Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: snap.do Startseite und Browserleiste (Firefox/Win7-32Bit) entfernen

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 15.04.2013, 22:30   #3
sideshowb
 
snap.do Startseite und Browserleiste (Firefox/Win7-32Bit) entfernen - Standard

snap.do Startseite und Browserleiste (Firefox/Win7-32Bit) entfernen



Super, vielen Dank!
Firefox und IE haben jetzt keine snap.do Toolbar und Starseite mehr!
Aber ist es damit vollständig behoben?

adwCleaner:
AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v2.200 - Datei am 15/04/2013 um 21:30:42 erstellt
# Aktualisiert am 02/04/2013 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzer : **NAME** - **NAME**-PC
# Bootmodus : Normal
# Ausgef¸hrt unter : C:\Users\**NAME**\Desktop\adwcleaner.exe
# Option [Lˆschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelˆscht : C:\Users\**NAME**\AppData\Roaming\Mozilla\Firefox\Profiles\89exxq82.default\searchplugins\Web Search.xml
Ordner Gelˆscht : C:\Users\**NAME**\AppData\Roaming\Mozilla\Firefox\Profiles\89exxq82.default\extensions\staged
Ordner Gelˆscht : C:\Users\**NAME**\AppData\Roaming\OpenCandy
Ordner Gelˆscht : C:\Users\**NAME**\AppData\Roaming\pdfforge

***** [Registrierungsdatenbank] *****

Schl¸ssel Gelˆscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schl¸ssel Gelˆscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schl¸ssel Gelˆscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schl¸ssel Gelˆscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schl¸ssel Gelˆscht : HKCU\Software\SmartBar
Schl¸ssel Gelˆscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schl¸ssel Gelˆscht : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}
Schl¸ssel Gelˆscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schl¸ssel Gelˆscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schl¸ssel Gelˆscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Wert Gelˆscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browser] *****

-\\ Internet Explorer v10.0.9200.16537

Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=ds&q={searchTerms}&installDate=14/04/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=hp&installDate=14/04/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=ds&q={searchTerms}&installDate=14/04/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=ds&q={searchTerms}&installDate=14/04/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=ds&q={searchTerms}&installDate=14/04/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=ds&q={searchTerms}&installDate=14/04/2013 --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=ds&q={searchTerms}&installDate=14/04/2013 --> hxxp://www.google.com

-\\ Mozilla Firefox v20.0.1 (de)

Datei : C:\Users\**NAME**\AppData\Roaming\Mozilla\Firefox\Profiles\89exxq82.default\prefs.js

Gelˆscht : user_pref("browser.search.selectedEngine", "Web Search");
Gelˆscht : user_pref("browser.startup.homepage", "hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=[...]
Gelˆscht : user_pref("extensions.helperbar.SmartbarDisabled", true);
Gelˆscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Gelˆscht : user_pref("keyword.URL", "hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=681[...]

*************************

AdwCleaner[S1].txt - [4391 octets] - [15/04/2013 21:30:42]

########## EOF - C:\AdwCleaner[S1].txt - [4451 octets] ##########
         
--- --- ---


OTL:
OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 15.04.2013 22:18:06 - Run 3
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\**NAME**\Desktop
 Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,99 Gb Total Physical Memory | 1,90 Gb Available Physical Memory | 63,58% Memory free
5,98 Gb Paging File | 4,81 Gb Available in Paging File | 80,41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144,17 Gb Total Space | 96,18 Gb Free Space | 66,71% Space Free | Partition Type: NTFS
Drive D: | 144,15 Gb Total Space | 11,23 Gb Free Space | 7,79% Space Free | Partition Type: NTFS
Drive F: | 14,83 Gb Total Space | 1,17 Gb Free Space | 7,88% Space Free | Partition Type: FAT32
 
