|
Plagegeister aller Art und deren Bekämpfung: lula Free Tec Adult Downloader wird immer angezeigtWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
27.08.2013, 19:28 | #1 |
| lula Free Tec Adult Downloader wird immer angezeigt Hallo ich brauche Hilfe. Es ist so das wenn ich meinen Laptop gestartet habe kommt immer einen Screen mit dem Titel lula TV Free Adult Downloader (Kein Internetexplorer bildschirm sonder so als ob es von einem Programm gesteuert wird. Ich habe Hiijacker ausgeführt und hier sind die Logfiles: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 19:58:28, on 27.08.2013 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v10.0 (10.00.9200.16660) Boot mode: Normal Running processes: C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe C:\Program Files (x86)\ASUS\Splendid\ACMON.exe C:\Windows\SysWOW64\ACEngSvr.exe C:\Program Files (x86)\Secunia\PSI\psi_tray.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Users\Lutz\Downloads\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://goggle.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE" O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe /S O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" O4 - Startup: An OneNote senden.lnk = C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files (x86)\Secunia\PSI\psi_tray.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: *.clonewarsadventures.com O15 - Trusted Zone: *.freerealms.com O15 - Trusted Zone: *.soe.com O15 - Trusted Zone: *.sony.com O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll, C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll O23 - Service: McAfee Application Installer Cleanup (0052531368808816) (0052531368808816mcinstcleanup) - Unknown owner - C:\Windows\TEMP\005253~1.EXE (file missing) O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe O23 - Service: Secunia Update Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\sua.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: System Store (SystemStoreService) - Unknown owner - C:\Program Files (x86)\SoftwareUpdater\SystemStore.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 10720 bytes Was kann das sein und was kann ich dagegen tun damit ich damit meinen pc optimal geschützt habe ich benutze noton 360° Vielen Dank schonmal im Voraus |
27.08.2013, 19:37 | #2 |
/// the machine /// TB-Ausbilder | lula Free Tec Adult Downloader wird immer angezeigt Hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
27.08.2013, 20:12 | #3 |
| lula Free Tec Adult Downloader wird immer angezeigt Hallo hier die Files
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-08-2013 03 Ran by Lutz (administrator) on 27-08-2013 20:54:26 Running from C:\Users\Lutz\Downloads Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (Intel Corporation) C:\Windows\system32\igfxpers.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (Microsoft Corporation) C:\Windows\system32\wwahost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe\LiveComm.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-13] (Realtek Semiconductor) HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-09-11] (ASUS) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-27] (NVIDIA Corporation) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [37960 2013-05-10] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2012-11-27] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe [3423104 2012-08-31] (ASUS Cloud Corporation) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] - C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.) AppInit_DLLs: C:\Windows\system32\nvinitx.dll, C:\PROGRA~1\NVIDIA~1\NVSTRE~1\rxinput.dll [653600 2013-07-27] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll, C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll [653600 2013-07-27] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) Startup: C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://goggle.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default FF Keyword.URL: hxxp://www.google.de/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF NetworkProxy: "type", 4 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default\searchplugins\computer-bild-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\IPSFFPlgn\ FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\IPSFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\coFFPlgn\ FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK FF Extension: No Name - C:\Program Files\McAfee\MSK ==================== Services (Whitelisted) ================= R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] () R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-20] (Symantec Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14984480 2013-07-27] (NVIDIA Corporation) R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1900728 2013-06-06] (Microsoft Corporation) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) S2 SystemStoreService; C:\Program Files (x86)\SoftwareUpdater\SystemStore.exe [296448 2013-08-26] () S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) S2 0052531368808816mcinstcleanup; C:\Windows\TEMP\005253~1.EXE -cleanup -nolog [x] ==================== Drivers (Whitelisted) ==================== R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [61824 2012-10-31] (ASUS Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-05-20] (Symantec Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-05-20] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [169048 2013-04-15] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-27] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-27] (Symantec Corporation) U3 EraserUtilDrv11311; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11311.sys [140376 2013-08-27] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-08-21] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\IPSDefs\20130826.001\IDSvia64.sys [520280 2013-08-14] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\IPSDefs\20130826.001\IDSvia64.sys [520280 2013-08-14] (Symantec Corporation) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130827.002\ENG64.SYS [126040 2013-08-18] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130827.002\ENG64.SYS [126040 2013-08-18] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130827.002\EX64.SYS [2098776 2013-08-18] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130827.002\EX64.SYS [2098776 2013-08-18] (Symantec Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39712 2013-05-14] (NVIDIA Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) R3 SRTSP; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSP64.SYS [796760 2013-05-15] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [36952 2013-03-04] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\1404000.028\SYMDS64.SYS [493656 2013-05-20] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1404000.028\SYMEFA64.SYS [1139800 2013-05-22] (Symantec Corporation) S0 SymELAM; C:\Windows\System32\drivers\N360x64\1404000.028\SymELAM.sys [23448 2013-03-04] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-08-19] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [224416 2013-03-04] (Symantec Corporation) R1 SymNetS; C:\Windows\system32\drivers\N360x64\1404000.028\SYMNETS.SYS [433752 2013-04-24] (Symantec Corporation) S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2013-06-21] (Anchorfree Inc.) U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-27 19:58 - 2013-08-27 19:58 - 00010722 _____ C:\Users\Lutz\Downloads\hijackthis.log 2013-08-27 15:03 - 2013-08-27 15:03 - 00000103 _____ C:\Windows\setupact.log 2013-08-27 15:03 - 2013-08-27 15:03 - 00000000 ____D C:\NvidiaLogging 2013-08-27 15:03 - 2013-08-27 15:03 - 00000000 _____ C:\Windows\setuperr.log 2013-08-27 15:03 - 2013-05-14 21:28 - 00039712 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-08-27 15:03 - 2013-05-14 21:27 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2013-08-27 15:03 - 2013-05-14 21:27 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-08-26 22:44 - 2013-08-27 13:44 - 00003196 _____ C:\Windows\PFRO.log 2013-08-26 19:13 - 2013-08-26 19:13 - 00003646 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint 2013-08-26 19:11 - 2013-08-26 22:43 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-26 19:10 - 2013-08-26 22:43 - 00000000 ____D C:\Program Files (x86)\FoxyDeal 2013-08-26 19:09 - 2013-08-27 16:06 - 00004208 _____ C:\Windows\System32\Tasks\Software Updater 2013-08-26 19:09 - 2013-08-27 16:06 - 00004142 _____ C:\Windows\System32\Tasks\Software Updater Ui 2013-08-26 19:08 - 2013-08-26 22:53 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-08-26 19:08 - 2013-08-26 19:10 - 00000000 ____D C:\Program Files (x86)\SoftwareUpdater 2013-08-26 19:03 - 2013-08-26 19:04 - 00000000 ____D C:\Users\Lutz\AppData\Local\DownloadGuide 2013-08-26 18:53 - 2013-08-26 21:33 - 1682428100 _____ C:\Users\Lutz\Downloads\rtws2014-demo-1.0a.zip 2013-08-26 14:54 - 2013-08-26 14:54 - 00444408 _____ C:\Users\Lutz\Downloads\free-system-utilities-DE.exe 2013-08-26 14:52 - 2013-08-27 19:58 - 00532359 _____ C:\Windows\WindowsUpdate.log 2013-08-24 15:27 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2013-08-24 15:27 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2013-08-24 15:26 - 2013-08-26 22:55 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-08-24 15:23 - 2013-08-24 15:25 - 17664368 _____ (Nullsoft, Inc.) C:\Users\Lutz\Downloads\winamp565_full_emusic-7plus_all.exe 2013-08-23 00:58 - 2013-08-23 00:58 - 00012882 _____ C:\Users\Lutz\Documents\Validation zusammenfassung grob.odt 2013-08-21 22:47 - 2013-08-21 22:47 - 00000000 ____D C:\ProgramData\Uniblue 2013-08-20 17:52 - 2013-08-20 17:52 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\OpenCandy 2013-08-20 17:46 - 2013-08-20 17:49 - 30190416 _____ (DVDVideoSoft Ltd. ) C:\Users\Lutz\Downloads\FreeYouTubeToMP3Converter.exe 2013-08-19 16:53 - 2013-08-19 16:53 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360 2013-08-19 16:52 - 2013-08-19 16:52 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-08-19 16:52 - 2013-08-19 16:52 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-08-19 16:52 - 2013-08-19 16:52 - 00002397 _____ C:\Users\Public\Desktop\Norton 360.lnk 2013-08-19 16:51 - 2013-08-19 16:51 - 00000000 ____D C:\Program Files (x86)\Norton 360 2013-08-19 16:37 - 2013-08-19 16:54 - 00000000 ____D C:\ProgramData\Norton 2013-08-19 16:37 - 2013-08-19 16:37 - 01019232 _____ (Symantec Corporation) C:\Users\Lutz\Downloads\N360Downloader.exe 2013-08-19 16:37 - 2013-08-19 16:37 - 00001270 _____ C:\Users\Lutz\Desktop\Norton-Installationsdateien.lnk 2013-08-19 16:21 - 2013-08-19 16:21 - 00866592 _____ C:\Users\Lutz\Downloads\Norton_Removal_Tool.exe 2013-08-19 15:43 - 2013-08-19 17:02 - 00000000 ____D C:\Users\Lutz\AppData\Local\LogMeIn Rescue Applet 2013-08-19 15:43 - 2013-08-19 15:43 - 00002178 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec.lnk 2013-08-18 21:54 - 2013-08-18 21:55 - 00000000 ____D C:\Windows\system32\MRT 2013-08-18 21:49 - 2013-07-02 02:44 - 00036288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2013-08-18 21:49 - 2013-07-02 00:08 - 00247216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2013-08-18 20:04 - 2013-08-18 20:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-14 11:41 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 11:41 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 11:41 - 2013-07-26 07:13 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-08-14 11:41 - 2013-07-26 07:13 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2013-08-14 11:41 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-14 11:41 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-14 11:41 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 11:41 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-14 11:41 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-14 11:41 - 2013-07-26 05:13 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-14 11:41 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-14 11:41 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-14 11:41 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-14 11:41 - 2013-07-26 02:54 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2013-08-14 11:40 - 2013-07-09 08:07 - 02233168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 11:40 - 2013-05-24 01:02 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 11:40 - 2013-05-24 00:25 - 00694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 11:35 - 2013-07-13 08:18 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 11:35 - 2013-07-13 08:16 - 01889280 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 11:35 - 2013-07-13 08:16 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 11:35 - 2013-07-13 08:15 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll 2013-08-14 11:35 - 2013-07-13 08:15 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll 2013-08-14 11:35 - 2013-07-13 06:24 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 11:35 - 2013-07-13 06:23 - 01568256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 11:35 - 2013-07-13 06:23 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll 2013-08-14 11:35 - 2013-07-13 06:23 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll 2013-08-14 02:09 - 2013-08-14 02:09 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\OpenOffice 2013-08-14 02:08 - 2013-08-14 02:09 - 00000000 ___SD C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.0 2013-08-14 02:08 - 2013-08-14 02:08 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-08-14 01:44 - 2013-08-14 01:58 - 162401424 _____ C:\Users\Lutz\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de.exe 2013-07-30 17:24 - 2013-07-30 17:24 - 00000000 ____D C:\Users\Lutz\AppData\Local\Secunia PSI 2013-07-30 17:24 - 2013-07-30 17:24 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ___RD C:\Users\Lutz\SkyDrive 2013-07-29 17:41 - 2013-07-29 17:41 - 00000000 ____D C:\Windows\ERUNT 2013-07-29 17:37 - 2013-07-29 17:37 - 00004568 _____ C:\AdwCleaner[S1].txt 2013-07-29 17:37 - 2013-07-29 17:37 - 00004408 _____ C:\AdwCleaner[R1].txt 2013-07-29 12:42 - 2013-07-29 12:42 - 00000000 ____D C:\FRST ==================== One Month Modified Files and Folders ======= 2013-08-27 20:53 - 2013-08-27 20:53 - 01579024 _____ (Farbar) C:\Users\Lutz\Downloads\FRST64.exe 2013-08-27 19:58 - 2013-08-27 19:58 - 00010722 _____ C:\Users\Lutz\Downloads\hijackthis.log 2013-08-27 19:58 - 2013-08-26 14:52 - 00532359 _____ C:\Windows\WindowsUpdate.log 2013-08-27 19:48 - 2013-05-16 17:54 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-27 19:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-08-27 16:06 - 2013-08-26 19:09 - 00004208 _____ C:\Windows\System32\Tasks\Software Updater 2013-08-27 16:06 - 2013-08-26 19:09 - 00004142 _____ C:\Windows\System32\Tasks\Software Updater Ui 2013-08-27 15:12 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-08-27 15:03 - 2013-08-27 15:03 - 00000103 _____ C:\Windows\setupact.log 2013-08-27 15:03 - 2013-08-27 15:03 - 00000000 ____D C:\NvidiaLogging 2013-08-27 15:03 - 2013-08-27 15:03 - 00000000 _____ C:\Windows\setuperr.log 2013-08-27 15:03 - 2012-12-28 18:22 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-08-27 15:03 - 2012-12-28 18:22 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-08-27 13:49 - 2013-05-16 15:24 - 00000507 _____ C:\Users\Lutz\AppData\Roaming\sp_data.sys 2013-08-27 13:45 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-27 13:44 - 2013-08-26 22:44 - 00003196 _____ C:\Windows\PFRO.log 2013-08-27 03:22 - 2012-07-26 07:26 - 00524288 ___SH C:\Windows\system32\config\BBI 2013-08-26 22:55 - 2013-08-24 15:26 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-08-26 22:53 - 2013-08-26 19:08 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-08-26 22:48 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\ELAM 2013-08-26 22:43 - 2013-08-26 19:11 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-26 22:43 - 2013-08-26 19:10 - 00000000 ____D C:\Program Files (x86)\FoxyDeal 2013-08-26 21:33 - 2013-08-26 18:53 - 1682428100 _____ C:\Users\Lutz\Downloads\rtws2014-demo-1.0a.zip 2013-08-26 19:13 - 2013-08-26 19:13 - 00003646 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint 2013-08-26 19:10 - 2013-08-26 19:08 - 00000000 ____D C:\Program Files (x86)\SoftwareUpdater 2013-08-26 19:04 - 2013-08-26 19:03 - 00000000 ____D C:\Users\Lutz\AppData\Local\DownloadGuide 2013-08-26 14:54 - 2013-08-26 14:54 - 00444408 _____ C:\Users\Lutz\Downloads\free-system-utilities-DE.exe 2013-08-25 03:58 - 2013-05-16 15:21 - 00000000 ____D C:\Users\Lutz\AppData\Local\VirtualStore 2013-08-24 15:59 - 2013-05-16 15:21 - 00002242 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2013-08-24 15:25 - 2013-08-24 15:23 - 17664368 _____ (Nullsoft, Inc.) C:\Users\Lutz\Downloads\winamp565_full_emusic-7plus_all.exe 2013-08-24 15:09 - 2013-05-16 15:31 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2984763435-1055683380-3862706603-1002 2013-08-23 15:26 - 2013-05-23 15:51 - 00000000 ____D C:\ProgramData\CanonIJPLM 2013-08-23 00:58 - 2013-08-23 00:58 - 00012882 _____ C:\Users\Lutz\Documents\Validation zusammenfassung grob.odt 2013-08-21 22:47 - 2013-08-21 22:47 - 00000000 ____D C:\ProgramData\Uniblue 2013-08-21 13:57 - 2013-06-17 15:10 - 00000000 ____D C:\Users\Lutz\AppData\Local\CrashDumps 2013-08-20 17:52 - 2013-08-20 17:52 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\OpenCandy 2013-08-20 17:49 - 2013-08-20 17:46 - 30190416 _____ (DVDVideoSoft Ltd. ) C:\Users\Lutz\Downloads\FreeYouTubeToMP3Converter.exe 2013-08-19 17:02 - 2013-08-19 15:43 - 00000000 ____D C:\Users\Lutz\AppData\Local\LogMeIn Rescue Applet 2013-08-19 17:00 - 2012-07-26 10:12 - 00000000 ___HD C:\Windows\ELAMBKUP 2013-08-19 16:54 - 2013-08-19 16:37 - 00000000 ____D C:\ProgramData\Norton 2013-08-19 16:53 - 2013-08-19 16:53 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360 2013-08-19 16:52 - 2013-08-19 16:52 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-08-19 16:52 - 2013-08-19 16:52 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-08-19 16:52 - 2013-08-19 16:52 - 00002397 _____ C:\Users\Public\Desktop\Norton 360.lnk 2013-08-19 16:52 - 2013-05-21 18:02 - 00003206 _____ C:\Windows\System32\Tasks\Norton WSC Integration 2013-08-19 16:52 - 2013-05-21 18:02 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared 2013-08-19 16:51 - 2013-08-19 16:51 - 00000000 ____D C:\Program Files (x86)\Norton 360 2013-08-19 16:37 - 2013-08-19 16:37 - 01019232 _____ (Symantec Corporation) C:\Users\Lutz\Downloads\N360Downloader.exe 2013-08-19 16:37 - 2013-08-19 16:37 - 00001270 _____ C:\Users\Lutz\Desktop\Norton-Installationsdateien.lnk 2013-08-19 16:37 - 2013-06-11 11:52 - 00000000 ____D C:\Users\Public\Downloads\Norton 2013-08-19 16:27 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\SysWOW64\en-GB 2013-08-19 16:21 - 2013-08-19 16:21 - 00866592 _____ C:\Users\Lutz\Downloads\Norton_Removal_Tool.exe 2013-08-19 15:43 - 2013-08-19 15:43 - 00002178 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec.lnk 2013-08-19 12:11 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache 2013-08-19 00:50 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Defender 2013-08-19 00:50 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-08-18 21:55 - 2013-08-18 21:54 - 00000000 ____D C:\Windows\system32\MRT 2013-08-18 21:54 - 2013-05-17 16:38 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-18 21:31 - 2013-05-16 16:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-18 20:43 - 2013-06-15 23:06 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MgameEU 2013-08-18 20:04 - 2013-08-18 20:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-14 21:42 - 2013-07-13 18:47 - 00448888 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-14 02:09 - 2013-08-14 02:09 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\OpenOffice 2013-08-14 02:09 - 2013-08-14 02:08 - 00000000 ___SD C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.0 2013-08-14 02:08 - 2013-08-14 02:08 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-08-14 01:58 - 2013-08-14 01:44 - 162401424 _____ C:\Users\Lutz\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de.exe 2013-07-31 13:26 - 2012-08-03 01:02 - 00753134 _____ C:\Windows\system32\perfh007.dat 2013-07-31 13:26 - 2012-08-03 01:02 - 00155826 _____ C:\Windows\system32\perfc007.dat 2013-07-31 13:26 - 2012-07-26 09:28 - 01745416 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-30 17:24 - 2013-07-30 17:24 - 00000000 ____D C:\Users\Lutz\AppData\Local\Secunia PSI 2013-07-30 17:24 - 2013-07-30 17:24 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ___RD C:\Users\Lutz\SkyDrive 2013-07-30 15:10 - 2013-05-16 15:21 - 00000000 ____D C:\Users\Lutz 2013-07-29 17:41 - 2013-07-29 17:41 - 00000000 ____D C:\Windows\ERUNT 2013-07-29 17:37 - 2013-07-29 17:37 - 00004568 _____ C:\AdwCleaner[S1].txt 2013-07-29 17:37 - 2013-07-29 17:37 - 00004408 _____ C:\AdwCleaner[R1].txt 2013-07-29 14:01 - 2013-07-27 11:04 - 00000408 _____ C:\Users\Gast\AppData\Roaming\sp_data.sys 2013-07-29 12:42 - 2013-07-29 12:42 - 00000000 ____D C:\FRST Files to move or delete: ==================== C:\ProgramData\SetStretch.exe C:\Users\Lutz\AppData\Local\Temp\WDE5A73.tmp\CddbLangDE.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\setup.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\NvVAD\nvaudcap32v.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\NvVAD\nvaudcap64v.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\NvVAD\nvgenco32.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\NvVAD\nvgenco64.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\NVI2\NVI2.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\NVI2\NVI2UI.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\NVI2\NVPrxy32.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\NVI2\NVPrxy64.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\NVI2\ReleaseHighlights.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\MS.NET\dotNetFx40_Full_setup.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\MS.NET\MSNetExt.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\x86\server\clrzmq.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\x86\server\detoured.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\x86\server\libzmq.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\x86\server\nvFBC.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\x86\server\nvsteamsupport.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\x86\server\nvstreamer.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\x86\server\nvstreamsvc.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\x86\server\protobuf-net.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\x86\server\rxinput.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\x86\server\steam_api.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\SteamLauncher\NVIDIA.SteamLauncher.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\amd64\server\detoured.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\amd64\server\libzmq.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\amd64\server\nvFBC.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\amd64\server\nvsteamsupport.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\amd64\server\nvstreamer.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\amd64\server\nvstreamsvc.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\amd64\server\rxinput.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience.NvStreamSrv\amd64\server\steam_api64.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\7z.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\DisplayCplExt.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\ExtensionLoader.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\GalaSoft.MvvmLight.Extras.WPF4.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\GalaSoft.MvvmLight.WPF4.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\GFExperience.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\GFExperienceControls.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\GFExperienceCore.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\GFExperienceExt.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\GridService.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\InstallerService.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\InstallerUIExtension.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\log4net.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\Microsoft.Practices.ServiceLocation.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\Microsoft.WindowsAPICodePack.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\Microsoft.WindowsAPICodePack.Shell.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\NVIDIA.Settings.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\NVIDIA.Settings.Properties.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\NVIDIA.UpdateService.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\NVIDIA.Win32Api.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\nvtmru.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\oaremote_plugin.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\ShadowPlay.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\System.Reactive.Core.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\System.Reactive.Interfaces.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\System.Reactive.Linq.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\System.Reactive.PlatformServices.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\System.Reactive.Providers.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\System.Reactive.Runtime.Remoting.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\System.Reactive.Windows.Threading.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\System.Windows.Interactivity.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\zh-CHT\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\zh-CHS\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\tr-TR\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\th-TH\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\sv-SE\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\sl-SI\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\sk-SK\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\ru-RU\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\pt-PT\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\pt-BR\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\pl-PL\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\nl-NL\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\nb-NO\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\ko-KR\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\ja-JP\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\it-IT\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\hu-HU\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\he-IL\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\fr-FR\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\fi-FI\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\es-MX\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\es-ES\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\en-US\GFExperience.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\en-US\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\en-GB\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\el-GR\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\de-DE\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\da-DK\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\cs-CZ\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\GFExperience\ar-AE\GFExperienceControls.resources.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\ComUpdatus.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\daemonu.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\easyDaemonAPIU32.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\easyDaemonAPIU64.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\nvupdt32.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\nvupdt64.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\nvupdtr32.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\nvupdtr64.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\nvupdtrXP32.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\nvupdtrXP64.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\nvupdtXP32.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\nvupdtXP64.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\UpdateExt.dll C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Update\WLMerger.exe C:\Users\Lutz\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\7.2.17.0\Display.Optimus\OptimusExt.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-20 11:23 ==================== End Of Log ============================ --- --- --- ich habe alle so ausgeführt wie oben beschrieben trotzdem zeigt er mir nach dem scan nur eine FRST.txt an keine addition.txt |
28.08.2013, 08:15 | #4 | |
/// the machine /// TB-Ausbilder | lula Free Tec Adult Downloader wird immer angezeigt Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.08.2013, 14:56 | #5 |
| lula Free Tec Adult Downloader wird immer angezeigt Hallo anbei die Ergebniss von ComboFix Combofix Logfile: Code:
ATTFilter ComboFix 13-08-28.02 - Lutz 28.08.2013 13:55:01.4.4 - x64 Microsoft Windows 8 6.2.9200.0.1252.49.1031.18.8077.6948 [GMT 2:00] ausgeführt von:: c:\users\Lutz\Desktop\ComboFix.exe AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton 360 *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2013-07-28 bis 2013-08-28 )))))))))))))))))))))))))))))) . . 2013-08-28 12:03 . 2013-08-28 12:03 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-08-28 12:03 . 2013-08-28 12:03 -------- d-----w- c:\users\Lutz\AppData\Local\temp 2013-08-28 12:03 . 2013-08-28 12:03 -------- d-----w- c:\users\Gast\AppData\Local\temp 2013-08-28 12:03 . 2013-08-28 12:03 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-08-28 11:09 . 2013-08-28 11:09 -------- d-----w- c:\program files (x86)\Common Files\Symantec Shared 2013-08-28 09:56 . 2013-08-28 09:56 177312 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS 2013-08-28 09:55 . 2013-05-22 21:25 1139800 ----a-r- c:\windows\system32\drivers\N360x64\1404000.028\SymEFA64.sys 2013-08-28 09:55 . 2013-05-20 21:02 493656 ----a-r- c:\windows\system32\drivers\N360x64\1404000.028\SymDS64.sys 2013-08-28 09:55 . 2013-05-15 21:02 796760 ----a-r- c:\windows\system32\drivers\N360x64\1404000.028\srtsp64.sys 2013-08-28 09:55 . 2013-04-24 16:43 433752 ----a-r- c:\windows\system32\drivers\N360x64\1404000.028\symnets.sys 2013-08-28 09:55 . 2013-04-15 18:41 169048 ----a-r- c:\windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys 2013-08-28 09:55 . 2013-03-04 18:14 23448 ----a-r- c:\windows\system32\drivers\N360x64\1404000.028\SymELAM.sys 2013-08-28 09:55 . 2013-03-04 17:40 224416 ----a-r- c:\windows\system32\drivers\N360x64\1404000.028\Ironx64.sys 2013-08-28 09:55 . 2013-03-04 17:21 36952 ----a-r- c:\windows\system32\drivers\N360x64\1404000.028\srtspx64.sys 2013-08-28 09:55 . 2013-08-28 09:55 -------- d-----w- c:\program files (x86)\Norton 360 2013-08-27 13:03 . 2013-08-27 13:03 -------- d-----w- C:\NvidiaLogging 2013-08-27 13:03 . 2013-05-14 19:28 39712 ----a-w- c:\windows\system32\drivers\nvvad64v.sys 2013-08-27 13:03 . 2013-05-14 19:27 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll 2013-08-27 13:03 . 2013-05-14 19:27 28448 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll 2013-08-26 17:10 . 2013-08-26 20:43 -------- d-----w- c:\program files (x86)\FoxyDeal 2013-08-26 17:08 . 2013-08-26 17:10 -------- d-----w- c:\program files (x86)\SoftwareUpdater 2013-08-26 17:08 . 2013-08-26 20:53 -------- d-----w- c:\program files (x86)\Web Check 2013-08-26 17:03 . 2013-08-26 17:04 -------- d-----w- c:\users\Lutz\AppData\Local\DownloadGuide 2013-08-24 13:27 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll 2013-08-24 13:27 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\SysWow64\d3dx9_31.dll 2013-08-24 13:26 . 