Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:01-12-2015 durchgeführt von Aneczka (Administrator) auf ANECZKA-PC (03-12-2015 00:03:58) Gestartet von C:\Users\Aneczka\Desktop Geladene Profile: Aneczka (Verfügbare Profile: Aneczka & Gast) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser nicht gefunden!) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (ActMask Co.,Ltd - hxxp://WWW.ALL2PDF.COM) C:\Windows\System32\PrintCtrl.exe () C:\Windows\SysWOW64\PSIService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (GG Network S.A.) C:\Users\Aneczka\AppData\Local\GG\Application\gghub.exe (GG Network S.A.) C:\Users\Aneczka\AppData\Local\GG\Application\ggapp.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Malwarebytes ) C:\Users\Aneczka\Downloads\Malwarebytes Anti-Malware Free 2.2.0.1024.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\MSOHTMED.EXE (Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation) C:\Windows\splwow64.exe (Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Dell) C:\Users\Aneczka\AppData\Local\Apps\2.0\MGJR61BB.E38\5OA3A5KL.16P\dell..tion_6d0a76327dca4869_0006.000b_9ebbe2fa9123034d\DellSystemDetect.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8067616 2009-08-18] (Realtek Semiconductor) HKLM-x32\...\Run: [StartCCC] => c:\program files (x86)\ati technologies\ati.ace\core-static\clistart.exe [61440 2009-02-25] (Advanced Micro Devices, Inc.) HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\...\Run: [ehTray.exe] => c:\windows\ehome\ehtray.exe [163328 2010-11-20] (Microsoft Corporation) HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\...\Run: [GG] => C:\Users\Aneczka\AppData\Local\GG\Application\gghub.exe [4078144 2015-03-24] (GG Network S.A.) HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\...\MountPoints2: N - N:\USBAutoRun.exe HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\...\MountPoints2: {400047f4-0365-11e5-ac0c-00241d8da3fc} - N:\Startme.exe HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\...\MountPoints2: {74d6b056-d524-11e3-ba8d-00241d8da3fc} - N:\Startme.exe HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\...\MountPoints2: {afa83a70-c672-11e3-958a-806e6f6e6963} - E:\CDMenu\CDMenu.exe HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\...\MountPoints2: {bc02912d-4a88-11df-a92e-00241d8da3fc} - N:\USBAutoRun.exe HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation) HKU\S-1-5-18\...\Run: [Bitdefender-Geldbörse-Agent] => "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" HKU\S-1-5-18\...\Run: [Bitdefender-Geldbörse] => "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard HKU\S-1-5-18\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => Keine Datei HKLM\...\AppCertDlls: [windows_service_for_control_application_23139093481232] -> C:\Users\Aneczka\AppData\Local\Hoffer\advapi.dll [104960 2015-10-30] () ShellIconOverlayIdentifiers: [GGDriveOverlay1] -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [2013-01-17] (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay2] -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [2013-01-17] (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay3] -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [2013-01-17] (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay4] -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [2013-01-17] (GG Network S.A.) GroupPolicy: Beschränkung - Chrome <======= ACHTUNG CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG CHR HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{8295bc72-cd7b-11de-a620-806e6f6e6963}: [NameServer] 5.104.108.204 Tcpip\..\Interfaces\{8A33152E-8310-44E3-A789-1B2464D318C3}: [DhcpNameServer] 192.168.2.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130849489367794355&GUID=00000000-0000-0000-0000-000000000000 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130849489367794355&GUID=00000000-0000-0000-0000-000000000000 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1428696794&from=cor&uid=395049983_1052514_243E1C7C&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1428696794&from=cor&uid=395049983_1052514_243E1C7C HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1428696794&from=cor&uid=395049983_1052514_243E1C7C HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1428696794&from=cor&uid=395049983_1052514_243E1C7C&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1428696794&from=cor&uid=395049983_1052514_243E1C7C&q={searchTerms} HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130849489392130397&GUID=00000000-0000-0000-0000-000000000000 HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1428696794&from=cor&uid=395049983_1052514_243E1C7C HKU\S-1-5-21-1280836393-1798441447-3805755999-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1428696794&from=cor&uid=395049983_1052514_243E1C7C&q={searchTerms} SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {13405F5E-08CD-815E-B115-74F3333C6226} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=164&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=tugumsd&cd=2XzuyEtN2Y1L1QzutDtDtByEtC0Dzz0D0AtA0F0CtC0CyB0CtN0D0Tzu0CyCyEtCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu2Z2Y1N2Y1H1B1Q&cr=527567552&ir= SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {2AD6CAF7-5D33-6D19-500C-703533C5DBD7} URL = hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=33206d1d-5c13-0724-0f0d-bb11db49a596&searchtype=ds&q={searchTerms}&installDate=19/09/2013 SearchScopes: HKU\S-1-5-21-1280836393-1798441447-3805755999-1000 -> DefaultScope {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-1280836393-1798441447-3805755999-1000 -> URL hxxp://search.conduit.com/Results.aspx?ctid=CT3326313&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP23423F7D-6F47-4AF5-954C-A3E22F698EB7&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-1280836393-1798441447-3805755999-1000 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-1280836393-1798441447-3805755999-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SL5MDF&PC=SL5M&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-1280836393-1798441447-3805755999-1000 -> {13405F5E-08CD-815E-B115-74F3333C6226} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=395049983_1052514_243E1C7C&ts=1428066817&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1280836393-1798441447-3805755999-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=395049983_1052514_243E1C7C&ts=1428066817&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1280836393-1798441447-3805755999-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=395049983_1052514_243E1C7C&ts=1428066817&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1280836393-1798441447-3805755999-1000 -> {F258B836-E083-4868-98D4-A1B262C64E34} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=395049983_1052514_243E1C7C&ts=1428066817&type=default&q={searchTerms} BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll [2009-08-05] (Microsoft Corporation) BHO: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO: adTech Class -> {934B156A-3D17-3981-B78A-5C138F423AD6} -> C:\Users\Aneczka\AppData\Roaming\pdfie\PdfConv_64.dll [2015-11-09] () BHO-x32: Kein Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> Keine Datei BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2012-03-04] (RealPlayer) BHO-x32: DivX Plus Web Player HTML5