Computer Name: **NAME**-PC | User Name: **NAME** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013.04.15 13:46:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\**NAME**\Desktop\OTL.exe
PRC - [2013.03.07 00:32:44 | 004,767,304 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe
PRC - [2013.03.07 00:32:44 | 000,045,248 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe
PRC - [2013.03.06 17:30:43 | 003,560,288 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2013.01.29 21:08:04 | 002,447,888 | ---- | M] (Check Point Software Technologies LTD) -- C:\Programme\CheckPoint\ZoneAlarm\vsmon.exe
PRC - [2013.01.29 20:35:36 | 000,073,832 | ---- | M] (Check Point Software Technologies LTD) -- C:\Programme\CheckPoint\ZoneAlarm\zatray.exe
PRC - [2012.11.23 04:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012.11.22 16:33:18 | 000,497,320 | ---- | M] (Check Point Software Technologies) -- C:\Programme\CheckPoint\ZAForceField\ISWSVC.exe
PRC - [2012.11.22 16:32:54 | 000,738,984 | ---- | M] (Check Point Software Technologies) -- C:\Programme\CheckPoint\ZAForceField\ForceField.exe
PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010.11.20 14:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.10.08 14:15:40 | 000,167,936 | ---- | M] (Mediafour Corporation) -- C:\Programme\Mediafour\MacDrive 8\MacDrive.exe
PRC - [2010.10.08 12:11:50 | 000,131,584 | ---- | M] (Mediafour Corporation) -- C:\Programme\Mediafour\MacDrive 8\MacDrive8Service.exe
 
 
========== Modules (No Company Name) ==========
 
 
========== Services (SafeList) ==========
 
SRV - [2013.04.10 08:56:49 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.03.07 00:32:44 | 000,045,248 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2013.03.06 17:30:43 | 003,560,288 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2013.02.28 19:09:08 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.01.29 21:08:04 | 002,447,888 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Programme\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon)
SRV - [2012.11.22 16:33:18 | 000,497,320 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Programme\CheckPoint\ZAForceField\ISWSVC.exe -- (IswSvc)
SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2010.10.08 12:11:50 | 000,131,584 | ---- | M] (Mediafour Corporation) [Auto | Running] -- C:\Programme\Mediafour\MacDrive 8\MacDrive8Service.exe -- (MacDrive8Service)
SRV - [2009.07.14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2006.10.26 19:49:34 | 000,441,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2013.03.07 00:33:24 | 000,765,736 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2013.03.07 00:33:24 | 000,368,176 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2013.03.07 00:33:24 | 000,164,736 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2013.03.07 00:33:24 | 000,062,376 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2013.03.07 00:33:24 | 000,049,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2013.03.07 00:33:23 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2013.03.07 00:33:23 | 000,060,656 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr)
DRV - [2013.03.07 00:33:22 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.12.13 11:49:38 | 000,454,744 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\Windows\System32\drivers\vsdatant.sys -- (Vsdatant)
DRV - [2012.11.22 16:33:30 | 000,027,056 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Programme\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL)
DRV - [2012.11.15 21:06:10 | 000,587,096 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\System32\drivers\klif.sys -- (KLIF)
DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010.10.07 15:36:04 | 000,234,160 | ---- | M] (Mediafour Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\MDFSYSNT.SYS -- (MDFSYSNT)
DRV - [2010.05.12 14:51:34 | 000,029,792 | ---- | M] (Mediafour Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\MDPMGRNT.SYS -- (MDPMGRNT)
DRV - [2010.05.12 14:42:50 | 000,057,800 | ---- | M] (EldoS Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\CBDisk.sys -- (CBDisk)
DRV - [2009.07.14 01:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
DRV - [2009.07.14 00:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = 
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = 
 
IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com
IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 5C E3 10 E7 C4 36 CE 01  [binary data]
IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com
IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com
IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: {68158704-666d-4655-a66f-e1a1a3aa6ac2}:1.0
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1483
FF - prefs.js..extensions.enabledAddons: %7B68158704-666d-4655-a66f-e1a1a3aa6ac2%7D:1.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.04.11 22:24:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2013.04.12 18:59:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 00:21:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
 
