![]() |
|
Log-Analyse und Auswertung: Windows 7: Penetrante Werbung und Werbelinks (überall!) im Browser!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 | ||
| ![]() Windows 7: Penetrante Werbung und Werbelinks (überall!) im Browser! Hallo! Ich werde nuns chon seit mehreren Wochen durch extrem nervende Werbung in meinem Browser (Firefox aber auch IE und google chrome) geplagt. Es werden automatisch irgendwelche Links in den Webseitentext generiert die vortäuschen sollen sie seien "richtige Links". Überall poppt WErbung auf, wenn ich eine Webseite eingebe, wird oft zusätzlich eine weitere/andere Webseite geöffnet. Alles sehr nervig, ein Arbeiten im browser ist nicht mehr möglich. Habe gestern versucht mit "Spybot Search and Destroy 2" der Lage Herr zuw erden. Das tool aht auch ne Menge gefunden. Hab zwar auf "Probleme lösen" geklickt und das Tool hat wohl auch, oder zumidnest angezeigt, dass die Probleme behoben wurden. Hier erstmal das log-file von "Spybot search and destroy" von gestern: Zitat:
Avira Antivirus Premium hat am 9 Sept. 2013 schonmal 10 Viren gefunden und entfernt. Hier der Log Zitat:
FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013 Ran by Viktoria (administrator) on SOKRATES on 09-11-2013 22:00:33 Running from C:\Users\Viktoria\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe (IDT, Inc.) C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_c06efa65923f756e\STacSV64.exe (Hewlett-Packard) C:\windows\system32\Hpservice.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe (DigitalPersona, Inc.) c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Andrea Electronics Corporation) C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_c06efa65923f756e\AESTSr64.exe (LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Hewlett-Packard Development Company, L.P) c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe (DigitalPersona, Inc.) c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (Dropbox, Inc.) C:\Users\Viktoria\AppData\Roaming\Dropbox\bin\Dropbox.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe (Hewlett-Packard Company) c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe ( ) C:\windows\system32\lxdxcoms.exe () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Hewlett-Packard, Inc.) c:\Program Files (x86)\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe (Hewlett-Packard) c:\Program Files (x86)\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsender.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Hewlett-Packard) c:\Program Files (x86)\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsender_gui.exe (Hewlett-Packard) c:\Program Files (x86)\Hewlett-Packard\HP SkyRoom\remote graphics sender\plugins\ice\Hp.SkyRoom.Windows.RgsPlugin.Authentication\Hp.SkyRoom.Windows.RgsPlugin.Authentication.exe (Hewlett-Packard) c:\Program Files (x86)\Hewlett-Packard\HP SkyRoom\remote graphics sender\plugins\ice\Hp.SkyRoom.Windows.RgsPlugin.Lens\Hp.SkyRoom.Windows.RgsPlugin.Lens.exe (Hewlett-Packard) c:\Program Files (x86)\Hewlett-Packard\HP SkyRoom\remote graphics sender\plugins\ice\Hp.SkyRoom.Windows.RgsPlugin.Licensing\Hp.SkyRoom.Windows.RgsPlugin.Licensing.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (DigitalPersona, Inc.) c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Microsoft Corporation) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe () C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe () C:\Users\Viktoria\Desktop\Defogger.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe [186904 2010-04-05] (Intel Corporation) HKLM\...\Run: [HPPowerAssistant] - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [1690680 2009-11-19] (Hewlett-Packard) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1861416 2009-10-10] (Synaptics Incorporated) HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2009-11-19] (Hewlett-Packard) HKLM\...\Run: [nwiz] - nwiz.exe /installquiet HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2009-11-18] (IDT, Inc.) HKLM\...\Run: [SpywareTerminatorShield] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe HKLM\...\Run: [SpywareTerminatorUpdater] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe, Winlogon\Notify\ScCertProp: C:\Windows\SysWOW64\explorer.exe (Microsoft Corporation) HKCU\...\Run: [AutoStartNPSAgent] - C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe [95576 2010-07-29] (Samsung Electronics Co., Ltd.) HKCU\...\CurrentVersion\Windows: [Load] C:\Users\Viktoria\AppData\Local\Temp\{57926~1.EXE <===== ATTENTION MountPoints2: {1bfe2d8c-0d2d-11e2-a318-70f395957183} - E:\Startme.exe MountPoints2: {1bfe2dd1-0d2d-11e2-a318-70f395957183} - E:\Startme.exe MountPoints2: {315e6ab0-3acb-11e1-af40-70f395957183} - D:\Startme.exe HKLM-x32\...