2013-08-24 13:26 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine 2013-08-24 13:26 . 2013-08-26 20:55 -------- d-----w- c:\program files (x86)\Winamp 2013-08-21 20:47 . 2013-08-21 20:47 -------- d-----w- c:\programdata\Uniblue 2013-08-20 15:52 . 2013-08-20 15:52 -------- d-----w- c:\users\Lutz\AppData\Roaming\OpenCandy 2013-08-19 14:51 . 2013-08-28 09:55 -------- d-----w- c:\program files (x86)\NortonInstaller 2013-08-19 14:37 . 2013-08-28 09:59 -------- d-----w- c:\programdata\Norton 2013-08-19 13:43 . 2013-08-28 10:10 -------- d-----w- c:\users\Lutz\AppData\Local\LogMeIn Rescue Applet 2013-08-18 19:54 . 2013-08-18 19:55 -------- d-----w- c:\windows\system32\MRT 2013-08-14 09:40 . 2013-05-23 23:02 1314816 ----a-w- c:\windows\system32\rpcrt4.dll 2013-08-14 09:40 . 2013-05-23 22:25 694272 ----a-w- c:\windows\SysWow64\rpcrt4.dll 2013-08-14 09:40 . 2013-07-09 06:07 2233168 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-08-14 09:35 . 2013-07-13 06:18 337408 ----a-w- c:\windows\system32\wintrust.dll 2013-08-14 09:35 . 2013-07-13 06:16 68096 ----a-w- c:\windows\system32\cryptsvc.dll 2013-08-14 09:35 . 2013-07-13 06:16 1889280 ----a-w- c:\windows\system32\crypt32.dll 2013-08-14 09:35 . 2013-07-13 06:15 98304 ----a-w- c:\windows\system32\apprepsync.dll 2013-08-14 09:35 . 2013-07-13 06:15 124416 ----a-w- c:\windows\system32\apprepapi.dll 2013-08-14 09:35 . 2013-07-13 04:24 261120 ----a-w- c:\windows\SysWow64\wintrust.dll 2013-08-14 09:35 . 2013-07-13 04:23 1568256 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-08-14 09:35 . 2013-07-13 04:23 87040 ----a-w- c:\windows\SysWow64\apprepapi.dll 2013-08-14 09:35 . 2013-07-13 04:23 74240 ----a-w- c:\windows\SysWow64\apprepsync.dll 2013-08-14 00:09 . 2013-08-14 00:09 -------- d-----w- c:\users\Lutz\AppData\Roaming\OpenOffice 2013-08-14 00:08 . 2013-08-14 00:08 -------- d-----w- c:\program files (x86)\OpenOffice 4 2013-07-30 15:24 . 2013-07-30 15:24 -------- d-----w- c:\users\Lutz\AppData\Local\Secunia PSI 2013-07-30 15:24 . 2013-07-30 15:24 -------- d-----w- c:\program files (x86)\Secunia 2013-07-30 13:10 . 2013-07-30 13:10 -------- d-----r- c:\users\Lutz\SkyDrive 2013-07-29 15:41 . 2013-07-29 15:41 -------- d-----w- c:\windows\ERUNT . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-28 11:51 . 2013-05-16 13:24 507 ----a-w- c:\users\Lutz\AppData\Roaming\sp_data.sys 2013-08-18 19:54 . 2013-05-17 14:38 78161360 ----a-w- c:\windows\system32\MRT.exe 2013-07-29 12:01 . 2013-07-27 09:04 408 ----a-w- c:\users\Gast\AppData\Roaming\sp_data.sys 2013-07-03 08:32 . 2013-07-03 08:32 18456 ----a-w- c:\windows\system32\drivers\psi_mf_amd64.sys 2013-06-27 22:04 . 2013-05-17 16:39 78200 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-27 22:04 . 2013-05-17 16:39 693112 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-06-21 12:06 . 2013-07-01 22:35 9239344 ----a-w- c:\windows\system32\nvcuda.dll 2013-06-21 12:06 . 2013-07-01 22:35 7687592 ----a-w- c:\windows\SysWow64\nvcuda.dll 2013-06-21 12:06 . 2013-07-01 22:35 7641832 ----a-w- c:\windows\system32\nvopencl.dll 2013-06-21 12:06 . 2013-07-01 22:35 6324360 ----a-w- c:\windows\SysWow64\nvopencl.dll 2013-06-21 12:06 . 2013-07-01 22:35 572704 ----a-w- c:\windows\system32\NvFBC64.dll 2013-06-21 12:06 . 2013-07-01 22:35 570656 ----a-w- c:\windows\system32\NvIFR64.dll 2013-06-21 12:06 . 2013-07-01 22:35 467232 ----a-w- c:\windows\SysWow64\NvIFR.dll 2013-06-21 12:06 . 2013-07-01 22:35 465184 ----a-w- c:\windows\SysWow64\NvFBC.dll 2013-06-21 12:06 . 2013-07-01 22:35 30496 ----a-w- c:\windows\system32\drivers\nvpciflt.sys 2013-06-21 12:06 . 2013-07-01 22:35 2953504 ----a-w- c:\windows\system32\nvcuvid.dll 2013-06-21 12:06 . 2013-07-01 22:35 27781920 ----a-w- c:\windows\system32\nvoglv64.dll 2013-06-21 12:06 . 2013-07-01 22:35 2777888 ----a-w- c:\windows\SysWow64\nvcuvid.dll 2013-06-21 12:06 . 2013-07-01 22:35 2363680 ----a-w- c:\windows\system32\nvcuvenc.dll 2013-06-21 12:06 . 2013-07-01 22:35 218592 ----a-w- c:\windows\system32\nvoglshim64.dll 2013-06-21 12:06 . 2013-07-01 22:35 21102368 ----a-w- c:\windows\SysWow64\nvoglv32.dll 2013-06-21 12:06 . 2013-07-01 22:35 2002720 ----a-w- c:\windows\SysWow64\nvcuvenc.dll 2013-06-21 12:06 . 2013-07-01 22:35 1832224 ----a-w- c:\windows\system32\nvdispco6432049.dll 2013-06-21 12:06 . 2013-07-01 22:35 181488 ----a-w- c:\windows\SysWow64\nvoglshim32.dll 2013-06-21 12:06 . 2013-07-01 22:35 15920536 ----a-w- c:\windows\system32\nvwgf2umx.dll 2013-06-21 12:06 . 2013-07-01 22:35 15144928 ----a-w- c:\windows\system32\nvd3dumx.dll 2013-06-21 12:06 . 2013-07-01 22:35 1511712 ----a-w- c:\windows\system32\nvdispgenco6432049.dll 2013-06-21 12:06 . 2013-07-01 22:35 13411896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2013-06-21 12:06 . 2013-07-01 22:35 11235104 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2013-06-21 12:06 . 2013-07-01 22:35 25256224 ----a-w- c:\windows\system32\nvcompiler.dll 2013-06-21 12:06 . 2013-07-01 22:35 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll 2013-06-21 12:06 . 2013-05-23 18:11 2597856 ----a-w- c:\windows\SysWow64\nvapi.dll 2013-06-21 12:06 . 2013-05-17 16:17 12427240 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2013-06-21 12:06 . 2012-12-28 16:22 2936208 ----a-w- c:\windows\system32\nvapi64.dll 2013-06-21 12:06 . 2012-12-28 16:22 925648 ----a-w- c:\windows\SysWow64\nvumdshim.dll 2013-06-21 12:06 . 2012-12-28 16:22 266448 ----a-w- c:\windows\system32\nvinitx.dll 2013-06-21 12:06 . 2012-12-28 16:22 214448 ----a-w- c:\windows\SysWow64\nvinit.dll 2013-06-21 12:06 . 2012-12-28 16:22 1059560 ----a-w- c:\windows\system32\nvumdshimx.dll 2013-06-21 10:23 . 2012-12-28 16:23 6496544 ----a-w- c:\windows\system32\nvcpl.dll 2013-06-21 10:23 . 2012-12-28 16:23 3514656 ----a-w- c:\windows\system32\nvsvc64.dll 2013-06-21 10:23 . 2012-12-28 16:23 884512 ----a-w- c:\windows\system32\nvvsvc.exe 2013-06-21 10:23 . 2012-12-28 16:23 67072 ----a-w- c:\windows\system32\nv3dappshextr.dll 2013-06-21 10:23 . 2012-12-28 16:23 63776 ----a-w- c:\windows\system32\nvshext.dll 2013-06-21 10:23 . 2012-12-28 16:23 2555680 ----a-w- c:\windows\system32\nvsvcr.dll 2013-06-21 10:23 . 2012-12-28 16:23 237856 ----a-w- c:\windows\system32\nvmctray.dll 2013-06-21 10:23 . 2012-12-28 16:23 1025312 ----a-w- c:\windows\system32\nv3dappshext.dll 2013-06-21 01:09 . 2013-06-21 01:09 42184 ----a-w- c:\windows\system32\drivers\taphss6.sys 2013-06-20 04:17 . 2012-12-28 16:23 3253909 ----a-w- c:\windows\system32\nvcoproc.bin 2013-06-16 22:41 . 2013-07-25 14:09 997632 ----a-w- c:\windows\system32\drivers\ndis.sys 2013-06-14 06:36 . 2013-05-16 13:41 564432 ----a-w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe 2013-06-01 11:54 . 2013-07-25 14:10 194816 ----a-w- c:\windows\system32\drivers\sdbus.sys 2013-06-01 11:54 . 2013-07-25 14:10 125184 ----a-w- c:\windows\system32\drivers\dumpsd.sys 2013-06-01 11:34 . 2013-07-25 14:10 2391280 ----a-w- c:\windows\explorer.exe 2013-06-01 11:29 . 2013-07-25 14:10 337152 ----a-w- c:\windows\system32\drivers\USBXHCI.SYS 2013-06-01 11:29 . 2013-07-25 14:10 213248 ----a-w- c:\windows\system32\drivers\UCX01000.SYS 2013-06-01 11:26 . 2013-07-25 14:10 327936 ----a-w- c:\windows\system32\drivers\volsnap.sys 2013-06-01 11:26 . 2013-07-25 14:10 6987008 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-06-01 10:24 . 2013-07-25 14:10 2106176 ----a-w- c:\windows\SysWow64\explorer.exe 2013-06-01 09:25 . 2013-07-25 14:10 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-06-01 09:25 . 2013-07-25 14:10 67584 ----a-w- c:\windows\SysWow64\samlib.dll 2013-06-01 09:25 . 2013-07-12 12:55 496640 ----a-w- c:\windows\SysWow64\qedit.dll 2013-06-01 09:24 . 2013-07-25 14:10 493056 ----a-w- c:\windows\SysWow64\mscms.dll 2013-06-01 09:24 . 2013-07-25 14:10 1453568 ----a-w- c:\windows\SysWow64\mfcore.dll 2013-06-01 09:24 . 2013-07-25 14:10 850944 ----a-w- c:\windows\SysWow64\mfasfsrcsnk.dll 2013-06-01 09:23 . 2013-07-25 14:10 1842176 ----a-w- c:\windows\SysWow64\dwmcore.dll 2013-06-01 09:23 . 2013-07-25 14:10 680960 ----a-w- c:\windows\system32\vds.exe 2013-06-01 09:22 . 2013-07-25 14:10 80896 ----a-w- c:\windows\system32\MbaeParserTask.exe 2013-06-01 09:22 . 2013-07-25 14:10 523264 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-06-01 09:22 . 2013-07-25 14:10 446976 ----a-w- c:\windows\system32\wwansvc.dll 2013-06-01 09:22 . 2013-07-25 14:10 190976 ----a-w- c:\windows\system32\vdsutil.dll 2013-06-01 09:21 . 2013-07-25 14:10 729600 ----a-w- c:\windows\system32\samsrv.dll 2013-06-01 09:21 . 2013-07-25 14:10 106496 ----a-w- c:\windows\system32\samlib.dll 2013-06-01 09:21 . 2013-07-12 12:55 595968 ----a-w- c:\windows\system32\qedit.dll 2013-06-01 09:20 . 2013-07-25 14:10 583168 ----a-w- c:\windows\system32\mscms.dll 2013-06-01 09:20 . 2013-07-25 14:10 1527808 ----a-w- c:\windows\system32\mfcore.dll 2013-06-01 09:20 . 2013-07-25 14:10 1048576 ----a-w- c:\windows\system32\mfasfsrcsnk.dll 2013-06-01 09:20 . 2013-07-25 14:10 2219520 ----a-w- c:\windows\system32\dwmcore.dll 2013-06-01 09:19 . 2013-07-25 14:10 207872 ----a-w- c:\windows\system32\DeviceSetupManager.dll 2013-06-01 09:19 . 2013-07-25 14:10 785408 ----a-w- c:\windows\system32\audiosrv.dll 2013-06-01 03:08 . 2013-07-25 14:10 37632 ----a-w- c:\windows\system32\drivers\BthAvrcpTg.sys 2013-05-30 23:24 . 2013-06-18 21:21 1257472 ----a-w- c:\windows\system32\kernel32.dll 2013-05-30 23:14 . 2013-07-12 13:23 4036096 ----a-w- c:\windows\system32\win32k.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-08-24 13:58 222832 ----a-w- c:\users\Lutz\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-08-24 13:58 222832 ----a-w- c:\users\Lutz\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-08-24 13:58 222832 ----a-w- c:\users\Lutz\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2013-05-10 37960] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2012-11-27 3187360] "ASUSWebStorage"="c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe" [2012-08-31 3423104] "IJNetworkScannerSelectorEX"="c:\program files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2012-03-26 449168] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-31 152392] . c:\users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ An OneNote senden.lnk - c:\program files\Microsoft Office 15\root\office15\onenotem.exe /tsr [2013-5-22 158808] . c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\ Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2013-7-3 563416] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "EnableUIADesktopToggle"= 0 (0x0) "EnableCursorSuppression"= 1 (0x1) "ConsentPromptBehaviorUser"= 3 (0x3) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll c:\progra~2\NVIDIA~1\NVSTRE~1\rxinput.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 0052531368808816mcinstcleanup;McAfee Application Installer Cleanup (0052531368808816);c:\windows\TEMP\005253~1.EXE;c:\windows\TEMP\005253~1.EXE [x] R2 SystemStoreService;System Store;c:\program files (x86)\SoftwareUpdater\SystemStore.exe -displayname System Store -servicename SystemStoreService;c:\program files (x86)\SoftwareUpdater\SystemStore.exe -displayname System Store -servicename SystemStoreService [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf_amd64.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf_amd64.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x] R3 WSDScan;WSD-Scanunterstützung;c:\windows\System32\drivers\WSDScan.sys;c:\windows\SYSNATIVE\drivers\WSDScan.sys [x] R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x] R4 SymELAM;Symantec ELAM Driver;c:\windows\system32\drivers\N360x64\1404000.028\SymELAM.sys;c:\windows\SYSNATIVE\drivers\N360x64\1404000.028\SymELAM.sys [x] S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\1404000.028\SYMDS64.SYS;c:\windows\SYSNATIVE\drivers\N360x64\1404000.028\SYMDS64.SYS [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\1404000.028\SYMEFA64.SYS;c:\windows\SYSNATIVE\drivers\N360x64\1404000.028\SYMEFA64.SYS [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [x] S1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys;c:\windows\SYSNATIVE\drivers\N360x64\1404000.028\ccSetx64.sys [x] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\IPSDefs\20130827.001\IDSvia64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\IPSDefs\20130827.001\IDSvia64.sys [x] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS;c:\windows\SYSNATIVE\drivers\N360x64\1404000.028\Ironx64.SYS [x] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\N360x64\1404000.028\SYMNETS.SYS;c:\windows\SYSNATIVE\drivers\N360x64\1404000.028\SYMNETS.SYS [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe;c:\program files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [x] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe;c:\program files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 OfficeSvc;Microsoft Office-Dienst;c:\program files\Microsoft Office 15\ClientX64\integratedoffice.exe;c:\program files\Microsoft Office 15\ClientX64\integratedoffice.exe [x] S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe [x] S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe;c:\program files (x86)\Secunia\PSI\sua.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 AiCharger;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AiCharger.sys [x] S3 ATP;ASUS PS/2 Port Input Device;c:\windows\System32\drivers\AsusTP.sys;c:\windows\SYSNATIVE\drivers\AsusTP.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 HIDSwitch;ASUS Wireless Radio Control;c:\windows\System32\drivers\AsHIDSwitch64.sys;c:\windows\SYSNATIVE\drivers\AsHIDSwitch64.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 RSBASTOR;Realtek PCIE CardReader Driver - BA;c:\windows\system32\DRIVERS\RtsBaStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsBaStor.sys [x] S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2013-08-28 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-16 21:36] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-08-24 13:59 261744 ----a-w- c:\users\Lutz\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-08-24 13:59 261744 ----a-w- c:\users\Lutz\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-08-24 13:59 261744 ----a-w- c:\users\Lutz\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)] @="{8BA85C75-763B-4103-94EB-9470F12FE0F7}" [HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}] 2013-06-14 07:38 2328776 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)] @="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}" [HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}] 2013-06-14 07:38 2328776 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)] @="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}" [HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}] 2013-06-14 07:38 2328776 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B] @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}" [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}] 2012-03-13 09:23 1500672 ----a-w- c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O] @="{64174815-8D98-4CE6-8646-4C039977D808}" [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}] 2012-03-13 09:23 1500672 ----a-w- c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_U] @="{1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D}" [HKEY_CLASSES_ROOT\CLSID\{1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D}] 2012-03-13 09:23 1500672 ----a-w- c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-08-16 170304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-08-16 398656] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-07-13 12936848] "ACMON"="c:\program files (x86)\ASUS\Splendid\ACMON.exe" [2012-09-11 107192] "Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-07-27 1028896] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll c:\progra~1\NVIDIA~1\NVSTRE~1\rxinput.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://goggle.de/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\program files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com FF - ProfilePath - c:\users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default\ FF - prefs.js: keyword.URL - hxxp://www.google.de/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF - prefs.js: network.proxy.type - 4 FF - ExtSQL: 2013-07-02 01:34; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF - ExtSQL: 2013-08-19 16:52; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\coFFPlgn FF - ExtSQL: 2013-08-19 16:58; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\IPSFFPlgn . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) AddRemove-Plus-HD-2.6 - c:\program files (x86)\Plus-HD-2.6\Uninstall.exe AddRemove-DSite - c:\users\Lutz\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360] "ImagePath"="\"c:\program files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Engine\20.4.0.40\diMaster.dll\" /prefetch:1" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) @SACL=(02 0000) . Zeit der Fertigstellung: 2013-08-28 15:41:46 ComboFix-quarantined-files.txt 2013-08-28 13:41 . Vor Suchlauf: 15 Verzeichnis(se), 236.148.408.320 Bytes frei Nach Suchlauf: 16 Verzeichnis(se), 235.695.382.528 Bytes frei . - - End Of File - - 804522203B1F5FA1A77D17E230D276AA |