[2013.04.11 22:50:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\**NAME**\AppData\Roaming\mozilla\Extensions
[2013.04.15 21:30:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\**NAME**\AppData\Roaming\mozilla\Firefox\Profiles\89exxq82.default\extensions
[2013.04.11 22:50:16 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.04.11 22:24:55 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
File not found (No name found) -- C:\USERS\**NAME**\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\89EXXQ82.DEFAULT\EXTENSIONS\{68158704-666D-4655-A66F-E1A1A3AA6AC2}
[2013.04.10 08:57:39 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013.04.10 10:18:46 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.04.10 10:18:46 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013.04.10 10:18:46 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2013.04.10 10:18:46 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2013.04.10 10:18:46 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.04.10 10:18:46 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Getting started with MacDrive 8] C:\Program Files\Mediafour\MacDrive 8\MDGetStarted.exe (Mediafour Corporation)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [MacDrive 8 application] C:\Program Files\Mediafour\MacDrive 8\MacDrive.exe (Mediafour Corporation)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKU\.DEFAULT..\RunOnce: [SPReview] C:\Windows\System32\SPReview\SPReview.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [SPReview] C:\Windows\System32\SPReview\SPReview.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{71DB1997-A1B9-4F5C-BD32-383F1BED20D2}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{e63082c5-a2f8-11e2-93f3-001d72e49611}\Shell - "" = AutoRun
O33 - MountPoints2\{e63082c5-a2f8-11e2-93f3-001d72e49611}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.04.15 21:15:38 | 000,000,000 | ---D | C] -- C:\Windows\System32\appmgmt
[2013.04.15 14:09:03 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\**NAME**\Desktop\OTL.exe
[2013.04.14 10:54:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
[2013.04.14 10:54:41 | 000,088,576 | ---- | C] (pdfforge GbR) -- C:\Windows\System32\pdfcmon.dll
[2013.04.14 10:54:38 | 000,000,000 | ---D | C] -- C:\Program Files\PDFCreator
[2013.04.14 10:53:04 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Programs
[2013.04.13 13:59:01 | 000,000,000 | ---D | C] -- C:\Vegas_Prerender
[2013.04.13 13:58:12 | 000,000,000 | ---D | C] -- C:\Vegas_Data
[2013.04.13 13:32:50 | 000,000,000 | ---D | C] -- C:\Acer
[2013.04.13 13:31:06 | 000,000,000 | ---D | C] -- C:\Book
[2013.04.13 13:30:15 | 000,000,000 | ---D | C] -- C:\Treiber
[2013.04.13 13:25:11 | 000,000,000 | --SD | C] -- C:\Dropbox
[2013.04.13 13:20:50 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\Desktop\irgendwas
[2013.04.13 13:20:47 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\Desktop\DRUCK 29.8.12
[2013.04.13 13:20:32 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\Desktop\DriveNavi_for_HD-HSQ
[2013.04.13 13:20:31 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\Desktop\BORKUM
[2013.04.12 23:56:01 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\MAXON
[2013.04.12 19:10:10 | 000,000,000 | ---D | C] -- C:\Installationen
[2013.04.12 18:59:59 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\Documents\ForceField Shared Files
[2013.04.12 18:59:59 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\CheckPoint
[2013.04.12 18:59:38 | 000,587,096 | ---- | C] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys
[2013.04.12 18:59:38 | 000,075,096 | ---- | C] (Kaspersky Lab) -- C:\Windows\System32\drivers\klflt.sys
[2013.04.12 18:59:38 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2013.04.12 18:59:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
[2013.04.12 18:56:32 | 000,000,000 | ---D | C] -- C:\Program Files\CheckPoint
[2013.04.12 18:55:04 | 000,000,000 | ---D | C] -- C:\ProgramData\CheckPoint
[2013.04.12 18:50:11 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013.04.12 18:49:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2013.04.12 18:48:31 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Macromedia
[2013.04.12 18:48:03 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Adobe
[2013.04.12 14:13:09 | 000,000,000 | ---D | C] -- C:\Program Files\Tipp10
[2013.04.12 14:06:51 | 000,057,800 | ---- | C] (EldoS Corporation) -- C:\Windows\System32\drivers\CBDisk.sys
[2013.04.12 14:06:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MacDrive 8
[2013.04.12 14:06:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Mediafour
[2013.04.12 14:06:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Mediafour
[2013.04.12 14:05:27 | 000,000,000 | ---D | C] -- C:\Program Files\Mediafour
[2013.04.12 01:25:57 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\Documents\Ableton
[2013.04.12 01:25:57 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Ableton
[2013.04.12 01:25:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Ableton
[2013.04.12 01:24:20 | 000,233,472 | ---- | C] (Propellerhead Software AB) -- C:\Windows\System32\REX Shared Library.dll
[2013.04.12 01:24:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ableton
[2013.04.12 01:24:19 | 000,368,640 | ---- | C] (Propellerhead Software AB) -- C:\Windows\System32\ReWire.dll
[2013.04.12 01:21:52 | 000,000,000 | ---D | C] -- C:\Program Files\Ableton
[2013.04.12 00:48:24 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Publish Providers
[2013.04.12 00:33:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2013.04.12 00:33:06 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Sony
[2013.04.12 00:33:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony
[2013.04.12 00:33:06 | 000,000,000 | ---D | C] -- C:\Program Files\Sony
[2013.04.12 00:31:51 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Sony
[2013.04.12 00:29:46 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Apple Computer
[2013.04.12 00:23:42 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Apple Computer
[2013.04.12 00:21:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013.04.12 00:21:23 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2013.04.12 00:21:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2013.04.12 00:18:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2013.04.12 00:18:51 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Apple
[2013.04.12 00:18:49 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2013.04.12 00:18:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2013.04.12 00:09:25 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Diagnostics
[2013.04.11 23:58:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013.04.11 23:57:29 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2013.04.11 23:57:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2013.04.11 23:57:07 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2013.04.11 23:57:07 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2013.04.11 23:54:54 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Microsoft Help