\Run: [QlbCtrl.exe] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe [287800 2009-11-11] ( Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [111640 2009-11-04] () HKLM-x32\...\Run: [NPSStartup] - [x] HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421160 2011-04-14] (Apple Inc.) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2010-06-09] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512 2013-09-14] (RealNetworks, Inc.) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) AppInit_DLLs-x32: c:\progra~2\magnipic\sprote~1.dll [1046528 2013-01-24] () Lsa: [Notification Packages] DPPassFilter scecli Startup: C:\Users\Viktoria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Viktoria\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchou.com/?id=0ac7d9fa0000000000000024d7481b75 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/4 SearchScopes: HKLM - DefaultScope {C6842AF5-081F-4A21-AD5F-53CCFB0B7100} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - DefaultScope {C6842AF5-081F-4A21-AD5F-53CCFB0B7100} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {BA052AC4-62C7-4E47-BC68-5A7ADDCEF266} URL = hxxp://searchou.com/?q={searchTerms}&id=0ac7d9fa0000000000000024d7481b75&r=4 SearchScopes: HKCU - {BA052AC4-62C7-4E47-BC68-5A7ADDCEF266} URL = hxxp://searchou.com/?q={searchTerms}&id=0ac7d9fa0000000000000024d7481b75&r=4 BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO-x32: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.) BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: MaggnnIIPic - {97CD5F00-0CD2-AF6A-24DB-FD0EB078A4CE} - C:\ProgramData\MaggnnIIPic\51609fcddcc55.dll () BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Viktoria\AppData\Roaming\Mozilla\Firefox\Profiles\whqhf9c7.default FF user.js: detected! => C:\Users\Viktoria\AppData\Roaming\Mozilla\Firefox\Profiles\whqhf9c7.default\user.js FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF Homepage: www.orf.at FF Keyword.URL: user_pref("keyword.URL", ""); FF NetworkProxy: "type", 0 FF DefaultSearchEngine: LEO Eng-Deu FF SelectedSearchEngine: LEO Eng-Deu FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Viktoria\AppData\Roaming\Mozilla\Firefox\Profiles\whqhf9c7.default\searchplugins\privitize.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: MaggnnIIPic - C:\Users\Viktoria\AppData\Roaming\Mozilla\Firefox\Profiles\whqhf9c7.default\Extensions\k_enl@rsbpt.com FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\ FF Extension: DigitalPersona Extension - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\ FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ Chrome: ======= CHR RestoreOnStartup: "" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll No File CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll No File CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U5) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll No File CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.50.5) - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File CHR Extension: (RealDownloader) - C:\Users\Viktoria\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.3_0 CHR Extension: (Skype Click to Call) - C:\Users\Viktoria\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Viktoria\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx ==================== Services (Whitelisted) ================= R2 AESTFilters; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_c06efa65923f756e\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [948296 2013-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-01] (Avira Operations GmbH & Co. KG) R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [462088 2010-01-22] (DigitalPersona, Inc.) R2 HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [36864 2010-01-12] (Hewlett-Packard Development Company, L.P) R2 Hp.Skyroom.Windows.Service; C:\Program Files (x86)\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe [124984 2009-11-20] (Hewlett-Packard) R2 lxdx_device; C:\windows\system32\lxdxcoms.exe [1044648 2008-02-28] ( ) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.) R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] () R2 rgsender; c:\Program Files (x86)\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe [379904 2009-11-19] (Hewlett-Packard, Inc.) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_c06efa65923f756e\STacSV64.exe [244224 2009-11-18] (IDT, Inc.) S2 AviraUpgradeService; "C:\windows\TEMP\AVSETUP_5072a145\avupgsvc.exe" /TEMPSTART:""C:\windows\TEMP\AVSETUP_5072a145\setup.exe" /NOTEMPCLEANUP /CROSSUPGRADE" ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105856 2013-10-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-10-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) R3 rismcx64; C:\Windows\System32\DRIVERS\rismcx64.sys [59008 2009-07-20] (RICOH Company, Ltd.) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1805104 2009-09-18] () U3 ugddypob; \??\C:\Users\Viktoria\AppData\Local\Temp\ugddypob.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-09 22:00 - 2013-11-09 22:00 - 00000000 ____D C:\FRST 2013-11-09 21:59 - 2013-11-09 21:59 - 00000478 _____ C:\Users\Viktoria\Desktop\defogger_disable.log 2013-11-09 21:59 - 2013-11-09 21:59 - 00000000 _____ C:\Users\Viktoria\defogger_reenable 2013-11-09 21:57 - 2013-11-09 21:57 - 00050477 _____ C:\Users\Viktoria\Desktop\Defogger.exe 2013-11-09 21:56 - 2013-11-09 21:56 - 00377856 _____ C:\Users\Viktoria\Desktop\gmer_2.1.19163.exe 2013-11-09 21:55 - 2013-11-09 21:55 - 01957098 _____ (Farbar) C:\Users\Viktoria\Desktop\FRST64.exe 2013-11-09 21:53 - 2013-11-09 21:53 - 00050477 _____ C:\Users\Viktoria\Downloads\Defogger.exe 2013-11-09 21:52 - 2013-11-09 21:57 - 00000000 ____D C:\Users\Viktoria\Desktop\trojaner board 2013-11-08 10:46 - 2013-11-08 10:46 - 00000000 ____D C:\Users\Viktoria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte 2013-11-08 10:31 - 2013-11-08 11:14 - 00000000 ____D C:\Users\Viktoria\Desktop\Feministisch entwickeln 2013-11-07 22:13 - 2013-11-07 22:44 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-11-07 22:13 - 2013-11-07 22:14 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-11-07 22:13 - 2013-11-07 22:13 - 00001383 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-11-07 22:13 - 2013-11-07 22:13 - 00000000 ____D C:\windows\System32\Tasks\Safer-Networking 2013-11-07 22:13 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\windows\system32\sdnclean64.exe 2013-11-07 22:11 - 2013-11-07 22:11 - 00618912 _____ C:\Users\Viktoria\Downloads\SpyBot Search Destroy - CHIP-Downloader.exe 2013-11-07 22:07 - 2013-11-07 22:07 - 00000000 ____D C:\ProgramData\Oracle 2013-11-07 22:03 - 2013-11-07 22:03 - 00312744 _____ (Oracle Corporation) C:\windows\system32\javaws.exe 2013-11-07 22:03 - 2013-11-07 22:03 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe 2013-11-07 22:03 - 2013-11-07 22:03 - 00189352 _____ (Oracle Corporation) C:\windows\system32\java.exe 2013-11-07 22:03 - 2013-11-07 22:03 - 00108968 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll 2013-11-07 22:03 - 2013-11-07 22:03 - 00000000 ____D C:\Program Files\Java 2013-11-07 22:01 - 2013-11-07 22:01 - 30694824 _____ (Oracle Corporation) C:\Users\Viktoria\Downloads\jre-7u45-windows-x64.exe 2013-11-07 21:00 - 2013-11-09 09:55 - 00001035 _____ C:\windows\setupact.log 2013-11-07 21:00 - 2013-11-07 21:00 - 00000000 _____ C:\windows\setuperr.log 2013-11-07 16:26 - 2013-11-07 16:26 - 00002778 _____ C:\windows\System32\Tasks\CCleanerSkipUAC 2013-11-07 16:26 - 2013-11-07 16:26 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-11-07 16:26 - 2013-11-07 16:26 - 00000000 ____D C:\Program Files\CCleaner 2013-11-07 13:34 - 2013-11-07 13:34 - 00618912 _____ C:\Users\Viktoria\Downloads\CCleaner - CHIP-Downloader.exe 2013-10-30 19:47 - 2013-10-31 08:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-10-30 19:12 - 2013-11-07 16:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-30 18:45 - 2013-10-30 18:47 - 16805158 _____ C:\Users\Viktoria\Downloads\Hochzeitsfotos.zip 2013-10-25 11:50 - 2013-10-25 12:59 - 141025155 _____ C:\Users\Viktoria\Downloads\fotobox (1).zip 2013-10-25 11:31 - 2013-10-25 12:44 - 141025155 _____ C:\Users\Viktoria\Downloads\fotobox(1).zip 2013-10-25 11:11 - 2013-10-25 12:26 - 141025155 _____ C:\Users\Viktoria\Downloads\fotobox.zip 2013-10-23 13:34 - 2013-10-23 13:37 - 104859228 _____ C:\Users\Viktoria\Downloads\Aufnahmen - 14 Dateien.zip 2013-10-22 10:00 - 2013-10-22 10:00 - 00000000 ____D C:\Program Files\McAfee Security Scan 2013-10-10 11:09 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys 2013-10-10 11:09 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys 2013-10-10 11:09 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys 2013-10-10 11:09 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys 2013-10-10 11:09 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys 2013-10-10 11:09 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys 2013-10-10 11:09 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys 2013-10-10 09:38 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2013-10-10 