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Eintrag <C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\LBZQXNMY\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#VIZORFB-A.AKAMAIHD.NET\SETTINGS.SOL> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/24/2015 11:13:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Eintrag <C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\LBZQXNMY\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#VIZORFB-A.AKAMAIHD.NET\SETTINGS.SOL> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/24/2015 10:44:00 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Eintrag <C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\LBZQXNMY\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\SETTINGS.SOL> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/24/2015 10:44:00 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Eintrag <C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\LBZQXNMY\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\SETTINGS.SOL> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/24/2015 07:48:28 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Eintrag <C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\9N2JNYBZ\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#CDN.MOVAD.NET\SETTINGS.SOL> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/24/2015 07:48:28 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Eintrag <C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\9N2JNYBZ\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#CDN.MOVAD.NET\SETTINGS.SOL> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/24/2015 07:33:30 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Eintrag <C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\9N2JNYBZ\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#VIZORFB-A.AKAMAIHD.NET\SETTINGS.SOL> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/24/2015 07:33:30 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Eintrag <C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\9N2JNYBZ\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#VIZORFB-A.AKAMAIHD.NET\SETTINGS.SOL> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) System errors: ============= Microsoft Office: ========================= Error: (07/25/2015 08:03:07 AM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\LBZQXNMY\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#CDN.MOVAD.NET\SETTINGS.SOL Error: (07/25/2015 08:03:07 AM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\LBZQXNMY\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#CDN.MOVAD.NET\SETTINGS.SOL Error: (07/24/2015 11:13:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\LBZQXNMY\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#VIZORFB-A.AKAMAIHD.NET\SETTINGS.SOL Error: (07/24/2015 11:13:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\LBZQXNMY\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#VIZORFB-A.AKAMAIHD.NET\SETTINGS.SOL Error: (07/24/2015 10:44:00 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\LBZQXNMY\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\SETTINGS.SOL Error: (07/24/2015 10:44:00 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\LBZQXNMY\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\SETTINGS.SOL Error: (07/24/2015 07:48:28 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\9N2JNYBZ\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#CDN.MOVAD.NET\SETTINGS.SOL Error: (07/24/2015 07:48:28 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\9N2JNYBZ\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#CDN.MOVAD.NET\SETTINGS.SOL Error: (07/24/2015 07:33:30 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\9N2JNYBZ\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#VIZORFB-A.AKAMAIHD.NET\SETTINGS.SOL Error: (07/24/2015 07:33:30 PM) (Source: Windows Search Service) (EventID: 3013) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PEPPER DATA\SHOCKWAVE FLASH\WRITABLEROOT\#SHAREDOBJECTS\9N2JNYBZ\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#VIZORFB-A.AKAMAIHD.NET\SETTINGS.SOL CodeIntegrity Errors: =================================== Date: 2015-07-24 21:23:39.648 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-07-24 20:05:19.745 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-07-24 20:05:19.355 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-07-24 20:05:18.981 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-07-24 20:05:18.591 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-07-24 20:05:18.216 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-07-24 20:05:17.795 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-07-24 19:56:03.404 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-07-24 19:53:35.170 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-07-24 11:15:10.419 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\iS3\STOPzilla AntiVirus\Drivers\i386\w2k\SBTIS.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 CPU 6320 @ 1.86GHz Percentage of memory in use: 54% Total physical RAM: 2046.45 MB Available physical RAM: 932.38 MB Total Virtual: 4341.89 MB Available Virtual: 2717.74 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:195.31 GB) (Free:124.95 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:117.19 GB) (Free:106.48 GB) NTFS Drive e: () (Fixed) (Total:153.26 GB) (Free:147.39 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: B74FD3AC) Partition 1: (Active) - (Size=195.3 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=117.2 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=153.3 GB) - (Type=07 NTFS) ==================== End of log ========================= und hier der FRST Editor : FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-07-2015 |
Addition.txt bitte nochmal, da fehlt die Hälfte :) |
Code: Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x86) Version: 26-07-2015 |
Lade Dir bitte von hier ![]()
Scan mit Combofix
|
Hey, hab mir zuerst den Revo Uninstaller runter geladen und nach der Ask Toolbar gesucht. Die war dort aber nicht zu finden... Dann habe ich Combofix runter geladen und bin, soweit ich konnte, den Anweisungen gefolgt. Ich habe Avira per Task Manager deaktiviert, weil ich nicht wusste, wie ich es sonst ausschalte. Leider hat Combofix einen Neustart gemacht und direkt angefangen, so dass Avira wieder aktiviert wurde.... soweit hat es hoffentlich keine Probleme verursacht^^ Hier ist der Combo Log File : Code: ComboFix 15-07-23.01 - Sandra 28.07.2015 9:44.1.2 - x86 Vielen Dank noch mal für deine Hilfe, ohne die wäre ich aufgeschmissen ;) Ach sry, ich meine natürlich KB und nicht MB ^^ |
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Hey, ich habe das jetzt ein bissel beobachtet und es ist teilweise besser geworden. D.h. manchmal surfe ich ohne Probleme, dann mach ich 1 std später wieder den PC an und es zieht wieder irgendwas wie verrückt Daten, ohne dass sich die Seite richtig aufbaut. ich habe hier noch die Text Dateien, die du mir geraten hast. Code: Malwarebytes Anti-Malware Code: # AdwCleaner v4.208 - Bericht erstellt 29/07/2015 um 11:49:57 Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
Alle Zeitangaben in WEZ +1. Es ist jetzt 23:33 Uhr. |
Copyright ©2000-2025, Trojaner-Board