[2013.04.11 23:54:47 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2013.04.11 23:54:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2013.04.11 23:54:22 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2013.04.11 23:41:20 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2013.04.11 23:38:42 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Skype
[2013.04.11 23:38:35 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2013.04.11 23:38:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013.04.11 23:38:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2013.04.11 23:38:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2013.04.11 23:36:53 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\JAM Software
[2013.04.11 23:36:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TreeSize Free
[2013.04.11 23:36:51 | 000,000,000 | ---D | C] -- C:\Program Files\JAM Software
[2013.04.11 23:33:38 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\REAPER
[2013.04.11 23:33:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REAPER
[2013.04.11 23:33:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Propellerhead Software
[2013.04.11 23:33:09 | 000,000,000 | ---D | C] -- C:\Program Files\REAPER
[2013.04.11 23:30:33 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\vlc
[2013.04.11 23:16:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013.04.11 23:16:09 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2013.04.11 23:15:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2013.04.11 23:15:15 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2013.04.11 23:02:47 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
[2013.04.11 23:02:47 | 000,000,000 | ---D | C] -- C:\Program Files\ASIO4ALL v2
[2013.04.11 22:50:24 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Mozilla
[2013.04.11 22:50:24 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Mozilla
[2013.04.11 22:50:17 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2013.04.11 22:50:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2013.04.11 22:50:14 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013.04.11 22:26:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2013.04.11 22:26:02 | 000,368,176 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2013.04.11 22:26:02 | 000,029,816 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2013.04.11 22:26:00 | 000,060,656 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys
[2013.04.11 22:25:59 | 000,062,376 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2013.04.11 22:25:58 | 000,765,736 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2013.04.11 22:25:54 | 000,228,600 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2013.04.11 22:25:54 | 000,066,336 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2013.04.11 22:24:42 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2013.04.11 22:24:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2013.04.11 22:22:29 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2013.04.11 21:44:24 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Adobe
[2013.04.11 18:56:14 | 000,000,000 | ---D | C] -- C:\Windows\System32\SPReview
[2013.04.11 18:55:56 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2013.04.11 18:53:59 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\System32\fms.dll
[2013.04.11 17:21:29 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2013.04.11 17:21:14 | 000,000,000 | -HSD | C] -- C:\Boot
[2013.04.11 17:04:54 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2013.04.11 16:53:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\Lang
[2013.04.11 16:53:57 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2013.04.11 16:49:35 | 000,000,000 | ---D | C] -- C:\Windows\System32\x64
[2013.04.11 16:30:56 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013.04.11 16:30:56 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Searches
[2013.04.11 16:30:56 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013.04.11 16:30:44 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Identities
[2013.04.11 16:30:42 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Contacts
[2013.04.11 16:30:34 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\VirtualStore
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Vorlagen
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\AppData\Local\Verlauf
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\AppData\Local\Temporary Internet Files
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Startmenü
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\SendTo
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Recent
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Netzwerkumgebung
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Lokale Einstellungen
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Documents\Eigene Videos
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Documents\Eigene Musik
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Eigene Dateien
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Documents\Eigene Bilder
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Druckumgebung
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Cookies
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\AppData\Local\Anwendungsdaten
[2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Anwendungsdaten
[2013.04.11 16:30:29 | 000,000,000 | --SD | C] -- C:\Users\**NAME**\AppData\Roaming\Microsoft
[2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Videos
[2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Saved Games
[2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Pictures
[2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Music
[2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Links
[2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Favorites
[2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Downloads
[2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Documents
[2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Desktop
[2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013.04.11 16:30:29 | 000,000,000 | -H-D | C] -- C:\Users\**NAME**\AppData
[2013.04.11 16:30:29 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Temp
[2013.04.11 16:30:29 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Microsoft
[2013.04.11 16:30:29 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Media Center Programs
[2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Recovery
[2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Programme
[2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2013.04.11 16:25:27 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2013.04.11 16:22:52 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2013.04.11 16:22:31 | 000,000,000 | -HSD | C] -- C:\System Volume Information
 