28.08.2013, 17:09 | #6 |
/// the machine /// TB-Ausbilder | lula Free Tec Adult Downloader wird immer angezeigt Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> lula Free Tec Adult Downloader wird immer angezeigt |
29.08.2013, 16:26 | #7 |
| lula Free Tec Adult Downloader wird immer angezeigt hallo schrauber anbei die ergebnisseAdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.001 - Report created 29/08/2013 at 17:01:12 # Updated 24/08/2013 by Xplode # Operating System : Windows 8 (64 bits) # Username : Lutz - MEINER # Running from : C:\Users\Lutz\Desktop\adwcleaner.exe # Option : Scan ***** [ Services ] ***** Service Found : SystemStoreService ***** [ Files / Folders ] ***** File Found : C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default\foxydeal.sqlite File Found : C:\Windows\System32\Tasks\Software Updater File Found : C:\Windows\System32\Tasks\Software Updater Ui Folder Found C:\Program Files (x86)\FoxyDeal Folder Found C:\Program Files (x86)\SoftwareUpdater Folder Found C:\ProgramData\Uniblue\DriverScanner Folder Found C:\Users\Lutz\AppData\Local\DownloadGuide ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\AppDataLow\Software\Crossrider Key Found : HKCU\Software\AppDataLow\Software\Plus-HD-2.6 Key Found : HKCU\Software\dsiteproducts Key Found : HKCU\Software\FoxyDeal Key Found : HKCU\Software\Iminent Key Found : [x64] HKCU\Software\dsiteproducts Key Found : [x64] HKCU\Software\FoxyDeal Key Found : [x64] HKCU\Software\Iminent Key Found : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Key Found : HKLM\SOFTWARE\Classes\driverscanner Key Found : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Key Found : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Key Found : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Key Found : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Key Found : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Key Found : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Key Found : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Key Found : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Key Found : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Key Found : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Key Found : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Key Found : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Key Found : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Key Found : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Key Found : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Key Found : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Key Found : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Key Found : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Key Found : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Key Found : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Key Found : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Key Found : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Key Found : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Key Found : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Key Found : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Key Found : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Key Found : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Key Found : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Key Found : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Key Found : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Key Found : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Key Found : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Key Found : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Key Found : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Key Found : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Key Found : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Key Found : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Key Found : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Key Found : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Key Found : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Key Found : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Key Found : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Key Found : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Key Found : HKLM\Software\Iminent Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Key Found : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Plus-HD-2.6 Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Key Found : HKLM\Software\Plus-HD-2.6 ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16660 -\\ Mozilla Firefox v23.0.1 (de) [ File : C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default\prefs.js ] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.InstallationThankYouPage", false); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.InstallationTime", 1371330554); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.active", true); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.addressbar", ""); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.addressbarenhanced", ""); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.asyncdb.wasSet", true); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.asyncinternaldb.wasSet", true); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.backgroundver", 1); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.can_run_bg_code", true); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.certdomaininstaller", ""); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.changeprevious", false); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.Affiliate_settings.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.Affiliate_settings.value", "%22%7B%5C%22initUrl%5C%22%3A%5C%22hxxp%3A//api.jollywallet.com/[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.InstallationTime.value", "1371330554"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie._GPL_aoi.value", "%221374177377%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie._GPL_parent_zoneid.value", "%22295634%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie._GPL_zoneid.value", "%22295635%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.geo.expiration", "Mon Jul 29 2013 18:05:56 GMT+0200"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.geo.value", "%22DE%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.jw_token.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.jw_token.value", "%228f43b6c7-38d4-6a45-add5-8c26daf6ab91%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.key_list_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.key_list_id.value", "%2220120802-000%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.load_balancer.expiration", "Mon Jul 29 2013 22:32:12 GMT+0200"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.load_balancer.value", "%22%7B%20%5C%22Status%5C%22%3A%201%2C%5C%22Endpoint%5C%22%3A%20%5C%2[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.previous_page.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.previous_page.value", "%22hxxp%3A//www.trojaner-board.de/138962-probleme-msn-email-account-[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.user_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.user_id.value", "%2213f49aba76437eac71ef58ed0da364e4%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.description", "Turn YouTube videos to High Definition by default"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.domain", ""); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.enablesearch", false); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.homepage", ""); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.iframe", false); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%22D806A343ED6C4094B417D3B7D775C[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_appVer.value", "29"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_lastVersion.value", "1"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_meta.value", "%7B%7D"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_nextCheck.expiration", "Mon Jul 29 2013 22:29:17 GMT+0200"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_nextCheck.value", "true"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_queue.value", "%7B%7D"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_remote_resources.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_remote_resources.value", "%7B%22remoteId%22%3A0%7D"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb._country_code_.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb._country_code_.value", "%22DE%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/098f1094523324ac59b427a0c2532d9d_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/098f1094523324ac59b427a0c2532d9d_DE.value", "%22var%20cat_098f1094523324ac59b427a[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/1bb25568f8455e74906142466f792c87_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/1bb25568f8455e74906142466f792c87_DE.value", "%22var%20cat_1bb25568f8455e749061424[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/253712f62fa354f36c490a3f42ba9bfc_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/253712f62fa354f36c490a3f42ba9bfc_DE.value", "%22var%20cat_253712f62fa354f36c490a3[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/286965653b415f505622ea74d2bd3bbe_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/286965653b415f505622ea74d2bd3bbe_DE.value", "%22var%20cat_286965653b415f505622ea7[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/2d468ab97ca7b06a3c21e9e97b353a62_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/2d468ab97ca7b06a3c21e9e97b353a62_DE.value", "%22var%20cat_2d468ab97ca7b06a3c21e9e[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/3518e1eac042730aa1274618984462b3_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/3518e1eac042730aa1274618984462b3_DE.value", "%22var%20cat_3518e1eac042730aa127461[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/3fb584595510ffd42fa9866ce0f84f32_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/3fb584595510ffd42fa9866ce0f84f32_DE.value", "%22var%20cat_3fb584595510ffd42fa9866[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/4c3f63645c68db469df209c2dc3a46aa_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/4c3f63645c68db469df209c2dc3a46aa_DE.value", "%22var%20cat_4c3f63645c68db469df209c[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/530e52021dc20843b1aa62957edeb9f8.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/530e52021dc20843b1aa62957edeb9f8_expire.expiration", "Fri Feb 01 2030 00:00:00 GM[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/530e52021dc20843b1aa62957edeb9f8_expire.value", "%221375086556895%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/530e52021dc20843b1aa62957edeb9f8_version.expiration", "Fri Feb 01 2030 00:00:00 G[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/530e52021dc20843b1aa62957edeb9f8_version.value", "%22d6c2c64414b30436b9019b460379[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/56df29dfef36d0a64d0b754d8b7aa1df_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/56df29dfef36d0a64d0b754d8b7aa1df_DE.value", "%22var%20cat_56df29dfef36d0a64d0b754[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/5cdf8a7ef2ec84abac286c67587b78d9.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/5cdf8a7ef2ec84abac286c67587b78d9_expire.expiration", "Fri Feb 01 2030 00:00:00 GM[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/5cdf8a7ef2ec84abac286c67587b78d9_expire.value", "%221375086556503%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/5cdf8a7ef2ec84abac286c67587b78d9_version.expiration", "Fri Feb 01 2030 00:00:00 G[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/5cdf8a7ef2ec84abac286c67587b78d9_version.value", "%22a64db70efdf0ace7131e2fcedb58[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/62cce7d26ab5636bceb113b988d56c59_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/62cce7d26ab5636bceb113b988d56c59_DE.value", "%22var%20cat_62cce7d26ab5636bceb113b[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/658987e48ed8b4a20fa71afdd0c84454_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/658987e48ed8b4a20fa71afdd0c84454_DE.value", "%22var%20cat_658987e48ed8b4a20fa71af[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/6d4100dc97e9abad47303e5e0d38b2b6_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/6d4100dc97e9abad47303e5e0d38b2b6_DE.value", "%22var%20cat_6d4100dc97e9abad47303e5[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/7b5c48ef44d1cfcc48ffa2be5044fe7c_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/7b5c48ef44d1cfcc48ffa2be5044fe7c_DE.value", "%22var%20cat_7b5c48ef44d1cfcc48ffa2b[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/9c3a4c3f7d10f85147fa09d19f610015_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/9c3a4c3f7d10f85147fa09d19f610015_DE.value", "%22var%20cat_9c3a4c3f7d10f85147fa09d[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/9fde1e4ac93162562a3cb3a2ca4a207d_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/9fde1e4ac93162562a3cb3a2ca4a207d_DE.value", "%22var%20cat_9fde1e4ac93162562a3cb3a[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/aa36bceec49c832079e270icmc219ats.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/aa36bceec49c832079e270icmc219ats.value", "%22tcmPredefineRulesDict%3D%5B%5B%27d9f[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/b3688636ecfdc491aea728939c15f43e_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/b3688636ecfdc491aea728939c15f43e_DE.value", "%22var%20cat_b3688636ecfdc491aea7289[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/bdd26d3b7ab2292048466bbb3ec4a74d_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/bdd26d3b7ab2292048466bbb3ec4a74d_DE.value", "%22var%20cat_bdd26d3b7ab2292048466bb[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/d5baae4ef839769f8eb7e9f9d82d8a40_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/d965aead622233a60676ef2349956f38_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/d965aead622233a60676ef2349956f38_DE.value", "%22var%20cat_d965aead622233a60676ef2[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/d9fe5d2850f1ed167451b193e8bd0e0c_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/ddedfe6ede02f148caf19a2dec7f877d_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/ddedfe6ede02f148caf19a2dec7f877d_DE.value", "%22var%20cat_ddedfe6ede02f148caf19a2[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/e3cd5b2c64ca319aadec7c28c6c6feba_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/e3cd5b2c64ca319aadec7c28c6c6feba_DE.value", "%22var%20cat_e3cd5b2c64ca319aadec7c2[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/e7395ccc0c22b2cca7bf3e0c7db4d8a6_DE.