09:38 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2013-10-10 09:38 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2013-10-10 09:38 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2013-10-10 09:38 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2013-10-10 09:38 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2013-10-10 09:38 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2013-10-10 09:38 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2013-10-10 09:38 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2013-10-10 09:38 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll 2013-10-10 09:38 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2013-10-10 09:38 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2013-10-10 09:38 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2013-10-10 09:38 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-10-10 09:38 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-10-10 09:38 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-10-10 09:38 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-10-10 09:38 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-10-10 09:38 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-10-10 09:38 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-10-10 09:38 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-10-10 09:38 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-10-10 09:38 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-10-10 09:38 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-10-10 09:38 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-10-10 09:38 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-10-10 09:38 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-10-10 09:38 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-10-10 09:38 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2013-10-10 09:38 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-10-10 09:38 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-10 09:21 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys 2013-10-10 09:21 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2013-10-10 09:21 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll 2013-10-10 09:21 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswsock.dll 2013-10-10 09:21 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2013-10-10 09:21 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll 2013-10-10 09:21 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll 2013-10-10 09:21 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll 2013-10-10 09:21 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll 2013-10-10 09:21 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe 2013-10-10 09:21 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe 2013-10-10 09:21 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll 2013-10-10 09:21 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll 2013-10-10 09:21 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll 2013-10-10 09:21 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll 2013-10-10 09:21 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe 2013-10-10 09:21 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll 2013-10-10 09:21 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe 2013-10-10 09:21 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe 2013-10-10 09:21 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2013-10-10 09:21 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll 2013-10-10 09:21 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys 2013-10-10 09:21 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-10 09:21 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-10 09:21 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys 2013-10-10 09:21 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys 2013-10-10 09:21 - 2013-07-12 11:40 - 00109824 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBAUDIO.sys 2013-10-10 09:21 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll 2013-10-10 09:21 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll 2013-10-10 09:21 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll 2013-10-10 09:21 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll 2013-10-10 09:21 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll 2013-10-10 09:21 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.dll 2013-10-10 09:21 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys 2013-10-10 09:21 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys 2013-10-10 09:21 