========== Files - Modified Within 30 Days ==========
 
[2013.04.15 22:09:10 | 000,021,376 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.04.15 22:09:10 | 000,021,376 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.04.15 22:01:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.04.15 22:01:36 | 2408,390,656 | -HS- | M] () -- C:\hiberfil.sys
[2013.04.15 16:56:46 | 000,613,083 | ---- | M] () -- C:\Users\**NAME**\Desktop\adwcleaner.exe
[2013.04.15 15:38:10 | 000,001,129 | -H-- | M] () -- C:\Windows\System32\BTImages.dat
[2013.04.15 14:10:10 | 000,000,000 | ---- | M] () -- C:\Users\**NAME**\defogger_reenable
[2013.04.15 14:09:18 | 000,643,866 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.04.15 14:09:18 | 000,607,190 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.04.15 14:09:18 | 000,126,394 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.04.15 14:09:18 | 000,103,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.04.15 13:58:28 | 000,377,856 | ---- | M] () -- C:\Users\**NAME**\Desktop\gmer_2.1.19163.exe
[2013.04.15 13:51:54 | 000,050,477 | ---- | M] () -- C:\Users\**NAME**\Desktop\Defogger.exe
[2013.04.15 13:46:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\**NAME**\Desktop\OTL.exe
[2013.04.14 10:54:45 | 000,000,989 | ---- | M] () -- C:\Users\Public\Desktop\PDFCreator.lnk
[2013.04.12 19:02:34 | 000,417,507 | ---- | M] () -- C:\Windows\System32\drivers\vsconfig.xml
[2013.04.12 14:00:25 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013.04.12 00:47:28 | 000,002,540 | ---- | M] () -- C:\Users\**NAME**\Documents\Vegas Pro registrieren.htm
[2013.04.12 00:00:06 | 000,301,088 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.04.11 23:46:42 | 000,007,597 | ---- | M] () -- C:\Users\**NAME**\AppData\Local\Resmon.ResmonCfg
[2013.04.11 23:02:47 | 000,001,096 | ---- | M] () -- C:\Users\**NAME**\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2013.04.11 22:25:54 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2013.04.11 21:06:29 | 000,025,185 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2013.04.11 17:48:58 | 000,001,750 | ---- | M] () -- C:\Users\Public\Desktop\Browserwahl.lnk
[2013.04.11 17:21:16 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2013.04.11 16:26:16 | 000,057,035 | ---- | M] () -- C:\Windows\System32\license.rtf
[2013.03.30 14:58:42 | 001,321,553 | ---- | M] () -- C:\Users\**NAME**\Desktop\Projektanmeldung_Protokoll_Gesangskurs_Borkum.jpg
[2013.03.30 14:58:42 | 001,304,191 | ---- | M] () -- C:\Users\**NAME**\Desktop\Projektanmeldung_Protokoll_Borkum_Doku.jpg
 