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.cache/e7395ccc0c22b2cca7bf3e0c7db4d8a6_DE.value", "%22var%20cat_e7395ccc0c22b2cca7bf3e0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.hxxp://icm.ginyas.com/tcm1/include.php?affId=ginyas_465_000057&pubId=ginyas_465_33440&g[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.hxxp://icm.ginyas.com/tcm1/include.php?affId=ginyas_465_000057&pubId=ginyas_465_33440&g[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%22%3A%22D806A343[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.aliveNotificationMarker.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.aliveNotificationMarker.value", "%221%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.aliveNotificationMarker_Expiration.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.aliveNotificationMarker_Expiration.value", "%221375135200000%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.1c8d27171c45e3ddc2fddf97fc9b78b0.expiration", "Fri Feb 01 2030 00:0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.1c8d27171c45e3ddc2fddf97fc9b78b0.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.1c8d27171c45e3ddc2fddf97fc9b78b0_Expiration.expiration", "Fri Feb 0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.1c8d27171c45e3ddc2fddf97fc9b78b0_Expiration.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.303b44fd178d093779dbe5506164c54c.expiration", "Fri Feb 01 2030 00:0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.303b44fd178d093779dbe5506164c54c.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.303b44fd178d093779dbe5506164c54c_Expiration.expiration", "Fri Feb 0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.303b44fd178d093779dbe5506164c54c_Expiration.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.52bd9f0a029db2e2278080a4d775ed4b.expiration", "Fri Feb 01 2030 00:0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.52bd9f0a029db2e2278080a4d775ed4b.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.52bd9f0a029db2e2278080a4d775ed4b_Expiration.expiration", "Fri Feb 0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.52bd9f0a029db2e2278080a4d775ed4b_Expiration.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.826f06347b57e1867fb163d007eb1772.expiration", "Fri Feb 01 2030 00:0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.826f06347b57e1867fb163d007eb1772.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.826f06347b57e1867fb163d007eb1772_Expiration.expiration", "Fri Feb 0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.826f06347b57e1867fb163d007eb1772_Expiration.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.c198d9f016bb2a78d53e5e8629603c72.expiration", "Fri Feb 01 2030 00:0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.c198d9f016bb2a78d53e5e8629603c72.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.c198d9f016bb2a78d53e5e8629603c72_Expiration.expiration", "Fri Feb 0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.c198d9f016bb2a78d53e5e8629603c72_Expiration.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.dc62f3989351314caa53db6521b92601.expiration", "Fri Feb 01 2030 00:0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.dc62f3989351314caa53db6521b92601.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.dc62f3989351314caa53db6521b92601_Expiration.expiration", "Fri Feb 0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.dc62f3989351314caa53db6521b92601_Expiration.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.f4bc944da28847c8146c8c3443870335.expiration", "Fri Feb 01 2030 00:0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.f4bc944da28847c8146c8c3443870335.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.f4bc944da28847c8146c8c3443870335_Expiration.expiration", "Fri Feb 0[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.categoryMarked.f4bc944da28847c8146c8c3443870335_Expiration.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.clickProtectMarker.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.clickProtectMarker.value", "%221%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.clickProtectMarker_Expiration.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.clickProtectMarker_Expiration.value", "%221375107563557%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.clickProtectTransitionMarker.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.clickProtectTransitionMarker.value", "%221%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.clickProtectTransitionMarker_Expiration.expiration", "Fri Feb 01 2030 00:00:00 GMT[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.clickProtectTransitionMarker_Expiration.value", "%221375102293792%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.globalDoubleImpressionProtection.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100")[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.globalDoubleImpressionProtection.value", "%221%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.globalDoubleImpressionProtection_Expiration.expiration", "Fri Feb 01 2030 00:00:00[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.globalDoubleImpressionProtection_Expiration.value", "%221375111370569%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.impressions.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.impressions.value", "%22ac303c1d26c883c08b60432740cc633e%2C1375108161976%2C3%3B036[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.impressions_Expiration.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.impressions_Expiration.value", "%221375135200000%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.initialDayDelayMarker.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.initialDayDelayMarker.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.initialDayDelayMarker_Expiration.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100")[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.initialDayDelayMarker_Expiration.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.openFirstTimeBrowserToday.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.openFirstTimeBrowserToday.value", "%221%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.openFirstTimeBrowserToday_Expiration.expiration", "Fri Feb 01 2030 00:00:00 GMT+01[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.openFirstTimeBrowserToday_Expiration.value", "%221375135200000%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.preDefRuleImpressions.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.preDefRuleImpressions.value", "%22d9fe5d2850f1ed167451b193e8bd0e0c%2C1375111365572[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.preDefRuleImpressions_Expiration.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100")[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.preDefRuleImpressions_Expiration.value", "%221375135200000%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.quirksCount.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.quirksCount.value", "%220%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.quirksCount_Expiration.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.quirksCount_Expiration.value", "%22%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.version.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.version.value", "%220.3%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.version_Expiration.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.tcm2.version_Expiration.value", "%221375135200000%22"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.manifesturl", ""); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.name", "Plus-HD-2.6"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.newtab", ""); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.opensearch", ""); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_1.name", "base"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_1.ver", 6); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_101.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_101.name", "cortica_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_101.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_102.name", "dealply_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_102.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_103.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_103.name", "intext_5_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_103.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_104.name", "jollywallet_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_104.ver", 4); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_105.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_105.name", "corticas_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_105.ver", 2); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_107.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_107.name", "coupish_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_107.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_108.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_108.name", "icm_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_108.ver", 6); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_116.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_116.name", "ads_only_5_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_116.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_117.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_117.name", "coupons_intext_ads_5_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_117.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_119.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_119.name", "similar_web_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_119.ver", 2); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_120.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_120.name", "luck_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_120.ver", 2); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_123.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_123.name", "intext_adv_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_123.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_124.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_124.name", "superfish_no_search_no_coupons_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_124.ver", 2); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_125.code", "// for stats use - banners\n\nif (typeof appAPI.internal.monetization =[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_125.name", "arcadi2_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_125.ver", 4); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_126.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_126.name", "revizer_ws_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_126.ver", 4); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_127.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_127.name", "revizer_p_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_127.ver", 4); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_128.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_128.name", "superfish_pricora_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_128.ver", 2); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_129.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_129.name", "widdit_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_129.ver", 1); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_13.code", "(function(a){a.selectedText=function(e,c){function d(){if(window.getSele[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_13.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_132.code", "// for stats use - coupons"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_132.name", "arcadi_coupons_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_132.ver", 1); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_133.code", "// for stats use - intext"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_133.name", "arcadi_intext_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_133.ver", 1); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_134.code", "// for stats use - serp"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_134.name", "arcadi_serp_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_134.ver", 1); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_135.code", "// for stats use - banners\n\nif (typeof appAPI.internal.monetization =[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_135.name", "arcadi3_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_135.ver", 2); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_138.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_138.name", "getdeal_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_138.ver", 2); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefined\"){appAPI={};}var CR__bIsIEWindow=false;[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_14.ver", 9); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_16.name", "FFAppAPIWrapper"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_16.ver", 9); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_17.name", "jQuery"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_17.ver", 4); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_21.name", "debug"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_21.ver", 4); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_22.name", "resources"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_22.ver", 4); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_28.name", "initializer"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_28.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_4.code", "var jQuery = $jquery_171 = $jquery = null;\n\nif (document && typeof docu[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_4.name", "jquery_1_7_1"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_4.ver", 4); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_47.name", "resources_background"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_47.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_64.code", "(function(){var h=\"__CR_EMPTY_CHANNEL__\";var d=function(j){return(type[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_64.name", "appApiMessage"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_64.ver", 2); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_72.code", "if(appAPI.__should_activate_validation__===true){(function(){var d={WRON[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_72.name", "appApiValidation"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_72.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_78.code", "if(typeof jQuery!==\"undefined\"&&(jQuery)&&typeof navigator!==\"undefin[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_78.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_87.name", "ginyas_wrapper"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_87.ver", 4); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_91.name", "monetizationLoader.js"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_91.ver", 12); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_92.code", "if(typeof appAPI.internal.monetization===\"undefined\"){appAPI.internal.[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_92.name", "superfish_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_92.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_93.code", "if(typeof appAPI.internal.monetization===\"undefined\"){appAPI.internal.[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_93.name", "superfish_no_coupons_m"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_93.ver", 3); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_98.code", "(function(){var b=\"cr_\"+appAPI.appID+\"internalMessage\";var a=functio[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_98.name", "omniCommands"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_98.ver", 2); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins_lists.plugins_0", "4,14,78,16,64,47,72,98,91"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins_lists.plugins_1", "17,14,78,13,16,64,4,1,21,22,72,98,138,120,108,135,134,133,132,129,128,1[...] Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins_lists.plugins_5", "4,14,78,13,16,64,47,72"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.pluginsurl", "hxxps://w9u6a2p6.ssl.hwcdn.net/plugin/apps/33440/plugins/091/ff/plugins.json"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.pluginsversion", 25); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.publisher", "Plus HD"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.searchstatus", 0); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.setnewtab", false); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.thankyou", ""); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.updateinterval", 360); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.ver", 29); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.apps", "33440"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.bic", "13f49aba76437eac71ef58ed0da364e4"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.cid", 33440); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.firstrun", false); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.hadappinstalled", true); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.installationdate", 1371330554); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.lastcheck", 22918469); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.lastcheckitem", 22918537); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.modetype", "production"); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.reportInstall", true); Line Found : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.statsDailyCounter", 87); Line Found : user_pref("extensions.crossrider.bic", "140bb9e6256bfe2befa79d21750f54a3"); ************************* AdwCleaner[R0].txt - [64704 octets] - [29/08/2013 17:01:12] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [64765 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.5.5 (08.28.2013:1) OS: Windows 8 x64 Ran by Lutz on 29.08.2013 at 17:03:29,34 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dsiteproducts Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\iminent Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\iminent Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\driverscanner Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iminent_rasapi32 Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iminent_rasmancs Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\uniblue Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iminent_rasapi32 Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iminent_rasmancs ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted the following from C:\Users\Lutz\AppData\Roaming\mozilla\firefox\profiles\sfie7b8a.default\prefs.js user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \" user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_119.code", "if (typeof appAPI.internal.monetization === \" user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_120.code", "if (typeof appAPI.internal.monetization === \" user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_123.code", "if (typeof appAPI.internal.monetization === \" user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_138.code", "if (typeof appAPI.internal.monetization === \" user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.plugins.plugin_92.code", "if(typeof appAPI.internal.monetization===\"unde user_pref("extensions.crossrider.bic", "140bb9e6256bfe2befa79d21750f54a3"); user_pref("iminent.displayFavLinks", "1"); user_pref("iminent.version", "7.33.3.1"); user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.33.3.1\",\"InstallEventCTime\":1377537253994,\"InstallEvent\":\"True\"}"); ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 29.08.2013 at 17:05:43,68 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes Anti-Malware 1.75.0.1300 Malwarebytes : Free Anti-Malware download Datenbank Version: v2013.08.29.06 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16660 Lutz :: MEINER [Administrator] 29.08.2013 16:06:15 mbam-log-2013-08-29 (16-06-15).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 465404 Laufzeit: 31 Minute(n), 51 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 2 HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 2 C:\Users\Lutz\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Lutz\AppData\Roaming\OpenCandy\761E833AE68E4505A5C368B345714349 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 7 C:\Users\Lutz\AppData\Local\DownloadGuide\Offers\iminent.exe (PUP.Iminent.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Lutz\AppData\Local\DownloadGuide\Offers\plus-hd-3-8.exe (Adware.Packed.Ranver) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Lutz\Downloads\FreeYouTubeToMP3Converter.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Lutz\Downloads\winamp565_full_emusic-7plus_all.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Lutz\Downloads\Setup\Operation7(1).exe (PUP.Optional.Solimba) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Lutz\Downloads\Setup\Operation7.exe (PUP.Optional.Solimba) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Lutz\AppData\Roaming\OpenCandy\761E833AE68E4505A5C368B345714349\driverscanner.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-08-2013 03 Ran by Lutz (administrator) on 29-08-2013 17:09:11 Running from C:\Users\Lutz\Desktop Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE (Microsoft Corporation) C:\Windows\system32\dashost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (Microsoft Corporation) C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16613_none_6273bd8950d6cae2\TiWorker.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Intel Corporation) C:\Windows\system32\igfxpers.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\APRP\aprp.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-13] (Realtek Semiconductor) HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-09-11] (ASUS) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-27] (NVIDIA Corporation) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [37960 2013-05-10] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2012-11-27] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe [3423104 2012-08-31] (ASUS Cloud Corporation) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] - C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.) AppInit_DLLs: C:\Windows\System32\nvinitx.dll C:\PROGRA~1\NVIDIA~1\NVSTRE~1\rxinput.dll [266448 2013-06-21] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll [214448 2013-06-21] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) Startup: C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default FF Keyword.URL: hxxp://www.google.de/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF NetworkProxy: "type", 4 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default\searchplugins\computer-bild-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\IPSFFPlgn\ FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\IPSFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\coFFPlgn\ FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK FF Extension: No Name - C:\Program Files\McAfee\MSK ==================== Services (Whitelisted) ================= R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] () S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-20] (Symantec Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14984480 2013-07-27] (NVIDIA Corporation) R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1900728 2013-06-06] (Microsoft Corporation) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) S2 SystemStoreService; C:\Program Files (x86)\SoftwareUpdater\SystemStore.exe [296448 2013-08-26] () S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) S2 0052531368808816mcinstcleanup; C:\Windows\TEMP\005253~1.EXE -cleanup -nolog [x] ==================== Drivers (Whitelisted) ==================== R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [61824 2012-10-31] (ASUS Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-05-20] (Symantec Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-05-20] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [169048 2013-04-15] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-28] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-28] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-08-28] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\IPSDefs\20130828.001\IDSvia64.sys [520280 2013-08-27] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\IPSDefs\20130828.001\IDSvia64.sys [520280 2013-08-27] (Symantec Corporation) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130829.002\ENG64.SYS [126040 2013-08-29] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130829.002\ENG64.SYS [126040 2013-08-29] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130829.002\EX64.SYS [2099288 2013-08-29] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130829.002\EX64.SYS [2099288 2013-08-29] (Symantec Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39712 2013-05-14] (NVIDIA Corporation) S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) R1 SRTSP; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSP64.SYS [796760 2013-05-15] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [36952 2013-03-04] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\1404000.028\SYMDS64.SYS [493656 2013-05-20] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1404000.028\SYMEFA64.SYS [1139800 2013-05-22] (Symantec Corporation) S4 SymELAM; C:\Windows\system32\drivers\N360x64\1404000.028\SymELAM.sys [23448 2013-03-04] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-08-28] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [224416 2013-03-04] (Symantec Corporation) R1 SymNetS; C:\Windows\system32\drivers\N360x64\1404000.028\SYMNETS.SYS [433752 2013-04-24] (Symantec Corporation) S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2013-06-21] (Anchorfree Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-29 17:02 - 2013-08-29 17:02 - 00064858 _____ C:\Users\Lutz\Desktop\AdwCleaner[R0].txt 2013-08-29 17:01 - 2013-08-29 17:01 - 00000000 ____D C:\AdwCleaner 2013-08-29 17:00 - 2013-08-29 17:01 - 00026012 _____ C:\Users\Lutz\Documents\Gedankenübersicht01 .odt 2013-08-29 16:04 - 2013-08-29 16:04 - 01023533 _____ (Thisisu) C:\Users\Lutz\Desktop\JRT.exe 2013-08-29 16:04 - 2013-08-29 16:04 - 00994642 _____ C:\Users\Lutz\Desktop\adwcleaner.exe 2013-08-28 15:41 - 2013-08-28 15:41 - 00029276 _____ C:\ComboFix.txt 2013-08-28 12:26 - 2013-08-28 12:35 - 00013018 _____ C:\Users\Lutz\Documents\Unbenannt 1.odt 2013-08-28 12:18 - 2013-08-28 15:41 - 00000000 ____D C:\Qoobox 2013-08-28 12:18 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-28 12:18 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-28 12:18 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-28 12:18 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-28 12:18 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-28 12:18 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2013-08-28 12:18 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-28 12:18 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-28 12:18 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-28 12:17 - 2013-08-28 12:27 - 00000000 ____D C:\Windows\erdnt 2013-08-28 11:57 - 2013-08-28 11:57 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360 2013-08-28 11:56 - 2013-08-28 11:56 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-08-28 11:56 - 2013-08-28 11:56 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-08-28 11:56 - 2013-08-28 11:56 - 00002397 _____ C:\Users\Public\Desktop\Norton 360.lnk 2013-08-28 11:55 - 2013-08-28 11:55 - 00000000 ____D C:\Program Files (x86)\Norton 360 2013-08-28 11:45 - 2013-08-28 11:45 - 00866592 _____ C:\Users\Lutz\Desktop\Norton_Removal_Tool.exe 2013-08-28 11:42 - 2013-08-28 11:50 - 00000000 ____D C:\Users\Lutz\Desktop\Norton 2013-08-28 11:29 - 2013-08-28 11:29 - 00002178 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (2).lnk 2013-08-28 11:28 - 2013-08-28 11:28 - 00011249 _____ C:\Users\Lutz\Documents\Stomaversorgung.odt 2013-08-28 10:16 - 2013-08-28 11:29 - 01295200 _____ (LogMeIn, Inc.) C:\Users\Lutz\Desktop\Support-LogMeInRescue.exe 2013-08-28 10:01 - 2013-08-28 10:01 - 00000002 _____ C:\Windows\AsCDProc.log 2013-08-28 09:56 - 2013-08-28 09:57 - 05114728 ____R (Swearware) C:\Users\Lutz\Desktop\ComboFix.exe 2013-08-27 21:05 - 2013-08-27 21:05 - 01579024 _____ (Farbar) C:\Users\Lutz\Desktop\FRST64.exe 2013-08-27 20:59 - 2013-08-27 20:59 - 00047765 _____ C:\Users\Lutz\Downloads\FRST.txt 2013-08-27 20:53 - 2013-08-27 20:53 - 01579024 _____ (Farbar) C:\Users\Lutz\Downloads\FRST64.exe 2013-08-27 19:58 - 2013-08-27 19:58 - 00010722 _____ C:\Users\Lutz\Downloads\hijackthis.log 2013-08-27 15:03 - 2013-08-27 15:03 - 00000103 _____ C:\Windows\setupact.log 2013-08-27 15:03 - 2013-08-27 15:03 - 00000000 ____D C:\NvidiaLogging 2013-08-27 15:03 - 2013-08-27 15:03 - 00000000 _____ C:\Windows\setuperr.log 2013-08-27 15:03 - 2013-05-14 21:28 - 00039712 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-08-27 15:03 - 2013-05-14 21:27 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2013-08-27 15:03 - 2013-05-14 21:27 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-08-26 22:44 - 2013-08-29 17:07 - 00155476 _____ C:\Windows\PFRO.log 2013-08-26 19:13 - 2013-08-26 19:13 - 00003646 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint 2013-08-26 19:11 - 2013-08-26 22:43 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-26 19:10 - 2013-08-26 22:43 - 00000000 ____D C:\Program Files (x86)\FoxyDeal 2013-08-26 19:09 - 2013-08-29 16:02 - 00004208 _____ C:\Windows\System32\Tasks\Software Updater 2013-08-26 19:09 - 2013-08-29 16:02 - 00004142 _____ C:\Windows\System32\Tasks\Software Updater Ui 2013-08-26 19:08 - 2013-08-26 22:53 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-08-26 19:08 - 2013-08-26 19:10 - 00000000 ____D C:\Program Files (x86)\SoftwareUpdater 2013-08-26 18:53 - 2013-08-26 21:33 - 1682428100 _____ C:\Users\Lutz\Downloads\rtws2014-demo-1.0a.zip 2013-08-26 14:54 - 2013-08-26 14:54 - 00444408 _____ C:\Users\Lutz\Downloads\free-system-utilities-DE.exe 2013-08-26 14:52 - 2013-08-29 16:16 - 00980041 _____ C:\Windows\WindowsUpdate.log 2013-08-24 15:27 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2013-08-24 15:27 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2013-08-24 15:26 - 2013-08-26 22:55 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-08-23 00:58 - 2013-08-23 00:58 - 00012882 _____ C:\Users\Lutz\Documents\Validation zusammenfassung grob.odt 2013-08-21 22:47 - 2013-08-21 22:47 - 00000000 ____D C:\ProgramData\Uniblue 2013-08-19 16:37 - 2013-08-28 11:59 - 00000000 ____D C:\ProgramData\Norton 2013-08-19 16:37 - 2013-08-28 11:55 - 00001270 _____ C:\Users\Lutz\Desktop\Norton-Installationsdateien.lnk 2013-08-19 16:37 - 2013-08-19 16:37 - 01019232 _____ (Symantec Corporation) C:\Users\Lutz\Downloads\N360Downloader.exe 2013-08-19 16:21 - 2013-08-19 16:21 - 00866592 _____ C:\Users\Lutz\Downloads\Norton_Removal_Tool.exe 2013-08-19 15:43 - 2013-08-28 12:10 - 00000000 ____D C:\Users\Lutz\AppData\Local\LogMeIn Rescue Applet 2013-08-19 15:43 - 2013-08-19 15:43 - 00002178 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec.lnk 2013-08-18 21:54 - 2013-08-18 21:55 - 00000000 ____D C:\Windows\system32\MRT 2013-08-18 21:49 - 2013-07-02 02:44 - 00036288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2013-08-18 21:49 - 2013-07-02 00:08 - 00247216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2013-08-18 20:04 - 2013-08-18 20:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-14 11:41 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 11:41 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 11:41 - 2013-07-26 07:13 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-08-14 11:41 - 2013-07-26 07:13 