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys 2013-10-10 09:21 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys 2013-10-10 09:21 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll 2013-10-10 09:21 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll 2013-10-10 09:21 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll 2013-10-10 09:21 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll 2013-10-10 09:21 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll 2013-10-10 09:21 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll 2013-10-10 09:21 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll 2013-10-10 09:21 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll 2013-10-10 09:21 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll 2013-10-10 09:21 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll ==================== One Month Modified Files and Folders ======= 2013-11-09 22:00 - 2013-11-09 22:00 - 00000000 ____D C:\FRST 2013-11-09 21:59 - 2013-11-09 21:59 - 00000478 _____ C:\Users\Viktoria\Desktop\defogger_disable.log 2013-11-09 21:59 - 2013-11-09 21:59 - 00000000 _____ C:\Users\Viktoria\defogger_reenable 2013-11-09 21:59 - 2010-10-25 18:07 - 00000000 ____D C:\Users\Viktoria 2013-11-09 21:57 - 2013-11-09 21:57 - 00050477 _____ C:\Users\Viktoria\Desktop\Defogger.exe 2013-11-09 21:57 - 2013-11-09 21:52 - 00000000 ____D C:\Users\Viktoria\Desktop\trojaner board 2013-11-09 21:56 - 2013-11-09 21:56 - 00377856 _____ C:\Users\Viktoria\Desktop\gmer_2.1.19163.exe 2013-11-09 21:55 - 2013-11-09 21:55 - 01957098 _____ (Farbar) C:\Users\Viktoria\Desktop\FRST64.exe 2013-11-09 21:53 - 2013-11-09 21:53 - 00050477 _____ C:\Users\Viktoria\Downloads\Defogger.exe 2013-11-09 21:52 - 2012-12-06 15:11 - 00000000 ____D C:\Users\Viktoria\Desktop\VL Räume, Texte, Subjekte 2013-11-09 21:48 - 2010-10-13 19:39 - 01674671 _____ C:\windows\WindowsUpdate.log 2013-11-09 21:28 - 2013-01-03 10:07 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2013-11-09 21:14 - 2010-12-28 20:53 - 00001114 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-09 10:04 - 2009-07-14 05:45 - 00020944 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-09 10:04 - 2009-07-14 05:45 - 00020944 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-09 09:57 - 2012-01-11 23:58 - 00000000 ____D C:\Users\Viktoria\AppData\Roaming\Dropbox 2013-11-09 09:57 - 2010-10-13 18:01 - 00000000 ____D C:\ProgramData\HPQLOG 2013-11-09 09:56 - 2012-01-12 00:04 - 00000000 ___RD C:\Users\Viktoria\Dropbox 2013-11-09 09:55 - 2013-11-07 21:00 - 00001035 _____ C:\windows\setupact.log 2013-11-09 09:55 - 2010-12-28 20:53 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-09 09:55 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT 2013-11-08 21:32 - 2013-09-14 14:26 - 00003346 _____ C:\windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2442261950-2499510287-2221387579-1000 2013-11-08 21:32 - 2013-09-14 14:26 - 00003218 _____ C:\windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2442261950-2499510287-2221387579-1000 2013-11-08 21:25 - 2010-10-25 18:57 - 00000000 ____D C:\Users\Viktoria\AppData\Roaming\Skype 2013-11-08 17:03 - 2010-10-13 18:01 - 00659842 _____ C:\windows\system32\perfh007.dat 2013-11-08 17:03 - 2010-10-13 18:01 - 00131942 _____ C:\windows\system32\perfc007.dat 2013-11-08 17:03 - 2009-07-14 06:13 - 01507502 _____ C:\windows\system32\PerfStringBackup.INI 2013-11-08 11:34 - 2010-10-25 18:57 - 00000000 ____D C:\ProgramData\Skype 2013-11-08 11:14 - 2013-11-08 10:31 - 00000000 ____D C:\Users\Viktoria\Desktop\Feministisch entwickeln 2013-11-08 10:46 - 2013-11-08 10:46 - 00000000 ____D C:\Users\Viktoria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte 2013-11-08 10:46 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\NDF 2013-11-07 22:44 - 2013-11-07 22:13 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-11-07 22:44 - 2013-04-06 22:44 - 00000000 ____D C:\ProgramData\InstallMate 2013-11-07 22:14 - 2013-11-07 22:13 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-11-07 22:13 - 2013-11-07 22:13 - 00001383 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-11-07 22:13 - 2013-11-07 22:13 - 00000000 ____D C:\windows\System32\Tasks\Safer-Networking 2013-11-07 22:11 - 2013-11-07 22:11 - 00618912 _____ C:\Users\Viktoria\Downloads\SpyBot Search Destroy - CHIP-Downloader.exe 2013-11-07 22:07 - 2013-11-07 22:07 - 00000000 ____D C:\ProgramData\Oracle 2013-11-07 22:03 - 2013-11-07 22:03 - 00312744 _____ (Oracle Corporation) C:\windows\system32\javaws.exe 2013-11-07 22:03 - 2013-11-07 22:03 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe 2013-11-07 