========== Files Created - No Company Name ==========
 
[2013.04.15 21:22:29 | 000,001,118 | ---- | C] () -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013.04.15 21:13:30 | 000,613,083 | ---- | C] () -- C:\Users\**NAME**\Desktop\adwcleaner.exe
[2013.04.15 15:37:19 | 000,001,129 | -H-- | C] () -- C:\Windows\System32\BTImages.dat
[2013.04.15 14:10:10 | 000,000,000 | ---- | C] () -- C:\Users\**NAME**\defogger_reenable
[2013.04.15 14:09:14 | 000,377,856 | ---- | C] () -- C:\Users\**NAME**\Desktop\gmer_2.1.19163.exe
[2013.04.15 14:08:59 | 000,050,477 | ---- | C] () -- C:\Users\**NAME**\Desktop\Defogger.exe
[2013.04.14 10:54:45 | 000,000,989 | ---- | C] () -- C:\Users\Public\Desktop\PDFCreator.lnk
[2013.04.13 13:20:54 | 001,499,884 | ---- | C] () -- C:\Users\**NAME**\Desktop\02 Spur 2.wma
[2013.04.13 13:20:54 | 001,321,553 | ---- | C] () -- C:\Users\**NAME**\Desktop\Projektanmeldung_Protokoll_Gesangskurs_Borkum.jpg
[2013.04.13 13:20:54 | 001,304,191 | ---- | C] () -- C:\Users\**NAME**\Desktop\Projektanmeldung_Protokoll_Borkum_Doku.jpg
[2013.04.13 13:20:54 | 000,229,613 | ---- | C] () -- C:\Users\**NAME**\Desktop\zeiten.pdf
[2013.04.13 13:20:54 | 000,057,176 | ---- | C] () -- C:\Users\**NAME**\Desktop\NINA_Exposé_290113.pdf
[2013.04.13 13:20:54 | 000,000,894 | ---- | C] () -- C:\Users\**NAME**\Desktop\ASIO4ALL v2 Anleitung.lnk
[2013.04.12 19:00:01 | 000,417,507 | ---- | C] () -- C:\Windows\System32\drivers\vsconfig.xml
[2013.04.12 14:00:25 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013.04.12 00:47:28 | 000,002,540 | ---- | C] () -- C:\Users\**NAME**\Documents\Vegas Pro registrieren.htm
[2013.04.12 00:18:50 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013.04.11 23:46:42 | 000,007,597 | ---- | C] () -- C:\Users\**NAME**\AppData\Local\Resmon.ResmonCfg
[2013.04.11 23:41:23 | 000,001,132 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
[2013.04.11 23:02:47 | 000,001,096 | ---- | C] () -- C:\Users\**NAME**\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2013.04.11 22:50:19 | 000,001,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013.04.11 22:25:58 | 000,164,736 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2013.04.11 22:25:57 | 000,049,248 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2013.04.11 21:06:29 | 000,025,185 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2013.04.11 18:54:37 | 000,146,852 | ---- | C] () -- C:\Windows\System32\systemsf.ebd
[2013.04.11 18:53:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2013.04.11 18:53:47 | 000,010,429 | ---- | C] () -- C:\Windows\System32\ScavengeSpace.xml
[2013.04.11 18:53:44 | 000,105,559 | ---- | C] () -- C:\Windows\System32\RacRules.xml
[2013.04.11 17:48:58 | 000,001,750 | ---- | C] () -- C:\Users\Public\Desktop\Browserwahl.lnk
[2013.04.11 17:21:16 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
[2013.04.11 17:21:15 | 000,383,786 | RHS- | C] () -- C:\bootmgr
[2013.04.11 16:53:57 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2013.04.11 16:53:57 | 000,121,232 | ---- | C] () -- C:\Windows\System32\IScrNB.bmp
[2013.04.11 16:30:58 | 000,001,409 | ---- | C] () -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013.04.11 16:26:12 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2013.04.11 16:26:01 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2013.04.11 16:22:32 | 2408,390,656 | -HS- | C] () -- C:\hiberfil.sys
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2013.04.12 01:25:57 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\Ableton
[2013.04.12 18:59:59 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\CheckPoint
[2013.04.12 18:50:11 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013.04.13 00:00:20 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\JAM Software
[2013.04.12 23:56:01 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\MAXON
[2013.04.12 00:48:24 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\Publish Providers
[2013.04.11 23:36:11 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\REAPER
[2013.04.12 01:03:17 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\Sony
 