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2013-08-14 11:41 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-14 11:41 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-14 11:41 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 11:41 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-14 11:41 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-14 11:41 - 2013-07-26 05:13 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-14 11:41 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-14 11:41 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-14 11:41 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-14 11:41 - 2013-07-26 02:54 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2013-08-14 11:40 - 2013-07-09 08:07 - 02233168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 11:40 - 2013-05-24 01:02 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 11:40 - 2013-05-24 00:25 - 00694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 11:35 - 2013-07-13 08:18 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 11:35 - 2013-07-13 08:16 - 01889280 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 11:35 - 2013-07-13 08:16 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 11:35 - 2013-07-13 08:15 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll 2013-08-14 11:35 - 2013-07-13 08:15 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll 2013-08-14 11:35 - 2013-07-13 06:24 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 11:35 - 2013-07-13 06:23 - 01568256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 11:35 - 2013-07-13 06:23 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll 2013-08-14 11:35 - 2013-07-13 06:23 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll 2013-08-14 02:09 - 2013-08-14 02:09 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\OpenOffice 2013-08-14 02:08 - 2013-08-14 02:09 - 00000000 ___SD C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.0 2013-08-14 02:08 - 2013-08-14 02:08 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-08-14 01:44 - 2013-08-14 01:58 - 162401424 _____ C:\Users\Lutz\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de.exe 2013-07-30 17:24 - 2013-07-30 17:24 - 00000000 ____D C:\Users\Lutz\AppData\Local\Secunia PSI 2013-07-30 17:24 - 2013-07-30 17:24 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ___RD C:\Users\Lutz\SkyDrive ==================== One Month Modified Files and Folders ======= 2013-08-29 17:09 - 2013-08-26 14:52 - 00980041 _____ C:\Windows\WindowsUpdate.log 2013-08-29 17:08 - 2013-05-16 15:24 - 00000507 _____ C:\Users\Lutz\AppData\Roaming\sp_data.sys 2013-08-29 17:07 - 2013-08-26 22:44 - 00155476 _____ C:\Windows\PFRO.log 2013-08-29 17:07 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-29 17:05 - 2013-08-29 17:05 - 00003477 _____ C:\Users\Lutz\Desktop\JRT.txt 2013-08-29 17:02 - 2013-08-29 17:02 - 00064858 _____ C:\Users\Lutz\Desktop\AdwCleaner[R0].txt 2013-08-29 17:01 - 2013-08-29 17:01 - 00000000 ____D C:\AdwCleaner 2013-08-29 17:01 - 2013-08-29 17:00 - 00026012 _____ C:\Users\Lutz\Documents\Gedankenübersicht01 .odt 2013-08-29 17:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-08-29 16:48 - 2013-05-16 17:54 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-29 16:38 - 2013-07-13 16:34 - 00000000 ____D C:\Users\Lutz\Downloads\Setup 2013-08-29 16:05 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-08-29 16:04 - 2013-08-29 16:04 - 01023533 _____ (Thisisu) C:\Users\Lutz\Desktop\JRT.exe 2013-08-29 16:04 - 2013-08-29 16:04 - 00994642 _____ C:\Users\Lutz\Desktop\adwcleaner.exe 2013-08-29 16:02 - 2013-08-26 19:09 - 00004208 _____ C:\Windows\System32\Tasks\Software Updater 2013-08-29 16:02 - 2013-08-26 19:09 - 00004142 _____ C:\Windows\System32\Tasks\Software Updater Ui 2013-08-28 15:45 - 2013-05-16 15:31 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2984763435-1055683380-3862706603-1002 2013-08-28 15:41 - 2013-08-28 15:41 - 00029276 _____ C:\ComboFix.txt 2013-08-28 15:41 - 2013-08-28 12:18 - 00000000 ____D C:\Qoobox 2013-08-28 15:41 - 2012-07-26 07:37 - 00000000 __RHD C:\Users\Default 2013-08-28 14:04 - 2012-07-26 07:26 - 00000215 _____ C:\Windows\system.ini 2013-08-28 12:35 - 2013-08-28 12:26 - 00013018 _____ C:\Users\Lutz\Documents\Unbenannt 1.odt 2013-08-28 12:27 - 2013-08-28 12:17 - 00000000 ____D C:\Windows\erdnt 2013-08-28 12:10 - 2013-08-19 15:43 - 00000000 ____D C:\Users\Lutz\AppData\Local\LogMeIn Rescue Applet 2013-08-28 12:09 - 2012-07-26 10:12 - 00000000 ___HD C:\Windows\ELAMBKUP 2013-08-28 11:59 - 2013-08-19 16:37 - 00000000 ____D C:\ProgramData\Norton 2013-08-28 11:57 - 2013-08-28 11:57 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360 2013-08-28 11:56 - 2013-08-28 11:56 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-08-28 11:56 - 2013-08-28 11:56 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-08-28 11:56 - 2013-08-28 11:56 - 00002397 _____ C:\Users\Public\Desktop\Norton 360.lnk 2013-08-28 11:56 - 2013-05-21 18:02 - 00003206 _____ C:\Windows\System32\Tasks\Norton WSC Integration 2013-08-28 11:56 - 2013-05-21 18:02 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared 2013-08-28 11:55 - 2013-08-28 11:55 - 00000000 ____D C:\Program Files (x86)\Norton 360 2013-08-28 11:55 - 2013-08-19 16:37 - 00001270 _____ C:\Users\Lutz\Desktop\Norton-Installationsdateien.lnk 2013-08-28 11:50 - 2013-08-28 11:42 - 00000000 ____D C:\Users\Lutz\Desktop\Norton 2013-08-28 11:45 - 2013-08-28 11:45 - 00866592 _____ C:\Users\Lutz\Desktop\Norton_Removal_Tool.exe 2013-08-28 11:29 - 2013-08-28 11:29 - 00002178 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (2).lnk 2013-08-28 11:29 - 2013-08-28 10:16 - 01295200 _____ (LogMeIn, Inc.) C:\Users\Lutz\Desktop\Support-LogMeInRescue.exe 2013-08-28 11:28 - 2013-08-28 11:28 - 00011249 _____ C:\Users\Lutz\Documents\Stomaversorgung.odt 2013-08-28 10:01 - 2013-08-28 10:01 - 00000002 _____ C:\Windows\AsCDProc.log 2013-08-28 09:57 - 2013-08-28 09:56 - 05114728 ____R (Swearware) C:\Users\Lutz\Desktop\ComboFix.exe 2013-08-28 03:08 - 2012-07-26 07:26 - 00524288 ___SH C:\Windows\system32\config\BBI 2013-08-27 21:05 - 2013-08-27 21:05 - 01579024 _____ (Farbar) C:\Users\Lutz\Desktop\FRST64.exe 2013-08-27 20:59 - 2013-08-27 20:59 - 00047765 _____ C:\Users\Lutz\Downloads\FRST.txt 2013-08-27 20:53 - 2013-08-27 20:53 - 01579024 _____ (Farbar) C:\Users\Lutz\Downloads\FRST64.exe 2013-08-27 19:58 - 2013-08-27 19:58 - 00010722 _____ C:\Users\Lutz\Downloads\hijackthis.log 2013-08-27 15:03 - 2013-08-27 15:03 - 00000103 _____ C:\Windows\setupact.log 2013-08-27 15:03 - 2013-08-27 15:03 - 00000000 ____D C:\NvidiaLogging 2013-08-27 15:03 - 2013-08-27 15:03 - 00000000 _____ C:\Windows\setuperr.log 2013-08-27 15:03 - 2012-12-28 18:22 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-08-27 15:03 - 2012-12-28 18:22 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-08-26 22:55 - 2013-08-24 15:26 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-08-26 22:53 - 2013-08-26 19:08 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-08-26 22:48 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\ELAM 2013-08-26 22:43 - 2013-08-26 19:11 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-26 22:43 - 2013-08-26 19:10 - 00000000 ____D C:\Program Files (x86)\FoxyDeal 2013-08-26 21:33 - 2013-08-26 18:53 - 1682428100 _____ C:\Users\Lutz\Downloads\rtws2014-demo-1.0a.zip 2013-08-26 19:13 - 2013-08-26 19:13 - 00003646 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint 2013-08-26 19:10 - 2013-08-26 19:08 - 00000000 ____D C:\Program Files (x86)\SoftwareUpdater 2013-08-26 14:54 - 2013-08-26 14:54 - 00444408 _____ C:\Users\Lutz\Downloads\free-system-utilities-DE.exe 2013-08-25 03:58 - 2013-05-16 15:21 - 00000000 ____D C:\Users\Lutz\AppData\Local\VirtualStore 2013-08-24 15:59 - 2013-05-16 15:21 - 00002242 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2013-08-23 15:26 - 2013-05-23 15:51 - 00000000 ____D C:\ProgramData\CanonIJPLM 2013-08-23 00:58 - 2013-08-23 00:58 - 00012882 _____ C:\Users\Lutz\Documents\Validation zusammenfassung grob.odt 2013-08-21 22:47 - 2013-08-21 22:47 - 00000000 ____D C:\ProgramData\Uniblue 2013-08-21 13:57 - 2013-06-17 15:10 - 00000000 ____D C:\Users\Lutz\AppData\Local\CrashDumps 2013-08-19 16:37 - 2013-08-19 16:37 - 01019232 _____ (Symantec Corporation) C:\Users\Lutz\Downloads\N360Downloader.exe 2013-08-19 16:37 - 2013-06-11 11:52 - 00000000 ____D C:\Users\Public\Downloads\Norton 2013-08-19 16:27 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\SysWOW64\en-GB 2013-08-19 16:21 - 2013-08-19 16:21 - 00866592 _____ C:\Users\Lutz\Downloads\Norton_Removal_Tool.exe 2013-08-19 15:43 - 2013-08-19 15:43 - 00002178 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec.lnk 2013-08-19 12:11 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache 2013-08-19 00:50 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Defender 2013-08-19 00:50 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-08-18 21:55 - 2013-08-18 21:54 - 00000000 ____D C:\Windows\system32\MRT 2013-08-18 21:54 - 2013-05-17 16:38 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-18 21:31 - 2013-05-16 16:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-18 20:43 - 2013-06-15 23:06 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MgameEU 2013-08-18 20:04 - 2013-08-18 20:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-14 21:42 - 2013-07-13 18:47 - 00448888 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-14 02:09 - 2013-08-14 02:09 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\OpenOffice 2013-08-14 02:09 - 2013-08-14 02:08 - 00000000 ___SD C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.0 2013-08-14 02:08 - 2013-08-14 02:08 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-08-14 01:58 - 2013-08-14 01:44 - 162401424 _____ C:\Users\Lutz\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de.exe 2013-07-31 13:26 - 2012-08-03 01:02 - 00753134 _____ C:\Windows\system32\perfh007.dat 2013-07-31 13:26 - 2012-08-03 01:02 - 00155826 _____ C:\Windows\system32\perfc007.dat 2013-07-31 13:26 - 2012-07-26 09:28 - 01745416 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-30 17:24 - 2013-07-30 17:24 - 00000000 ____D C:\Users\Lutz\AppData\Local\Secunia PSI 2013-07-30 17:24 - 2013-07-30 17:24 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ___RD C:\Users\Lutz\SkyDrive 2013-07-30 15:10 - 2013-05-16 15:21 - 00000000 ____D C:\Users\Lutz Files to move or delete: ==================== C:\Users\Lutz\AppData\Local\Temp\jrt\erunt\ERUNT.EXE ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-20 11:23 ==================== End Of Log ============================ --- --- --- |
29.08.2013, 17:58 | #8 |
/// the machine /// TB-Ausbilder | lula Free Tec Adult Downloader wird immer angezeigtESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.08.2013, 23:20 | #9 |
| lula Free Tec Adult Downloader wird immer angezeigt Results of screen317's Security Check version 0.99.72 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Windows Defender Norton 360 WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Secunia PSI (3.0.0.7011) Malwarebytes Anti-Malware Version 1.75.0.1300 Adobe Flash Player 11.8.800.94 Adobe Reader 10.1.7 Adobe Reader out of Date! Mozilla Firefox (23.0.1) ````````Process Check: objlist.exe by Laurent```````` Norton ccSvcHst.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internetesets_scanner_update returned -1 esets_gle=12 # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=96eafbed141a9e48898ae511984b00da # engine=14947 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-29 09:50:05 # local_time=2013-08-29 11:50:05 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.2.9200 NT # compatibility_mode=3592 16777213 100 91 14424 128504301 0 0 # compatibility_mode=5122 16777214 0 9 8581940 37304715 0 0 # compatibility_mode=5893 16776574 100 94 946754 37319116 0 0 # scanned=193089 # found=0 # cleaned=0 # scan_time=3868 FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-08-2013 03 Ran by Lutz (administrator) on 30-08-2013 00:19:08 Running from C:\Users\Lutz\Desktop\I Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE (Microsoft Corporation) C:\Windows\system32\dashost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (Intel Corporation) C:\Windows\system32\igfxpers.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\system32\wwahost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe\LiveComm.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-13] (Realtek Semiconductor) HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-09-11] (ASUS) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-27] (NVIDIA Corporation) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [37960 2013-05-10] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2012-11-27] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe [3423104 2012-08-31] (ASUS Cloud Corporation) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] - C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.) AppInit_DLLs: C:\Windows\System32\nvinitx.dll C:\PROGRA~1\NVIDIA~1\NVSTRE~1\rxinput.dll [266448 2013-06-21] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll [214448 2013-06-21] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) Startup: C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default FF Keyword.URL: hxxp://www.google.de/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF NetworkProxy: "type", 4 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default\searchplugins\computer-bild-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\IPSFFPlgn\ FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\IPSFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\coFFPlgn\ FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK FF Extension: No Name - C:\Program Files\McAfee\MSK ==================== Services (Whitelisted) ================= R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] () R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-20] (Symantec Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14984480 2013-07-27] (NVIDIA Corporation) R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1900728 2013-06-06] (Microsoft Corporation) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) S2 0052531368808816mcinstcleanup; C:\Windows\TEMP\005253~1.EXE -cleanup -nolog [x] ==================== Drivers (Whitelisted) ==================== R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [61824 2012-10-31] (ASUS Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-05-20] (Symantec Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-05-20] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [169048 2013-04-15] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-28] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-28] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-08-28] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\IPSDefs\20130828.001\IDSvia64.sys [520280 2013-08-27] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\IPSDefs\20130828.001\IDSvia64.sys [520280 2013-08-27] (Symantec Corporation) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130829.017\ENG64.SYS [126040 2013-08-29] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130829.017\ENG64.SYS [126040 2013-08-29] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130829.017\EX64.SYS [2099288 2013-08-29] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130829.017\EX64.SYS [2099288 2013-08-29] (Symantec Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39712 2013-05-14] (NVIDIA Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) R1 SRTSP; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSP64.SYS [796760 2013-05-15] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [36952 2013-03-04] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\1404000.028\SYMDS64.SYS [493656 2013-05-20] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1404000.028\SYMEFA64.SYS [1139800 2013-05-22] (Symantec Corporation) S4 SymELAM; C:\Windows\system32\drivers\N360x64\1404000.028\SymELAM.sys [23448 