22:03 - 2013-11-07 22:03 - 00189352 _____ (Oracle Corporation) C:\windows\system32\java.exe 2013-11-07 22:03 - 2013-11-07 22:03 - 00108968 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll 2013-11-07 22:03 - 2013-11-07 22:03 - 00000000 ____D C:\Program Files\Java 2013-11-07 22:01 - 2013-11-07 22:01 - 30694824 _____ (Oracle Corporation) C:\Users\Viktoria\Downloads\jre-7u45-windows-x64.exe 2013-11-07 21:00 - 2013-11-07 21:00 - 00000000 _____ C:\windows\setuperr.log 2013-11-07 16:30 - 2012-05-16 22:00 - 00000000 ____D C:\Users\Viktoria\AppData\Roaming\BitTorrent 2013-11-07 16:30 - 2011-04-09 10:09 - 00000000 ____D C:\Users\Viktoria\AppData\Roaming\Winamp 2013-11-07 16:29 - 2010-12-18 17:25 - 00000000 ____D C:\windows\Minidump 2013-11-07 16:29 - 2009-07-27 16:04 - 00000000 ____D C:\windows\Panther 2013-11-07 16:28 - 2013-10-30 19:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-07 16:26 - 2013-11-07 16:26 - 00002778 _____ C:\windows\System32\Tasks\CCleanerSkipUAC 2013-11-07 16:26 - 2013-11-07 16:26 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-11-07 16:26 - 2013-11-07 16:26 - 00000000 ____D C:\Program Files\CCleaner 2013-11-07 16:25 - 2010-12-28 20:53 - 00002259 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-07 13:34 - 2013-11-07 13:34 - 00618912 _____ C:\Users\Viktoria\Downloads\CCleaner - CHIP-Downloader.exe 2013-11-06 13:25 - 2010-11-01 08:20 - 00000000 ____D C:\Users\Viktoria\Desktop\IE 2013-11-04 10:28 - 2010-11-22 21:43 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log 2013-11-02 12:54 - 2012-05-06 16:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-31 08:10 - 2013-10-30 19:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-10-30 18:47 - 2013-10-30 18:45 - 16805158 _____ C:\Users\Viktoria\Downloads\Hochzeitsfotos.zip 2013-10-25 12:59 - 2013-10-25 11:50 - 141025155 _____ C:\Users\Viktoria\Downloads\fotobox (1).zip 2013-10-25 12:44 - 2013-10-25 11:31 - 141025155 _____ C:\Users\Viktoria\Downloads\fotobox(1).zip 2013-10-25 12:26 - 2013-10-25 11:11 - 141025155 _____ C:\Users\Viktoria\Downloads\fotobox.zip 2013-10-23 13:37 - 2013-10-23 13:34 - 104859228 _____ C:\Users\Viktoria\Downloads\Aufnahmen - 14 Dateien.zip 2013-10-22 10:00 - 2013-10-22 10:00 - 00000000 ____D C:\Program Files\McAfee Security Scan 2013-10-22 10:00 - 2010-10-28 09:32 - 00001931 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2013-10-20 16:38 - 2010-10-25 18:57 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-10-19 18:02 - 2013-03-28 14:39 - 00000000 ____D C:\Users\Viktoria\Desktop\Filme 2013-10-17 12:23 - 2009-07-14 06:08 - 00032640 _____ C:\windows\Tasks\SCHEDLGU.TXT 2013-10-16 18:55 - 2010-10-26 02:56 - 00000000 ____D C:\windows\rescache 2013-10-14 22:09 - 2010-12-28 20:53 - 00004110 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-14 22:09 - 2010-12-28 20:53 - 00003858 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-11 13:54 - 2010-10-25 19:04 - 00000000 ____D C:\Users\Viktoria\AppData\Local\Thunderbird 2013-10-10 10:27 - 2009-07-14 05:45 - 00441264 _____ C:\windows\system32\FNTCACHE.DAT 2013-10-10 10:23 - 2012-05-13 07:26 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-10 10:23 - 2012-05-13 07:26 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-10 09:42 - 2011-10-22 22:11 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-10-10 09:32 - 2013-07-15 16:35 - 00000000 ____D C:\windows\system32\MRT 2013-10-10 09:29 - 2012-12-04 11:37 - 80541720 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-10-10 09:28 - 2013-10-09 20:28 - 17813896 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-10 09:28 - 2013-01-03 10:07 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2013-10-10 09:28 - 2013-01-03 10:07 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater 2013-10-10 09:28 - 2011-11-30 00:10 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl Some content of TEMP: ==================== C:\Users\Viktoria\AppData\Local\Temp\avgnt.exe C:\Users\Viktoria\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-31 08:51 ==================== End Of Log ============================ to be continued.... Geändert von viktoria28 (09.11.2013 um 22:40 Uhr) |
Themen zu Windows 7: Penetrante Werbung und Werbelinks (überall!) im Browser! |
.com, agent, antivirus, appdatalow, autorun, browser, chromium, computer, explorer, explorer.exe, farbar, farbar recovery scan tool, firefox, flash player, google, helper, helper.exe, installation, launch, links, log-file, logfiles, microsoft, object, plug-in, probleme, registry, registry key, safer networking, software, start, user agent, viren, werbung, wickel, windows |