========== Purity Check ==========
 
 

< End of report >
         
--- --- ---
__________________

 

Themen zu snap.do Startseite und Browserleiste (Firefox/Win7-32Bit) entfernen
antivirus, aswrvrt.sys, autorun, avast, awdcleaner, bho, chip.de, defender, entfernen, error, explorer, fehler, format, helper, install.exe, installation, kaspersky, logfile, mozilla, msvcrt, nicht möglich, ntdll.dll, problem, registry, rundll, scan, security, senden, services.exe, smartbar, snap do, svchost.exe, udp, windows internet




Ähnliche Themen: snap.do Startseite und Browserleiste (Firefox/Win7-32Bit) entfernen


  1. Win7 32Bit: Gesellschaft zur Verfügung von Urheberrechtsverletzungen
    Log-Analyse und Auswertung - 07.01.2015 (13)
  2. Win7: Firefox: Startseite "mystartsearch.com" unentfernbar, Windows-manger-protect setup, Browservirus?
    Plagegeister aller Art und deren Bekämpfung - 01.12.2014 (20)
  3. Snap.do Startseite bei Chrome und IE
    Log-Analyse und Auswertung - 06.04.2014 (10)
  4. Win7: Snap.Do und Internet Probleme
    Log-Analyse und Auswertung - 12.12.2013 (28)
  5. Win7-32bit: (GVU?) Trojaner inkl. Foto via WebCam
    Plagegeister aller Art und deren Bekämpfung - 16.10.2013 (7)
  6. Win7 - Startseite Firefox auf QV06 umgeleitet - Scan u. Desinfektion mit MbAM, nun weitere Funde nach online-Scan mit ESET
    Log-Analyse und Auswertung - 24.08.2013 (9)
  7. BKA/GVU Trojaner Win7 32bit
    Plagegeister aller Art und deren Bekämpfung - 18.06.2013 (21)
  8. Snap Do Seitenumleitung (Firefox/Win7)
    Log-Analyse und Auswertung - 15.04.2013 (16)
  9. "search.snap.do" als Startseite und "Snap.Do" auf Symbolleiste
    Plagegeister aller Art und deren Bekämpfung - 18.03.2013 (37)
  10. Claro Serch - Firefox startseite - Win7: lässt sich nicht entfernen. (FirmenPC)
    Plagegeister aller Art und deren Bekämpfung - 06.11.2012 (5)
  11. [Win7]32Bit Bka-Trojaner 1.13
    Plagegeister aller Art und deren Bekämpfung - 18.10.2012 (2)
  12. Win7 32bit GVU Trojaner
    Plagegeister aller Art und deren Bekämpfung - 17.10.2012 (3)
  13. BKA Trojaner 1.13 auf Win7 Home 32Bit
    Log-Analyse und Auswertung - 05.10.2012 (8)
  14. GVU Trojaner auf Win7 32bit
    Log-Analyse und Auswertung - 11.09.2012 (7)
  15. Win7/32bit Live Security Platinum
    Log-Analyse und Auswertung - 15.08.2012 (1)
  16. Befall mit BKA Trojaner, Win7 32bit
    Log-Analyse und Auswertung - 10.08.2012 (12)
  17. 4GB RAM unter Win7 32Bit
    Alles rund um Windows - 27.12.2010 (4)

Zum Thema snap.do Startseite und Browserleiste (Firefox/Win7-32Bit) entfernen - Super, vielen Dank! Firefox und IE haben jetzt keine snap.do Toolbar und Starseite mehr! Aber ist es damit vollständig behoben? adwCleaner: AdwCleaner Logfile: Code: Alles auswählen Aufklappen ATTFilter # AdwCleaner - snap.do Startseite und Browserleiste (Firefox/Win7-32Bit) entfernen...
Archiv
Du betrachtest: snap.do Startseite und Browserleiste (Firefox/Win7-32Bit) entfernen auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.