2013-03-04] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-08-28] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [224416 2013-03-04] (Symantec Corporation) R1 SymNetS; C:\Windows\system32\drivers\N360x64\1404000.028\SYMNETS.SYS [433752 2013-04-24] (Symantec Corporation) S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2013-06-21] (Anchorfree Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-29 22:39 - 2013-08-29 22:39 - 00000000 ____D C:\Program Files (x86)\ESET 2013-08-29 22:36 - 2013-08-29 22:36 - 02347384 _____ (ESET) C:\Users\Lutz\Desktop\esetsmartinstaller_enu.exe 2013-08-29 22:36 - 2013-08-29 22:36 - 00891115 _____ C:\Users\Lutz\Desktop\SecurityCheck.exe 2013-08-29 22:17 - 2013-08-29 22:17 - 00000000 ___RD C:\Users\Lutz\Desktop\I 2013-08-29 17:01 - 2013-08-29 17:13 - 00000000 ____D C:\AdwCleaner 2013-08-29 17:00 - 2013-08-29 17:01 - 00026012 _____ C:\Users\Lutz\Documents\Gedankenübersicht01 .odt 2013-08-28 15:41 - 2013-08-28 15:41 - 00029276 _____ C:\ComboFix.txt 2013-08-28 12:26 - 2013-08-28 12:35 - 00013018 _____ C:\Users\Lutz\Documents\Unbenannt 1.odt 2013-08-28 12:18 - 2013-08-28 15:41 - 00000000 ____D C:\Qoobox 2013-08-28 12:18 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-28 12:18 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-28 12:18 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-28 12:18 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-28 12:18 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-28 12:18 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2013-08-28 12:18 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-28 12:18 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-28 12:18 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-28 12:17 - 2013-08-28 12:27 - 00000000 ____D C:\Windows\erdnt 2013-08-28 11:57 - 2013-08-28 11:57 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360 2013-08-28 11:56 - 2013-08-28 11:56 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-08-28 11:56 - 2013-08-28 11:56 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-08-28 11:55 - 2013-08-28 11:55 - 00000000 ____D C:\Program Files (x86)\Norton 360 2013-08-28 11:29 - 2013-08-28 11:29 - 00002178 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (2).lnk 2013-08-28 11:28 - 2013-08-28 11:28 - 00011249 _____ C:\Users\Lutz\Documents\Stomaversorgung.odt 2013-08-28 10:01 - 2013-08-28 10:01 - 00000002 _____ C:\Windows\AsCDProc.log 2013-08-27 20:59 - 2013-08-27 20:59 - 00047765 _____ C:\Users\Lutz\Downloads\FRST.txt 2013-08-27 20:53 - 2013-08-27 20:53 - 01579024 _____ (Farbar) C:\Users\Lutz\Downloads\FRST64.exe 2013-08-27 19:58 - 2013-08-27 19:58 - 00010722 _____ C:\Users\Lutz\Downloads\hijackthis.log 2013-08-27 15:03 - 2013-08-27 15:03 - 00000103 _____ C:\Windows\setupact.log 2013-08-27 15:03 - 2013-08-27 15:03 - 00000000 ____D C:\NvidiaLogging 2013-08-27 15:03 - 2013-08-27 15:03 - 00000000 _____ C:\Windows\setuperr.log 2013-08-27 15:03 - 2013-05-14 21:28 - 00039712 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-08-27 15:03 - 2013-05-14 21:27 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2013-08-27 15:03 - 2013-05-14 21:27 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-08-26 22:44 - 2013-08-29 17:07 - 00155476 _____ C:\Windows\PFRO.log 2013-08-26 19:13 - 2013-08-26 19:13 - 00003646 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint 2013-08-26 19:11 - 2013-08-26 22:43 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-26 19:08 - 2013-08-26 22:53 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-08-26 18:53 - 2013-08-26 21:33 - 1682428100 _____ C:\Users\Lutz\Downloads\rtws2014-demo-1.0a.zip 2013-08-26 14:54 - 2013-08-26 14:54 - 00444408 _____ C:\Users\Lutz\Downloads\free-system-utilities-DE.exe 2013-08-26 14:52 - 2013-08-29 18:07 - 01040430 _____ C:\Windows\WindowsUpdate.log 2013-08-24 15:27 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2013-08-24 15:27 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2013-08-24 15:26 - 2013-08-26 22:55 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-08-23 00:58 - 2013-08-23 00:58 - 00012882 _____ C:\Users\Lutz\Documents\Validation zusammenfassung grob.odt 2013-08-21 22:47 - 2013-08-29 17:13 - 00000000 ____D C:\ProgramData\Uniblue 2013-08-19 16:37 - 2013-08-28 11:59 - 00000000 ____D C:\ProgramData\Norton 2013-08-19 16:37 - 2013-08-19 16:37 - 01019232 _____ (Symantec Corporation) C:\Users\Lutz\Downloads\N360Downloader.exe 2013-08-19 16:21 - 2013-08-19 16:21 - 00866592 _____ C:\Users\Lutz\Downloads\Norton_Removal_Tool.exe 2013-08-19 15:43 - 2013-08-28 12:10 - 00000000 ____D C:\Users\Lutz\AppData\Local\LogMeIn Rescue Applet 2013-08-19 15:43 - 2013-08-19 15:43 - 00002178 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec.lnk 2013-08-18 21:54 - 2013-08-18 21:55 - 00000000 ____D C:\Windows\system32\MRT 2013-08-18 21:49 - 2013-07-02 02:44 - 00036288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2013-08-18 21:49 - 2013-07-02 00:08 - 00247216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2013-08-18 20:04 - 2013-08-18 20:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-14 11:41 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 11:41 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 11:41 - 2013-07-26 07:13 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-08-14 11:41 - 2013-07-26 07:13 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2013-08-14 11:41 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-14 11:41 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 11:41 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-14 11:41 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 11:41 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-14 11:41 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-14 11:41 - 2013-07-26 05:13 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-14 11:41 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-14 11:41 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-14 11:41 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-14 11:41 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-14 11:41 - 2013-07-26 02:54 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2013-08-14 11:40 - 2013-07-09 08:07 - 02233168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 11:40 - 2013-05-24 01:02 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 11:40 - 2013-05-24 00:25 - 00694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 11:35 - 2013-07-13 08:18 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 11:35 - 2013-07-13 08:16 - 01889280 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 11:35 - 2013-07-13 08:16 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 11:35 - 2013-07-13 08:15 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll 2013-08-14 11:35 - 2013-07-13 08:15 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll 2013-08-14 11:35 - 2013-07-13 06:24 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 11:35 - 2013-07-13 06:23 - 01568256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 11:35 - 2013-07-13 06:23 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll 2013-08-14 11:35 - 2013-07-13 06:23 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll 2013-08-14 02:09 - 2013-08-14 02:09 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\OpenOffice 2013-08-14 02:08 - 2013-08-14 02:09 - 00000000 ___SD C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.0 2013-08-14 02:08 - 2013-08-14 02:08 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-08-14 01:44 - 2013-08-14 01:58 - 162401424 _____ C:\Users\Lutz\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de.exe ==================== One Month Modified Files and Folders ======= 2013-08-30 00:16 - 2013-08-30 00:16 - 00000869 _____ C:\Users\Lutz\Desktop\checkup.txt 2013-08-30 00:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-08-29 23:48 - 2013-05-16 17:54 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-29 22:39 - 2013-08-29 22:39 - 00000000 ____D C:\Program Files (x86)\ESET 2013-08-29 22:36 - 2013-08-29 22:36 - 02347384 _____ (ESET) C:\Users\Lutz\Desktop\esetsmartinstaller_enu.exe 2013-08-29 22:36 - 2013-08-29 22:36 - 00891115 _____ C:\Users\Lutz\Desktop\SecurityCheck.exe 2013-08-29 22:17 - 2013-08-29 22:17 - 00000000 ___RD C:\Users\Lutz\Desktop\I 2013-08-29 18:07 - 2013-08-26 14:52 - 01040430 _____ C:\Windows\WindowsUpdate.log 2013-08-29 17:21 - 2013-05-16 15:24 - 00000507 _____ C:\Users\Lutz\AppData\Roaming\sp_data.sys 2013-08-29 17:15 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-29 17:13 - 2013-08-29 17:01 - 00000000 ____D C:\AdwCleaner 2013-08-29 17:13 - 2013-08-21 22:47 - 00000000 ____D C:\ProgramData\Uniblue 2013-08-29 17:07 - 2013-08-26 22:44 - 00155476 _____ C:\Windows\PFRO.log 2013-08-29 17:01 - 2013-08-29 17:00 - 00026012 _____ C:\Users\Lutz\Documents\Gedankenübersicht01 .odt 2013-08-29 16:38 - 2013-07-13 16:34 - 00000000 ____D C:\Users\Lutz\Downloads\Setup 2013-08-29 16:05 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-08-28 15:45 - 2013-05-16 15:31 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2984763435-1055683380-3862706603-1002 2013-08-28 15:41 - 2013-08-28 15:41 - 00029276 _____ C:\ComboFix.txt 2013-08-28 15:41 - 2013-08-28 12:18 - 00000000 ____D C:\Qoobox 2013-08-28 15:41 - 2012-07-26 07:37 - 00000000 __RHD C:\Users\Default 2013-08-28 14:04 - 2012-07-26 07:26 - 00000215 _____ C:\Windows\system.ini 2013-08-28 12:35 - 2013-08-28 12:26 - 00013018 _____ C:\Users\Lutz\Documents\Unbenannt 1.odt 2013-08-28 12:27 - 2013-08-28 12:17 - 00000000 ____D C:\Windows\erdnt 2013-08-28 12:10 - 2013-08-19 15:43 - 00000000 ____D C:\Users\Lutz\AppData\Local\LogMeIn Rescue Applet 2013-08-28 12:09 - 2012-07-26 10:12 - 00000000 ___HD C:\Windows\ELAMBKUP 2013-08-28 11:59 - 2013-08-19 16:37 - 00000000 ____D C:\ProgramData\Norton 2013-08-28 11:57 - 2013-08-28 11:57 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360 2013-08-28 11:56 - 2013-08-28 11:56 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-08-28 11:56 - 2013-08-28 11:56 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-08-28 11:56 - 2013-05-21 18:02 - 00003206 _____ C:\Windows\System32\Tasks\Norton WSC Integration 2013-08-28 11:56 - 2013-05-21 18:02 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared 2013-08-28 11:55 - 2013-08-28 11:55 - 00000000 ____D C:\Program Files (x86)\Norton 360 2013-08-28 11:29 - 2013-08-28 11:29 - 00002178 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec (2).lnk 2013-08-28 11:28 - 2013-08-28 11:28 - 00011249 _____ C:\Users\Lutz\Documents\Stomaversorgung.odt 2013-08-28 10:01 - 2013-08-28 10:01 - 00000002 _____ C:\Windows\AsCDProc.log 2013-08-28 03:08 - 2012-07-26 07:26 - 00524288 ___SH C:\Windows\system32\config\BBI 2013-08-27 20:59 - 2013-08-27 20:59 - 00047765 _____ C:\Users\Lutz\Downloads\FRST.txt 2013-08-27 20:53 - 2013-08-27 20:53 - 01579024 _____ (Farbar) C:\Users\Lutz\Downloads\FRST64.exe 2013-08-27 19:58 - 2013-08-27 19:58 - 00010722 _____ C:\Users\Lutz\Downloads\hijackthis.log 2013-08-27 15:03 - 2013-08-27 15:03 - 00000103 _____ C:\Windows\setupact.log 2013-08-27 15:03 - 2013-08-27 15:03 - 00000000 ____D C:\NvidiaLogging 2013-08-27 15:03 - 2013-08-27 15:03 - 00000000 _____ C:\Windows\setuperr.log 2013-08-27 15:03 - 2012-12-28 18:22 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-08-27 15:03 - 2012-12-28 18:22 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-08-26 22:55 - 2013-08-24 15:26 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-08-26 22:53 - 2013-08-26 19:08 - 00000000 ____D C:\Program Files (x86)\Web Check 2013-08-26 22:48 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\ELAM 2013-08-26 22:43 - 2013-08-26 19:11 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-26 21:33 - 2013-08-26 18:53 - 1682428100 _____ C:\Users\Lutz\Downloads\rtws2014-demo-1.0a.zip 2013-08-26 19:13 - 2013-08-26 19:13 - 00003646 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint 2013-08-26 14:54 - 2013-08-26 14:54 - 00444408 _____ C:\Users\Lutz\Downloads\free-system-utilities-DE.exe 2013-08-25 03:58 - 2013-05-16 15:21 - 00000000 ____D C:\Users\Lutz\AppData\Local\VirtualStore 2013-08-24 15:59 - 2013-05-16 15:21 - 00002242 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2013-08-23 15:26 - 2013-05-23 15:51 - 00000000 ____D C:\ProgramData\CanonIJPLM 2013-08-23 00:58 - 2013-08-23 00:58 - 00012882 _____ C:\Users\Lutz\Documents\Validation zusammenfassung grob.odt 2013-08-21 13:57 - 2013-06-17 15:10 - 00000000 ____D C:\Users\Lutz\AppData\Local\CrashDumps 2013-08-19 16:37 - 2013-08-19 16:37 - 01019232 _____ (Symantec Corporation) C:\Users\Lutz\Downloads\N360Downloader.exe 2013-08-19 16:37 - 2013-06-11 11:52 - 00000000 ____D C:\Users\Public\Downloads\Norton 2013-08-19 16:27 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\SysWOW64\en-GB 2013-08-19 16:21 - 2013-08-19 16:21 - 00866592 _____ C:\Users\Lutz\Downloads\Norton_Removal_Tool.exe 2013-08-19 15:43 - 2013-08-19 15:43 - 00002178 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Symantec.lnk 2013-08-19 12:11 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache 2013-08-19 00:50 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Defender 2013-08-19 00:50 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-08-18 21:55 - 2013-08-18 21:54 - 00000000 ____D C:\Windows\system32\MRT 2013-08-18 21:54 - 2013-05-17 16:38 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-18 21:31 - 2013-05-16 16:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-18 20:43 - 2013-06-15 23:06 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MgameEU 2013-08-18 20:04 - 2013-08-18 20:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-14 21:42 - 2013-07-13 18:47 - 00448888 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-14 02:09 - 2013-08-14 02:09 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\OpenOffice 2013-08-14 02:09 - 2013-08-14 02:08 - 00000000 ___SD C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.0 2013-08-14 02:08 - 2013-08-14 02:08 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-08-14 01:58 - 2013-08-14 01:44 - 162401424 _____ C:\Users\Lutz\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de.exe 2013-07-31 13:26 - 2012-08-03 01:02 - 00753134 _____ C:\Windows\system32\perfh007.dat 2013-07-31 13:26 - 2012-08-03 01:02 - 00155826 _____ C:\Windows\system32\perfc007.dat 2013-07-31 13:26 - 2012-07-26 09:28 - 01745416 _____ C:\Windows\system32\PerfStringBackup.INI Files to move or delete: ==================== C:\Users\Lutz\AppData\Local\Temp\Quarantine.exe C:\Users\Lutz\AppData\Local\Temp\RarSFX0\SecurityCheck\Objlist.exe C:\Users\Lutz\AppData\Local\Temp\RarSFX0\SecurityCheck\runprocesses.exe C:\Users\Lutz\AppData\Local\Temp\RarSFX0\SecurityCheck\uninstalllist.exe C:\Users\Lutz\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\cmdinfo.exe C:\Users\Lutz\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\nircmdc.exe C:\Users\Lutz\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\sed.exe C:\Users\Lutz\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\swreg.exe C:\Users\Lutz\AppData\Local\Temp\jrt\erunt\ERUNT.EXE ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-20 11:23 ==================== End Of Log ============================ --- --- --- |
30.08.2013, 15:25 | #10 |
/// the machine /// TB-Ausbilder | lula Free Tec Adult Downloader wird immer angezeigt Adobe updaten. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.09.2013, 10:56 | #11 |
| lula Free Tec Adult Downloader wird immer angezeigt Hallo Schrauber vielen lieben Dank für deine Hilfe. Alles hat sich erledigt. schönen Tag noch |
02.09.2013, 14:18 | #12 |
/// the machine /// TB-Ausbilder | lula Free Tec Adult Downloader wird immer angezeigt Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu lula Free Tec Adult Downloader wird immer angezeigt |
acrobat update, adobe, adobe flash player, adware.packed.ranver, canon, flash player, internet explorer, pup.iminent.a, pup.optional.iminent.a, pup.optional.opencandy, pup.optional.solimba, secunia psi, software, symantec, virus, windows |